City-hall change control wants NSX Manager appliances kept off Distributed Firewall enforcement so a new default-deny cannot lock operators out of the GUI. Where is that exclusion list?
Select an answer to reveal the explanation.
Short Explanation
Don't put the fire-alarm panel on the sprinkler circuit. NSX Managers belong on the Distributed Firewall exclusion list under Security DFW settings—not on a segment checkbox or Workspace ONE.
Full Explanation
The Distributed Firewall exclusion list (Security > Distributed Firewall Exclusion List / DFW settings) prevents listed VMs, including management appliances, from receiving DFW enforcement. That protects NSX Managers from an accidental default-deny. Segment names, transport-zone flags, and Workspace ONE Access do not implement the DFW exclusion list. Associate operators identify that Security DFW setting.