In the last post of this series, I discussed how to create NSX Projects and apply RBAC and Quota policies to them. I also touched base briefly on the project’s security (DFW) aspect.
In this post, I will discuss the project’s security in greater detail.
If you are not following along, you can read the earlier parts of this series from the below links:
1: NSX Multitenancy Introduction
One of the key purposes of the Project feature is to allow security policy management to be delegated to the project admin to avoid the danger of rules being applied to the wrong virtual machines.
When an NSX project is created by the Enterprise Admin, the system generates default Distributed & Gateway firewall rules to regulate the default behavior of east-west and north-south traffic for the VMs in the NSX project. The firewall rules in a project apply only to the VMs created in that project and don’t impact VMs created in other projects or the default space.… Read More