NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ......

9
1 Copyright © 2018 Tufin Tufin and SecureChange are registered trademarks of Tufin. Unified Security Policy, Tufin Orchestration Suite, SecureTrack, and SecureApp are trademarks of Tufin. All other product names mentioned herein are trademarks or registered trademarks of their respective owners. NSX Reference Design Document Contents Overview .................................................................................................................................. 1 VMware SDDC Approach Redefines Data Center Network Security .................................... 1 SDN and Securing East-West and North-South Traffic ......................................................... 2 Visibility and SDN – You can’t secure what you can’t see ........................................................ 4 Managing Micro-segmentation ................................................................................................ 5 Automation through Tufin Orchestration Suite ....................................................................... 6 Automation through integration with VMWare vRealize Automation (vRA) ........................... 8 Conclusion – Integration Key Benefits ..................................................................................... 9 Overview VMware SDDC Approach Redefines Data Center Network Security The Software-Defined Data Center (SDDC) enables a substantially improved operational model that provides greater speed and agility, lower operational overhead, and lower capital expenditure. VMware NSX delivers network virtualization for the SDDC, with a full service, programmable platform that provides logical network abstraction of the physical network with programmatic provisioning and management abilities. Following the successful abstraction of the compute and storage elements, network virtualization provides the next step towards a fully virtualized data center. VMware NSX also offers an opportunity to redefine the way we secure our networks. One of the fundamental challenges of network security has been the inability to isolate policy enforcement from the operational network plane. Within the SDDC, the hypervisor provides a perfectly isolated layer to enforce security policy while maintaining the application context to enable better security control and visibility. NSX provides isolation and network segmentation by default. Virtual networks run in their own address space and have no communication path to each other or to physical networks. Native firewalling and policy enforcement at the virtual layer provides segmentation, and micro-segmentation is achieved through security controls at the unit level or virtual machine level. Leveraging network virtualization

Transcript of NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ......

Page 1: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

1Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

NSXReferenceDesignDocument

ContentsOverview..................................................................................................................................1

VMwareSDDCApproachRedefinesDataCenterNetworkSecurity....................................1

SDNandSecuringEast-WestandNorth-SouthTraffic.........................................................2

VisibilityandSDN–Youcan’tsecurewhatyoucan’tsee........................................................4

ManagingMicro-segmentation................................................................................................5

AutomationthroughTufinOrchestrationSuite.......................................................................6

AutomationthroughintegrationwithVMWarevRealizeAutomation(vRA)...........................8

Conclusion–IntegrationKeyBenefits.....................................................................................9

Overview

VMwareSDDCApproachRedefinesDataCenterNetworkSecurityTheSoftware-DefinedDataCenter(SDDC)enablesasubstantiallyimprovedoperationalmodelthatprovidesgreaterspeedandagility,loweroperationaloverhead,andlowercapitalexpenditure.VMwareNSXdeliversnetworkvirtualizationfortheSDDC,withafullservice,programmableplatformthatprovideslogicalnetworkabstractionofthephysicalnetworkwithprogrammaticprovisioningandmanagementabilities.Followingthesuccessfulabstractionofthecomputeandstorageelements,networkvirtualizationprovidesthenextsteptowardsafullyvirtualizeddatacenter.VMwareNSXalsooffersanopportunitytoredefinethewaywesecureournetworks.Oneofthefundamentalchallengesofnetworksecurityhasbeentheinabilitytoisolatepolicyenforcementfromtheoperationalnetworkplane.WithintheSDDC,thehypervisorprovidesaperfectlyisolatedlayertoenforcesecuritypolicywhilemaintainingtheapplicationcontexttoenablebettersecuritycontrolandvisibility.NSXprovidesisolationandnetworksegmentationbydefault.Virtualnetworksrunintheirownaddressspaceandhavenocommunicationpathtoeachotherortophysicalnetworks.Nativefirewallingandpolicyenforcementatthevirtuallayerprovidessegmentation,andmicro-segmentationisachievedthroughsecuritycontrolsattheunitlevelorvirtualmachinelevel.Leveragingnetworkvirtualization

Page 2: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

2Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

technology,theSDDCenablessecuritytobearchitectedintothenetworkitself.Thisallowssecuritycontrolstobebasedonlogicalboundariesandmakesdatacentermicro-segmentationoperationallyfeasible.

