In addition to the NSX Distributed Firewall, NSX also provides firewall functionality on the NSX ESG. The Edge can perform layer 2 to layer 4 firewalling, and is intended to complement the Distributed Firewall to restrict north/south flows from a logical networking segment.
In this recipe, we will configure a single firewall rule on the NSX ESG to allow SSH access from a virtual machine. The following diagram depicts the topology for this recipe and the ESG where the firewall rule will be configured:
![](https://static.packt-cdn.com/products/9781782174257/graphics/assets/9bee0a10-c113-4b97-a42a-0c14f7396f47.png)