You can deploy your VM-Series firewall to secure the
traffic of multiple Hyper-V hosts. In the example below, the VM-Series
is deployed in Layer 2 mode protecting traffic to and from the guest
VMs. A single VM-Series firewall protects traffic between four guest
VMs spread across two Hyper-V hosts. VLAN tagging is used to logically
isolate traffic and direct it to the firewall. Additionally, management
traffic is decoupled from all other traffic by placing it on its
own external vSwitch.