SDNandSecuringEast-WestandNorth-SouthTrafficEast-westnetworktrafficisthetransferofdatapacketsfromservertoserverwithinadatacenterinthesameSDN(NSX)environment.North-SouthindicatesnetworktrafficfromtheNSXenvironmenttothelegacydatacenterorviceversa.

Visibilityintobothtypesoftraffic–east-westandnorth-south–iscriticalfororganizationstodeterminethebestsecuritypracticesfortheirnetworksanddatacenters.Whilemanyorganizationsfocusonsecuringexternaltrafficthatenterstheirnetworks,itisincreasinglyimportantfororganizationstomonitorinternaltrafficpatternstoidentifymalwarethathasinfiltratedthenetworkandforinsiderthreats.

Micro-segmentation(greaterdetailinafollowingchapter)significantlyreducestheattacksurfaceavailableformaliciousactivity,andlessenstheimpactofanattackspreadthrougheast-westtraffic.Ifthedatacenterissegmentedintologicalunits,datacenteradministratorscantailoruniquesecuritypoliciesandrulesforeachlogicalunit.Thistightly-coupledapproacheliminatesthetedious,error-pronemanualconfigurationprocessesthatoftenleadtosecurityflawsafteramigration.

East-WestTraffic

North-Sou

thTraffic

Page 3: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

3Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

TheTufinOrchestrationSuite™SolutionforVMwareNSXTheTufinOrchestrationSuite™isacompletesolutionforautomaticallydesigning,provisioning,analyzingandauditingnetworksecuritypolicychangesfromtheapplicationlayerdowntothenetworklayer.WiththeTufinOrchestrationSuite™,ITandsecurityorganizationscancentrallymanageandcontrolmicro-segmentation,continuouslymonitoradherenceandidentifyviolationstosecuritypolicy,andautomatechangesthroughouttheentiredata-centerviaasingleinterface.TheTufinOrchestrationSuite™providesunprecedentedvisibilityandcontrolofsecurityintheSDDCensuringaunifiedsecuritypolicymanagementacrosstheentireenterprise–includingphysicalandvirtualnetworksaswellashybridcloudplatforms.

TherearefourusecasesfortheintegrationpointsbetweenTufinOrchestrationSuiteandVMWareNSX:

1. Visibility–ViewandtrackchangestosecuritypolicyandconfigurationintheNSXenvironment.2. Micro-segmentation–defineandmanagemicro-segmentationbothwithintheNSXenvironmentas

wellaswiththeexternalDatacenter.3. Policy-drivenchangeautomation–automatechangesthroughTufinSecureChangewhileensuring

adherencetocorporatesecuritypolicy,understandthepotentialrisk,andpushchangestotherelevantdevicesinNSXandtheDFW,andoutsideofittotheappropriateFWs.

4. Integratedpolicy-drivenchangeautomation–automatechangesthroughintegrationwithVMWarevRealizeOrchestrator(vRO).

ThefollowingchapterscovertheaboveusecasesindepthwhileoutliningthebusinesschallengesandhowTufincanhelpsolvethem.

