StorageReview.com

VMware vDefend Claims 75Tbps Distributed Firewall Throughput in Broadcom VCF 9.1 Update

Cloud  ◇  Enterprise

Broadcom has issued updates for VMware vDefend and VMware Avi Load Balancer, enhancing security, performance, deployment, and automation features for VMware Cloud Foundation 9.1 environments. These updates include vDefend SSP 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4, and the vDefend and Avi Conversion Tool 3.0.

The updates focus on private cloud deployments where IT teams implement distributed security controls across virtual machines, Kubernetes services, AI infrastructure, and application APIs. Broadcom frames these releases within a multi-layer model integrating east-west microsegmentation, intrusion prevention, malware analysis, web application firewall features, API security, and application delivery.

Broadcom graphic of the vDefend 1-2-3 deployment workflow for Advanced Threat Prevention

Faster vDefend Deployment and Expanded On-Premises Security

The vDefend Security Services Platform adds a 1-2-3 deployment workflow for Advanced Threat Prevention. This process reduces the operational work needed to deploy threat prevention services by providing a guided path for policy assessment, rule recommendations, and deployment.

VMware vDefend Security Services Platform overview graphic

The workflow integrates with vDefend Distributed Firewall, using workload-level visibility to assess security posture and recommend segmentation policies. The goal is to shorten deployment timelines for advanced threat prevention and reduce manual policy creation by security teams.

Broadcom also added on-premises malware prevention through local sandboxing. Static and dynamic malware artifacts can be analyzed within the customer environment without sending data to a cloud service. This option suits organizations with data sovereignty, regulated data, or isolated environment requirements.

VMware vDefend air-gapped deployment graphic showing offline threat intelligence updates

All vDefend capabilities now support air-gapped environments. Broadcom said threat intelligence can be updated offline, allowing disconnected environments to receive current threat data while maintaining network isolation.

Native API Protection for VMs, Kubernetes, and AI Workloads

Avi Load Balancer now adds native API protection for VMs, vSphere Kubernetes Services, and AI workloads. This combines web application firewall controls with API protection, creating a WAAP capability to identify exposed APIs, apply protections, and improve application-layer visibility.

Broadcom graphic of Avi Load Balancer WAAP combining web application firewall and API protection

APIs have become a common attack surface in private cloud deployments, especially as applications decompose into microservices exposed through Kubernetes-based services. Integrating API protection with Avi Load Balancer can reduce the number of separate security products needed to protect application traffic while keeping policy enforcement close to the load balancing and application delivery layer.

Higher Distributed Firewall and IDPS Performance

Broadcom also reported higher throughput figures for vDefend Distributed Firewall and Distributed Intrusion Detection and Prevention System deployments.

For Distributed Firewall, Broadcom cites throughput up to 22Gbps on servers with 25GbE NICs, a 129 percent increase, and up to 75Gbps on systems with 100GbE NICs, a 241 percent increase. At scale, Broadcom reports Distributed Firewall throughput up to 75Tbps per VMware Cloud Foundation instance.

VMware vDefend Distributed Firewall performance graphic with throughput gains

The company also increased distributed IDPS performance up to 17Gbps per server, an 89 percent increase. Broadcom reports scale-out IDPS throughput up to 17Tbps per VCF instance. All performance figures are based on internal Broadcom test results from July 2026.

These capabilities support virtual patching at the workload layer. Distributed IDPS can inspect traffic and block exploit attempts within the hypervisor layer, providing compensating control while organizations test and deploy software patches. This is especially relevant for AI infrastructure and other data-heavy environments where lateral traffic volumes can be substantial.

Reduced SSP Footprint and Avi Throughput Gains

vDefend SSP 5.2 introduces a two-node deployment model. Broadcom said this configuration can reduce the physical infrastructure needed to operate SSP by up to 33 percent while retaining lateral segmentation functionality.

Avi Load Balancer also receives scale-out performance improvements. Broadcom reports up to 12.25Tbps throughput per controller instance, an 88 percent increase. For large application environments, this targets higher application delivery density without proportional expansion of load balancing infrastructure.

AI Assistant and Firewall Migration Automation

Both vDefend Distributed Firewall and Avi Load Balancer now include an AI Assistant to simplify administration, troubleshooting, and remediation workflows. Broadcom did not provide implementation details but positioned it as an embedded tool to reduce operational complexity in security and load balancing operations.

Broadcom vDefend and Avi Conversion Tool graphic for migrating legacy firewalls

The updated vDefend and Avi Conversion Tool, vACT 3.0, adds migration capabilities for moving from legacy agent-based firewalls to vDefend Distributed Firewall. The tool automates elements of firewall policy migration and reduces the effort of transitioning to a distributed, hypervisor-based segmentation model.

The new features are compatible with VMware Cloud Foundation 9.1.

Engage with StorageReview

Newsletter | YouTube | Podcast iTunes/Spotify | Instagram | Twitter | TikTok | RSS Feed

Harold Fritts

I have been in the tech industry since IBM created Selectric. My background, though, is writing. So I decided to get out of the pre-sales biz and return to my roots, doing a bit of writing but still being involved in technology.