<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NSX Edge as perimeter firewall in Networking Members</title>
    <link>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837726#M10</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;As you see, distributed IDS/IPS is a new feature for East-West traffics. Otherwise, you could enable NSX Edge Firewall rules or the other stateful services on T1 level, so that you may deploy T0 in active-active mode.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 01:22:20 GMT</pubDate>
    <dc:creator>AntareSLyu</dc:creator>
    <dc:date>2021-03-24T01:22:20Z</dc:date>
    <item>
      <title>NSX Edge as perimeter firewall</title>
      <link>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837452#M6</link>
      <description>&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;Hi Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;I have one concern/feasibility check request from customer to consider VMware edge as perimeter firewall for their IT private cloud.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;Afaik, above theory is not reco&lt;/SPAN&gt;&lt;SPAN&gt;mmended as Edge firewall lacks advanced features such as IDS,IPS etc,. (At least I’m not aware if they are supported)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;My queries are below&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;1. Can Gateway firewall supports IDS ? (For North-south traffic)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;2. Let's say if I use gateway firewalls in&amp;nbsp;&lt;/SPAN&gt;cluster, will there be stateful information sync between them. For example, if one gateway firewall is down then do clients need to re-establish their connection?&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;3. If I integrate 3rd party service firewalls, can they work as Active/Active cluster? I see there is a limitation of running Active/Standby services in NSX for stateful services. Is this citation applicable to 3rd party services as well?&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Thanks in advance.&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 05:31:17 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837452#M6</guid>
      <dc:creator>cbg2008</dc:creator>
      <dc:date>2021-03-23T05:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: NSX Edge as perimeter firewall</title>
      <link>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837460#M7</link>
      <description>&lt;P&gt;As far as I am aware IDS/IPS is enabled at the hypervisor level and not at the edge, if you are going to be using an SVM / service insertion then the t0 gateway has to be in Active-Standby.&amp;nbsp;&lt;A href="https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.1/administration/GUID-53D6C480-7AD3-4B23-922D-430C89992B57.html" target="_blank"&gt;https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.1/administration/GUID-53D6C480-7AD3-4B23-922D-430C89992B57.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Have you had a look at the security reference design guide&amp;nbsp;&lt;A href="https://nsx.techzone.vmware.com/resource/nsx-security-reference-design-guide" target="_blank"&gt;https://nsx.techzone.vmware.com/resource/nsx-security-reference-design-guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Also the reference design guide&amp;nbsp;&lt;A href="https://communities.vmware.com/t5/VMware-NSX-Documents/VMware-NSX-T-Reference-Design/ta-p/2778093" target="_blank"&gt;https://communities.vmware.com/t5/VMware-NSX-Documents/VMware-NSX-T-Reference-Design/ta-p/2778093&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;This blog my be of use as well.&amp;nbsp;&lt;A href="https://blogs.vmware.com/networkvirtualization/2020/08/the-nsx-t-gateway-firewall-secures-physical-servers.html/#:~:text=We%20can%20use%20the%20NSX,any%20site%2C%20and%20any%20cloud" target="_blank"&gt;https://blogs.vmware.com/networkvirtualization/2020/08/the-nsx-t-gateway-firewall-secures-physical-servers.html/#:~:text=We%20can%20use%20the%20NSX,any%20site%2C%20and%20any%20cloud&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;Just trying to dig up some information regarding states for you.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 06:25:33 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837460#M7</guid>
      <dc:creator>shank89</dc:creator>
      <dc:date>2021-03-23T06:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: NSX Edge as perimeter firewall</title>
      <link>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837462#M8</link>
      <description>&lt;P&gt;Does that mean we can't have IDS at Edge firewall for North-South traffic&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 06:36:16 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837462#M8</guid>
      <dc:creator>cbg2008</dc:creator>
      <dc:date>2021-03-23T06:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: NSX Edge as perimeter firewall</title>
      <link>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837484#M9</link>
      <description>&lt;P&gt;IDS is currently not supported on the Edge, you can youse introspection / SVM's to inspect traffic if you'd like.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 08:32:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837484#M9</guid>
      <dc:creator>shank89</dc:creator>
      <dc:date>2021-03-23T08:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: NSX Edge as perimeter firewall</title>
      <link>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837726#M10</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;As you see, distributed IDS/IPS is a new feature for East-West traffics. Otherwise, you could enable NSX Edge Firewall rules or the other stateful services on T1 level, so that you may deploy T0 in active-active mode.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 01:22:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Networking-Members/NSX-Edge-as-perimeter-firewall/m-p/2837726#M10</guid>
      <dc:creator>AntareSLyu</dc:creator>
      <dc:date>2021-03-24T01:22:20Z</dc:date>
    </item>
  </channel>
</rss>

