Configuring and viewing the NSX Distributed Firewall Log
In this recipe, we will work through the process of configuring an ESXi host to ship log data to a centralized syslog server, configure a distributed firewall rule to log all flows that match its five tuple rule, and view the DFW log on the ESXi host via the console.
Getting ready
You will need to have the following access and configurations present before proceeding with this recipe:
- NSX Manager deployed
- Access to vCenter Server via the vSphere Web Client
- Syslog collector available for the log shipment
- Access to the ESXi host via the SSH protocol
How to do it...
This recipe is made up of two different parts-configuring NSX DFW log and viewing NSX DFW logs.
Configuring the NSX DFW logs
NSX DFW logs are part of the ESXi host log and need to be configured on each ESXi host that has NSX DFW installed:
- Log in to the
vSphere Web Client
UI, navigate toHome
|Host & Clusters
, and select an ESXi host. In the center pane of the selected ESXi host...