SlideShare a Scribd company logo
2
Most read
7
Most read
10
Most read
Confidential │ ©2019 VMware, Inc.
Webinar
Ashwin Manekar
Product Line Manager, NSBU, VMware
September 26th 2019
What’s New with
VMware NSX Advanced
Load Balancer (Avi
Networks)
Confidential │ ©2019 VMware, Inc. 2
The Foundation of the Virtual Cloud Network
VMware NSX Portfolio
NETWORK AND SECURITY VIRTUALIZATION
Security Integration Extensibility Automation Elasticity
NSX Data Center NSX Cloud AppDefense SD-WAN by VeloCloud HCX
NSX Service Mesh NSX Advanced Load Balancer
Avi Networks, now part of VMware
• Industry’s only complete L2-L7 software-defined stack
• A leader in the ADC market with multi-cloud LB, WAF and
analytics
Confidential │ ©2019 VMware, Inc. 3
VMware NSX Advanced Load Balancer Portfolio
VMware NSX
Integration+Standalone
Multi-cloud
LB & WAF
NSX Data Center NSX Cloud NSX Service
Mesh
VMware Cloud on AWS (VMC)
VMware Horizon & UAG
4Confidential │ ©2019 VMware, Inc.
Avi Networks Product Overview
Confidential │ ©2019 VMware, Inc. 5
Load Balancing is the Blocker for Digital Transformation
Drivers
Increased
IT Demands
ON-
PREMISES
Load Balancing is Not
Automated
Network
StorageCompute
CLOUD
Challenges
Scalability
Agility
Flexibility
# Apps
# Changes
#
Env/Infra
Cost
Efficiency
$
Time to
Market
Modern
Apps
Load
Balancers
?
Confidential │ ©2019 VMware, Inc. 6
Hardware / Virtual Load Balancer Challenges
DC1 DC2
DEPT1 DEPT2
Standby
0%
Active
15%
Separate control points – operational complexity, hard to automate, painful upgrades
Capacity management – manual VIP placement, costly overprovisioning, no capacity pooling
Not designed for modern new environments
ON-PREMISES CLOUD CONTAINER
Confidential │ ©2019 VMware, Inc. 7
BARE METAL VIRTUALIZED CONTAINERSON PREMISES PUBLIC CLOUDVIRTUALIZED CONTAINERS
Modern, Scalable, Multi-Cloud Architecture
CONTROLLER
SERVICE
ENGINE
SEPARATE CONTROL
& DATA PLANE
ELASTICITY
INTELLIGENCE AUTOMATIONMULTI-CLOUD
Confidential │ ©2019 VMware, Inc. 8
Comprehensive Application Services Platform
• Web App Firewall
• SSL Termination
• DDoS Protection
• L3-4 ACLs
• L7 Rules/Policies
• Rate Limiting
SECURITY
• Application Map
• Service Health Score
• Network Performance
• App Performance
• Request Logging
• Security Insights
ANALYTICS
• Central Management
• 100% REST API / SDK
• Self-Service
• Multi-Tenancy
• Service Discovery
• IPAM/DNS
PLATFORM
• L7 (HTTP) LB
• L4 (TCP/UDP) LB
• Global Load Balancing
• Content Switching
• Caching/Compression
• Autoscaling
LOAD BALANCING
Features
(K8S, OpenShift, PKS, AKS, GKE,
EKS, ...)
Enterprise-grade Ingress
• Converged LB, Security, Analytics
• Service Discovery & App Map
• Multi-cluster and Multi-cloud
Containers
Use
Cases
(ESXi, x86, NSX, ACI, OpenStack…)
• Central Management
• Real-time Analytics
• SDN Integration and Automation
• Cost Savings
SDDC / On-Prem
(AWS, Azure, GCP, VMC, …)
• Cloud-native Automation
• Enterprise-grade Features
• Real-time Analytics
• Multi-cloud Consistency
Public Cloud
9Confidential │ ©2019 VMware, Inc.
What’s new in 18.2.6
- Positive Security Model
- Learning Mode for WAF
Confidential │ ©2019 VMware, Inc. 10
Comprehensive Security Stack
NSX Advanced Load Balancer
Encryption
SSL/TLS
L3/4 Firewall Rules
IP-Port based Security Rules
L7 Firewall Rules
Content (URI) based security rules
DDoS Protection
DDoS detection and mitigation with elastic scaling
Application Rate Limiting
Control and restrict by application or tenants
Security
Insights
Security score
Attack insights
SSL Insights
WAF analytics
Web Application Firewall
OWASP TOP 10, Application protection, Attack Analytics
Centralized Management
Multi-Cloud Elastic Fabric
Automation & Programmability
Real Time Visibility & Analytics
REST API
Data Center Private Cloud Public Cloud
Confidential │ ©2019 VMware, Inc.
iWAF policy checks
Whitelist
• High performance for trusted traffic
• Match Criteria: Headers, IP, Path and more
• Similar to HTTP policy matching
PSM
• Positive definition of Application behavior
• Zero-day attacks defense and performance
• Rules: Learning, Scanners, Manual
Signatures
