One VM-Series firewall per virtual network
—Deploy
a VM-Series firewall for every virtual network. If you have designed your
network such that one or more ESXi hosts has a group of virtual
machines that belong to the internal network, a group that belongs
to the external network, and some others to the DMZ, you can deploy
a VM-Series firewall to safeguard the servers in each group. If
a group or virtual network does not share a virtual switch or port
group with any other virtual network, it is completely isolated
from all other virtual networks within or across the host(s). Because
there is no other physical or virtual path to any other network,
the servers on each virtual network, must use the firewall to talk
to any other network. Therefore, it allows the firewall visibility
and control to all traffic leaving the virtual (standard or distributed)
switch attached to each virtual network.