NSX Security, the Money Maker

Elver Sena Sosa · 2020

The primary function of Edge Firewall is to filter North-South traffic in and out of the NSX environment. Traditional router Access Control List firewall solutions were built around the idea that most of the traffic is what enters and exits the network (North-South), while server-to-server traffic (East-West) is secondary in volume. This chapter helps readers to understand the placement of Distributed Firewall (DFW) in the IOChain. Traditional firewalls have rules based on five elements (5-tuple) of IP traffic: source IP address, destination IP address, source port number, destination port number, and protocol. The main components for NSX DFW internal communications are vCenter, the NSX Manager, and the ESXi host. When NSX Manager pushes the rule to the firewall service on an ESXi host, it sends it over the established channel, which is encrypted with SSL.

Read the paper · More papers on PaperTik