NSX The Foundational Glue for a True Cloud Operating Model
The Cloud Operating Model
Benefits of the Cloud Operating Model Minimal Maintenance Hyperscale Agility Developer Productivity Efficient, Secure, Shared Infrastructure Flexible Consumption Built-in Resilience Advantages of On-Prem or Private Infrastructure 3
User/Device to App Network Experience [ Traditional Bottom-Up Approach ] Physical Network Infrastructure
User/Device to App Network Experience Stringent Maintenance Windows Not Elastic No Self-Service Rigid VLAN Boundaries RIGID / STATIC Physical Network Infrastructure [ Traditional Bottom-Up Approach ]
Physical Network Infrastructure [ Modern Top-Down Approach ] User/Device to App Network Experience Built Twice a Year Not Mobile No Self-Service Fixed IPs RIGID / STATIC
Physical Network Infrastructure Ubiquitous Self-Healing Running 7/24 Across Environments Self-Service Responsive [ Modern Top-Down Approach ] User/Device to App Network Experience
Abstracted Away Complexity + Better Utilization to Deliver Customer Value PHASES Virtual Infrastructure Software-Defined Data Center Multi-Cloud Platform 80% of enterprises have a hybrid cloud approach VMware vSphere VMware Cloud VMware Cloud Foundation
Abstracted Away Complexity + Better Utilization to Deliver Customer Value PHASES Virtual Infrastructure Software-Defined Data Center Multi-Cloud Platform VMware vSphere VMware Cloud VMware Cloud Foundation Networking Is The Glue That Ties It Together
SWITCHING ROUTING LOAD BALANCING FIREWALL NDR/NTA COMMODITY X86 NSX Advanced Load Balancing Network Virtualization Distributed Firewall & ATP Advanced Load Balancing Network Virtualization Distributed Firewall & ATP
HYPERVISOR App 1 App 2 App 3 Distributed Networking Fabric A Foundation for Innovation VDS The Power of the Hypervisor Full Stack Networking Networking and Security Seamless with vMotion vNIC vNIC vNIC
SINGLE POINT OF MANAGEMENT Distributed Networking Fabric A Foundation for Innovation The Power of the Hypervisor Full Stack Networking Networking and Security Seamless with vMotion HYPERVISOR VDS vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC vNIC +
Observe Flows as Workloads Move without Taps Policy Moves Seamlessly, Retires with Workload Workload with Attached Policy Limit Blast Radius of Breaches Network Virtualization = Better Security
NSX+ Futureproofed No Matter Where You Go
Partial automation is an oxymoron.
One Click. Deploy Workload
Deploy and Power-up Scale-up & Down (Sizing) Update Firewall Signatures Hairpin Traffic to the Firewall TICKET ID Vulnerable Assets Connect Network Tap to Monitoring Tool Deploy Net Tap TICKET Config VLANs Config BGP on Router Config VLAN Interfaces on Router Config Physical Switches TICKET LB Exists? Identify HW Perf? TICKET Config LB Reserve IP TICKET Config Logging and Alerts TICKET Test end-to-end (simulate events) TICKET TICKETS 34 DAYS 42 NETWORKING Security ALB NTA/NDR
WEEKS MINUTES TICKETS 34 DAYS 42 “I want to provide connectivity to my application.” Config VLANs on Hosts Config Physical Switches Config VLAN interfaces on router Config VLANs on Physical Infrastructure Attach VLANs to Router Enable BGP on Every Leaf and Spine Switch Peer BGP Between Every L eaf & Spine Peer BGP Between Leaf Pairs Configure BGP EVPN Overlays Configure VTEPs on Every L eaf Pair Configure and Enable a VLAN on Every Leaf Downlink Map VLAN to VNI on Every L eaf … Done ENABLE ON VSHPERE CLUSTER NETWORKING
Done MINUTES WEEKS Automated. Simple. Error-free. ENABLE ON VSPHERE CLUSTER Decision Automation Allocate a virtual network Distribute the virtual network info on all Hosts Distribute virtual network info to NSX Edges for N-S traffic Publish routes / reachability to external network for N-S traffic Configure and make DHCP available on virtual network Make virtual network available in vSphere to attach to VMs Make network highly available during NIC failures Extend virtual network to remote sites if required NETWORKING
How Do We Meet Both Needs? Dev teams want agility and self-service. Infrastructure teams want to maintain control.
