A school-district Distributed Firewall allow never hits because the student-information VM sits on a VLAN port group that is not prepared for NSX. What should the administrator do first?
Select an answer to reveal the explanation.
Short Explanation
DFW only inspects VMs that live on the NSX fabric. A plain VLAN port group is off that fabric, so the rule never sees the packet. Prepare the host and put the VM on an NSX segment first.
Full Explanation
Distributed Firewall policy applies on NSX-prepared hosts and segments. A VM on an unprepared VLAN is off-fabric, so the rule cannot hit. Duplicating the allow, substituting Carbon Black Cloud isolation, or using Workspace ONE Tunnel does not place the workload on the NSX data plane.