Punkgeek
Enthusiast
Enthusiast

Enhancing ESXi Host Security Against Ransomware with VMware NSX DFW

Hello,

I have an ESXi host with a public IP address, and it is connected to the vCenter via the public IP address. Given that I am unable to move the ESXi into a private network, I'm considering using VMware NSX DFW to enhance its security against ransomware. Would this solution suffice?

Regards,

Reply
0 Kudos
jeffersonc47
Enthusiast
Enthusiast

The NSX DFW can't do firewalling of ESXi host vmk interfaces. However, there is a firewall native to ESXi that you can use - https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-8912DD42-C6EA-429....

Reply
0 Kudos
Punkgeek
Enthusiast
Enthusiast

Thank you for your response.

Is it safe enough to only limit IP addresses in the ESXi firewall?

Reply
0 Kudos