Learning NSX micro-segmentation
NSX supports advanced ways of defining firewall rules beyond traditional sources – destination IPs. When leveraging micro-segmentation powered by Distributed Firewall (DFW), customers can use native vSphere objects to control the traffic flow.
The benefits of micro-segmentation architecture
Micro-segmentation allows customers to logically separate an SDDC into security zones and provide security control for services that run across each zone, as described in the example of securing a multi-tiered application. DFW is unique, as it is applied to all network parts and dissociates network security policies from network architecture. It allows for the maintenance of security policies while the network infrastructure is modified. Workloads can be migrated, and IP addresses can change while applying the same security policies. Security administrators can leverage traditional non-contextual parameters, such as IP addresses and ports for policies...