VMware Networking Community
tyt063144
Contributor
Contributor

Issue with DNS Service on Newly Imported EXSI Hosts Affected by Default DFW Rules

We recently installed a new NSX manager and successfully imported a cluster into the manager. Our objective is to use the DFW firewall exclusively for filtering east-west traffic. Accordingly, we opted for the "security only" option while installing NSX on the hosts, assuming that this would not alter any settings since we weren't actively adding firewall rules.

However, we've encountered an unexpected issue: post-import, the DNS service (running on a VM) appears to be impacted. people no longer be able to reach it. The import of the cluster has been our sole action to this point. Could we have overlooked a step during the process, or is there an additional configuration required to resolve this?

Any insights or suggestions would be greatly appreciated.

0 Kudos
1 Reply
EvertAM
Enthusiast
Enthusiast

The default rule in NSX is any any allow (unless that changed between versions). Regardless, if you haven't put anything in overlay segments or VLAN-backed segments, the DFW can't do anything in the first place.

0 Kudos