This article provides a structured troubleshooting approach for Identity Firewall (IDFW) rules that fail to match traffic as expected. Use these steps to validate configuration, verify log events, and isolate rule-matching issues in Guest Introspection (GI) or Event Log Scraping (ELS) environments.
[root@<ESXI-HostName>~] summarize-dvfilter | grep -A 9 <VM-Name>
port 671##### UPSAv2-02.eth0
vNic slot 2
name: nic-######-eth0-vmware-sfw.2 <<< VM-Filter-Name
agentName: vmware-sfw
state: IOChain Attached
vmState: Attached
failurePolicy: failClosed
serviceVMID: 4
filter source: Dynamic Filter Creation
moduleName: nsxt-vsip-20737187
[root@<ESXI-HostName>~] vsipioctl getrules -f <VM-Filter-Name>
[root@localhost:~] vsipioctl getsidcache -f VM-Filter-Name>
NOTE: The preceding log excerpts are only examples. Date, time and environmental variables may vary depending on your environment
Following are the rule and group configuration recommendations for IDFW rules: