When I started working with vDefend, I quickly noticed that SSP is often treated as “that thing you also have to deploy”. In reality it’s the foundation for a big part of the vDefend feature set. This is the first post in a small series about SSP. Here I explain what SSP is and what runs on it. In the next posts I’ll go through what’s new in SSP 5.1 and 5.2.

What is SSP?
SSP is a high-performance, scalable platform that runs vDefend features like the Security Segmentation Report and Score, Security Intelligence, Metrics, Network Detection and Response, Malware Prevention and Network Traffic Analysis. Think of it as a scale-out data lake that ingests network flow records and telemetry. On top of that data it gives you flow visibility, security assessment scores, policy recommendations and guided workflows.

Under the hood it’s Kubernetes. You deploy it with the SSP Installer (SSPi) appliance, and once it’s running you can follow what’s happening with plain kubectl commands. I used that in a previous post to follow an NSX onboarding.
What doesn’t run on SSP?
This one confuses people. The enforcement itself stays in NSX. Distributed Firewall, Gateway Firewall and the malware policy and service VM management are still done through the NSX API. So your firewall keeps working without SSP. What you miss is the analysis, the guided workflows and the advanced threat prevention on top of it.
Why a separate platform?
Processing flow data from a whole private cloud needs its own scalable layer, separate from the NSX management plane. SSP is a self-contained, scale-out platform with a simplified network design and streamlined lifecycle management. That makes deploying Security Intelligence, NDR and Malware Prevention a lot easier than it used to be.
