nerdexam
Broadcom-VMware

5V0-41.21 · Question #42

Which two are true of the NSX Gateway Firewall? (Choose two.)

The correct answer is B. Firewall rules in Pre Rule category are applied to all gateways. D. Security Groups can be used in Applied-To column. NSX Gateway Firewall is a distributed firewall that provides security for east-west traffic within a virtual environment. 1. Firewall rules in Pre Rule category are applied to all gateways. This category contains system- defined rules that are always applied first to all…

NSX-T Data Center Architecture and Technologies

Question

Which two are true of the NSX Gateway Firewall? (Choose two.)

Options

  • AFirewall rules in System category cannot be edited.
  • BFirewall rules in Pre Rule category are applied to all gateways.
  • CNAT service can be configured in NSX Gateway Firewall policy.
  • DSecurity Groups can be used in Applied-To column.
  • EApplied-To can be configured at Firewall Policy level.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    83% (20)
  • C
    4% (1)
  • E
    8% (2)

Explanation

NSX Gateway Firewall is a distributed firewall that provides security for east-west traffic within a virtual environment. 1. Firewall rules in Pre Rule category are applied to all gateways. This category contains system- defined rules that are always applied first to all gateways and cannot be modified. These rules include the default deny all rule and others that control basic connectivity. 2. Security Groups can be used in Applied-To column. Security groups allow you to group together VMs that have similar security requirements and then apply firewall policies to those groups. This way you can apply the same security rules to multiple VMs at once, instead of configuring the rules on each individual VM.

Topics

#Gateway Firewall#Pre Rule category#Security Groups#Applied-To

Community Discussion

No community discussion yet for this question.

Full 5V0-41.21 Practice