SlideShare a Scribd company logo
Changing the Economics of Firewall Services in the
Software-Defined Center –
VMware NSX Distributed Firewall
Srinivas Nimmagadda, VMware
Anirban Sengupta, VMware
SEC5893
#SEC5893
2
Business Needs
Agility
Flexibility
Elasticity/Scalability
Simplicity
Business Challenges
Reality
Inflexible Networks
Archaic Security
Perf/Scale Issues
Complex Rule Bases
3
Data Center Firewall Architecture
Aggregation Layer
Campus
Core
Core Layer
Access Layer
4
Application Profiles Changing…
Campus
Core
Client – Server
& Web 1.0
Server
3-Tier Apps
Web
App
DB
Web 2.0,
Portals,
Enterprise Apps
5
Virtualization - Changing Dynamics
Campus
Core
VM – VM traffic doesn’t hit network
IP Address Based Rule Sets
Scalability Issues
Complex Firewall Rule Tables
Firewall – “Choke Point”
6
Firewall as a VM
IP Address Based Rule Sets
Server Consolidation Issues
Virtual Appliance Issues
VM Firewall – Still a bottleneck
vMotion & App Placement Issues
7
Wouldn’t It Be Great If My Firewall…
 Removes the need to hair-pin traffic
 Enables Rules based on VM attributes
 Provides High Performance & Scale
 API based Programmability
8
Distributed Virtual Firewall
VM
VM
VM VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
Focus
• Custom built for
Virtual Data Centers
• Distributed
Enforcement
• Centralized
Management
• Performance & Scale
9
DVFW – Hypervisor Embedded Firewall
ESXi
VM VM FW
Benefits…
• Is built right in to the Hypervisor and is lightening fast
• “Line Rate” Performance (10Gbps+ per host)
• No VM can circumvent Firewall
ESXi
VM VM VM
ESXi
VM VM
FW
VM
10
DVFW – Scale Out Architecture
ESXi
VM VM
FW
Benefits…
• Scales with additional “Hosts”
• No “Fork Lift” upgrade to get better scale
ESXi
VM VM
FW ESXi
VM VM
FW
11
DVFW – Flexible Access Control Mechanisms
Benefits…
• Security Groups: Logical grouping of VMs
• VM Tags: Dynamic VM attributes
• User Identity: Identity based firewall
• IP/VLAN: Support physical infrastructure based rules
• Rules follow the VMs
ESXi
Web App
FW
DB
ESXi
Web App
FW
DB
ESXi
Web App
FW
DB
12
Identity & Application Visibility
Active Directory
Eric Frost
User AD Group App Name Originating VM
Name
Destination
VM Name
Source IP Destination IP
Eric Engineering SPDesigner.exe Eric-Win7 Ent-Sharepoint 192.168.10.75 192.168.10.78
ESXi FW
13
DVFW – Centralized Management
ESXi
VM VM VM
ESXi
VM VM VM
Reuse vCenter Objects
Single Rule Table
Role Based (RBAC)
Control
Full REST API
Familiar “Apply To” Model
Central Monitoring
14
Extensibility…
15
Security Service Insertion
Hypervisor
VM
DFW
VM
VM
AV
Vulnerability
Scan
DLP
IPS
NG
FW
APT
16
Vulnerability Scan + Firewall Use Case
Security Architect Deny outbound traffic from “Quarantine” VMs
Vulnerability
Scanner
Identifies serious vulnerabilities in APP-VM-6
and tags the VM as “Quarantine” system
Firewall Blocks outbound traffic from APP-VM-6
Security Operations Patches the OS/Application to address vulnerability
Vulnerability
Scanner
APP-VM-6 is no longer a “Quarantine” machine
Firewall Outbound traffic from APP-VM-6 permitted
17
IPS Use Case
Hypervisor
VM
DFW
VM
VM
IPS
VMware DVFW
High Throughput
User, VM Segmentation
Selective IPS Forward
IPS
Signature Based IPS
+ Malware/APT
18
Changing The Economics…
19
Themes
Security
• VM Attribute Based
• User Identity
• VM Appliance
Agility
• vCenter Integration
• REST API
• vMotion
Integration with
existing Host &
Network Security
solutions
Perf & Scale
Better
Consolidation
Compliance (PCI)
20
Deployment
 Edge Firewall & Distributed Firewall
 Firewall Monitoring & Troubleshooting
 RBAC and Admin Separation
 Auditing & Compliance
21
N-S Firewall, E-W Router / Firewall Logical Topology
Distributed Router & Firewall
VXLAN Transit/Uplink Network
………..
VLAN last mile
FW HA Pair
(High Throughput & CPS)
LB, DHCP
(One-arm) NET 1 NET 2 NET 3
WebFrontEnds
AppTier
DatabaseBackends
3-tier App
OSPF
Physical Routing Edge
Physical Network Fabric
Network Virtualization
iBGP
NAT, FW, VPN, LB
High Port Density
Router & Firewall
NET 1000
22
WAN /
INTERNET /
Corp backbone
Model for Routing & L4-L7 Services
FW/Routing - Phy. Or Virtual
Appiance
Features: NAT,
Perimeter Firewall,
SSLVPN, IPsec VPN,
GSLB, DNS
Routing
L2 Bridge
Distributed Routing
One-armed LB
Features: Server
Loadbalancing, DHCP,
L2VPN
Features: Distributed
ACLs in OVS, anti-spoof
control
Logical L2
23
Other VMware Activities Related to This Session
 HOL:
HOL-SDC-1303
VMware NSX Network Virtualization Platform
 Group Discussions:
SEC1000-GD
Distributed Virtual Firewall - Management, Architecture, Scalability and
Performance with Serge Maskalik
THANK YOU
VMworld 2013: Changing the Economics of Firewall Services in the Software-Defined Center – VMware NSX Distributed Firewall
Changing the Economics of Firewall Services in the
Software-Defined Center –
VMware NSX Distributed Firewall
Srinivas Nimmagadda, VMware
Anirban Sengupta, VMware
SEC5893
#SEC5893

