County finance requires Spoof Guard on the treasury overlay so VMs cannot spoof MAC or IP addresses. How is that enabled in the NSX GUI?
Select an answer to reveal the explanation.
Short Explanation
Spoof Guard is a name-tag checker at the segment door: only the MAC/IP NSX already learned may speak. Stick a Spoof Guard segment profile on the treasury segment in Networking—IDFW, FT, and NAT64 are not that checker.
Full Explanation
Spoof Guard is enabled by attaching a Spoof Guard segment profile to the target segment (or port) in the Networking UI so unauthorized MAC/IP combinations are dropped at the vNIC. Identity firewall groups users, not MAC/IP spoofing. vSphere FT is a compute HA feature, and NAT64 is a professional translation service outside this associate GUI task.