
VMware NSX Cookbook
By :

Before working with the distributed firewall, it is important to make sure the DFW module is installed and running properly. In this recipe, we will verify NSX DFW status through the command-line interface from an ESXi host.
Make sure you have SSH access to ESXi hosts that are prepared for NSX, and at least auditor access to NSX.
As explained in Chapter 1, Getting Started with Vmware NSX for vSphere, the installation of NSX VIBs is essential for the DFW to operate. If the DFW VIBs are present, we will then verify if the process managing the DFW is running on the ESXi host.
The first obvious thing to check is that the vSphere cluster is prepared for NSX and that the firewall is enabled:
Home
| Networking & Security
| Installation
| Host Preparation
.Firewall
is Enabled
: