Firewall exclusion lists are made of groups that can be excluded from a firewall rule based on group membership.
NSX-T Data Center has system excluded virtual machines, and user excluded groups. NSX Manager and NSX Edge node virtual machines are automatically added to the read-only the System Excluded VMs list. User-defined groups can be excluded from firewall rules, and there are a maximum of 100 groups that can be on the list. IP sets, MAC sets, and Active Directory groups cannot be included as members in a group that is used in a firewall exclusion list.
Antrea groups are not supported in a firewall exclusion list.
Users should not edit the system generated firewall exclusion list. If edited, traffic may be disrupted.