Clinic VMs on the same overlay must have east-west allow and deny rules between application tiers. Which NSX GUI area creates those rules?
Select an answer to reveal the explanation.
Short Explanation
Clinic web talking to clinic app is hallway traffic, not a trip out to the street. East-west rules live under Security, then Distributed Firewall. A hardware perimeter box, Horizon Blast, and NAT are the wrong counters.
Full Explanation
East-west overlay rules between clinic VMs are created as Distributed Firewall policies under Security in the Policy UI. Hairpinning that traffic to a physical perimeter firewall is the traditional problem NSX DFW avoids. Horizon Blast policies are display-protocol settings. NAT translates addresses; it does not implement east-west micro-segmentation.