SlideShare a Scribd company logo
NSX for vSphere, intro and use cases 
Oct 2014 
Ángel Villar Garea 
avillargarea@vmware.com 
@AVillarGarea
DISCLAIMER 
2 
This is NOT VMware’s official documentation. 
It is just my understanding of technology and products. Any inaccuracy or error you may 
find it is only my responsibility and not VMware’s.
3 
The biggest industry transformation since 
mainframe to client server computing?
What customers demand 
Business/IT Execs 
Speed and Agility 
Secure Infrastructure 
Time-to-Market 
Competitive Advantage 
4 
IT Operations 
Efficiency of change 
IT Infrastructure & Security 
Data Center Micro-segmentation 
Scale-out DMZ 
Network hardware choice 
Compute capacity utilization
The Software Defined Data Center (SDDC) 
Intelligence in Software 
Operational Model of VM for Data Center 
Automated Configuration & Management 
Software 
Data Center Virtualization Layer 
Hardware Compute, Network and Storage Capacity 
Pooled, Vendor Independent, Best Price/Performance Infrastructure 
Simplified Configuration & Management 
5
The Network Is a Barrier to Software Defined Data Center!! 
Compute Virtualization Abstraction Layer 
Physical 
Infrastructure 
Software Defined Data Center 
• Provisioning is slow 
• Placement is limited 
• Mobility is limited 
• Hardware dependent 
• Operationally intensive 
6
Physical 
Infrastructure 
• Provisioning is slow 
• Placement is limited 
• Mobility is limited 
• Hardware dependent 
• Operationally intensive 
Introducing VMware NSX 
L2 Switch Firewall 
Network Virtualization with NSX 
Operational model 
of a VM 
Sofare 
• Programmatic provisioning 
• Place any workload anywhere 
• Move any workload anywhere 
• Decoupled from hardware 
• Operationally L3 Router Load Balancer efficient 
7
Virtual Network – A Complete Network in Software 
Internet 
8
VMware NSX – Networking & Security Capabilities 
Any Application 
(without modification) 
Virtual Networks 
Any Cloud Management Platform 
VMware NSX Network Virtualization Platform 
Logical 
Firewall 
Logical L2 
Any Network Hardware 
Logical 
Load Balancer 
Logical L3 
Logical 
VPN 
Any Hypervisor 
Logical Switching– Layer 2 over Layer 3, decoupled from 
the physical network 
Logical Routing– Routing between virtual networks without 
exiting the software container 
Logical Firewall – Distributed Firewall, Kernel Integrated, 
High Performance 
Logical Load Balancer – Application Load Balancing in 
software 
Logical VPN – Site-to-Site & Remote Access VPN in 
software 
NSX API – RESTful API for integration into any Cloud 
Management Platform 
Partner Eco-System 
9
VMware NSX Transforms the Operational Model of the Network 
Reduce network 
provisioning time from days to 
seconds 
Network provisioning time reduced 
from days to seconds 
Cost Savings 
Operational Automation 
Simplified IP hardware 
Reduce operational costs up to 80% 
Increase compute asset utilization up 
to 90% 
Reduce hardware costs by 40-50% 
Choice 
Any hypervisor 
Any CMP 
with Partner 
Any Hypervisor: 
vSphere, KVM, Xen, Hyper-V 
Any CMP: 
vCAC, OpenStack 
Any Network Hardware 
Broad Partner Ecosystem 
10
Gartner Data Center Networking Magic Quadrant 2014 
11 
“The 
NSX 
solu-on 
should 
be 
considered 
by 
exis-ng 
VMware 
customers 
as 
a 
way 
of 
providing 
network 
agility 
and 
reducing 
network 
opera3onal 
challenges 
within 
the 
data 
center.” 
Gartner 
Data 
Center 
Networking 
Magic 
Quadrant, 
April 
24, 
2014
12 
Use cases
Rack N’ Roll!! 
13 
Web 
App 
Database 
Deploy Applications from CMP 
VMs, Logical Networks and Security 
Add Capacity on Demand 
VM 
VM 
VM 
