Environments running workloads with ENS Poll Mode enabled eperience any of the below behaviours:
Create Dedicated Logical Switches (Segments) or Ports and add it to the firewall exclusion list.
Log into the NSX Manager UI.
Navigate to Security > Distributed Firewall.
Click the Actions dropdown menu on the firewall policy window and select Exclusion List.
Choose either logical switches or logical potrs as per the infrastructure design:
Select Logical Switches (Segments) to add the entire network segment hosting the workloads.
Select Logical Ports to target the specific virtual ports bound to the impacted virtual machines.
Click Save / Apply.
Any current or future virtual machine connected to these excluded switches or ports will automatically bypass the NSX DFW firewall inspection.
Automate Exclusion using Infrastructure Tags
Create a tag at the vCenter Server Create a Tag, ensure target virtual machines are assigned a designated tag identifier (e.g., Category: Workload-Type, Tag: <Tag name>).
Log into NSX Manager and navigate to Inventory > Groups.
Click Add Group.
Click Set Members and stay on the default Membership Criteria tab.
Click Add Criterion and set the rule: Object: Virtual Machine | Property: Tag | Operator: Equals | Value: <Tag name>.
Click Apply, then Save.
Return to Security > Distributed Firewall > Actions > Exclusion List.
Under the Groups tab, add your newly created dynamic group and click Save.