Session	
  Title	
  -­‐	
  VMWare	
  on	
  VMWare	
  -­‐	
  How	
  VMware	
  IT	
  Implemented	
  Micro-­‐Segmentation	
  and	
  
Deployed	
  Large	
  Scale	
  Private	
  Cloud	
  Using	
  NSX	
  
	
  
Session	
  Abstract	
  
VMware	
   IT	
   implemented	
   micro-­‐segmentation	
   using	
   NSX	
   Distributed	
   Firewall	
   to	
   secure	
   production	
  
applications	
  and	
  deployed	
  NSX	
  in	
  a	
  large-­‐scale	
  internal	
  private	
  cloud	
  environment.	
  	
  We	
  will	
  review	
  use	
  
cases	
  for	
  micro-­‐segmentation	
  such	
  as	
  SAP	
  and	
  discuss	
  design	
  considerations.	
  We	
  will	
  outline	
  our	
  approach	
  
for	
  finalizing	
  the	
  firewall	
  policy	
  model	
  using	
  Log	
  Insight	
  for	
  firewall	
  traffic	
  monitoring	
  and	
  analytics	
  and	
  
discuss	
  roles	
  and	
  responsibilities	
  and	
  lessons	
  learned.	
  	
  Please	
  join	
  us	
  to	
  learn	
  how	
  VMware	
  secured	
  its	
  
business	
  services	
  by	
  leveraging	
  NSX	
  and	
  scaled	
  its	
  internal	
  private	
  cloud	
  deployment	
  using	
  NSX	
  features.	
  
We	
   will	
   discuss	
   the	
   design,	
   technical	
   and	
   organizational	
   considerations	
   of	
   one	
   of	
   the	
   world’s	
   largest	
  
deployments	
  of	
  NSX	
  for	
  vSphere	
  (hosting	
  over	
  20,000	
  VMs).	
  	
  We	
  will	
  review	
  the	
  decisions	
  involved	
  in	
  
deploying	
   new	
   NSX	
   environments	
   and	
   how	
   VMware’s	
   internal	
   private	
   cloud	
   leverages	
   NSX	
   edge	
  
firewalling	
  to	
  achieve	
  a	
  scalable,	
  multi-­‐tenant	
  security	
  model.	
  	
  	
  	
  
	
  
Session	
  Outline	
  
•   Design	
  considerations	
  for	
  implementing	
  micro	
  segmentation	
  
•   NSX	
  Distributed	
  Firewall	
  traffic	
  monitoring	
  and	
  analytics	
  using	
  Log	
  Insight	
  
•   Review	
  micro-­‐segmentation	
  use	
  cases	
  such	
  as	
  the	
  SAP	
  Enterprise	
  Resource	
  Planning	
  (ERP)	
  
Solution	
  and	
  Virtual	
  Desktop	
  Infrastructure	
  (VDI)	
  
•   Overview	
  of	
  VMware’s	
  Private	
  Cloud	
  infrastructure	
  
•   Multi-­‐tenant	
  considerations	
  in	
  VMware’s	
  Private	
  Cloud	
  
•   NSX	
  features	
  deployed	
  in	
  VMware’s	
  Private	
  Cloud	
  
•   Recommendations	
  for	
  implementing	
  NSX	
  in	
  brownfield	
  and	
  greenfield	
  environments	
  
	
  
Key	
  Takeaway	
  1:	
  How	
  to	
  plan	
  and	
  implement	
  an	
  NSX	
  Distributed	
  Firewall	
  deployment	
  	
  
	
  
Key	
  Takeaway	
  2:	
  Design	
  considerations	
  for	
  large-­‐scale,	
  multi-­‐tenant	
  NSX	
  environments	
  
	
  
Key	
  Takeaway	
  3:	
  Recommendations	
  for	
  greenfield	
  and	
  brownfield	
  NSX	
  implementation	
  
	
  
Technical	
  Level:	
  Technical	
  
	
  
Track:	
  Software	
  Defined	
  Data	
  Center	
  
	
  
Sub-­‐track:	
  Networking	
  and	
  Security	
  
	
  
Product	
  and	
  Topic:	
  NSX	
  
	
  
Audience:	
  	
  IT-­‐Network,	
  IT	
  –	
  Risk/Compliance/Security	
  
	
  
Link	
  to	
  the	
  recorded	
  session	
  -­‐	
  
http://vmware.mediasite.com/mediasite/Showcase/default/VideoSearch#VideoSearch/0/swapnil/2/nul
l/null/0	
  	
  
	
  
To	
  schedule	
  a	
  discussion	
  with	
  an	
  SME	
  on	
  this	
  topic	
  contact:	
  vmwonvmw@vmware.com	
  	
  

VMWare on VMWare - How VMware IT Implemented Micro-Segmentation and Deployed Large Scale Private Cloud Using NSX

  • 1.
        Session  Title  -­‐  VMWare  on  VMWare  -­‐  How  VMware  IT  Implemented  Micro-­‐Segmentation  and   Deployed  Large  Scale  Private  Cloud  Using  NSX     Session  Abstract   VMware   IT   implemented   micro-­‐segmentation   using   NSX   Distributed   Firewall   to   secure   production   applications  and  deployed  NSX  in  a  large-­‐scale  internal  private  cloud  environment.    We  will  review  use   cases  for  micro-­‐segmentation  such  as  SAP  and  discuss  design  considerations.  We  will  outline  our  approach   for  finalizing  the  firewall  policy  model  using  Log  Insight  for  firewall  traffic  monitoring  and  analytics  and   discuss  roles  and  responsibilities  and  lessons  learned.    Please  join  us  to  learn  how  VMware  secured  its   business  services  by  leveraging  NSX  and  scaled  its  internal  private  cloud  deployment  using  NSX  features.   We   will   discuss   the   design,   technical   and   organizational   considerations   of   one   of   the   world’s   largest   deployments  of  NSX  for  vSphere  (hosting  over  20,000  VMs).    We  will  review  the  decisions  involved  in   deploying   new   NSX   environments   and   how   VMware’s   internal   private   cloud   leverages   NSX   edge   firewalling  to  achieve  a  scalable,  multi-­‐tenant  security  model.           Session  Outline   •   Design  considerations  for  implementing  micro  segmentation   •   NSX  Distributed  Firewall  traffic  monitoring  and  analytics  using  Log  Insight   •   Review  micro-­‐segmentation  use  cases  such  as  the  SAP  Enterprise  Resource  Planning  (ERP)   Solution  and  Virtual  Desktop  Infrastructure  (VDI)   •   Overview  of  VMware’s  Private  Cloud  infrastructure   •   Multi-­‐tenant  considerations  in  VMware’s  Private  Cloud   •   NSX  features  deployed  in  VMware’s  Private  Cloud   •   Recommendations  for  implementing  NSX  in  brownfield  and  greenfield  environments     Key  Takeaway  1:  How  to  plan  and  implement  an  NSX  Distributed  Firewall  deployment       Key  Takeaway  2:  Design  considerations  for  large-­‐scale,  multi-­‐tenant  NSX  environments     Key  Takeaway  3:  Recommendations  for  greenfield  and  brownfield  NSX  implementation     Technical  Level:  Technical     Track:  Software  Defined  Data  Center     Sub-­‐track:  Networking  and  Security     Product  and  Topic:  NSX     Audience:    IT-­‐Network,  IT  –  Risk/Compliance/Security    
  • 2.
    Link  to  the  recorded  session  -­‐   http://vmware.mediasite.com/mediasite/Showcase/default/VideoSearch#VideoSearch/0/swapnil/2/nul l/null/0       To  schedule  a  discussion  with  an  SME  on  this  topic  contact:  vmwonvmw@vmware.com