A county on-premises NSX-T Manager cluster has tight Distributed Firewall policy. Workloads in a VMware Cloud SDDC with its own NSX-T instance remain any-any. An engineer added those cloud VMs to an on-premises NSX group. What should the administrator conclude?
Select an answer to reveal the explanation.
Short Explanation
Each NSX Manager cluster is its own security city. Dropping a cloud VM name into an on-prem group does not teleport DFW across the WAN. Fix or duplicate policy in the cloud fabric — don't assume one on-prem group covers VMC.
Full Explanation
NSX-T Distributed Firewall policy is realized by the Manager cluster that prepared those transport nodes. A VMware Cloud or other public-cloud SDDC runs a separate NSX-T instance, so on-premises groups and policies do not automatically apply there. Identity firewall directory sync and Carbon Black Cloud sensor groups also do not stretch on-prem DFW into the cloud SDDC. Troubleshoot multi-cloud posture by treating each fabric separately or by using the vendor's supported cloud security pattern, then author policy where the workloads actually live.