NSX assists customers in configuring multi-layered security. An NSX firewall will provide primary security, and AWS security groups that are managed by NSX will provide a second layer of security. It is fully configurable to each VPC with exclusion lists. It enables agility for VM deploy/tear-down in test-dev while maintaining the structural integrity of production VPCs to get the best of both worlds.
There are environments where we would say VPCs need to be fully onboarded. It is okay to have some VMs that have an agent and some that won't have an agent in some environments. This is a typical test and dev environment, or a brownfield environment, that already has VMs running so we ...