An administrator configures a new VMware NSX overlay segment for a new pool of virtual desktops to connect to with default segment policies. The virtual desktops will obtain an IPv4 address from a DHCP server connected to the same segment.
Which action must the administrator take to ensure IPv4 lease addresses can be successfully obtained from the DHCP server?
In VMware Cloud Foundation 9.0, network security and segment integrity are maintained through Segment Security Profiles. These profiles are applied to NSX segments to define what type of traffic is permitted to originate from or be received by the virtual machines attached to that segment.
According to the VCF 9.0 (NSX) Networking and Security Guide:
The Default Segment Security Profile is designed with a 'Zero Trust' approach for foundational services. One of its key default settings is DHCP Server Block, which is set to Yes. This is a security measure to prevent 'rogue' DHCP servers from being accidentally or maliciously connected to a segment and disrupting the network by handing out unauthorized IP addresses.
When an administrator intentionally places a legitimate DHCP server on a segment:
Segment Security Profile: The 'DHCP Server Block' feature resides specifically within the Segment Security Profile, not the IP Discovery profile (which handles how NSX learns IP addresses via ARP/DHCP snooping).
Cloning vs. Editing: In VCF 9.0, the 'Default' profiles are system-defined. While some default settings can be edited in certain versions, the architectural best practice and documented procedure for production environments is to Clone the default profile. This creates a custom profile where the DHCP Server Block can be set to No, allowing the DHCP server's 'Offer' and 'ACK' packets to pass through the segment.
Application: Once the cloned profile is modified, it must be manually applied to the specific segment where the virtual desktops and the DHCP server reside.
VMware Cloud Foundation 9.0 Administration Guide: Configuring Segment Security Profiles.
VMware NSX (VCF 9.0) Product Documentation: Managing Segment Profiles and DHCP Security.
Currently there are no comments in this discussion, be the first to comment!