Transit north-south traffic never hits the NSX-T gateway firewall after a core-switch change. East-west Distributed Firewall still works. The Edge uplink VLAN is missing from the physical trunk toward the Edge host. What should the administrator fix?
Select an answer to reveal the explanation.
Short Explanation
Gateway firewall only sees traffic that actually arrives on the Edge uplink. If the switch trunk forgot that VLAN, north-south never gets to the bouncer while east-west DFW on the host still works. Put the VLAN back on the trunk.
Full Explanation
NSX-T gateway firewall enforces north-south policy on Edge uplinks. If the physical trunk toward the Edge host does not permit the uplink VLAN, north-south traffic never reaches that firewall even when east-west Distributed Firewall on transport nodes remains healthy. Carbon Black Cloud sensors and Workspace ONE UEM compliance are not north-south gateway enforcement. Restore the VLAN on the switch trunk, verify tagging on the uplink, then confirm gateway firewall hits.