Book Image

VMware NSX Network Essentials

By : sreejith c
Book Image

VMware NSX Network Essentials

By: sreejith c

Overview of this book

VMware NSX is at the forefront of the software-defined networking revolution. It makes it even easier for organizations to unlock the full benefits of a software-defined data center – scalability, flexibility – while adding in vital security and automation features to keep any sysadmin happy. Software alone won’t power your business – with NSX you can use it more effectively than ever before, optimizing your resources and reducing costs. Getting started should be easy – this guide makes sure it is. It takes you through the core components of NSX, demonstrating how to set it up, customize it within your current network architecture. You’ll learn the principles of effective design, as well as some things you may need to take into consideration when you’re creating your virtual networks. We’ll also show you how to construct and maintain virtual networks, and how to deal with any tricky situations and failures. By the end, you’ll be confident you can deliver, scale and secure an exemplary virtualized network with NSX.
Table of Contents (15 chapters)
VMware NSX Network Essentials
Credits
Foreword
About the Author
About the Reviewer
www.PacktPub.com
Preface

NSX SpoofGuard


Another powerful feature of NSX is SpoofGuard. The SpoofGuard feature will monitor and manage the IP address of a virtual machine. OK! Why do we need such a feature? If a virtual machine is compromised by chance, what are the outcomes? A hacker can certainly change the IP and bypass all firewall policies and the rest will be history. SpoofGuard gives us that granular control to ensure all IP changes are approved, until when traffic would be blocked. NSX Manager will collect the IP address of the virtual machines as long we have a VMware tool installed and running.

The following methods are supported in SpoofGuard:

  • Automatically trust IP assignments on their first use: This mode allows all traffic from your virtual machines to pass; additionally, it builds a table of vNIC-to-IP address assignments. That way, we can review this table and make IP address changes. Both IPv4 and IPv6 are supported.

  • Manually inspect and approve all IP assignments before use: This mode blocks all...