M05 - SDDC Advanced Security
M05 - SDDC Advanced Security
May 2023
3. Disabling Add-ons
Shared
Users
Services
Web Tier
Policies align to the
environment instead
App Tier
of the application
DB Tier
Shared
Users
Services
Web Tier
Identify application
boundaries and
App Tier
determine intended
network traffic
DB Tier
Shared
Users
Services
Web Tier
Isolate the application
and only allow
App Tier
required
communication
DB Tier
Finance HR Engineering
Perimeter
firewall Zero Trust/Least Privilege
DMZ
Model
Inside
firewall Each VM can now be its own
perimeter
App
Policies align with logical
groups
Prevents threats from
DB
spreading
Network Topology Agnostic
Services
East-West Protection for workloads Deep Packet Inspection for Layer 7 Per User/ session application access
Application control
Detect attempts at exploiting
vulnerabilities in applications Built-in Application IDs for common DFW based enforcement at the
enterprise applications source
Distributed traffic inspection scales
linearly with workloads FQDN based access control –per AD/ LDAP integration to
VM automatically curate access to
Context based threat detection applications
Reduce the attack surface to
Integrated with NSX Threat intended application/ protocols
Intelligence Cloud Service
Port-Independent Micro-
Compliance Zones Reducing the Attack Surface
segmentation
Enforce the use of strong cryptography Only allow the intended Allow APP-owners to run services across
and secure protocols application/protocol to run across a port any port
BLAST/22443
HTTP
RDP/3389 RDSH
UAG MRS-
RDP/22443 APP-1
MYSQL
MRS-
DB-1
Finance-App-1
• Session-based
• Supported for both VDI and RDSH
• Granular On/Off per Cluster
• Requires VMware Tools/Thin agent
Remote Desktop Session Hosts / Published Apps
HR-App-1
Web App DB
Before NSX IDS & IPS With NSX IDS & IPS
IDPS
Hair-pin traffic
to centralized
appliances
Before NSX IDS & IPS With NSX IDS & IPS
Move Inspection to
each workload
FIREWALL IDS/IPS
172.20.20.12
• Detect unusual behavior and prevent possible
zero day attacks
D-IDPS
Confidence of the detection being Numeric value indicating Combined Value of Risk Score and 5 Levels indicating “badness” of a
accurate “badness” of a threat confidence score 0-100 threat
0 – 100 Risk score = 0 – 100 Also forms the base score for Critical
events in NDR High
Higher score indicates higher Factor in Impact Score Medium
confidence (lower false positives) New in VMC 1.19 Low
New in VMC 1.19
Lower score indicates increased Suspicious
proneness to false positives Based on signature_severity
Factor in Impact Score value carried in signature, CVSS
or classification type
New in VMC 1.19
Severity also available in VMC
1.16-1.18
• Context-based event-filtering
2. Deactivating Add-on stops users from adding/ updating rules in DFW L7/ IDS.
3. Existing rules continue to persist, but not be enforced, until users delete them.
SDDC
1. Implement Context-aware
firewalling Demo-Net
CGW
3. Implement Distributes Intrusion BGP Desktop-Net
detection and prevention
Edge NSX
vCenter </> HCX
MGW
Connected VPC