Quantcast
Channel: VMware Communities: Message List
Viewing all articles
Browse latest Browse all 258290

Re: VMtools + NSX Micro Segmentation

$
0
0

Dear nsxv4746,

 

You can always use micro-segmentation for any virtual workload with NSX-v, however if VMtools are not installed then IP based discovery is the way out.

 

Rest would suggest you to refer these articles, to get better understanding what feature and method you wanna use, as it has context aware segmentation feature which could be useful.

 

Context-Aware Micro-segmentation - an innovative approach to Application and User Identity Firewall - Network Virtualiza…

 

https://www.virtual-allan.com/vmware-nsx-for-vsphere-6-4-released/

 

IP address discovery mechanisms for VMs: Authoritative enforcement of security policies based on VM names, or other vCenter-based attributes requires that NSX know the IP address of the VM. NSX 6.2 introduced the option to discover the VM's IP address using DHCP snooping, or ARP snooping. In NSX 6.4.0, the number of ARP discovered IPs have been increased up to 128 and are configurable from 1 to 128.  These new discovery mechanisms enable NSX to enforce IP address-based security rules on VMs that do not have VMware Tools installed.


Viewing all articles
Browse latest Browse all 258290

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>