NSX security basic configuration
The NSX Edge firewall, also known as the Gateway Firewall in VMware Cloud on AWS, provides security for North/South traffic. There are two default Edge firewalls: the MGW firewall, and the CGW firewall. In addition, as we have seen in this chapter, each Tier-1 gateway manages its own firewall rules.
Management Gateway firewall
The Management Gateway firewall protects access to management components such vCenter and NSX.
There are two types of management groups: predefined management groups and user-defined management groups. When choosing a source or destination for a management firewall rule, there are three choices: Any, System-Defined, and User-Defined.
System-defined groups simplify the creation of common Management Gateway firewall rules. User-defined groups allow the creation of custom groups based only on an IP address. Such groups are commonly used to provide remote administrators access to management components.
You manage the...