SlideShare a Scribd company logo
© 2016 VMware Inc. All rights reserved.
NSX
La Virtualizzazione di Rete e il Futuro della Sicurezza
Luca Morelli
Sr. Systems Engineer @ VMware
Qualche Info sullo Speaker…
© 2016 VMware Inc. All rights reserved. 2
•  Nato a Catanzaro, la città delle 3 V, circa 37 anni fà
•  Ingegnere Informatico – Università di Rende
•  Nell’IT da circa 15 anni – Esperienze in Spagna, Francia, Olanda e altri paesi
•  Iniziato con lo sviluppo software quindi prevendita da circa 8 anni
•  Quasi 7 anni con un vendor di rete “fisica”
•  “Virtualizzato” dal Gennaio 2015
•  Appassionato di subacquea, apnea, arrampicata e della mia splendida compagna
•  Aggiungetemi su LinkedIn (Non solo NSX)
Agenda
3
1 La Visione di VMware nel Software Defined Data Center
2 Introduzione alla Virtualizzazione di Rete con NSX
3 Il Paradigma della Micro-Segmentazione
4 Principali Casi d’Uso
© 2016 VMware Inc. All rights reserved.
Software-Defined Data Center (SDDC)
The Foundation of the New Model of IT
© 2016 VMware Inc. All rights reserved. 4
Any
Application
One
Cloud
Any
Device
Build-Your-Own
Converged
Infrastructure
Hyper-Converged
Infrastructure
Software-Defined Data Center
Cloud Management
Compute Network Storage
Extensibility
Traditional
Applications
Modern, Cloud
Applications
Business Mobility: Applications | Devices | Content
Hybrid Cloud
PRIVATE
Your
Data Center
PUBLIC
vCloud Air
MANAGED
vCloud Air
Network
Compute Virtualization Abstraction Layer
The Network Is a Barrier to Software Defined Data Center!!
Physical
Network
Software Defined Data Center
•  Provisioning is slow
•  Mobility is limited
•  Hardware dependent
•  Operationally intensive
5
Servers
© 2016 VMware Inc. All rights reserved.
NSX - Distributed Services in the Hypervisor
Applications
Virtual
Machines
Virtual
Networks
Virtual
Storage
Data Center Virtualization
Location Independence
Software
Hardware
L2 Switching
L3 Routing
Firewalling/ACLs
Load Balancing
Automated operational model
of the SDDC
Network & Security Services
Now in the Hypervisor
Pooled compute, network and storage
capacity; Vendor independent, best
price/perf; Simplified config and mgt.
Compute
Capacity
Network
Capacity
Storage
Capacity
© 2016 VMware Inc. All rights reserved.
NSX Logical Switching
•  Per Application/Multi-tenant segmentation
•  VM Mobility requires L2 everywhere
•  Large L2 Physical Network Sprawl – STP
Issues
•  HW Memory (MAC, FIB) Table Limits
•  Scalable Multi-tenancy across data center
•  Enabling L2 over L3 Infrastructure
•  Overlay Based with VXLAN, etc.
•  Logical Switches span across Physical Hosts
and Network Switches
Challenges Benefits
VMware	NSX	
Logical Switch 1 Logical Switch 2 Logical Switch 3
Generic IP Fabric
Host A
vSphere
Distributed Switch
NSX and VXLAN
8
dvUplink-PG
Logical SW A
VM1
dvPG-VTEP
VXLAN
VTEP
•  VXLAN can be seen as service on the host
•  VXLAN uses a vmknic and implements a VXLAN Virtual
Tunnel End Point (VTEP) functionality
•  Depending on the uplink configuration, there might be
several VTEPs on a host
–  A single dvPortGroup is created for all VTEPs
•  A logical switch is a L2 broadcast domain implemented
using VXLAN
–  A dvPortGroup is created for each logical switch
Generic IP Fabric
Host A Host B
vSphere Distributed Switch
Traffic Flowing on a VXLAN Backed VDS
9
•  In this setup, VM1 and VM2 are on different hosts but belong to the same logical switch
•  A VXLAN tunnel is established between the two hosts
dvUplink-PG
Logical SW A
VM1
dvUplink-PG
dvPG-VTEP
VTEP
dvPG-VTEP
VTEP
VXLAN Tunnel
Logical SW A
VM2
Host BHost A
vSphere Distributed Switch
Traffic Flowing on a VXLAN Backed VDS
10
•  Assume VM1 sends some traffic to VM2:
dvUplink-PG
Logical SW A
VM1
dvUplink-PG
dvPG-VTEP
VTEP
dvPG-VTEP
VTEP
Logical SW A
VM2L2 frame L2 frame
VM1 sends L2 frame to
local VTEP1
VTEP adds VXLAN, UDP
& IP headers2 Physical Transport
Network forwards as a
regular IP packet
3 Destination Hypervisor
VTEP decapsulates frame4 L2 frame delivered
to VM25
Generic IP Fabric
VXLAN Tunnel
IP/UDP/VXLAN L2 frame
NSX Routing: Distributed, Feature-Rich
•  Physical Infrastructure Scale
Challenges – Routing Scale
•  VM Mobility is a challenge
•  Multi-Tenant Routing Complexity
•  Traffic hair-pins
Challenges
•  Distributed Routing in Hypervisor
•  Dynamic, API based Configuration
•  Full featured – OSPF, BGP, IS-IS
•  Logical Router per Tenant
•  Routing Peering with Physical Switch
Benefits
SCALABLE ROUTING – Simplifying Multi-tenancy
L2
L2
Tenant A
Tenant B
L2
L2
L2
Tenant C
L2
L2
L2
CMP
NSX vSwitch
With NSXBefore NSX
Default Gateway
UCS Fabric A UCS Fabric B
UCS Blade 1
vswitch
6 wire hops 6 wire hops
UCS Fabric A UCS Fabric B
UCS Blade 1 UCS Blade 2
vswitch vswitch
UCS Fabric A UCS Fabric B
0 wire hops
UCS Fabric A UCS Fabric B
UCS Blade 1 UCS Blade 2
With NSXBefore NSX
East-West Routing / Same host East-West Routing / Host to host
