VMware Security Blog 09月29日 10:48
vDefend 9.0 增强功能:提升私有云安全与效率
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

VMware vDefend 9.0 针对 VMware Cloud Foundation (VCF) 9.0 推出一系列重要更新,旨在加速企业私有云环境的横向安全防护和威胁响应。新功能包括 VPC 感知横向安全,实现多租户环境下的精细化控制和隔离;自助式微隔离,允许应用所有者在中心化策略框架内自行配置安全规则,支持 DevOps 流程自动化;以及简化的 vDefend 迁移至 VCF 的集成,保留现有策略,降低迁移成本。此外,全球集中式 IDS/IPS 策略管理和实时 IDS/IPS 签名查询门户,显著提升了威胁检测和响应能力,而 Geo-IP 过滤功能则提供了对全球流量的精细控制,共同构建更强大、更易于管理的零信任安全架构。

🔒 **VPC 感知横向安全:** 此次更新最大的亮点之一是引入了 VPC 感知横向安全。这意味着 vDefend 的安全策略现在可以部署在虚拟私有云 (VPC) 层面,为每个租户提供独立的、隔离的安全管理。这极大地增强了多租户环境下的安全隔离能力,并支持更精细化的权限委托管理,使得每个 VPC 管理员只能管理其自身 VPC 的配置,从而实现安全和效率的双重提升。

🛠️ **自助式微隔离与 DevOps 集成:** vDefend 9.0 赋予了应用所有者更大的灵活性,允许他们在基础设施团队创建的中心化安全策略框架内,自行配置细粒度的微隔离规则。这些策略还可以通过 API 在 DevOps CI/CD 流水线中实现自动化,极大地加速了应用的部署和安全策略的实施过程,真正将安全融入了开发生命周期。

🔄 **简化的 vDefend 迁移至 VCF:** 对于已有 vDefend 部署的用户,新版本提供了无缝迁移方案。现有的 vDefend 部署可以轻松导入到 VCF 9.0 环境中,并保留所有策略配置,这大大降低了迁移的复杂性和成本,使用户能够更快速、更高效地过渡到完整的 VCF 平台。

🚨 **增强的集中式威胁检测与响应:** 全球集中式 IDS/IPS 策略管理功能确保了在分布式 VCF 部署中实现一致的安全策略执行,并支持为不同环境分配特定的签名包。新增的 IDS/IPS 签名查询门户允许用户实时研究签名更新,无需登录 vDefend 控制台,这极大地提高了安全分析师的效率,增强了威胁覆盖意识和事件响应能力。Geo-IP 过滤功能则允许直接在网关防火墙层面根据地理位置允许或阻止流量,提供了更精准的流量控制。

🌐 **多实例 VCF 环境下的统一安全管理:** 对于拥有多个 VCF 实例的大型企业,vDefend 9.0 提供了跨实例的统一 IDS/IPS 策略管理能力,即使在气隙(air-gapped)环境中也能实现签名包的交付。所有 IDS/IPS 事件都集中显示在一个管理控制台中,显著简化了大规模部署的安全运维工作。

New enhancements include VPC-Aware Lateral Security, Self-Service Micro-segmentation, Streamlined vDefend Migration to VCF, and Global Centralized IDS/IPS Policy Management for Accelerated Threat Response and Enforcement 

The modern enterprise is rapidly adopting a private cloud strategy for its environments. A recent research study involving 1,800 senior leaders revealed that their organizations are prioritizing private cloud to address challenges stemming from cost concerns, the need for predictability, AI workload requirements, lateral security, and compliance. 

With digital enterprises doubling down on private cloud strategies, IT and security teams face the challenge of securing workloads as quickly and efficiently as possible. With most ransomware breaches involving lateral propagation of threats to hunt for high-value assets, security strategies are evolving to protect both critical and non-critical workloads across all private cloud deployments. vDefend is a leading software-defined, hypervisor-integrated, lateral security solution purpose-built to comprehensively protect every VMware Cloud Foundation (VCF) workload. vDefend brings robust, integrated network security controls directly into the VCF fabric. The solution enables micro-segmentation and threat defense to be rapidly adopted, managed, and scaled, ultimately accelerating an organization’s zero-trust implementation strategies. 

