Permitting wants a Distributed Firewall rule that matches HTTP as an application, not only TCP/80, on the civic-web group. Where in Policy-mode NSX Manager is that L7 match defined and then used?
Select an answer to reveal the explanation.
Short Explanation
Port 80 is just the door number; HTTP is the kind of conversation. In Policy mode you define that APP-ID as a context profile under Inventory, then hang it on a DFW rule.
Full Explanation
NSX-T Policy context profiles (APP-ID, FQDN, and similar) are created under Inventory > Context Profiles and referenced in Distributed Firewall rules. That L7 match is a Policy-mode Security/Inventory workflow, not an uplink-profile teaming setting, a Manager-mode logical-switch attribute, or a vRealize Operations metric. Associate operators identify creating the profile and attaching it on the DFW rule.