More Related Content

PPTX
WAF CC Introduction
PPT
Virutalization and the Future of Datacenter Security
PPTX
Vmware training presentation
PPTX
What’s new in vSphere 5 and vCenter Server Heartbeat – Customer Presentation
PDF
Kona Web Application Firewall Product Brief - Application-layer defense to pr...
PPTX
Web Api services using IBM Datapower
PPTX
System Center 2012 for VMware Infrastructure
WAF CC Introduction
Virutalization and the Future of Datacenter Security
Vmware training presentation
What’s new in vSphere 5 and vCenter Server Heartbeat – Customer Presentation
Kona Web Application Firewall Product Brief - Application-layer defense to pr...
Web Api services using IBM Datapower
System Center 2012 for VMware Infrastructure

What's hot (20)

PDF
Spirent CloudStress - One click cloud validation
PDF
Intorduction to Datapower
PPS
Safe checkup - vmWare vSphere 5.0 22feb2012
PPTX
Cloud Computing
PPTX
Cloud Management With System Center Application Controller ver1
PPTX
Cloud Management Gateway Architecture (CMG) – Modern device management
PDF
Automated Deployment of Unix / Linux Systems using SOVM - Technical Overview
PPTX
Session 3c The SF SaaS Framework
PDF
Barracuda web application_firewall_wp_advantage
PPTX
Application Virtualization overview - BayCUG
PPT
DC Metro And Federal VMUG March 2009
PPTX
E2EVC SCVMM-Mania
PPTX
Mule management console
PPT
Branch Office Solution Son Vu
PDF
Mfp80 certificate pinning
PDF
Beginning Microservices with .NET & RabbitMQ
PDF
Evento Veeam & Assyrus - 6 Pianificare lato sorgente
PPTX
Virtualization: Security and IT Audit Perspectives
PDF
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
PDF
Zerto - Software Defined Disaster Recovery
Spirent CloudStress - One click cloud validation
Intorduction to Datapower
Safe checkup - vmWare vSphere 5.0 22feb2012
Cloud Computing
Cloud Management With System Center Application Controller ver1
Cloud Management Gateway Architecture (CMG) – Modern device management
Automated Deployment of Unix / Linux Systems using SOVM - Technical Overview
Session 3c The SF SaaS Framework
Barracuda web application_firewall_wp_advantage
Application Virtualization overview - BayCUG
DC Metro And Federal VMUG March 2009
E2EVC SCVMM-Mania
Mule management console
Branch Office Solution Son Vu
Mfp80 certificate pinning
Beginning Microservices with .NET & RabbitMQ
Evento Veeam & Assyrus - 6 Pianificare lato sorgente
Virtualization: Security and IT Audit Perspectives
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
Zerto - Software Defined Disaster Recovery
Ad

