SlideShare a Scribd company logo
Using SDN to secure the campus
Hewlett Packard Enterprise
Eugene Berger
HPE Aruba CTO, UK&I
@Eugatwork
Cloud and Datacenter
Leader
Leadership in both
SMB & enterprise
networking
Leading the Mobility
and Campus
Enterprise
HPE and Aruba – Better Together
Using sdn to secure the campus - Networkshop44
HPE SDN vision and strategy
SDN provides programmable networks that rapidly aligns to business
applications
Data center, campus
& branch automation
Open Standards
ecosystem
Reignite
innovation
Easily accessible
marketplace
Agility Alignment
Coexist with brownfield Platform for innovation
Use case-led Automation & simplicity
Journey to Software-defined Networking
HP & Stanford collaborate and demo OpenFlow
HP Ships 30 Million SDN-Enabled Ports
& SDN Controller
Software-defined Networking
2007
2011
2015+
Solving the problems of the
New Style of IT
SDN is Now
Security Cloud Big Data Mobility Innovation
Defining Software-defined Networking
Open standard-based programmatic access
to infrastructureInfrastructure
Control
Application
Separate control and data plane; abstract
control plane of many devices to one
Deliver open programmable interfaces to
orchestrate network service automation
SDNArchitecture
Source: opennetworking.org
Delivering the functions of an SDN architecture
Software-defined Network components
Infrastructure
Control
Application
Separate control and data plane; abstract
control plane of many devices to one
Deliver open programmable interfaces to
orchestrate network service automation
SDNArchitecture
Open standard-based programmatic access
to infrastructure
Network Device Network Device Network Device
Controller
Open Programmable Interface
Cloud
Orchestration
SDN
Applications
Open Programmable APIs
Virtual Application Networks SDN Controller
Infrastructure
SDNArchitecture
Programmable network aligned to business objectives
Virtual Application Networks deliver automation, agility
Virtual Cloud
Network Protector
Load Balancing
Partner Apps
Network Optimizer
ConvergedControl Design
Implementation
and Support
Services
Over 30 million ports across 50 Switches
10 Routers
VAN Network
Resource
Automation
Intelligent
ManagementCenter
VAN SDN
Manager
Management
Applications
Control
VAN Server Connect
VXLAN, NVGRE
Risk-free SDN Deployment
Snapshot of Where We are Today
92 Members
OptimizationSecurity Orchestration
Select SDN Customers
21 SDN Apps
Enabling real-time threat protection across enterprise networks
HPE Network Protector – Security
• Malware/Botnet/
Spyware
Protection
• IPS as a Service
• Security Sensors
& Actions
TippingPoint
HP Network Protector – IPS Integration
Core
Distribution
Edge
Threat Management Center
(1M+ bad sites)
• Reputation(piratesmustdie.com)  Malware
• Inspect all User traffic
Bad DNS Response
IPS
SDN Controller &
Network Protector
South Washington County
Network Protector SDN App
• Maintain 31-site wired and wireless network
serving over 30,000 users with 1 staff member
• Deploy in less than 1 hour
• Fraction of the cost, $200K vs $2million of
hardware
Roseville – R&D Protector
Roseville – R&D Protector
SDN: Knowing the context vs guessing - Clearpass
Traditional Network ‘guessing’ User/Application Directed
??
Traffic Classification
Identity Inference
Context Inference
Telemetry
Inferred Network Policy
Inferred Action
AppUser
Traffic Classification
Telemetry
Network Policy
Coordinated Action
Identity
Event Context
Service Request
CLEARPASS
SDN Customer References
SDN Customer References Brochure
Thank you
18
19CONFIDENTIAL © Copyright 2015. Aruba Networks, an HP company. All rights reserved.
Network Optimizer Customers
SDN Customer References Brochure
HPE VMware Network Virtualization (SDN) collaboration
Network virtualization solutions can run over any IP
network, but app performance/reliability and service
delivery rely on underlying physical network.
VN = logical network services
L2/3, L4-7 - connected to
workloads
Problem: Data Center Network Security
Perimeter-centric network security has proven
insufficient, and micro-segmentation is operationally
infeasible
Little or no
lateral controls
inside perimeter
Internet Internet
Insufficient Operationally
Infeasible
+
Why traditional approaches are
operationally infeasible…
Internet
Perimeter
Firewalls
• Create firewall rules before provisioning
• Update Firewall rules when move or change
• Delete firewall rules when app decommissioned
• Problem increases with more East-West traffic
+
VMware NSX makes micro-segmentation
possible
Internet
Security Policy
Perimeter
Firewalls
Cloud
Management
Platform
+

More Related Content

PPTX
Exhibitor session: Efficient IP
PPTX
Software defined networking - huawei - Networkshop44
PPTX
Exhibitor session: Cisco Meraki
PPTX
Solving access for hybrid it Axians (introducing pulse secure) - Networkshop44
PDF
Solution BluePrint v. Smart Parking
PDF
Mapping EPN Partnerships
PDF
Cyber Security Practices and Future Plan: Real Scenario in ISPs In Nepal
PDF
IPv6 and Internet of Things: A Nice Couple
Exhibitor session: Efficient IP
Software defined networking - huawei - Networkshop44
Exhibitor session: Cisco Meraki
Solving access for hybrid it Axians (introducing pulse secure) - Networkshop44
Solution BluePrint v. Smart Parking
Mapping EPN Partnerships
Cyber Security Practices and Future Plan: Real Scenario in ISPs In Nepal
IPv6 and Internet of Things: A Nice Couple

What's hot (20)

PPTX
Detroit A Smart City..... inspired by a "Community of Practice"
PDF
Open access and beyond
PPTX
How you can engage the future of business
PDF
Connected Healthcare
PPTX
Quortus Edge Computing
PDF
Federations on the rise
PPTX
ASIS 2013: Extending Surveillance Through Wireless Communications
PPTX
Extreme Networks IdentiFi
PDF
Unified Access from Application Chaos to Application Fluency
PDF
Extreme networks - Better Connections. Better Experiences. For Everyone.
PDF
Next Generation Network For Next Generation Students
PPTX
Seminar ppt on li fi technology
PDF
Nas nie zaatakują!
PPTX
Extreme Networks Retail Guest Analytics Solution
PDF
Telefónica Edge Computing Case Study
PPTX
Internet infrastructure in South Asia
PDF
Services Update ARM 3/bdNOG 1
PDF
Simplify Operations
PPTX
APSIG 2016 - IANA Transition: Why do we care?
PDF
Edge computing: Cord build 17 telefonica use cases
Detroit A Smart City..... inspired by a "Community of Practice"
Open access and beyond
How you can engage the future of business
Connected Healthcare
Quortus Edge Computing
Federations on the rise
ASIS 2013: Extending Surveillance Through Wireless Communications
Extreme Networks IdentiFi
Unified Access from Application Chaos to Application Fluency
Extreme networks - Better Connections. Better Experiences. For Everyone.
Next Generation Network For Next Generation Students
Seminar ppt on li fi technology
Nas nie zaatakują!
Extreme Networks Retail Guest Analytics Solution
Telefónica Edge Computing Case Study
Internet infrastructure in South Asia
Services Update ARM 3/bdNOG 1
Simplify Operations
APSIG 2016 - IANA Transition: Why do we care?
Edge computing: Cord build 17 telefonica use cases
Ad

Viewers also liked (20)

PPTX
Eduroam seminar - Networkshop44 2016
PPTX
Find out about Jisc - Networkshop44 2016
PPTX
Whats new in ict law - Networkshop44
PPTX
Network performance lessons from the coal face - Networkshop44
PPTX
Welcome to Networkshop44 - Networkshop44
PPTX
Jisc and janet network updates from network operations, operational services ...
PPTX
Eduroam in portsmouth's wireless city - Networkshop44
PPTX
End to end performance - Networkshop44
PPTX
Next gen insight networkshop44
PPTX
Eduroam workshop nic mitev probes - networkshop44
PPTX
Jisc update janet6 upgrade networkshop44
PPTX
Edupert best practices in supporting end users - Networkshop44
PPTX
Managing and monitoring large scale data transfers - Networkshop44
PPTX
End to end performance networkshop44
PPTX
Dealing with pervasive monitoring - Networkshop44
PPTX
Eduroam workshop nic mitev proactive learning - networkshop44
PPTX
Eduroam workshop nic mitev loughborough uni - networkshop44
PPTX
Multiprotocol label switching (mpls) - Networkshop44
PPTX
Hyper efficient data centres – key ingredient intelligence networkshop44
PPTX
Dev ops, noops or hypeops - Networkshop44
Eduroam seminar - Networkshop44 2016
Find out about Jisc - Networkshop44 2016
Whats new in ict law - Networkshop44
Network performance lessons from the coal face - Networkshop44
Welcome to Networkshop44 - Networkshop44
Jisc and janet network updates from network operations, operational services ...
Eduroam in portsmouth's wireless city - Networkshop44
End to end performance - Networkshop44
Next gen insight networkshop44
Eduroam workshop nic mitev probes - networkshop44
Jisc update janet6 upgrade networkshop44
Edupert best practices in supporting end users - Networkshop44
Managing and monitoring large scale data transfers - Networkshop44
End to end performance networkshop44
Dealing with pervasive monitoring - Networkshop44
Eduroam workshop nic mitev proactive learning - networkshop44
Eduroam workshop nic mitev loughborough uni - networkshop44
Multiprotocol label switching (mpls) - Networkshop44
Hyper efficient data centres – key ingredient intelligence networkshop44
Dev ops, noops or hypeops - Networkshop44
Ad

Similar to Using sdn to secure the campus - Networkshop44 (20)

PPTX
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
PPTX
Apache Hadoop India Summit 2011 Keynote talk "Exploring the Future IT Infrast...
PDF
Cisco Connect Halifax 2018 Simple IT
PPTX
Software Defined networking (SDN)
PPTX
TFI2014 Session I - State of SDN - Sam K. Aldrin
PDF
Virtual Application Networks Innovations Advance Software-defined Network Lea...
PDF
Stephen Wallo
PPT
Data Center Design Guide 4 1
PPTX
F5 Networks - парадная дверь в облака
PPTX
Software Defined Networking
PDF
Better Connections.Better Experiences.For Everyone - Extreme Networks
PDF
08 sdn system intelligence short public beijing sdn conference - 130828
PDF
PDF
Are you ready to be edgy? Bringing applications to the edge of the network
PDF
What is Your Edge From the Cloud to the Edge, Extending Your Reach
PPT
Cloud infrastructure and Cloud Services
PPTX
Spider & F5 Round Table - The Flexible Data Center
PPTX
MARLABS - Cloud services CIO Conference
PPTX
Managed Cloud Services CIO Conference Oil Gas
PDF
Evolving the WAN for the Cloud, using SD-WAN & NFV
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Apache Hadoop India Summit 2011 Keynote talk "Exploring the Future IT Infrast...
Cisco Connect Halifax 2018 Simple IT
Software Defined networking (SDN)
TFI2014 Session I - State of SDN - Sam K. Aldrin
Virtual Application Networks Innovations Advance Software-defined Network Lea...
Stephen Wallo
Data Center Design Guide 4 1
F5 Networks - парадная дверь в облака
Software Defined Networking
Better Connections.Better Experiences.For Everyone - Extreme Networks
08 sdn system intelligence short public beijing sdn conference - 130828
Are you ready to be edgy? Bringing applications to the edge of the network
What is Your Edge From the Cloud to the Edge, Extending Your Reach
Cloud infrastructure and Cloud Services
Spider & F5 Round Table - The Flexible Data Center
MARLABS - Cloud services CIO Conference
Managed Cloud Services CIO Conference Oil Gas
Evolving the WAN for the Cloud, using SD-WAN & NFV

More from Jisc (20)

