WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

Changing the default behavior of the NSX-T Distributed Firewall (DFW) in VMC to Deny All

01.30.2019 by William Lam // 3 Comments

In VMware Cloud on AWS (VMC), the default behavior of the NSX-T Distributed Firewall (DFW) is to currently allow all traffic between compute workloads even across different logical networks (Segments). Today, the default behavior is currently not configurable and is something the NSX team is looking into with a few update of the VMC Service.


Having said that, it is actually pretty straight forward to create a new Deny All policy that would achieve the same desired behavior of blocking all traffic by default. Since this topic has come up a few times, I figure it would be useful to share the quick fix and big thanks to Michael Kolos, one of our VMC Customer Success Engineers who shared the original tidbit with me.

[Read more...]

Categories // NSX, VMware Cloud on AWS Tags // DFW, Distributed Firewall Rule, NSX-T, VMC, VMware Cloud on AWS

Managing Distributed Firewall Rules in VMC using PowerShell & NSX-T Policy API

01.04.2019 by William Lam // Leave a Comment

Back in November 2018, VMware Cloud on AWS (VMC) SDDC 1.5 Patch 1 was released and it was one of the most highly anticipated release by our customers. Although this was a "patch" release, it included a ton of new features and also brought the full power of the NSX-T platform to VMC as a generally available feature!

With NSX-T, customers also now have access to the highly requested Distributed Firewall (DFW) capability which enables granular control over East-West traffic between application workloads. In addition to enabling micro-segmentation in VMC, customers can now easily manage DFW rules using a number of grouping constructs (Tags, Virtual Machines & Conditional Statements) to create dynamic policies which follow their workloads.


Customers can configure DFW (as well as Edge Firewall) rules using the VMC Console UI but many of you have been asking for an automated method, especially if you need to create a large number of policies for more than a couple of workloads. After returning from the holiday, I spent the last couple of days updating my NSX-T Policy PowerShell Module which now includes basic support for managing DFW. For those of you who are new to using the NSX-T Policy API and PowerCLI, be sure to give these two articles a read here and here before proceeding further.

[Read more...]

Categories // NSX, PowerCLI, VMware Cloud on AWS Tags // DFW, Distributed Firewall Rule, NSX-T, PowerCLI, powershell, PowerShellCore, VMware Cloud on AWS

NSX-T Policy PowerShell Community Module for VMC

09.21.2018 by William Lam // 12 Comments

Earlier this week I had published an article on how to get started with the new NSX-T Policy API in VMware Cloud on AWS (VMC), if you have not read through that guide yet, I recommend you take a look at that first as this covers the prerequisites which will be required. As mentioned in that article, I planned to add a few more NSX-T Policy API examples and now the community NSX-T Policy PowerShell includes 37 additional functions which you can see the complete list below:

  • Connect-NSXTProxy
  • Get-NSXTFirewall
  • Get-NSXTGroup
  • Get-NSXTSegment
  • Get-NSXTService
  • New-NSXTFirewall
  • New-NSXTGroup
  • New-NSXTSegment
  • New-NSXTServiceDefinition (renamed as of 07/01/2019)
  • Remove-NSXTFirewall
  • Remove-NSXTGroup
  • Remove-NSXTSegment
  • Get-NSXTDistFirewallSection (as of 01/02/2019)
  • Get-NSXTDistFirewall (as of 01/02/2019)
  • New-NSXTDistFirewall (as of 01/03/2019)
  • Remove-NSXTDistFirewall (as of 01/03/2019)
  • Get-NSXTOverviewInfo (as of 02/02/2019)
  • Get-NSXTInfraScope (as of 03/14/2019)
  • Get-NSXTInfraGroup (as of 03/14/2019)
  • New-NSXTDistFirewallSection (as of 04/19/2019)
  • Remove-NSXTService (as of 04/19/2019)
  • Get-NSXTPolicyBasedVPN (as of 05/09/2019)
  • New-NSXTPolicyBasedVPN (as of 05/09/2019)
  • Remove-NSXTPolicyBasedVPN (as of 05/09/2019)
  • Get-NSXTDNS (as of 06/08/2019)
  • Set-NSXTDNS (as of 06/08/2019)
  • Get-NSXTPublicIP (as of 07/01/2019)
  • New-NSXTPublicIP (as of 07/01/2019)
  • Remove-NSXTPublicIP (as of 07/01/2019)
  • Get-NSXTNatRule (as of 07/01/2019)
  • New-NSXTNatRule (as of 07/01/2019)
  • Remove-NSXTNatRule (as of 07/01/2019)
  • Set-NSXTSegment (as of 03/05/2020)
  • Get-NSXTT0Stats (as of 07/16/2020)
  • Get-NSXTLinkedVpc (as of 08/01/2020)
  • Get-NSXTL2VPN (as of 08/01/2020)
  • Get-NSXTPortMirror (as of 08/01/2020)
  • Get-NSXTIPFIXCollector (as of 08/01/2020)
  • Get-NSXTDirectConnectVIF (as of 08/01/2020)
  • Get-NSXTVifPerHost (as of 08/01/2020)
  • Get-NSXTVM (as of 08/01/2020)
  • Get-NSXTSegmentPort (as of 08/01/2020)
  • Get-NSXTGroupMember (as of 08/01/2020)

After importing the module, to see the list of all functions, you can run the following command:

Get-Command -Module VMware.VMC.NSXT


[Read more...]

Categories // NSX, PowerCLI, VMware Cloud on AWS

  • « Previous Page
  • 1
  • …
  • 13
  • 14
  • 15
  • 16
  • 17
  • …
  • 22
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • Quick Tip - Improved NVMe Tiering Device Health Monitoring in VCF 9.1 09/22/2026
  • Using VCF Download Tool (VCFDT) with a Kerberos-Authenticated HTTPS Proxy 09/21/2026
  • VCF 9.1.1 - Connecting Pi Coding Agent to VCF Private AI Services (PAIS) 09/17/2026
  • Quick Tip - Automating vDefend Security Services Platform (SSP) 5.2.0 Installer OVA Deployment 09/16/2026
  • VCF 9.1.1 - Simplified vSphere Kubernetes Service (VKS) using VLAN-Backed VPCs without NSX Tunnel Endpoints (TEPs) 09/15/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026

Loading Comments...