• Scans for common attack patterns
• Rules: OWASP Top 10 protection rules
Confidential │ ©2019 VMware, Inc. 12
How does Positive Security Model work?
FastPas
s
Deep Inspection
Negative Security
Deny
Allow
Traffic
ML Classifier
Automating Application Security using Machine Learning
Confidential │ ©2019 VMware, Inc. 13
Avi’s WAF Capabilities
Application defense in depth
• Application Learning and Positive Security
• OWASP Top 10 Protection
• Signatures and app-specific rules
• HTTP protocol enforcement and input
Validation – XSS, SQLi, etc.
• Virtual patching using scripting for
application logic flaws
• API protection for JSON, XML
• Metrics and statistics about the current
application attack surface
• Bot detection
Backend
Application
Untrusted Trusted
WAN
14Confidential │ ©2019 VMware, Inc.
What’s new in 18.2.6
- Support for modern encryption – TLS
1.3
Confidential │ ©2019 VMware, Inc. 15
NSX Advanced LB supports versions SSLv3, TLS
1.0
Starting 18.2.6, TLSv1.3 protocol is supported.
Ciphersuites: Users must select one or more of
the three supported TLSv1.3 ciphers in the list of
ciphers
Enable Early Data:
- Enables TLS terminated applications to send
application data without having to first wait for the
TLS handshake to complete
- Saves one full round trip time between the client
and server before the client requests can be
processed
Terminate SSL connections between the client and the virtual service
Enable encryption between NSX Advanced LB and the back-end servers
SSL/TLS Profile
16Confidential │ ©2019 VMware, Inc.
What’s new in 18.2.6
- Flexible Upgrade
Confidential │ ©2019 VMware, Inc. 17
Current Challenges
Everybody needs to get onto the bus!
Upgrade ALL
Validate ALL
Rollback ALL
Need to boil the ocean
for a simple fix for a
single application
Nightmare to coordinate
and cancellation is
common
All or Nothing
No Targeted
Upgrades
Approval
& Scheduling
Confidential │ ©2019 VMware, Inc. 18
Segmentation
Per-tenant
Per-app
Per-SE group
Smaller scale & isolated impact
Faster resolution or rollback
Modern approach to upgrade
Need an ability to upgrade LB infrastructure in an isolated manner
Granular Upgrades Selective Upgrades Simplified Upgrades
Unable to deliver flexible upgrades with legacy appliances
Either ALL or NOTHING!!
Confidential │ ©2019 VMware, Inc. 19
Separated control plane upgrades from data plane upgrades
Upgrade Control Plane independent from Data Plane
Patch the controller without impacting the data plane
Non-disruptive, headless operations, no failover needed
Allow selective upgrades to the desired assets only
Upgrade individual SE Groups (segmentation)
Push specific features to only the selected SEs associated with that apps
Simpler verification, Faster rollback
Failure impact is on a smaller scale, Faster to resolve and Faster rollback
Delivers higher high time to value to the end users
Flexible Upgrades
Confidential │ ©2019 VMware, Inc. 20
How can you use Flexible Upgrades?
Se group X Se group Y
Se group Z
Tenant 1 Tenant 2
V 1
V 1 V 1
V 1
V 2
V 2
V 2
• Sandbox Upgrades
– Upgrade an Se group, validate prior to upgrade remaining
• Introduce new features or patches only for the Apps that need
them
– Meet application demands without impact to others
• Canary Upgrades
– Continue/rollback upgrades based upon analytics engine data
• Flexible Upgrade scheduling
• Self Service Upgrades
• Sandbox Upgrades
– Upgrade an Se group, validate prior to upgrade remaining
• Introduce new features or patches only for the Apps that
need them
– Meet application demands without impact to others
• Canary Upgrades
– Continue/rollback upgrades based upon analytics engine data
• Flexible Upgrade scheduling
• Self Service Upgrades
• Sandbox Upgrades
– Upgrade an Se group, validate prior to upgrade remaining
• Introduce new features or patches only for the Apps that need
them
– Meet application demands without impact to others
• Canary Upgrades
– Continue/rollback upgrades based upon analytics engine data
• Flexible Upgrade scheduling
• Self Service Upgrades
Confidential │ ©2019 VMware, Inc.
Thank You
Confidential │ ©2019 VMware, Inc.
Thank You