Similar to VMworld 2013: Changing the Economics of Firewall Services in the Software-Defined Center – VMware NSX Distributed Firewall (20)

PDF
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
PDF
VMware NSX for vSphere - Intro and use cases
PPTX
nsx overview with use cases 1.0
PPTX
VMware vShield - Overview
PPTX
Securing virtual workload and cloud
PPT
Why Security Teams should care about VMware
PDF
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
PPTX
Software defined security-framework_final
PPTX
New Threats, New Approaches in Modern Data Centers
PPTX
VMware-vShield-Presentation-pp-en-Dec10.pptx
PDF
NSX on VMware Data Center
PPTX
VMware overview presentation by alamgir hossain
PPTX
Integration of pola alto and v mware nsx to protect virtual and cloud environ...
PDF
25 years of firewalls and network filtering - From antiquity to the cloud
PDF
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
PDF
VMworld 2013: Datacenter Transformation with Network Virtualization: Today an...
PDF
VMworld 2015: The Future of Network Virtualization with VMware NSX
PDF
Alternatives for-securing-virtual-networks
PDF
Vss Security And Compliance For The Cloud
PDF
Vmware Seminar Security & Compliance for the cloud with Trend Micro
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
VMware NSX for vSphere - Intro and use cases
nsx overview with use cases 1.0
VMware vShield - Overview
Securing virtual workload and cloud
Why Security Teams should care about VMware
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
Software defined security-framework_final
New Threats, New Approaches in Modern Data Centers
VMware-vShield-Presentation-pp-en-Dec10.pptx
NSX on VMware Data Center
VMware overview presentation by alamgir hossain
Integration of pola alto and v mware nsx to protect virtual and cloud environ...
25 years of firewalls and network filtering - From antiquity to the cloud
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
VMworld 2013: Datacenter Transformation with Network Virtualization: Today an...
VMworld 2015: The Future of Network Virtualization with VMware NSX
Alternatives for-securing-virtual-networks
Vss Security And Compliance For The Cloud
Vmware Seminar Security & Compliance for the cloud with Trend Micro
Ad

More from VMworld (20)

