SlideShare a Scribd company logo
© Copyright Fortinet Inc. All rights reserved.
Le nuove sfide della cyber security su
infrastrutture software defined.
Advanced Security in Vmware NSX with FortiGate-VMX
Antonio Gentile
agentile@fortinet.com
Systems Engineer, Italy
Agenda
➢ Fortinet Security Fabric
➢ Fortinet Cloud & SDN Vision
➢ FortiGate-VMX Integration with NSX
➢ Key Points and Licensing
➢ Q&A
‹N›
2018 Fortinet Security Fabric
A Security Architecture that provides:
BROAD Visibility & Protection of the
Digital Attack Surface
INTEGRATED Detection of Advanced
Threats
AUTOMATED Response & Continuous
Trust Assessment
Delivered as:
Appliance Virtual
Machine
Hosted Cloud Software
‹N›
2018 Fortinet Solutions
Network
Security
Multi-Cloud
Security
Endpoint
Security
Email
Security
Web Application
Security
Secure
Unified Access
Advanced
Threat Protection
Management
- Analytics
FortiGate
Enterprise Firewall
FortiGate
Cloud Firewall
Network Security
FortiClient
EPP
FortiWeb
Web Application
Firewall
FortiMail
Secure Email
Gateway
FortiSandbox
Advanced Threat
Protection
FortiAnalyzer
Central Logging /Reporting
FortiManager
Central Security Management
FortiSIEM
Security Information &
Event Management
FortiGate
Virtual Firewall
Network Security
FortiAP
Wireless
Infrastructure
FortiSwitch
Switching
InfrastructureSWG
SD-WAN
IPS
Agenda
➢ Fortinet Cloud & SDN Vision
➢ FortiGate-VMX Integration with NSX
➢ Key Points And Licensing
➢ Q&A
‹N›
Virtualization SDN Cloud (IaaS) Cloud (SaaS)
Fortinet Cloud & SDN Vision
Physical & Virtual Security Appliances
FortiGate FortiManagerFortiSandbox FortiAnalyzer FortiWeb FortiADC FortiDDoSFortiWifiFortiMail
vSpher
e
XenServe
r
Hyper-V NSX
‹N›
Fortinet Programmable Networking Partnership Ecosystem
Platform Extensibility
Orchestration Platforms
Programmable Switching
vCNS certified
NSX Partner program
NSX Manager
Full NSX
Centralized Policy & Analytics
ACI
‹N›
SDx
Physical/Virtual/SDN/Cloud
North
South
East
West
Hybrid Cloud
Public
Cloud
Private
Cloud
FortiAnalyzer FortiManager
FortiWeb
FortiGate
VirtualCloud VirtualCloud
CLOUD SECURITY
FortiCore FortiGate VMX
FortiOSFortiGuardFortiASIC
5.4
Security for the Cloud
Agenda
➢ Fortinet Cloud & SDN Vision
➢ FortiGate-VMX Integration with NSX
➢ Key Points And Licensing
➢ Q&A
‹N›
NSX Platform Network and Security Virtualization
Components
Cloud Consumption
(CMP)
NSX Manager
NSX Controller
Data Plane
• Self Service Portal
• VMware vRealize Automation, vCloud Director, OpenStack, Custom
CMS
• High-performance data plane
• Scale-out distributed forwarding model
• Single configuration portal
• REST API entry-point
• Manages logical networks
• Run-time state
• Scale out, HA
• Separation of control and data plane
ESXi, KVM, Xen
Distributed Services
• Logical Switch
• Distributed Logical Router
• Firewall
• Load Balancer
HW VTEPNSX Edge
‹N›
VMWare-NSX Architecture
Physical Host
NSX vSwitch
VM
VM
VM
NSX vSwitch
VM
User Space
VM
VM
Hypervisor
User Space
Hypervisor
Virtual Network
Cluster Controller
Cloud Mgt Platform
Simplified IP Backplane No VLANs, No ACLs, No Firewall Rules
Existing Physical Network
SrcIP = Hypervisor-1
DstIP = Hypervisor-2
???????
‹N›
Added Value of Security integration in SDDC
Requirements Solution
Visibility on Guest to Guest traffic
Micro-Segmentation and Zero Trust
Control of ‘east-west’ traffic, Inter and Intra VM
security, Logical Security Zone (multi-tier)
Not just firewall, but advanced features
‹N›
Manage
Components for NSX Integration
Mandatory Components for NSX Integration
Third Party Solution
Service Manager
Service Appliance
ESXi Hosts
VMware
vCenter Server
V5.5 or v6.0
VMware vSphere
(Enterprise Plus license
v5.5 or v6.0)
REST API
Fortinet Solution
FortiGate-VMX
Service Manager
FortiGate-VMX
Security Appliance
‹N›
FortiGate-VMX and NSX Integration/Interactions
dvSwitch
FGT-VMX FGT-VMX
Push
polic
y
synch
roniz
ation
to all
Forti
Gate-
VMX
deplo
yed
in
cluste
r 7
Register Fortinet as security service with NSX Manager1
Auto-
deploy
FortiGat
e-VMX
