{"id":848,"date":"2021-10-21T18:51:26","date_gmt":"2021-10-21T17:51:26","guid":{"rendered":"https:\/\/vminded.com\/?p=848"},"modified":"2021-11-22T12:08:08","modified_gmt":"2021-11-22T11:08:08","slug":"nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2","status":"publish","type":"post","link":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/","title":{"rendered":"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)"},"content":{"rendered":"\n<p>In my <a href=\"https:\/\/vminded.com\/index.php\/2021\/10\/20\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-1\/\" target=\"_blank\" rel=\"noreferrer noopener\">previous post<\/a>, I have introduced you to the new <a href=\"https:\/\/www.vmware.com\/latam\/products\/nsx-advanced-firewall-for-vmc.html\" target=\"_blank\" rel=\"noreferrer noopener\">Advanced Firewall Add-on<\/a> in <a href=\"https:\/\/www.vmware.com\/fr\/products\/vmc-on-aws.html\" target=\"_blank\" rel=\"noreferrer noopener\">VMWare Cloud on AWS<\/a>. <\/p>\n\n\n\n<p>I also covered the <strong>Context Aware Firewall <\/strong>feature to filter connection based on the <strong>App id <\/strong>and not only the protocol number.<\/p>\n\n\n\n<p>In this post, I am going to cover <strong><a href=\"https:\/\/docs.vmware.com\/en\/VMware-NSX-T-Data-Center\/3.1\/administration\/GUID-63262728-CA72-47D2-8E4F-16617B63A9A4.html\" target=\"_blank\" rel=\"noreferrer noopener\">Distributed FW FQDN filtering<\/a><\/strong> to allow applications that communicate outside the SDDC gain layer 7 protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-introducing-the-fqdn-filtering-feature\">Introducing the FQDN Filtering feature<\/h2>\n\n\n\n<p>This feature can allow users to only access specific domains by <strong>whitelisting<\/strong> and\/or <strong>blacklisting<\/strong> FQDNs. In many high-security environments, outgoing traffic is filtered using the Distributed firewall. When you want to access an external service, you usually create IP-based firewall rules. In some cases, you don&#8217;t know which IP addresses hide behind a domain. This is where domain filters come in handy.<\/p>\n\n\n\n<p>Because&nbsp;NSX-T Data Center&nbsp;uses <strong>DNS Snooping <\/strong>to obtain a mapping between the IP address and the FQDN, you must set up a DNS rule first, and then the FQDN <em>allowlist <\/em>or <em>denylist <\/em>rule below it. <\/p>\n\n\n\n<p><strong>SpoofGuard <\/strong>should be enabled across the switch on all logical ports to protect against the risk of DNS spoofing attacks. A DNS spoofing attack is when a malicious VM can inject spoofed DNS responses to redirect traffic to malicious endpoints or bypass the firewall<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png\" alt=\"\"\/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>You can define specific FQDNs that are allowed and apply them to DFW policies. Conversely, you can define specific FQDNs that are denied access to applications in the SDDC. The DFW maintains the context of VMs when they migrate. You can then increasingly rely on application profiling and FQDN filtering to reduce the attack surface of their applications to designated protocols and destinations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Configuring DFW with FQDN filtering<\/h2>\n\n\n\n<p>In this section, I will show you how to setup a <strong>FQDN Context Profile<\/strong>, and a <strong>Firewall policy<\/strong> to limit access to specific URLs from VMs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Creating a FQDN Context Profile.<\/h3>\n\n\n\n<p>First thing first !  Let&#8217;s create the context Profile.<\/p>\n\n\n\n<p>Under <strong>Networking and Security<\/strong>, in the <strong>Inventory<\/strong> section, click&nbsp;<strong>Context Profile<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"527\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37-1024x527.png\" alt=\"\" class=\"wp-image-854\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37-1024x527.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37-300x154.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37-768x395.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37-1536x790.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37-1200x617.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.41.37.png 1924w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Click&nbsp;<strong>FQDNs<\/strong>&nbsp;Tab<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.49.11-1024x821.png\" alt=\"\" class=\"wp-image-855\" width=\"547\" height=\"438\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.49.11-1024x821.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.49.11-300x241.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.49.11-768x616.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-11.49.11.png 1200w\" sizes=\"auto, (max-width: 547px) 85vw, 547px\" \/><\/figure>\n\n\n\n<p>Click&nbsp;<strong>ACTIONS &#8211;&gt; Add FQDN<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.04.01-1024x555.png\" alt=\"\" class=\"wp-image-859\" width=\"569\" height=\"308\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.04.01-1024x555.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.04.01-300x163.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.04.01-768x416.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.04.01.png 1104w\" sizes=\"auto, (max-width: 569px) 85vw, 569px\" \/><\/figure>\n\n\n\n<p>Enter the Domain:&nbsp;<strong>*.yahoo.com<\/strong>,  and then Click&nbsp;<strong>SAVE<\/strong>.<\/p>\n\n\n\n<p>Create a second FQDN with <strong>*.google.com<\/strong>.