VM-Series
Deployment
Guide
61
The VM-Series NSX Edition Firewall
Deploy the VM-Series NSX Edition Firewall
Define Policies on the NSX Manager
Apply Policies to the VM-Series Firewall
Define Policies on the NSX Manager
In order for the VM-Series firewall to secure the traffic, you must first create security groups on the NSX
Manager and assign virtual machines (guests) to the groups. Then, define and apply rules to redirect traffic from
the ESXi hosts in these groups to the VM-Series firewall.
A security group is a logical container that assembles guests across multiple ESXi hosts in the cluster. Creating
security groups makes it easier to manage and secure the guests; to understand how security groups enable
policy enforcement, see
Policy Enforcement using Dynamic Address Groups
.
Set up Security Groups on the NSX Manager
Assign the guests into security groups on NSX.
1.
Select
Networking and Security > Service Composer > Security Groups
, and add a
New Security Group
.
2.
Add a
Name
and
Description
. This name will display in the match criteria list when defining Dynamic Address
Groups on Panorama.
3.
Select the guests that constitute the security group. You can either add members dynamically using
Define
Dynamic Membership
or statically using
Select the Objects to Include
. In the following screenshot, the guests
that belong to the security group are selected using the
Select objects to include
>
Virtual Machine
option.
4.
Review the details and click
OK
to create the security group.