More Related Content

PDF
CloudFrontで実現するセキュアコンテンツ配信と効果のトラッキング
PDF
[Final] best practices for access management (mule soft meetups riyadh) - j...
PDF
PPTX
DevOps seminar ppt
PDF
AWSではじめるDNSSEC
PDF
Azure DevOps - Azure Guatemala Meetup
PDF
GDG Cloud Southlake #8 Steve Cravens: Infrastructure as-Code (IaC) in 2022: ...
PPTX
VMware vSphere 6.0 - Troubleshooting Training - Day 2
CloudFrontで実現するセキュアコンテンツ配信と効果のトラッキング
[Final] best practices for access management (mule soft meetups riyadh) - j...
DevOps seminar ppt
AWSではじめるDNSSEC
Azure DevOps - Azure Guatemala Meetup
GDG Cloud Southlake #8 Steve Cravens: Infrastructure as-Code (IaC) in 2022: ...
VMware vSphere 6.0 - Troubleshooting Training - Day 2

What's hot (20)

PPTX
コンテナ/マイクロサービス/サーバーレスのセキュリティと監査
PPTX
Infrastructure as Code
PDF
An Introduction to VMware NSX
PPTX
Logging best practice in mule using logger component
PDF
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
PPTX
FIWARE Context Information Management
PPT
Bringing up Aruba Mobility Master, Managed Device & Access Point
PDF
Understanding SASE
PDF
Docker (Compose) 활용 - 개발 환경 구성하기
PPTX
VMware ESXi 6.0 Installation Process
PDF
Kubernetes Networking | Kubernetes Services, Pods & Ingress Networks | Kubern...
PDF
IoT におけるセキュリティ
PPTX
Policy as Code: IT Governance With HashiCorp Sentinel
PPTX
Introduction of OpenStack cascading solution
PPTX
Container Orchestration
PDF
Aks pimarox from zero to hero
PDF
NGINX Ingress Controller for Kubernetes
PDF
20210526 AWS Expert Online マルチアカウント管理の基本
PPTX
cloud_foundation_on_vxrail_vcf_pnp_licensing_guide.pptx
PPTX
AWS Amplify 入門
コンテナ/マイクロサービス/サーバーレスのセキュリティと監査
Infrastructure as Code
An Introduction to VMware NSX
Logging best practice in mule using logger component
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
FIWARE Context Information Management
Bringing up Aruba Mobility Master, Managed Device & Access Point
Understanding SASE
Docker (Compose) 활용 - 개발 환경 구성하기
VMware ESXi 6.0 Installation Process
Kubernetes Networking | Kubernetes Services, Pods & Ingress Networks | Kubern...
IoT におけるセキュリティ
Policy as Code: IT Governance With HashiCorp Sentinel
Introduction of OpenStack cascading solution
Container Orchestration
Aks pimarox from zero to hero
NGINX Ingress Controller for Kubernetes
20210526 AWS Expert Online マルチアカウント管理の基本
cloud_foundation_on_vxrail_vcf_pnp_licensing_guide.pptx
AWS Amplify 入門
Ad

Similar to What's New VMware NSX Advanced Load Balancer (Avi Networks) (20)

PPTX
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
PPTX
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
PDF
Deploying Elastic Self-Service Load Balancing
PPTX
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
PPTX
How Multi-Cloud Load Balancing Automates Application Delivery and Drives Oper...
PDF
VMworld 2014: Introduction to NSX
PPTX
Deploying Elastic, Self-Service Load Balancing for VMware NSX-T
PPTX
Avi v20.1 — What’s New in Scalable, Multi-Cloud Load Balancing
PDF
vRA + NSX Technical Deep-Dive
PDF
vmware-need-to-migrate-thousands-of-workloads-no-problem.pdf
PDF
Business Agility and Security with VMware
PPSX
NetScaler 11 Update
PPTX
Cloud_controllers_public_webinar_aug31_v1.pptx
PPTX
Self service it with v realizeautomation and nsx
PPTX
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
PPTX
VMworld 2015: What's New in vSphere?
PDF
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
PDF
Cozystack: Free PaaS platform and framework for building clouds
PPTX
20151019 v mworld2015-recap-02
PPTX
VMworld 2016 Recap
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
Deploying Elastic Self-Service Load Balancing
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
How Multi-Cloud Load Balancing Automates Application Delivery and Drives Oper...
VMworld 2014: Introduction to NSX
Deploying Elastic, Self-Service Load Balancing for VMware NSX-T
Avi v20.1 — What’s New in Scalable, Multi-Cloud Load Balancing
vRA + NSX Technical Deep-Dive
vmware-need-to-migrate-thousands-of-workloads-no-problem.pdf
Business Agility and Security with VMware
NetScaler 11 Update
Cloud_controllers_public_webinar_aug31_v1.pptx
Self service it with v realizeautomation and nsx
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
VMworld 2015: What's New in vSphere?
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
Cozystack: Free PaaS platform and framework for building clouds
20151019 v mworld2015-recap-02
VMworld 2016 Recap
Ad

More from Avi Networks (20)

PPTX
DR On Demand At Fraction of the Cost (1).pptx
PPTX
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
PPTX
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
PPTX
One And Done Multi-Cloud Load Balancing Done Right.pptx
PPTX
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
PPTX
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
PDF
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
PPTX
Avi workshop-101
PDF
Working From Anywhere​ with​ Advanced Load Balancing​ and ​ VMware Horizon VDI
PPTX
Enterprise-Grade Load Balancing for VMware Cloud on AWS (VMC)
PPTX
Multi Cloud Load Balancing 101 and Hands On Lab
PPTX
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
PPTX
Multi Cloud Load balancing 101 and Hands-on Lab
PPTX
Multi-Cloud Load Balancing 101 and Hands-On Lab
PPTX
Enabling Remote Employees with Horizon VDI and Avi Networks
PPTX
Multi-Cloud Load Balancing – Separating Fact from Fiction
PPTX
Advanced Web Application Security with an Intelligent WAF
PPTX
State of Load Balancing 2020
PPTX
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
PPTX
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
DR On Demand At Fraction of the Cost (1).pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptx
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
Avi workshop-101
Working From Anywhere​ with​ Advanced Load Balancing​ and ​ VMware Horizon VDI
Enterprise-Grade Load Balancing for VMware Cloud on AWS (VMC)
Multi Cloud Load Balancing 101 and Hands On Lab
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
Multi Cloud Load balancing 101 and Hands-on Lab
Multi-Cloud Load Balancing 101 and Hands-On Lab
Enabling Remote Employees with Horizon VDI and Avi Networks
Multi-Cloud Load Balancing – Separating Fact from Fiction
Advanced Web Application Security with an Intelligent WAF
State of Load Balancing 2020
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World

Recently uploaded (20)

PDF
cuic standard and advanced reporting.pdf
PPTX
Cloud computing and distributed systems.
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Electronic commerce courselecture one. Pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPT
Teaching material agriculture food technology
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Encapsulation theory and applications.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
cuic standard and advanced reporting.pdf
Cloud computing and distributed systems.
Network Security Unit 5.pdf for BCA BBA.
Building Integrated photovoltaic BIPV_UPV.pdf
Spectral efficient network and resource selection model in 5G networks
Mobile App Security Testing_ A Comprehensive Guide.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Chapter 3 Spatial Domain Image Processing.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
The AUB Centre for AI in Media Proposal.docx
20250228 LYD VKU AI Blended-Learning.pptx
Electronic commerce courselecture one. Pdf
MYSQL Presentation for SQL database connectivity
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Teaching material agriculture food technology
Reach Out and Touch Someone: Haptics and Empathic Computing
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Encapsulation theory and applications.pdf
Per capita expenditure prediction using model stacking based on satellite ima...

