Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

JOINT SOLUTION BRIEF

Automated Application Visibility for


the Software-Defined Data Center
Introduction
The Challenge Limitations of physical networking and traditional security in an increasingly dynamic
Current network and security virtual world create artificial barriers to fast provisioning of networking and security
solutions are rigid, restricted to services and simplified network operations. Manual provisioning and fragmented
one cloud deployment, and often management interfaces reduce efficiency and limit the ability of enterprises to rapidly and
vendor-specific. This creates a securely deploy, move, and scale applications and data to meet business demands.
costly barrier to data center agility,
efficiency and scale. Paramount to securing and monitoring the SDDC infrastructure is the ability to
have an immediate and rich understanding of activity in your network. Security,
Integrated Solution application and network monitoring solutions require traffic visibility of both virtual and
Software Defined Data Centers physical infrastructure.
(SDDC) enable fast provisioning
of networking and security Pervasive visibility into the data center enables application and security monitoring
services, simplified operations and tools to analyze congestion points, security threats and application behavior. This helps
fundamentally better security for data automate, secure and optimize the data center network.
centers. Gigamon and VMware have
developed an integrated multi-cloud
The Gigamon and VMware Joint Solution Overview
solution that leverages the Gigamon
Visibility Fabric and the VMware Using the Software Defined Data Center approach, Gigamon, a leader in traffic visibility
NSX-V/T network virtualization suites. solutions and VMware, the leader in server and network visualization are providing
This solution delivers pervasive pervasive and intelligent infrastructure visibility by integrating the Gigamon Visibility
and automated visibility of traffic Fabric with the VMware NSX platform.
traversing both physical and virtual
workloads and networks. VMware NSX is the leading network virtualization platform that delivers the operational
model of a virtual machine for the network. Similar to virtual machines for compute,
Joint Solution Benefits virtual networks are programmatically provisioned and managed independent of
• Automate application-layer underlying hardware. NSX reproduces the entire network model in software, enabling
traffic visibility in multi-cloud any network topology—from simple to complex multi-tier networks—to be created and
environments with NSX-T provisioned in seconds.
• Enable SecOps and NetOps
teams to automate the selection, Legacy NSX-V solutions are tied to VMware-based infrastructures. With NSX-T, VMware is
filtering and forwarding of the ever focused on emerging application workloads and architectures.
growing east-west virtual traffic for
security and monitoring analytics Relative to its predecessor, the new suite is hypervisor agnostic, decoupled from vCenter,
• Dynamically update policies/rules can run in multiple clouds, supports container-as-a-service (CaaS), and is interoperable
and monitor new and relocated with Kubernetes container orchestration methods.
VMs with vMotion
• Deploy over existing physical The Gigamon GigaVUE Cloud Suite for VMware is an innovative solution that delivers
networks or next generation pervasive and dynamic visibility of traffic traversing communication networks. This
topologies including multi-cloud Visibility Fabric significantly improves network flexibility by enabling static tools to
and container without disrupting connect to dynamic, virtualized applications, so users can efficiently and securely address
the production network their business needs.
• Instantiate G-vTAP VM using
NSX Dynamic Service Insertion The Visibility Fabric consists of distributed physical nodes (GigaVUE HC Series platforms)
without manual intervention and virtual (G-vTAP VM) nodes that provide an advanced level of filtering intelligence. At
• Enable monitoring in micro- the heart of the fabric is Gigamon’s patented Flow Mapping® technology that identifies
segmented environments with and directs incoming traffic to single or multiple tools based on user-defined rules
superior tenant security implemented from a centralized fabric management console, GigaVUE-FM. The fabric is
fully integrated with NSX and is certified in both NSX-V and NSX-T environments.

1
JOINT SOLUTION BRIEF | AUTOMATED TRAFFIC VISIBILITY FOR THE SOFTWARE-DEFINED DATA CENTER

REST APIs

Software-Defined Visibility
vCenter APIs, Events
NSX-T/V Manager
NSX APIs, Service Insertion
Virtual Traffic
Centralized Tools
GigaVUE-FM
Security

vCenter Anti-Malware
VXLAN=6000
POWERED BY
GigaSMART® IDS

SSL
Visibility &
DLP
Decryption Analytics Fabric
TLS 1.3
Advanced
Network Forensics
Flow Slicing

APT
Internet Application
Intelligence
De-cap VXLAN
Monitoring

Application Application Performance


Metadata

Network Performance
Header
TAPs Stripping
NetFlow/AMI Metadata
Customer Experience
G-vTAP VM
Filtered and Sliced Virtual Traffic

How the Joint Solution Works


• Using GigaVUE-FM, discover the inventory of the SDDC • VMware NetX automates the traffic visibility for new VMs in
managed by vCenter and NSX-T/V Manager using NSX APIs the Security Groups as n-tier applications scale-out
• Insert Traffic Visibility Service using the Gigamon Visibility • G-vTAP VM adds additional L2-L4 filtering and packet
Fabric and the virtual visibility component, G-vTAP VM slicing optimizations and forwards the traffic to the Gigamon
• Define and associate traffic policies to NSX Security Groups Visibility Fabric
using NSX APIs • For better traffic insight and inspection, additional filtering
• VMware NetX APIs and Copy Packet feature, filters and and L4-L7 optimizations, NetFlow/metadata generation or
copies the micro-segment’s virtual traffic to G-vTAP VM SSL decryption can be enabled on the Gigamon Visibility
Fabric before delivering to the security and monitoring tools

VMware vCenter
NSX-T/V Manager GigaVUE-FM
1 vCenter and NSX APIs for Inventory, Security Groups, Events

NetOps / SecOps
Admin
2 Register ‘Gigamon Traffic Visibility Service’ and ‘Traffic Policies’
Cloud
Admin
ks
ec

3 Deploy ‘Traffic Visibility’ Service VM on NSX Cluster


Ch
cy
oli
cP

4 Associate Traffic Policies to Security Groups


raffi

APM
dT
an
tus

Visibility &
Sta

Analytics Fabric
7

SG1 SG2 SG3 G-vTAP VM SIEM

VM VM VM

6 Filtered Virtual Traffic

vSwitch APT
5 Copy Packet

VMware NSX-T/V

For more information on Gigamon and VMware, visit:


www.gigamon.com and www.vmware.com

© 2019-2020 Gigamon. All rights reserved. Gigamon and the Gigamon logo are trademarks of Gigamon in the United States and/or other countries. Gigamon trademarks can be found at
www.gigamon.com/legal-trademarks. All other trademarks are the trademarks of their respective owners. Gigamon reserves the right to change, modify, transfer, or otherwise revise this publication
without notice.

Worldwide Headquarters
3300 Olcott Street, Santa Clara, CA 95054 USA
+1 (408) 831-4000 | www.gigamon.com 05.20_08

You might also like