A logical port, logical switch, or NSGroup can be excluded from a firewall rule.
After you've created a section with firewall rules you may want to exclude an NSX appliance port from the firewall rules.
Note:
NSX automatically adds
NSX Manager and
NSX Edge node virtual machines to the firewall exclusion list.
Prerequisites
Verify that Manager mode is selected in the NSX Manager user interface. See NSX Manager. If you do not see the Policy and Manager mode buttons, see Configure the User Interface Settings.