---
title: "Distributed Firewall Traffic Flow"
slug: "distributed-firewall-traffic-flow"
updated: 2023-03-27T14:38:10Z
published: 2023-03-27T14:38:10Z
canonical: "kb.expedient.com/distributed-firewall-traffic-flow"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Distributed Firewall Traffic Flow

![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/image-1679922861431.png)

**Steps as shown in the above diagram:**

1. Write Rules in the Distributed Firewall (DFW) config in vCD
2. Upon Saving, vCD pushes rules to the applicable Hypervisors
  1. If your rule references IPs used by VM1 and VM2 only, then the rule is pushed only to Hypervisor A.
  2. If your rule references IPs used by VM2 and VM4, then appropriate rule(s) are pushed to Hypervisor A and B
3. Traffic between VM 1 and VM 2 is shown - Remember that DFW rules contain "in," "out," and "in/out" directionality
4. Traffic between VM 2, VM4, and some external IP
