Configuring the NSX Advanced Firewall service
The NSX Advanced Firewall service enables the following capabilities:
- A distributed IDS/IPS
- A distributed Firewall with the Layer 7 Application ID
- A distributed Firewall (DFW) with an Active Directory-based user ID – Identity Firewall (IDFW)
- A distributed Firewall with FQDN filtering
The NSX Advanced Firewall service further enhances the capabilities of the integrated distributed firewall, by providing end-to-end visibility and protection for the application traffic. This service protects both east-west and north-south traffic flows and offers additional protection against malware. From an architectural perspective, incorporating the NSX Advanced Firewall service into an SDDC is advisable when your design necessitates stringent compliance and security requirements, mandating end-to-end protection for application traffic. The NSX Advanced Firewall service is a paid service, billed per all the hosts in the...