Advanced Micro-Segmentation Services With Vmware NSX and Palo Alto Networks

Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

PALO ALTO NETWORKS: Advanced Micro-Segmentation Services with VMware NSX Datasheet

Advanced Micro-Segmentation Services with


VMware NSX and Palo Alto Networks®
Technology Segment: Virtualization and Cloud

The Palo Alto Networks Technology SOLUTION OVERVIEW

Partner Program includes a select While organizations have gained operational flexibility and
group of partners that deliver solutions lowered datacenter costs by deploying virtualization solutions,
or products that interoperate with the the true promise of a secure, agile, extensible, and flexible
next-generation firewall. private cloud continues to be elusive. One of the key barriers
is the ability to deploy security services at the same pace as
HIGHLIGHTS virtual machine deployments without compromising the level
The VMware NSX and Palo Alto Networks integrated of protection needed. VMware and Palo Alto Networks have
solution unlocks the full potential of the software
partnered to address these challenges.
defined datacenter, allowing IT organizations to:
• Automate delivery of next-generation security services VMware NSX is a network virtualization platform that delivers the operational model
• Accelerate deployment of business critical applications of a VM for the network. Using the NSX platform extensible service insertion
through transparent security enforcement and chaining capabilities, Palo Alto Networks builds on VMware’s native
kernel-based firewall capabilities to add next-generation security services. The
• Optimize operational efficiency via simplified security
deployment of next-generation security from Palo Alto Networks is automated;
policies with virtual, cloud and business context
context is shared between virtualization and security elements, and rich security
• Reduce errors in security configuration through policies based on applications, users, content, and virtual machine “containers” can
context sharing between virtualization and security be defined.
environments
• Facilitate dynamic service chaining and service
Security Barriers in the Software Defined Datacenter
orchestration
Existing network security solutions, whether physical or virtualized, exhibit
• Support micro-segmentation initiatives to easily limited security features or are too complex to deploy in a dynamic, agile cloud
isolate and safely enable virtualized applications of environment. In order to fully realize the benefits of the software defined
different trust levels in the datacenter datacenter, security requirements need to be addressed in an automated, integrated
• Create consistent policies across North/South and manner, without trading off features or performance. Challenges include:
East/West datacenter traffic
• Lack of visibility into East-West traffic
• Address simplified security and compliance mandates
with protection against known and unknown threats • Security not keeping pace with the rate of change in virtual environments
including exploits, viruses, spyware, malware and • Manual, process-intensive networking configurations to deploy security
advanced persistent threats (APTs). within the virtualized environment
• Performance degradation in virtual environments
• Misaligned cloud admin and security admin workflows
• Incomplete protection against threats to the datacenter
PALO ALTO NETWORKS: Advanced Micro-Segmentation Services with VMware NSX Datasheet

VMware NSX and Palo Alto Networks Next-Generation Security • Palo Alto Networks Panorama: Panorama is the Palo Alto
The joint solution featuring VMware NSX and the Palo Alto Networks centralized management platform, providing the
Networks enterprise security platform was designed to solve these ability to manage a distributed network of virtualized and
datacenter security challenges. The components of the solution physical firewalls from a centralized location. Capabilities
include: include the ability to view all firewall traffic, manage all
aspects of device configuration, push global policies; and
• VMware NSX: NSX is the leading network and security generate reports on traffic patterns or security incidents.
virtualization platform that delivers the operational model
of a VM for the network. NSX is a full-service, programmable As shown in Figure 1, the tightly integrated solution delivers the
platform that provides logical network abstraction of the following capabilities:
physical network and reproduces the entire network model
in software allowing diverse network topologies to be created • Independence from networking topology. Security policies are
and provisioned in seconds. The NSX distributed service applied regardless of where a VM connects at a point in time.
framework and service insertion platform and APIs enable This works with any network overlay, and with traditional
integration of next-generation security services. This is facilitated VLAN networking.
by the native, kernel based VMware NSX Firewall that provides
basic firewall capabilities and steers traffic seamlessly and • Automated deployment and provisioning of next-generation
transparently to the Palo Alto Networks next-generation security in lock step with the fluid virtual compute layer.
security platform for inspection. Panorama communicates with the NSX Manager to register as a
security management platform, providing information about the
• Palo Alto Networks VM-Series for NSX: The VM-Series is the VM-Series. NSX Manager then automates the deployment of
Palo Alto Networks enterprise security platform in next-generation security services on every VMware ESXi server.
virtualized form factor, designed to address security challenges Each VM-Series deployed then communicates directly with
in virtualized and cloud environments. At the core of this Panorama for automated licensing and provisioning.
platform is the next-generation firewall, which offers the ability
to identify, control, and safely enable applications while • Seamless traffic steering to next-generation security: Within the
inspecting all content for all threats all the time. Palo Alto VMware virtualized server environment, application traffic is
Networks uses multiple threat prevention disciplines, steered to the VM-Series via NSX APIs without needing to manually
including IPS and anti-malware, along with URL filtering make configuration changes to virtual networking elements.
and file and content blocking, to control known threats, and • Dynamic security policies based on application, user, content
uses automated sandbox analysis of suspicious files to reveal and virtual machine “container”: Palo Alto Networks next-
unknown malware and APTs (advanced persistent threats). generation security policies can be defined based on applications,
Unlike traditional security solutions, the VM-Series offers users, content and virtual machine (VM) “containers”. As
the same set of security features as the next-generation virtualized applications are instantiated and placed in logical
physical firewalls, and is managed using the same management “containers”, the notion of “containers” can be extended
platform, ensuring a consistent set of policies is maintained in to VM-Series security policies via the Palo Alto Networks
the datacenter. dynamic address group feature.

Cloud Admin Security Admin


Dynamic Objects
NSX Manager Panorama
Manage NSX FW rules Manage East-West
Manage Perimeter Policy

Deploy VM-Series Policy

Web Servers DNS Servers

NSX
Firewall VM VM VM VM VM VM VM VM VM VM VM VM

Palo Alto
ks
Palo Alto Networks Networks
VM-Series PA-5000 Series
VM- VM- VM-
SERIES SERIES SERIES

External Network
k

Figure 1: VMware NSX and Palo Alto Networks Next-Generation Security Platform
PALO ALTO NETWORKS: Advanced Micro-Segmentation Services with VMware NSX Datasheet

Full context sharing between the VMware and Palo Alto About Palo Alto Networks
Networks management platforms ensures that dynamic
address groups is updated with the latest information Palo Alto Networks is the leading next-generation network security
representing the VM container instead of having to manually company. Its innovative platform allows enterprises, service
track hundreds or thousands of IP addresses. This makes it providers, and government entities to secure their networks by
incredibly easy to apply security to virtualized applications no safely enabling the increasingly complex and rapidly growing
matter when they are created or moved across the network. number of applications running on their networks and by providing
prevention against cyberthreats. The core of Palo Alto Networks is
• Next-generation security protection for virtualized applications its enterprise security platform which delivers application, user, and
and data: Because the VM-Series supports the PAN-OSTM content visibility and control integrated within the firewall through
operating system, comprehensive next-generation security its proprietary hardware and software architecture. Palo Alto
features can be deployed to identify, control, and safely Networks products and services can address a broad range of
enable data enter applications while inspecting all content for network security requirements, from the datacenter to the network
all threats. Safe application enablement means you can build perimeter, as well as the distributed enterprise, which includes
firewall policies that are based on application/application branch offices and a growing number of mobile devices. Palo Alto
feature, users and groups, and content, as opposed to port, Networks products are used by more than 17,000 customers
protocol and IP address, transforming your traditional allow in over 120 countries. For more information, visit www.
or deny firewall policy into business-friendly elements. Threat paloaltonetworks.com.
protection capabilities address the whole attack lifecycle,
featuring protection against exploits, viruses, spyware,
malware and targeted unknown threats such as advanced
persistent threats (APTs).
• Scales linearly with the number of hypervisors: The IT
administrator no longer needs to guess how much network
security capacity is needed. Any time a new hypervisor is
added, next-generation security capacity is automatically
added.

Summary
The VMware NSX and Palo Alto Networks integrated
solution extend the basic firewall services delivered by the
NSX virtualization platform. The joint solution provides an
integrated datacenter solution that allows IT organizations to
unlock all the benefits of the software defined datacenter, from
optimized capacity utilization and operational efficiencies to
greater flexibility and agility without compromising security. IT
administrators can now automate the delivery of leading next-
generation security services from Palo Alto Networks in lock step
with the fluid virtual compute layer, to provide comprehensive
visibility and safe enablement of all datacenter traffic including
intra-server virtual machine communications.

4401 Great America Parkway Copyright ©2014, Palo Alto Networks, Inc. All rights reserved. Palo Alto Networks,
Santa Clara, CA 95054 the Palo Alto Networks Logo, PAN-OS, App-ID and Panorama are trademarks of
Palo Alto Networks, Inc. All specifications are subject to change without notice.
Main: +1.408.753.4000
Palo Alto Networks assumes no responsibility for any inaccuracies in this document
Sales: +1.866.320.4788
or for any obligation to update information in this document. Palo Alto Networks
Support: +1.866.898.9087 reserves the right to change, modify, transfer, or otherwise revise this publication
www.paloaltonetworks.com without notice. PAN_DS_NSX_073114

You might also like