CloudGuard Network Security for NSX (Microsegmenta... - Check Point CheckMates

CloudGuard Network Security for NSX (Microsegmentation)

Hello community,

I would like to present a case study and get your opinions or recommendations. We are currently implementing a new virtualization infrastructure with VMware 9 and NSX-T. This platform will be located on two physical sites that will be viewed as a single site on the platform. Although the NSX tool has microsegmentation and security capabilities, we are not entirely confident in the solution. Furthermore, our entire current environment is covered by Check Point. We would like to protect it with CloudGuard Network Security. However, we encountered the unfortunate news that Broadcom has removed all third-party support for native NSX integration, so it is no longer an option.

Searching for alternatives, I found this document:

Customer Guidance for VMware NSX Discontinuation of 3rd Party

However, alternative type A doesn't allow us to perform microsegmentation on the same host, so I have two questions.

For example,

Network A (Production VMs)

Network B (QA VMs)

Check Point Clustex XL IP: 10.1.1.5

Route Table:

0.0.0.0/0 ----> 10.1.1.5

Network A ----> 10.1.1.5

Network B ----> 10.1.1.5

This is how I implemented it in Azure, and it allows me to see the traffic of two VMs that are in the same vNetwork through the Security Gateway (Network A to Network A).

It is worth noting that the network gateway will be outside of NSX or Check Point and will be managed in Cisco fabric.

I am very grateful for any information.

Regards

Labels

Preview file

42 KB

0

Kudos

Click here to give kudos to this post.


1 Reply

Jeff_Engel

Hi @Ddavila

Sending you a private message.  Will return to this thread with our conclusions.