PPTX
Strengthening open access through collaboration: building connections with OP...
PPTX
Andrew-Brown-JUSP-showcase-20240730.pptx
PPTX
JUSP Showcase - Rebuilding Data presentation
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
FE Accessibility training matrix partnership - information session
PPTX
Procuring a research management system: why is it so hard?
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
How libraries can support authors with open access requirements for UKRI fund...
PPTX
Supporting (UKRI) OA monographs at Salford.pptx
PPTX
The approach at University of Liverpool.pptx
PPTX
Jisc's value to HE: the University of Sheffield
PPTX
Towards a code of practice for AI in AT.pptx
PPTX
Jamworks pilot and AI at Jisc (20/03/2024)
PPTX
Wellbeing inclusion and digital dystopias.pptx
PPTX
Accessible Digital Futures project (20/03/2024)
PPTX
Procuring digital preservation CAN be quick and painless with our new dynamic...
PPTX
International students’ digital experience: understanding and mitigating the ...
PPTX
Digital Storytelling Community Launch!.pptx
PPTX
Open Access book publishing understanding your options (1).pptx
PPTX
Scottish Universities Press supporting authors with requirements for open acc...
Strengthening open access through collaboration: building connections with OP...
Andrew-Brown-JUSP-showcase-20240730.pptx
JUSP Showcase - Rebuilding Data presentation
Adobe Express Engagement Webinar (Delegate).pptx
FE Accessibility training matrix partnership - information session
Procuring a research management system: why is it so hard?
Adobe Express Engagement Webinar (Delegate).pptx
How libraries can support authors with open access requirements for UKRI fund...
Supporting (UKRI) OA monographs at Salford.pptx
The approach at University of Liverpool.pptx
Jisc's value to HE: the University of Sheffield
Towards a code of practice for AI in AT.pptx
Jamworks pilot and AI at Jisc (20/03/2024)
Wellbeing inclusion and digital dystopias.pptx
Accessible Digital Futures project (20/03/2024)
Procuring digital preservation CAN be quick and painless with our new dynamic...
International students’ digital experience: understanding and mitigating the ...
Digital Storytelling Community Launch!.pptx
Open Access book publishing understanding your options (1).pptx
Scottish Universities Press supporting authors with requirements for open acc...

Recently uploaded (20)

PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PDF
01-Introduction-to-Information-Management.pdf
PPTX
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
PDF
Complications of Minimal Access Surgery at WLH
PDF
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PDF
Pre independence Education in Inndia.pdf
PDF
Origin of periodic table-Mendeleev’s Periodic-Modern Periodic table
PPTX
Cell Types and Its function , kingdom of life
PPTX
Introduction to Child Health Nursing – Unit I | Child Health Nursing I | B.Sc...
PDF
Mark Klimek Lecture Notes_240423 revision books _173037.pdf
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PPTX
The Healthy Child – Unit II | Child Health Nursing I | B.Sc Nursing 5th Semester
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
PDF
Basic Mud Logging Guide for educational purpose
PDF
VCE English Exam - Section C Student Revision Booklet
PDF
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
PPTX
Cell Structure & Organelles in detailed.
PPTX
Final Presentation General Medicine 03-08-2024.pptx
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
01-Introduction-to-Information-Management.pdf
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
Complications of Minimal Access Surgery at WLH
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
Pre independence Education in Inndia.pdf
Origin of periodic table-Mendeleev’s Periodic-Modern Periodic table
Cell Types and Its function , kingdom of life
Introduction to Child Health Nursing – Unit I | Child Health Nursing I | B.Sc...
Mark Klimek Lecture Notes_240423 revision books _173037.pdf
FourierSeries-QuestionsWithAnswers(Part-A).pdf
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
The Healthy Child – Unit II | Child Health Nursing I | B.Sc Nursing 5th Semester
human mycosis Human fungal infections are called human mycosis..pptx
Basic Mud Logging Guide for educational purpose
VCE English Exam - Section C Student Revision Booklet
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
Module 4: Burden of Disease Tutorial Slides S2 2025
Cell Structure & Organelles in detailed.
Final Presentation General Medicine 03-08-2024.pptx

