The 311 VIP needs centralized NAT, while east-west isolation between 311 VMs uses the Distributed Firewall. How do Edge and host data planes interact for those services?
Select an answer to reveal the explanation.
Short Explanation
East-west inspection lives on the hosts; NAT for a VIP is a centralized Edge job. Do not flip those planes. vCenter HA is not the NAT box.
Full Explanation
NSX runs distributed services such as overlay switching and Distributed Firewall on hypervisor transport nodes, while centralized services such as NAT run on Edge nodes. That is the Edge versus host data-plane interaction for a 311 VIP plus east-west DFW. Hosts do not own centralized NAT, Edges do not replace DFW on every vNIC, and vCenter HA does not terminate those services.