- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: vSEC NSX with MDS
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
vSEC NSX with MDS
Hi,
With vSEC NSX do you have the possibility to select what sort of security groups etc should be visible in each CMA when running it with MDS?
When am checking all "design documents" for NSX it looks like everyone running some sort of physical gateway like an vSEC VE or an VSX. is there a reason why the NSX "gw" it self cant be used as peremeter fw?
In specific case it would be a client VRF that would be connecting to the NSX network and not Internet to say.
Regards,
Magnus
- Tags:
- mds r80.10
- vsec nsx
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Magnus, I was checking also some designs as far as I know Vsec NSX only works with east to west traffic because it is using Network Introspection, to connect to external network or other devices you need to use the Edge router of NSX o Vsec VE, the DLR can be used as Designated Instance.
Some good sites
https://blah.cloud/networks/implementing-multi-tenant-networking-platform-nsx/
http://chansblog.com/6-nsx-distributed-logical-router/
http://virtualelephant.com/2016/11/22/nsx-dlr-designated-instance/