cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

vSEC NSX with MDS

Hi,

With vSEC NSX do you have the possibility to select what sort of security groups etc should be visible in each CMA when running it with MDS?

When am checking all "design documents" for NSX it looks like everyone running some sort of physical gateway like an vSEC VE or an VSX. is there a reason why the NSX "gw" it self cant be used as peremeter fw?

In specific case it would be a client VRF that would be connecting to the NSX network and not Internet to say.

Regards,
Magnus

Tags (2)
0 Kudos
1 Reply
Highlighted

Re: vSEC NSX with MDS

Hello Magnus, I was checking also some designs as far as I know Vsec NSX only works with east to west traffic because it is using Network Introspection, to connect to external network or other devices you need to use the Edge router of NSX o Vsec VE, the DLR can be used as Designated Instance.

Some good sites 


https://blah.cloud/networks/implementing-multi-tenant-networking-platform-nsx/

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/vcat/vmware-architecting-tenant-ne...

http://chansblog.com/6-nsx-distributed-logical-router/

http://virtualelephant.com/2016/11/22/nsx-dlr-designated-instance/

https://blogs.vmware.com/networkvirtualization/2013/11/distributed-virtual-and-physical-routing-in-v...

0 Kudos