Gateway firewall represents rules applied at the perimeter firewall.

There are predefined categories under the All Shared Rules view, where rules across all gateways are visible. Categories are evaluated from left to right, and the rules within the category are evaluated top down. The category names can be changed using the API.


Used for Quarantine. Can also be used for Allow rules.

These rules are automatically generated by NSX and are specific to internal control plane traffic, such as, BFD rules, VPN rules, and so on.
Note: Do not edit System rules.
Shared Pre Rules

These rules are globally applied across gateways.

Local Gateway

These rules are specific to a particular gateway.

Auto Service Rules

These are auto-plumbed rules applied to the data plane. You can edit these rules as required.


These rules define the default gateway firewall behavior.