VMware vDefend Firewall configured with Identity Firewall
VMware NSX
Event Log Scraping (ELS) in NSX-T/NSX relies on Windows Event ID 4624 (Logon) to map a user's identity to their current IP address. By default, Mac OS clients authenticating against an Active Directory Domain Controller generate a Kerberos TGT request, which results in Event ID 4768 on the Domain Controller. Since NSX ELS does not natively scrape Event 4768, it fails to create a valid IDFW user session for the Mac client's IP address.
To resolve this issue, you must force the Mac OS client to generate a Network Logon event (Event ID 4624) that NSX can scrape.
SYSVOL or NETLOGON share).mount_smbfs command or the "Connect to Server" feature to authenticate against the share during the user's login sequence.vsipioctl getfwconfig -f <filter-id> and verify the IDFW rule includes the ext_src_ip addrset containing the Mac client's IP.