Using sdn to secure the campus - Networkshop44

  • 1. Using SDN to secure the campus Hewlett Packard Enterprise Eugene Berger HPE Aruba CTO, UK&I @Eugatwork
  • 2. Cloud and Datacenter Leader Leadership in both SMB & enterprise networking Leading the Mobility and Campus Enterprise HPE and Aruba – Better Together
  • 4. HPE SDN vision and strategy SDN provides programmable networks that rapidly aligns to business applications Data center, campus & branch automation Open Standards ecosystem Reignite innovation Easily accessible marketplace Agility Alignment Coexist with brownfield Platform for innovation Use case-led Automation & simplicity
  • 5. Journey to Software-defined Networking HP & Stanford collaborate and demo OpenFlow HP Ships 30 Million SDN-Enabled Ports & SDN Controller Software-defined Networking 2007 2011 2015+ Solving the problems of the New Style of IT SDN is Now Security Cloud Big Data Mobility Innovation
  • 6. Defining Software-defined Networking Open standard-based programmatic access to infrastructureInfrastructure Control Application Separate control and data plane; abstract control plane of many devices to one Deliver open programmable interfaces to orchestrate network service automation SDNArchitecture Source: opennetworking.org
  • 7. Delivering the functions of an SDN architecture Software-defined Network components Infrastructure Control Application Separate control and data plane; abstract control plane of many devices to one Deliver open programmable interfaces to orchestrate network service automation SDNArchitecture Open standard-based programmatic access to infrastructure Network Device Network Device Network Device Controller Open Programmable Interface Cloud Orchestration SDN Applications Open Programmable APIs
  • 8. Virtual Application Networks SDN Controller Infrastructure SDNArchitecture Programmable network aligned to business objectives Virtual Application Networks deliver automation, agility Virtual Cloud Network Protector Load Balancing Partner Apps Network Optimizer ConvergedControl Design Implementation and Support Services Over 30 million ports across 50 Switches 10 Routers VAN Network Resource Automation Intelligent ManagementCenter VAN SDN Manager Management Applications Control VAN Server Connect VXLAN, NVGRE
  • 10. Snapshot of Where We are Today 92 Members OptimizationSecurity Orchestration Select SDN Customers 21 SDN Apps
  • 11. Enabling real-time threat protection across enterprise networks HPE Network Protector – Security • Malware/Botnet/ Spyware Protection • IPS as a Service • Security Sensors & Actions TippingPoint
  • 12. HP Network Protector – IPS Integration Core Distribution Edge Threat Management Center (1M+ bad sites) • Reputation(piratesmustdie.com)  Malware • Inspect all User traffic Bad DNS Response IPS SDN Controller & Network Protector
  • 13. South Washington County Network Protector SDN App • Maintain 31-site wired and wireless network serving over 30,000 users with 1 staff member • Deploy in less than 1 hour • Fraction of the cost, $200K vs $2million of hardware
  • 14. Roseville – R&D Protector
  • 15. Roseville – R&D Protector
  • 16. SDN: Knowing the context vs guessing - Clearpass Traditional Network ‘guessing’ User/Application Directed ?? Traffic Classification Identity Inference Context Inference Telemetry Inferred Network Policy Inferred Action AppUser Traffic Classification Telemetry Network Policy Coordinated Action Identity Event Context Service Request CLEARPASS
  • 17. SDN Customer References SDN Customer References Brochure
  • 19. 19CONFIDENTIAL © Copyright 2015. Aruba Networks, an HP company. All rights reserved. Network Optimizer Customers SDN Customer References Brochure
  • 20. HPE VMware Network Virtualization (SDN) collaboration Network virtualization solutions can run over any IP network, but app performance/reliability and service delivery rely on underlying physical network. VN = logical network services L2/3, L4-7 - connected to workloads
  • 21. Problem: Data Center Network Security Perimeter-centric network security has proven insufficient, and micro-segmentation is operationally infeasible Little or no lateral controls inside perimeter Internet Internet Insufficient Operationally Infeasible +
  • 22. Why traditional approaches are operationally infeasible… Internet Perimeter Firewalls • Create firewall rules before provisioning • Update Firewall rules when move or change • Delete firewall rules when app decommissioned • Problem increases with more East-West traffic +
  • 23. VMware NSX makes micro-segmentation possible Internet Security Policy Perimeter Firewalls Cloud Management Platform +

