5V0-41.21 · Question #42
Which two are true of the NSX Gateway Firewall? (Choose two.)
The correct answer is B. Firewall rules in Pre Rule category are applied to all gateways. D. Security Groups can be used in Applied-To column. NSX Gateway Firewall is a distributed firewall that provides security for east-west traffic within a virtual environment. 1. Firewall rules in Pre Rule category are applied to all gateways. This category contains system- defined rules that are always applied first to all…
Question
Which two are true of the NSX Gateway Firewall? (Choose two.)
Options
- AFirewall rules in System category cannot be edited.
- BFirewall rules in Pre Rule category are applied to all gateways.
- CNAT service can be configured in NSX Gateway Firewall policy.
- DSecurity Groups can be used in Applied-To column.
- EApplied-To can be configured at Firewall Policy level.
How the community answered
(24 responses)- A4% (1)
- B83% (20)
- C4% (1)
- E8% (2)
Explanation
NSX Gateway Firewall is a distributed firewall that provides security for east-west traffic within a virtual environment. 1. Firewall rules in Pre Rule category are applied to all gateways. This category contains system- defined rules that are always applied first to all gateways and cannot be modified. These rules include the default deny all rule and others that control basic connectivity. 2. Security Groups can be used in Applied-To column. Security groups allow you to group together VMs that have similar security requirements and then apply firewall policies to those groups. This way you can apply the same security rules to multiple VMs at once, instead of configuring the rules on each individual VM.
Topics
Community Discussion
No community discussion yet for this question.