Courts NSX-T Manager syslog and Carbon Black Cloud check-ins through an on-premises proxy both stall after a core hardware firewall change. Overlay east-west Distributed Firewall still hits. Packet captures stop at the core firewall, which now rate-limits and ACLs those destinations. What should the administrator identify?
Select an answer to reveal the explanation.
Short Explanation
Civic clouds still sit behind a box with blinking lights. If that hardware firewall's ACL or rate-limit started chewing syslog and the CBC proxy, NSX and Carbon Black both look sick while east-west DFW on the host is fine. Fix the physical ACL.
Full Explanation
Physical firewalls often remain in the path for management logging and for SaaS or proxy egress. An ACL or rate-limit on that hardware can starve NSX-T Manager syslog and Carbon Black Cloud connectivity without affecting already-realized east-west Distributed Firewall. Guest Introspection, identity firewall, and Workspace ONE Access network ranges are the wrong first suspects when captures die on the core firewall. Identify and correct the hardware ACL or rate-limit, then retest syslog and sensor or proxy check-in.