Arista-20 Years of Growth and Innovation
Today marks the 20th anniversary of Arista! Over that time, our company has grown from nothing to #1 in Data Center Ethernet, a highly profitable...
Enterprises are grappling with security in their infrastructure and many point products try to solve this in different use cases. As enterprises migrate from north-south to east-west traffic patterns, the need for consistent security across cloud-network and firewall infrastructure is paramount. Furthermore, additional security concerns emerge as organizations contemplate leveraging access to the public cloud along with hybrid deployment of virtual machines in the private data center. A true secure cloud architect must address both dedicated data centers (i.e. private cloud and virtual workloads) and also some of its applications into the public cloud. Migrating from legacy three-tier architecture to two-tier leaf-spine improves network performance, but adds security risk, as there is no longer an in-line natural insertion point for firewalls. Indeed, a more holistic network-wide segmentation to scale firewall services is now becoming a mandate to mitigate security threats.
Micro-segmentation Today for Secure Virtual Machines
Initiated by VMware NSX in 2014, Micro-segmentation is the application of security policies universally across the board and directly to all virtual machines providing service insertion for workloads. This comforts security teams by offering:
Deploying Micro-segmentation by using virtualized firewalls (within either a public or private cloud environment), can be achieved with an Arista Universal Cloud Network and VMware NSX. There are many additional ways to virtualize your data center and a number of well-known virtualization hypervisors available on the market, such as Microsoft HyperV, VMware’s ESXi, Xen, and KVM.
Introducing Macro-Segmentation for Secure Virtual Physical Cloud
Complementing Micro-segmentation, Arista is proud to introduce Macro-Segmentation Service (MSS™). Macro-Segmentation is another example of our pioneering innovation with real-time automation of cloud network operations, in tandem with security administration, without massive re-architectures. MSS works with server, storage, and network virtualization solutions from Arista's key partners like VMware and security leaders Palo Alto Networks, Check Point, F5 and Fortinet. This enhanced deployment of physical workloads and security services validates the vision of the software defined data center for L2-, L3- and VXLAN-based networks.
MSS is dynamically applied to cloud networks, depending on the type of host connected, for secure workload mobility and workflow visibility. As an example, the trio of Arista, Palo Alto Networks and VMware are at the forefront of driving capabilities of integrating firewalling directly using CloudVision®. This is all standards-based without any proprietary frame formats. Using our patented state-based change management makes uniform security control with Palo Alto Networks' Panorama as shown in the example below:
Example: Arista Macro-Segmentation with Palo Alto Networks and VMware
Bringing Radical Shift to Flexible Cloud Security
MSS provides dynamic and scalable network functions to insert security into the path of traffic, regardless of whether the security service or workload is physical or virtual, with elastic placement of services, firewalls and workloads. Some salient highlights include:
Summary:
I am excited by the power and potential of MSS into both the security and networking industries, where both are undergoing massive transitions to next generations. It unifies two islands, making a profound impact on our ecosystem and customers alike to deliver secure cloud networking. Together with CloudVision, we bring network-wide state integration of resources without a massive undertaking or re-do of existing enterprises. This is critical to successful deployment of uncompromised security in a private or hybrid cloud evolution. Welcome to the new world of secure cloud networking. I always welcome your comments feedback@arista.com
Today marks the 20th anniversary of Arista! Over that time, our company has grown from nothing to #1 in Data Center Ethernet, a highly profitable...
We are excited to share that Meta has deployed the Arista 7700R4 Distributed Etherlink Switch (DES) for its latest Ethernet-based AI cluster. It's...
As I think about the evolution of the CloudVisionⓇ platform over the last 10 years, and our latest announcement today, I’m reminded of three...