to all
hosts in
security
cluster
2
FortiGat
e-VMX
connects
with
FortiGat
e-VMX
Service
Manager
3
License verification & configuration
synchronization with
FortiGate-VMX
4
NSX
Secur
ity
Polic
y
define
netwo
rk
intros
pectio
n
rules
to
redire
ct
traffic
5
Real-time updates of object database6
FortiGate-VMX
Service Manager
‹N›
FortiGate-VMX and NSX Manager Setup
Adding VMware NSX details on FortiGate Service Manager
FortiGate VMX Service on NSX Manager
‹N›
FGT-VMX imports NSX Security Groups
● On NSX create Security Groups and assign “Objects”
Security Groups defined on NSX are automatically created on FGT-VMX
‹N›
FGT-VMX imports NSX Security Groups
● On NSX create Security Groups and assign “Objects”
● FortiGate VMX automatically imports the Security Groups as a dynamic firewall
addresses with the VMs IP address
Security Groups defined on NSX are automatically created on FGT-VMX
‹N›
NSX Security Group definition and usage
Server SG
FortiGate-VMX NSX Manager
Service Groups created on NSX Manager
automatically get sent to the FortiGate-VMX and
are available for Policy Creation
Policy Created on FortiGate-
VMX using Exchanged
Security Group
‹N›
VMware Kernel
dvSwitch
FGT-VMX and VMWARE NSX Filter Driver Interaction
1 Define NGFW Firewall Policies
2
Sync config on FGT-VMX
FGT-VMX
NetX NSX Filter Driver
int
ext
Packet Flow
1. From VM to NSX Filter Driver
2. NSX Filter Driver Forward to Third
party Solution (FGT-VMX)
3. FGT-VMX applies Security and sends
packet back to NSX Filter Driver
4. NSX Filter Driver can do service
chaining or send packet to destination
FortiGate-VMX
Service Manager
A B
‹N›
Policy Creation
● Firewall Policy is now IP independent
Policy created based on Security Group
Internal External
Distributed
Virtual
Switch
‹N›
VMWare-NSX Architecture with FortiGate-VMX
Physical Host
NSX vSwitch
VM VM
VM
NSX vSwitch
VM
User Space
VM
VM
Hypervisor
User Space
Hypervisor
Virtual Network
Cluster Controller
Cloud Mgt Platform
Existing Physical Network
Anti-botnet
Intrusion
Prevention
Antivirus
Application
Control
Web Application
Firewall
Web Filtering
FortiAnalyzer
Logging & Reporting
FortiSandbox
ATP
FortiGate-VMX
Service Manager
FortiGate-VMX
Security Appliance
FortiGate-VMX
Security Appliance
Agenda
➢ Fortinet Cloud & SDN Vision
➢ FortiGate-VMX Integration with NSX
➢ License Model and Key Points
➢ Q&A
‹N›
FortiGate-VMX License Model
● One license for the FortiGate-VMX Service Manager
● Simple license based on number of FGT-VMX Security Appliance deployed
» One FortiGate-VMX license per ESXi host
» No limits placed on resources (virtual or hardware), nor number of protected VM workloads
Hypervisor with 2 sockets Hypervisor with 1 socket 2 FGT-VMX
Licenses
3 FGT-VMX
Licenses
Hypervisor with 2 sockets
Central license server with auto decrement
‹N›
● Utilizing Fortinet Virtual Domains
(VDOMs)
• Segment a single FortiGate-VMX Security
Node to service different flows completely
segregated from each other.
• Greater flexibility for both Enterprise and
Managed Service Providers as seen in the
sample Security Policy configurations
below.
FortiGate-VMX VDOMs
‹N›
Migration (vMotion) Support
● Migration
» Session handover done by VM is picked up by VMX
Hypervisor with 2 sockets Hypervisor with 2 sockets
Web-01 App-
01
SSH
SSH
‹N›
FortiGate-VMX Key Points
● Real Multi-tenancy (VDOM) support
● Per Security Appliance instance Resource monitor
● Improved throughput for firewall and security functionality using TSO (TCP Segment Offload)
● Service Manager to Security Appliance instantaneous update of the security policies
● Automatic creation of NSX Security Groups in FortiGate-VMX Service Manager
● Central license server with auto decrement
● OVF footprint < 40 MB
● License independent from physical or virtual resources
● NSX integrated upgrade process
● Real-time FortiGuard updates
Agenda
➢ Fortinet Cloud & SDN Vision
➢ FortiGate-VMX Integration with NSX
➢ Key Points And Licensing
➢ Q&A
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet

More Related Content

What's hot

Application delivery controllers
Application delivery controllersApplication delivery controllers
Application delivery controllers
cubixtech
 
Driving Success In The Cloud With NGINX
Driving Success In The Cloud With NGINXDriving Success In The Cloud With NGINX
Driving Success In The Cloud With NGINX
NGINX, Inc.
 
A New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the CloudA New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the Cloud
NETSCOUT
 
Presentación Enrique Algaba NFV movilforum
Presentación Enrique Algaba NFV movilforumPresentación Enrique Algaba NFV movilforum
Presentación Enrique Algaba NFV movilforum
videos
 
Presentación Red Hat evento NFV movilforum
Presentación Red Hat evento NFV movilforumPresentación Red Hat evento NFV movilforum
Presentación Red Hat evento NFV movilforum
videos
 
Cisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful TechnologyCisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful Technology
Cisco Canada
 
Cisco Connect Halifax 2018 Simple IT
Cisco Connect Halifax 2018   Simple ITCisco Connect Halifax 2018   Simple IT
Cisco Connect Halifax 2018 Simple IT
Cisco Canada
 
vSEC pro VMware NSX
vSEC pro VMware NSXvSEC pro VMware NSX
vSEC pro VMware NSX
MarketingArrowECS_CZ
 
Assuring VNF image integrity and host sealing in telco cloud
Assuring VNF image integrity and host sealing in telco cloudAssuring VNF image integrity and host sealing in telco cloud
Assuring VNF image integrity and host sealing in telco cloud
Shankar Lal
 
vSEC pro CISCO ACI
vSEC pro CISCO ACIvSEC pro CISCO ACI
vSEC pro CISCO ACI
MarketingArrowECS_CZ
 
Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018
Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018
Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018
Cloudify Community
 
SDN/NFV architecture vision and reality
SDN/NFV architecture vision and reality SDN/NFV architecture vision and reality
SDN/NFV architecture vision and reality
Colt Technology Services
 
Jak využít cloudu pro zvýšení bezpečnosti vašeho IT
Jak využít cloudu pro zvýšení bezpečnosti vašeho ITJak využít cloudu pro zvýšení bezpečnosti vašeho IT
Jak využít cloudu pro zvýšení bezpečnosti vašeho IT
MarketingArrowECS_CZ
 
Production-Grade Kubernetes With NGINX Ingress Controller
Production-Grade Kubernetes With NGINX Ingress ControllerProduction-Grade Kubernetes With NGINX Ingress Controller
Production-Grade Kubernetes With NGINX Ingress Controller
NGINX, Inc.
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco Canada
 
LKNOG3 - Telco Cloud Common – VIM/ CIM
LKNOG3 - Telco Cloud Common – VIM/ CIMLKNOG3 - Telco Cloud Common – VIM/ CIM
LKNOG3 - Telco Cloud Common – VIM/ CIM
LKNOG
 
Securing Micro Services in Cloud Foundry
Securing Micro Services in Cloud FoundrySecuring Micro Services in Cloud Foundry
Securing Micro Services in Cloud Foundry
PLUMgrid
 
Netronome Corporate Brochure
Netronome Corporate BrochureNetronome Corporate Brochure
Netronome Corporate Brochure
Carly Steele
 
vArmour - Securing the Modern Data Centre
vArmour - Securing the Modern Data CentrevArmour - Securing the Modern Data Centre
vArmour - Securing the Modern Data Centre
Infront
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco Canada
 

What's hot (20)

Application delivery controllers
Application delivery controllersApplication delivery controllers
Application delivery controllers
 
Driving Success In The Cloud With NGINX
Driving Success In The Cloud With NGINXDriving Success In The Cloud With NGINX
Driving Success In The Cloud With NGINX
 
A New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the CloudA New Approach to Continuous Monitoring in the Cloud
A New Approach to Continuous Monitoring in the Cloud
 
Presentación Enrique Algaba NFV movilforum
Presentación Enrique Algaba NFV movilforumPresentación Enrique Algaba NFV movilforum
Presentación Enrique Algaba NFV movilforum
 
Presentación Red Hat evento NFV movilforum
Presentación Red Hat evento NFV movilforumPresentación Red Hat evento NFV movilforum
Presentación Red Hat evento NFV movilforum
 
Cisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful TechnologyCisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful Technology
 
Cisco Connect Halifax 2018 Simple IT
Cisco Connect Halifax 2018   Simple ITCisco Connect Halifax 2018   Simple IT
Cisco Connect Halifax 2018 Simple IT
 
vSEC pro VMware NSX
vSEC pro VMware NSXvSEC pro VMware NSX
vSEC pro VMware NSX
 
Assuring VNF image integrity and host sealing in telco cloud
Assuring VNF image integrity and host sealing in telco cloudAssuring VNF image integrity and host sealing in telco cloud
Assuring VNF image integrity and host sealing in telco cloud
 
vSEC pro CISCO ACI
vSEC pro CISCO ACIvSEC pro CISCO ACI
vSEC pro CISCO ACI
 
Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018
Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018
Edge Orchestration & Federated Kubernetes Clusters - Open Networking Summit 2018
 
SDN/NFV architecture vision and reality
SDN/NFV architecture vision and reality SDN/NFV architecture vision and reality
SDN/NFV architecture vision and reality
 
Jak využít cloudu pro zvýšení bezpečnosti vašeho IT
Jak využít cloudu pro zvýšení bezpečnosti vašeho ITJak využít cloudu pro zvýšení bezpečnosti vašeho IT
Jak využít cloudu pro zvýšení bezpečnosti vašeho IT
 
Production-Grade Kubernetes With NGINX Ingress Controller
Production-Grade Kubernetes With NGINX Ingress ControllerProduction-Grade Kubernetes With NGINX Ingress Controller
Production-Grade Kubernetes With NGINX Ingress Controller
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
 
LKNOG3 - Telco Cloud Common – VIM/ CIM
LKNOG3 - Telco Cloud Common – VIM/ CIMLKNOG3 - Telco Cloud Common – VIM/ CIM
LKNOG3 - Telco Cloud Common – VIM/ CIM
 
Securing Micro Services in Cloud Foundry
Securing Micro Services in Cloud FoundrySecuring Micro Services in Cloud Foundry
Securing Micro Services in Cloud Foundry
 
Netronome Corporate Brochure
Netronome Corporate BrochureNetronome Corporate Brochure
Netronome Corporate Brochure
 
vArmour - Securing the Modern Data Centre
vArmour - Securing the Modern Data CentrevArmour - Securing the Modern Data Centre
vArmour - Securing the Modern Data Centre
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
 

Similar to 07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet

Fortinet & VMware integration
Fortinet & VMware integrationFortinet & VMware integration
Fortinet & VMware integration
VMUG IT
 
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSXPLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
PROIDEA
 
Software defined security-framework_final
Software defined security-framework_finalSoftware defined security-framework_final
Software defined security-framework_final
Lan & Wan Solutions
 
VMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use casesVMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use cases
Angel Villar Garea
 
Secure AWS with Fortinet Security Fabric.pptx
Secure AWS with Fortinet Security Fabric.pptxSecure AWS with Fortinet Security Fabric.pptx
Secure AWS with Fortinet Security Fabric.pptx
Yitao Cen
 
Threat Landscape for Education
Threat Landscape for EducationThreat Landscape for Education
Threat Landscape for Education
ColloqueRISQ
 
2022 Q1 Webinar Securite du Cloud public (1).pdf
2022 Q1 Webinar Securite du Cloud public (1).pdf2022 Q1 Webinar Securite du Cloud public (1).pdf
2022 Q1 Webinar Securite du Cloud public (1).pdf
YounesChafi1
 
04 vsx power-r65
04 vsx power-r6504 vsx power-r65
04 vsx power-r65
Richard Cove
 
Fortinet Tanıtım
Fortinet TanıtımFortinet Tanıtım
Fortinet Tanıtım
Güney Bilişim
 
Fortigate fortiwifi-80f-series
Fortigate fortiwifi-80f-seriesFortigate fortiwifi-80f-series
Fortigate fortiwifi-80f-series
Julian Ernesto Martinez Oliva
 
GAMO VMware vCloud Air
GAMO VMware vCloud AirGAMO VMware vCloud Air
GAMO VMware vCloud Air
GAMO a.s.
 
LOAD 2014-Prezentare BitDefender
LOAD 2014-Prezentare BitDefenderLOAD 2014-Prezentare BitDefender
LOAD 2014-Prezentare BitDefenderSilviu Cojocaru
 
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_ShahzadSEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_Shahzadshezy22
 
VMware-vShield-Presentation-pp-en-Dec10.pptx
VMware-vShield-Presentation-pp-en-Dec10.pptxVMware-vShield-Presentation-pp-en-Dec10.pptx
VMware-vShield-Presentation-pp-en-Dec10.pptx
Abasse KPEGOUNI
 
VMware vShield - Overview
VMware vShield - OverviewVMware vShield - Overview
VMware vShield - Overview
Irsandi Hasan
 
FortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptxFortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptx
NuttapolMix
 
fortigate-600f-series pdf manual routeur
fortigate-600f-series pdf manual routeurfortigate-600f-series pdf manual routeur
fortigate-600f-series pdf manual routeur
rezkellahhichem
 
VMware overview presentation by alamgir hossain
VMware overview presentation by alamgir hossainVMware overview presentation by alamgir hossain
VMware overview presentation by alamgir hossain
ALAMGIR HOSSAIN
 
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – BarracudaProtección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Plain Concepts
 

Similar to 07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet (20)

Fortinet & VMware integration
Fortinet & VMware integrationFortinet & VMware integration
Fortinet & VMware integration
 
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSXPLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
PLNOG19 - Michał Taterka - FortiGate-VMX - integracja z VMware NSX
 
Software defined security-framework_final
Software defined security-framework_finalSoftware defined security-framework_final
Software defined security-framework_final
 
VMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use casesVMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use cases
 
Secure AWS with Fortinet Security Fabric.pptx
Secure AWS with Fortinet Security Fabric.pptxSecure AWS with Fortinet Security Fabric.pptx
Secure AWS with Fortinet Security Fabric.pptx
 
Threat Landscape for Education
Threat Landscape for EducationThreat Landscape for Education
Threat Landscape for Education
 
2022 Q1 Webinar Securite du Cloud public (1).pdf
2022 Q1 Webinar Securite du Cloud public (1).pdf2022 Q1 Webinar Securite du Cloud public (1).pdf
2022 Q1 Webinar Securite du Cloud public (1).pdf
 
Forti os ngfw
Forti os ngfwForti os ngfw
Forti os ngfw
 
04 vsx power-r65
04 vsx power-r6504 vsx power-r65
04 vsx power-r65
 
Fortinet Tanıtım
Fortinet TanıtımFortinet Tanıtım
Fortinet Tanıtım
 
Fortigate fortiwifi-80f-series
Fortigate fortiwifi-80f-seriesFortigate fortiwifi-80f-series
Fortigate fortiwifi-80f-series
 
GAMO VMware vCloud Air
GAMO VMware vCloud AirGAMO VMware vCloud Air
GAMO VMware vCloud Air
 
LOAD 2014-Prezentare BitDefender
LOAD 2014-Prezentare BitDefenderLOAD 2014-Prezentare BitDefender
LOAD 2014-Prezentare BitDefender
 
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_ShahzadSEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
 
VMware-vShield-Presentation-pp-en-Dec10.pptx
VMware-vShield-Presentation-pp-en-Dec10.pptxVMware-vShield-Presentation-pp-en-Dec10.pptx
VMware-vShield-Presentation-pp-en-Dec10.pptx
 
VMware vShield - Overview
VMware vShield - OverviewVMware vShield - Overview
VMware vShield - Overview
 
FortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptxFortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptx
 
fortigate-600f-series pdf manual routeur
fortigate-600f-series pdf manual routeurfortigate-600f-series pdf manual routeur
fortigate-600f-series pdf manual routeur
 
VMware overview presentation by alamgir hossain
VMware overview presentation by alamgir hossainVMware overview presentation by alamgir hossain
VMware overview presentation by alamgir hossain
 
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – BarracudaProtección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
 

More from VMUG IT

04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri
VMUG IT
 
03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam
VMUG IT
 
02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino
VMUG IT
 
01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto
VMUG IT
 
07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini
VMUG IT
 
06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli
VMUG IT
 
05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers
VMUG IT
 
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
VMUG IT
 
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
VMUG IT
 
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
VMUG IT
 
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
VMUG IT
 
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
VMUG IT
 
00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro
VMUG IT
 
Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017 Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017
VMUG IT
 
Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon
VMUG IT
 
Gianni Resti
Gianni Resti  Gianni Resti
Gianni Resti
VMUG IT
 
Frank Denneman keynote
Frank Denneman keynoteFrank Denneman keynote
Frank Denneman keynote
VMUG IT
 
Vmug 2017 Guido Frabotti
Vmug 2017 Guido FrabottiVmug 2017 Guido Frabotti
Vmug 2017 Guido Frabotti
VMUG IT
 
Claudio Panerai - Achab
Claudio Panerai - Achab Claudio Panerai - Achab
Claudio Panerai - Achab
VMUG IT
 
Tintri Clouditalia - vmugit 2017 usercon
Tintri Clouditalia - vmugit 2017 userconTintri Clouditalia - vmugit 2017 usercon
Tintri Clouditalia - vmugit 2017 usercon
VMUG IT
 

More from VMUG IT (20)

04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri
 
03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam
 
02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino
 
01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto
 
07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini
 
06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli
 
05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers
 
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
 
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
 
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
 
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
 
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
 
00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro
 
Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017 Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017
 
Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon
 
Gianni Resti
Gianni Resti  Gianni Resti
Gianni Resti
 
Frank Denneman keynote
Frank Denneman keynoteFrank Denneman keynote
Frank Denneman keynote
 
Vmug 2017 Guido Frabotti
Vmug 2017 Guido FrabottiVmug 2017 Guido Frabotti
Vmug 2017 Guido Frabotti
 
Claudio Panerai - Achab
Claudio Panerai - Achab Claudio Panerai - Achab
Claudio Panerai - Achab
 
Tintri Clouditalia - vmugit 2017 usercon
Tintri Clouditalia - vmugit 2017 userconTintri Clouditalia - vmugit 2017 usercon
Tintri Clouditalia - vmugit 2017 usercon
 

Recently uploaded

FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Ramesh Iyer
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi
Fwdays
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
CatarinaPereira64715
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
DianaGray10
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 

Recently uploaded (20)

FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 

07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet

  • 1. © Copyright Fortinet Inc. All rights reserved. Le nuove sfide della cyber security su infrastrutture software defined. Advanced Security in Vmware NSX with FortiGate-VMX Antonio Gentile agentile@fortinet.com Systems Engineer, Italy
  • 2. Agenda ➢ Fortinet Security Fabric ➢ Fortinet Cloud & SDN Vision ➢ FortiGate-VMX Integration with NSX ➢ Key Points and Licensing ➢ Q&A
  • 3. ‹N› 2018 Fortinet Security Fabric A Security Architecture that provides: BROAD Visibility & Protection of the Digital Attack Surface INTEGRATED Detection of Advanced Threats AUTOMATED Response & Continuous Trust Assessment Delivered as: Appliance Virtual Machine Hosted Cloud Software
  • 4. ‹N› 2018 Fortinet Solutions Network Security Multi-Cloud Security Endpoint Security Email Security Web Application Security Secure Unified Access Advanced Threat Protection Management - Analytics FortiGate Enterprise Firewall FortiGate Cloud Firewall Network Security FortiClient EPP FortiWeb Web Application Firewall FortiMail Secure Email Gateway FortiSandbox Advanced Threat Protection FortiAnalyzer Central Logging /Reporting FortiManager Central Security Management FortiSIEM Security Information & Event Management FortiGate Virtual Firewall Network Security FortiAP Wireless Infrastructure FortiSwitch Switching InfrastructureSWG SD-WAN IPS
  • 5. Agenda ➢ Fortinet Cloud & SDN Vision ➢ FortiGate-VMX Integration with NSX ➢ Key Points And Licensing ➢ Q&A
  • 6. ‹N› Virtualization SDN Cloud (IaaS) Cloud (SaaS) Fortinet Cloud & SDN Vision Physical & Virtual Security Appliances FortiGate FortiManagerFortiSandbox FortiAnalyzer FortiWeb FortiADC FortiDDoSFortiWifiFortiMail vSpher e XenServe r Hyper-V NSX
  • 7. ‹N› Fortinet Programmable Networking Partnership Ecosystem Platform Extensibility Orchestration Platforms Programmable Switching vCNS certified NSX Partner program NSX Manager Full NSX Centralized Policy & Analytics ACI
  • 8. ‹N› SDx Physical/Virtual/SDN/Cloud North South East West Hybrid Cloud Public Cloud Private Cloud FortiAnalyzer FortiManager FortiWeb FortiGate VirtualCloud VirtualCloud CLOUD SECURITY FortiCore FortiGate VMX FortiOSFortiGuardFortiASIC 5.4 Security for the Cloud
  • 9. Agenda ➢ Fortinet Cloud & SDN Vision ➢ FortiGate-VMX Integration with NSX ➢ Key Points And Licensing ➢ Q&A
  • 10. ‹N› NSX Platform Network and Security Virtualization Components Cloud Consumption (CMP) NSX Manager NSX Controller Data Plane • Self Service Portal • VMware vRealize Automation, vCloud Director, OpenStack, Custom CMS • High-performance data plane • Scale-out distributed forwarding model • Single configuration portal • REST API entry-point • Manages logical networks • Run-time state • Scale out, HA • Separation of control and data plane ESXi, KVM, Xen Distributed Services • Logical Switch • Distributed Logical Router • Firewall • Load Balancer HW VTEPNSX Edge
  • 11. ‹N› VMWare-NSX Architecture Physical Host NSX vSwitch VM VM VM NSX vSwitch VM User Space VM VM Hypervisor User Space Hypervisor Virtual Network Cluster Controller Cloud Mgt Platform Simplified IP Backplane No VLANs, No ACLs, No Firewall Rules Existing Physical Network SrcIP = Hypervisor-1 DstIP = Hypervisor-2 ???????
  • 12. ‹N› Added Value of Security integration in SDDC Requirements Solution Visibility on Guest to Guest traffic Micro-Segmentation and Zero Trust Control of ‘east-west’ traffic, Inter and Intra VM security, Logical Security Zone (multi-tier) Not just firewall, but advanced features
  • 13. ‹N› Manage Components for NSX Integration Mandatory Components for NSX Integration Third Party Solution Service Manager Service Appliance ESXi Hosts VMware vCenter Server V5.5 or v6.0 VMware vSphere (Enterprise Plus license v5.5 or v6.0) REST API Fortinet Solution FortiGate-VMX Service Manager FortiGate-VMX Security Appliance
  • 14. ‹N› FortiGate-VMX and NSX Integration/Interactions dvSwitch FGT-VMX FGT-VMX Push polic y synch roniz ation to all Forti Gate- VMX deplo yed in cluste r 7 Register Fortinet as security service with NSX Manager1 Auto- deploy FortiGat e-VMX to all hosts in security cluster 2 FortiGat e-VMX connects with FortiGat e-VMX Service Manager 3 License verification & configuration synchronization with FortiGate-VMX 4 NSX Secur ity Polic y define netwo rk intros pectio n rules to redire ct traffic 5 Real-time updates of object database6 FortiGate-VMX Service Manager
  • 15. ‹N› FortiGate-VMX and NSX Manager Setup Adding VMware NSX details on FortiGate Service Manager FortiGate VMX Service on NSX Manager
  • 16. ‹N› FGT-VMX imports NSX Security Groups ● On NSX create Security Groups and assign “Objects” Security Groups defined on NSX are automatically created on FGT-VMX
  • 17. ‹N› FGT-VMX imports NSX Security Groups ● On NSX create Security Groups and assign “Objects” ● FortiGate VMX automatically imports the Security Groups as a dynamic firewall addresses with the VMs IP address Security Groups defined on NSX are automatically created on FGT-VMX
  • 18. ‹N› NSX Security Group definition and usage Server SG FortiGate-VMX NSX Manager Service Groups created on NSX Manager automatically get sent to the FortiGate-VMX and are available for Policy Creation Policy Created on FortiGate- VMX using Exchanged Security Group
  • 19. ‹N› VMware Kernel dvSwitch FGT-VMX and VMWARE NSX Filter Driver Interaction 1 Define NGFW Firewall Policies 2 Sync config on FGT-VMX FGT-VMX NetX NSX Filter Driver int ext Packet Flow 1. From VM to NSX Filter Driver 2. NSX Filter Driver Forward to Third party Solution (FGT-VMX) 3. FGT-VMX applies Security and sends packet back to NSX Filter Driver 4. NSX Filter Driver can do service chaining or send packet to destination FortiGate-VMX Service Manager A B
  • 20. ‹N› Policy Creation ● Firewall Policy is now IP independent Policy created based on Security Group Internal External Distributed Virtual Switch
  • 21. ‹N› VMWare-NSX Architecture with FortiGate-VMX Physical Host NSX vSwitch VM VM VM NSX vSwitch VM User Space VM VM Hypervisor User Space Hypervisor Virtual Network Cluster Controller Cloud Mgt Platform Existing Physical Network Anti-botnet Intrusion Prevention Antivirus Application Control Web Application Firewall Web Filtering FortiAnalyzer Logging & Reporting FortiSandbox ATP FortiGate-VMX Service Manager FortiGate-VMX Security Appliance FortiGate-VMX Security Appliance
  • 22. Agenda ➢ Fortinet Cloud & SDN Vision ➢ FortiGate-VMX Integration with NSX ➢ License Model and Key Points ➢ Q&A
  • 23. ‹N› FortiGate-VMX License Model ● One license for the FortiGate-VMX Service Manager ● Simple license based on number of FGT-VMX Security Appliance deployed » One FortiGate-VMX license per ESXi host » No limits placed on resources (virtual or hardware), nor number of protected VM workloads Hypervisor with 2 sockets Hypervisor with 1 socket 2 FGT-VMX Licenses 3 FGT-VMX Licenses Hypervisor with 2 sockets Central license server with auto decrement
  • 24. ‹N› ● Utilizing Fortinet Virtual Domains (VDOMs) • Segment a single FortiGate-VMX Security Node to service different flows completely segregated from each other. • Greater flexibility for both Enterprise and Managed Service Providers as seen in the sample Security Policy configurations below. FortiGate-VMX VDOMs
  • 25. ‹N› Migration (vMotion) Support ● Migration » Session handover done by VM is picked up by VMX Hypervisor with 2 sockets Hypervisor with 2 sockets Web-01 App- 01 SSH SSH
  • 26. ‹N› FortiGate-VMX Key Points ● Real Multi-tenancy (VDOM) support ● Per Security Appliance instance Resource monitor ● Improved throughput for firewall and security functionality using TSO (TCP Segment Offload) ● Service Manager to Security Appliance instantaneous update of the security policies ● Automatic creation of NSX Security Groups in FortiGate-VMX Service Manager ● Central license server with auto decrement ● OVF footprint < 40 MB ● License independent from physical or virtual resources ● NSX integrated upgrade process ● Real-time FortiGuard updates
  • 27. Agenda ➢ Fortinet Cloud & SDN Vision ➢ FortiGate-VMX Integration with NSX ➢ Key Points And Licensing ➢ Q&A