Road to VCAP6-NV: Objective 6.3 – Configure and Manage Universal Logical Security Objects

VMwareNSX
In this blog post I will cover section 6 objective 6.3 of the VCAP6-NV Deploy exam.

Objective 6.3 – Configure and Manage Universal Logical Security Objects

 

Skills and Abilities

  • Configure Universal MAC sets
  • Configure Universal IP sets
  • Configure Universal security groups
  • Configure Universal firewall rules
  • Configure Universal services and service groups

The concept of group security objects is the same for both a normal NSX environment and a universal NSX environment. It’s a way to combine multiple objects together to be used on the distributed firewall for constructing rules. When creating universal grouping objects, they must be created from the primary NSX manager.

 

Configure Universal MAC sets

You can group MAC addresses to be used in the source or destination fields on the distributed firewall when creating rules. To create a universal mac set first navigate to Networking & Security > Groups and Tags > Grouping Objects > MAC Sets. Click the green +.

unisec01

Enter in a name, description, and MAC addresses. Also, make sure to click the box for “Mark this object for Universal Synchronization”. Click OK.

unisec02

Now you will see the universal MAC set that can be used in the DFW when creating rules.

unisec03

Now if I go to my DFW and create a new universal firewall rule, I have the MAC set that I can choose to enter as a source or destination.

unisec04

 

Configure Universal IP sets

You can group IP addresses to be used in the source or destination fields on the distributed firewall when creating rules. To create a universal mac set first navigate to Networking & Security > Groups and Tags > Grouping Objects > IP Sets. Click the green +.

unisec05

Enter in a name, description, and IP addresses. Also, make sure to click the box next to “Mark this object for Universal Synchronization”. Click OK.

unisec06

Now you will see the newly created Universal IP Set.

unisec07

Now if we try to create a new rule under our universal rule section, we can select our IP Set in the source or destination fields.

unisec08

 

Configure Universal security groups

Universal security groups are like regular security groups except it can only contain other universal security objects. (Ex. Universal MAC Sets, Universal IP sets, etc.) To create a universal security group, navigate to Networking & Security > Groups and Tags > Grouping Objects > Security Group. Click the green +.

unisec09

Enter in a name and description. Make sure you check the box for “Mark this object for Universal Synchronization”. Click Next.

unisec10

As mentioned, you can only add other universal security groups, IP sets, and MAC sets to a universal security group. Click Next.

unisec11

Click Finish.

unisec12

Now you see the newly created universal security group.

unisec13

 

Configure Universal firewall rules

To create a universal firewall rule, we must create a new section under the distributed firewall. Navigate to Networking & Security > Security > Firewall and click the Add Section button.

unisec14.png

Enter in a name for the section and click the box for “Mark this section for Universal Synchronization”. Click Save.

Now I can go and create a universal firewall rule under that new section and it will also show on the secondary NSX manager.

unisec15

 

Configure Universal services and service groups

To configure a universal service, navigate to Networking & Security > Groups and Tags > Grouping Objects > Service. Click the green +. Give the service a name and make sure to check the box for “Mark this object for Universal Synchronization”. Click OK.

unisec16

To configure a universal service group, navigate to Networking & Security > Groups and Tags > Grouping Objects > Service Group. Click the green +. Give a name to the service group. Click the box for “Mark this object for Universal Synchronization”. You can only add other universal services to a universal service group. Click OK.

unisec17

Now you see the newly created universal service group.

unisec18

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s