You add firewall rules at the NSX Manager scope. Using the Applied To field, you can then narrow down the scope at which you want to apply the rule. You can add multiple objects at the source and destination levels for each rule, which helps reduce the total number of firewall rules to be added.
Procedure
Create a Firewall Rule You add firewall rules at the NSX Manager scope. Using the Applied To field, you can then narrow down the scope at which you want to apply the rule. You can add multiple objects at the source and destination levels for each rule, which helps reduce the total number of firewall rules to be added.
Add a Firewall Rule Source or Destination You can use IP addresses, vCenter objects, and NSX grouping objects as sources. You can also define sources and destinations and negate them. If no sources or destinations are defined, the source or destination is set to "any".
Add a Firewall Rule Service For firewall rules you can create a new service group or use a predefined service group.
Specify a Firewall Rule Action and Logging Firewall rules can be set to allow, block, or reject traffic from a specified source, destination, or service.
Define the Firewall Scope Using the Applied To field, you can narrow down the scope at which you want to apply the rule.
Publish a Firewall Rule After creating a new firewall rule, you have to publish it for changes to take effect.