SlideShare a Scribd company logo
© Copyright Fortinet Inc. All rights reserved.
Fortinet & VMware Integration
VMUGIT Meeting Roma
Antonio Gentile
Systems Engineer, Italy
agentile@fortinet.com
26/09/2016
Agenda
• Fortinet Cloud & SDN Vision
• Fortinet NSX Integration
• Use Cases
• Demonstration
3
End-to-End Global Cybersecurity Platform
Coverage from Endpoint to Edge to Core to Data Center to Cloud
Client
Security
Secure
Access
Network
Segmentation
Application
Security
Cloud
Security
Control & Visibility
Security Services & Framework
USERS
NETWORK
DATA CENTER
FortiGate
FortiManager FortiAnalyzer
FortiGate
for AWS
FortiGate
VMX
FortiClient
4
Fortinet Cloud & SDN Vision
Network Security as Agile and Elastic Underlying Infrastructure
Virtualization SDN Cloud (IaaS) Cloud (SaaS)
vSphere
XenServer
Hyper-V
NSX
Physical
& Virtual
Security
Appliances FortiGate FortiManagerFortiSandbox FortiAnalyzer FortiWeb FortiADC FortiDDoSFortiWifiFortiMail
5
Security for the Cloud
Virtualization
Hypervisor Port
Hypervisor
Private Cloud
SDDC - SDN - Orchestration
Integration
Public Cloud
On-Demand
IaaS Cloud
Connector API
East-West
NGFW WAF Management Reporting APT
SaaS Cloud
Proxy
CASI
Broker
API
Hybrid
6
Security Across all of the Network - Global and Local
App Control Antivirus Anti-spam
IPS Web App Database
Web
Filtering
Vulnerability
Management
Botnet
Mobile
Security
Cloud
Sandbox
Deep
App Control
PartnerFortiWebFortiMailFortiClient FortiGate
Threat
Researchers
Threat Intelligence
Exchange
FortiSandbox
7
Fortinet Virtualized (Guests) Security Solutions
• FortiGate-VM
• Unified Threat Management
• FortiManager-VM
• Centralized Management
• FortiAnalyzer-VM
• Logging and Reporting
• FortiWeb-VM
• Web Application Security
• FortiMail-VM
• Messaging Security
• FortiAuthenticator-VM
• User Identity Management
• FortiADC-VM
• Application Delivery
• FortiCache-VM
• Content Caching
• FortiVoice-VM
• Complete Business Phone Systems
• FortiRecorder-VM
• Video Security
• FortiSanbox-VM
• Advanced Threat Detection
8
Fortinet Virtualized (Guests) Security Solutions
• FortiGate-VM
• Unified Threat Management
• FortiManager-VM
• Centralized Management
• FortiAnalyzer-VM
• Logging and Reporting
• FortiWeb-VM
• Web Application Security
• FortiMail-VM
• Messaging Security
• FortiAuthenticator-VM
• User Identity Management
• FortiADC-VM
• Application Delivery
• FortiCache-VM
• Content Caching
• FortiVoice-VM
• Complete Business Phone Systems
• FortiRecorder-VM
• Video Security
• FortiSanbox-VM
• Advanced Threat Detection
Guest-VMs
9
Virtual Appliance Platforms – Private and Public Cloud
Virtual Appliance
VMware Citrix Open Source Amazon Microsoft
vSphere
v4.0, 4.1
vSphere v5.0
vSphere
v5.1, 5.5
vSphere v6.0
Xen
Server
v5.6 SP2
Xen
Server v6.0
Xen KVM AWS
Hyper-V
2008 R2
Hyper-V
2012
FortiGate-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔
FortiManager-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔
FortiAnalyzer-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔
FortiWeb-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔
FortiMail-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔
FortiAuthenticator-VM ✔ ✔ ✔ ✔ ✔ ✔
FortiADC-VM ✔ ✔ ✔
FortiCache-VM ✔ ✔ ✔ ✔
FortiVoice-VM ✔ ✔ ✔ ✔ ✔ ✔
FortiRecorder-VM ✔ ✔ ✔ ✔ ✔ ✔
FortiSandbox-VM ✔ ✔
FortiPrivateCloud ✔ ✔
*
* Also available as pay-as-you-go licensing option
*
10
Virtual Data Center Security Challenges
§ Difficult configuration to have security within the same vSwitch and/or forward domain
§ Perimeter-centric network security has proven insufficient
§ Use fine-grained network segmentation approach - wrap security control around much smaller
groups of resources
§ Best practice approach from a security perspective, but difficult to apply in traditional
environments
§ Two key operational barriers
» throughput capacity
» operations/change management East-West
Micro-Segmentation Zero-Trust East-West Control
Trust No One – Not Even Your End Users
FortiGate VMX with VMware NSX
12
Added Value of Security integration in SDDC
Requirements Solution
Not just firewall, but advanced features
Micro-Segmentation and Zero Trust
Control of ‘east-west’ traffic, Inter and Intra VM
security, Logical Security Zone (multi-tier)
Integration, Orchestration and Automation
13
Key Cloud Security Use Cases
Segment End-to-End Traffic Within and Across the
Hybrid Cloud or Intra-VM
Mitigate increasing concentration of data and risk in
consolidated data centers, and across private and
public cloud
Security Requirements
Whitelist-based policy model
Fine-grained honeycomb based on user,
role, apps, devices
Deployable into flat, open networks
without disruption
Monitor and restrict VPN and data
connection between on-premise and
public clouds
Internet
Cloud
Internal
Network
(100 Gbps+)
Private
Cloud
Edge
Gateway
Data Center
ISFW
ISFW
ISFW
ISFWISFW
External
Internal
Hypervisor
ISFW
SG3
SG2
SG1
FortiGate-VMX	
Security		Node
14
Manage
Components for NSX Integration
Mandatory Components for NSX Integration
Third Party Solution
Service Manager
Service Appliance
ESXi Hosts
VMware
vCenter Server
V5.5 or v6.0
VMware vSphere
(Enterprise Plus license
v5.5 or v6.0)
REST API
Fortinet Solution
FortiGate-VMX
Service Manager
FortiGate-VMX
Security Appliance
15
FortiGate-VMX and NSX Integration/Interactions
dvSwitch
FGT-VMX FGT-VMX
Pushpolicysynchronizationtoall
FortiGate-VMXdeployedincluster
7
Register Fortinet as security service with NSX Manager1
Auto-deployFortiGate-VMX
toallhostsinsecuritycluster
2
FortiGate-VMXconnects
withFortiGate-VMX
ServiceManager
3
License verification & configuration
synchronization with
FortiGate-VMX
4
NSXSecurityPolicydefinenetwork
introspectionrulestoredirecttraffic
5
Real-time updates of object database6
FortiGate-VMX
Service Manager
16
FortiGate-VMX and NSX Manager Setup
Adding VMware NSX details on FortiGate Service Manager
FortiGate VMX Service on NSX Manager
17
FGT-VMX imports NSX Security Groups
§ On NSX create Security Groups and assign “Objects”
Security Groups defined on NSX are automatically created on FGT-VMX
18
FGT-VMX imports NSX Security Groups
§ On NSX create Security Groups and assign “Objects”
§ FortiGate VMX automatically imports the Security Groups as a dynamic firewall
addresses with the VMs IP address
Security Groups defined on NSX are automatically created on FGT-VMX
19
NSX Security Group definition and usage
Server SG
FortiGate-VMX NSX Manager
Service Groups created on NSX Manager
automatically get sent to the FortiGate-
VMX and are available for Policy Creation
Policy Created on
FortiGate-VMX using
Exchanged Security
Group
20
VMware Kernel
dvSwitch
FGT-VMX and VMWARE NSX Filter Driver Interaction
1 Define NGFW Firewall Policies
2
FGT-VMX
NetX NSX Filter Driver
int
ext
Packet Flow
1. From VM to NSX Filter Driver
2. NSX Filter Driver Forward to Third
party Solution (FGT-VMX)
3. FGT-VMX applies Security and
sends packet back to NSX Filter
Driver
4. NSX Filter Driver can do service
chaining or send packet to
destination
FortiGate-VMX
Service Manager
21
Policy Creation
§ Firewall Policy is now IP independent
Policy created based on Security Group
Internal External
DistributedVirtual
Switch
22
FortiGate-VMX License Model
§ One license for the FortiGate-VMX Service Manager
§ Simple license based on number of FGT-VMX Security Appliance deployed
» One FortiGate-VMX license per ESXi host
» No limits placed on resources (virtual or hardware), nor number of protected VM
workloads
Hypervisor with 2 sockets Hypervisor with 1 socket 2 FGT-VMX
Licenses
3 FGT-VMX
Licenses
Hypervisor with 2 sockets
Central license server with auto decrement
23
Multiple Services/Customers
§ Real Multi-tenancy (VDOM) support
» Virtual Domain (VDOM) dedicated per tenant or individual security feature
» Service Profile and Groups ensure proper segmentation
24
Resource Monitoring
§ Per Security Appliance instance Resource monitor
25
CLOUD SECURITY
Use Cases
27
TELCO – Use Case – Dedicated Customer Firewall
(FortiGate-VM)
Web Servers Application Servers Database Servers
vSwitch APP
Hypervisor
vSwitch DBvSwitch WEB
vSwitch External
Internet
•Customer Managed
Firewall
•Orchestrated Customer
Creation
•FortiGate-VM to control
east-west application
traffic
• Traffic is required to
flow through the
FortiGate-VM (L2 or L3)
to secure traffic
• Intra-VM security
requires L2 VDOMs and
inter-VDOM link
configuration
• Physical FortiGate to
control north-south traffic
App Control Antivirus Anti-spam
IPS Web App Web
Filtering
Botnet
Cloud
Sandbox
28
ENTERPRISE – NSX Integration Use Case: Function
Segmentation with VDOMs
Security	
Group	D
Security	
Group	C
Security	
Group	B
VDOM1:
IPS
VDOM	2:
URL	Filtering
VDOM	3:	
App	Control
VDOM	5:
Anti-Virus
VDOM	6:
Anti	spam
nsx VDOM	(on	by	default):	NGFW,	IPS,	URL	Filtering,	Anti-Virus	etc..
Security	
Group	A
• Segmented groups can have
unique feature set applied
• Provides performance benefits
as all groups don’t have identical
security requirements
• Each department eg.. Human
Resources, Legal, Marketing
etc. can have it’s own VDOM
and it’s own security feature set
• Fortinet Patented
Virtual Domain
Technology
• Only Security Vendor
to support Virtual
Segmentation by
Function for Security.
VDOM	4:	
Web	Application	
Firewall
29
ENTERPRISE – NSX Integration Use Case: Function
Segmentation with VDOMs
Security	
Group	D
Security	
Group	C
Security	
Group	B
VDOM1:
IPS
VDOM	2:
URL	Filtering
VDOM	3:	
App	Control
VDOM	5:
Anti-Virus
VDOM	6:
Anti	spam
nsx VDOM	(on	by	default):	NGFW,	IPS,	URL	Filtering,	Anti-Virus	etc..
Security	
Group	A
VDOM	4:	
Web	Application	
Firewall
Demo!!
31
Multi-Tier Application Diagram
web-01 web-02
Web-01
10.0.1.0/24
.11 .12
External
192.168.195.0/23
App-01
.11
.1
.1
.1
.2
App-02
.12
App-01
10.0.2.0/24
DB-01
.11
.1
DB-01
10.0.3.0/24
Transit-01
172.16.1.0/24
.2
VIP-Web: 192.168.195.143:80 (Web-01:80+Web-02:80)
VIP-App: 172.16.1.6:80 (App-01:80+App-02:80)
Client to Web: HTTP (80)1
Web to App: HTTP (80)2
App to DB: mysql (3306)3
32
Demonstration - Use Cases 1
§ Security Policies for Multi-Tier Application Segmentation
» Web Tier allowed to receive request from outside and generate
requests to App Tier only
» App Tier allowed to receive requests from Web Tier and generate
requests to BD Tier only
» DB Tier allowed to receive requests from App Tier and not allowed to
generate requests
App-02
App-01
Web-02
Web-01
DB-01
IPS Web App
App Control IPS
Antivirus
Questions??
Fortinet & VMware integration

More Related Content

PDF
Stl meetup cloudera platform - january 2020
PDF
Microsoft Power BI Copilot
PPTX
You Need a Data Catalog. Do You Know Why?
