Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Magnus-Holmberg
Advisor

vSEC NSX with MDS

Hi,

With vSEC NSX do you have the possibility to select what sort of security groups etc should be visible in each CMA when running it with MDS?

When am checking all "design documents" for NSX it looks like everyone running some sort of physical gateway like an vSEC VE or an VSX. is there a reason why the NSX "gw" it self cant be used as peremeter fw?

In specific case it would be a client VRF that would be connecting to the NSX network and not Internet to say.

Regards,
Magnus

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
1 Reply
Pablo_Barriga
Advisor

Hello Magnus, I was checking also some designs as far as I know Vsec NSX only works with east to west traffic because it is using Network Introspection, to connect to external network or other devices you need to use the Edge router of NSX o Vsec VE, the DLR can be used as Designated Instance.

Some good sites 


https://blah.cloud/networks/implementing-multi-tenant-networking-platform-nsx/

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/vcat/vmware-architecting-tenant-ne...

http://chansblog.com/6-nsx-distributed-logical-router/

http://virtualelephant.com/2016/11/22/nsx-dlr-designated-instance/

https://blogs.vmware.com/networkvirtualization/2013/11/distributed-virtual-and-physical-routing-in-v...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.