NSX allows you to install Distributed Security for vSphere Distributed Switch (VDS). As the host switch is of the type VDS, DFW capabilities can be enabled on workload VMs..
Distributed Security provides security-related functionality to your VDS such as:
- Distributed Firewall (DFW)
- Distributed IDS/IPS
- Identity Firewall
- L7 App ID
- Fully Qualified Domain Name (FQDN) Filtering
- NSX Intelligence
- NSX Malware Prevention
- NSX Guest Introspection
Prerequisites
The following are the requirements for installing Distributed Security for VDS:
- vSphere 7.0 or later.
- The vSphere cluster should have at least one VDS with distributed switch version 6.6 or later configured and ESXi cluster hosts must be members of a VDS with uplinks configured.
- A compute manager must be registered in NSX. See Add a Compute Manager.
Before you deploy and configure Distributed Security on hosts, ensure that NSX is not deployed on such hosts.
Procedure
Results
Distributed Security is installed and you can begin using security capabilities such as creating DFW policies and rules for the VDS.