Distributed Firewall Rule Status Identification (Greyed Out Toggle)
search cancel

Distributed Firewall Rule Status Identification (Greyed Out Toggle)

book

Article ID: 444134

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

  • NSX Role-Based Access Control grants varying levels of Read, Write, Update, and Delete permissions to NSX Users. 
  • When a user with only Read permissions for the Distributed Firewall (DFW) views DFW rules in the NSX UI, the toggle to enable or disable rules appears greyed out. This is by design to serve as a visual indicator that the user lacks permission to edit the rule's state. 

Environment

VMware NSX

vDefend Firewall

Cause

This is expected behavior for users with read-only permissions.

Resolution

  • For enabled rules, the circle will be on the right side of the toggle switch. Emphasized with a green outline in the screenshot below.
  • For disabled rules, the circle will be on the left side of the toggle switch. Emphasized with a red outline in the screenshot below.
 
 
  • Additionally, a text box stating "Deactivate Rule" will pop up when hovering your cursor over the toggle for enabled rules. You will instead see a text box stating "Activate Rule" when hovering over the toggle for disabled rules. In both cases the toggle remains unclickable because the user lacks the required permissions.