How it works...

The DFW exclusion list provides the ability to exclude virtual machines from DFW enforcement. NSX components such as NSX Manager, NSX controller nodes, NSX DLR control VMs, and NSX edge VMs are automatically excluded from the DFW. If the management cluster is prepared for NSX, such as in shared management/edge clusters, it is recommended to exclude the following virtual machines from the DFW:

  • vCenter Server.
  • Platform Services Controller.
  • vCenter server's database server (if available).
  • Virtual machines in promiscuous mode. Performance of virtual machines requiring promiscuous mode may be adversely affected behind NSX DFW.
  • An NSX partner service virtual machine (SVM), such as a third-party layer 7 firewall or agentless anti-virus/malware ...

Get VMware NSX Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.