How it works...

The DFW feature comes as a kernel module called VMware Internetworking Service Insertion Platform (VSIP) in the form of a vSphere installation bundle (VIB). The VSIP kernel module is controlled by VSIP I/O Control (VSIPIOCTL). The VSIP module retrieves firewall rules from NSX Manager through the vShield Firewall Daemon (vsfwd) which is automatically started in the ESXi host's user space upon host preparation. The DFW VIB is installed as part of NSX host preparation. Check out Chapter 1, Getting Started with VMware NSX for vSphere, to understand how ESXi host preparation works for NSX.

It is also important to note that VSFWD is part of the message bus user world agent (UWA), a component that allows the NSX Manager message bus ...

Get VMware NSX Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.