This hypervisor-based security solution for virtualized data centers and clouds gives full visibility and granular access control over all traffic within and between virtual machines.
Data Center Security Demo vGW DemoNeed Help?
The vGW Virtual Gateway security solution for virtualized data centers and clouds monitors and protects them while maintaining maximum capacity and performance. Its hypervisor-based stateful firewall integrates intrusion detection (IDS),virtualization-specific antivirus (AV) protection, and compliance tools, with management scale.
VM Introspection gives vGW a complete view of network traffic flowing between VMs, and a complete VM and VM group inventory, including virtual network settings, and knowledge of all VM states, including installed applications, operating systems, and patch levels.
The stateful firewall provides layers of defenses and automated security through access control over all traffic using policies that define which ports, protocols, destination and VMs, should be blocked.
An integrated intrusion detection engine inspects packets for malware or malicious traffic and sends alerts as appropriate, whileAV protections provide on-demand and on-access scanning of VM disks and files with full quarantine capabilities.
vGW monitors for and enforces corporate and regulatory policies, including segregation of duties, business-warranted access, and ideal/desired images and configurations, for all transactions in the virtual space. VM access is limited by application, protocol and VM type as well as by role.
Smart Group policies are created from a synthesis of VM Introspection and vCenter information, ensuring that certain types of VMs are secured with appropriate policies. The VM Image Enforcer ensures that any image deviation triggers an alert or a VM quarantine.
| Feature | Benefits |
|---|---|
| Stateful virtual firewall | Granular access control and VM isolation via policy enforcement for groups and individual VMs |
| VMsafe implementation | Certified hypervisor-based security processing for breakthrough performance with more than 10x the throughput of non-VMsafe fast-path virtual firewalls |
| VM Introspection |
X-ray view of VMs and their installed OSes, applications and services |
| VM Image Enforcer | Enforcement of the desired or ideal VM configuration with options for alerting and/or quarantining for VMs whose image deviates |
| Virtualization-specific antivirus (AV) | On-demand and on-access scanning of VM disks and files with quarantining of infected entities |
| Intrusion detection system (IDS) |
Selectable, protocol and application-specific deep-packet inspection of allowed traffic for malware detection |
| Smart Groups | Automated VM security for newly created or replicated VMs |
| Network monitoring | Visibility and comprehensive auditing of inter-VM and intra-VM communications and Netflow-style data collection |
| Highly scalable central management | Synchronization of security policies across vGW management centers for safe, large-scale, multi-tenant virtualization |
| IPv6 / IPv4 firewall enforcement and management | Greater flexibility and efficiency of traffic protection with the ability to manage the entire vGW infrastructure via IPv4 or IPv6 addresses |
| vGW Cloud API and SDK | Time and resource savings through customization and automation of security controls during VM provisioning |