PPTX
[DSC Europe 22] Overview of the Databricks Platform - Petar Zecevic
PDF
Mlflow with databricks
PDF
Architect’s Open-Source Guide for a Data Mesh Architecture
PDF
CDC patterns in Apache Kafka®
PDF
Power the SOC of the Future with scale, speed and choice - Splunk Public Sect...
Stl meetup cloudera platform - january 2020
Microsoft Power BI Copilot
You Need a Data Catalog. Do You Know Why?
[DSC Europe 22] Overview of the Databricks Platform - Petar Zecevic
Mlflow with databricks
Architect’s Open-Source Guide for a Data Mesh Architecture
CDC patterns in Apache Kafka®
Power the SOC of the Future with scale, speed and choice - Splunk Public Sect...

What's hot (20)

PDF
Data Storage Formats in Hadoop
PPTX
Splunking HL7 Healthcare Data for Business Value
PPTX
Data mesh
PDF
The Parquet Format and Performance Optimization Opportunities
PPTX
vmware_cloud_foundation_on_vxrail_technical_customer_presentation.pptx
PPTX
Vce vxrail-customer-presentation new
PDF
Modern Data Architecture
PDF
Alphorm.com Formation Microsoft Azure (AZ-104) : Administration
PDF
Data Analytics Strategies & Solutions for SAP customers
PDF
Cloud-native Semantic Layer on Data Lake
PDF
Serverless Kafka on AWS as Part of a Cloud-native Data Lake Architecture
PPTX
Azure purview
PDF
Essential Metadata Strategies
PPTX
Data Lakehouse, Data Mesh, and Data Fabric (r2)
PPT
Hadoop Security Architecture
PDF
From Data Warehouse to Lakehouse
PDF
Dell Technologies - Company and Portfolio Introduction in 20 Minutes
PDF
Data Governance — Aligning Technical and Business Approaches
PPTX
Data platform modernization with Databricks.pptx
PPTX
Apache Atlas: Why Big Data Management Requires Hierarchical Taxonomies
Data Storage Formats in Hadoop
Splunking HL7 Healthcare Data for Business Value
Data mesh
The Parquet Format and Performance Optimization Opportunities
vmware_cloud_foundation_on_vxrail_technical_customer_presentation.pptx
Vce vxrail-customer-presentation new
Modern Data Architecture
Alphorm.com Formation Microsoft Azure (AZ-104) : Administration
Data Analytics Strategies & Solutions for SAP customers
Cloud-native Semantic Layer on Data Lake
Serverless Kafka on AWS as Part of a Cloud-native Data Lake Architecture
Azure purview
Essential Metadata Strategies
Data Lakehouse, Data Mesh, and Data Fabric (r2)
Hadoop Security Architecture
From Data Warehouse to Lakehouse
Dell Technologies - Company and Portfolio Introduction in 20 Minutes
Data Governance — Aligning Technical and Business Approaches
Data platform modernization with Databricks.pptx
Apache Atlas: Why Big Data Management Requires Hierarchical Taxonomies
Ad

Viewers also liked (20)

PDF
Nutanix - Inail User Case
PPTX
Fortinet av
PDF
Advanced Threat Protection – ultimátní bezpečnostní řešení
PPTX
Fortinet
PPTX
Advanced Threat Protection
PDF
Fortinet security ecosystem
PPTX
Devops journey chefpopup-2016.04.26-v2
PPTX
InterVision-Overview.January-2016
PPTX
OpenStack Foundation 2H 2015 Marketing Plan
PPTX
Cloud Native Applications - DevOps, EMC and Cloud Foundry
PPT
Fortinet FortiOS 5 Presentation
PDF
Intro to Platform9: Private Clouds Made Easy
PDF
Managing vSphere Across Multiple Regions and Multiple vCenters
PDF
Patterns and Practices of a Successful DevOps Transformation
PPTX
Achieving DevOps Success with Chef Automate
PDF
Creating a fortigate vpn network & security blog
PDF
Chef Automate Workflow Demo
Nutanix - Inail User Case
Fortinet av
Advanced Threat Protection – ultimátní bezpečnostní řešení
Fortinet
Advanced Threat Protection
Fortinet security ecosystem
Devops journey chefpopup-2016.04.26-v2
InterVision-Overview.January-2016
OpenStack Foundation 2H 2015 Marketing Plan
Cloud Native Applications - DevOps, EMC and Cloud Foundry
Fortinet FortiOS 5 Presentation
Intro to Platform9: Private Clouds Made Easy
Managing vSphere Across Multiple Regions and Multiple vCenters
Patterns and Practices of a Successful DevOps Transformation
Achieving DevOps Success with Chef Automate
Creating a fortigate vpn network & security blog
Chef Automate Workflow Demo
Ad

Similar to Fortinet & VMware integration (20)

PDF
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
PDF
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
PPTX
Software defined security-framework_final
PPTX
PeeringOne - Raffcomm Migration Proposal v1.4 (1).pptx
PDF
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
PDF
End to End Application Visibility and Troubleshooting Across the Virtual Clou...