Page 4: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

4Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

VisibilityandSDN–Youcan’tsecurewhatyoucan’tseeChallenge:Whenitcomestosecuritypolicymanagement,organizationsneedtomanagetheirpoliciescentrally—eventhoughthepoliciesmaybeenforcedondifferentplatformsfromdifferentvendorsonphysical,virtual,andcloud-basedplatforms.Securitymanagersneedbroadandunifiedvisibility,anaudittrailofallchanges,andadvancedanalysisandreportingcapabilities.ConfigurationofsecurityrulesmustbeappliedtotheDistributedFirewall(DFW)withinNSX,NGFWs,andonlegacyfirewall(e.g.CheckPoint,PaloAlto,Cisco,Fortinet)toensureconnectivityandsecurity.Securitymanagersrequirevisibilityintochangesacrossallofthesefirewalls–whatwaschangedandwhochangedit–withoutjumpingbetweendifferenttoolsordifferentdashboards.Thisbecomesanecessityasenterprisesnetworksbecomemorecomplexwithagreaternumberofsecuritydevicesinstalled.TufinSolution:TheTufinOrchestrationSuite™servesasasinglepaneofglasstomanageandcontrolsecurityacrosshybridcloudandphysicalnetworks.TheSuiteprovidessecuritymanagerswiththesamelevelofvisibilityandcontrolintheirnewsoftware-definedenvironmentthattheyareaccustomedtoinatraditionaldatacenter.Inaddition,theTufinOrchestrationSuite™retainsanaccurateaudittrailofallchangesandusesadvancedchangemonitoringandanalysisforfullaccountability.Allchangescanbetrackedandreportscanbeproducedforauditorswhennecessary.Thescreenshotbelowdemonstrateschangetrackingofasecuritypolicy,ensuringthatatanypointit'seasytoseewhodidwhat,whenandwhy,andthiscanbefullydocumentedforfuturereference.

Tufin’sSecureTrackprovidesaside-by-sidecomparisonofthepolicybeforeandafterchanges.

Page 5: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

5Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

ManagingMicro-segmentationChallenge:Organizationsneedtobeabletodesignandeffectivelymanagemicro-segmentationbothinsideandoutsidetheNSXenvironment.Micro-segmentationprovidesbettersecuritybytighteningthesecuritycontrolsaroundaserver(virtualmachine)thantraditionalsecuritycontrolsbasedonsubnetsegmentation.Operationalizingmicro-segmentationrequireseffectiveconfigurationandmanagement.However,approachingthechallengeoftenleadswith“HowcanIensurethatmyNSXsegmentationisproperlyconfiguredtotakeadvantageofthisinnovativetechnology,thatserversarenotinadvertentlyexposed,andthatapplicationconnectivityisretained?”Managingmicrosegmentationinacomplexenvironmentisdifficult.Akeyparameteristobeabletotrackandmanagethiscomplexprocessinasimple,visualizedwaywithoutmanuallyapplyingdifferentsecurityconfigurationsandrulesacrossNSXandtherestofyourfirewalldevices.

TufinSolution:TherearethreewaysinwhichtheTufinOrchestrationSuite™enablessuccessfulmanagementofmicro-segmentationforNSX.TheTufinOrchestrationSuite™provides:

• Aunifiedandconsistentpolicyacrossbothphysicalandvirtualenvironments,withcleargraphicalvisibilityintothatpolicy.

• Acentralizedapproachtoidentifyingandmanagingviolationsandexceptions.• Automaticchecksofplannedchangesagainstasecuritypolicybeforeitisimplementedtomakesure

thatthechangeisnotintroducinganewpolicyviolation.ThefigureonthefollowingpageshowstheTufinOrchestrationSuite’s™zonesegmentationmatrixwhichisanelementoftheUnifiedSecurityPolicy(USP).Thismatrixrepresentsthedifferentnetworkzonesonboththehorizontalandverticalaxes,andthecolorsoftheblocksindicatethepermittedcommunicationbetweenthetwointersectingzonesshouldbe.Inthezonesegmentationmatrix,agreenblockrepresentsthattrafficofspecificservicesbetweentwozonesisallowed,agrayblockmeansthattrafficisnotallowed,andaredblockindicatestrafficisallowedwhichcurrentlyviolatessecuritypolicy.Eachzonerepresentsphysical,virtualorhybridcloudplatforms.