PPTX
VMworld 2016: vSphere 6.x Host Resource Deep Dive
PPTX
VMworld 2016: Troubleshooting 101 for Horizon
PPTX
VMworld 2016: Advanced Network Services with NSX
PPTX
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
PPTX
VMworld 2016: Enforcing a vSphere Cluster Design with PowerCLI Automation
PPTX
VMworld 2016: What's New with Horizon 7
PPTX
VMworld 2016: Virtual Volumes Technical Deep Dive
PPTX
VMworld 2016: Advances in Remote Display Protocol Technology with VMware Blas...
PPTX
VMworld 2016: The KISS of vRealize Operations!
PPTX
VMworld 2016: Getting Started with PowerShell and PowerCLI for Your VMware En...
PPTX
VMworld 2016: Ask the vCenter Server Exerts Panel
PPTX
VMworld 2016: Virtualize Active Directory, the Right Way!
PPTX
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
PPTX
VMworld 2015: Troubleshooting for vSphere 6
PPTX
VMworld 2015: Monitoring and Managing Applications with vRealize Operations 6...
PPTX
VMworld 2015: Advanced SQL Server on vSphere
PPTX
VMworld 2015: Virtualize Active Directory, the Right Way!
PPTX
VMworld 2015: Site Recovery Manager and Policy Based DR Deep Dive with Engine...
PPTX
VMworld 2015: Building a Business Case for Virtual SAN
PPTX
VMworld 2015: Explaining Advanced Virtual Volumes Configurations
VMworld 2016: vSphere 6.x Host Resource Deep Dive
VMworld 2016: Troubleshooting 101 for Horizon
VMworld 2016: Advanced Network Services with NSX
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
VMworld 2016: Enforcing a vSphere Cluster Design with PowerCLI Automation
VMworld 2016: What's New with Horizon 7
VMworld 2016: Virtual Volumes Technical Deep Dive
VMworld 2016: Advances in Remote Display Protocol Technology with VMware Blas...
VMworld 2016: The KISS of vRealize Operations!
VMworld 2016: Getting Started with PowerShell and PowerCLI for Your VMware En...
VMworld 2016: Ask the vCenter Server Exerts Panel
VMworld 2016: Virtualize Active Directory, the Right Way!
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
VMworld 2015: Troubleshooting for vSphere 6
VMworld 2015: Monitoring and Managing Applications with vRealize Operations 6...
VMworld 2015: Advanced SQL Server on vSphere
VMworld 2015: Virtualize Active Directory, the Right Way!
VMworld 2015: Site Recovery Manager and Policy Based DR Deep Dive with Engine...
VMworld 2015: Building a Business Case for Virtual SAN
VMworld 2015: Explaining Advanced Virtual Volumes Configurations

Recently uploaded (20)

PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
cuic standard and advanced reporting.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
KodekX | Application Modernization Development
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
A Presentation on Artificial Intelligence
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Unlocking AI with Model Context Protocol (MCP)
cuic standard and advanced reporting.pdf
Empathic Computing: Creating Shared Understanding
KodekX | Application Modernization Development
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Advanced methodologies resolving dimensionality complications for autism neur...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
NewMind AI Weekly Chronicles - August'25 Week I
20250228 LYD VKU AI Blended-Learning.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
A Presentation on Artificial Intelligence
Digital-Transformation-Roadmap-for-Companies.pptx
Spectral efficient network and resource selection model in 5G networks
The AUB Centre for AI in Media Proposal.docx
Diabetes mellitus diagnosis method based random forest with bat algorithm

VMworld 2013: Changing the Economics of Firewall Services in the Software-Defined Center – VMware NSX Distributed Firewall

