Zero Trust Microsegmentation Demo

Zero Trust Microsegmentation Demo

Watch our microsegmentation demo to see how NetFoundry's Zero Trust platform eliminates complex firewall rules and secures multi-cloud connectivity instantly.

Watch Jerome Mills, Sales Engineer at NetFoundry, demonstrate how to simplify microsegmentation across multi-cloud environments like AWS, Azure, and GCP using the NetFoundry Zero Trust platform. Learn how to eliminate complex firewall rules, overcome network drift, and instantly secure application connectivity with software-based, outbound-only connections.

Three Key Takeaways

  • Simplifies Network Security: Eliminates the need for complex firewall rules, ACLs, and NAT configurations by routing all traffic via standard, outbound-only port 443 connections.
  • True Zero Trust Architecture: Implements a “default deny” posture with continuous authentication. Connections are backed by X.509 certificates and mutual TLS, meaning access drops instantly if authorization changes.
  • Agnostic & Centralized Management: Operates as a purely software-based solution independent of underlying hardware, allowing unified, centralized policy management across multi-cloud environments (AWS, Azure, GCP).

FAQs

1. What are the challenges of traditional microsegmentation? Traditional microsegmentation requires a complex understanding of network topologies and is highly susceptible to network drift. As environments scale, organizations must manage excessive firewall rules, ACLs, and overlapping IP addresses, leading to performance degradation and difficult troubleshooting.

2. How does NetFoundry simplify microsegmentation? NetFoundry simplifies microsegmentation by making all connections outbound-only via standard port 443 (HTTPS). This software-driven approach eliminates the need to open inbound firewall ports, configure NATs, or write complex access control lists (ACLs).

3. How does NetFoundry secure network connections? All identities in the NetFoundry platform are backed by X.509 certificates to establish mutual TLS connections. The platform relies on a “default deny” architecture combined with continuous authentication and authorization to ensure only verified users and devices gain access.

4. What happens if access is revoked in NetFoundry’s platform? Because the platform utilizes continuous authentication and authorization, any revoked access triggers an immediate disconnection. The moment an identity or service is no longer authorized, the session is instantly dropped.

5. Does NetFoundry require specific hardware to run? No, NetFoundry is a 100% software-based solution. It is entirely independent of underlying hardware and can run seamlessly on commercial off-the-shelf (COTS) infrastructure, public clouds (like AWS, Azure, and GCP), or be integrated directly via SDKs.

Transcription

Hi, my name is Jerome Mills. I’m a Sales Engineer at NetFoundry. Today, I’ll be going over the microsegmentation demo using NetFoundry’s Zero Trust platform.

With traditional microsegmentation projects, the initial phase of getting a deep and complex understanding of your network topology is where many fail. This can take multiple steps, and with network drift, things will change in an ongoing manner. After that, you have to have a multitude of firewall rules and ACLs, and these only exacerbate as you increase by adding new data centers and different branches. Now you have to deal with overlapping IP addresses, NATs, and a whole lot of more issues. This can really result in performance degradation, harder-to-troubleshoot block traffic, and excessive firewall rules mean it’s hard to figure out which specific rule needs to be changed in order to allow or stop access altogether.

With the NetFoundry solution, all connections are made via port 443, outbound only. That means there is no need to change any firewall rules, no NATs, no special configuration. Everything is done via a standard HTTPS internet port. All identities are backed by an X.509 certificate, meaning that there is a mutual TLS connection. An ongoing authentication and authorization means that anytime a service is no longer allowed, it will immediately disconnect. All services and applications are done at a specific allow-access only. Everything is denied by default, and you can make those service policies as wide or as specific as you want, down to the specific IP and port combination. Everything now becomes centralized throughout your multiple pieces of network infrastructure, and so monitoring becomes a lot easier as you can see what identity went to where, for how long, and how much data they sent.

In this example, we have several EC2 instances located in AWS. They are all configured to read and verify connectivity to themselves, as well as Azure and GCP. I’ll be connecting via a trusted external source, and when I make changes to access policies, we’ll see how quickly it is that those services change.

Currently, nothing is allowed to talk to anything. We see that no specific instance is allowed to talk to any other instance. I can do a connectivity check up here, and we see that every single one has failed. Now, here in the customer connect console, down in the access policies, I’ll select this specific policy which is connected to this specific instance. I’ll go ahead and add several connectors, including EC instance 1 and Azure K8s. I’ll go ahead and save the access policy, wait a couple of seconds to reload the graph, and now we can see that App02 has connectivity to App01 as well as Azure K8s. Something to note as well is App01 still cannot connect to App00. This is because all rules are unidirectional, and so there is no need for any excessive firewall rules on multiple sides. We can verify the policy again, and we see that in fact we have several successes, and if I go to App1, we still have all of those fails.

To review, we’ve seen that with the NetFoundry solution, everything is done by a simple click of the button to allow access to specific devices to specific services. Our platform is software-based, so everything is done regardless of the underlying infrastructure or the changes in the hardware. We can run on COTS infrastructure, as well as in the cloud, and we have things directly down to the SDK as well. As our solution, we can make this happen. Thank you for your time, and reach out for more information.