Micro-Segmentation TechTalk 47
Transcript
hi this is Keith Townsen and welcome to episode 47 of virtualized Geeks Tech talk so today we're going to continue the conversation around vmware's concept of the goldilock zone as a reminder The goldilock Zone basically VMware concept of the software defined data center allows uh for the hypervisor to be the central component of the data center with the hypervisor being the central component of the data center Services running in the current such as uh storage or storage compute or networking can be easily monitored by either third-party security devices or uh vmware's own tools the ideal of the goldilock zone is because the data center is virtualized and because everything's running in a single kernel granular controls can be applied uh to all three levels of the software defined Data Center one of the offshoots of the goldilock zone is vmware's concept of micro segmentation or their specific implementation of uh kind of this East West secur security zones that uh most security organizations would love to deploy but from a uh physical infrastructure perspective is Impractical so let's talk about why that's impractical in the physical data center to begin with so in the physical data center let's take the most basic basic types of uh security zones the public internet and the private data center so we'll call uh the private data center Zone one and the public internet zone two and in between these two security zones you normally have of course a firewall and this firewall can control north south flow of data so if there is a malicious Intruder on the internet trying to get into your private Network that's not allowed so everything in zone one is protected from uh devices connected to zone two the problem with this approach is that the assumption is that everything on Zone one is trusted so if we have servers within Zone one there is no Layer Two protection between the two devices or even layer three protection normally in order to compensate for that uh we can create additional zones so we can uh have a Zone one.
com for more software defined networking and infrastructure Technologies in general thanks have a great day