Editor's Notes

  • #5: Bullets: Our vision for SDN is to create a programmable network that delivers business applications quickly To offer agility for the network As well as alignment for the network It has to include consistent architecture across the enterprise: DC, campus and branch It must be built on open standards that enable an open ecosystem, so that everybody can participate – partners, customers and developers And that open ecosystem will reignite innovation for the networking industry (new apps) And those innovations need to be easily accessible to customers in a new marketplace that enables new business models
  • #9: Virtual application networks deliver automation and agility. We are the first in the market to have a complete portfolio for each layer of SDN architecture.
  • #10: Phase 1: SDN Ready Deploy: SDN-enabled networks Benefits : - Investment protection - Open Standards - Low risk Phase 2: Hybrid SDN (now) Deploy: Hybrid Mode SDN Networks Benefits: - Application aware network - Reduced complexity - Non disruptive Phase 3: Native SDN Deploy: End-to-end SDN Networks Benefits: - Fully programmable - Highly automated - Rapid innovation
  • #18: Ballarat Grammar The Bama Companies Deltion College Faculty of Science and Technology - Universidade Nova de Lisboa Istanbul Kultur University RMIT University South Washington County Schools The Via Group UBM – InteropNet Lancaster University – SDN Symposium
  • #20: J. R. SIMPLOT LOWNDES COUNTY SCHOOL DISTRICT DREAMWORKS ANIMATION SKG VICTORIA & ALBERT MUSEUM TATA CONSULTANCY SERVICES ADRIENNE CENTER FOR THE PERFOR STICHTING DELTION COLLEGE BDX FÖRETAGEN AB AL MEHBAJ TRADING EST KUWAIT AIRWAYS CORPORATION K.S.C. KÜLTÜR ÜNIVERSITESI TRANS-SYSTEM INC LEVI STRAUSS & CO. ENTEL S.A. UNIVERSITY OF ST.FRANCIS WORLDCOM EXCHANGE INC FACHHOCHSCHULE DÜSSELDORF SMART COMMUNICATIONS, INC.
  • #21: With NSX, virtual networks are programmatically created, provisioned and managed, utilizing the underlying physical network as a simple packet forwarding backplane. Network and security services in software are distributed to hypervisors and “attached” to individual VMs in accordance with networking and security policies defined for each connected application. When a VM is moved to another host, its networking and security services move with it. And when new VMs are created to scale an application, the necessary policies are dynamically applied to those VMs as well.
  • #22: It’s important to understand the challenge micro-segmentation solves, because it’s one that has been know but not solvable in reality until now. If we look at all the well publicized attacks over the last couple of years, Target, Home Depot, Sony and more they all were different from a hacker code perspective, but they all had one thing in common…once the threat got through the perimeter defense, whether through the firewall or from the inside…there was little of no lateral controls to keep the threat from moving from server to server until it found what it was looking for and started pumping out credit card numbers or other private information   Nirvana to most security teams is “micro-segmentation” or a “zero-trust” approach. However, even if your company can afford the capital expense for enough firewalls to deliver the throughput capacity required to achieve high availability micro-segmentation for East-West traffic in your data center, the operational complexity of managing changes, VM movement, policy granularity, unsustainable policy table changes across all of these firewalls quickly becomes operationally infeasible.
  • #23: It’s easy to understand why traditional approaches are operationally infeasible… When packets leave the VM they must traverse the network to be evaluated and enforced at a chokepoint firewall. That means that when the VM was provisioned, someone had to write the rules and put them into the firewall, a time consuming, error prone process that slows down application provisioning...then, if the VM ever moves, the firewall likely needs to be manually updated and if the VM is deleted, the firewall should be manually updated to remove the rules for the deleted VM. All combine to make this operationally infeasible at scale.
  • #24: So how does an SDDC approach make it feasible? We automate everything, when a VM is provisioned, it’s security policies are provisioned with it, so that when the packet leaves the VM, it is evaluated and enforced, right at the virtual interface Then is the VM ever moves, the rules move with it, and if the VM is ever delete, the rules are deleted with it…no human interaction, it’s all automated.