Protecting a corporate network is not as simple as building a wall around it. Threats can still sneak through the network firewall or circumvent security infrastructure altogether. Once they are inside, they can move around and attack at will since there are few, if any, controls inside the datacentre to prevent malicious traffic.
For a lot of security practitioners, nirvana is the ability to do micro-segmentation within the datacentre, or build a honeycomb, in effect, so that any threat that gets into the datacentre is actually captured within the honeycomb and cannot move very much. [Micro-segmentation divides a network into small isolated zones, each with its own security controls, preventing lateral movement by attackers who breach the perimeter.] What we can do with network virtualisation is bring that firewalling all the way down to the virtual interface.
VMware NSX has been around for more than two years now, and in that time software-defined networking and network virtualisation have become integrated into modern datacentre architecture. It seems like an inconceivable amount of progress has been made. But the reality is that we are only at the beginning of this journey.
The transformation of networking from a hardware industry into a software industry is having a profound impact on services, security and IT organisations around the world. As more datacentres adopt the power of network virtualisation and a software-defined datacentre architecture, we will see a broad range of traditional security solutions that leverage the unique position of the network virtualisation platform in the hypervisor.
Detailed knowledge of VMs and application process owners, combined with automated provisioning speed and operational efficiency, is the foundation for an exciting new approach to some very old challenges.
The VMware NSX business, the network virtualisation and security platform for the software-defined datacentre, grew over 100 per cent year-over-year, bringing the total annual bookings run rate to well over $600 million in 2015. The past year also saw hundreds of production deployments of network virtualisation. Over 200 customers are running VMware NSX in production datacentres, with more being added every week.
We saw customers sign up for our NSX offering, signalling that CIOs in India are also convinced this transformative architecture will help them deploy workloads faster, as well as giving them greater agility in the face of increasingly dynamic datacentres.
Two observations stand out as we look at customer adoption of NSX in 2015. The first is the diversity of customers, in terms of both size and industry. This is an indication of the maturing of the market for this technology. In contrast to the early days, customers do not need to be especially large or sophisticated to see the benefits of network virtualisation, or to put the technology into production.
While we still see lots of interest from our traditional large, technology-focused customers, adoption is clearly spreading across industry segments such as healthcare, retail, the public sector and many others. Additionally, there are plenty of smaller customers in the mix with large enterprises and service providers.
The second observation is that no single use case is dominating adoption of network virtualisation; in fact, the breadth of use cases continues to increase. While the emergence of micro-segmentation as a use case definitely increased customer interest in NSX and continues to be important, customer deployments are spread across many different use cases such as agility and automation, service insertion and multi-datacentre applications such as disaster recovery. Increasingly we are seeing customers tackling multiple use cases in a single deployment.
Overall this breadth of usage points to the general-purpose nature of network virtualisation technology.
Aside from confidently predicting more customers, deployments and use cases, there is actually one other notable trend that should emerge in 2016. That is an increase in the range of endpoints that can be managed by NSX. This is a natural extension to the development of NSX over the past three years.
From the early days we have had support for workloads running on a range of hypervisors (ESX, KVM, Xen), and we have been able to extend virtual networks to physical workloads as well. By integrating NSX with AirWatch, we have been able to extend the security capabilities of micro-segmentation to applications running on mobile devices. We have started to use micro-segmentation to improve the security of virtual desktops.
In 2016 we will see this ability to provide networking and security services to a range of endpoints move to another level. The set of endpoints that NSX can manage will extend to containers and public cloud workloads. We will also see NSX extending out to branch offices as Software Defined WAN (SD-WAN) solutions take root.
Recognising that for at least some of their end users, public clouds will be the chosen venue for a workload to run, IT managers want to have a consistent view of networking and security policy. They also want to maintain that consistency even if a workload at some point moves from one public cloud to another, or moves back to on-premise deployment. Meeting this requirement will be the objective as we expand NSX into public cloud environments.
A similar desire for consistency in networking and security policies will drive the extensions to support containers as first-class endpoints for NSX.
By the numbers
- $600 million
- VMware NSX annual bookings run rate in 2015
- 100%
- Year-over-year growth of NSX business
- 200+
- Customers running NSX in production datacentres
So, it continues to be an exciting time for network virtualisation. Adoption of the technology will increase, and we will see still more breadth of customer types and use cases. Perhaps most exciting is that we are moving well beyond our traditional sweet spot of delivering networking services to on-premise virtualised workloads, as we expand the reach of NSX to everything from handsets to public clouds to the software-defined WAN.
The writer is senior director, systems engineering, India and SAARC, VMware

