How it works...

When an administrator configures and publishes DFW rules, the rules are transmitted to the NSX Manager via the NSX plugin for vCenter, and NSX manager pushes the rules down to ESXi hosts (user world agent) using the message bus (AMQP).

In this example, we created three DFW rules for the three-tier app, used the virtual machine as the destination object type, and applied to the distributed firewall, which means applying to all clusters that are enabled for the DFW. We will cover how to use and configure the applied to field in a separate recipe.

DFW rules are enforced in top-to-bottom ordering. The first rule in the table that matches the rule criteria is enforced; if a match is not seen, the next rule is evaluated, and so ...

Get VMware NSX Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.