VMware Networking Community
vmmedmed
Enthusiast
Enthusiast
Jump to solution

NSX Firewall Rule Processing

Real basic question:

Are rules processed from top down in NSX firewall? That is - suppose

rule no 1 says deny traffic from host 10.10.10.100 to the Internet.

But rule 10 says permit port 80 traffic from host 10.10.10.100 to

Internet host 5.5.5.5. Should the specificity of rule 10 win the

day or is the top position of rule No 1 win the day? Thank you.

0 Kudos
1 Solution

Accepted Solutions
grosas
Community Manager
Community Manager
Jump to solution

Yes - top to bottom; only the first match applies to the flow.

_____________________________________
Gabe Rosas (VMware HCX team at VMware)
Blog: hcx.design
LinkedIn: /in/gaberosas
Twitter: gabe_rosas

View solution in original post

0 Kudos
2 Replies
grosas
Community Manager
Community Manager
Jump to solution

Yes - top to bottom; only the first match applies to the flow.

_____________________________________
Gabe Rosas (VMware HCX team at VMware)
Blog: hcx.design
LinkedIn: /in/gaberosas
Twitter: gabe_rosas
0 Kudos
vmmedmed
Enthusiast
Enthusiast
Jump to solution

Thank you. That appeared to be the case based on the logging that I saw. But wanted to confirm.

0 Kudos