Two wastewater VMs on the same ESXi host exchange packets that never leave the hypervisor, so the hardware firewall never sees them. Which virtual-networking capability closes that traditional gap?
Select an answer to reveal the explanation.
Short Explanation
Same-host VM talk is like two offices passing notes under the door—the street cop at the hardware firewall never sees it. A distributed firewall sits at each vNIC and reads those notes before they hop. vMotion or Workspace ONE Intelligence does not become that in-host checkpoint.
Full Explanation
Traffic between two vNICs on the same hypervisor can be switched locally and never reach a physical firewall. NSX-T distributed firewall enforces policy at the vNIC, so same-host wastewater workloads are still inspected. Forcing vMotion just to trombone packets, mirroring to Workspace ONE Intelligence, or disabling the virtual switch does not close that hypervisor-bypass gap.