Page 6: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

6Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

TheTufinOrchestrationSuite™zonesegmentationmatrix

IntheNSXenvironmentzonescanbeIPsorsubnets,butaremostoftenSecurityGroupsgiventhedynamicnatureoftheSDDC.AsVMsareprovisionedanddestroyedrapidly,theusageofIPslessrelevantduetounmanageability.Onceanorganizationhasdesigneditssegmentationpolicyandimplementedittoproducethevisualmatrixview,theTufinOrchestrationSuite™analyzesthenetworktoidentifythegapsbetweenthedesiredstateofsecuritypolicycomplianceandtheactualenforcementpoliciesrunningacrossnetworkfirewalls,routers,andsecuritygroups.Unlikemanualspreadsheetsthatsecurityadministratorsoftencreateandrelyon,thismatrixisconnectedtothenetworkandautomaticallydetectsandalertsfirewalladministratorsofviolations.ForNSX,thisensuresthatifaruleisaddedtotheDFWortotheperimeterFW,theimpactontherelevantzonesisknown.Operationalneedsoccasionallyrequireanexceptiontoadesiredsegmentationpolicy.Forexample,allowingaspecificbusinessapplicationnon-compliantorriskyaccessmayberequiredinordertorunproperly,eventhoughitintroducesrisktotheorganization.TheUnifiedSecurityPolicyprovidescentralizedexceptionmanagementthatallowsasecurityadministratortoidentifyandmanageexceptions,assignanexpirationdatetonon-compliantrules,andensurethattheyarere-examinedandapproved,orremoved,byaspecificdate.Thisprocessprovidesthesecurityadministratortimetotalkwiththebusinessapplicationownerandfindawaytoeitherchangehowtheapplicationworks,orchangethesegmentationpolicy.Allpolicyexceptionsareautomaticallydocumentedandauditable.

AutomationthroughtheTufinOrchestrationSuite™Challenge:NGFWs,suchasNSXDFW,andlegacyfirewallsarethefirstlineofdefense,buteffectivemanagementoffirewallsdrainspersonnelresourcesfromsecurityprogramsalreadycopingwithashortageofskilledlabor.Regardless,securitypoliciesneedtobechecked,firewallsoptimized,andcontinuouscomplianceanddemonstrablyachieved.Thesefirewallmanagementtasksaretypicallymanualprocessesthatarebothtimeconsumingandrifewithmanualerror,necessitatingasolutiontoeliminatemisconfigurationsandreturnpersonnelresourcestostrategicorimminentchallenges.WorkloadscanrundedicatedonSDNenvironmentorspanacrossNSXandon-premiseinfrastructure,henceautomationmustsupportthemultipleplatformandtechnologiesused.FailingtosupportthediversityofvendorsbeyondNSXprohibitsachievingagility,anddelaysaccesstoadatacenter’sdatabasewhenbehinddifferentfirewallsandrouters,andthetasksassociatedwithmanagingallofthem.

Page 7: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

7Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

TufinSolution:TheTufinOrchestrationSuite™providescentralmanagementandafullyautomatedchangeprocess,providingend-to-endconnectivityacrossthehybridnetworkwhilemeetingsecuritypolicymandates.End-to-endautomationofnetworksecuritychangeswithbaked-insecurityandcomplianceenablesbothNorth-SouthandEast-WestconnectivitybyprovisioningtotheNSXDistributedFirewallaswellaslegacyfirewallsusingSecurityGroups.ThechangeprocessprovidedbytheTufinOrchestrationSuite™includesautomatedriskanalysisforbuilt-inpolicycomplianceandbestpractices,automateddesignandprovisioningforon-premfirewallsandNSX,andautomatedconnectivityverificationtoboostproductivityandacceleratedelivery.TufindeliversautomatedprovisioningforchangestoNSXsecuritygroups(orIPandIPsets)andguidesuserstoensurethattherightsecuritygroupsarechanged.TheautomatedchangedesignisbasedonthemostaccuratetopologysimulationandefficientpathanalysisacrossNSXandotherplatforms/vendorsWhileallthesecapabilitiesaresupportedthroughtheSecureChangeUI,customersoftenintegrateTufinworkflowsandprocessmanagementintotheirexistingthird-partyticketingtools(e.g.ServiceNoworRemedy)throughAPIsorintegrationapplicationstokeeptheirexistingbusinessprocessesandflowsunchanged.

