The Security Implications of VEPA

Opinion
Dec 14, 20092 mins

IT teams will need to choose when to deploy physical vs. virtual security

Last week Extreme Networks announced that it will base its next-generation data center architecture on the emerging IEEE Virtual Ethernet Port Aggregation (VEPA) specification. VEPA pushes virtual machine data switching from the server to the switching hardware. A consequence of implementing VEPA is servers will stick to traditional server-based security (host IDS/IPS, access control, file integrity control, logging, etc.) and physical network security devices will do the security heavy lifting. VEPA forces IT teams to make choices on when to deploy physical versus virtual security.

The security advantage of VEPA is it’s an open standard, offering a non-proprietary architecture for deploying and managing a virtual network infrastructure. VEPA itself provides little direct security benefit over a virtual switch implementation. For example, the initial proposal points to security functionality not available with virtual switches such as DHCP Snooping, IP Source port filtering and ARP inspection. Yet, Cisco is releasing this functionality on the Nexus 1000v this month. Similarly, VEPA brings network control back to the networking team, enhancing the overall security posture of the organization. This matches virtual switch-based approaches taken by vendors including Arista, Brocade and Cisco.

VEPA forces security teams to determine when it’s better to route all traffic to the physical switch to interface with security appliances versus the virtual switch. The standard supports co-existence with a virtual switch. The bottom line is VEPA offers a different architectural approach to virtualization security and just like proprietary solutions VEPA must be evaluated as part of an overall defense-in-depth strategy.