VM-Series
Deployment
Guide
25
Set Up a VM-Series Firewall on the Citrix SDX Server
Supported Deployments—VM Series Firewall on Citrix SDX
Supported Deployments—VM Series Firewall on Citrix SDX
In the following scenarios, the VM-Series firewall secures traffic destined to the servers on the network. It works
in conjunction with the NetScaler VPX to manage traffic before or after it reaches the NetScaler VPX.
Scenario 1—Secure North-South Traffic
Scenario 2—Secure East-West Traffic (VM-Series Firewall on Citrix SDX)
Scenario 1—Secure North-South Traffic
To secure north-south traffic using a VM-Series firewall on an SDX server, you have the following options:
VM-Series Firewall Between the NetScaler VPX and the Servers
VM-Series Firewall Before the NetScaler VPX
VM-Series Firewall Between the NetScaler VPX and the Servers
The perimeter firewall gates all traffic in to the network. All traffic permitted into the network flows through
the NetScaler VPX and then through the VM-Series firewall before the request is forwarded to the servers.
In this scenario, the VM-Series firewall secures north-south traffic and can be deployed using virtual wire, L2,
or L3 interfaces.
VM-Series Firewall with L3 Interfaces
VM-Series Firewall with L2 or Virtual Wire Interfaces