Discovering the NSX Advanced Firewall Add-On
The NSX Advanced Firewall Add-On is available to customers as a purchase option on top of the SDDC costs, and it has to be activated for all hosts in the SDDC cluster. NSX Advanced Firewall helps customers enhance the NSX security capabilities beyond distributed Layer 4 firewall security to advanced application security capabilities, such as distributed IPS/IDS, Layer 7 Context Profiles (app IDs), FQDN filtering, and Identity-Based Firewall.
IPS/IDS
NSX Distributed IPS/IDS inspects all traffic inside an SDDC without any dependency on its architecture, which contrasts with traditional IPS/IDS solutions where networking architecture needs to be taken into significant consideration when deploying an IPS/IDS solution.
Security administrators can create a virtual zone in a SDDC using the DFW and IDS/IPS features. IPS/IDS can detect and prevent the lateral movement of attackers who infiltrate data centers, leveraging attack signatures...