A pragmatic application for SDN
But because of the growth of SDN and SDDC, this means that micro-segmentation must be much grander in scale and spread, as what was once simply a few virtual instances needed to be segmented is now an entire virtual ecosystem must now be dynamically defended. For this approach to be effective, it is necessary to understand what exactly must be segmented and how. While, often, the concept of segmentation stops at the network layer, there is a very real need to extend that ability further toward the edge and the entity to enhance security control and manageability. Doing this pragmatically, however, is difficult in concept and can be even harder in practicality if one does not think about what to segment and how.
For better command, control, and visibility of the defensive surface, it is necessary to have visibility of all assets that communicate using east-west traffic, or internal network traffic, communicate within the same security zone. Doing this...