A library Distributed Firewall rule uses an L7 context profile for HTTP, but the catalog flow is TLS-encrypted and application-id never matches. What should the administrator understand?
Select an answer to reveal the explanation.
Short Explanation
An L7 profile is reading labels on the box, and TLS wraps the box in opaque tape. If the protocol is not visible, app-id fails. Use a port-based allow or a design that can see TLS, not wishful decryption.
Full Explanation
NSX L7 context profiles identify applications from visible protocol characteristics. Encrypted TLS often prevents app-id, so the HTTP context profile never matches. Port-based allows or an inspection design that exposes the protocol are the practical alternatives. Carbon Black Cloud and Identity Firewall do not supply DFW L7 classification for that encrypted flow, and context profiles do not automatically decrypt all TLS.