VMware NSX

 View Only

nsx-v dfw permit / deny installed on the edge

  • 1.  nsx-v dfw permit / deny installed on the edge

    Posted Mar 12, 2022 03:57 PM

    Hi

    I added "permit any any" rule installed on one egde. After some time I see the counter is zero but in the vRealize Log I see logs related to that rule but only HA related. When I add the "deny any any" installed on the same edge the HA related traffic is dropped by the rule.

    My questions:

    1. Why the HA related traffic don't increase the counter?

    2. Is it related with the fact the HA traffic is sent via internal interface (traffic via uplinks show counters correctly)?

    3. Can you confirm the explicit "permit 169.254.1.X 169.254.1.X" is enough to not break HA cluster (when I have "deny any any" installed on the same edge)?

    Thanks