VM 
VM 
VM
Virtual Networks are isolated from each other 
(Overlapping IP Addresses) 
Virtual Networks are isolated from underlying 
physical network (IPv6 over IPv4) 
Multitenancy – Complete Isolation 
14
Problem – Data Center Network Security 
Perimeter-centric network security has proven insufficient, and micro-segmentation is operationally infeasible 
Internet Internet 
Little or no 
lateral controls 
inside perimeter 
Insufficient Operationally 
Infeasible 15
Data Plane 
Distributed switching, routing, 
firewall 
CONFIDENTIAL 16 
Solution – Micro-segmentation with NSX 
CONFIDENTIAL 
Unit-level trust 
Control Plane 
NSX Manager 
Physical workloads 
and VLANS 
§ Each hypervisor has its own 
firewalling with flexible granularity: 
entire data center down to the vNIC 
REST API 
§ Security is shrink-wrapped around 
each workload 
§ Faults and threats are contained with 
micro-granularity 
Management Plane 
vCenter
Data Plane 
Distributed switching, routing, 
firewall 
CONFIDENTIAL 17 
Control Plane 
NSX Manager 
Physical workloads 
and VLANS 
REST API 
Management Plane 
vCenter 
Central Management / 
Distributed Control 
§ Security policies are coordinated and 
centralized 
§ Security actions are orchestrated 
centrally 
§ Firewall policies are provisioned, 
moved, and retired with their 
associated workloads 
Solution – Micro-segmentation with NSX
Segmentation with NSX 
18 
Traditional Data Center NSX Data Center 
DMZ/Web VLAN 
App VLAN 
HR 
Finance 
Finance HR 
Services/Management VLAN 
DB VLAN 
Services Mgmt 
Finance HR 
Perimeter 
firewall 
Inside firewall 
Perimeter 
firewall 
DMZ/Web 
App 
DB 
HR Group 
Finance Group 
DMZ/Web 
App 
DB 
Services/Management 
Group 
Services Mgmt 
NSX segmentation simplifies network security 
§ Each VM can now be its own perimeter § Policies align with logical groups 
§ Control communication within a single VLAN
Service Insertion Example – Palo Alto Networks Next Gen Firewall 
Internet 
Security Policy 
Security Admin 
Traffic 
Steering 
19
Automated Security in a Software Defined Data Center 
Quarantine Vulnerable Systems until Remediated Security Group = Quarantine Zone! 
Members = {Tag = ‘ANTI_VIRUS.VirusFound’, L2 
Isolated Network} ! 
Policy Definition Security Group = Web Tier! 
Standard Desktop VM Policy 
þ Anti-Virus – Scan 
Quarantined VM Policy 
þ Firewall – Block all except security tools 
þ Anti-Virus – Scan and remediate 
20
NSX Extensibility – Partner Integration 
NSX API 
NSX Controller 
Partner 
Network Extensions 
Security 
Platform 
Network 
Gateway 
Services 
Application 
Delivery 
Services 
Security 
Services 
+ 
Cloud Mgmt 
Platforms 
21 
More on NSX Technology Partners: 
http://www.vmware.com/products/nsx/resources.html
Questions 
22
More information 
23 
Description Link 
VMware NSX web site http://www.vmware.com/products/nsx/ 
NSX and SDDC dedicated web site http://virtualizeyournetwork.com/ 
VMware NSX Twitter https://twitter.com/vmwarensx 
Hands-on-Labs Networking http://labs.hol.vmware.com/HOL/catalogs/catalog/130 
VMware NSX customer case – WestJet http://www.youtube.com/watch?v=3OsXGuZjxxY 
VMware NSX customer case – Colt http://blogs.vmware.com/networkvirtualization/2014/08/vmware-nsx-customer- 
story-colt-decreases-data-center-networking-complexity.html 
VMware NSX customer case – NTT http://www.vmware.com/company/news/releases/vmw-ntt-netvirt-061013 
Brad Hedlund on end-to-end visibility in VMware NSX http://www.youtube.com/watch?v=wRL47AmFAUU 
VMware NSX and Splunk - Operational Visibility Across 
Virtual and Physical Domains http://www.youtube.com/watch?v=PzMvQFeojCk
Thank you

