From NSX to vDefend: What Has Changed in VCF Security

2 minutes

Updated


Recently, I’ve been diving deeper into the security features of VCF. It turns out a lot has changed since the old days. In this post, I’ll cover some of the changes I consider especially relevant so you can also start your own research.

What has changed?

If you haven’t followed the changes made over the last few years, know this: all VMware security features have been rebranded. It’s not unusual to encounter a customer with older components that need to be completely upgraded or even migrated to a new architecture. I’ve put together a comparison that might help you.

LicensingPrevious NameSuccessor
vDefend FirewallNSX Application Platform (NAPP)Security Services Platform (SSP)
vDefend FirewallNSX Distributed Firewall (DFW)VMware vDefend Distributed Firewall
vDefend FirewallNSX Gateway FirewallVMware vDefend Gateway Firewall
vDefend FirewallNSX IntelligenceVMware vDefend Security Intelligence
vDefend Firewall with Advanced Threat PreventionNSX Network Traffic Analysis (NTA)VMware vDefend Network Traffic Analysis
vDefend Firewall with Advanced Threat PreventionNSX Network Detection and Response (NDR)VMware vDefend Network Detection and Response
vDefend Firewall with Advanced Threat PreventionNSX Malware Prevention (MPS)VMware vDefend Malware Prevention

New Security Platform Installer

With this new structure, we now have an installer appliance called Security Services Platform Installer (SSPI). With it, you’ll be able to deploy all the vDefend components, as well as Avi Load Balancer and License Hub.

There is also an important clarification here: if you plan to use the most recent versions of vDefend and Avi, using License Hub is mandatory.

vDefendAVI Load BalancerLicensing
5.232.XDeployment and use of License Hub 2.0 for VMware® vDefend and Avi Load Balancer are mandatory.
5.131.XCan be licensed directly through Avi Cloud Console or License Hub 5.1.

Requirements

The number of IP addresses required will vary depending on the size of your deployment. Regardless of the size, make sure you meet the following requirements:

  • The ‘instance FQDN’ must point to the first IP in the Service IP pool.
  • The ‘messaging FQDN’ must point to the second IP in the Service IP pool.

Discover more from LanzNot.com

Subscribe now to keep reading and get access to the full archive.

Continue reading