3V0-25.25 · Question #18
Which two statements describe the recommended strategy for configuring and synchronizing security policies across Federated NSX sites? (Choose two.)
The correct answer is B. Security policies, such as Distributed Firewall rules and security groups, must be defined as global D. Local Managers (LMs) can define local policies, but any global policies defined on the GM always. NSX Federation is the cornerstone of multi-site VMware Cloud Foundation (VCF) security, enabling administrators to maintain a consistent security posture across geographically dispersed data centers. The management of security in a Federated environment relies on a hierarchical…
Question
Options
- AConsistency is achieved by ensuring all security groups have the exact same name on every
- BSecurity policies, such as Distributed Firewall rules and security groups, must be defined as global
- CThe Global Manager only synchronizes networking (L2/L3) configurations. Security rules must be
- DLocal Managers (LMs) can define local policies, but any global policies defined on the GM always
- ESecurity policies should be defined locally on each LM and only synchronized manually by an
How the community answered
(35 responses)- A6% (2)
- B80% (28)
- C3% (1)
- E11% (4)
Explanation
NSX Federation is the cornerstone of multi-site VMware Cloud Foundation (VCF) security, enabling administrators to maintain a consistent security posture across geographically dispersed data centers. The management of security in a Federated environment relies on a hierarchical relationship between the Global Manager (GM) and Local Managers (LMs). According to VMware documentation, the recommended strategy is to define Global Security Policies on the Global Manager (Option B). When a security group or a Distributed Firewall (DFW) rule is created on the GM, it is automatically synchronized to all registered Local Managers. This ensures that a "Finance App" security policy is identical in AZ1 and AZ2. These global objects are identified by a specific tag in the local NSX Manager UI, indicating they are managed globally and cannot be modified locally. Furthermore, NSX handles the coexistence of global and local rules through a specific evaluation order (Option D). In the NSX DFW category structure, Global Categories (managed by the GM) are evaluated before Local Categories (managed by the LM). This ensures that corporate-wide security mandates (like "Block All SSH to Management") defined at the GM level are enforced first and cannot be bypassed by localized site-level rules.
Topics
Community Discussion
No community discussion yet for this question.