<\/p>\n\n\n\n<p>Click the&nbsp;<strong>Context Profile&nbsp;<\/strong>Tab, and Click&nbsp;<strong>ADD CONTEXT PROFILE<\/strong><\/p>\n\n\n\n<p>Give it a Name:&nbsp;<strong>Allowed FQDNs<\/strong>, Click&nbsp;<strong>Set<\/strong><\/p>\n\n\n\n<p>Click&nbsp;<strong>ADD ATTRIBUTE &#8211;&gt; Domain(FQDN) Name<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.08.36.png\" alt=\"\" class=\"wp-image-863\" width=\"421\" height=\"316\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.08.36.png 822w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.08.36-300x226.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-12.08.36-768x577.png 768w\" sizes=\"auto, (max-width: 421px) 85vw, 421px\" \/><\/figure>\n\n\n\n<p>Select the following domains: <strong>*.yahoo.com<\/strong>, <strong>*.office.com<\/strong>, *.<strong>google.com<\/strong> and Click&nbsp;<strong>ADD<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59-1024x225.png\" alt=\"\" class=\"wp-image-862\" width=\"600\" height=\"131\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59-1024x225.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59-300x66.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59-768x169.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59-1536x338.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59-1200x264.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.08.59.png 1672w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p>Click<strong>&nbsp;APPLY,<\/strong> Click&nbsp;<strong>SAVE<\/strong>. We now have a <strong>Context Profile<\/strong> setup.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"423\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.09.29-1024x423.png\" alt=\"\" class=\"wp-image-864\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.09.29-1024x423.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.09.29-300x124.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.09.29-768x317.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.09.29-1200x496.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-16.09.29.png 1346w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Creating a Firewall rule and a Policy<\/h3>\n\n\n\n<p>I have created a Group called <strong>MyDesktops<\/strong> which includes a segment with my Windows VMs.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"398\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24-1024x398.png\" alt=\"\" class=\"wp-image-866\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24-1024x398.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24-300x117.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24-768x299.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24-1536x597.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24-1200x466.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.20.24.png 1662w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>Now I am going to setup a Firewall Policy including this Context Profile. I will limit my VM in the <strong>MyDesktops<\/strong> group to access to the <strong>Allowed FQDNs<\/strong>. Also I limit access from this Group of VMs to specific <strong>DNS servers<\/strong> (8.8.8.8, 8.8.4.4).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"175\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-1024x175.png\" alt=\"\" class=\"wp-image-867\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-1024x175.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-300x51.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-768x131.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-1536x262.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-2048x349.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.33.20-1200x205.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>I also add a Drop rule at the end to limit access to only the FQDNs that were whitelisted.<\/p>\n\n\n\n<p>Now I am allowed to access <strong>google.com<\/strong> and <strong>Yahoo.com<\/strong> but I can&#8217;t connect anymore to the <strong>vmware.com<\/strong> site.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"419\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-1024x419.png\" alt=\"\" class=\"wp-image-868\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-1024x419.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-300x123.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-768x314.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-1536x629.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-2048x838.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-21-at-19.49.13-1200x491.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>This concludes the post on FQDN Filtering. In my <a href=\"https:\/\/vminded.com\/index.php\/2021\/11\/18\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-3\/\" target=\"_blank\" rel=\"noreferrer noopener\">final post<\/a>, I will cover the <a href=\"https:\/\/docs.vmware.com\/en\/VMware-NSX-T-Data-Center\/3.1\/administration\/GUID-E54E9E76-175E-4D65-80E9-8BE169DB2066.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Distributed<\/strong> <strong>IDS\/IPS<\/strong><\/a> feature.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In my previous post, I have introduced you to the new Advanced Firewall Add-on in VMWare Cloud on AWS. I also covered the Context Aware Firewall feature to filter connection based on the App id and not only the protocol number. In this post, I am going to cover Distributed FW FQDN filtering to allow &hellip; <a href=\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-848","post","type-post","status-publish","format-standard","hentry","category-vmconaws"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2) - vminded.