Next generation networking: VMware NSX-T

Today, our expert Kris joins us from his home office to take you into the world of Next Generation Networking.

‍

Written by
Iris Nicolaas
&
Posted on
22
-
04
-
2021
2024
Written by
Iris Nicolaas
&
Posted on
22
-
04
-
2021
2024

Kris: “Next Generation Networking is a popular term with a broad meaning. Every industry and organization puts its own spin on it. We are also working on Next Generation Networking, and for us, it means focusing on the latest trends in networking. But what are those trends, in our view? And how are we responding to them?

The trends: security and Software Defined Networking

In the world of networking, we are seeing two major trends:

  1. Integration with security: everything today revolves around secure connections.
  2. Software Defined Networking: innovations are increasingly being implemented via software (virtually) rather than physically, with far-reaching automation capabilities as a key benefit.

How does Fundaments integrate these innovations?

For us, Next Generation Networking this year is all about integrating security solutions and innovations into our network architecture. A key part of this is the rollout of VMware NSX-T. This allows us to enable full-stack network and security virtualization. With NSX-T, we connect and protect applications across our Cloud infrastructure, including VMs, containers, and bare metal servers. VMware NSX-T is a complete network and security virtualization platform that enables us to protect and manage both Public and Private Clouds. This fits seamlessly with our Multi-Cloud strategy.

VMware NSX-T offers several major benefits for our customers:

Security through micro-segmentation

Thanks to micro-segmentation, applications are protected down to the individual workload. This means that not only does the virtual datacenter get its own firewall, but a firewall can be configured for every single component of an application. This creates highly specific, multi-layered security focused on protecting all parts of an application. In the event of a security trigger, you can act very specifically and isolate an individual component to prevent any further impact on the environment.

Security through IDS/IPS

Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) are automated systems that detect and act upon unauthorized access to your network or machine. Because NSX-T IDS/IPS can be configured per application component, it is possible to apply granular security rules for maximum control over network security. By linking with firewalls, it is even possible to make the security policy self-learning by using an application over a period of time and analyzing the network traffic. Based on this analysis, a set of security rules can then be applied.

Advanced load balancer

Modern applications are increasingly using load balancers. This load balancer distributes the load within the cluster where an application is running. A next generation has been introduced here as well: features like auto-scaling, as well as integration with analytics and web application firewalls, make scaling and load management intelligent. Scaling is truly based on usage, and abuse is filtered out immediately. With this new generation, smart scaling takes application availability to the next level. Current load balancers can be replaced or expanded with a new NSX-T advanced load balancer (AVI), which includes all these new features.

Through all these techniques, we can implement what is known as Zero Trust Security: it is possible to gain control over network traffic across all layers of the network, at any location, and for every application.

Cross-VDC networking

The introduction of these innovations into the technology stack also brings a degree of complexity. That is precisely why it is important to focus on management. Applications are becoming more demanding in terms of infrastructure, but they also require more physical locations and different Cloud platforms. Fundaments provides ease of use here as well: with NSX-T, management of your VDC networks can be handled from a single overview. Adding networks that need to be rolled out and secured across multiple locations can be done from one place. These Cross-VDC networks literally bridge multiple Clouds and make daily management a lot easier.”

Kris

ABOUT KRIS

Kris is an enthusiastic Network Engineer who absorbs new technology and tests fresh ideas daily from the Office of the CTO. He carefully plans all potential optimizations with the Cloud Engineering team and rolls them out after extensive testing. In doing so, he makes the Fundaments network robust, versatile, and easy to manage for our customers and his immediate colleagues.

‍

No items found.
No items found.
No items found.