Skip to main content

Security

Overview

Our Cloud platform integrates multi-layered security to protect customer workloads end-to-end.
At the edge, advanced threat protection is delivered through Palo Alto Networks ATP, combining IP reputation filtering and on-demand IDS/IPS.
This provides proactive detection and blocking of malicious traffic before it reaches workloads.
Within the platform, VMware NSX-T delivers advanced firewalling capabilities.
It includes stateful inspection for north-south traffic and distributed east-west firewalling for micro-segmentation.
Workload-level protection is reinforced with antivirus powered by Trend Micro.
Sensitive data can be secured with optional VM encryption using a KMS integrated with HSM-backed key management.
This ensures strong control and isolation of encryption keys.
For cyber recovery scenarios, replication and failover capabilities are enabled through VMware vCloud Director Availability.
Together, these components provide a resilient and secure-by-design cloud foundation.

The security features available on IaaS Dual Site/ HDS are integrated at several levels:

  • IPS / IDS services through Palo Alto Networks ATP.
  • NSXT and AVI Security Features.
  • TrendMicro Antivirus services to detect and prevent malware, ransomware, and file-based threats.
  • Key Management System (KMS) ensuring that data remains confidential, compliant, and protected.
  • Global anti-DDOS protection is in place for all customers.

Palo Alto IPS / IDS

Provides advanced threat protection is delivered through Palo Alto Networks ATP, combining IP reputation filtering and on-demand IDS/IPS.

IP reputation

IP reputation is a security mechanism that evaluates the trustworthiness of an IP address based on aggregated behavioral signals such as origin, infrastructure, usage patterns, and historical activity (who, what, where, when, and how). This scoring relies on large-scale threat intelligence combining multiple data sources (SIGINT, OSINT), enriched with machine learning, heuristics, and expert analysis from trusted providers (e.g. Spamhaus).

Within our platform, IP reputation is implemented upstream of customer tenants at the edge layer, acting as a first line of defense. Incoming traffic is continuously evaluated against real-time reputation datasets, and enforcement policies are applied dynamically (block, allow, rate-limit, or further inspect).

This approach enables early filtering of malicious sources before they reach tenant workloads, reduces attack surface, and offloads security processing from customer environments while maintaining performance and scalability.

This feature is available for all tenants be default.

IPS / IDS

These feature are available from cloud store portal and on demand basis.

NSX-T

Perimeter firewall

The T1 gateway embeds a perimeter firewall, allowing North-South flows to be filtered, exactly as a physical firewall does. It manages the address translation rules (NAT) and thus makes it possible to protect the VMs of the organization networks carried by the T1.

Distributed firewall

NSX-T also makes it possible to deploy a distributed firewall, which can manage security in the scope of :

  • one vDC
  • several vDC, if they are grouped into a Datacenter Group.

This implementation, carried out at the ESXi level, makes it possible to manage east-west flows between the VMs. The rules can be based on tags placed on the VMs, in order to facilitate the propagation of the rules. For example, VMs tagged DEV will not have access to the internet, while VMs tagged PROD will ha

AVI

VMware NSX Advanced Load Balancer (commonly referred to as VMware AVI) providing Load Balancing (LB) and Web Application Firewall (WAF) services to tenants in Cloud Avenue.

Tenant connectivity AVI Service Engines are deployed in Active – Standby mode.

VDR Service Engine is Active and CHA Service Engine is Standby to provide dual site resiliency.

The implementation is carried out at the T1 gateway level in a vDC . Tenant can create/manage the load balancer configurations from the tenant user interface (vCloud Director – VCD portal).

General diagram of the load balancer

A load balancer option is available on the T1 gateway.

You can create:

  • Virtual Services: A virtual service is a combination of an IP address and a port that uses a single network protocol. A virtual service listens for traffic to an IP address. It processes client requests and directs valid requests to a member of the load balancer server pool.
  • Pools: A server pool is a group of one or more servers that you configure to run the same application and ensure high availability.
  • Application Profiles: Application profiles determine the behavior of virtual services based on the type of application. Types of application profiles, such as HTTP, HTTPS, L4 TCP, L4 UDP, L4 TLS, can be used.

Advanced Load Balancer – For Tenants

NSX ALB , default form factor is medium (for Shared and Dedicated SEG)

Note:- Changing SEG form factor upgrade involve high cost implications.

The load balancer services available on IaaS Dual Site are as follows :

Type of LBaaSConfiguration RequirementsLoad Balancing Engine ResilienceLoad Balancing Engine Resilience
SharedT0 VRF Premium20 VIPActive / Standby & Active / Active
Dedicated T0 VRF Premium200 VIPActive / Standby & Active / Active
Configuration ParametersService Status
Application TypeHTTP
HTTPS
L4 TCP
L4 UDP
L4 TLS
Load Balancing AlgorithmLeast Connections
Round Robin
Consistent Hash
Fastest Response
Least Load
Fewest Servers
Random
Fewest Tasks
Core Affinity
Pool PersistenceClient IP
HTTP Cookie
Custom HTTP Header
Application Cookie
Client IP
Active Health MonitorHTTP
HTTPS
TCP
UDP
PING
AnalyticsDashboard
Advanced FeaturesHTTP Policy
WAF

Data Security

Key Management Service (KMS) is a critical component for maintaining data security across applications, databases, cloud environments, and enterprise systems.

It plays a critical role in ensuring that data remains confidential, compliant, and protected across its lifecycle

KMS is deployed in Dual site mode, so it is a site resilient service.

  • HDS customers will have ability to request VM level encryption service.
  • VM level encryption allows customer to have option to pick and choose which virtual machines they want to protect based on their data classification. VMs with HDS specific data can be encrypted by customer.
  • VM level encryption requires vm to be in offline state

NOTE : Data at rest encryption service will not be available for customers initially for HDS | IaaS-EXT-EU.

Protection Against Ransomeware

VCDA (VMware Cloud Director Availability) is used for protecting customer critical workloads against ransomware attack and data corruption.

  • VDR – Mono Site

VCDA will replicate customer VMs within the same mono-site vDC. Customers can restore their VMs using VCDA within that vDC when needed.

  • VDR + CHA – Dual Site

VCDA will replicate customer VMs hosted in the dual-site vDC to the VDR mono-site vDC. Customers can restore their VMs using VCDA to the VDR mono-site vDC as required.