52
VM-Series
Deployment
Guide
VM-Series NSX Edition Firewall Overview
Set Up a VM-Series NSX Edition Firewall
Traffic that does not need to be inspected by the VM-Series firewall, for example network data backup or
traffic to an internal domain controller, does not need to be redirected to the VM-Series firewall and can be
sent to the virtual switch for onward processing.
Rules centrally managed on Panorama and applied by the VM-Series firewall
—The next- generation
firewall rules are applied by the VM-Series firewall. These rules are centrally defined and managed on
Panorama using templates and device groups and pushed to the VM-Series firewalls. The VM-Series firewall
then enforces security policy by matching on source or destination IP address—the use of Dynamic Address
Groups allows the firewall to populate the members of the groups in real time—and forwards the traffic to
the filters on the NSX Firewall.
To understand how the NSX Manager and Panorama stay synchronized with the changes in the SDDC and
ensure that the VM-Series firewall consistently enforces policy, see
Policy Enforcement using Dynamic
Address Groups
.
Policy Enforcement using Dynamic Address Groups
Unlike the other versions of the VM-Series firewall, the NSX edition does not use security zones as the primary
traffic segmentation mechanism because both virtual wire interfaces belong to the same zone. Instead, the NSX
edition uses Dynamic Address Groups to segment traffic.
A Dynamic Address Group is used as a source or destination object in security policy. Because IP addresses are
constantly changing in a datacenter environment, Dynamic Address Groups offer a way to automate the process
of referencing source and/or destination addresses within security policies. Unlike static address objects that
must be manually updated in configuration and committed whenever there is an address change (addition,
deletion, or move), Dynamic Address Groups automatically adapt to changes.
All security groups defined on the NSX Manager are automatically provided as updates to Panorama using the
NetX API management plane integration and can be used as filter criteria to create Dynamic Address Groups;
the firewall filters for the name of the security group, which is a tag, to find all the members that belong to a
security group.