IP Sets are not supported in the "Applied to" field of the DFW.
The "Applied to" field of the DFW supports only the following selected objects:
- Cluster
- Datacenter
- Distributed Virtual Port Group
- NSX Edge
- Network
- Virtual Machine
- vNIC
- Logical Switch
- Security Group
- Host System
For more information, see the
NSX-v 6.3 Administration Guide.
While all of the above items are supported in the "Applied to" field, it is possible to configure unsupported items indirectly through the DFW interface. For instance, an IP or MAC set can be applied to a given Security Group, and then apply the DFW to that Security Group. This results in an unsupported configuration and NSX Manager does not push the firewall rules to the VMs/hosts.