SSP 5.1: DFW 1-2-3-4, a guided path to microsegmentation

This is part 2 of my SSP series. In the first post I explained what SSP is. SSP 5.1 arrived together with VCF 9.0, and one of its big additions is DFW 1-2-3-4. It’s a feature of Security Intelligence, available through SSP 5.1.

What is DFW 1-2-3-4?

It’s a guided workflow that takes you through segmentation in stages, following the lateral traffic patterns in your environment. Under the hood an analytics engine discovers communication patterns, identifies unprotected traffic and recommends firewall rules.

The idea is to prevent you from jumping straight to application-level microsegmentation without the visibility you need. Instead you start with the quick wins and work towards the application level.

The four stages

1. Security Segmentation Assessment & Report

You generate a Security Segmentation Report that shows your current posture. The segmentation score re-calibrates automatically when your environment changes, so you can track progress over time and show it to management or auditors.

2. Infrastructure (shared) services

Protect DNS, NTP, Syslog, SNMP, DHCP and LDAP first. The workflow discovers these services for you, or you can feed your known endpoints through a CSV file. Locking down DNS alone already removes some of the most common command and control and exfiltration paths.

3. Environment (zone) segmentation

Define zones like Dev and Production. You can import the metadata from a CSV, for example exported from a CMDB like ServiceNow or from vCenter. The workflow assigns the security tags, creates default zone-level rules and monitors for traffic leaking between zones.

4. Application microsegmentation

This stage has three steps:

  • 4a. Map workloads to applications, again via CSV. The workflow auto-tags them and creates the application groups.
  • 4b. Define ring-fencing for each application. The system recommends rules that only allow communication between the permitted entities.
  • 4c. Continuously monitor the applications, before and after publishing rules, and fine-tune the rules between the application tiers.

My take

VMware says a typical rollout can be done in as little as a few weeks. I’d treat that as a best case, because the CSV input (zones, workload-to-application mapping) depends on how good your CMDB data is. But the structure alone is useful, especially in brownfield environments where nobody knows exactly what talks to what.

What is the Security Services Platform (SSP) in VMware vDefend?

When I started working with vDefend, I quickly noticed that SSP is often treated as “that thing you also have to deploy”. In reality it’s the foundation for a big part of the vDefend feature set. This is the first post in a small series about SSP. Here I explain what SSP is and what runs on it. In the next posts I’ll go through what’s new in SSP 5.1 and 5.2.

What is SSP?

SSP is a high-performance, scalable platform that runs vDefend features like the Security Segmentation Report and Score, Security Intelligence, Metrics, Network Detection and Response, Malware Prevention and Network Traffic Analysis. Think of it as a scale-out data lake that ingests network flow records and telemetry. On top of that data it gives you flow visibility, security assessment scores, policy recommendations and guided workflows.

Under the hood it’s Kubernetes. You deploy it with the SSP Installer (SSPi) appliance, and once it’s running you can follow what’s happening with plain kubectl commands. I used that in a previous post to follow an NSX onboarding.

What doesn’t run on SSP?

This one confuses people. The enforcement itself stays in NSX. Distributed Firewall, Gateway Firewall and the malware policy and service VM management are still done through the NSX API. So your firewall keeps working without SSP. What you miss is the analysis, the guided workflows and the advanced threat prevention on top of it.

Why a separate platform?

Processing flow data from a whole private cloud needs its own scalable layer, separate from the NSX management plane. SSP is a self-contained, scale-out platform with a simplified network design and streamlined lifecycle management. That makes deploying Security Intelligence, NDR and Malware Prevention a lot easier than it used to be.

Related