Create a security group

Security groups are essential for managing your NSX-T firewall.

You can create a security group in three different ways.

Security groups are associated with a gateway or a datacenter group.

Prerequisites

Master your network infrastructure

Security Groups

Static Groups

You can use static groups on:

  • The Distributed Firewall *
  • Your NSX T1 gateway

The distributed firewall manages traffic East West (Between VMs and between VDCs) *

Creating a static group

Manage Group Members

The members of the static datacenter group are networks.

Display of 'Manage Group Members' window

Show Associated VMs

The associated VMs are those with a network card on the group’s member networks.

Display of 'Associated VMs of the group' window

IP Address Sets

From the tab NETWORKING > Edge Gateways > IP Address Sets

  1. Click on NEW
Creating a new IP address set
  1. Name your IP address set.
  2. Describe it.
  3. Enter your IP addresses, IP pools, or networks.
Display of 'New IP address set' window

Dynamic Groups

You can create dynamic groups only on gateways connected to a datacenter group or directly on it.

  1. Click on NEW
Display of 'Dynamic Groups' item in 'Datacenter Groups' tab of 'Networking' menu
Display of message 'The displayed dynamic groups are shared between the Edge gateway firewall rules and the distributed firewall rules of the VDC group of the owner. Changes to these dynamic groups will'

Creating the Group

  1. Enter a Name and a Description

There are two types:

  • The tag (TAG)
  • The VM name

You can define one or more criteria for group inclusion, with up to three rules per criterion.

Display of 'New Dynamic Group' window

Select your dynamic group

You can:

  • Modify it
  • View the list of VMs in this group
Selecting a dynamic group

Security Tags

From the tab Networking > Security Tags

  1. Click on ADD A TAG
  2. Name your tag
  3. Choose the VMs that will carry this tag
Display of 'Add a Tag' window

Application Port Profiles

From the tab NETWORKING > Edge Gateways > Application Port Profiles

Display of 'Application Port Profiles' item in 'Edge Gateways' tab of 'Networking' menu
  1. Name your application port profile.
  2. Describe it.
  3. Select the protocol.
  4. Define the port.
  5. You can add multiple ports separated by commas.
Display of 'New Application Port Profile' window