Protect Your Distributed Data Center with a Purpose-Built Internal Firewall

Rely on a distributed, scale-out internal firewall, built on NSX, to secure east-west traffic across multi-cloud environments. Gain superior protection against lateral movement of malware with stateful layer 7 security controls that include IDS/IPS. VMware’s unique, intrinsic approach to security simplifies deployments and streamlines firewalling of every workload—at a fraction of the cost. 

Enable Intrinsic Security with the Service-defined Firewall

Watch the overview video on how the Service-defined Firewall enables intrinsic security for today’s distributed data centers and applications.

Securing East-West Traffic for the Modern Data Center

Securing East-West Traffic for the Modern Data Center

See why traditional firewall architectures are failing to protect east-west network traffic — and how internal firewalls can solve the problem.

Eliminate the Trade-off Between Security and Simplicity 

Mitigate Security Risk

Gain superior ability to prevent lateral movement of malware inside the data center with the only stateful Layer 7 firewall built into your infrastructure. Operating from a unique position within the hypervisor, Service-defined Firewall enjoys unmatched visibility into the network and unrivaled workload context to provide better threat protection while remaining isolated from the attack surface.

Accelerate Security Operations

Enable security to move at the speed of development to deliver a true public cloud experience on-premises, decoupled from physical infrastructure constraints. Deliver “security as code” with an API driven, object-based policy model which ensures new workloads automatically inherit relevant security policies and automates policy mobility with workloads.

Ensure Compliance

Eliminate the visibility and security blind-spots that result from misaligned controls across disparate solutions, and the selective traffic inspection that comes with appliance-based architectures. Demonstrate compliance by easily creating virtual security zones and complete Layer 7 security coverage for your sensitive applications and data.

Simplify Security Architecture

Replace multiple application-based solutions with L2-L7 virtual controls built into the NSX platform, thus reducing CapEx by up to 60%. Radically simplify network deployment and operations by eliminating the need for changes to the physical network, complex traffic hair-pinning architectures, or agent management overhead.

How is VMware Internal Firewall Different?

Distributed architecture

Distributed architecture

Elastic throughput

Elastic throughput

Built-in security

Built-in security

Superior workload context

Superior workload context

What Are the Key Use Cases for the Service-defined Firewall? 

Rapidly Deploy Network Segments

Quickly create and reconfigure network segments, virtual security zones, and partner domains by defining them entirely in software. Avoid the need to re-architect your network or deploy discrete appliances.

More on Network Segmentation 

Meet Compliance Requirements

Address regulatory requirements (such as PCI-DSS, HIPAA, etc.) for compliance zones by inspecting all east-west traffic for threats with a fully distributed IDS/IPS delivered in software.

More on IDS/IPS 

Prevent Lateral Movement of Attacks

Leverage stateful Layer 7 firewalling including AppID and UserID-based policies, and advanced threat protection at each workload to protect against ransomware and other attacks that propagate laterally within data centers.

Read the Blog 

Achieve Zero Trust with Micro-segmentation

Easily create, enforce, and automatically manage granular micro-segmentation policies between applications, services, and workloads across multi-cloud environments spanning VMs, containers, and bare metal infrastructure.

More on Distributed Analytics 

Spotlight on Internal Firewall 

Security Done Differently and Done Better

Security Done Differently and Done Better

Tom Gillis, SVP/GM Networking and Security, discusses reimagining firewalls and IDS/IPS with an intrinsic security approach.

Knock, Knock: Is this Security Thing Working?

SANS discusses challenges with today’s data center security and the need for an intrinsic approach. 

Download White Paper

Secure Virtual Desktops with Service-Defined Firewall

Deliver comprehensive security for VDI environments by isolating desktops and segmenting VDI infrastructure with just a few policies.

Read Secure VDI Solution Overview

Advanced Security for VMware Cloud Foundation

See how VMware’s security portfolio provides best-in-class data center security for workloads, applications, and networks.

Read the Blog

Powering Customer Success with the Service-defined Firewall

Securely Drive Productivity and Flexibility

Securely Drive Productivity and Flexibility

Preferred Mutual maximizes remote employee and IT staff productivity while ensuring the security of company data with NSX, Workspace One, and Horizon.

Provide a Reliable Learning Platform

Provide a Reliable Learning Platform

Region 11 supports students and teachers with a more secure, integrated, and reliable technology platform via VMware solutions that include NSX and Horizon.

Meet Government Security Regulations

Meet Government Security Regulations

Cenitex delivers the rock-solid security that governments require with a fully-integrated range of VMware solutions across data centers and digital workspaces.

Elevate and Consolidate Security

Elevate and Consolidate Security

USSFCU went from planning to deployment in just weeks, replacing multiple legacy security tools with NSX for networking and micro-segmentation as part of their zero trust initiative.

Expand Your Virtual Cloud Capabilities

Deliver Intrinsic Security

Leverage your infrastructure to provide deep visibility and security for your network and workloads across data center, cloud, WAN, and endpoints.

More on Intrinsic Security 

Build on a Foundation of NSX

Connect and protect applications across your data centers and clouds with virtualized networking and security via VMware NSX.

More on NSX 

Get Advanced Threat Detection with IDS/IPS

Replace discrete appliances with a distributed software IDS/IPS solution to detect lateral threat movement on east-west traffic & easily achieve compliance.

More on NSX Distributed IDS/IPS 

Get Recommended Security Policies

Simplify operationalizing micro-segmentation with rich application topology visualization and automated policy recommendations.

More on NSX Intelligence