Page 8: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

8Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

AutomationthroughintegrationwithVMWarevRealizeAutomation(vRA)NSXandvRealizeAutomationaretwomajorproductsfromVMware.vRealizeAutomationcanbuildaprivatecloudenvironmentwhileNSXbuildstheunderlyingsoftwaredefinednetwork.BoththeefficiencyandsecuritycontrolovertheSDDCisrealizedwhenusingNSXandvRealizeAutomationinconcert.WithNSXyoucanbuilddynamicrouting,loadbalancing,firewallrulestocreatethevirtualizednetwork–vRealizeAutomationusesvRealizeOrchestrator(vRO)asitsunderlyingorchestrationengine.

IntegratingvROwithSecureChangeenablescustomerstoachievefullautomationfordesigningandprovisioningapplicationconnectivity.Together,vRAandvROcanbeusedtospinupamulti-layerapplicationthroughasingleclickalongwithitsnetwork,firewallrules,andloadbalancer.ApplicationsrunningwithintheSDDCandconsumingnon-SDDCresources(e.g.LDAPserverorDB),requirenorth-southconnectivity.ThiscanbeachievedbyincorporatingvROworkflowcallstoaTufinworkflowthroughAPIsfor:

1. TopologyDiscovery:findtraditionalfirewallsinfrontoftheprovisionedVMs.2. RiskAnalysis:CompliancecheckagainstTufinUSPbeforeimplementation.3. Provisioning:PushingchangestotraditionalfirewallsinfrontoftheprovisionedVMsrunningonNSX.

Atypicalflowcanbe:

1. DeploynewVMsfromvROworkflowbasedonVMtemplates(usingvCenterAPItoprovisionnewVMs).

2. CacheVMsnetworkinformationlikeIPAllocated,andPolicyTemplate3. UsetheHTTP-RESTClientfromvROtoopenaticketonSecureChange(JSONformattedquery)4. InSecureChange,runafullyautomatedworkflowforprovisioningrulesonCiscoASAandCheckPoint

firewallsandconnecttheVMstothenetwork.

Page 9: NSX Reference Design Document - Tufin · 2018-01-24 · NSX Reference Design Document Contents ... Automation through integration with VMWare vRealize Automation (vRA) ... , Palo

9Copyright©2018Tufin

TufinandSecureChangeareregisteredtrademarksofTufin.UnifiedSecurityPolicy,TufinOrchestrationSuite,SecureTrack,andSecureApparetrademarksofTufin.Allotherproductnamesmentionedhereinaretrademarksorregisteredtrademarksoftheirrespectiveowners.

TheaboveissimilartootherITSMintegrationlikeBMCRemedy,ServiceNow,andothertools(furtheravailableintheTufinProfessionalServicesCatalogue).

Conclusion–IntegrationKeyBenefitsTheintegratedVMwareNSX™andTufinOrchestrationSuite™solutiondeliversvisibility,unifiedsecuritypolicymanagement,andcomplianceacrossphysicalandvirtualnetworks,andhybridcloud.ThestrategicintegrationenablesITorganizationsandsecurityteamsto:

• Viewandmanagesecuritypoliciesacrossthenetworkfromasinglepainofglass,therebyreducingcomplexity.

• TrackchangestosecuritypoliciesonNSXaswellasonotherleadingcloudplatforms,andpresentwhatwasthechangeandwhodidit.

• ReduceauditpreparationtimeandenablecontinuouscomplianceusingtheUnifiedSecurityPolicy• Design,implement,manage,andmonitormicro-segmentationacrossNSX,physicalandhybrid

networks• Visualizepoliciesandnetworkconnectivityacrosstheheterogeneouscorporatenetwork,enablingIT

teamstotroubleshootconnectivityissuesquicklyandeasily• Maximizeagilitywithend-to-endautomationofnetworksecuritychangeswithbaked-insecurityand

complianceproviding:o Automatedriskanalysisforbaked-insecurityandcomplianceo Automatedchangedesignbasedonaccuratetopologysimulationandpathanalysisacross

NSXandothervendor’splatformso AutomatedprovisioningforNSXtoreducecomplexity,eliminatehumanerror,andensure

connectivity