VMWORLD 2021 JAPAN Returns SASE & SD-WAN Digest version

VMWORLD 2021 JAPAN Returns SASE & SD-WAN Digest version

In Session 1 on the second day, Shinichi Ohira, Director of the Vehemware Network & Security Division Technical Division, was in charge of the lecture under the theme of "VMWORLD 2021 JAPAN's Review SASE & SD-WAN Digest Version".

The agenda of the lecture is as follows.Each will touch the contents in order.

VMware Sase and SD-WAN4.5

VMware Sase, a cloud host solution, allows users to use cloud applications with enhanced security, regardless of location, using any device.You can build an access environment that maintain reliability and pursue efficiency.

Against the backdrop of Corona's evil, telework is normal.It is no longer a special thing, and has changed to a prerequisite for working styles.However, many corporate networks have not been able to catch up before they accept full telework.

It is managed in a boundary defense -type security environment assuming a "company environment", and even from home or cafes, it must go through the data center of the headquarters through VPN (Virtual Private Network).There is an inefficient side because it does not become.There were also issues due to the unable to process traffic that exceeded the number of users expected by VPN.The distributed work environment, which is assumed by remote work, has created various concerns:

Therefore, VMware advocates the idea of "Anywhere Workspace".In an environment where users and software are scattered everywhere, networks and security are not integrated into on -premises, but ideas to be clouded and served.

The lecture introduces services that connect various SaaS and IAAS, and VMware Sase using SD-WAN, and a service that connects users and devices in all places.In addition, SD-WAN4.5 also achieves functional expansion regarding integration with ZSCaler.

Zscaler Integration Enhancement

VMware SD-WAN has been combined with ZSCaler products, but will continue to support it.

VMworld 2021 JAPANの振り返り SASE & SD-WAN ダイジェスト版

When trying to go out of the SD-WAN gateway, it can be linked to the ZSCALER service, but in the future, in addition to the conventional IPsec (Security Architecture for Internet Protocol), it is GRE (Generic Routing Encapsulation).It supports automatic connection functions.

Connect to zscaler with minimal settings and provide 2Gbps performance.It introduces various functions, such as automatically enabling health checks in Layer7.

Utilization of VMware SD-WAN in multi-cloud

VMware has focused on Microsoft Azure in multi -cloud efforts.VMware has been officially certified by Microsoft as an SD-Wan manufacturer, and introduces that a global WAN configuration can be made in combination with SD-WAN and Azure.

VMware SD-WAN can also be deployed on Google's Google Cloud Network.By changing the route of the cloud rotor and VMware centalouter SD-WAN with BGP (BGP), the regional communication that is provided by Google can also communicate over regions.

He also mentioned in cooperation with AWS Cloud Wan announced in December 2021.It introduces that the network can be logically divided by using segments and VRF (Virtual Routing and Forwarding) to enhance safety.

Edge Network Intelligence

VMware Sase, SD-WAN, has a service called Edge Network Intelligence.This is to monitor the performance of various applications during the network and provide a network solution that can be used comfortably.

These are performed automatically using machine learning.It is said that the assumed use case is from ① to ⑤ in the following figure.

① Application experience for each client

② Most the most important device is operated

③ Telework and business continuity

④ Make sure the wireless environment of the remote site

⑤ SLA goal, service upsel, workflow integration

Through these initiatives, reducing the problem of telework environments will reduce the burden of the information system department.

Zero truss environment realized by SASE

VMware SASE has begun to provide VMware SD-WAN functions.This will provide a secure environment of telework in line with the concept of zero trade, which will be a new guideline for network security.

The company also says that using the cloud web security provided by VMware to access SaaS and the Internet can provide a quick and comfortable environment while ensuring safety.