NSM: How is VSYS support implemented in NSM?
NSM
Q: How is VSYS support implemented in NSM?
A: Virtual systems in NSM are treated as separate devices, with a special device type used to create them. Virtual systems of a NetScreen device can be placed in the same domain as, or in any sub-domain of the root device. NSM can also be used to create new Virtual Systems on a device, and to configure the settings for them.
For example, if a service provider customer wants to configure Virtual Systems, a root-level admin will create a root device in the Global domain and configure its Virtual Systems and settings (i.e., interfaces or sub-interfaces for the VSYS and possibly shared virtual routers and security zones). After completing these configurations, the root-level admin can exit the virtual system and allow a VSYS admin, if defined, to log on and begin configuring addresses, users, services, VPNs, and policies on a particular VSYS.
The NSM Device Server only maintains an SSP connection to the root device, which can greatly simplify network overhead. Note that while only one connection is maintained, each virtual system will count towards the total number of devices licensed in NSM.