NSX-T 3.1 – Deploying Distributed IDS/IPS

In NSX-T 3.0 VMware introduce distributed IDS and now in NSX-T 3.1 this has been expanded to include distributed IPS. In this blog I will highlight the steps to enabled and configured distributed IDS/IPS and end with a demonstration. Overview Distributed Intrusion Detection and Prevention Service (IDS/IPS) monitors network traffic on the host for suspiciousContinue reading “NSX-T 3.1 – Deploying Distributed IDS/IPS”

NSX-T 3.1 – Configuring DHCP Server

As I build out various demonstrations in my lab I wanted to reduce the amount of static IP allocations on my demo work loads so that I can move them between network segments for different demonstrations and with this enabling a DHCP Server in my NSX-T deployment makes sense. So in this post I willContinue reading “NSX-T 3.1 – Configuring DHCP Server”

Product Offerings for VMware NSX Security 3.1.x

New VMware NSX Security editions became available to order on October 29th, 2020. The tiers of NSX Security licenses are as follows: NSX Firewall for Baremetal Hosts: For organizations needing an agent-based network segmentation solution. NSX Firewall Edition: For organizations needing network security and network segmentation. NSX Firewall with Advanced Threat Prevention Edition: For organizationsContinue reading “Product Offerings for VMware NSX Security 3.1.x”

Configuring NSX-T VRF Lite Networking

VMware introduced VRF capabilities in NSX-T 3.0, this post will guide you how through the steps to configure and enabled VRF capabilities. A virtual routing and forwarding (VRF) gateway makes it possible for multiple instances of a routing table to exist within the same gateway at the same time. VRFs are the layer 3 equivalentContinue reading “Configuring NSX-T VRF Lite Networking”

Deploying NSX-T Data Center Federation with 3.1.0

VMware recently announced the general availability of NSX-T 3.1.0 bringing a host of new features and functionality. One of the key features which is now production ready is the Multi-Site solution, Federation. Support for standby Global Manager Cluster Global Manager can now have an active cluster and a standby cluster in another location. Latency betweenContinue reading “Deploying NSX-T Data Center Federation with 3.1.0”

NSX-T 3.1 – Federation Global Manager Redundancy

A quick post to set up and configure Redundancy for NSX-T Federation Global Managers across two locations. My Primary Global Manager (GM) has been deployed and configured it as Active – I have only deployed a single GM appliance at each location, in a production deployment it is highly recommended to deploy a 3 nodeContinue reading “NSX-T 3.1 – Federation Global Manager Redundancy”

NSX-T 3.0 URL Analysis

VMware recently introduced URL Analysis capabilities on the NSX L7 Edge Firewall. “The Layer 7 Edge Firewall is now further enhanced in NSX-T 3.0 with the implementation of URL Analysis for URL Classification and Reputation. The Edge Firewall detects access from outside the datacenter for granular detection and categorization of in-bound and outbound URLs.” URL analysis allows administrators to gain insight into the type of websitesContinue reading “NSX-T 3.0 URL Analysis”