For the foreseeable future, data centers will be hybrid computing environments
Earlier I expressed concern that nextgen networking architectures will force a choice between physical and virtual security. Yet, for the foreseeable future, data centers will be hybrid physical-virtual computing environments requiring us instead to choose physical and virtual approaches to security.
While 42% of workloads on average already run on a hypervisor, clients tell us a significant percentage of the remainder will stay physical for some time, for the following reasons:
1. Performance: Multitasking of network bandwidth and storage operations is central to virtualization but introduce latency. Some applications—such as trading floor applications—cannot tolerate this level of latency and potentially, jitter.
2. Legacy Coding: There are legacy applications that are virtualization incompatible because of software hard coded to specific hardware or non-standard operating systems.
3. Compliance: Some systems are not yet certified to operate on a virtualization platform. For example, the Food and Drug Administration (FDA) has yet to certify virtualization for most patient-facing systems.
4. Unique Hardware: Some systems require unique hardware adapters and co-processors that are incompatible with virtualization.
Physical security devices will continue to be the first layer of defense for nonvirtualized servers. But physical security devices currently require hairpin VLAN routing to secure traffic among co-resident VMs and are not virtual machine movement aware—ultimately limiting agility and flexibility. Virtualization also flattens the infrastructure, reducing a layer of depth. In the end, to restore defense-in-depth, optimize agility and flexibility, and support physical servers, a hybrid security architecture integrating physical with virtual security is optimal.




