Transit north-south gateway firewall policy looks correct in NSX Manager, but the Edge datapath does not have the rule and permit-desk NAT traffic is unfiltered. What should the administrator check?
Select an answer to reveal the explanation.
Short Explanation
The picture in the UI is not the same as the Edge actually enforcing. Gateway firewall can be off per gateway, or realization can be stuck. Check the Edge datapath, not a UEM profile.
Full Explanation
Gateway firewall policy in the UI is not enforced until it is realized on the Edge and gateway firewall is enabled on that gateway. A disabled gateway firewall or failed realization leaves north-south traffic unfiltered despite a correct-looking policy. DFW exclusion, Workspace ONE UEM, and Carbon Black Cloud are not the gateway datapath.