INFRASTRUCTURE Isolated Environments with Security Domains
INFRASTRUCTURE VPC 1 VPC 4 VPC 2 VPC 3 Isolated Environments with Security Domains Self-Service With Enterprise-Level Controls
LOB - 1 Admin LOB - 2 Admin Multi-Tenancy Provider Admin Provider Environment Default Self-Service With Enterprise-Level Controls Dev Team A VPC 1 Dev Isolated Environments with Security Domains Dev Team B VPC 2 Dev Dev Team C VPC 3 Dev
Agility for your people and your budget. The OpEx and CapEx benefits of the cloud operating model
Concrete ROI Across 4000+ Enterprise Customers 59% 35% Network Virtualization Improvement Perimeter operating expense Less compute infrastructure Minimized network refreshes Day 0/1/2 operations (1-click, no tickets, workload attached policies) 73% Zero proprietary appliances 50% Network Security Cost of operations savings 6-month payback 43% Hardware replacement Advanced Load Balancing CAPEX OPEX
Advanced Load Balancing Networking Distributed Firewall & ATP Manage Your Infrastructure By Business Directives RESILIENCY PERFORMANCE SECURITY
Advanced Load Balancing Networking Distributed Firewall & ATP Manage Your Infrastructure By Business Directives RESILIENCY PERFORMANCE SECURITY Set Business Directives Infrastructure Auto Adjusts
Multiple DCs with Federated Networking DC Location 1 DC Location 2 DC Location 3 DC Location 4 Global Manager Hardware VLAN independent Common constructs for mobility, testing, and disaster recovery Solves multi-vendor interoperability issues LOCAL MANAGER
DC 2 DC 1 ACTIVE 01100101001 010 1010 01010000 10100 1010000 1000 STANDBY 01100101001 010 1010 01010000 10100 1010000 1000 Data Sync NSX DC STORM ALERT! DC Outage Chicago, IL San Francisco, CA
DC 2 DC 1 Chicago, IL INACTIVE San Francisco, CA 01100101001 010 1010 01010000 10100 1010000 1000 STANDBY 01100101001 010 1010 01010000 10100 1010000 1000 Minimal Runbook Meet/Exceed RPO Minimize RTO ACTIVE
NSX+ VMware Cloud Native Public Cloud Private Cloud Partner Cloud Simplify cloud infrastructure consumption Achieve end- to-end application visibility Use a consistent operating model for private and public clouds Policy-as-a-service, consistent across all clouds Strengthen multi-cloud security NEW
Strong Lateral Security Defense and Recovery Security that’s built into the infrastructure
Full Visibility to Connections and Conversations Network Sandbox Per Hop Distributed IDS/IPS Network Segmentation & Micro-segmentation Multi-hop Network Traffic Analysis (NTA) Network Detection and Response (NDR) Connections (L4) Conversations (L7)
Service App Web App File Server Private/Hybrid Cloud AIR GAP Service App Web App File Server On-Demand Isolated Recovery Environment 9:30 10:00 9:00 VERIFIED VERIFIED !
