28
VM-Series
Deployment
Guide
Supported Deployments—VM Series Firewall on Citrix SDX
Set Up a VM-Series Firewall on the Citrix SDX Server
VM-Series Firewall Before the NetScaler VPX
In this scenario, the perimeter firewall is replaced with the VM-Series firewall that can be deployed using L3, L2,
or virtual wire interfaces. All traffic on your network is secured by the VM-Series firewall before the request
reaches the NetScaler VPX and is forwarded to the servers. For details, see
Deploy the VM-Series Firewall
Before the NetScaler VPX
.
Scenario 2—Secure East-West Traffic (VM-Series Firewall on Citrix SDX)
The VM-Series firewall is deployed along with two NetScaler VPX systems that service different server
segments on your network or operate as termination points for SSL tunnels. In this scenario, the perimeter
firewall secures incoming traffic. Then, the traffic destined to the DMZ servers flows to a NetScaler VPX that
load balances the request. To add an extra layer of security to the internal network, all east-west traffic between
the DMZ and the corporate network are routed through the VM-Series firewall. The firewall can enforce
network security and validate access for that traffic. For details, see
Secure East-West Traffic with the VM-Series
Firewall
.