PPTX
FortiProxy sales presentation-02022020_Vee.pptx
PDF
VMware NSX for vSphere - Intro and use cases
PPTX
VMWARE Professionals - Security, Multitenancy and Flexibility
PPTX
Secure AWS with Fortinet Security Fabric.pptx
PDF
Vmware Seminar Security & Compliance for the cloud with Trend Micro
PDF
Vss Security And Compliance For The Cloud
PPTX
VMware-vShield-Presentation-pp-en-Dec10.pptx
PPTX
Self service it with v realizeautomation and nsx
PDF
Business Agility and Security with VMware
PPT
04 vsx power-r65
PDF
Securing Your AWS Global Transit Network: Are You Asking the Right Questions?
PPTX
VMware vShield - Overview
PDF
GAMO VMware vCloud Air
PDF
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
Software defined security-framework_final
PeeringOne - Raffcomm Migration Proposal v1.4 (1).pptx
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
End to End Application Visibility and Troubleshooting Across the Virtual Clou...
FortiProxy sales presentation-02022020_Vee.pptx
VMware NSX for vSphere - Intro and use cases
VMWARE Professionals - Security, Multitenancy and Flexibility
Secure AWS with Fortinet Security Fabric.pptx
Vmware Seminar Security & Compliance for the cloud with Trend Micro
Vss Security And Compliance For The Cloud
VMware-vShield-Presentation-pp-en-Dec10.pptx
Self service it with v realizeautomation and nsx
Business Agility and Security with VMware
04 vsx power-r65
Securing Your AWS Global Transit Network: Are You Asking the Right Questions?
VMware vShield - Overview
GAMO VMware vCloud Air
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...

More from VMUG IT (20)

PDF
04 vmugit aprile_2018_raff_poltronieri
PDF
03 vmugit aprile_2018_veeam
PDF
02 vmugit aprile_2018_il_restodelcarlino
PDF
01 vmugit aprile_2018_bologna_benvenuto
PDF
07 vmugit aprile_2018_massimiliano_moschini
PDF
06 vmugit aprile_2018_alessandro_tinivelli
PDF
05 vmugit aprile_2018_7_layers
PDF
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
PDF
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
PDF
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
PPTX
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
PDF
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
PPTX
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
PPTX
00 - VMUGIT - Lecce 2018 - Intro
PPTX
Luca dell'oca - italian vmug usercon 2017
PPTX
Luc Dekens - Italian vmug usercon
PPTX
Gianni Resti
PDF
Frank Denneman keynote
PPTX
Vmug 2017 Guido Frabotti
PPTX
Claudio Panerai - Achab
04 vmugit aprile_2018_raff_poltronieri
03 vmugit aprile_2018_veeam
02 vmugit aprile_2018_il_restodelcarlino
01 vmugit aprile_2018_bologna_benvenuto
07 vmugit aprile_2018_massimiliano_moschini
06 vmugit aprile_2018_alessandro_tinivelli
05 vmugit aprile_2018_7_layers
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
00 - VMUGIT - Lecce 2018 - Intro
Luca dell'oca - italian vmug usercon 2017
Luc Dekens - Italian vmug usercon
Gianni Resti
Frank Denneman keynote
Vmug 2017 Guido Frabotti
Claudio Panerai - Achab

Recently uploaded (20)

PDF
KodekX | Application Modernization Development
PPTX
Programs and apps: productivity, graphics, security and other tools
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Approach and Philosophy of On baking technology
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Encapsulation theory and applications.pdf
KodekX | Application Modernization Development
Programs and apps: productivity, graphics, security and other tools
The AUB Centre for AI in Media Proposal.docx
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Machine learning based COVID-19 study performance prediction
Spectral efficient network and resource selection model in 5G networks
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Building Integrated photovoltaic BIPV_UPV.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Electronic commerce courselecture one. Pdf
Review of recent advances in non-invasive hemoglobin estimation
NewMind AI Weekly Chronicles - August'25 Week I
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Approach and Philosophy of On baking technology
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Unlocking AI with Model Context Protocol (MCP)
Encapsulation theory and applications.pdf

Fortinet & VMware integration

  • 1. © Copyright Fortinet Inc. All rights reserved. Fortinet & VMware Integration VMUGIT Meeting Roma Antonio Gentile Systems Engineer, Italy agentile@fortinet.com 26/09/2016
  • 2. Agenda • Fortinet Cloud & SDN Vision • Fortinet NSX Integration • Use Cases • Demonstration
  • 3. 3 End-to-End Global Cybersecurity Platform Coverage from Endpoint to Edge to Core to Data Center to Cloud Client Security Secure Access Network Segmentation Application Security Cloud Security Control & Visibility Security Services & Framework USERS NETWORK DATA CENTER FortiGate FortiManager FortiAnalyzer FortiGate for AWS FortiGate VMX FortiClient
  • 4. 4 Fortinet Cloud & SDN Vision Network Security as Agile and Elastic Underlying Infrastructure Virtualization SDN Cloud (IaaS) Cloud (SaaS) vSphere XenServer Hyper-V NSX Physical & Virtual Security Appliances FortiGate FortiManagerFortiSandbox FortiAnalyzer FortiWeb FortiADC FortiDDoSFortiWifiFortiMail
  • 5. 5 Security for the Cloud Virtualization Hypervisor Port Hypervisor Private Cloud SDDC - SDN - Orchestration Integration Public Cloud On-Demand IaaS Cloud Connector API East-West NGFW WAF Management Reporting APT SaaS Cloud Proxy CASI Broker API Hybrid
  • 6. 6 Security Across all of the Network - Global and Local App Control Antivirus Anti-spam IPS Web App Database Web Filtering Vulnerability Management Botnet Mobile Security Cloud Sandbox Deep App Control PartnerFortiWebFortiMailFortiClient FortiGate Threat Researchers Threat Intelligence Exchange FortiSandbox
  • 7. 7 Fortinet Virtualized (Guests) Security Solutions • FortiGate-VM • Unified Threat Management • FortiManager-VM • Centralized Management • FortiAnalyzer-VM • Logging and Reporting • FortiWeb-VM • Web Application Security • FortiMail-VM • Messaging Security • FortiAuthenticator-VM • User Identity Management • FortiADC-VM • Application Delivery • FortiCache-VM • Content Caching • FortiVoice-VM • Complete Business Phone Systems • FortiRecorder-VM • Video Security • FortiSanbox-VM • Advanced Threat Detection
  • 8. 8 Fortinet Virtualized (Guests) Security Solutions • FortiGate-VM • Unified Threat Management • FortiManager-VM • Centralized Management • FortiAnalyzer-VM • Logging and Reporting • FortiWeb-VM • Web Application Security • FortiMail-VM • Messaging Security • FortiAuthenticator-VM • User Identity Management • FortiADC-VM • Application Delivery • FortiCache-VM • Content Caching • FortiVoice-VM • Complete Business Phone Systems • FortiRecorder-VM • Video Security • FortiSanbox-VM • Advanced Threat Detection Guest-VMs
  • 9. 9 Virtual Appliance Platforms – Private and Public Cloud Virtual Appliance VMware Citrix Open Source Amazon Microsoft vSphere v4.0, 4.1 vSphere v5.0 vSphere v5.1, 5.5 vSphere v6.0 Xen Server v5.6 SP2 Xen Server v6.0 Xen KVM AWS Hyper-V 2008 R2 Hyper-V 2012 FortiGate-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ FortiManager-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ FortiAnalyzer-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ FortiWeb-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ FortiMail-VM ✔ ✔ ✔ ✔ ✔ ✔ ✔ ✔ FortiAuthenticator-VM ✔ ✔ ✔ ✔ ✔ ✔ FortiADC-VM ✔ ✔ ✔ FortiCache-VM ✔ ✔ ✔ ✔ FortiVoice-VM ✔ ✔ ✔ ✔ ✔ ✔ FortiRecorder-VM ✔ ✔ ✔ ✔ ✔ ✔ FortiSandbox-VM ✔ ✔ FortiPrivateCloud ✔ ✔ * * Also available as pay-as-you-go licensing option *
