Protect all Workloads with Consistent Network Security
Consistent Security Coverage
Enjoy consistent network security coverage across your NSX environment with a Layer-7 gateway firewall that includes NSX Advanced Threat Prevention and URL filtering.
Unified Management
Manage NSX Gateway Firewall together with NSX Distributed Firewall for all your public and private cloud firewall needs.
Lower Cost
No specialized hardware and simple operations translate to CAPEX and OPEX savings.
Use Cases

Protect Physical Workloads
Provide Layer-7 firewalling for physical workloads without needing access to the operating system.

Secure Private Cloud Zones
Add to your private cloud protections by filtering all traffic at the boundary of designated security zones.

Patrol the Public Cloud Edge
Inspect north-south traffic at the perimeter of your public cloud environment.

Related Products
NSX Distributed Firewall
Layer 7 internal firewall
NSX Advanced Threat Prevention
Complete network traffic inspection
NSX Intelligence
Distributed analytics engine for topology visualization & policy recommendations
Why VMware Gateway Firewall?
Frequently Asked Questions
Both the Gateway and Distributed Firewall are part of the NSX product family and have similar components. However, the Distributed Firewall is designed to handle east-west network traffic (internal traffic). The Gateway Firewall complements the Distributed Firewall to protect east-west traffic in specialized cases such as securing physical workloads. The Gateway Firewall can also function as a private cloud zone firewall or a public cloud edge firewall (for north-south traffic).