New enhancements include a prescriptive workflow to accelerate Advanced Threat Prevention (ATP) deployment, an on-premises Malware Prevention System, comprehensive air-gapped support, an AI Assistant for firewall operations, major performance gains for the Distributed Firewall and Intrusion Detection and Prevention Service (IDPS), and automated migration tooling.
Earlier in May, VMware vDefend delivered Self-Service Lateral Security for VMware Cloud Foundation (VCF) 9.1, featuring support for unified lateral threat prevention for VMs and VKS workloads, high-performance threat prevention with IDPS Turbo Mode, and enhanced distributed firewall capabilities.
As Frontier AI continues to reshape the threat landscape, enterprises face new challenges in securing, operating, and scaling their private clouds. Attackers are using Frontier AI to exploit software vulnerabilities at machine speed, and the rapid adoption of agentic AI is drastically expanding the attack surface. At the same time, fragmented tools and manual processes are slowing down security teams, while rising hardware costs make it difficult for organizations to scale efficiently.
VMware vDefend addresses these challenges with new innovations focused on three pillars: enhanced security, simplified operations, and optimized performance and resources.
The detailed innovations under these three pillars are as follows:
1. Enhanced Security
- Accelerated Advanced Threat Prevention with vDefend 1-2-3: Introduces a streamlined, three-step deployment workflow that accelerates time-to-value for ATP, enabling overextended IT teams to rapidly deploy defenses in just a few weeks instead of many months.
- On-Premises Malware Prevention System: Brings malware sandboxing on-prem, analyzing static and dynamic artifacts entirely within the local network. All vDefend capabilities are now fully supported on-prem.
- Comprehensive Air-Gapped Support: All vDefend capabilities are now fully supported in air-gapped environments. This deployment model enables secure, offline threat intelligence updates, allowing highly sensitive environments to stay up to date on the latest threat signatures without connecting to the cloud.
2. Simplified Operations
- AI Assistant: vDefend now includes AI Assistant to streamline lateral security operations. It embeds AI-powered automation directly into the platform to simplify firewall operations and troubleshooting.
- Automated Migration to vDefend Distributed Firewall: This vACT enhancement simplifies and automates the migration of legacy, agent-based firewall solutions to DFW, significantly reducing migration costs and accelerating security posture.
3. Optimized Performance and Resources
- Distributed Firewall Performance Improvements: To secure data-heavy AI workloads, vDefend significantly enhances Distributed Firewall (DFW) throughput to 22 Gbps on 25G NIC servers (a 129% increase) and 75 Gbps on 100G NIC servers (an additional 241% increase), achieving up to 75 Tbps scale-out performance per VCF instance.
- Distributed Intrusion Detection and Prevention System Performance: vDefend can now boost Intrusion Detection and Prevention System (IDPS) performance to 17Gbps per server (an 89% increase), delivering up to 17 Tbps of scale-out performance for distributed virtual patching per VCF instance.
- Leaner Security Services Platform Deployment Model: vDefend introduces a leaner Security Services Platform (SSP) deployment model that reduces the physical hardware required to run the platform, lowering infrastructure costs.
The sections below describe each vDefend innovation in detail and highlight customer benefits.
vDefend 1-2-3 for ATP: Deployment Automation Workflows
Infiltration occurs when network traffic goes uninspected; therefore, implementing IDPS across all workloads, not just mission-critical ones, is essential. Additionally, robust network security requires zero-day threat detection and mitigation capabilities.
vDefend 1-2-3 for ATP is a new guided workflow that accelerates the deployment of Advanced Threat Prevention across private cloud environments. Designed similarly to the vDefend 1-2-3-4 for DFW workflow for lateral (macro and micro) segmentation, ATP workflow streamlines the implementation of IDPS, Network Traffic Analysis (NTA), and Network Detection and Response (NDR), reducing deployment times from months to weeks.
The workflow consists of three stages:
- Stage 1: Conducts a threat posture assessment focused on IDPS, NTA, and NDR to evaluate current risks and provide recommendations.
- Stage 2: Applies recommended IDPS policies to protect shared services infrastructure, such as Active Directory, DNS, and NTP.
- Stage 3: Expands IDPS policies across zones (environments) such as DMZ, Dev, and Production.
By using this guided workflow, IT teams can rapidly deploy Advanced Threat Prevention, including virtual patching and zero-day threat mitigation, to strengthen security posture and compliance.
On-Premises Malware Prevention System
Highly regulated industries face strict data sovereignty requirements and compliance standards such as HIPAA and GDPR, which make it essential to keep sensitive data and files inside local data centers. vDefend now offers an on-premises Malware Prevention System (MPS) that meets these requirements without compromising threat detection. This architecture brings malware sandboxing directly into the local data center, eliminating the need to upload files to an external public cloud. By keeping all sensitive data, files, and metadata strictly inside local boundaries, enterprises remove external attack surfaces while maintaining full control over their sensitive data.