  • 10. 10 Virtual Data Center Security Challenges § Difficult configuration to have security within the same vSwitch and/or forward domain § Perimeter-centric network security has proven insufficient § Use fine-grained network segmentation approach - wrap security control around much smaller groups of resources § Best practice approach from a security perspective, but difficult to apply in traditional environments § Two key operational barriers » throughput capacity » operations/change management East-West Micro-Segmentation Zero-Trust East-West Control Trust No One – Not Even Your End Users
  • 11. FortiGate VMX with VMware NSX
  • 12. 12 Added Value of Security integration in SDDC Requirements Solution Not just firewall, but advanced features Micro-Segmentation and Zero Trust Control of ‘east-west’ traffic, Inter and Intra VM security, Logical Security Zone (multi-tier) Integration, Orchestration and Automation
  • 13. 13 Key Cloud Security Use Cases Segment End-to-End Traffic Within and Across the Hybrid Cloud or Intra-VM Mitigate increasing concentration of data and risk in consolidated data centers, and across private and public cloud Security Requirements Whitelist-based policy model Fine-grained honeycomb based on user, role, apps, devices Deployable into flat, open networks without disruption Monitor and restrict VPN and data connection between on-premise and public clouds Internet Cloud Internal Network (100 Gbps+) Private Cloud Edge Gateway Data Center ISFW ISFW ISFW ISFWISFW External Internal Hypervisor ISFW SG3 SG2 SG1 FortiGate-VMX Security Node
  • 14. 14 Manage Components for NSX Integration Mandatory Components for NSX Integration Third Party Solution Service Manager Service Appliance ESXi Hosts VMware vCenter Server V5.5 or v6.0 VMware vSphere (Enterprise Plus license v5.5 or v6.0) REST API Fortinet Solution FortiGate-VMX Service Manager FortiGate-VMX Security Appliance
  • 15. 15 FortiGate-VMX and NSX Integration/Interactions dvSwitch FGT-VMX FGT-VMX Pushpolicysynchronizationtoall FortiGate-VMXdeployedincluster 7 Register Fortinet as security service with NSX Manager1 Auto-deployFortiGate-VMX toallhostsinsecuritycluster 2 FortiGate-VMXconnects withFortiGate-VMX ServiceManager 3 License verification & configuration synchronization with FortiGate-VMX 4 NSXSecurityPolicydefinenetwork introspectionrulestoredirecttraffic 5 Real-time updates of object database6 FortiGate-VMX Service Manager
  • 16. 16 FortiGate-VMX and NSX Manager Setup Adding VMware NSX details on FortiGate Service Manager FortiGate VMX Service on NSX Manager
  • 17. 17 FGT-VMX imports NSX Security Groups § On NSX create Security Groups and assign “Objects” Security Groups defined on NSX are automatically created on FGT-VMX
  • 18. 18 FGT-VMX imports NSX Security Groups § On NSX create Security Groups and assign “Objects” § FortiGate VMX automatically imports the Security Groups as a dynamic firewall addresses with the VMs IP address Security Groups defined on NSX are automatically created on FGT-VMX
  • 19. 19 NSX Security Group definition and usage Server SG FortiGate-VMX NSX Manager Service Groups created on NSX Manager automatically get sent to the FortiGate- VMX and are available for Policy Creation Policy Created on FortiGate-VMX using Exchanged Security Group
