Using NSX to make a Virtualized DMZ
Need a more specific use-case to get started with Micro-segmentation and the NSX Distributed Firewall? Your DMZ is an excellent place to start! Why let your blast-area be the entire DMZ network – limit the scope of damage to each individual server. OS-level firewalls are great – but are subject to being disabled once the server has been compromised. NSX, with it’s point of control at the vNIC level, completely gets around that limitation to help reduce your exposure.
via VMware NSX