Comprehensive Air-Gapped Support
For infrastructure requiring absolute operational isolation and strict data privacy, defending against modern threats without exposing internal systems to the internet is critical.
vDefend now offers a comprehensive, air-gapped deployment model to keep all network traffic, files, and data strictly inside the local data center. It eliminates external dependencies and public cloud connectivity. Security teams can safely download offline threat intelligence updates and manually upload them to vDefend. This maintains up-to-date signatures against new threats without connecting to external cloud services.
AI Assistant for vDefend
Complex workflows and troubleshooting slow infrastructure and security teams down, consuming time, introducing risk, and holding back business agility. To reduce this complexity, VMware is introducing an AI Assistant for vDefend. By embedding intelligence directly into the platform, the tool accelerates troubleshooting, provides version-aware design guidance, and automates policy cleanup to eliminate duplicate and redundant rules. It also offers real-time visibility into live configurations, performance metrics, security events, and API assistance for automation. This operational intelligence allows security teams to streamline day-to-day operations and improve overall efficiency.
Leaner Security Services Platform (SSP) for Lower-Footprint Entry Point
Enterprise IT teams need deep traffic visibility and security posture assessments to manage security risks effectively. The Security Services Platform (SSP) serves as a scale-out data lake that ingests network flow records and telemetry, providing granular flow visibility, security assessment scores, policy recommendations, and guided workflows. With rising server costs, vDefend now offers a leaner SSP deployment model with a lower-footprint entry point starting at 32 CPU cores. This new deployment model reduces physical server requirements by up to 33%, allowing organizations to lower infrastructure costs. The scale-out architecture of the SSP platform allows it to expand as needs grow.
Enhanced Distributed Firewall and IDPS Performance
vDefend delivers major performance improvements across both the Distributed Firewall (DFW) and IDPS engines.
- Distributed Firewall: DFW can now scale up to 22 Tbps (129% increase) and 75 Tbps (further 241% increase) per VCF instance using 25G and 100G NIC servers, respectively. With server costs on the rise, these enhancements allow enterprises to scale performance-intensive workloads using their existing server hardware via a software upgrade.
- Distributed IDPS: IDPS now delivers up to 17 Gbps per host, providing up to 17 Tbps (89% increase) scale-out capacity per VCF instance. These enhancements allow organizations to run hypervisor-native distributed virtual patching and secure performance-intensive AI traffic at scale, all delivered via a software upgrade.

Automated Migration to vDefend Distributed Firewall
Migrating from legacy, agent-based firewall solutions is often slow and resource-intensive due to the manual effort required to translate complex rule sets. To eliminate this deployment friction, VMware offers the vDefend and Avi Conversion Tool (vACT) to automate security policy migrations. The tool automatically converts existing firewall rules and configurations directly into native vDefend policies. By accelerating transition and minimizing manual errors, vACT enables organizations to reduce overall migration costs and improve lateral security posture more quickly.
The new enhancements are delivered in vDefend Security Services Platform 5.2, vDefend 9.1.1, and vDefend and Avi Conversion Tool (vACT) 3.0 releases, all of which are compatible with the VCF private cloud 9.1 release.
Lateral Defense for Agentic AI workloads
As enterprises deploy agentic AI in their private cloud, Zero Trust lateral security will be necessary day one. Additionally, security technologies must recognize new agentic AI constructs, such as LLMs, agents, tools and AI protocols. One example is the Model Context Protocol (MCP), which enables agents to interact with various enterprise tools, data, and services. In addition to securing MCP traffic, it is important to harden the MCP itself in line with established enterprise-ready protocols like HTTP, SIP, SSH, and TLS. vDefend engineers took a leading role by championing a proposal to harden stateless MCP interactions, which is now reflected in Agentic AI Foundation’s updated MCP specification released in July 2026 (see coverage in the Ars Technica article). Such collaborations are critical for achieving the visibility and policy enforcement required to secure agentic AI workloads.
Conclusion
Modern enterprises require a multi-layer private cloud lateral defense that is distributed, automated, and high-performance to protect workloads against evolving, AI-driven threats. The latest vDefend enhancements further strengthen the solution through streamlined Advanced Threat Prevention workflows, flexible deployment models for highly sensitive environments, AI-assisted firewall operations, and significantly improved distributed firewall and IDPS performance. Together, these innovations enable security teams to stay ahead of threats and ensure the robust, multi-layer security required for modern private clouds.
To learn more about vDefend, see the links below.
Resources
- Dark Reading: Why Virtual Patching and Multi-Layer Defense are Critical in the Age of Frontier AI
- Multi-layer Defense in the AI Era
- VMware vDefend for VCF 9.1: Zero Trust Lateral Security for the AI Era
- vDefend DFW 1-2-3-4: Deploy Zero Trust Microsegmentation
- Zero Trust Lateral Security for Kubernetes Workloads on VCF
- Advancing Zero Trust Private Cloud with vDefend Lateral Security
- Enhance Lateral Security and Ingress Load Balancing for Kubernetes Workloads
- Broadcom Unveils AI-Ready Lateral Security and App Delivery Innovations
- vDefend Webinar Series
- Customer Case Studies: St. John’s Health | United States Senate Federal Credit Union | GCI





