You can change the order of user-defined firewall rules that were added in the Edge Firewall tab to customize traffic flowing through the NSX Edge. For example, suppose you have a rule to allow load balancer traffic. You can now add a rule to deny the load balancer traffic from a specific IP address group, and position this rule above the LB allow traffic rule.
Procedure
- Log in to the vSphere Web Client.
- Click .
- Double-click an NSX Edge.
- Click .
- Select the rule for which you want to change the order.
Important: You cannot change the order of system-generated internal rules and the default rule.
- Click the Move Up ( or ) or Move Down ( or ) icon.
Tip: In
NSX 6.4.6 and later, you can drag user-defined rules to change the order. Point to the user-defined rule that you want to drag. A drag handle (
) icon appears to the left of this rule. Click and drag this handle to move the rule to a valid location in the firewall table.
- Click Publish Changes.