  • 1. Changing the Economics of Firewall Services in the Software-Defined Center – VMware NSX Distributed Firewall Srinivas Nimmagadda, VMware Anirban Sengupta, VMware SEC5893 #SEC5893
  • 3. 3 Data Center Firewall Architecture Aggregation Layer Campus Core Core Layer Access Layer
  • 4. 4 Application Profiles Changing… Campus Core Client – Server & Web 1.0 Server 3-Tier Apps Web App DB Web 2.0, Portals, Enterprise Apps
  • 5. 5 Virtualization - Changing Dynamics Campus Core VM – VM traffic doesn’t hit network IP Address Based Rule Sets Scalability Issues Complex Firewall Rule Tables Firewall – “Choke Point”
  • 6. 6 Firewall as a VM IP Address Based Rule Sets Server Consolidation Issues Virtual Appliance Issues VM Firewall – Still a bottleneck vMotion & App Placement Issues
  • 7. 7 Wouldn’t It Be Great If My Firewall…  Removes the need to hair-pin traffic  Enables Rules based on VM attributes  Provides High Performance & Scale  API based Programmability
  • 8. 8 Distributed Virtual Firewall VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM Focus • Custom built for Virtual Data Centers • Distributed Enforcement • Centralized Management • Performance & Scale
  • 9. 9 DVFW – Hypervisor Embedded Firewall ESXi VM VM FW Benefits… • Is built right in to the Hypervisor and is lightening fast • “Line Rate” Performance (10Gbps+ per host) • No VM can circumvent Firewall ESXi VM VM VM ESXi VM VM FW VM
  • 10. 10 DVFW – Scale Out Architecture ESXi VM VM FW Benefits… • Scales with additional “Hosts” • No “Fork Lift” upgrade to get better scale ESXi VM VM FW ESXi VM VM FW
  • 11. 11 DVFW – Flexible Access Control Mechanisms Benefits… • Security Groups: Logical grouping of VMs • VM Tags: Dynamic VM attributes • User Identity: Identity based firewall • IP/VLAN: Support physical infrastructure based rules • Rules follow the VMs ESXi Web App FW DB ESXi Web App FW DB ESXi Web App FW DB
  • 12. 12 Identity & Application Visibility Active Directory Eric Frost User AD Group App Name Originating VM Name Destination VM Name Source IP Destination IP Eric Engineering SPDesigner.exe Eric-Win7 Ent-Sharepoint 192.168.10.75 192.168.10.78 ESXi FW
  • 13. 13 DVFW – Centralized Management ESXi VM VM VM ESXi VM VM VM Reuse vCenter Objects Single Rule Table Role Based (RBAC) Control Full REST API Familiar “Apply To” Model Central Monitoring
  • 16. 16 Vulnerability Scan + Firewall Use Case Security Architect Deny outbound traffic from “Quarantine” VMs Vulnerability Scanner Identifies serious vulnerabilities in APP-VM-6 and tags the VM as “Quarantine” system Firewall Blocks outbound traffic from APP-VM-6 Security Operations Patches the OS/Application to address vulnerability Vulnerability Scanner APP-VM-6 is no longer a “Quarantine” machine Firewall Outbound traffic from APP-VM-6 permitted
  • 17. 17 IPS Use Case Hypervisor VM DFW VM VM IPS VMware DVFW High Throughput User, VM Segmentation Selective IPS Forward IPS Signature Based IPS + Malware/APT
  • 19. 19 Themes Security • VM Attribute Based • User Identity • VM Appliance Agility • vCenter Integration • REST API • vMotion Integration with existing Host & Network Security solutions Perf & Scale Better Consolidation Compliance (PCI)
  • 20. 20 Deployment  Edge Firewall & Distributed Firewall  Firewall Monitoring & Troubleshooting  RBAC and Admin Separation  Auditing & Compliance
  • 21. 21 N-S Firewall, E-W Router / Firewall Logical Topology Distributed Router & Firewall VXLAN Transit/Uplink Network ……….. VLAN last mile FW HA Pair (High Throughput & CPS) LB, DHCP (One-arm) NET 1 NET 2 NET 3 WebFrontEnds AppTier DatabaseBackends 3-tier App OSPF Physical Routing Edge Physical Network Fabric Network Virtualization iBGP NAT, FW, VPN, LB High Port Density Router & Firewall NET 1000
  • 22. 22 WAN / INTERNET / Corp backbone Model for Routing & L4-L7 Services FW/Routing - Phy. Or Virtual Appiance Features: NAT, Perimeter Firewall, SSLVPN, IPsec VPN, GSLB, DNS Routing L2 Bridge Distributed Routing One-armed LB Features: Server Loadbalancing, DHCP, L2VPN Features: Distributed ACLs in OVS, anti-spoof control Logical L2
  • 23. 23 Other VMware Activities Related to This Session  HOL: HOL-SDC-1303 VMware NSX Network Virtualization Platform  Group Discussions: SEC1000-GD Distributed Virtual Firewall - Management, Architecture, Scalability and Performance with Serge Maskalik
  • 26. Changing the Economics of Firewall Services in the Software-Defined Center – VMware NSX Distributed Firewall Srinivas Nimmagadda, VMware Anirban Sengupta, VMware SEC5893 #SEC5893