VMware SDWAN Strategy - CTO Advisor 083
VMware landed into the network space with NSX. Now the company is expanding into SDWAN by acquiring Velocloud. In this replay of a CTO Dose, Keith sits down and talks to VMware’s VP and CTO of Network Security Business Unit Pere Monclus. Keith asks about VMware’s plans for Velocloud and future integration with VMware NSX. Subscribe iTunes | RSS Originally posted on CTODose.com as a video.
Transcript
com. We're on site in Palo Alto at the VMWorks campus, lovely campus, not just because they have Peet's Coffee, the most fanciest coffee that I've had so far for a CTO dose. Today, first interview of the day of many VMware interviews, I'm with the CTO of the NSBU, I hope I said that right, the network security business unit, Peter Mankos. Yes. Peter, introduce yourself, how long have you been with VMware? I've been at VMware for now over a year, it's been a great ride, it's an interesting transition from the startup world.
Before that, I was the founder of Plumgrid, it was an SEM company that we were focusing more on the OpenStack ecosystem and kind of the cloud, native cloud ecosystem. And before that, I was for many years at Cisco, I was a service engineer at Cisco. So a lot of networking chops, right before we started recording, we were talking about Iovisor and the cool stuff that Plumgrid is going. The VMware folks at some point will let me talk to you about the Iovisor work and all of that super geeky stuff.
I'll reference the blog post that I did a couple of years ago on Iovisor and Plumgrid, really cool technology, I'm looking to see how that's applicable to the enterprise. But speaking of startups and applicability to the enterprise, VMware made a huge splash, at least in my opinion, acquiring, is it VeloCloud? The acquisition closed, what, about three months ago? Something like that, November. Yeah, we're recording in February, so late November, mid November, something like that. For those who didn't know, what did VeloCloud do pre and now within VMware?
For me, the first question is about why were we interested in the SD-WAN space and what triggered that move? So the first thing is that as VMware, I mean, it's well known, we start from a data-centric position in a way that we provide infrastructure, software infrastructure to essentially power a lot of applications for enterprise. And as we go into the journey of a software-defined data center, automating everything, providing an infrastructure that automatically expands, we enter into the networking space with the NSX product line.
And what was happening is that NSX was having a great traction in the data center while providing microsegmentation, automation, disaster recovery, and so on. But the question is, what are the customers that consume the applications that you have in the data center? Right. And you have kind of two types of customers, the ones that they create an application to be consumed by users that exist in the internet, and those users would essentially connect directly from the internet to your data center or to your cloud.
But most of our customers were having a different type of situation, which is essentially the fact that you had branches, remote offices, you had retailers, you have financial institutions. And what they were coming to us saying, look, it's great to have microsegmentation, it's great to have security automation in the data center, but at the end of the day, what happens is that we still have to do a lot of configuration steps to reach where our customers are and understand the identity of them. So they were essentially living in the remote office, and in order to set up the VPN tunnels, the security policies, the whole connectivity, in order that when the requests would arrive to the data center and we could enforce the policies and automation that we had, it was too complex.
Right. So essentially, the customers were asking us, saying, how do you extend this concept of security by default, zero trust, and microsegmentation to where my employees, my users of my data center applications are? And this is what triggered us to pay attention to the SD-WAN space and to look deep into it and to eventually move with Available Cloud. So that's a great overview of how VMware is interesting, and I think we'll go into maybe deep into a specific use case. But before then, just to recap, what VeloCloud and other SD-WAN solutions provided pre-acquisition by VMware was this ability to have a WAN in a box at the edge.
So one of the huge benefits of SD-WAN was the ability to take commodity circuits, combine that – and this is just one use case – combine those circuits and find best of paths. So a lot of companies were actually displacing or augmenting their MPLS networks with this so they could take their MPLS connection, bring in an internet connection, and then intelligently, the SD-WAN solution would decide where's the best path to send application-specific traffic. Back in the old days, we'd say, you know what, all voice goes over MPLS, period, because MPLS offers consistent class of service versus the internet.
