Microsegmentation part of aNET or aSEC

EduardoOliveira Lv1Posted Apr-15-2026 00:17

Hello team,

On the HCI presentation slide is showing DFW as part of aNet and Microsegmentation as part of aSEC.

I need to understand the different between them. With the anet license can I create DFW policys ?

What is the minimum license i need to run some distributed firewall rules?

Thanks in advance

Humayun Ahmed has solved this question and earned 20 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

DFW is the firewall enforcement engine integrated into the virtual network layer.
Typical capabilities:
Allow / deny rules
IP / subnet based rules
Security groups
Inter-VLAN / inter-segment control
Distributed enforcement on hosts

Microsegmentation is the security strategy / advanced policy model built on top of DFW.
Typical capabilities:
VM-to-VM granular isolation
App tier segmentation (Web/App/DB)
Dynamic membership
Least privilege east-west security
Security posture alignment

Yes, aNET-enabled HCI license (with DFW feature included in your edition/version)
For advanced microsegmentation, you typically need:
aSEC add-on / security edition
Is this answer helpful?
net_specialist Lv2Posted Apr-15-2026 08:44
  
DFW is the engine.
Microsegmentation is the security strategy.
aNet gives you the engine.
aSEC lets you use it properly
Humayun Ahmed Lv4Posted Apr-15-2026 11:54
  
DFW is the firewall enforcement engine integrated into the virtual network layer.
Typical capabilities:
Allow / deny rules
IP / subnet based rules
Security groups
Inter-VLAN / inter-segment control
Distributed enforcement on hosts

Microsegmentation is the security strategy / advanced policy model built on top of DFW.
Typical capabilities:
VM-to-VM granular isolation
App tier segmentation (Web/App/DB)
Dynamic membership
Least privilege east-west security
Security posture alignment

Yes, aNET-enabled HCI license (with DFW feature included in your edition/version)
For advanced microsegmentation, you typically need:
aSEC add-on / security edition
Newbie517762 Lv5Posted Apr-15-2026 12:09
  
HiHi,

The distributed firewall (DFW) on HCI is included in the Network Virtualization (aNET) license key. To use the distributed firewall feature, you must have the aNET license authorization.

The distributed firewall operates by creating policies that implement access control for any node within the HCI platform, based on VMs, VM groups, VM tags, IP ranges, and IP groups. It is built-in and does not require uploading templates or installing plugins.

Regarding the difference with microsegmentation under aSEC: The distributed firewall on HCI imposes network access restrictions on the virtual network, similar to an Internet Access Gateway function for limiting access. In contrast, the aSEC cloud security center provides security protection capabilities for VM endpoints by uploading security protection platform EDR images, enabling unified security policies and management in the cloud with targeted protection for different businesses.

Therefore, with the aNET license, you can create distributed firewall policies and run distributed firewall rules. The minimum license required to run distributed firewall rules is the aNET license.

Prosi Lv3Posted Apr-15-2026 20:14
  
With the anet license can I create DFW policys? Yes, aNet can create basic DFW policies
What is the minimum license? Minimum license for DFW = aNet

I Can Help:

Change

Board Leaders

NyxZale...

Weekly Sharers

Newbie5...

Weekly Questioners