Inspectors' home traffic hits a civic firewall rule that allows TCP 443 only to the Unified Access Gateway VIP. Other inbound ports stay closed. What is that rule doing?
Select an answer to reveal the explanation.
Short Explanation
The firewall is a locked service window: 443 to the UAG address, nothing else inbound. Inspectors do not get raw RDP to desktop VMs. That allow-list is basic civic firewalling, not a vCenter publish.
Full Explanation
A firewall allow-list to Unified Access Gateway on 443 is the associate pattern for remote Horizon access. Desktop VMs and vCenter stay off the internet. The rule does not disable TLS and it is not an invitation to expose RDP. Operators should describe the access appliance as the inbound target.