Antrea Network Policies

This post will go through the Antrea-native policy resources and how to use them to secure your Kubernetes environment combined with K8s network policies. Abbreviations used in this article: Container Network Interface = CNI Antrea Cluster Network Policies = ACNP Antrea Network Policies = ANP Kubernetes Network Policies = K8s policies or KNP When it comes to securing your K8s infrastructure it can be done in several layers in the infrastructure as a whole....

10 July, 2021 路 18 min 路 3755 words 路 Me

Managing your Antrea K8s clusters running in VMC from your on-prem NSX Manager

This week I was fortunate to get hold of a VMC on AWS environment and wanted to test out the possibility of managing my K8s security policies from my on-prem NSX manager by utilizing the integration of Antrea in NSX. I haven鈥檛 covered that specific integration part in a blog yet, but in short: by using Antrea as your CNI and you are running NSX-T 3.2 you can manage all your K8s policies from the NSX manager GUI....

13 March, 2022 路 16 min 路 3336 words 路 Me

VMware NSX Application Platform

VMware NSX 3.2 is out and packed with new features. One of them is the NSX Application Platform which runs on Kubernetes to provide the NSX ATP (Advanced Threat Protection) functionality such as NSX Intelligence (covered in a previous post), NSX Network Detection and Response (NDR) and NSX Malware. This post will go through how to spin up a K8s cluster for this specific scenario covering the pre-reqs from start to finish....

18 January, 2022 路 11 min 路 2142 words 路 Me


This page will explain my lab environment, which is used in all the examples, tutorials in this blog. Lab overview/connectivity - physical, logical and hybrid It is nice to have an overview of how the underlying hardware looks like and when reading my different articles. So I decided to create some diagrams to illustrate this. Which hopefully will help understanding my blog posts further. First out is the physical components (which is relevant for the posts in this blog)....

19 October, 2021 路 1 min 路 171 words 路 Me


This post will go through the IDS/IPS built-in feature of the NSX distributed firewall. Abbreviations used in this article: IDS = Intrusion Detection System IPS = Intrusion Prevention System Introduction to VMware NSX distributed IDS & IPS Before we dive into how to configure and use the distributed IDS and IPS feature in NSX let me just go through the basics where I compare the traditional approach with IDS/IPS and the NSX distributed IDS/IPS....

19 October, 2021 路 11 min 路 2179 words 路 Me