If we look at vSphere, we can see new port groups, which contain the name of the VRF and the bridge domain:
Earlier, we placed the interfaces of the ASA into the first set of port groups that were created when we joined the tenant to the VMWare domain. Now if we check on the ASA, we can see that they have changed:
If we look at the ASA's configuration, we can see the access-list-inbound access list, containing the extra entry we added:
ASAv# show access-list access-list cached ACL log flows: total 0, denied 0 (deny-flow-max ...