vSEC NSX with MDS
With vSEC NSX do you have the possibility to select what sort of security groups etc should be visible in each CMA when running it with MDS?
When am checking all "design documents" for NSX it looks like everyone running some sort of physical gateway like an vSEC VE or an VSX. is there a reason why the NSX "gw" it self cant be used as peremeter fw?
In specific case it would be a client VRF that would be connecting to the NSX network and not Internet to say.
Hello Magnus, I was checking also some designs as far as I know Vsec NSX only works with east to west traffic because it is using Network Introspection, to connect to external network or other devices you need to use the Edge router of NSX o Vsec VE, the DLR can be used as Designated Instance.
Some good sites