VMware Service-defined Firewall works in bare-metal, VM, container environments and supports hybrid cloud. Credit: Getty Images VMware has taken the wraps off a firewall it says protects enterprise applications and data inside data centers or clouds. Unlike perimeter firewalls that filter traffic from an unlimited number of unknown hosts, VMware says its new Service-defined Firewall gains deep visibility into the hosts and services that generate network traffic by tapping into into its NSX network management software, vSphere hypervisors and AppDefense threat-detection system. “VMware’s service defined firewall is significant because it leverages host and network context via AppDefense and NSX, respectively, to apply contextual, adaptive access control policies, hence the positioning of the offering as an internal versus external firewall” said Doug Cahill, Group Director and Senior Analyst with the Enterprise Strategy Group. The product doesn’t require added software agents to do its job as many security packages do, VMware said. It also lets organizations more easily enforce security policies without forcing traffic to go through a security appliance for scanning, VMware stated. The firewall works in bare metal, virtual-machine and container-based application environments, and will support hybrid cloud settings such as VMware Cloud on AWS and, down the road, AWS Outposts. Using network-generated information to determine and verify the expected – or “known good” – behavior of applications, the firewall’s Application Verification Cloud builds an accurate map of the good or normal state of the application. Any transactions outside that behavior are then blocked. Once a verified understanding of known good application behavior is established, the system can generate security policies for the Service-defined Firewall that are layer 7 capable and can perform full stateful inspection, wrote Alex Berger product marketing manager with the Networking & Security business unit at VMware in a blog about the announcement. The idea is to consistently allow an application’s known good behavior across heterogenous workloads and private and public clouds, Burger stated. “In today’s modern data center, change is constant. A dynamic approach to segmentation allows customers to keep pace with change,” Cahill said. “Applications are more distributed, deployed across multiple private and public clouds, using many different types of infrastructure and accessed from many different devices,” said Rajiv Ramaswami, chief operating officer, products and services, VMware in a statement. “Security sprawl – too many products, agents, and interfaces deployed across an organization – creates complexity for security management.” VMware’s strategy is to remove the complexity inherent with security today and deliver security that is intrinsic from endpoint to cloud, Ramaswami stated. Related content news HPE Aruba looks to fight AI threats with AI weapons HPE Aruba Networking Central gains AI-powered security observability and monitoring features. By Michael Cooney May 07, 2024 4 mins IoT Security Network Security news AI features boost Cisco's Panoptica application security software Cisco pads cloud-native security platform Panoptica with features that help customers protect containerized, microservice applications. By Michael Cooney May 07, 2024 5 mins Network Security Cloud Computing news analysis Red Hat extends Lightspeed generative AI tool to OpenShift and Enterprise Linux Red Hat's Lightspeed, a gen AI-powered assistant, will be extended to RHEL and OpenShift to help enterprises that want to use Linux, automation, and hybrid clouds but may not have the skills in house. By Maria Korolov May 07, 2024 4 mins Linux Network Management Software Servers news analysis Red Hat introduces 'policy as code' for Ansible New 'policy as code' capability for the Red Hat Ansible automation platform is aimed at reducing human error and the cost of implementing compliance directives. By Maria Korolov May 07, 2024 5 mins Linux Network Management Software PODCASTS VIDEOS RESOURCES EVENTS NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe