NetworkPolicy Enforcement & NSX DFW Integration
Objectives
- Deploy front-end and database tiers; enforce NetworkPolicy; verify NSX DFW rule generation.
Prerequisites
VCF lab environment deployed and operational
Lab Environment
Standard VCF lab environment for Advanced VCF 9.0 VKS (vSphere Kubernetes Service)
Tasks
Task 1 NetworkPolicy Enforcement & NSX DFW Integration
Deploy front-end and database tiers; enforce NetworkPolicy; verify NSX DFW rule generation.
Deploy app namespace with labels: frontend (web), backend (api), database (db).
Deploy test pods in each tier; verify all pods can communicate (no policy yet).
Create deny-all NetworkPolicy for ingress.
Create allow-policies: frontend ↔ backend, backend ↔ database.
Test connectivity: frontend can reach backend, backend can reach database; database cannot reach frontend.
In NSX, verify DFW rules created: get firewall rules | grep production
Modify policy to add port restriction (backend to database on TCP 5432 only).
Retest: Confirm 3306 (MySQL) blocked, 5432 allowed.
Extract policy rules to JSON; document L3/L4 mapping to NSX DFW entries.
Validation Gate
Check: Verify lab completion
Expected: Lab exercise completed successfully
Common Errors
Final Validation
Lab completed successfully
✓ All steps completed → No errors observed
Cleanup / Restore
• Revert to snapshot if needed
Design Reflection (VCDX)
NSX-DFW integration with Kubernetes NetworkPolicy demonstrates defense-in-depth. VCDX panelists test how you layer K8s NetworkPolicy with NSX DFW for comprehensive micro-segmentation.