Subscribe to Blog Notification Emails

Latest Blog Post

Security in Cloud Networking

Jayshree Ullal
by Jayshree Ullal on Oct 6, 2015 3:29:34 AM

Enterprises are grappling with security in their infrastructure and many point products try to solve this in different use cases. As enterprises migrate from north-south to east-west traffic patterns, the need for consistent security across cloud-network and firewall infrastructure is paramount. Furthermore, additional security concerns emerge as organizations contemplate leveraging access to the public cloud along with hybrid deployment of virtual machines in the private data center. A true secure cloud architect must address both dedicated data centers (i.e. private cloud and virtual workloads) and also some of its applications into the public cloud. Migrating from legacy three-tier architecture to two-tier leaf-spine improves network performance, but adds security risk, as there is no longer an in-line natural insertion point for firewalls. Indeed, a more holistic network-wide segmentation to scale firewall services is now becoming a mandate to mitigate security threats.

Micro-segmentation Today for Secure Virtual Machines

Initiated by VMware NSX in 2014, Micro-segmentation is the application of security policies universally across the board and directly to all virtual machines providing service insertion for workloads. This comforts security teams by offering:

  1. Classification of all traffic, across all ports, all the time.
  2. Reduction of threats by preventing known vulnerabilities.
  3. Prevention of unknown threats.

Deploying Micro-segmentation by using virtualized firewalls (within either a public or private cloud environment), can be achieved with an Arista Universal Cloud Network and VMware NSX. There are many additional ways to virtualize your data center and a number of well-known virtualization hypervisors available on the market, such as Microsoft HyperV, VMware’s ESXi, Xen, and KVM.

Introducing Macro-Segmentation for Secure Virtual Physical Cloud

Complementing Micro-segmentation, Arista is proud to introduce Macro-Segmentation Service (MSS™). Macro-Segmentation is another example of our pioneering innovation with real-time automation of cloud network operations, in tandem with security administration, without massive re-architectures. MSS works with server, storage, and network virtualization solutions from Arista's key partners like VMware and security leaders Palo Alto Networks, Check Point, F5 and Fortinet. This enhanced deployment of physical workloads and security services validates the vision of the software defined data center for L2-, L3- and VXLAN-based networks.

MSS is dynamically applied to cloud networks, depending on the type of host connected, for secure workload mobility and workflow visibility. As an example, the trio of Arista, Palo Alto Networks and VMware are at the forefront of driving capabilities of integrating firewalling directly using CloudVision®. This is all standards-based without any proprietary frame formats. Using our patented state-based change management makes uniform security control with Palo Alto Networks' Panorama as shown in the example below:

MSS Blog Drawing

Example: Arista Macro-Segmentation with Palo Alto Networks and VMware

Bringing Radical Shift to Flexible Cloud Security

MSS provides dynamic and scalable network functions to insert security into the path of traffic, regardless of whether the security service or workload is physical or virtual, with elastic placement of services, firewalls and workloads.  Some salient highlights include:

  • Location Independent: This allows larger data centers to centralize and insert security in the path between any workloads on demand or based on firewall rules.
  • Easy Integration: By not changing any frame formats, it allows traffic to be monitored by existing tools and ensures that any platform can be easily integrated.
  • Open: To emphasize just how non-proprietary the approach is, Macro-Segmentation can fully function if the network is multi-vendor without lock-in or proprietary protocols.
  • Agile: Hosts can and do move (vMotion and DR), so services dynamically move with them to secure the deployment model.
  • Seamless Co-existence: Arista's Macro-Segmentation Service does not try to "own policy" or run as an "uber-controller". It co-exists with defined firewall rules within the security tool framework.

Summary:

I am excited by the power and potential of MSS into both the security and networking industries, where both are undergoing massive transitions to next generations. It unifies two islands, making a profound impact on our ecosystem and customers alike to deliver secure cloud networking. Together with CloudVision, we bring network-wide state integration of resources without a massive undertaking or re-do of existing enterprises. This is critical to successful deployment of uncompromised security in a private or hybrid cloud evolution. Welcome to the new world of secure cloud networking. I always welcome your comments feedback@arista.com

Press Release

MSS Video

MSS CloudVision Site

MSS White Paper

Opinions expressed here are the personal opinions of the original authors, not of Arista Networks. The content is provided for informational purposes only and is not meant to be an endorsement or representation by Arista Networks or any other party.
Jayshree Ullal
Written by Jayshree Ullal
As CEO and Chairperson of Arista, Jayshree Ullal is responsible for Arista's business and thought leadership in AI and cloud networking. She led the company to a historic and successful IPO in June 2014 from zero to a multibillion-dollar business. Formerly Jayshree was Senior Vice President at Cisco, responsible for a $10B business in datacenter, switching and services. With more than 40 years of networking experience, she is the recipient of numerous awards including E&Y's "Entrepreneur of the Year" in 2015, Barron's "World's Best CEOs" in 2018 and one of Fortune's "Top 20 Business persons" in 2019. Jayshree holds a B.S. in Engineering (Electrical) and an M.S. degree in engineering management. She is a recipient of the SFSU and SCU Distinguished Alumni Awards in 2013 and 2016.

Related posts

The New AI Era: Networking for AI and AI for Networking*

As we all recover from NVIDIA’s exhilarating GTC 2024 in San Jose last week, AI state-of-the-art news seems fast and furious....

Jayshree Ullal
By Jayshree Ullal - March 25, 2024
The Arrival of Open AI Networking

Recently I attended the 50th golden anniversary of Ethernet at the Computer History Museum. It was a reminder of how familiar...

Jayshree Ullal
By Jayshree Ullal - July 19, 2023
Network Identity Redefined for Zero Trust Enterprises

The perimeter of networks is changing and collapsing. In a zero trust network, no one and no thing is trusted from inside or...

Jayshree Ullal
By Jayshree Ullal - April 24, 2023