Follow the steps below and commands on how to verify DFW rules that get pushed into the ESXi host from NSX Manager:
- Log in to the NSX Manager console.
- To locate the vNIC filter name, use the following commands:
show dfw cluster all show dfw cluster <cluster id> show dfw host <host-id> show dfw vm <vm-id>
- To show the applied rules, use the command show dfw host <host id> filter <filter name> rules.
- The output will use NSX internal objects addrset such as dst###, ip-ipset-#, and ip-vm-### as the source or destination. To view the actual mapping between internal objects and the associated IP or MAC address, use the command show dfw host host-31 filter nic69373-eth0-vmware-sfw.2 addrsets.