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2) - vminded.com\" \/>\n<meta property=\"og:description\" content=\"In my previous post, I have introduced you to the new Advanced Firewall Add-on in VMWare Cloud on AWS. I also covered the Context Aware Firewall feature to filter connection based on the App id and not only the protocol number. In this post, I am going to cover Distributed FW FQDN filtering to allow &hellip; Continue reading &quot;NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\" \/>\n<meta property=\"og:site_name\" content=\"vminded.com\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-21T17:51:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-11-22T11:08:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png\" \/>\n<meta name=\"author\" content=\"Christophe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christophe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\"},\"author\":{\"name\":\"Christophe\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"headline\":\"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)\",\"datePublished\":\"2021-10-21T17:51:26+00:00\",\"dateModified\":\"2021-11-22T11:08:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\"},\"wordCount\":555,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png\",\"articleSection\":[\"VMConAWS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\",\"url\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\",\"name\":\"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2) - vminded.com\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png\",\"datePublished\":\"2021-10-21T17:51:26+00:00\",\"dateModified\":\"2021-11-22T11:08:08+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage\",\"url\":\"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png\",\"contentUrl\":\"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/vminded.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vminded.com\/#website\",\"url\":\"https:\/\/vminded.com\/\",\"name\":\"vminded.com\",\"description\":\"feed your mind with virtual thoughts\",\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/vminded.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\",\"name\":\"Christophe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"caption\":\"Christophe\"},\"logo\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/vminded.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2) - vminded.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/","og_locale":"en_US","og_type":"article","og_title":"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2) - vminded.com","og_description":"In my previous post, I have introduced you to the new Advanced Firewall Add-on in VMWare Cloud on AWS. I also covered the Context Aware Firewall feature to filter connection based on the App id and not only the protocol number. In this post, I am going to cover Distributed FW FQDN filtering to allow &hellip; Continue reading \"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)\"","og_url":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/","og_site_name":"vminded.com","article_published_time":"2021-10-21T17:51:26+00:00","article_modified_time":"2021-11-22T11:08:08+00:00","og_image":[{"url":"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png","type":"","width":"","height":""}],"author":"Christophe","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christophe","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#article","isPartOf":{"@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/"},"author":{"name":"Christophe","@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"headline":"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)","datePublished":"2021-10-21T17:51:26+00:00","dateModified":"2021-11-22T11:08:08+00:00","mainEntityOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/"},"wordCount":555,"commentCount":2,"publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage"},"thumbnailUrl":"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png","articleSection":["VMConAWS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/","url":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/","name":"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2) - vminded.com","isPartOf":{"@id":"https:\/\/vminded.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage"},"thumbnailUrl":"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png","datePublished":"2021-10-21T17:51:26+00:00","dateModified":"2021-11-22T11:08:08+00:00","breadcrumb":{"@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#primaryimage","url":"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png","contentUrl":"https:\/\/media.screensteps.com\/image_assets\/assets\/004\/592\/490\/medium\/d7ced0bf-2fd0-4817-a976-bf05763c7937.png"},{"@type":"BreadcrumbList","@id":"https:\/\/vminded.com\/index.php\/2021\/10\/21\/nsx-advanced-firewall-add-on-for-vmware-cloud-on-aws-part-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vminded.com\/"},{"@type":"ListItem","position":2,"name":"NSX Advanced Firewall Add On for VMware Cloud on AWS (Part 2)"}]},{"@type":"WebSite","@id":"https:\/\/vminded.com\/#website","url":"https:\/\/vminded.com\/","name":"vminded.com","description":"feed your mind with virtual thoughts","publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vminded.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a","name":"Christophe","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","caption":"Christophe"},"logo":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/vminded.com"]}]}},"_links":{"self":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/comments?post=848"}],"version-history":[{"count":22,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/848\/revisions"}],"predecessor-version":[{"id":1045,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/848\/revisions\/1045"}],"wp:attachment":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/media?parent=848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/categories?post=848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/tags?post=848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}