Recently, I’ve been diving deeper into the security features of VCF. It turns out a lot has changed since the old days. In this post, I’ll cover some of the changes I consider especially relevant so you can also start your own research.
What has changed?
If you haven’t followed the changes made over the last few years, know this: all VMware security features have been rebranded. It’s not unusual to encounter a customer with older components that need to be completely upgraded or even migrated to a new architecture. I’ve put together a comparison that might help you.
| Licensing | Previous Name | Successor |
| vDefend Firewall | NSX Application Platform (NAPP) | Security Services Platform (SSP) |
| vDefend Firewall | NSX Distributed Firewall (DFW) | VMware vDefend Distributed Firewall |
| vDefend Firewall | NSX Gateway Firewall | VMware vDefend Gateway Firewall |
| vDefend Firewall | NSX Intelligence | VMware vDefend Security Intelligence |
| vDefend Firewall with Advanced Threat Prevention | NSX Network Traffic Analysis (NTA) | VMware vDefend Network Traffic Analysis |
| vDefend Firewall with Advanced Threat Prevention | NSX Network Detection and Response (NDR) | VMware vDefend Network Detection and Response |
| vDefend Firewall with Advanced Threat Prevention | NSX Malware Prevention (MPS) | VMware vDefend Malware Prevention |
New Security Platform Installer
With this new structure, we now have an installer appliance called Security Services Platform Installer (SSPI). With it, you’ll be able to deploy all the vDefend components, as well as Avi Load Balancer and License Hub.
There is also an important clarification here: if you plan to use the most recent versions of vDefend and Avi, using License Hub is mandatory.
| vDefend | AVI Load Balancer | Licensing |
| 5.2 | 32.X | Deployment and use of License Hub 2.0 for VMware® vDefend and Avi Load Balancer are mandatory. |
| 5.1 | 31.X | Can be licensed directly through Avi Cloud Console or License Hub 5.1. |
Requirements
Basically, the sizing you choose for your environment will depend on the services you’ll use. You can check the Security Services Platform System Requirements and the Platform Details and Available Features for a detailed explanation.
The number of IP addresses required will vary depending on the size of your deployment. Regardless of the size, make sure you meet the following requirements:
- The ‘instance FQDN’ must point to the first IP in the Service IP pool.
- The ‘messaging FQDN’ must point to the second IP in the Service IP pool.