We are excited to announce new vDefend innovations for VCF 9.0:

vDefend implementation with VCF 9.0 makes advanced security easier to adopt, tenant-aware, and centrally managed, turning security from a barrier into a built-in capability.

VPC-Aware Lateral Security

Multi-tenancy is foundational for enterprises, but achieving complete isolation across both the data and control planes has been a persistent challenge. The introduction of VPCs brought significant improvements by enabling both data and control plane separation for networking and security, allowing for more granular application-level isolation, often managed by the DevOps team. 

With the VMware Cloud Foundation (VCF) 9.0 release, vDefend extends lateral security capabilities to deliver true per-VPC network isolation with microsegmentation, allowing only trusted application traffic. This enhancement enables delegated administration, ensuring that each VPC admin can only view and manage configurations within their own VPC. Teams can now work in parallel with full self-service and complete isolation, making secure multi-tenancy in private clouds a reality.

Self-Service Micro-segmentation

vDefend Firewall empowers both infrastructure administrators and VPC owners. Infrastructure administrators can establish secure Virtual Private Clouds (VPCs), minimizing east-west communication. Simultaneously, VPC owners gain the flexibility to configure detailed rules for their applications, ensuring functionality without compromising central security policies. This approach promotes security self-service for end-users while upholding the organization’s overall security posture.

Seamless Migration with VCF Import

Existing vDefend deployments outside of VCF can be easily imported into the VCF 9.0 environment with their current vDefend Firewall policies intact, which reduces the overhead associated with transition. This streamlined migration process enables customers to transition to a full-stack VCF platform efficiently, reducing overhead and eliminating the need to start from scratch.

Simplified, Centralized IDS/IPS Policy Management Across Multi-instance VCF with Air-Gap support 

Large, multi-instance (federated) VCF environments require a consistent, organization-wide IDS/IPS security policy and signature management with efficient and easy operations. Customers can now deliver global IDS/IPS security policies across distributed VCF deployments with centralized policy management capabilities. 

In addition, multiple IDS/IPS signature bundle assignments enable users to apply specific signature bundles where needed across their VCF deployments. For air-gapped environments, delivery of IDS/IPS signature bundles to Local Managers is supported even when internet connectivity and compliance restrictions are in place. 

Together, these capabilities offer consistent, centralized threat prevention policy management across multi-instance VCF deployments. All IDS/IPS events are visible within a single management console.

Real-Time Visibility With New IDS/IPS Signature Portal

Keeping security defenses current is non-negotiable; enterprises rely on frequent signature updates to stay ahead of emerging threats. While vDefend already makes it easy to download and review the latest IDS/IPS signature bundles through the vDefend console, security analysts often need deeper insight, such as identifying what’s new in each bundle, tracking version history, searching for coverage against specific CVEs (Common Vulnerabilities and Exposures), or looking for coverage against specific attack patterns such as Command and Control communications. 

With the new IDS/IPS Signature Portal, we’re introducing a powerful tool that allows operators to research signature updates in real time, without needing to log into the vDefend console. With easy web-based access, the portal lets teams research signatures, search for specific threat coverage, compare versions, and export signature lists. This capability not only streamlines initial planning and deployment but also facilitates easier collaboration and quicker action among teams, ultimately enhancing threat coverage awareness and incident response across the organization.

 

Precision Control of Traffic Flows with Country-based Geo-fencing of Traffic

Infrastructure administrators can now allow or block incoming and outgoing traffic based on specific geographic locations in vDefend Gateway Firewall. This new capability provides precise, targeted control of traffic, enhancing security posture and ensuring compliance.

 

Join Us at VMware Explore 2025 

Mark your calendars for August 25-28, 2025! We will be sharing all the details of these new innovations at VMware Explore 2025 in Las Vegas. You can find all the exciting event details, including new registration pricing packages here.

The post VMware vDefend Integrations with VMware Cloud Foundation 9.0: Accelerating Lateral Security for All VCF Applications appeared first on VMware Security Blog.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

vDefend VMware Cloud Foundation VCF 9.0 Lateral Security Micro-segmentation Zero Trust Private Cloud Security IDS/IPS DevOps Security Multi-tenancy vDefend 9.0 Cloud Security Network Security Threat Response VPC Security
相关文章