NSX Intelligence: Checking Applied Rules on a VM

A short conversation on how to check the applied Distributed Firewall Rules on a VM by using NSX Intelligence!!

CuriousTechie: Hello IT Guy, during our last conversation here we discussed about three ways to check applied DFW rules but you did mention there is another way to check the rules, can we talk about that?

ITGuy: Sure ! You can leverage Security Intelligence aka NSX intelligence to validate the rules applied on a VM.

CuriousTechie: I have been using Security Intelligence to get flow information and recommendations but never seen how to check applied rules using it, can you show me?

ITGuy: Sure !

  1. Go to Plan & Troubleshoot
  2. Go to Discover & Take Action
  3. On the Top bar Select Computer -> Search and select the VM that you want to check the applied rules.
  4. Right click the VM -> Go to Related Firewall Rules
  5. You will see all the rules applied on that particular VM
Continue reading “NSX Intelligence: Checking Applied Rules on a VM”

3 Ways to Verify Applied Distributed Firewall Rules on a VNIC

A short conversation on how to check the applied Distributed Firewall Rules on a vnic!!

CuriousTechie: Hello IT Guy, I am working on a project to implement DFW rules in an environment and often need to check exactly what firewall rules are applied on a vnic, is there a way to do that?

ITGuy: Sure ! We can talk about three different ways to do that and we can talk about pro’s and con’s of each.

CuriousTechie: Okay cool!

ITGuy:

  • From NSX UI
  • From ESXi Host shell
  • From ARIA Operations for Networks aka vRNI
Continue reading “3 Ways to Verify Applied Distributed Firewall Rules on a VNIC”

AVI (NSX-ALB) Quick tip for troubleshooting network connectivity!

A short conversation on how to check and troubleshoot network connectivity from AVI Service Engines.

CuriousTechie: Hello IT Guy, I am new to AVI and sometimes I get stuck in troubleshooting connectivity issues on service engines. Is there a way to check connectivity of the data nics from the service engines?

ITGuy: Sure there is a simple way! You may login to the network namespace of the data nic inside the service engine and check the connectivity.

CuriousTechie: Can you please show me how to do that? Here is my scenario!

I have NSX-T cloud with service engines running, I have created a virtual service but the Virtual Service is DOWN and the Pool is DOWN as well. Also I am not able to reach the SE data nics.

Continue reading “AVI (NSX-ALB) Quick tip for troubleshooting network connectivity!”

NSX API: Quick Troubleshooting Trick

A conversation about using browser Developer tools to validate NSX API’s for quick troubleshooting in some cases.

CuriousTechie: Hello IT Guy, I am planning to upgrade my NSX but I see a problem with the upgrade status in UI and not sure where to start the troubleshoot process.

ITGuy: Okay sure! Let’s take a look at the problem then we can get some clue to move ahead.

CuriousTechie: My upgrade screen is stuck like this.

Continue reading “NSX API: Quick Troubleshooting Trick”

VMC: Understand GFW on Customer Managed CGW (Tier-1 Gateway)

A conversation about how Gateway Firewall works on a Customer Managed Compute Gateway (CGW) i.e. custom Tier-1 Gateway implemented on VMware Cloud On AWS.

CuriousTechie: Hello IT Guy, I am exploring the functionality of Customer Managed CGW in VMConAWS and I am confused about the Gateway Firewall implementation. Can we discuss how it is implemented?

ITGuy: Sure! Did you get a chance to read this blog post here, it provides a good description of the feature and its functionality. On a high level the topology looks like this.

CuriousTechie: Yes, I have read this post, but the implementation of Gateway Firewall is still not clear to me. For example, when I try to configure rules on CGW, I get the option in the Applied To field to select the uplink where I want to apply the rule as shown below.

Continue reading “VMC: Understand GFW on Customer Managed CGW (Tier-1 Gateway)”

NSX-ALB GSLB Public or Private IP??

A conversation about how to configure GSLB service to provide the appropriate Public or Private IP as per the incoming DNS request.

CuriousTechie: Hello IT Guy, I am in a planning phase for a GSLB implementation and have some doubts around the DNS services, can you help me with it.

ITGuy: Sure! I recently had a conversation around GSLB which you can find here.

CuriousTechie: Yes! I have a fair understanding of GSLB, but I am looking for some specifics around how the GSLB DNS service determines which IP (Public or Private) it provides in the DNS response for Internal and External users. Can you help me to get some clarity and show the actual configuration?

Continue reading “NSX-ALB GSLB Public or Private IP??”

Broke my LAB with Distributed Firewall !!!

Recently I had an interesting conversation about implementing micro-segmentation using NSX Distributed Firewall and things to be careful about while implementation.

CuriousTechie: Hey, I was implementing Micro-segmentation in my Lab using DFW and I broke the Lab. Can you check if it can be fixed or I have to rebuild from scratch again!!

ITGuy: Let’s take a look at the problem and see if we can recover from it. What did you do?

CuriousTechie: I was testing micro-segmentation and changed the default rule to reject all traffic.

ITGuy: Let me guess..! You forgot it’s a collapsed cluster and you accidently locked away your NSX manager and vCenter ?

Continue reading “Broke my LAB with Distributed Firewall !!!”

NSX ALB – A conversation about GSLB Basics

CuriousTechie: Hey, I am learning to setup Global Server Load Balancing on AVI. I do not have much experience on GSLB especially with AVI or NSX ALB, can you help me understand the basic concept of GSLB with NSX ALB?

ITGuy: Sure! Are you good with how GSLB works irrespective of the Load Balancer?

CuriousTechie: I know some basics, but a white board refresher will be helpful.

ITGuy: Sure! Let’s see what happens when you type a URL in your favourite web browser. You input a URL lets say “curioustechies.in”and DNS does its magic and run multiple DNS queries to find you the IP of the web site/server that you are looking for. I believe you have a fair understanding of how DNS works so will not go much deep into it. OK?

Continue reading “NSX ALB – A conversation about GSLB Basics”

NSX ALB Virtual Service Placement

A conversation about placement of Virtual Services on NSX ALB Service Engines

CuriousTechie: Hey IT Guy, I am starting my starting my journey with NSX ALB and I am little confused with different knobs in the Service Engine Group setting to manage the Virtual Service Placement. Can you show me around the setting to build a better understanding?

ITGuy: Yes, sure! Let’s start with some basic understanding of the knobs and then we can work on few scenarios to see how the placement works.

Continue reading “NSX ALB Virtual Service Placement”