2 wire hops
NSX vSwitch
UCS Blade 1
The Advantage of Distributing Services
Routing - more efficient networking, fewer hops
Default Gateway Default Gateway Default Gateway
© 2016 VMware Inc. All rights reserved.
NSX Edge Services Gateway: Integrated Network Services
….
Firewall
Load Balancer
VPN
Routing/NAT
DHCP/DNS relayDDI
VM	 VM	 VM	 VM	 VM	
•  Integrated L3 – L7 services
•  Virtual appliance model to provide
rapid deployment and scale-out
Overview
•  Real time service instantiation
•  Support for dynamic service
differentiation per tenant/application
•  Uses x86 compute capacity
Benefits
VLAN 20
Edge Uplink
External Network
Physical Router
Web1 App1 DB1 Webn Appn DBn
NSX Edge
VXLAN 5020
Transit Link
Distributed
Routing
RoutingPeering
14
How it looks like a Basic NSX Topology
…
High Scale Multi Tenant Topology
External Network
Tenant 1
Web Logical
Switch App Logical Switch DB Logical Switch
…
Web Logical
Switch App Logical Switch DB Logical Switch
Tenant NSX Edge
Services Gateway
NSX Edge X-Large
(Route Aggregation Layer)
Tenant NSX Edge
Services Gateway
VXLAN Uplinks (or
VXLAN Trunk)
VXLAN Uplinks (or
VXLAN Trunk)
VXLAN 5100
Transit
15
NSX provides Highest Level of Visibility in the Network
16
Log Insight
NSX content pack
Native
capabilities
Integration with
partner ecosystem
NSX API
Syslog
IPFIX
Port mirroring
SNMP
Traceflow
And more.
vRealize
Operations Suite
How do I manage NSX ?
17
Traditional approaches to Micro-Segmentation
18
Centralized
firewalls
•  Create firewall rules before provisioning
•  Update firewall rules when moving or changing
•  Delete firewall rules when app decommissioned
•  Problem increases with more east-west traffic
Internet
Internet
How an SDDC approach makes Micro-Segmentation feasible
19
Security policy
Perimeter
firewalls
Cloud
Management
Platform
NSX Distributed Firewalling
•  Centralized Firewall Model
•  Static Configuration
•  IP Address based Rules
•  40 Gbps per Appliance
•  Lack of visibility with encapsulated traffic
•  Distributed at Hypervisor Level
•  Dynamic, API based Configuration
•  VM Name, VC Objects, Identity-based Rules
•  Line Rate ~20 Gbps per host
•  Full Visibility to encapsulated traffic
Challenges Benefits
PHYSICAL SECURITY MODEL DISTRIBUTED FIREWALLING
Firewall Mgmt
VMware	NSX	
API
CMP
NSX Distributed Firewall Enablement
DFW enforces rules at
vNIC layer:
•  DFW independent of
transport network (VLAN
or VXLAN)
•  All VM ingress and egress
packets are subject to
DFW processing
•  Security Policy
independent of
VM location
•  V-to-V and P-to-V support
21
DFW has NO Dependancy on Network Topology !
VXLAN 5001
vSphere Host
VM1
MAC1
IP1
VTEP IP: 10.20.10.10
vSphere Distributed Switch
vSphere Host
VM2
VTEP IP: 10.20.10.11
VM3
MAC2
IP2
MAC3
IP3
DFW Policy Rules:
Source Destination Service Action
VM1 VM2, VM3 TCP port 123 Allow
VM1 VM2, VM3 any Block
DVS port-group
vSphere Host
VM1
MAC1
IP1
VTEP IP: 10.20.10.10
vSphere Distributed Switch
vSphere Host
VM2
VTEP IP: 10.20.10.11
VM3
MAC2
IP2
MAC3
IP3
DFW Policy Rules:
Source Destination Service Action
VM1 VM2, VM3 TCP port 123 Allow
VM1 VM2, VM3 any Block
VLAN 501 VLAN 501 VLAN 501
VXLAN 5001
Logical Switch
VXLAN 5001
CONFIDENTIAL
NSX DFW Policy Objects
•  Policy rules construct:
•  Rich dynamic container based rules apart from just IP addresses:
VC containers
•  Clusters
•  datacenters
•  Portgroups
•  VXLAN
VM containers
•  VM names
•  VM tags
•  VM attributes
Identity
•  AD Groups
IPv6 compliant
•  IPv6 address
•  IPv6 sets
Services
•  Protocol
•  Ports
•  Custom
IPv6 Services
Choice of PEP (Policy
Enforcement Point)
•  Clusters
•  VXLAN
•  vNICs
•  …
Rule ID Rule Name Source Destination Service Action Applied To
Action
•  Allow
•  Block
•  Reject
22
23
Configure Policies with Security Groups
Select elements to uniquely identify
application workloads
Use attributes to create Security Groups Apply policies to security groups
1 2 3
ABC
DEF
Group
XYZ
App 1
OS: Windows 8
TAG: “Production”
§  Enforce policy based on logical constructs
§  Reduce configuration errors
§  Policy follows VM, not IP
§  Reduce rule sprawl and complexity
Use security groups to abstract policy from application workloads.
Group
XYZ
Policy 1
“IPS for Desktops”
“FW for Desktops”
Policy 2
“AV for Production”
“FW for Production”
Element type
Static Dynamic
Data center
Virtual net
Virtual machine
vNIC
VM name
OS type
User ID
Security tag
Micro-segmentation simplifies network security
§  Each VM can now be its own perimeter
§  Policies align with logical groups
§  Prevents threats from spreading
App
DMZ
Services
DB
Perimeter
firewall
AD NTP DHCP DNS CERT
Inside
firewall
Finance EngineeringHR
WAN
Internet
Compute Cluster Compute Cluster
Perimeter
Firewall
(Physical)
NSX
EDGE
Service
Gateway
Compute Cluster
SDDC (Software Defined DC)
DFW DFW DFW
DFW: E-W
NSX EDGE Service
Gateway positioned to
protect border of the
SDDC:
EDGE: North – South
traffic protection
NSX DFW positioned for
internal SDDC traffic
protection:
DFW: East – West
traffic protection
Physical
Virtual
Compute Cluster
EDGE:N-S
NSX Security in SDDC
25
Micro-segmentation in detail
SegmentationIsolation Advanced services
Controlled communication path within
a single network
•  Fine-grained enforcement of security
•  Security policies based on logical
groupings of VMs
Advanced services: addition of 3rd
party security, as needed by policy
•  Platform for including leading
security solutions
•  Dynamic addition of advanced
security to adapt to changing
security conditions
No communication path between
unrelated networks
•  No cross-talk between networks
•  Overlay technology assures networks
are separated by default
Third-Party Firewall, Network Security Options for
NSX Integration
Src Dst Action
ANY Shared Service Allow
Desktop WEB_GROUP Redirect to
3rd party
Platform for Distributed Services
Redirect via global rule to 3rd party
WEB_ GROUP
“Web Policy”
þ  Firewall – redirect to 3rd
party
þ  3rd party – do deep packet
inspection
Redirect via policy template,
for reuse in automation
workflows
3rd party can program NSX
distributed firewall directly –
and set/get context to inform
policy
27
Example : Orchestrating Security Between Multiple Services
(Vulnerability Scan)
SG: QuarantineSG: Web Servers
1.Web Server VM running IIS is deployed, unknowingly having a vulnerability
2.Vulnerability Scan is initiated on web server (3rd party AV product)
3.VM is tagged in NSX Manager with the CVE and CVSS Score
4.NSX Manager associates the VM with the Quarantine (F/W Deny)
5.[Externally] Admin applies patches, 3rd party AV product re-scans VMs, clears tag
6.NSX Manager removes the VM from Quarantine ; VM returns to it’s normal duties
Services Services
Membership: Include VMs which have CVSS score >= 9Membership: Include VMs which have been provisioned as “WebServer”
NSX Manager
antivirus antivirus
NSX Partners and Service Categories
Application
Delivery Services
Physical-to-Virtual
Services Operations and Visibility Security
NSX Partner Extensions
http://www.vmware.com/products/nsx/resources.html
Ground-breaking use cases
30
Enterprises can often justify the cost of NSX through a single use case
Micro segmentation
DMZ anywhere
Secure end user
Security
IT automating IT
Multi-tenant
infrastructure
Developer cloud
IT automation
Disaster recovery
Metro pooling
Hybrid cloud
networking
Application continuity IT optimization
Server asset utilization
Price | performance
Hardware lifecycle
$
Use Case: Infrastructure Management with vRealize Automation
New Features
§  Simplified Multi-Tier App Deployment
§  Improved Connectivity
− Deployment of logical switches and networks
§  Enhanced Security
−  Intelligent placement of workloads in security groups
protected by firewalls
§  Increased Availability
−  Via deployment of NSX distributed
firewalls and load balancers
Benefits
§  Deliver secure, scalable, performing
application-specific infrastructure on-demand
Dynamically Provision and Decommission
NSX Logical Services
Use Case: Disaster recovery with NSX network virtualization
SAN SAN
10.0.30.21 10.0.30.21
Virtual Network
10.0.30/24
Virtual Network
10.0.30/24
NSX Controller NSX Controller
Snapshot
network
security
2b
1
Snapshot VM
Network and security
already exists
Recover
the VM
3
Physical network infrastructure Physical network infrastructure2a
Replicate
VM and storage
10.0.10/24 10.0.20/24
Step 1 & 2
(e.g VMware SRM)
32
Primary site Recovery Site
Use Case: A True Hybrid Cloud powered by VMware NSX
Local Data Center
InternetIPSec VPN
(vCloud Air Network)(vCloud Air Network)
vCloud Air
L2 VPN
Some Benefits:
•  L2VPN for DC Extension
•  Granular Network Security with Trust Groups
•  Bi-directional workload migration using
vSphere web client
33
Some Benefits:
•  Today with vCloud AIR
•  Tomorrow with Amazon AWS,
Azure, Google and other
Public Cloud Providers
NSX Vision: Driving NSX Everywhere
Managing Security and Connectivity for many Heterogeneous End Points
34
Automation
IT at the Speed
of Business
Security
Inherently Secure
Infrastructure
Application Continuity
Data Center
Anywhere
On-Premise Data Center
New app frameworks
Mobile Devices
(Airwatch)
Virtual Desktop
(VDI)
Branch offices
(Partner)
Internet of things
Public clouds
What’s Next…
VMware NSX
Hands-on Labs
labs.hol.vmware.com
35
Explore, Engage, Evolve
virtualizeyournetwork.com
Network Virtualization Blog
blogs.vmware.com/networkvirtualization
NSX Product Page
vmware.com/go/nsx
NSX Training & Certification
www.vmware.com/go/NVtraining
NSX Technical Resources
Reference Designs
vmware.com/products/nsx/resources
VMware NSX YouTube Channel
youtube.com/user/vmwarensx
VMware NSX Community
communities.vmware.com/community/vmtn/nsx
Play Learn Deploy
Thank you.