Private/Hybrid Cloud AIR GAP Service App Web App File Server On-Demand Isolated Recovery Environment Service App Web App File Server
We’ve Done It for So Many Others We Can Do It for You
#1 in market share, over 90% of the Fortune 100 use NSX VMware Networking Customer Momentum
NSX is the Glue of the True Cloud Operating Model Foundation for VMware’s Private, Public, and Hybrid Cloud Solutions NSX Native Public Clouds 1 Cloud connectivity aaS and perimeter services (longer-term future roadmap) Modern Apps Container networking in Kubernetes PaaS solutions Telco Networks Advanced networking topologies, performance and IPv6 for Telco / NFV market VMware Public Clouds Networking and security stack in all VMware Clouds (AWS, Azure, Google Cloud, Ali, Oracle) Service Providers (VCPP) Strong demand from managed service providers VCPP program VCF Integrated into the full SDDC with VCF vSphere Deep integration with vSphere
Take the Next Step with NSX Get our support every step of the way Schedule a Product Demo Try a Hands-on Lab Take a Test Drive
Networking & Security Update for Core
Modern Apps and Public Cloud End-User Computing Private and Hybrid Cloud TKO | TAP Aria Guardrails | Aria Cost
Infra and Ops Initiatives That Accelerate App Modernization Adding value on any cloud that matters to you Private Cloud Public Cloud Sovereign Cloud Partner Cloud Edge VMware Cloud Cloud Console Cost, Automation, Operations, Security Cloud Consumption Interface Compute Storage Network VMware Tanzu Optimize and modernize your data center to increase agility and efficiency. Modernize Protect Enforce a Zero-trust ransomware defense to safeguard your business apps and data Migrate apps using the fastest, least costly path to the public cloud. Migrate
SWITCHING ROUTING LOAD BALANCING FIREWALL NDR/NTA COMMODITY X86 NSX Advanced Load Balancing Network Virtualization Distributed Firewall & ATP Advanced Load Balancing Network Virtualization Distributed Firewall & ATP
Outcomes Achieve speed, agility and scalability of cloud with control and security of on-premises data center Automate deployment and lifecycle management Accelerate modern app development- Set-up a developer-ready Kubernetes on-premises, using existing VMware tools and skills Lower TCO – reduce costs with consistent operations and cost-effective move to the cloud of your choice Implement a multi-cloud operating model with unified management across cost, performance, secure configuration, and delivery automation Impact ROI on implementing private/hybrid cloud model with VMware* Time it takes to recoup investment in private/hybrid cloud* 171 % 9 months * Forrester The Total Economic Impact™ Of VMware’s VMware Cloud Foundation, 2022VMware, Inc. Modernize the Data Center NSX Networking & Security, NSX-ALB, HCX+, Antrea Container Networking, NSX+
Outcomes Strong lateral security, including micro-segmentation and behavioral-based detection, to find and evict threat actors Consistent networking and security posture across clouds Confidently and rapidly recover from modern ransomware attack Solution identifies, cleanses, validates and prevents reinfection during the recovery process Impact Protect Apps Using Zero Trust Ransomware Defense 360 % Reduction in CAPEX and OPEX from implementing a more efficient and effective networking and security architecture with VMware* 50 % 73 % ROI comparing the average cost of a ransomware attack to the cost of VMware Zero Trust Ransomware Defense** * VMware Internal Study **VMware Internal Analysis based on “Comparing the cost of a ransomware attack ($4.62M per Ponemon and IBM Cost of a Data Breach Report 2022) to the cost of VMware Ransomware Recovery solution. NSX Security (Distributed Firewall & ATP), NSX+
Outcomes Consolidate, right size or evacuate entire data center Intelligently plan, migrate and modernize apps according to business need Easily extend the data center to any cloud to meet capacity or seasonal demands Adopt a consistent cloud operating model - improve performance, reduce risk and costs Impact Migrate Select Apps or Whole Data Centers to the Cloud 50 % 46 % Faster cloud migrations on average over alternative approaches* TCO savings compared to using traditional public cloud IaaS** * IDC - The Business Value of Running Applications on VMware Cloud on AWS in VMware Hybrid Cloud Environments ** “Comparing VMware Cloud to Traditional Public Cloud by Total Cost of. Ownership. ”Brandon Da Costa, Craig Stanley and Bill Roth, 2022 ***Forrester TEI Study, The Total Economic Impact™ Of VMware vRealize Operations, Sept 2021 90 % Reduction in unplanned downtime*** HCX/HCX+, Aria Ops for Networks, NSX ALB, NSX Adv Firewall, NSX+