More Related Content

PDF
VMware Tanzu Introduction
VMware Tanzu
 
PPTX
Microsoft azure
Charith Suriyakula
 
PDF
Microsoft Azure Overview
David J Rosenthal
 
PDF
Azure 101
Korry Lavoie
 
PDF
Datacenter migration using vmware
Wilson Erique
 
PPTX
Azure Cloud Services
Kajal Kathrotiya
 
PPTX
Azure vnet
zekeLabs Technologies
 
PPTX
Azure Introduction
brunoterkaly
 
VMware Tanzu Introduction
VMware Tanzu
 
Microsoft azure
Charith Suriyakula
 
Microsoft Azure Overview
David J Rosenthal
 
Azure 101
Korry Lavoie
 
Datacenter migration using vmware
Wilson Erique
 
Azure Cloud Services
Kajal Kathrotiya
 
Azure Introduction
brunoterkaly
 

What's hot (20)

PDF
Microsoft Azure
Novosco
 
PDF
Introduction to Azure
Robert Crane
 
PDF
Az 104 session 3 azure compute
AzureEzy1
 
PPTX
App Modernization with Microsoft Azure
Microsoft Tech Community
 
PDF
Data Center Security
devalnaik
 
PDF
NF101: Nutanix 101
NEXTtour
 
PPTX
Understanding Azure Disaster Recovery
New Horizons Ireland
 
PDF
Microsoft Azure Fundamentals
Adwait Ullal
 
PPTX
Cloud Computing
Mohammad Shakirul islam
 
PPTX
Azure App Service Architecture. Web Apps.
Alexander Feschenko
 
PPTX
Introduction to Microsoft Azure
Kasun Kodagoda
 
PDF
Introduction to Azure IaaS
Robert Crane
 
ODP
Introduction to Virtualization
Rahul Hada
 
PDF
Building Kubernetes images at scale with Tanzu Build Service
VMware Tanzu
 
PDF
Server Virtualization
rjain51
 
PDF
12 Things You Must Know About VDI
Shivani Sehta
 
PDF
Application Security - Key Vault
Eng Teong Cheah
 
PDF
Az 104 session 5: Azure networking
AzureEzy1
 
PPTX
Azure Storage
Mustafa
 
PPTX
VMware App Volumes Troubleshooting
Denis Gundarev
 
Microsoft Azure
Novosco
 
Introduction to Azure
Robert Crane
 
Az 104 session 3 azure compute
AzureEzy1
 
App Modernization with Microsoft Azure
Microsoft Tech Community
 
Data Center Security
devalnaik
 
NF101: Nutanix 101
NEXTtour
 
Understanding Azure Disaster Recovery
New Horizons Ireland
 
Microsoft Azure Fundamentals
Adwait Ullal
 
Cloud Computing
Mohammad Shakirul islam
 
Azure App Service Architecture. Web Apps.
Alexander Feschenko
 
Introduction to Microsoft Azure
Kasun Kodagoda
 
Introduction to Azure IaaS
Robert Crane
 
Introduction to Virtualization
Rahul Hada
 
Building Kubernetes images at scale with Tanzu Build Service
VMware Tanzu
 
Server Virtualization
rjain51
 
12 Things You Must Know About VDI
Shivani Sehta
 
Application Security - Key Vault
Eng Teong Cheah
 
Az 104 session 5: Azure networking
AzureEzy1
 
Azure Storage
Mustafa
 
VMware App Volumes Troubleshooting
Denis Gundarev
 
Ad

Viewers also liked (20)

PDF
An Introduction to VMware NSX
Scott Lowe
 
PDF
Network Virtualization with VMware NSX
Scott Lowe
 
PPTX
VMworld 2015: VMware NSX Deep Dive
VMworld
 
PDF
VMware NSX - Lessons Learned from real project
David Pasek
 
PPTX
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
VMworld
 
PPTX
VMworld 2016: Advanced Network Services with NSX
VMworld
 
PPTX
Reference design for v mware nsx
solarisyougood
 
PDF
The Future of Cloud Networking is VMware NSX
Scott Lowe
 
PDF
VMworld 2014: Virtualize your Network with VMware NSX
VMworld
 
PDF
Software Defined Networking (SDN) with VMware NSX
Zivaro Inc
 
PPTX
#NET5488 - Troubleshooting Methodology for VMware NSX - VMworld 2015
Dmitri Kalintsev
 
PPTX
VMworld 2016: vSphere 6.x Host Resource Deep Dive
VMworld
 
PDF
Diseño de centros de computo multi sitio con vmware NSX - vforum 2014
Wetcom
 
PDF
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld
 
PDF
VMworld 2014: Introduction to NSX
VMworld
 
PPTX
Self service it with v realizeautomation and nsx
solarisyougood
 
PDF
vRA + NSX Technical Deep-Dive
VMUG IT
 
PDF
VMware NSX + Cumulus Networks: Software Defined Networking
Cumulus Networks
 
PPTX
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
VMworld
 
PDF
VMUG - NSX Architettura e Design
VMUG IT
 
An Introduction to VMware NSX
Scott Lowe
 
Network Virtualization with VMware NSX
Scott Lowe
 
VMworld 2015: VMware NSX Deep Dive
VMworld
 
VMware NSX - Lessons Learned from real project
David Pasek
 
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
VMworld
 
VMworld 2016: Advanced Network Services with NSX
VMworld
 
Reference design for v mware nsx
solarisyougood
 
The Future of Cloud Networking is VMware NSX
Scott Lowe
 
VMworld 2014: Virtualize your Network with VMware NSX
VMworld
 
Software Defined Networking (SDN) with VMware NSX
Zivaro Inc
 
#NET5488 - Troubleshooting Methodology for VMware NSX - VMworld 2015
Dmitri Kalintsev
 
VMworld 2016: vSphere 6.x Host Resource Deep Dive
VMworld
 
Diseño de centros de computo multi sitio con vmware NSX - vforum 2014
Wetcom
 
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld
 
VMworld 2014: Introduction to NSX
VMworld
 
Self service it with v realizeautomation and nsx
solarisyougood
 
vRA + NSX Technical Deep-Dive
VMUG IT
 
VMware NSX + Cumulus Networks: Software Defined Networking
Cumulus Networks
 
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
VMworld
 
VMUG - NSX Architettura e Design
VMUG IT
 
Ad

Similar to VMware NSX for vSphere - Intro and use cases (20)

PDF
GAMO VMware vCloud Air
GAMO a.s.
 
PPSX
Síťová virtualizace s VMware
MarketingArrowECS_CZ
 
PDF
Business Agility and Security with VMware
Angel Villar Garea
 
PPSX
VMware: my jsme “software defined”
MarketingArrowECS_CZ
 
PDF
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld
 
PDF
Sdn primer pdf
Pooja Patel
 
PPTX
New NSX Pitch Deck 2023 030302020202.pptx
contaworldigital
 
PPTX
VMworld 2015: Introducing Application Self service with Networking and Security
VMworld
 
PPTX
6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il ...
Jürgen Ambrosi
 
PPTX
Reston Virtualization Group 9-18-2014
VMwareJenn
 
PDF
VMworld 2013: VMware Compliance Reference Architecture Framework Overview
VMworld
 
PDF
VMworld 2013: Datacenter Transformation with Network Virtualization: Today an...
VMworld
 
PPTX
20150311 NSX update 301
Kevin Groat
 
PDF
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
VMworld
 
PDF
VMware NSX @ VMUG.IT 20150529
VMUG IT
 
PPTX
New Threats, New Approaches in Modern Data Centers
Iben Rodriguez
 
PPTX
nsx overview with use cases 1.0
Ploynatcha Akkaraputtipat
 
PDF
Gigamon Pervasive Visibility into SDDC/NSX Deployments
Angel Villar Garea
 
PPT
Virtulaisation
Srinivasa Rao
 
GAMO VMware vCloud Air
GAMO a.s.
 
Síťová virtualizace s VMware
MarketingArrowECS_CZ
 
Business Agility and Security with VMware
Angel Villar Garea
 
VMware: my jsme “software defined”
MarketingArrowECS_CZ
 
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld
 
Sdn primer pdf
Pooja Patel
 
New NSX Pitch Deck 2023 030302020202.pptx
contaworldigital
 
VMworld 2015: Introducing Application Self service with Networking and Security
VMworld
 
6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il ...
Jürgen Ambrosi
 
Reston Virtualization Group 9-18-2014
VMwareJenn
 
VMworld 2013: VMware Compliance Reference Architecture Framework Overview
VMworld
 
VMworld 2013: Datacenter Transformation with Network Virtualization: Today an...
VMworld
 
20150311 NSX update 301
Kevin Groat
 
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
VMworld
 
VMware NSX @ VMUG.IT 20150529
VMUG IT
 
New Threats, New Approaches in Modern Data Centers
Iben Rodriguez
 
nsx overview with use cases 1.0
Ploynatcha Akkaraputtipat
 
Gigamon Pervasive Visibility into SDDC/NSX Deployments
Angel Villar Garea
 
Virtulaisation
Srinivasa Rao
 

More from Angel Villar Garea (9)

PDF
VMware NSX NTT Case Study
Angel Villar Garea
 
PDF
A New Approach to Healthcare Security
Angel Villar Garea
 
PDF
VMware Solutions for the Connected Car
Angel Villar Garea
 
PDF
Business and Economic Benefits of VMware NSX
Angel Villar Garea
 
PDF
Arkin and VMware NSX Operations
Angel Villar Garea
 
PDF
NSX on VMware Data Center
Angel Villar Garea
 
PDF
OneCloud-VMwareNSX
Angel Villar Garea
 
PDF
NSX Infographic - Security
Angel Villar Garea
 
PDF
Welcome!
Angel Villar Garea
 
VMware NSX NTT Case Study
Angel Villar Garea
 
A New Approach to Healthcare Security
Angel Villar Garea
 
VMware Solutions for the Connected Car
Angel Villar Garea
 
Business and Economic Benefits of VMware NSX
Angel Villar Garea
 
Arkin and VMware NSX Operations
Angel Villar Garea
 
NSX on VMware Data Center
Angel Villar Garea
 
OneCloud-VMwareNSX
Angel Villar Garea
 
NSX Infographic - Security
Angel Villar Garea
 

Recently uploaded (20)

PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PDF
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PDF
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
PDF
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 

