Security
Overview
Our Cloud platform integrates multi-layered security to protect customer workloads end-to-end.
At the edge, advanced threat protection is delivered through Palo Alto Networks ATP, combining IP reputation filtering and on-demand IDS/IPS.
This provides proactive detection and blocking of malicious traffic before it reaches workloads.
Within the platform, VMware NSX-T delivers advanced firewalling capabilities.
It includes stateful inspection for north-south traffic and distributed east-west firewalling for micro-segmentation.
Workload-level protection is reinforced with antivirus powered by Trend Micro.
Sensitive data can be secured with optional VM encryption using a KMS integrated with HSM-backed key management.
This ensures strong control and isolation of encryption keys.
For cyber recovery scenarios, replication and failover capabilities are enabled through VMware vCloud Director Availability.
Together, these components provide a resilient and secure-by-design cloud foundation.
The security features available on IaaS Dual Site/ HDS are integrated at several levels:
- IPS / IDS services through Palo Alto Networks ATP.
- NSXT and AVI Security Features.
- TrendMicro Antivirus services to detect and prevent malware, ransomware, and file-based threats.
- Key Management System (KMS) ensuring that data remains confidential, compliant, and protected.
- Global anti-DDOS protection is in place for all customers.
Palo Alto IPS / IDS
Provides advanced threat protection is delivered through Palo Alto Networks ATP, combining IP reputation filtering and on-demand IDS/IPS.
IP reputation
IP reputation is a security mechanism that evaluates the trustworthiness of an IP address based on aggregated behavioral signals such as origin, infrastructure, usage patterns, and historical activity (who, what, where, when, and how). This scoring relies on large-scale threat intelligence combining multiple data sources (SIGINT, OSINT), enriched with machine learning, heuristics, and expert analysis from trusted providers (e.g. Spamhaus).
Within our platform, IP reputation is implemented upstream of customer tenants at the edge layer, acting as a first line of defense. Incoming traffic is continuously evaluated against real-time reputation datasets, and enforcement policies are applied dynamically (block, allow, rate-limit, or further inspect).
This approach enables early filtering of malicious sources before they reach tenant workloads, reduces attack surface, and offloads security processing from customer environments while maintaining performance and scalability.
This feature is available for all tenants be default.
IPS / IDS
These feature are available from cloud store portal and on demand basis.

NSX-T
Perimeter firewall
The T1 gateway embeds a perimeter firewall, allowing North-South flows to be filtered, exactly as a physical firewall does. It manages the address translation rules (NAT) and thus makes it possible to protect the VMs of the organization networks carried by the T1.
Distributed firewall
NSX-T also makes it possible to deploy a distributed firewall, which can manage security in the scope of :
- one vDC
- several vDC, if they are grouped into a Datacenter Group.
This implementation, carried out at the ESXi level, makes it possible to manage east-west flows between the VMs. The rules can be based on tags placed on the VMs, in order to facilitate the propagation of the rules. For example, VMs tagged DEV will not have access to the internet, while VMs tagged PROD will ha
AVI
VMware NSX Advanced Load Balancer (commonly referred to as VMware AVI) providing Load Balancing (LB) and Web Application Firewall (WAF) services to tenants in Cloud Avenue.
Tenant connectivity AVI Service Engines are deployed in Active – Standby mode.
VDR Service Engine is Active and CHA Service Engine is Standby to provide dual site resiliency.
The implementation is carried out at the T1 gateway level in a vDC . Tenant can create/manage the load balancer configurations from the tenant user interface (vCloud Director – VCD portal).
General diagram of the load balancer

A load balancer option is available on the T1 gateway.
You can create:
- Virtual Services: A virtual service is a combination of an IP address and a port that uses a single network protocol. A virtual service listens for traffic to an IP address. It processes client requests and directs valid requests to a member of the load balancer server pool.
- Pools: A server pool is a group of one or more servers that you configure to run the same application and ensure high availability.
- Application Profiles: Application profiles determine the behavior of virtual services based on the type of application. Types of application profiles, such as HTTP, HTTPS, L4 TCP, L4 UDP, L4 TLS, can be used.
Advanced Load Balancer – For Tenants
NSX ALB , default form factor is medium (for Shared and Dedicated SEG)
Note:- Changing SEG form factor upgrade involve high cost implications.
The load balancer services available on IaaS Dual Site are as follows :
| Type of LBaaS | Configuration Requirements | Load Balancing Engine Resilience | Load Balancing Engine Resilience |
| Shared | T0 VRF Premium | 20 VIP | Active / Standby & Active / Active |
| Dedicated | T0 VRF Premium | 200 VIP | Active / Standby & Active / Active |
| Configuration Parameters | Service Status | |
|---|---|---|
| Application Type | HTTP | ▲ |
| HTTPS | ▲ | |
| L4 TCP | ▲ | |
| L4 UDP | ▲ | |
| L4 TLS | ▲ | |
| Load Balancing Algorithm | Least Connections | ▲ |
| Round Robin | ▲ | |
| Consistent Hash | ▲ | |
| Fastest Response | ▲ | |
| Least Load | ▲ | |
| Fewest Servers | ▲ | |
| Random | ▲ | |
| Fewest Tasks | ▲ | |
| Core Affinity | ▲ | |
| Pool Persistence | Client IP | ▲ |
| HTTP Cookie | ▲ | |
| Custom HTTP Header | ▲ | |
| Application Cookie | ▲ | |
| Client IP | ▲ | |
| Active Health Monitor | HTTP | ▲ |
| HTTPS | ▲ | |
| TCP | ▲ | |
| UDP | ▲ | |
| PING | ▲ | |
| Analytics | Dashboard | ▲ |
| Advanced Features | HTTP Policy | ▲ |
| WAF | ▲ | |
Data Security
Key Management Service (KMS) is a critical component for maintaining data security across applications, databases, cloud environments, and enterprise systems.
It plays a critical role in ensuring that data remains confidential, compliant, and protected across its lifecycle
KMS is deployed in Dual site mode, so it is a site resilient service.
- HDS customers will have ability to request VM level encryption service.
- VM level encryption allows customer to have option to pick and choose which virtual machines they want to protect based on their data classification. VMs with HDS specific data can be encrypted by customer.
- VM level encryption requires vm to be in offline state
NOTE : Data at rest encryption service will not be available for customers initially for HDS | IaaS-EXT-EU.
Protection Against Ransomeware
VCDA (VMware Cloud Director Availability) is used for protecting customer critical workloads against ransomware attack and data corruption.
- VDR – Mono Site
VCDA will replicate customer VMs within the same mono-site vDC. Customers can restore their VMs using VCDA within that vDC when needed.
- VDR + CHA – Dual Site
VCDA will replicate customer VMs hosted in the dual-site vDC to the VDR mono-site vDC. Customers can restore their VMs using VCDA to the VDR mono-site vDC as required.