Broadcom has announced new capabilities for VMware vDefend and VMware Avi Load Balancer, designed to strengthen security across private-cloud workloads while reducing deployment and operational complexity for stretched security teams.
The updates extend VMware Cloud Foundation (VCF) with additional controls for lateral movement, malware, API attacks and vulnerable workloads.
For CISOs, the focus is on consolidating protection within the private-cloud environment rather than relying on disconnected point products, particularly as virtual machines, Kubernetes services and artificial intelligence workloads expand the attack surface.
Faster protection and response
Broadcom’s vDefend Security Services Platform introduces a three-step Advanced Threat Prevention workflow, known as vDefend 1-2-3. The company says the prescriptive process can reduce deployment time from many months to a matter of weeks when used with Distributed Firewall capabilities.
The workflow is intended to provide workload-level visibility, highlight security posture, recommend rules and guide security teams through implementation. VCF customers can also deploy malware sandboxing on premises, allowing static and dynamic analysis to take place within the local network.
Full support for air-gapped environments enables offline threat-intelligence updates for sensitive systems that cannot connect to the cloud.
Avi Load Balancer now adds native API protection for virtual machines, vSphere Kubernetes Services and AI workloads. Its Web Application and API Protection capabilities are designed to give security teams greater visibility into API traffic and help close gaps between application, workload and network controls.
“As AI-fuelled cyberattacks and vulnerability exploits redefine the threat landscape, a fragmented security approach is no longer an option,” said Umesh Mahajan, vice president and general manager, Application Networking and Security Division, Broadcom.
“With today’s updates to vDefend and Avi Load Balancer, we are giving enterprise customers the protection, performance and automation they need to defend their application infrastructure at scale.” Umesh Mahajan
Lower infrastructure and migration overhead
The updates also target the cost of operating private-cloud security. Broadcom says a new two-node vDefend deployment model can reduce the physical hardware required by up to 33%.
The company reports Distributed Firewall throughput of up to 75Gbps on 100G NIC servers, while Avi Load Balancer throughput can reach 12.25Tbps per controller instance. These are vendor-reported figures and will depend on deployment conditions.
An AI Assistant has been added to vDefend Distributed Firewall and Avi Load Balancer to support troubleshooting and remediation.
Meanwhile, version 3.0 of the vDefend and Avi Conversion Tool is intended to automate migration from legacy agent-based firewalls to Distributed Firewall, potentially reducing migration effort and cost.










