DFW Multi-Tier Micro-Segmentation
Objectives
- Create NSX groups for web, app, db tiers. Deploy DFW rules enforcing intra-tier isolation and inter-tier allow.
Prerequisites
VCF lab environment deployed and operational
Lab Environment
Standard VCF lab environment for Advanced VCF 9.0 Networking (NSX & Advanced Routing)
Tasks
Task 1 DFW Multi-Tier Micro-Segmentation
Create NSX groups for web, app and db tiers, then deploy DFW rules enforcing intra-tier isolation and inter-tier allow, finishing by tightening the default rule from its out-of-the-box Allow to Drop.
Create tag-based security groups for each tier — In NSX Manager go to Inventory > Groups > Add Group. Create three groups — sg-web, sg-app, sg-db — each with Membership Criteria of Virtual Machine > Tag > Equals (tier|web, tier|app, tier|db). Tag the VMs first under Inventory > Virtual Machines > Actions > Edit Tags. Tag-based membership is dynamic: a newly deployed VM with the right tag joins its group automatically, which is why this is preferred over static VM lists in environments where VMs are frequently created and destroyed.
Build the inter-tier allow rules — Under Security > Distributed Firewall, create a policy 'App-3Tier' in the Application category. Add rules in order: (1) Any -> sg-web, HTTPS 443, Allow. (2) sg-web -> sg-app, the app port (e.g. TCP 8080), Allow. (3) sg-app -> sg-db, the DB port (e.g. TCP 5432), Allow. Set Applied To on every rule to the specific group rather than DFW-wide — this limits rule realization to the relevant vNICs and keeps the datapath rule table small.
Enforce intra-tier isolation — Add a rule sg-web -> sg-web with service Any and action Drop (repeat for sg-app and sg-db) to prevent east-west movement between peers in the same tier. This is the micro-segmentation step that stops a compromised web VM from reaching its siblings. Verify with a ping or SSH attempt between two web VMs.
Tighten the default rule — Locate the last rule in the Application category. Out of the box the DFW default rule is set to ALLOW — there is no implicit deny — so unmatched traffic is currently permitted. Once you have confirmed your allow-list rules work, change its action to Drop (or Reject) and publish. Enable logging on it so unmatched traffic is visible in the logs. The rule cannot be deleted or disabled, only changed.
Validate realization and troubleshoot a drop — Use Traceflow (Plan & Troubleshoot > Traceflow) between a web and a db VM to confirm which rule drops the packet. On the ESXi host, confirm the rules are realized in the datapath with 'vsipioctl getrules -f <filter-name>' after finding the filter via 'vsipioctl getfilters'. Cross-check the rule ID reported by Traceflow against the published rule.
Validation Gate
Check: Verify lab completion
Expected: Lab exercise completed successfully
Common Errors
Final Validation
Lab completed successfully
✓ All steps completed → No errors observed
Cleanup / Restore
• Revert to snapshot if needed
Design Reflection (VCDX)
DFW micro-segmentation is the most commonly tested NSX topic in VCDX. Panelists ask about category ordering, Applied-To optimization, and how you prevent accidental lockout.