Library overlay VMs lose DNS after a resolver outage, and NSX-T FQDN-based Distributed Firewall context profiles stop matching even though IP/port rules still hit. What should the administrator restore first?
Select an answer to reveal the explanation.
Short Explanation
FQDN firewall is a bouncer that only recognizes names it just heard at DNS. If the library VMs cannot reach a resolver, that bouncer never learns the IP and the context profile looks broken while plain IP/port rules still work. Fix DNS first.
Full Explanation
NSX-T FQDN-based Distributed Firewall rules depend on DNS resolution and DNS snooping so context profiles can map names to IPs. When overlay workloads cannot reach DNS, those mappings go stale or never populate, so FQDN rules stop matching while L4 IP/port rules continue to hit. Carbon Black Cloud hash rules, identity firewall logon events, and Workspace ONE Access network ranges do not populate NSX FQDN context. Restore DNS connectivity on the overlay, then confirm context-profile hits.