What we've discovered that that's not necessarily always the case. Sometimes the internet path is the better path, and these SD-WAN solutions would do this for us dynamically based on network statistics such as jitter and other factors, including latency. Is that pretty accurate to describe what VeloCloud offers today? I would say SD-WAN brings many value propositions, as you were pointing out, right? The first one is the aspect of saying there's multiple access technologies, and having kind of this indirection in the edge allows you to pick the best option for your business, for your quality of experience, and so on.
The other aspect is the notion of you have many sites, and if you have to manage them individually, that's painful from an operations point of view, and SD-WAN gives you this kind of Uber management experience where now you can see and create consistent configurations experience across many sites. And the third is what we were discussing, is like the aspect of with this automation and this centralized experience, now you can tie it to the data center. So I would say when we look at the problem of SD-WAN, we were not necessarily looking at the aspect of saying, do we have to pick in between internet technologies or MPLS or things like that, but rather is how do we focus from an enterprise point of view into an end-to-end experience?
So let's talk about that. I look at that as pretty much the abstraction of the control plane. Yes. VMware did a great job early on with NSX. I wanted NSX like right away. When someone said, you know what, there's a hypervisor for networking, immediately I kind of get the content. You know, I can pause, rewind, and it's a DVR for the network. I can take my control plane and do the same thing that I could do with my virtual servers and my virtual infrastructure.
I can do that with the networking. And VMware acquired Nesera, and I saw the Nesera solution. I'm like, you know what, I want that yesterday. Where is it? You know, Martin Casado even took me out for a burrito and berated me over a burrito about, you know, one of my blog posts. He was right, but, you know, it was all the same. Now we're taking that same concept, VMware is taking that same concept and bringing it out to the edge.
Why should we get excited, just excited about data center abstraction, network abstraction? Why should we be excited about that edge abstraction? Talk to me practically about a use case that a customer takes their NSX constructs and extend that out to the edge. Yes. Maybe the first, as you were saying, that working is a topic that has been done for many, many years and with very successful companies in the space, I would say what's different about VMware that is fueling kind of this growth into the NSX product line and into network virtualization.
So if you think, like many years ago, we were focusing on kind of the end-to-end principle. You have endpoints with IP addresses and networking was about how do I connect end-to-end. And the network had a mission by itself. Fast forward a few years and with the acquisition of NYSEDA and the introduction of NSX and what VMware brought to the industry was, why do we do networking? Is it about networking for the sake of networking or is it because we have to provide a service to applications?
Right. And as such, we took kind of this reference point, right? NSX and VMware is about creating networking useful to applications. Now you start saying, okay, where are the applications running? Today they are running from bare metal servers to virtualized environments, moving to containers, moving to serverless functions. So the commitment that VMware had from a networking point of view is, I'm going to provide an environment that fulfills whatever the application needs. And the application needs essentially connectivity, security, and elasticity, which in the old world were like routers, firewalls, or load balancers.
And the new world becomes kind of this Uber network virtualization solution that enables applications to appear and disappear as they go, fully automated. Now as you take this concept of following the application, you say, well, how this extends to SD-WAN, right? Because as you were mentioning, SD-WAN has a very specific value proposition about do I pick MPLS or internet or some specific access technologies? And there is a component of that. But if that was the sole component, then it would be kind of networking for the sake of networking again.
And there's already plenty of networking companies that focus on that. So we were going more to the operational aspect that you were mentioning, right? You go one level up and you say, what is this Uber control plane and for whom? And what's the reference point to simplify the life of our customers? And you go like that. And again, it's like, when I create my applications, where are the users, where are the sites, where are the environments? How do I connect everything?
How do I secure everything with a unified reference point, centralized control point that simplifies the operations and the lives of IT and our customers? And I think one of the real world examples of where this plays in, I've worked for a large, very large R&D organization. And one of the challenges we had was we're trying to figure out what we call business traffic and R&D traffic over the web. Yes. And this is the pain point everyone, I think, who transfers a large amount of data over the WAN can comprehend.