More Related Content

What's hot

The Future of Cloud Networking is VMware NSX
The Future of Cloud Networking is VMware NSXThe Future of Cloud Networking is VMware NSX
The Future of Cloud Networking is VMware NSX
Scott Lowe
 
VMUGbe 21 Filip Verloy
VMUGbe 21 Filip VerloyVMUGbe 21 Filip Verloy
VMUGbe 21 Filip Verloy
Filip Verloy
 
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld
 
Software Defined Networking (SDN) with VMware NSX
Software Defined Networking (SDN) with VMware NSXSoftware Defined Networking (SDN) with VMware NSX
Software Defined Networking (SDN) with VMware NSX
Zivaro Inc
 
NSX 9 Core Use Cases
NSX 9 Core Use CasesNSX 9 Core Use Cases
NSX 9 Core Use Cases
Kevin Groat
 
NSX-MH
NSX-MHNSX-MH
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld
 
Network Virtualization with VMware NSX
Network Virtualization with VMware NSXNetwork Virtualization with VMware NSX
Network Virtualization with VMware NSX
Scott Lowe
 
VMworld 2015: The Future of Network Virtualization with VMware NSX
VMworld 2015: The Future of Network Virtualization with VMware NSXVMworld 2015: The Future of Network Virtualization with VMware NSX
VMworld 2015: The Future of Network Virtualization with VMware NSX
VMworld
 
VMware NSX primer 2014
VMware NSX primer 2014VMware NSX primer 2014
VMware NSX primer 2014
Sanjay Basu
 
VMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined NetworkingVMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined Networking
Cumulus Networks
 
VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld 2013: Operational Best Practices for NSX in VMware Environments VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld
 
VMworld 2013: Advanced VMware NSX Architecture
VMworld 2013: Advanced VMware NSX Architecture VMworld 2013: Advanced VMware NSX Architecture
VMworld 2013: Advanced VMware NSX Architecture
VMworld
 
VMworld Europe 2014: Advanced Network Services with NSX
VMworld Europe 2014: Advanced Network Services with NSXVMworld Europe 2014: Advanced Network Services with NSX
VMworld Europe 2014: Advanced Network Services with NSX
VMworld
 
VMware NSX - Lessons Learned from real project
VMware NSX - Lessons Learned from real projectVMware NSX - Lessons Learned from real project
VMware NSX - Lessons Learned from real project
David Pasek
 
Self service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsxSelf service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsx
solarisyougood
 
VMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep DiveVMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep Dive
VMworld
 
VMworld 2014: Introduction to NSX
VMworld 2014: Introduction to NSXVMworld 2014: Introduction to NSX
VMworld 2014: Introduction to NSX
VMworld
 
VMware NSX 101: What, Why & How
VMware NSX 101: What, Why & HowVMware NSX 101: What, Why & How
VMware NSX 101: What, Why & How
Aniekan Akpaffiong
 
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_ShahzadSEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
shezy22
 

What's hot (20)

The Future of Cloud Networking is VMware NSX
The Future of Cloud Networking is VMware NSXThe Future of Cloud Networking is VMware NSX
The Future of Cloud Networking is VMware NSX
 
VMUGbe 21 Filip Verloy
VMUGbe 21 Filip VerloyVMUGbe 21 Filip Verloy
VMUGbe 21 Filip Verloy
 
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
 
Software Defined Networking (SDN) with VMware NSX
Software Defined Networking (SDN) with VMware NSXSoftware Defined Networking (SDN) with VMware NSX
Software Defined Networking (SDN) with VMware NSX
 
NSX 9 Core Use Cases
NSX 9 Core Use CasesNSX 9 Core Use Cases
NSX 9 Core Use Cases
 
NSX-MH
NSX-MHNSX-MH
NSX-MH
 
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
 
Network Virtualization with VMware NSX
Network Virtualization with VMware NSXNetwork Virtualization with VMware NSX
Network Virtualization with VMware NSX
 
VMworld 2015: The Future of Network Virtualization with VMware NSX
VMworld 2015: The Future of Network Virtualization with VMware NSXVMworld 2015: The Future of Network Virtualization with VMware NSX
VMworld 2015: The Future of Network Virtualization with VMware NSX
 
VMware NSX primer 2014
VMware NSX primer 2014VMware NSX primer 2014
VMware NSX primer 2014
 
VMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined NetworkingVMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined Networking
 
VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld 2013: Operational Best Practices for NSX in VMware Environments VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld 2013: Operational Best Practices for NSX in VMware Environments
 
VMworld 2013: Advanced VMware NSX Architecture
VMworld 2013: Advanced VMware NSX Architecture VMworld 2013: Advanced VMware NSX Architecture
VMworld 2013: Advanced VMware NSX Architecture
 
VMworld Europe 2014: Advanced Network Services with NSX
VMworld Europe 2014: Advanced Network Services with NSXVMworld Europe 2014: Advanced Network Services with NSX
VMworld Europe 2014: Advanced Network Services with NSX
 
VMware NSX - Lessons Learned from real project
VMware NSX - Lessons Learned from real projectVMware NSX - Lessons Learned from real project
VMware NSX - Lessons Learned from real project
 
Self service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsxSelf service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsx
 
VMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep DiveVMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep Dive
 
VMworld 2014: Introduction to NSX
VMworld 2014: Introduction to NSXVMworld 2014: Introduction to NSX
VMworld 2014: Introduction to NSX
 
VMware NSX 101: What, Why & How
VMware NSX 101: What, Why & HowVMware NSX 101: What, Why & How
VMware NSX 101: What, Why & How
 
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_ShahzadSEC8022_Securing_SDDC_NSX_Hammad_Shahzad
SEC8022_Securing_SDDC_NSX_Hammad_Shahzad
 

Similar to NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza

VMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep DiveVMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep Dive
VMworld
 
VMware nsx network virtualization tool
VMware nsx network virtualization toolVMware nsx network virtualization tool
VMware nsx network virtualization tool
Daljeet Singh Randhawa
 
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
VMworld
 
VMUG - NSX Architettura e Design
VMUG - NSX Architettura e DesignVMUG - NSX Architettura e Design
VMUG - NSX Architettura e Design
VMUG IT
 
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSXOVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud
 
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
nvirters
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
Cisco Canada
 
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
OpenStack Korea Community
 
Reference design for v mware nsx
Reference design for v mware nsxReference design for v mware nsx
Reference design for v mware nsx
solarisyougood
 
VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...
VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...
VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...
VMworld
 
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
VMworld
 
VMworld 2013: Deploying VMware NSX Network Virtualization
VMworld 2013: Deploying VMware NSX Network Virtualization VMworld 2013: Deploying VMware NSX Network Virtualization
VMworld 2013: Deploying VMware NSX Network Virtualization
VMworld
 
A consolidated virtualization approach to deploying distributed cloud networks
A consolidated virtualization approach to deploying distributed cloud networksA consolidated virtualization approach to deploying distributed cloud networks
A consolidated virtualization approach to deploying distributed cloud networks
Aruba, a Hewlett Packard Enterprise company
 
Understanding and deploying Network Virtualization
Understanding and deploying Network VirtualizationUnderstanding and deploying Network Virtualization
Understanding and deploying Network Virtualization
SDN Hub
 
Operators experience and perspective on SDN with VLANs and L3 Networks
Operators experience and perspective on SDN with VLANs and L3 NetworksOperators experience and perspective on SDN with VLANs and L3 Networks
Operators experience and perspective on SDN with VLANs and L3 Networks
Jakub Pavlik
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
nvirters
 
Open stack networking_101_update_2014-os-meetups
Open stack networking_101_update_2014-os-meetupsOpen stack networking_101_update_2014-os-meetups
Open stack networking_101_update_2014-os-meetups
yfauser
 
VMworld 2013: An Introduction to Network Virtualization
VMworld 2013: An Introduction to Network Virtualization VMworld 2013: An Introduction to Network Virtualization
VMworld 2013: An Introduction to Network Virtualization
VMworld
 
Understanding network and service virtualization
Understanding network and service virtualizationUnderstanding network and service virtualization
Understanding network and service virtualization
SDN Hub
 
Design and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsDesign and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANs
Fab Fusaro
 

Similar to NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza (20)

VMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep DiveVMworld 2015: VMware NSX Deep Dive
VMworld 2015: VMware NSX Deep Dive
 
VMware nsx network virtualization tool
VMware nsx network virtualization toolVMware nsx network virtualization tool
VMware nsx network virtualization tool
 
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
 
VMUG - NSX Architettura e Design
VMUG - NSX Architettura e DesignVMUG - NSX Architettura e Design
VMUG - NSX Architettura e Design
 
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSXOVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
 
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
 
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
 
Reference design for v mware nsx
Reference design for v mware nsxReference design for v mware nsx
Reference design for v mware nsx
 
VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...
VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...
VMworld 2014: Advanced Topics & Future Directions in Network Virtualization w...
 
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
 
VMworld 2013: Deploying VMware NSX Network Virtualization
VMworld 2013: Deploying VMware NSX Network Virtualization VMworld 2013: Deploying VMware NSX Network Virtualization
VMworld 2013: Deploying VMware NSX Network Virtualization
 
A consolidated virtualization approach to deploying distributed cloud networks
A consolidated virtualization approach to deploying distributed cloud networksA consolidated virtualization approach to deploying distributed cloud networks
A consolidated virtualization approach to deploying distributed cloud networks
 
Understanding and deploying Network Virtualization
Understanding and deploying Network VirtualizationUnderstanding and deploying Network Virtualization
Understanding and deploying Network Virtualization
 
Operators experience and perspective on SDN with VLANs and L3 Networks
Operators experience and perspective on SDN with VLANs and L3 NetworksOperators experience and perspective on SDN with VLANs and L3 Networks
Operators experience and perspective on SDN with VLANs and L3 Networks
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
Open stack networking_101_update_2014-os-meetups
Open stack networking_101_update_2014-os-meetupsOpen stack networking_101_update_2014-os-meetups
Open stack networking_101_update_2014-os-meetups
 
VMworld 2013: An Introduction to Network Virtualization
VMworld 2013: An Introduction to Network Virtualization VMworld 2013: An Introduction to Network Virtualization
VMworld 2013: An Introduction to Network Virtualization
 
Understanding network and service virtualization
Understanding network and service virtualizationUnderstanding network and service virtualization
Understanding network and service virtualization
 
Design and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsDesign and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANs
 

More from VMUG IT

04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri
VMUG IT
 
03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam
VMUG IT
 
02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino
VMUG IT
 
01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto
VMUG IT
 
07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini
VMUG IT
 
06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli
VMUG IT
 
05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers
VMUG IT
 
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
VMUG IT
 
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
VMUG IT
 
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
VMUG IT
 
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
VMUG IT
 
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
VMUG IT
 
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
VMUG IT
 
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
VMUG IT
 
00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro
VMUG IT
 
Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017 Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017
VMUG IT
 
Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon
VMUG IT
 
Gianni Resti
Gianni Resti  Gianni Resti
Gianni Resti
VMUG IT
 
Frank Denneman keynote
Frank Denneman keynoteFrank Denneman keynote
Frank Denneman keynote
VMUG IT
 
Vmug 2017 Guido Frabotti
Vmug 2017 Guido FrabottiVmug 2017 Guido Frabotti
Vmug 2017 Guido Frabotti
VMUG IT
 

More from VMUG IT (20)

04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri04 vmugit aprile_2018_raff_poltronieri
04 vmugit aprile_2018_raff_poltronieri
 
03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam03 vmugit aprile_2018_veeam
03 vmugit aprile_2018_veeam
 
02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino02 vmugit aprile_2018_il_restodelcarlino
02 vmugit aprile_2018_il_restodelcarlino
 
01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto01 vmugit aprile_2018_bologna_benvenuto
01 vmugit aprile_2018_bologna_benvenuto
 
07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini07 vmugit aprile_2018_massimiliano_moschini
07 vmugit aprile_2018_massimiliano_moschini
 
06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli06 vmugit aprile_2018_alessandro_tinivelli
06 vmugit aprile_2018_alessandro_tinivelli
 
05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers05 vmugit aprile_2018_7_layers
05 vmugit aprile_2018_7_layers
 
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
07 - VMUGIT - Lecce 2018 - Antonio Gentile, Fortinet
 
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
 
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
05 - VMUGIT - Lecce 2018 - Raff Poltronieri, CloudItalia
 
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
 
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
03 - VMUGIT - Lecce 2018 - Massimiliano Mortillaro, Tech Unplugged
 
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
02 - VMUGIT - Lecce 2018 - Enrico Signoretti, OpenIO
 
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
01 - VMUGIT - Lecce 2018 - Fabio Rapposelli, VMware
 
00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro00 - VMUGIT - Lecce 2018 - Intro
00 - VMUGIT - Lecce 2018 - Intro
 
Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017 Luca dell'oca - italian vmug usercon 2017
Luca dell'oca - italian vmug usercon 2017
 
Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon Luc Dekens - Italian vmug usercon
Luc Dekens - Italian vmug usercon
 
Gianni Resti
Gianni Resti  Gianni Resti
Gianni Resti
 
Frank Denneman keynote
Frank Denneman keynoteFrank Denneman keynote
Frank Denneman keynote
 
Vmug 2017 Guido Frabotti
Vmug 2017 Guido FrabottiVmug 2017 Guido Frabotti
Vmug 2017 Guido Frabotti
 

Recently uploaded

GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
Tomaz Bratanic
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
Pixlogix Infotech
 
UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
Wouter Lemaire
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
Edge AI and Vision Alliance
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial IntelligenceAI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
IndexBug
 
Artificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopmentArtificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopment
Octavian Nadolu
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
Zilliz
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
名前 です男
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
Matthew Sinclair
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”
Claudio Di Ciccio
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Tosin Akinosho
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
Brandon Minnick, MBA
 
Infrastructure Challenges in Scaling RAG with Custom AI models
Infrastructure Challenges in Scaling RAG with Custom AI modelsInfrastructure Challenges in Scaling RAG with Custom AI models
Infrastructure Challenges in Scaling RAG with Custom AI models
Zilliz
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 

Recently uploaded (20)

GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
 
UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial IntelligenceAI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
 
Artificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopmentArtificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopment
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
 
Infrastructure Challenges in Scaling RAG with Custom AI models
Infrastructure Challenges in Scaling RAG with Custom AI modelsInfrastructure Challenges in Scaling RAG with Custom AI models
Infrastructure Challenges in Scaling RAG with Custom AI models
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 

NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza

  • 1. © 2016 VMware Inc. All rights reserved. NSX La Virtualizzazione di Rete e il Futuro della Sicurezza Luca Morelli Sr. Systems Engineer @ VMware
  • 2. Qualche Info sullo Speaker… © 2016 VMware Inc. All rights reserved. 2 •  Nato a Catanzaro, la città delle 3 V, circa 37 anni fà •  Ingegnere Informatico – Università di Rende •  Nell’IT da circa 15 anni – Esperienze in Spagna, Francia, Olanda e altri paesi •  Iniziato con lo sviluppo software quindi prevendita da circa 8 anni •  Quasi 7 anni con un vendor di rete “fisica” •  “Virtualizzato” dal Gennaio 2015 •  Appassionato di subacquea, apnea, arrampicata e della mia splendida compagna •  Aggiungetemi su LinkedIn (Non solo NSX)
  • 3. Agenda 3 1 La Visione di VMware nel Software Defined Data Center 2 Introduzione alla Virtualizzazione di Rete con NSX 3 Il Paradigma della Micro-Segmentazione 4 Principali Casi d’Uso © 2016 VMware Inc. All rights reserved.
  • 4. Software-Defined Data Center (SDDC) The Foundation of the New Model of IT © 2016 VMware Inc. All rights reserved. 4 Any Application One Cloud Any Device Build-Your-Own Converged Infrastructure Hyper-Converged Infrastructure Software-Defined Data Center Cloud Management Compute Network Storage Extensibility Traditional Applications Modern, Cloud Applications Business Mobility: Applications | Devices | Content Hybrid Cloud PRIVATE Your Data Center PUBLIC vCloud Air MANAGED vCloud Air Network
  • 5. Compute Virtualization Abstraction Layer The Network Is a Barrier to Software Defined Data Center!! Physical Network Software Defined Data Center •  Provisioning is slow •  Mobility is limited •  Hardware dependent •  Operationally intensive 5 Servers © 2016 VMware Inc. All rights reserved.
  • 6. NSX - Distributed Services in the Hypervisor Applications Virtual Machines Virtual Networks Virtual Storage Data Center Virtualization Location Independence Software Hardware L2 Switching L3 Routing Firewalling/ACLs Load Balancing Automated operational model of the SDDC Network & Security Services Now in the Hypervisor Pooled compute, network and storage capacity; Vendor independent, best price/perf; Simplified config and mgt. Compute Capacity Network Capacity Storage Capacity © 2016 VMware Inc. All rights reserved.
  • 7. NSX Logical Switching •  Per Application/Multi-tenant segmentation •  VM Mobility requires L2 everywhere •  Large L2 Physical Network Sprawl – STP Issues •  HW Memory (MAC, FIB) Table Limits •  Scalable Multi-tenancy across data center •  Enabling L2 over L3 Infrastructure •  Overlay Based with VXLAN, etc. •  Logical Switches span across Physical Hosts and Network Switches Challenges Benefits VMware NSX Logical Switch 1 Logical Switch 2 Logical Switch 3
  • 8. Generic IP Fabric Host A vSphere Distributed Switch NSX and VXLAN 8 dvUplink-PG Logical SW A VM1 dvPG-VTEP VXLAN VTEP •  VXLAN can be seen as service on the host •  VXLAN uses a vmknic and implements a VXLAN Virtual Tunnel End Point (VTEP) functionality •  Depending on the uplink configuration, there might be several VTEPs on a host –  A single dvPortGroup is created for all VTEPs •  A logical switch is a L2 broadcast domain implemented using VXLAN –  A dvPortGroup is created for each logical switch
  • 9. Generic IP Fabric Host A Host B vSphere Distributed Switch Traffic Flowing on a VXLAN Backed VDS 9 •  In this setup, VM1 and VM2 are on different hosts but belong to the same logical switch •  A VXLAN tunnel is established between the two hosts dvUplink-PG Logical SW A VM1 dvUplink-PG dvPG-VTEP VTEP dvPG-VTEP VTEP VXLAN Tunnel Logical SW A VM2
  • 10. Host BHost A vSphere Distributed Switch Traffic Flowing on a VXLAN Backed VDS 10 •  Assume VM1 sends some traffic to VM2: dvUplink-PG Logical SW A VM1 dvUplink-PG dvPG-VTEP VTEP dvPG-VTEP VTEP Logical SW A VM2L2 frame L2 frame VM1 sends L2 frame to local VTEP1 VTEP adds VXLAN, UDP & IP headers2 Physical Transport Network forwards as a regular IP packet 3 Destination Hypervisor VTEP decapsulates frame4 L2 frame delivered to VM25 Generic IP Fabric VXLAN Tunnel IP/UDP/VXLAN L2 frame
  • 11. NSX Routing: Distributed, Feature-Rich •  Physical Infrastructure Scale Challenges – Routing Scale •  VM Mobility is a challenge •  Multi-Tenant Routing Complexity •  Traffic hair-pins Challenges •  Distributed Routing in Hypervisor •  Dynamic, API based Configuration •  Full featured – OSPF, BGP, IS-IS •  Logical Router per Tenant •  Routing Peering with Physical Switch Benefits SCALABLE ROUTING – Simplifying Multi-tenancy L2 L2 Tenant A Tenant B L2 L2 L2 Tenant C L2 L2 L2 CMP
  • 12. NSX vSwitch With NSXBefore NSX Default Gateway UCS Fabric A UCS Fabric B UCS Blade 1 vswitch 6 wire hops 6 wire hops UCS Fabric A UCS Fabric B UCS Blade 1 UCS Blade 2 vswitch vswitch UCS Fabric A UCS Fabric B 0 wire hops UCS Fabric A UCS Fabric B UCS Blade 1 UCS Blade 2 With NSXBefore NSX East-West Routing / Same host East-West Routing / Host to host 2 wire hops NSX vSwitch UCS Blade 1 The Advantage of Distributing Services Routing - more efficient networking, fewer hops Default Gateway Default Gateway Default Gateway © 2016 VMware Inc. All rights reserved.
  • 13. NSX Edge Services Gateway: Integrated Network Services …. Firewall Load Balancer VPN Routing/NAT DHCP/DNS relayDDI VM VM VM VM VM •  Integrated L3 – L7 services •  Virtual appliance model to provide rapid deployment and scale-out Overview •  Real time service instantiation •  Support for dynamic service differentiation per tenant/application •  Uses x86 compute capacity Benefits
  • 14. VLAN 20 Edge Uplink External Network Physical Router Web1 App1 DB1 Webn Appn DBn NSX Edge VXLAN 5020 Transit Link Distributed Routing RoutingPeering 14 How it looks like a Basic NSX Topology …
  • 15. High Scale Multi Tenant Topology External Network Tenant 1 Web Logical Switch App Logical Switch DB Logical Switch … Web Logical Switch App Logical Switch DB Logical Switch Tenant NSX Edge Services Gateway NSX Edge X-Large (Route Aggregation Layer) Tenant NSX Edge Services Gateway VXLAN Uplinks (or VXLAN Trunk) VXLAN Uplinks (or VXLAN Trunk) VXLAN 5100 Transit 15
  • 16. NSX provides Highest Level of Visibility in the Network 16 Log Insight NSX content pack Native capabilities Integration with partner ecosystem NSX API Syslog IPFIX Port mirroring SNMP Traceflow And more. vRealize Operations Suite
  • 17. How do I manage NSX ? 17
  • 18. Traditional approaches to Micro-Segmentation 18 Centralized firewalls •  Create firewall rules before provisioning •  Update firewall rules when moving or changing •  Delete firewall rules when app decommissioned •  Problem increases with more east-west traffic Internet
  • 19. Internet How an SDDC approach makes Micro-Segmentation feasible 19 Security policy Perimeter firewalls Cloud Management Platform
  • 20. NSX Distributed Firewalling •  Centralized Firewall Model •  Static Configuration •  IP Address based Rules •  40 Gbps per Appliance •  Lack of visibility with encapsulated traffic •  Distributed at Hypervisor Level •  Dynamic, API based Configuration •  VM Name, VC Objects, Identity-based Rules •  Line Rate ~20 Gbps per host •  Full Visibility to encapsulated traffic Challenges Benefits PHYSICAL SECURITY MODEL DISTRIBUTED FIREWALLING Firewall Mgmt VMware NSX API CMP
  • 21. NSX Distributed Firewall Enablement DFW enforces rules at vNIC layer: •  DFW independent of transport network (VLAN or VXLAN) •  All VM ingress and egress packets are subject to DFW processing •  Security Policy independent of VM location •  V-to-V and P-to-V support 21 DFW has NO Dependancy on Network Topology ! VXLAN 5001 vSphere Host VM1 MAC1 IP1 VTEP IP: 10.20.10.10 vSphere Distributed Switch vSphere Host VM2 VTEP IP: 10.20.10.11 VM3 MAC2 IP2 MAC3 IP3 DFW Policy Rules: Source Destination Service Action VM1 VM2, VM3 TCP port 123 Allow VM1 VM2, VM3 any Block DVS port-group vSphere Host VM1 MAC1 IP1 VTEP IP: 10.20.10.10 vSphere Distributed Switch vSphere Host VM2 VTEP IP: 10.20.10.11 VM3 MAC2 IP2 MAC3 IP3 DFW Policy Rules: Source Destination Service Action VM1 VM2, VM3 TCP port 123 Allow VM1 VM2, VM3 any Block VLAN 501 VLAN 501 VLAN 501 VXLAN 5001 Logical Switch VXLAN 5001
  • 22. CONFIDENTIAL NSX DFW Policy Objects •  Policy rules construct: •  Rich dynamic container based rules apart from just IP addresses: VC containers •  Clusters •  datacenters •  Portgroups •  VXLAN VM containers •  VM names •  VM tags •  VM attributes Identity •  AD Groups IPv6 compliant •  IPv6 address •  IPv6 sets Services •  Protocol •  Ports •  Custom IPv6 Services Choice of PEP (Policy Enforcement Point) •  Clusters •  VXLAN •  vNICs •  … Rule ID Rule Name Source Destination Service Action Applied To Action •  Allow •  Block •  Reject 22
  • 23. 23 Configure Policies with Security Groups Select elements to uniquely identify application workloads Use attributes to create Security Groups Apply policies to security groups 1 2 3 ABC DEF Group XYZ App 1 OS: Windows 8 TAG: “Production” §  Enforce policy based on logical constructs §  Reduce configuration errors §  Policy follows VM, not IP §  Reduce rule sprawl and complexity Use security groups to abstract policy from application workloads. Group XYZ Policy 1 “IPS for Desktops” “FW for Desktops” Policy 2 “AV for Production” “FW for Production” Element type Static Dynamic Data center Virtual net Virtual machine vNIC VM name OS type User ID Security tag
  • 24. Micro-segmentation simplifies network security §  Each VM can now be its own perimeter §  Policies align with logical groups §  Prevents threats from spreading App DMZ Services DB Perimeter firewall AD NTP DHCP DNS CERT Inside firewall Finance EngineeringHR
  • 25. WAN Internet Compute Cluster Compute Cluster Perimeter Firewall (Physical) NSX EDGE Service Gateway Compute Cluster SDDC (Software Defined DC) DFW DFW DFW DFW: E-W NSX EDGE Service Gateway positioned to protect border of the SDDC: EDGE: North – South traffic protection NSX DFW positioned for internal SDDC traffic protection: DFW: East – West traffic protection Physical Virtual Compute Cluster EDGE:N-S NSX Security in SDDC 25
  • 26. Micro-segmentation in detail SegmentationIsolation Advanced services Controlled communication path within a single network •  Fine-grained enforcement of security •  Security policies based on logical groupings of VMs Advanced services: addition of 3rd party security, as needed by policy •  Platform for including leading security solutions •  Dynamic addition of advanced security to adapt to changing security conditions No communication path between unrelated networks •  No cross-talk between networks •  Overlay technology assures networks are separated by default
  • 27. Third-Party Firewall, Network Security Options for NSX Integration Src Dst Action ANY Shared Service Allow Desktop WEB_GROUP Redirect to 3rd party Platform for Distributed Services Redirect via global rule to 3rd party WEB_ GROUP “Web Policy” þ  Firewall – redirect to 3rd party þ  3rd party – do deep packet inspection Redirect via policy template, for reuse in automation workflows 3rd party can program NSX distributed firewall directly – and set/get context to inform policy 27
  • 28. Example : Orchestrating Security Between Multiple Services (Vulnerability Scan) SG: QuarantineSG: Web Servers 1.Web Server VM running IIS is deployed, unknowingly having a vulnerability 2.Vulnerability Scan is initiated on web server (3rd party AV product) 3.VM is tagged in NSX Manager with the CVE and CVSS Score 4.NSX Manager associates the VM with the Quarantine (F/W Deny) 5.[Externally] Admin applies patches, 3rd party AV product re-scans VMs, clears tag 6.NSX Manager removes the VM from Quarantine ; VM returns to it’s normal duties Services Services Membership: Include VMs which have CVSS score >= 9Membership: Include VMs which have been provisioned as “WebServer” NSX Manager antivirus antivirus
  • 29. NSX Partners and Service Categories Application Delivery Services Physical-to-Virtual Services Operations and Visibility Security NSX Partner Extensions http://www.vmware.com/products/nsx/resources.html
  • 30. Ground-breaking use cases 30 Enterprises can often justify the cost of NSX through a single use case Micro segmentation DMZ anywhere Secure end user Security IT automating IT Multi-tenant infrastructure Developer cloud IT automation Disaster recovery Metro pooling Hybrid cloud networking Application continuity IT optimization Server asset utilization Price | performance Hardware lifecycle $
  • 31. Use Case: Infrastructure Management with vRealize Automation New Features §  Simplified Multi-Tier App Deployment §  Improved Connectivity − Deployment of logical switches and networks §  Enhanced Security −  Intelligent placement of workloads in security groups protected by firewalls §  Increased Availability −  Via deployment of NSX distributed firewalls and load balancers Benefits §  Deliver secure, scalable, performing application-specific infrastructure on-demand Dynamically Provision and Decommission NSX Logical Services
  • 32. Use Case: Disaster recovery with NSX network virtualization SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 Virtual Network 10.0.30/24 NSX Controller NSX Controller Snapshot network security 2b 1 Snapshot VM Network and security already exists Recover the VM 3 Physical network infrastructure Physical network infrastructure2a Replicate VM and storage 10.0.10/24 10.0.20/24 Step 1 & 2 (e.g VMware SRM) 32 Primary site Recovery Site
  • 33. Use Case: A True Hybrid Cloud powered by VMware NSX Local Data Center InternetIPSec VPN (vCloud Air Network)(vCloud Air Network) vCloud Air L2 VPN Some Benefits: •  L2VPN for DC Extension •  Granular Network Security with Trust Groups •  Bi-directional workload migration using vSphere web client 33 Some Benefits: •  Today with vCloud AIR •  Tomorrow with Amazon AWS, Azure, Google and other Public Cloud Providers
  • 34. NSX Vision: Driving NSX Everywhere Managing Security and Connectivity for many Heterogeneous End Points 34 Automation IT at the Speed of Business Security Inherently Secure Infrastructure Application Continuity Data Center Anywhere On-Premise Data Center New app frameworks Mobile Devices (Airwatch) Virtual Desktop (VDI) Branch offices (Partner) Internet of things Public clouds
  • 35. What’s Next… VMware NSX Hands-on Labs labs.hol.vmware.com 35 Explore, Engage, Evolve virtualizeyournetwork.com Network Virtualization Blog blogs.vmware.com/networkvirtualization NSX Product Page vmware.com/go/nsx NSX Training & Certification www.vmware.com/go/NVtraining NSX Technical Resources Reference Designs vmware.com/products/nsx/resources VMware NSX YouTube Channel youtube.com/user/vmwarensx VMware NSX Community communities.vmware.com/community/vmtn/nsx Play Learn Deploy