What does zero-trust security look like when it keeps pace with AI, virtual machine, and Kubernetes workloads? This blog post shows how VMware vDefend™ for VCF 9.1 applies a unified zero-trust model that reduces lateral attack risk while maintaining the performance modern applications demand. Read the blog to see how VMware helps you strengthen security without added complexity.
What is VMware vDefend for VCF 9.1 and why does it matter for AI workloads?
VMware vDefend for VCF 9.1 is a zero-trust lateral security solution built directly into VMware Cloud Foundation (VCF). It is designed to protect modern, distributed workloads—including AI and high-performance computing—without sacrificing performance or agility.
As enterprises deploy AI agents and AI workloads across private clouds that span both VMs and Kubernetes, the attack surface grows and becomes more dynamic. Recent activity such as CISA-reported BRICKSTORM malware and AI-assisted, semi-autonomous cyberattacks shows that attackers now operate at machine speed. Traditional perimeter-only security is no longer enough.
vDefend addresses this by:
- Embedding zero-trust lateral security into the VCF platform, so security is part of the core infrastructure rather than an add-on.
- Using a hypervisor-native, distributed, software-defined model that creates a closed-loop security architecture.
- Providing consistent controls across VMs, containers, and Kubernetes (VKS) workloads, so policies follow workloads as they are created or moved.
Key data points:
- 3x throughput increase with IDPS Turbo Mode: from 3 Gbps to 9 Gbps per host, and up to 9 Tbps per VCF domain.
- 5x increase in Application Identification coverage, adding 4,000 new Application IDs for deeper Layer 7 visibility.
For CISOs and infrastructure leaders, this means you can reimagine lateral security as an integrated, high-performance capability that keeps pace with AI-era workloads while helping meet compliance needs such as PCI-DSS and HIPAA.
How does vDefend unify security for both VMs and Kubernetes (VKS) workloads?
vDefend 9.1 is designed to give security teams one consistent way to protect both VM and Kubernetes (VKS) workloads, which is critical as AI and cloud-native adoption accelerate.
Here’s how it unifies security:
- Single IDS/IPS engine for VMs and VKS: vDefend extends its hypervisor-native IDS/IPS from VMs to vSphere Kubernetes Service (VKS) clusters via CNI integration. You can enable IDS/IPS at the pod level, continuously inspecting traffic and blocking threats on mixed-mode hosts (VMs and Kubernetes).
- One console and one policy model: Security teams manage lateral threat prevention for VMs, containers, and even bare-metal workloads from a single interface, using a consistent policy framework. This helps remove blind spots that attackers often exploit.
- Compliance and virtual patching: Customers typically deploy IDS/IPS to (1) meet compliance requirements such as PCI-DSS and HIPAA, and (2) enable virtual patching so they can quickly protect against software vulnerabilities while official patches are rolled out.
With vDefend, you can rethink lateral security as a unified control plane that follows your workloads—whether they are traditional VMs or Kubernetes-based AI services—without forcing you to manage separate, fragmented point solutions.
What new capabilities in vDefend 9.1 help teams scale security with automation and performance?
vDefend 9.1 introduces several enhancements aimed at helping teams secure fast-growing AI and high-capacity workloads while simplifying operations.
1. Self-Service Lateral Security with VCF Automation
- System-defined Security Profiles: Five predefined security profiles let Tenant Admins apply consistent, repeatable security to Virtual Private Clouds (VPCs) with one-click using VPC Simplified Security.
- Automated Distributed Firewall (DFW) policies: Selecting a profile automatically sets the default security posture and foundational DFW rules per VPC. System-defined rules cannot be manually modified, while user-defined policies take precedence, balancing control and safety.
- Delegated security and guardrails: Infrastructure and security teams can set guardrails (e.g., VPC security profiles, delegated DFW settings) so tenant admins can consume security on demand, speeding application onboarding while maintaining a uniform baseline.
- Granular firewall control: Enhanced control for both Distributed and Gateway Firewalls, plus automated orchestration using Privileged Labels.
2. High-Performance Threat Prevention with IDPS Turbo Mode
- 3x throughput increase: Turbo Mode boosts Distributed IDS/IPS throughput from 3 Gbps to 9 Gbps per host, and up to 9 Tbps per VCF instance, supporting AI and other high-capacity workloads.
- Traffic exemptions: New exempt actions let admins choose which traffic to inspect and exclude trusted flows (for example, nightly backups), improving efficiency and reducing unnecessary inspection overhead.
3. Enhanced Distributed Firewall and Identity-Based Controls
- Layer 7 visibility with Application Identification: A 5x increase in Application Identification coverage adds 4,000 new Application IDs, enabling more granular, application-aware firewall rules instead of relying only on ports and protocols.
- Federated identity-based firewalling: Identity-based firewall policies now work across multi-site (federated) environments, providing consistent policy enforcement at scale.
Together, these capabilities help teams reimagine lateral security as an automated, high-performance foundation for VCF—one that keeps pace with AI-era workloads while simplifying day-to-day security operations.