Chapter 6. NSX Security Features
Traditionally, isolating and securing a network was done at the perimeter level of any data center, which was an error-prone and time-consuming activity. In the current Software Defined Data Center world, where most workloads are dynamic, we need better control over the security feature, and at the same time we expect configuration and management of these tasks to be automated without compromising any security features. If there is a virtual machine migration from one server to another server all my polices should move along with that irrespective of Layer 2 and Layer 3 boundaries. But the real question would be, is that really possible? In this chapter, we will discuss how NSX has changed the view of modern-day data center security. We will be covering the following topics with some classic examples:
- NSX Distributed Firewall
- NSX Service Composer
- NSX Distributed Firewall monitoring
- NSX SpoofGuard
- DFW takeaways