If you auto-generate steering policy, you must also auto-generate steering rules. And if
you manually create steering policy, you must also manually create steering
rules.
| Where Can I Use
This? | What Do I Need? |
Steering rules are defined in steering policy.
A rule defines the source and destination of the traffic, introspection
services, the NSX-T objects the rule is applied to, and the traffic
redirection policy. You can create steering rules manually or generate
steering rules automatically.
You must generate or create
steering policy before generating or creating steering rules.
To
auto generate a steering rule based on a security rules created
on Panorama, the security rule must meet the following criteria:
Belongs to a parent or child device group registered with
an NSX-T Service Manager.
Is an intrazone policy and includes only one zone.
Does not include a static address group, IP range, or netmask
configured for the rule.
Auto-generated steering
rules uses the auto_<device-group-name>_<device-group-rule-name> naming format.
By
default, auto-generated steering rules are configured without an
NSX services specified. Additionally, the NSX Traffic Direction
is set to in-out, Logging is disabled, IP protocol is ipv4-ipv6,
and the Action is set to redirect. After auto-generating rules,
you can update the steering to change the default values.
Additionally,
you have the option to select all your service managers instead
of selecting specific service managers. Choosing All is
not recommended.
If you auto-generate steering policy,
you must also auto-generate steering rules. And if you manually
create steering policy, you must also manually create steering rules.
Steering rules changes should be made only
on Panorama; do not make changes on NSX-T Manager. If you make changes
on NSX-T Manager, the Panorama plugin for VMware NSX show the service
definition as out-of-sync. You should click on the Out-of-Sync link
to see the specific reason for the out-of-sync status. If a steering
rules change is the cause, perform a configuration sync by clicking NSX-T
Config-Sync.