You can create groups to be used as source and destination for firewall rules. Groups include different objects that can be a combination of virtual machines, IP sets, MAC sets, segment ports, segments, AD user groups, and other groups. While configuring a group, you can add objects both statically and dynamically. To add objects dynamically, you have to specify a criteria based on tag, machine name, OS name, or computer name. When a rule has to be applied to a group, NSX-T Data Center processes the criteria to calculate members dynamically and adds or removes objects based on conditions of the criteria.
Groups can also be excluded from firewall rules, and there are a maximum of 100 groups that can be on the list. IP sets, MAC sets, and AD groups cannot be included as members in a group that is used in a firewall exclusion list. See Manage a Firewall Exclusion List for more information.
A single group can be used as the source only within a distributed firewall rule. If IP and Active Directory groups are needed at the source, create two separate firewall rules.
Groups consisting of only IP addresses, MAC Addresses, or Active Directory groups cannot be used in the Applied to text box.For Policy Groups containing IPs, MAC addresses, and Identity Groups the listing API will NOT display the ‘members’ attribute. This applies to Groups containing a combination of static members also. For example, a Policy Group containing IP and VMs, will not display the the members attribute.
For Policy Groups not containing IPs, MAC addresses, or Identity Groups, the member attribute will be displayed in the NSGroup response. However new members and criteria introduced in NSX-T Data Center (such as DVPort and DVPG) will not be included in the MP group definition. Users can view the definition in Policy.
Tags in NSX are case-sensitive, but a group that is based on tags is "case- insensitive." For example, if the dynamic grouping membership criterion is VM Tag Equals 'quarantine'
, the group includes all VMs that contain either the tags 'quarantine' or 'QUARANTINE'.
If you are using NSX Cloud, see Group VMs using NSX-T Data Center and Public Cloud Tags for information on the how to use public cloud tags to group your workload VMs in NSX Manager.