3 Replies Latest reply on Sep 6, 2019 10:15 AM by Firewatch_Colby

    Flows Hitting Multiple NSX DFW Firewall Rules

    Firewatch_Colby Lurker

      Building NSX DFW rules and trying to show only the flows that are hitting the default rule at the end of the firewall policy.  vRNI is showing all flows that could hit the default rule but also that hit other rules.  In reality, if a flow hits a particular rule in DFW, NSX will stop processing the flow and take the designated action.  But vRNI is showing flows that hit on the default rule even when higher-level rules are hit too.  In the output of vRNI, it shows a list of the firewall rules that each flow hits.

       

      Is there a way to query vRNI to show only the flows that would ONLY hit the default rule?