VMware NSX for vSphere - Intro and use cases

  • 1. NSX for vSphere, intro and use cases Oct 2014 Ángel Villar Garea [email protected] @AVillarGarea
  • 2. DISCLAIMER 2 This is NOT VMware’s official documentation. It is just my understanding of technology and products. Any inaccuracy or error you may find it is only my responsibility and not VMware’s.
  • 3. 3 The biggest industry transformation since mainframe to client server computing?
  • 4. What customers demand Business/IT Execs Speed and Agility Secure Infrastructure Time-to-Market Competitive Advantage 4 IT Operations Efficiency of change IT Infrastructure & Security Data Center Micro-segmentation Scale-out DMZ Network hardware choice Compute capacity utilization
  • 5. The Software Defined Data Center (SDDC) Intelligence in Software Operational Model of VM for Data Center Automated Configuration & Management Software Data Center Virtualization Layer Hardware Compute, Network and Storage Capacity Pooled, Vendor Independent, Best Price/Performance Infrastructure Simplified Configuration & Management 5
  • 6. The Network Is a Barrier to Software Defined Data Center!! Compute Virtualization Abstraction Layer Physical Infrastructure Software Defined Data Center • Provisioning is slow • Placement is limited • Mobility is limited • Hardware dependent • Operationally intensive 6
  • 7. Physical Infrastructure • Provisioning is slow • Placement is limited • Mobility is limited • Hardware dependent • Operationally intensive Introducing VMware NSX L2 Switch Firewall Network Virtualization with NSX Operational model of a VM Sofare • Programmatic provisioning • Place any workload anywhere • Move any workload anywhere • Decoupled from hardware • Operationally L3 Router Load Balancer efficient 7
  • 8. Virtual Network – A Complete Network in Software Internet 8
  • 9. VMware NSX – Networking & Security Capabilities Any Application (without modification) Virtual Networks Any Cloud Management Platform VMware NSX Network Virtualization Platform Logical Firewall Logical L2 Any Network Hardware Logical Load Balancer Logical L3 Logical VPN Any Hypervisor Logical Switching– Layer 2 over Layer 3, decoupled from the physical network Logical Routing– Routing between virtual networks without exiting the software container Logical Firewall – Distributed Firewall, Kernel Integrated, High Performance Logical Load Balancer – Application Load Balancing in software Logical VPN – Site-to-Site & Remote Access VPN in software NSX API – RESTful API for integration into any Cloud Management Platform Partner Eco-System 9
  • 10. VMware NSX Transforms the Operational Model of the Network Reduce network provisioning time from days to seconds Network provisioning time reduced from days to seconds Cost Savings Operational Automation Simplified IP hardware Reduce operational costs up to 80% Increase compute asset utilization up to 90% Reduce hardware costs by 40-50% Choice Any hypervisor Any CMP with Partner Any Hypervisor: vSphere, KVM, Xen, Hyper-V Any CMP: vCAC, OpenStack Any Network Hardware Broad Partner Ecosystem 10
  • 11. Gartner Data Center Networking Magic Quadrant 2014 11 “The NSX solu-on should be considered by exis-ng VMware customers as a way of providing network agility and reducing network opera3onal challenges within the data center.” Gartner Data Center Networking Magic Quadrant, April 24, 2014
  • 13. Rack N’ Roll!! 13 Web App Database Deploy Applications from CMP VMs, Logical Networks and Security Add Capacity on Demand VM VM VM VM VM VM
  • 14. Virtual Networks are isolated from each other (Overlapping IP Addresses) Virtual Networks are isolated from underlying physical network (IPv6 over IPv4) Multitenancy – Complete Isolation 14
  • 15. Problem – Data Center Network Security Perimeter-centric network security has proven insufficient, and micro-segmentation is operationally infeasible Internet Internet Little or no lateral controls inside perimeter Insufficient Operationally Infeasible 15
  • 16. Data Plane Distributed switching, routing, firewall CONFIDENTIAL 16 Solution – Micro-segmentation with NSX CONFIDENTIAL Unit-level trust Control Plane NSX Manager Physical workloads and VLANS § Each hypervisor has its own firewalling with flexible granularity: entire data center down to the vNIC REST API § Security is shrink-wrapped around each workload § Faults and threats are contained with micro-granularity Management Plane vCenter
  • 17. Data Plane Distributed switching, routing, firewall CONFIDENTIAL 17 Control Plane NSX Manager Physical workloads and VLANS REST API Management Plane vCenter Central Management / Distributed Control § Security policies are coordinated and centralized § Security actions are orchestrated centrally § Firewall policies are provisioned, moved, and retired with their associated workloads Solution – Micro-segmentation with NSX
  • 18. Segmentation with NSX 18 Traditional Data Center NSX Data Center DMZ/Web VLAN App VLAN HR Finance Finance HR Services/Management VLAN DB VLAN Services Mgmt Finance HR Perimeter firewall Inside firewall Perimeter firewall DMZ/Web App DB HR Group Finance Group DMZ/Web App DB Services/Management Group Services Mgmt NSX segmentation simplifies network security § Each VM can now be its own perimeter § Policies align with logical groups § Control communication within a single VLAN
  • 19. Service Insertion Example – Palo Alto Networks Next Gen Firewall Internet Security Policy Security Admin Traffic Steering 19
  • 20. Automated Security in a Software Defined Data Center Quarantine Vulnerable Systems until Remediated Security Group = Quarantine Zone! Members = {Tag = ‘ANTI_VIRUS.VirusFound’, L2 Isolated Network} ! Policy Definition Security Group = Web Tier! Standard Desktop VM Policy þ Anti-Virus – Scan Quarantined VM Policy þ Firewall – Block all except security tools þ Anti-Virus – Scan and remediate 20
  • 21. NSX Extensibility – Partner Integration NSX API NSX Controller Partner Network Extensions Security Platform Network Gateway Services Application Delivery Services Security Services + Cloud Mgmt Platforms 21 More on NSX Technology Partners: http://www.vmware.com/products/nsx/resources.html
  • 23. More information 23 Description Link VMware NSX web site http://www.vmware.com/products/nsx/ NSX and SDDC dedicated web site http://virtualizeyournetwork.com/ VMware NSX Twitter https://twitter.com/vmwarensx Hands-on-Labs Networking http://labs.hol.vmware.com/HOL/catalogs/catalog/130 VMware NSX customer case – WestJet http://www.youtube.com/watch?v=3OsXGuZjxxY VMware NSX customer case – Colt http://blogs.vmware.com/networkvirtualization/2014/08/vmware-nsx-customer- story-colt-decreases-data-center-networking-complexity.html VMware NSX customer case – NTT http://www.vmware.com/company/news/releases/vmw-ntt-netvirt-061013 Brad Hedlund on end-to-end visibility in VMware NSX http://www.youtube.com/watch?v=wRL47AmFAUU VMware NSX and Splunk - Operational Visibility Across Virtual and Physical Domains http://www.youtube.com/watch?v=PzMvQFeojCk