VMware Networking Community
thiefqw
Contributor
Contributor

How does nsx-t protect esxi itself

Can NSX protect the MGMT vmkernel of esxi through DFW and IDS / IPS
Reply
0 Kudos
3 Replies
SandeepMan
Contributor
Contributor

its is totally depend on your requirement why do you want to do .

Reply
0 Kudos
Sreec
VMware Employee
VMware Employee

DFW is certainly supported. However, it will create cyclic dependency and that is a key reason it is recommended to avoid for the management plane communication. If you have serious limitations with existing firewall devices, you can consider this approach. When more solutions are getting integrated, it will become a tedious job. IDS/IPS use is targeting workloads running on top of the hypervisor. You should rather follow the vSphere security guide to harden the vSphere platform.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
Reply
0 Kudos
thiefqw
Contributor
Contributor

Thank you for your answer! Because our security department asked us to use IDS \ IPS function to protect esxi itself
Reply
0 Kudos