search
Get Started
search
VMware NSX Distributed Firewall - Firewall
zoom_in Click to enlarge

VMware NSX Distributed Firewall

language

description VMware NSX Distributed Firewall Overview

VMware NSX Distributed Firewall is a software-defined firewall that operates across virtual and physical networks, inspecting traffic at the application layer to enforce security policies and control network access within a data center environment.

help VMware NSX Distributed Firewall FAQ

How is the NSX Distributed Firewall different from a traditional perimeter firewall?

NSX Distributed Firewall enforces security policies directly at each individual virtual machine's virtual network interface rather than routing all traffic through a centralized appliance at the network edge. This enables east-west micro-segmentation inside the data center, so you can control traffic between two VMs on the same ESXi host without it ever leaving the hypervisor.

What OSI layers can the NSX Distributed Firewall inspect?

The NSX Distributed Firewall can enforce rules from Layer 2 through Layer 7, meaning it can filter based on MAC addresses, IP addresses, ports, and application-level attributes. At Layer 7, it can use context such as Active Directory group membership and computer identity to create identity-based rules that go beyond simple IP matching.

Do I need NSX Advanced or Enterprise licensing to use the Distributed Firewall?

Yes, the Distributed Firewall feature requires at minimum the NSX Data Center Advanced edition license, which includes micro-segmentation capabilities. The Enterprise edition adds additional features such as IDS/IPS and network detection, but core distributed firewalling is available starting at the Advanced tier.

Does the NSX Distributed Firewall work with physical servers that are not virtual machines?

Full distributed firewall enforcement is applied through the ESXi hypervisor's virtual switch, so it only inspects traffic to and from protected VMs running on NSX-prepared hosts. Physical servers or workloads on non-VMware hypervisors cannot leverage the distributed firewall directly, though VMware does offer guest-introspection-based alternatives for some workloads.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare