1 // Guardicore
Security Common Practice:
Build A Wall Perimeter wall 1 // Guardicore Spoiler Alert: Wall - - PowerPoint PPT Presentation
Security Common Practice: Build A Wall Perimeter wall 1 // Guardicore Spoiler Alert: Wall Will be Breached 2 // Guardicore The answer: Micro-segmentation Welcome To Zero Trust 3 // Guardicore Micro-segmentation : Walls don t work
1 // Guardicore
Security Common Practice:
2 // Guardicore
3 // Guardicore
The answer:
Welcome To Zero Trust
4 // Guardicore
Micro-segmentation: Walls don’t work in data centers
Constant Change Multiple Locations Roaming Requirements Diverse Protection Needs
Hybrid cloud environments span multiple physical locations Fixed walls (e.g., firewalls, VLANs) can’t follow moving assets Modern and legacy deployment models have different protection requirements Manual rule management can’t keep pace with DevOps and IT automation
5 // Guardicore
▪ Provide full visibility ▪ Abstract enforcement from
infrastructure
▪ Policy based on context,
not IPs The solution:
Guardicore’s approach
6 // Guardicore
See Critical IT Assets Through a Human Lens
7 // Guardicore
Create Granular, Platform-Independent Policies, Based on context, not IP
Bare Metal Virtual Machines Cloud Containers
8 // Guardicore
9 // Guardicore
10 // Guardicore
11 // Guardicore
12 // Guardicore
Architecture:
Agent-based overlay
13 // Guardicore
With Mellanox:
No agent on workload
▪ Policy Enforcement on NIC ▪ Complete network level visibility ▪ Automatic Policy updates ▪ Single centralized managed policy
14 // Guardicore 14 // Guardicore Confidential
15 // Guardicore
Challenges
vendor
implemented by:
Agentless Segmentation
✓ OS agnostic ✓ Participates in the same network policy ✓ Zero Trusted - Ring fence your
appliance
✓ Complete traffic visibility for the entire
environment
✓ No performance impact ✓ No reliance on the 3rd party vendor ✓ No network changes, no downtime
16 // Guardicore
Challenges
access and control
configuring top-of-rack switches and network appliances
Agentless Segmentation
✓ Distributed policy ✓ Centrally managed ✓ Built for scale ✓ DevOps ready - support automation ✓ Detached from the OS, controlled by
the provider
✓ No network changes, no downtime
17 // Guardicore
Challenges
support performance
Agentless Segmentation
✓ Offload the security to the hardware ✓ Make “space” for the things that
matter the most on the OS
✓ Securing every server individually ✓ Use the power of the high-
performance DPU to reduce latency and improve throughput