As more applications are deployed on virtualized service platforms in data centers, east-west traffic between services accounts for an ever-growing share of overall network traffic. Traditional security models, however, often fail to control the security of east-west network traffic within data centers.
Micro-segmentation is grounded in the zero trust model, requiring allowlist authorization for any east-west communication. By integrating with the workload platform, the ANS distributed firewall automatically applies fine-grained policies to workload resources, effectively eliminating internal threats caused by lateral movement within the data center, significantly reducing the overall attack surface, and providing robust security protection for east-west workload traffic.
The figure below shows a typical three-tier web application architecture. ANS micro-segmentation groups the virtual machines hosting the application, and security policies are integrated with the management platform to automatically associate security rules, ensuring the finest-grained mutual isolation and least-privilege communication between services.
