Understanding and configuring the Universal Distributed Firewall
The Universal Distributed Firewall allows centralized management of firewall rules that apply to all DFW-prepared ESXi hosts in your environment. Cross-vCenter vMotion is also supported, which enables you to move workloads or virtual machines from one vCenter server to another with a security policy that follows the VM as it migrates between data centers.
The Universal Distributed Firewall supports both layer 2 (L2) and layer 3 (L3) rules to span across vCenter domains; universal rules take precedence over local distributed firewall rules and are contained in universal firewall sections. The universal rules are populated into their corresponding L2 or L3 universal sections, which are then synchronized to the Secondary NSX Manager(s) using the universal synchronization service.
Note
It is important to note that universal and local distributed firewall rules are not mutually exclusive, and both can be used in any NSX domain.
The...