The Security Administrator observes unexpected blocked traffic between the App Tier and DB Tier, despite believing the correct DFW rules are in place. They suspect a rule precedence issue or a conflict between Edge Gateway rules and DFW rules.
What are characteristic differences between how Edge Gateway firewalls and Distributed Firewalls process traffic in the VCD/NSX-T environment described? (Select all that apply.)
A. Distributed Firewall rules are processed only on the NSX Edge Transport Nodes.
B. DFW rules have higher precedence than Edge Gateway firewall rules for traffic between VMs within the OrgVD
C. Edge Gateway firewall rules generally apply to North-South traffic, while DFW rules primarily apply to East-West traffic.
D. Distributed Firewall rules are enforced at the vNIC level of each virtual machine.
E. Edge Gateway firewall rules are stateful by default, whereas DFW rules are stateless by default.
F. Edge Gateway firewall rules are processed only on the NSX Edge Transport Nodes (Service Routers).