54
VM-Series
Deployment
Guide
VM-Series NSX Edition Firewall Overview
Set Up a VM-Series NSX Edition Firewall
When Panorama receives the API notification, it verifies/updates the IP address of each guest and the security
group to which that guest belongs. Then, Panorama pushes these real-time updates to all the firewalls that are
included in the device group and notifies device groups in the service manager configuration on Panorama.
On each firewall, all policy rules that reference these Dynamic Address Groups are updated at runtime. Because
the firewall matches on the security group tag to determine the members of a Dynamic Address Group, you do
not need to modify or update the policy when you make changes in the virtual environment. The firewall
matches the tags to find the current members of each Dynamic Address Group and applies the security policy
to the source/destination IP address that are included in the group.