What's New VMware NSX Advanced Load Balancer (Avi Networks)

  • 1. Confidential │ ©2019 VMware, Inc. Webinar Ashwin Manekar Product Line Manager, NSBU, VMware September 26th 2019 What’s New with VMware NSX Advanced Load Balancer (Avi Networks)
  • 2. Confidential │ ©2019 VMware, Inc. 2 The Foundation of the Virtual Cloud Network VMware NSX Portfolio NETWORK AND SECURITY VIRTUALIZATION Security Integration Extensibility Automation Elasticity NSX Data Center NSX Cloud AppDefense SD-WAN by VeloCloud HCX NSX Service Mesh NSX Advanced Load Balancer Avi Networks, now part of VMware • Industry’s only complete L2-L7 software-defined stack • A leader in the ADC market with multi-cloud LB, WAF and analytics
  • 3. Confidential │ ©2019 VMware, Inc. 3 VMware NSX Advanced Load Balancer Portfolio VMware NSX Integration+Standalone Multi-cloud LB & WAF NSX Data Center NSX Cloud NSX Service Mesh VMware Cloud on AWS (VMC) VMware Horizon & UAG
  • 4. 4Confidential │ ©2019 VMware, Inc. Avi Networks Product Overview
  • 5. Confidential │ ©2019 VMware, Inc. 5 Load Balancing is the Blocker for Digital Transformation Drivers Increased IT Demands ON- PREMISES Load Balancing is Not Automated Network StorageCompute CLOUD Challenges Scalability Agility Flexibility # Apps # Changes # Env/Infra Cost Efficiency $ Time to Market Modern Apps Load Balancers ?
  • 6. Confidential │ ©2019 VMware, Inc. 6 Hardware / Virtual Load Balancer Challenges DC1 DC2 DEPT1 DEPT2 Standby 0% Active 15% Separate control points – operational complexity, hard to automate, painful upgrades Capacity management – manual VIP placement, costly overprovisioning, no capacity pooling Not designed for modern new environments ON-PREMISES CLOUD CONTAINER
  • 7. Confidential │ ©2019 VMware, Inc. 7 BARE METAL VIRTUALIZED CONTAINERSON PREMISES PUBLIC CLOUDVIRTUALIZED CONTAINERS Modern, Scalable, Multi-Cloud Architecture CONTROLLER SERVICE ENGINE SEPARATE CONTROL & DATA PLANE ELASTICITY INTELLIGENCE AUTOMATIONMULTI-CLOUD
  • 8. Confidential │ ©2019 VMware, Inc. 8 Comprehensive Application Services Platform • Web App Firewall • SSL Termination • DDoS Protection • L3-4 ACLs • L7 Rules/Policies • Rate Limiting SECURITY • Application Map • Service Health Score • Network Performance • App Performance • Request Logging • Security Insights ANALYTICS • Central Management • 100% REST API / SDK • Self-Service • Multi-Tenancy • Service Discovery • IPAM/DNS PLATFORM • L7 (HTTP) LB • L4 (TCP/UDP) LB • Global Load Balancing • Content Switching • Caching/Compression • Autoscaling LOAD BALANCING Features (K8S, OpenShift, PKS, AKS, GKE, EKS, ...) Enterprise-grade Ingress • Converged LB, Security, Analytics • Service Discovery & App Map • Multi-cluster and Multi-cloud Containers Use Cases (ESXi, x86, NSX, ACI, OpenStack…) • Central Management • Real-time Analytics • SDN Integration and Automation • Cost Savings SDDC / On-Prem (AWS, Azure, GCP, VMC, …) • Cloud-native Automation • Enterprise-grade Features • Real-time Analytics • Multi-cloud Consistency Public Cloud
  • 9. 9Confidential │ ©2019 VMware, Inc. What’s new in 18.2.6 - Positive Security Model - Learning Mode for WAF
  • 10. Confidential │ ©2019 VMware, Inc. 10 Comprehensive Security Stack NSX Advanced Load Balancer Encryption SSL/TLS L3/4 Firewall Rules IP-Port based Security Rules L7 Firewall Rules Content (URI) based security rules DDoS Protection DDoS detection and mitigation with elastic scaling Application Rate Limiting Control and restrict by application or tenants Security Insights Security score Attack insights SSL Insights WAF analytics Web Application Firewall OWASP TOP 10, Application protection, Attack Analytics Centralized Management Multi-Cloud Elastic Fabric Automation & Programmability Real Time Visibility & Analytics REST API Data Center Private Cloud Public Cloud
  • 11. Confidential │ ©2019 VMware, Inc. iWAF policy checks Whitelist • High performance for trusted traffic • Match Criteria: Headers, IP, Path and more • Similar to HTTP policy matching PSM • Positive definition of Application behavior • Zero-day attacks defense and performance • Rules: Learning, Scanners, Manual Signatures • Scans for common attack patterns • Rules: OWASP Top 10 protection rules
