Distributed Firewall takeaways
Distributed Firewall is a feature-rich firewall. But we have to be extremely careful while installing and creating rules. Gone are the days when gigantic physical firewalls were used for traffic filtering and other security measures. Applications demanded firewalls to be a little closer to them rather than running at Top of Rack (TOR). All we needed was a stateful firewall that is more application-aware. When we are inspecting the traffic at near line rate processing that too for East-West traffic which will give us better visibility over the traffic and reduces any attacking loopholes in virtualized data centers, we can call NSX DFW firewall the foundation pillar of Micro Segmentation. Worried about bottlenecks? No problem! DFW is the new kid in town. Let's have a quick look at a few key takeaways from this chapter.
DFW doesn't demand any physical network topology changes.
Make a note of all management virtual machines (VMware appliances, third-party appliances...