Announcing Avi’s software-defined Web Application and API Protection (WAAP), significant performance improvement and AI-powered Assistant to enhance operator productivity
Earlier in May, VMware Avi Load Balancer delivered plug-and-play integration in VMware Cloud Foundation (VCF) 9.1, featuring support for self-service multi-tenant Virtual Private Clouds (VPC) and complete automation via the VMware vSphere Kubernetes Service (VKS). We are now announcing additional Avi enhancements focused on:
- Software-defined WAAP – now with API protection – a scale-out and built-in solution to protect vulnerable APIs with in-line web application security across VMs, VKS and AI workloads.
- AI Assistant for VMware Avi to improve operational efficiency: a GenAI-powered assistant designed to accelerate how administrators troubleshoot security anomalies and application performance issues.
- Improved Application Delivery Performance to reduce CapEx with scale-out throughput boosted up to 12.25Tbps (88% increase) per controller instance.

WAF to WAAP: Enhancing In-Line Web App Security
Web Application Firewalls (WAFs) provide the first line of defense against OWASP Top 10 Web Attacks including cross-site scripting (XSS) and SQL injection (SQLi). Avi has made significant enhancements to WAF performance, evaluation mode and web app security assessment report. WAF is a mandatory requirement for compliance including PCI, HIPAA and GDPR.
APIs have emerged as primary vectors for malicious actors attempting infrastructure breaches. Nearly 87% of global organizations suffered an API security incident last year1, and 43% of Cybersecurity and Infrastructure Security Agency (CISA) known exploited vulnerabilities (KEV) additions are API-related2. The unprecedented velocity, massive scale and expanded attack surface of AI-fueled web threats demand a critical evolution from WAFs to comprehensive WAAP frameworks. The exponential growth of API interactions driven by Kubernetes and AI workloads requires comprehensive protection against the OWASP Top 10 API vulnerabilities.
To close this gap, Avi is extending its WAF into a software-defined, scale-out WAAP solution that auto heals, auto scales and delivers high performance to counter automated AI-driven exploits. By integrating directly into the load-balancing data path, Avi delivers a single, in-line security shield that delivers high-performance, scale-out and hairpin-free protection against both web vulnerabilities as well as sophisticated API exploits. Avi provides protection throughout the discovery, enforcement, and operations stages.

Key features of Avi’s WAAP solution include:
- Comprehensive Web App Security Stack: Avi WAAP provides a fully integrated, defense-in-depth architecture that simplifies policy management for both applications and APIs. The stack unifies WAF with distributed DDoS protection, advanced bot management, Layer 7 rate limiting, IP reputation filtering, and robust SSL/TLS termination all functioning within a single, software-defined architecture.
- Zero-Day Protection: Leveraging closed-loop analytics and AI-assisted application learning, Avi establishes a positive security model that validates known good behavior in real time. When new threats emerge, Avi is quick to respond, scale and protect.
- Deep API Discovery and Visualization: Positioned directly inline of the application traffic, Avi WAAP leverages AI and machine learning to automatically discover all API traffic without requiring manual developer entry. This data is transformed into actionable visualizations, providing real-time visibility into how end users actually consume applications, bridging the gap between how the APIs were architected and utilized. The visualization provides:
- API Breakdown: Modernized interface for enhanced user experience and streamlined API lifecycle workflows.
- Integrated Statistics: Application insights are now natively part of the Virtual Service.
- API Characteristics: Superior visualization of API endpoint behavior and characteristics.

- Automated “SOZA” API Classification: Avi WAAP automatically categorizes every discovered endpoint into four distinct categories: Shadow, Orphan, Zombie, and Active (SOZA). This highlights hidden risks, enforces security posture, and identifies gaps between actual application traffic and intended specifications. This proactive visibility enables security teams to quickly shrink their attack surface and safely retire undocumented code before it can be exploited.
- Granular Per-API Policy Enforcement: Instead of relying solely on broad, virtual-service-level policies, Avi empowers security teams to apply controls with pinpoint precision. Custom rate limiting, authentication requirements, HTTP security policies and specific WAF rules can be extended down to the individual API endpoint or path. This granularity ensures highly sensitive or resource-intensive APIs are protected without degrading performance or accessibility.
- OpenAPI Spec Enforcement: To prevent unauthorized access and mitigate vulnerabilities from reaching backend application systems, Avi enables administrators to import standard Swagger/OpenAPI specifications directly into the API Protection policy. This creates a strict allow-list based on least privilege principles, ensuring the application only accepts traffic matching predefined schemas, authorized paths, and expected data formats rejecting anything outside the defined contract.

Deep Operational ROI: Meet AI Assistant for Avi
Modern enterprises require application delivery infrastructure that accelerates business agility, but increasing architectural complexity often traps IT teams in fragmented visibility and reactive troubleshooting war rooms. To deliver seamless digital experiences at scale, organizations must transition from manual management to intelligent, automated operations.

AI Assistant for Avi is an advanced, GenAI-powered chat assistant designed to modernize how enterprises deploy, manage and secure their application infrastructure. By combining Avi’s industry-leading, context-aware analytics with a conversational AI interface, AI Assistant translates rich network telemetry into actionable operational insights.
Here is how AI Assistant empowers enterprise IT teams to drive efficiency, drastically reduce mean time to resolution (MTTR), and maximize operational ROI:
- Knowledge Hub to Boost Team Productivity: Built directly from Avi documentation, release notes, deployment guides, knowledge base articles and Avi APIs guides right at your team’s fingertips, the AI Assistant for Avi acts as a consistent “brain” for your organization. By instantly connecting teams with accurate answers derived from this knowledge hub, it reduces repetitive questions and wasted search time. This centralized intelligence streamlines daily workflows and dramatically boosts overall productivity.
- Assisted Troubleshooting and Expedited Root-Cause Analysis: Less of manual log aggregation and prolonged operational war rooms, AI Assistant allows administrators to interact directly with real-time analytics using natural language. Queries such as, “Why is the e-commerce virtual service experiencing high latency?” yield instant, diagnostic insights, rapidly resolving complex triaging paths and significantly reducing MTTR.
- Contextual App Insights and Best Practice Recommendations: Being the knowledge hub, AI Assistant delivers contextual, expert-level configuration step-by-step recommendations, and API assistance for automation. It provides operations teams with continuous access to curated app insights, accelerates enablement and standardizes operational excellence across your IT teams.
Boosting Application Delivery Performance
Legacy, appliance-based approach to load balancing and web application security is increasingly deficient in the era of agentic AI, exacerbated by rising hardware cost. It’s more important than ever to enhance scale-out performance with a software-defined, distributed platform: elastic active-active, auto heal and auto scale capabilities. Furthermore, the performance improvements can be delivered through a simple software upgrade.

Learn More
- Read vDefend Announcement Blog: VMware vDefend Advances Multi-Layer Lateral Security, Deployment Automation and Performance for the Frontier AI Era
- Attend Umesh Mahajan’s Explore Session: Operationalizing Cyber Defense and App Resilience for the Agentic AI Era [SECB1789LV]
- Attend VMware Explore Session on WAAP: Secure the Unknown: Automating API Protection and WAF with VMware Avi Load Balancer [SECB1572LV]
- More sessions, check out the Explore blogs: vDefend and Avi
Sources