SD-WAN can help with this, but the problem is still the orchestration of that traffic. I would love to be able to just say, I have overlays and I can turn the knob for R&D traffic and certain points of day increase the amount of bandwidth available to certain R&D traffic, isolate that traffic on a WAN and get it into the endpoints. I'd like to say from a rule setting, you know what, this time of day, use this protected path for business traffic such as voice or this protected amount of bandwidth.
Operationally, what we discovered was no matter how much bandwidth we purchased, how many circuits we purchased from the data center all the way where the applications ran all the way to the edge where the computation was done. That was an immensely challenging problem. In my mind, the combination of SD-WAN VMware NSX solves that, helps to solve that problem. Yeah, definitely. When you start thinking in terms of application recognition and traffic, we always talk over the years about SLAs and QAs in the data center, but in the data center, you have plenty of bandwidth and you can always upgrade to the next technology.
When you go into the WAN, then the problem is very real. I mean, it's where SLAs per application policies in terms of what bandwidth reservation or latencies path that you pick, it becomes very relevant. So completely with you, I mean, one of the things that we are aiming is the notion of understanding and recognizing the applications that we understand in the data center, carrying that experience and knowledge into who's using those type of applications and being able to tie SLAs and paths and path discovery into this end-to-end experience.
And as you were saying, it's not anymore about I have a WAN problem or a data center problem. It's like, oh, this specific time, this application is very real and very important to me. Can I do something in terms of rerouting it based on some service label or can I grantee certain elements in the WAN that are going to grantee the experience of the end users? So let's put in a conversation on ecosystem. You're from PumbGrid and a bunch of networking background before.
You've worked in the OpenStack community. You understand the value of the overall community. And this is something that VMware can't, even with the acquisition, VMware can't do it on your own. You need application folks to get on board, network vendors, telcos, et cetera. There's still movement. Where's the biggest challenge in getting this end-to-end vision? We've been trying to basically work much more on the ecosystem, but it's something that as we go into the SD-WAN space, we have to do even better.
I mean, even Velo had a lot of partner relations that we are carrying forward into VMware in the space of security, in the space of visibility. And now, as we bring this ecosystem together, you're correct, VMware cannot do everything. VMware kind of provides the base where now you can build on top, like providing the connectivity aspect and some policy engines and so on. And now the question is, who has the ability to understand identity? Who has the ability to do the packet inspection at the level that you can have ideas, ideas?
Who has the ability to create advanced machine learning analytics and capabilities? So we are trying to develop, as we create this kind of foundational technology that expands across all the elements of the enterprises, who builds value on top of us? What kind of ecosystem partners do we bring? And this is a place where now we are dedicating definitely much more energy, and you will see this from an NSVU, you have the AppDefense product line doing partnerships with security startups and security companies specialized in the space.
But when you take it into the data center or into the SD-WAN, you'll see that we'll keep doing more and more about how do we bring third-party virtual network functions or third-party partners that augment in terms of operations, in terms of network capabilities, the offering that we have. So, Peter, I really appreciate you spending the time to talk to the CTO Advisor about what VMware is doing in the SD-WAN space. I'll be that same antagonist, see, I said the word right this time.
And pushing VMware and saying, hey, where's the solution? I know it's hard work, but these are problems that a lot of enterprises have to solve today. And I'm happy to see that VMware, just like NSX with Nisera, is pushing the envelope and extending this concept of the software-defined, I don't even know what we can call it, software-defined data center anymore. It's like the software-defined enterprise. So, I really appreciate the time. Do you do social media or anything like that at all?
Not much. I'm a little bit of social, but I'll take you on the Iovisor discussion anytime. I'm looking forward to talking about Iovisor. We got to get our friend, you know what, follow Roger on Twitter. I'll put his Twitter handle and pressure him to have that Iovisor conversation. It's really geeky stuff, really fun stuff about what a lot of industry players are using that technology to do quite the amazing things with things like Intel DPDK, which I've talked about and wrote about an awful lot.
Until then, tune into the rest of these videos. We're talking to the cloud services BU a little bit later on today, as well as the other cloud BU. VM has two cloud BUs now. Go figure. com. Talk to you next, CTO Dopes.