vDefend Security

Security that starts inside the data centre

With vDefend evoila brings multi-layered security directly into your VCF environment. Microsegmentation, IDS and IPS, threat prevention and network detection run natively in the stack, without additional appliances.

The perimeter held. The network behind it did not.

Perimeter security alone no longer holds. Attackers who reach the network move laterally almost unchecked whenever there is no workload-based segmentation. That single gap turns one compromised credential into a full-scale incident.

vDefend closes the gap with a multi-layered security architecture directly inside the VCF stack. Distributed Firewall, IDS/IPS, Advanced Threat Prevention, Malware Detection and Network Detection & Response work together without additional appliances. evoila designs, implements and operates vDefend as an integral part of your VCF security strategy.

Business benefits at a glance:

  • Reduced attack surface: Microsegmentation and Distributed Firewall structurally limit lateral movement
  • Compliance capability: IDS/IPS and audit trails support audit requirements under NIS2, ISO 27001, and other regulations
  • No additional hardware: Security functions run natively in the hypervisor, without appliance overhead

Security Doesn’t End at the Perimeter

Traditional security architectures are based on the perimeter model: a strong outer wall is supposed to keep attackers out. This model is structurally obsolete in modern data centers. Attackers who breach the perimeter—through phishing, compromised credentials, or supply chain attacks—often find a flat network behind it: little segmentation, minimal detection, and unrestricted movement.

At the same time, regulatory requirements are growing: NIS2, ISO 27001, and industry-specific guidelines demand verifiable security measures at the network and workload levels. Those who cannot provide this evidence risk not only security incidents but also regulatory consequences.

VCF environments without an integrated security architecture are particularly vulnerable: consolidating compute, storage, and networking onto a single platform creates a large, shared attack surface in the event of a breach. Security must therefore be deeply embedded within the stack—not as an add-on, but as a structural design principle.

A breached perimeter and a flat network behind it is all an attacker needs

Without workload-level segmentation, one foothold becomes free movement across your entire estate.

The Challenge

Attackers think in networks. Your defences should too

Flat network, free movement

A successful perimeter breach meets no internal resistance. Without segmentation, attackers move laterally across workloads at will.

Detection arrives too late

IDS/IPS capability rarely reaches the workload level. Attacks are caught long after the damage, or never at all.

Compliance without controls

NIS2 and ISO 27001 demand granular, verifiable controls. Without them, audit evidence is nearly impossible to produce.

Appliances under strain

Classic perimeter firewalls were never built for east-west traffic. They become bottlenecks and still leave internal flows uncontrolled.

Threats without visibility

There is no central view of what is happening inside the network. Attacks unfold across workloads with nothing watching the east-west traffic.

The good news: security does not have to sit on top of your platform

With vDefend, it lives inside it.

Our Solution

Multi-layered security in the VCF stack

Security by design, not as an afterthought

evoila embeds security into the VCF architecture from the very beginning. vDefend is not implemented as an isolated security product, but as an integral part of the overall design—tailored to the network architecture, operating model, and compliance requirements. What we deliver:

Distributed Firewall & Microsegmentation

A granular segmentation strategy with the NSX Distributed Firewall at the core of vDefend: close to the workload, policy-based, no hardware appliances. Lateral movement is structurally limited, not merely detected.

Workload-Level IDS/IPS

Intrusion detection and prevention directly in the data path, with signature-based and behaviour-based detection. evoila configures detection profiles, exception rules and response policies tailored to your specific workload landscape.

Advanced Threat Prevention & Malware Detection

Integration of the vDefend Advanced Threat Prevention Engine for deep packet analysis and file-based malware detection, including encrypted traffic where technically possible.

Network Detection & Response

NDR capabilities for continuous analysis of network traffic for anomalies and attack patterns, as the foundation for rapid incident response and forensic analysis.

Gateway Firewall

Configuration of the vDefend Gateway Firewall for controlled north-south traffic, complementing the Distributed Firewall and offloading or replacing classic perimeter appliances.

Compliance Documentation & Audit Trails

evoila helps you establish verifiable security controls, with structured policy documentation, logging concepts and audit trail configuration that meet regulatory requirements.

Tech-Deep-Dive

The architecture behind IT

vDefend as an Integrated Security Platform

vDefend is the consolidated security platform within the NSX and VCF stacks. It brings together multiple security functions under a single management interface—without separate appliances, without additional agents at the workload level, and without gaps in policy management. All security functions run natively within the hypervisor data path.

Distributed Firewall: Security at the Source

The architectural core of vDefend is the distributed firewall. It enforces security policies directly at the vNIC of each workload, rather than centrally on an appliance. This means that every east-west data flow is controlled at its source, regardless of network topology or workload placement. evoila develops a structured tagging and policy framework that scales with a growing environment and remains maintainable.

IDS/IPS Engine: Detection in the Data Path

The vDefend IDS/IPS Engine analyses network traffic based on signatures and behavioral patterns, directly in the hypervisor data path, without traffic redirection. Signature updates are distributed centrally, and detection profiles can be configured differently for each workload group. evoila configures initial baseline profiles and works with the customer to develop a long-term tuning strategy to minimise false positive rates.

Advanced Threat Prevention & Malware Sandbox

The Advanced Threat Prevention Engine complements IDS/IPS with file-based malware analysis and an integrated sandbox function. Suspicious files are analysed in an isolated environment without compromising production systems. Combined with Network Detection & Response, this creates a multi-layered detection architecture that covers both known and novel threat patterns.

Policy-Management & Compliance-Integration

All vDefend policies are managed centrally via NSX Manager. They are versioned, documented, and auditable. evoila is developing a policy framework that structurally incorporates compliance requirements from NIS2 and ISO 27001: with clear naming conventions, change management processes, and exportable audit trails for verification purposes

Technical Advantages

Why the architecture pays off

Workload-based security

Distributed firewall enforces policies directly at the vNIC, regardless of network topology

Multi-layered detection

IDS/IPS, Advanced Threat Prevention, and NDR work in combination against known and emerging threats

No appliance dependency

All security functions run natively in the hypervisor, without additional hardware or traffic redirection

Scalable policy management

Centralised policy framework with tagging strategy scales with a growing workload landscape

Audit-ready security architecture

Structured logging and documentation concepts for NIS2, ISO 27001, and other regulations

Gateway firewall as a perimeter replacement

North-south traffic is controlled without bottlenecks caused by central appliances

Your partner of choice

Architecture is a decision, not a product

Security architecture is not a product you buy

It is a design decision that shapes every other layer. evoila combines deep VCF platform knowledge with specific vDefend expertise, proven in production environments across a wide range of compliance requirements, from mid-sized data centres to regulated industrial and financial estates. The integrated approach is what sets it apart. evoila treats security as a structural design principle, aligned with network architecture, operating models and automation frameworks. vDefend, NSX and VCF are designed together, never implemented in isolation. For organisations under pressure from NIS2 or an active certification project, evoila also brings hands-on experience in audit-ready documentation and evidence management.

Production-proven

vDefend deployed in live environments under real compliance demands.

One team, full stack

The engineers who design vDefend also implement and operate it.

Compliance built in

NIS2 and ISO 27001 requirements designed into the policy framework.

Broadcom partnership

A leading Broadcom partner in Europe, deep in the NSX stack.

Partnerships

Technologies & Partner

VMware vDefend:
Consolidated security platform within the NSX/VCF stack

NSX Distributed Firewall:
Workload-based microsegmentation & policy enforcement

vDefend IDS/IPS:
Signature- and behavior-based detection in the data path

Advanced Threat Prevention:
File-based malware analysis & sandbox functionality

Partner:

Gateway Firewall:
Control of north-south traffic as a perimeter supplement

NSX Manager:
Centralised policy management & audit trail configuration

Network Detection & Response:
Continuous anomaly detection & incident response foundation

Introductory Offer

vDefend Security Assessment

Security starts with a realistic picture of the current state. In the evoila vDefend Security Assessment, we analyse:

Existing segmentation architecture and level of exposure

IDS/IPS and detection capabilities in the current stack

Compliance gaps relative to NIS2, ISO 27001, or industry-specific requirements

Integration potential with existing VCF and NSX environments

The result is a prioritised security action plan with a clear implementation roadmap.

Attackers think in networks

Security architecture must do the same. vDefend makes VCF environments structurally more resilient, more compliant, and more manageable. evoila makes it actionable.

Let’s secure the inside of your stack

Tell us about your VCF environment and we will show you where vDefend fits.

FAQs

Commonly asked questions about vDefend Security