VMware Networking Community
vmware3222
Enthusiast
Enthusiast
Jump to solution

FW - DfW - FW VM what the difference ? what avantages for NSX FW

Hi for all,

I'm confused

i can't see the avantages for NSX FW

what is the difference except that he is in the kernel Smiley Happy

Thank you

Reply
0 Kudos
1 Solution

Accepted Solutions
RPolisuk
Contributor
Contributor
Jump to solution

I am only using NSX firewall. So it is very much possible.

Richard

View solution in original post

Reply
0 Kudos
4 Replies
RPolisuk
Contributor
Contributor
Jump to solution

NSX has two kinds of firewalls - Distributed Firewall (DFW) and Edge  Firewall. Both serve different purposes. The Edge firewall is the firewall you use in the "North/South" case to protect your network from external connections. I am using it as an Internet firewall. The Distributed Firewall protects the actual VM which is more for "East/West" protection. I will be using it to only allow Internet VPN users access to a group of VMs. It can be used to only allow or prevent ports directly to the VM. You are correct that the DFW is in the kernel of the ESX node whereas the Edge Firewall runs as a VM.

I hope this helps a little. I would be happy to answer to the best of my knowledge any other questions you may have.

Richard

vmware3222
Enthusiast
Enthusiast
Jump to solution

Thank you very much Richard

yes i have another question .

is it possible to use only nsx FW  or a physical FW is necessary ?

Reply
0 Kudos
RPolisuk
Contributor
Contributor
Jump to solution

I am only using NSX firewall. So it is very much possible.

Richard

Reply
0 Kudos
vmware3222
Enthusiast
Enthusiast
Jump to solution

Thank you  Richard

Reply
0 Kudos