Broadcom has released a set of security and application delivery updates for
VMware Cloud Foundation, adding new capabilities to
VMware vDefend and
VMware Avi Load Balancer. The announcements address several parts of private cloud security, including lateral movement, malware analysis, application delivery, web application protection, and API discovery. Broadcom is also adding AI assistants to both products, along with performance improvements designed to help customers support larger workloads without adding hardware.
Avi adds API discovery and protection
Avi Load Balancer now includes native web application and API protection for virtual machines, VMware vSphere Kubernetes Service workloads, and AI applications. The update extends Avi’s web application firewall into a software-defined web application and API protection platform. It sits directly in the load-balancing data path, giving security teams a single place to inspect web and API traffic without sending requests through a separate security service.
The platform automatically discovers APIs by observing live application traffic. It then classifies endpoints as active, shadow, orphan or zombie APIs, which can help teams find undocumented interfaces and services that remain exposed after they are no longer needed. Policies can be applied to individual API endpoints and paths. Administrators can set authentication requirements, rate limits, HTTP security policies and WAF rules based on the sensitivity or behavior of each API.Avi can also import Swagger and OpenAPI specifications.
vDefend adds a guided threat-prevention workflow
VMware vDefend is adding a guided deployment process for Advanced Threat Prevention, including intrusion detection and prevention, network traffic analysis, and network detection and response. The workflow begins with a threat posture assessment. It then applies recommended protection policies to shared services such as Active Directory, DNS and NTP before expanding coverage across development, production, and demilitarized zones.
Broadcom said the process is designed to reduce deployments that previously took months to a matter of weeks. The guided model also gives infrastructure teams a more structured way to introduce virtual patching and zero-day mitigation across private cloud workloads.
vDefend now supports on-premises malware sandboxing. Files, metadata, and analysis remain inside the customer’s local environment rather than being uploaded to a public cloud service. The option is aimed at organizations with data sovereignty, privacy or regulatory requirements that limit where files can be analyzed. It also gives customers more control over how suspicious artifacts move through the investigation process.
vDefend support is also extended to air-gapped environments as well. Customers can download threat intelligence updates separately and transfer them into isolated networks without connecting the protected environment to an external cloud service.
AI assistants focus on troubleshooting and operations
Broadcom is adding separate AI assistants to vDefend and Avi Load Balancer. The vDefend assistant can answer questions about configurations, performance, security events and product guidance. It can also help identify duplicate firewall rules, support policy cleanup and provide API guidance for automation.
The Avi assistant uses product documentation, deployment guides, release notes, knowledge base articles and application telemetry. Administrators can ask natural-language questions about issues such as latency or service health and receive diagnostic information tied to the current environment.
These assistants are being positioned as operational tools. Their value will depend on how accurately they interpret live configurations and whether teams can rely on their recommendations during troubleshooting.
Multi-tenant management for MSPs and MSSPs
The ability to operate the products across multiple customer environments will be important for service providers looking to build recurring offerings around the technology.
Umesh Mahajan, VP and GM of Broadcom's Application Networking and Security Division, told ChannelE2E that both products support multi-tenant managed service delivery, although they use different architectures.
“MSPs and MSSPs can manage both VMware vDefend and VMware Avi Load Balancer across multiple customer environments,” Mahajan said.
“vDefend is built for multi-tenant managed service delivery, with each customer environment managed as a completely isolated tenant through a VPC-aware architecture. The vDefend Security Services Platform (SSP), a scale-out data lake, is dedicated per tenant by design. This architecture ensures strict isolation of VPC-aware security policies, visibility and reporting for each MSSP client.”
Avi allows providers to manage multiple tenants through a shared controller while maintaining separate customer boundaries.
“Avi Load Balancer is purpose-built for multi-tenant managed service delivery, with each customer operating as a completely isolated tenant within a single Avi Controller deployment,” Mahajan said. “Tenant boundaries, traffic isolation, and access controls are enforced automatically through the software-defined architecture.”
The design supports shared or dedicated Service Engine groups, depending on how a provider wants to separate customer workloads and resources.
“Additionally, it offers MSPs a unified ‘All Tenants’ operations dashboard, while simultaneously ensuring each tenant has exclusive, secure access to their own performance analytics,” Mahajan said.
That gives providers a central operational view while keeping customer policies, analytics and access separated. It also creates a foundation for standardized services that can be applied across several accounts without placing all customers inside the same policy or reporting structure.
Partners can build tiered managed services
Broadcom is positioning both products as platforms that MSPs and MSSPs can package into tiered managed services.
The spokesperson said each product includes its capabilities within a single SKU, allowing providers to determine which functions are included at each service level.
“VMware vDefend and Avi Load Balancer allow MSPs to monetize services using a tiered approach,” Mahajan said. “Since all capabilities for each solution are included in a single SKU, respectively, MSPs can easily create tiered service offerings that align with their customers’ specific needs.”
For vDefend, an entry-level service could include tenant isolation, security posture assessments, scoring and visibility. An advanced tier could add protection for infrastructure services such as DNS and NTP, along with zone segmentation.
Higher tiers could include managed intrusion detection and prevention, virtual patching, application segmentation and managed network detection and response backed by a service-level agreement.
“This approach enables partners to monetize higher-value services at significantly higher margins,” Mahajan said.
The Avi model follows a similar path. A basic managed application delivery service could cover local Layer 4 and Layer 7 load balancing, SSL and TLS termination, certificate lifecycle management, health monitoring and application analytics.
An advanced tier could add Kubernetes or OpenShift ingress, container load balancing, global server load balancing and multicluster services. A managed application security tier could add WAF policy development, tuning, OWASP Top 10 coverage and virtual patching for virtual machine and container workloads.
The highest tier could include managed web application and API protection, API discovery, API security policy management, DDoS controls, and rate limiting for conventional and AI workloads.
Support extends beyond a VMware-only environment
The new security capabilities are tied closely to VMware Cloud Foundation, but Broadcom said vDefend and Avi can also operate across mixed infrastructure.
“VMware vDefend provides deployment models that protect heterogeneous environments,” Mahajan said.
For virtual machines, vDefend uses a hypervisor-native distributed firewall. Container protection is delivered through firewalls embedded in VMware vSphere Kubernetes Service and Kubernetes environments.Bare-metal systems can be protected through Linux host plug-ins or an operating system-agnostic gateway firewall. The vDefend NDR Sensor can also operate as an out-of-band collection appliance for physical and nonvirtualized workloads.
The company said customers can extend consistent policies and operating workflows to VMware Cloud Foundation environments running in AWS, Microsoft Azure and Google Cloud.
Avi has a broader infrastructure-agnostic deployment model. “The Avi Load Balancer features an infrastructure-agnostic architecture, supporting deployments across VCF private clouds, virtualized and Kubernetes workloads, non-VMware Kubernetes workloads, bare metal workloads, and public cloud environments,” said Mahajan.
APIs connect the platforms to MSP tooling
MSPs also need to connect security and application delivery platforms to the systems they already use for monitoring, automation, ticketing, and customer reporting.
“Comprehensive API and programmatic integration frameworks are available for both VMware vDefend and VMware Avi Load Balancer to connect natively with third-party security, operations, and ticketing platforms,” Mahajan said.
vDefend supports integrations with SIEM platforms, including Splunk, IBM QRadar, and ArcSight. Its NDR component can send detection and campaign logs to SIEM systems using JSON over HTTPS.
“Additionally, vDefend offers REST API-based export, enabling the structured, context-rich security event data ideal for custom SOAR playbooks and automated triage workflows,” Mahajan said.
For IT service management, providers can use the ServiceNow plug-in for VMware Cloud Foundation Automation to route approval processes, change requests, and incident tickets through ServiceNow workflows.
Avi is built around a northbound REST API that covers the platform’s capabilities.
“Avi features 100% northbound REST API coverage across all capabilities,” Mahajan said. “This allows providers to connect load balancing operations, WAF configurations, and telemetry fields directly into their existing ticketing, such as ServiceNow, SIEM/SOAR platforms, or custom-built partner control portals.”