API Doc
Search Docs...
⌘ K
ACOSABSAVEANSABDR
  • ANS distributed firewall technical whitepaper>
  • Overview

Challenges

Insecure traditional perimeter-focused data centers

Traditional data center network security relies primarily on strengthening perimeter defense. The perimeter security model assumes that internal networks are trustworthy and that security threats come mainly from outside the perimeter: As long as the perimeter is well protected, everything inside is considered safe. However, as organizations shift toward cloud adoption, virtualization, and mobile workforces, the traditional perimeter has been stretched and is gradually fading. Once a data center is breached from within, the entire system and all critical data are exposed. The data center's internal network can no longer be considered a trusted security zone.

At the same time, data centers are evolving toward server virtualization, containerization, microservices, and converged infrastructure. Modern applications have shifted from monolithic architectures to microservice architectures, with individual components exhibiting a highly distributed structure. These changes expand data centers' internal attack surface, making internal networks increasingly vulnerable.

Inadequate traditional network segmentation against emerging threats

Traditional networks can only segment and isolate traffic between broadcast domains using VLANs or IP subnets, as shown below.

Traditional network segmentation is coarse-grained and affects large scopes. As workloads increase and application architectures become more complex, traditional segmentation struggles to meet the growing network security demands of virtual services. Perimeter firewall rules are also network address-based, requiring administrators to write and maintain large numbers of security policies built around IP addresses or ranges to achieve complex traffic control. The push for "fine-grained security" means policies must become more granular, to the point where every security policy must use "each IP address and port" as the matching criteria. When any IP address in the data center changes, or its role changes, for example, if an IP previously serving only HTTP or HTTPS now also needs FTP, administrators must update each IP-address-based security rule individually. This not only imposes significant management overhead but inevitably leads to configuration errors, resulting in frequent security vulnerabilities and connectivity issues.

High cost of traditional network and security models

Because hardware cannot be scaled on demand, all hardware-based networking and security projects must be provisioned for peak capacity from the initial purchase and deployment. The costs of capacity reservation and high availability architectures are substantial. To keep up with the workload increase, whenever hardware utilization exceeds the reserved safety threshold or new security capabilities are required, hardware must be upgraded, expanded, tested, and cut over, which is a process that typically takes weeks or even months. All of these factors add tangible and intangible costs that cannot be optimized within a hardware-centric infrastructure, and these persistent costs have become one of the key challenges facing enterprises.

In summary, traditional networking and security lack integration with workloads, as traditional security devices and mechanisms cannot keep the mapping between IP addresses and workloads recorded and updated in real time, and they fail to respond in time to the ever-evolving network threat landscape. The pace of expansion for traditional network and security architectures can no longer meet the agile, elastic demands of growing workloads, becoming a bottleneck in enterprise digital transformation and development. Enterprise application infrastructure heading into the cloud era must modernize its networking and security mechanisms to adapt to new application development and deployment models, rather than forcing applications and workloads to conform to legacy network technologies and security approaches.