VMware Networking Community
vmmedmed
Enthusiast
Enthusiast
Jump to solution

Verifying DFW rules were pushed to the vnic of all intended VMs

After you publish new Distributed Firewall Rules, how can you verify that each VM affected

by the new rules have them in fact, working at their vNic?

Tags (1)
0 Kudos
1 Solution

Accepted Solutions
Sreec
VMware Employee
VMware Employee
Jump to solution

Yes, you can fetch it via NSX Manager as well

CLI Commands for DFW

---------------------------------------------------------------------------------------------------------

Was it helpful? Let us know by completing this short survey here.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered

View solution in original post

4 Replies
Sreec
VMware Employee
VMware Employee
Jump to solution

One way of checking is like below

1.vsipioctl getfilters

2.vsipioctl getrules -f  nic-2739622-eth0-vmware-sfw.2(give the respective  filtername)

3.For active connections/flows you can use getconnections/getflows instead of getrules command.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
vmmedmed
Enthusiast
Enthusiast
Jump to solution

That's very helpful. Thank you. On this consult gig I don't think I have access to the ESXi hosts unfortunately.

Only access to NSX, VRNI, vCenter. Perhaps access to the CLI NSX. Perhaps a thought on verifying the

push with one of those tools?

0 Kudos
nipanwar
Enthusiast
Enthusiast
Jump to solution

Vmwre docs provide more details around it, Troubleshooting Distributed Firewall

Sreec
VMware Employee
VMware Employee
Jump to solution

Yes, you can fetch it via NSX Manager as well

CLI Commands for DFW

---------------------------------------------------------------------------------------------------------

Was it helpful? Let us know by completing this short survey here.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered