build 980262fe | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 208 | 0 skipped |
Post · 2024-05-07

Distributed Network & Security Services

Virtualised networks have been running on hypervisor platforms in data centres for more than 20 years. What has changed is what they now have to cover: automation and security together.

2024-05-07Date
Matthias GrasmückAuthor
4Min read
822words
no translation reviewed
Topics capabilities · idf weight Network network 2.83 Security security 2.23
Vendors vendors · idf weight VMware vmware 0.91

For more than 20 years, virtualised networks, the kind broadly associated with the term software-defined network, have been running on hypervisor platforms in data centres, and by now they are indispensable. As IT infrastructure and the virtualisation and containerisation platforms on top of it get more automated, the need grows for network solutions that cover the whole picture and unite the virtual and physical networks. Beyond network automation, these technologies also have to meet requirements for integral network security, and ideally fit into the automation process.

That means supporting familiar, existing network concepts while making new approaches possible:

  • End-to-end automation, so network and security functions can be delivered quickly.
  • Visibility across every connection, so analysis is faster and the operational effort drops.
  • Separating the control plane from the data plane, which makes programmable network and flexible security architectures possible.
  • Less operational effort through standardised, consistent and automated configuration.
  • Better network performance through load distribution and optimal path selection.
  • Enforcing security functions such as stateful firewalling directly at the workload’s network interface, without depending on the workload.

For more than eight years we have accompanied our customers in planning and building software-defined networking (SDN) infrastructure, using the leading and established SDN technology, VMware NSX.

Did you know the first release of VMware NSX came out of the acquisition of Nicira in 2012?

Nicira was founded in 2007 out of research at Stanford University and did pioneering work in software-defined networking.

Software-defined networking with VMware NSX

Since it appeared over 10 years ago, VMware NSX has taken a distributed approach to network and security architecture. Traffic does not have to be funnelled centrally through individual appliances the way it is in classic network infrastructure; it can be inspected and processed efficiently at the source, where it enters the virtual ether. That is what makes zero trust network architecture (ZTNA) approaches possible, because the workload can be microsegmented effectively without redirecting traffic to a firewall appliance first.

Other vendors now claim this distributed network and security services approach too, and allow network as well as security functions to be applied on distributed network components.

VMware NSX can be implemented alongside or combined with other network technologies, because it is essentially agnostic and can be implemented without complex dependencies on the underlying network infrastructure.

Did you know VMware NSX lets you choose an SDN-only topology (distributed network services only) or a security-only topology (distributed security services only) instead of the full stack?

If you only want to automate or simplify your network, you can deploy VMware NSX as the networking stack. You can equally deploy VMware NSX without the networking stack and still get distributed security functions through the VMware NSX Distributed Firewall, which enables a ZTNA approach without changing the existing network infrastructure.

Distributed network and security services

Introducing an SDN technology takes a few factors into account:

  • Interoperability with other products and interfaces, so the full potential of end-to-end automation can be reached.
  • Central and consistent management of SDN components, such as scaling resources and capacity up or out, and lifecycle operations.
  • Central monitoring and analysis, for evaluating and verifying data flows within the SDN.
  • Thorough product and adoption support from the vendor, a good number of capable partners and a broad technical community, all of which make adopting a technology like this considerably easier.

Beyond that, it is worth being clear about where distributed network and security functions produce the most effect in processing data. The diagram below describes two different layers at which distributed network and security services can be delivered:

distributed network and security services

The two approaches have these characteristics:

Distributed services on the traditional network layer: distributed network and security functions are processed at the access/leaf layer. All traffic inside the platform has to pass through that layer. Depending on the vendor and technology, security functions such as firewalling can be enforced there, or traffic is forwarded to one or more distributed firewall appliances that then apply them. Scaling is usually defined, and limited, by the topology, leaf-spine for example.

Distributed services integrated into the hypervisor layer: this takes an integrated and considerably more distributed approach, extending the hypervisor kernel with the corresponding network and security functions. They can be applied directly at the source, where traffic enters the virtual ether, which takes load off the physical network infrastructure and cuts unnecessary traffic. Several scaling options are available, up and out, and they generally offer higher efficiency both in distributing and in processing the data, thanks to the virtualisation context.

Closing thought

As so often in IT, there is no single right way. Take the time you need when planning and introducing an SDN technology, and draw on capable, experienced partners where it helps. We are glad to bring our expertise and years of project experience to that (contact form).

You might also like