ccrcabiuki's Posts

Is NSX-T a replacement for NSX-V? is this a correct observation?
Thanks for the response with all the great points. We currently have few PA-VM500s deployed in the environment that are basically sitting there whistling. But I know their policy model ... See more...
Thanks for the response with all the great points. We currently have few PA-VM500s deployed in the environment that are basically sitting there whistling. But I know their policy model is not very optimal as they only have rules that apply to the vms that share the same host with them, and vmotion to other clusters has not been considered.
Hello, Our company has purchased Paloalto VM-Series ELA licenses to be deployed for microsegmentation. So we don't have any restriction on number of VM Firewalls or the size of them. My bos... See more...
Hello, Our company has purchased Paloalto VM-Series ELA licenses to be deployed for microsegmentation. So we don't have any restriction on number of VM Firewalls or the size of them. My boss wants to steer all the traffice to VM series firewalls and not use NSX DFW at all, considering two thing, having one single place to manage the traffic and firewall rules. and second because I am the only one with a little bit knowledge of NSX (VCP-NV) and the rest of the team only know PAN he wants to reduce the cost of education and relying only on one resource. I know that when you vmotion a vm the current sessions won't be managed with the VMseries on the new host and they will continue to pass traffic until the session is ended, like a big file transfer or replication. I also know that VRNI which we own as well makes life so easy by detecting traffic flows and suggesting security policies. Other than the above is there any other reason we shouldn't steer all the traffic to VM series? and leave the NSX DFW to allow everything? Regards