VM-Series
Deployment
Guide
47
Set Up a VM-Series NSX Edition Firewall
VM-Series NSX Edition Firewall Overview
vCenter Server
The vCenter server is required to manage the NSX Manager and the ESXi hosts in your datacenter. This joint
solution requires that the ESXi hosts be organized into one or more clusters on the vCenter server and must be
connected to a distributed virtual switch.
For information on clusters, distributed virtual switch, DRS, and the vCenter server, refer to your VMware
documentation:
http://www.vmware.com/support/vcenter-server.html.
NSX Manager
NSX is VMware’s network virtualization platform that is completely integrated with vSphere. The NSX Firewall
and the Service Composer are key features of the NSX Manager. The NSX firewall is a logical firewall that allows
you to attach network and security services to the virtual machines, and the Service Composer allows you to
group virtual machines and create policy to redirect traffic to the VM-Series firewall (called the Palo Alto
Networks NGFW service on the NSX Manager).
Panorama
Panorama is used to register the NSX edition of the VM-Series firewall as the
Palo Alto Networks NGFW
service
on the NSX Manager. Registering the Palo Alto Networks NGFW service on the NSX Manager allows the NSX
Manager to deploy the NSX edition of the VM-Series firewall on each ESXi host in the ESXi cluster.
Panorama serves as the central point of administration for the VM-Series NSX edition firewalls. When a new
VM-Series NSX edition firewall is deployed, it communicates with Panorama to obtain the license and receives
its configuration/policies from Panorama. All configuration elements, policies, and Dynamic Address Groups
on the VM-Series NSX edition firewalls can be centrally managed on Panorama using Device Groups and
Templates. The REST-based XML API integration in this solution, enables Panorama to synchronize with the
NSX Manager and the VM-Series NSX edition firewalls to allow the use of Dynamic Address Groups and share
context between the virtualized environment and security enforcement. For more information, see
Policy
Enforcement using Dynamic Address Groups
.