  • 20. 20 VMware Kernel dvSwitch FGT-VMX and VMWARE NSX Filter Driver Interaction 1 Define NGFW Firewall Policies 2 FGT-VMX NetX NSX Filter Driver int ext Packet Flow 1. From VM to NSX Filter Driver 2. NSX Filter Driver Forward to Third party Solution (FGT-VMX) 3. FGT-VMX applies Security and sends packet back to NSX Filter Driver 4. NSX Filter Driver can do service chaining or send packet to destination FortiGate-VMX Service Manager
  • 21. 21 Policy Creation § Firewall Policy is now IP independent Policy created based on Security Group Internal External DistributedVirtual Switch
  • 22. 22 FortiGate-VMX License Model § One license for the FortiGate-VMX Service Manager § Simple license based on number of FGT-VMX Security Appliance deployed » One FortiGate-VMX license per ESXi host » No limits placed on resources (virtual or hardware), nor number of protected VM workloads Hypervisor with 2 sockets Hypervisor with 1 socket 2 FGT-VMX Licenses 3 FGT-VMX Licenses Hypervisor with 2 sockets Central license server with auto decrement
  • 23. 23 Multiple Services/Customers § Real Multi-tenancy (VDOM) support » Virtual Domain (VDOM) dedicated per tenant or individual security feature » Service Profile and Groups ensure proper segmentation
  • 24. 24 Resource Monitoring § Per Security Appliance instance Resource monitor
  • 27. 27 TELCO – Use Case – Dedicated Customer Firewall (FortiGate-VM) Web Servers Application Servers Database Servers vSwitch APP Hypervisor vSwitch DBvSwitch WEB vSwitch External Internet •Customer Managed Firewall •Orchestrated Customer Creation •FortiGate-VM to control east-west application traffic • Traffic is required to flow through the FortiGate-VM (L2 or L3) to secure traffic • Intra-VM security requires L2 VDOMs and inter-VDOM link configuration • Physical FortiGate to control north-south traffic App Control Antivirus Anti-spam IPS Web App Web Filtering Botnet Cloud Sandbox
  • 28. 28 ENTERPRISE – NSX Integration Use Case: Function Segmentation with VDOMs Security Group D Security Group C Security Group B VDOM1: IPS VDOM 2: URL Filtering VDOM 3: App Control VDOM 5: Anti-Virus VDOM 6: Anti spam nsx VDOM (on by default): NGFW, IPS, URL Filtering, Anti-Virus etc.. Security Group A • Segmented groups can have unique feature set applied • Provides performance benefits as all groups don’t have identical security requirements • Each department eg.. Human Resources, Legal, Marketing etc. can have it’s own VDOM and it’s own security feature set • Fortinet Patented Virtual Domain Technology • Only Security Vendor to support Virtual Segmentation by Function for Security. VDOM 4: Web Application Firewall
  • 29. 29 ENTERPRISE – NSX Integration Use Case: Function Segmentation with VDOMs Security Group D Security Group C Security Group B VDOM1: IPS VDOM 2: URL Filtering VDOM 3: App Control VDOM 5: Anti-Virus VDOM 6: Anti spam nsx VDOM (on by default): NGFW, IPS, URL Filtering, Anti-Virus etc.. Security Group A VDOM 4: Web Application Firewall
  • 31. 31 Multi-Tier Application Diagram web-01 web-02 Web-01 10.0.1.0/24 .11 .12 External 192.168.195.0/23 App-01 .11 .1 .1 .1 .2 App-02 .12 App-01 10.0.2.0/24 DB-01 .11 .1 DB-01 10.0.3.0/24 Transit-01 172.16.1.0/24 .2 VIP-Web: 192.168.195.143:80 (Web-01:80+Web-02:80) VIP-App: 172.16.1.6:80 (App-01:80+App-02:80) Client to Web: HTTP (80)1 Web to App: HTTP (80)2 App to DB: mysql (3306)3
  • 32. 32 Demonstration - Use Cases 1 § Security Policies for Multi-Tier Application Segmentation » Web Tier allowed to receive request from outside and generate requests to App Tier only » App Tier allowed to receive requests from Web Tier and generate requests to BD Tier only » DB Tier allowed to receive requests from App Tier and not allowed to generate requests App-02 App-01 Web-02 Web-01 DB-01 IPS Web App App Control IPS Antivirus