VMware plans to run its distributed firewalls in smartNICs in a move that will allow enterprises to attach security to sensitive applications.
This plan to put its NSX Services-Defined Firewall in a smartNIC builds on VMware’s Project Monterey, which it announced at September’s VMworld event. It’s a collaboration with chipmakers including Intel and Nvidia that uses VMware software to provide a consistent management platform for distributed compute across multiple hardware accelerators using smartNICs. Offloading virtualization and security functions to the smartNICs frees up CPU cycles to run applications, which translates to data center cost savings.
VMware first announced its NSX Services-Defined Firewall at RSA Security Conference in 2019.
VMware Monterey SmartNICs
“The news we’re announcing today is that we take that same firewall code, and we can actually run it in the network interface card,” said Tom Gillis, SVP and GM of VMware’s Networking and Security business unit. “So it’s not an agent, but it’s not a network device.”
Instead, Gillis described it as an “interesting hybrid” that will allow these smartNICs to run Layer 2 and Layer 3 switching and routing at line speed. They will also run stateful Layer 4 and Layer 7 firewall services as well as VMware’s IDS/IPS signatures and its ESX hypervisor.
The firewall capabilities “are particularly interesting for an application like a high-performance database, because the database is often so high performance that you don’t even want to virtualize it, you don’t want to put a hypervisor on it, and you’re certainly not gonna put an agent into it.”
These databases are where “the crown jewels often reside,” and yet they are frequently the least patched systems in an enterprise data center, Gillis said. “They are the most vulnerable, and yet they have the most valuable data.” Putting an application layer firewall in the NIC essentially adds an air gap and isolates this sensitive data, he added.
Plus, the hypervisor will allow VMware to also provide management capabilities such as using its vMotion software to migrate workloads between bare metal servers, Gillis added. “I know it sounds like alchemy. Taken together, this is a very, very powerful set of capabilities that will be running in the network interface card, and it opens up a whole new type of deployment for this hybrid, virtualized-slash-bare-metal implementation in the data center.”
VMware hasn’t said when its NSX Services-Defined Firewall will be available in smartNICs.
Comments