
The platform's security: advanced distributed firewall and threat prevention inside VCF — the defense where the workloads live.
vDefend extends NSX from segmentation to active defense: distributed IPS/IDS on the traffic between the VMs, a sandbox for the malware, network traffic analysis and threat intelligence — all inside the hypervisor, where the east-west traffic lives. The ransomware moving between the servers meets inspection, not just rules.


IPS and analysis first on the ERP, domain controllers and backup: the defense where the damage is greatest.
Profiles per segment and false positives tamed: the security that doesn't break production.
The suspicious VM isolated via policy in seconds: containment as a platform action.
The internal traffic inspected and documented: NIS2 and audits served.
vDefend is VCF's security: the Distributed Firewall microsegments at the vNIC level with dynamic groups, the Advanced Threat Prevention adds distributed IDS/IPS, sandboxing (NTA) and network detection; the Security Intelligence discovers the flows and RECOMMENDS the policies (the microsegmentation project accelerated); the malware analysis sees the files in transit; all without appliances in the middle: the inspection lives in the hypervisor.
The lateral movement not just blocked: seen and analyzed.
The internal inspection with the proof.
The backup network under special watch.