  • 12. Confidential │ ©2019 VMware, Inc. 12 How does Positive Security Model work? FastPas s Deep Inspection Negative Security Deny Allow Traffic ML Classifier Automating Application Security using Machine Learning
  • 13. Confidential │ ©2019 VMware, Inc. 13 Avi’s WAF Capabilities Application defense in depth • Application Learning and Positive Security • OWASP Top 10 Protection • Signatures and app-specific rules • HTTP protocol enforcement and input Validation – XSS, SQLi, etc. • Virtual patching using scripting for application logic flaws • API protection for JSON, XML • Metrics and statistics about the current application attack surface • Bot detection Backend Application Untrusted Trusted WAN
  • 14. 14Confidential │ ©2019 VMware, Inc. What’s new in 18.2.6 - Support for modern encryption – TLS 1.3
  • 15. Confidential │ ©2019 VMware, Inc. 15 NSX Advanced LB supports versions SSLv3, TLS 1.0 Starting 18.2.6, TLSv1.3 protocol is supported. Ciphersuites: Users must select one or more of the three supported TLSv1.3 ciphers in the list of ciphers Enable Early Data: - Enables TLS terminated applications to send application data without having to first wait for the TLS handshake to complete - Saves one full round trip time between the client and server before the client requests can be processed Terminate SSL connections between the client and the virtual service Enable encryption between NSX Advanced LB and the back-end servers SSL/TLS Profile
  • 16. 16Confidential │ ©2019 VMware, Inc. What’s new in 18.2.6 - Flexible Upgrade
  • 17. Confidential │ ©2019 VMware, Inc. 17 Current Challenges Everybody needs to get onto the bus! Upgrade ALL Validate ALL Rollback ALL Need to boil the ocean for a simple fix for a single application Nightmare to coordinate and cancellation is common All or Nothing No Targeted Upgrades Approval & Scheduling
  • 18. Confidential │ ©2019 VMware, Inc. 18 Segmentation Per-tenant Per-app Per-SE group Smaller scale & isolated impact Faster resolution or rollback Modern approach to upgrade Need an ability to upgrade LB infrastructure in an isolated manner Granular Upgrades Selective Upgrades Simplified Upgrades Unable to deliver flexible upgrades with legacy appliances Either ALL or NOTHING!!
  • 19. Confidential │ ©2019 VMware, Inc. 19 Separated control plane upgrades from data plane upgrades Upgrade Control Plane independent from Data Plane Patch the controller without impacting the data plane Non-disruptive, headless operations, no failover needed Allow selective upgrades to the desired assets only Upgrade individual SE Groups (segmentation) Push specific features to only the selected SEs associated with that apps Simpler verification, Faster rollback Failure impact is on a smaller scale, Faster to resolve and Faster rollback Delivers higher high time to value to the end users Flexible Upgrades
  • 20. Confidential │ ©2019 VMware, Inc. 20 How can you use Flexible Upgrades? Se group X Se group Y Se group Z Tenant 1 Tenant 2 V 1 V 1 V 1 V 1 V 2 V 2 V 2 • Sandbox Upgrades – Upgrade an Se group, validate prior to upgrade remaining • Introduce new features or patches only for the Apps that need them – Meet application demands without impact to others • Canary Upgrades – Continue/rollback upgrades based upon analytics engine data • Flexible Upgrade scheduling • Self Service Upgrades • Sandbox Upgrades – Upgrade an Se group, validate prior to upgrade remaining • Introduce new features or patches only for the Apps that need them – Meet application demands without impact to others • Canary Upgrades – Continue/rollback upgrades based upon analytics engine data • Flexible Upgrade scheduling • Self Service Upgrades • Sandbox Upgrades – Upgrade an Se group, validate prior to upgrade remaining • Introduce new features or patches only for the Apps that need them – Meet application demands without impact to others • Canary Upgrades – Continue/rollback upgrades based upon analytics engine data • Flexible Upgrade scheduling • Self Service Upgrades
  • 21. Confidential │ ©2019 VMware, Inc. Thank You
  • 22. Confidential │ ©2019 VMware, Inc. Thank You