Discover the center of the multi-cloud universe August 29 – September 1.
VMware Contexa™ sees what others don’t, powering VMware Security to stop threats others can’t.
Enable your security team to respond more effectively to threats across your data centers with VMware’s Distributed IDS/IPS solution.NSX Distributed Firewall includes a comprehensive set of detection and prevention capabilities, including Distributed IDS/IPS. Leverage its unique architecture and precise app context to replace discrete appliances and gain operational simplicity.
Achieve more zero-false-positive workloads with curated rulesets and higher-fidelity signature matches based on precise application context.
Scale inspection capacity automatically and eliminate hardware bottlenecks via IDS/IPS functionality built-in to each workload.
Reduce network congestion and simplify network design by eliminating the need to hair-pin traffic to centralized appliances.
Re-use existing stranded compute capacity and eliminate the need for dedicated appliances.
Leverage native IDS/IPS capabilities within NSX to replace traditional IDS/IPS appliances, including standalone, firewall-based, or virtual host-based.
Utilize IDS/IPS to enable wide-spread use of virtual patching for all workloads in the data center.
Create and customize multiple virtual security zones for internal teams and partners without requiring physical separation of the network.
Simply turn on traffic inspection through a software-driven deployment model — without needing to buy expensive appliances.
Distributed IDS/IPS in the data center operates under different constraints than a traditional IDS/IPS. Watch the lightboard video to understand why.
Secure workload access on your journey to zero trust.
Learn why enterprise networks continue to be breached despite significant spending on security. Get started with intrinsic security in your network using data you already have.
Layer 7 internal firewall
Complete malware analysis
AI-powered correlation of events across multiple detection engines
NSX Distributed IDS/IPS is an application-aware intrusion detection system/intrusion prevention system (IDS/IPS) purpose-built for analyzing east-west traffic and detecting lateral threat movements.
NSX Distributed IDS/IPS uses an all-software distributed approach that moves traffic inspection out to every workload. It eliminates the need to hair-pin traffic to discrete appliances, ensuring comprehensive coverage without any blind spots.
Key capabilities of NSX Distributed IDS/IPS include:
For full capabilities, see the solution overview.
Use cases for NSX Distributed IDS/IPS include:
The benefits of NSX Distributed IDS/IPS include: