Adding a vendor-partner DMZ for the permitting contractor was quoted as a new physical firewall pair. How does virtual networking address extra hardware per security zone?
Select an answer to reveal the explanation.
Short Explanation
A new hardware pair for every partner is like buying a new gatehouse for each visiting contractor. Logical segments and a gateway firewall draw that DMZ on the existing fabric. Guest Wi-Fi and Horizon UAG are not the civic server-zone isolation the seed is after.
Full Explanation
Traditional designs often add a dedicated physical firewall pair whenever a new security zone appears. NSX-T can isolate a partner DMZ with overlay segments and gateway firewall services on the existing Edge and transport fabric. Buying another hardware pair, dropping vendor VMs on guest Wi-Fi, or treating Horizon Unified Access Gateway as the server DMZ does not address that hardware-per-zone challenge.