NSX Distributed Firewall
NSX Distributed Firewall (DFW) focuses on East-West traffic and NSX Edge firewall focuses on North-South traffic. Those of us who remember the vCloud network security days will feel like this is an enhancement of the vShield app. Okay! For now, I would certainly agree with that; it is certainly an enhanced feature-rich version of the vShield app firewall. But the app demands that you run a dedicated firewall VM for each host and the virtual machine remains protected irrespective of where they are moving. Apart from the fact that it demands a hypervisor-specific firewall (FW) virtual machine, it was a featureless firewall and installation and troubleshooting was also slightly tedious. NSX Distributed Firewall is a hypervisor kernel-embedded firewall and policies are totally virtualization-aware. What does that mean? We can apply policies on vCenter objects such as data centers and clusters and virtual machine names and tags, and network constructs such as IP/VLAN...