VMware Cloud provides numerous ways in which workloads can be made resilient to security and other types of incidents. NSX GatewaysWorkload network segments that are defined in the SDDC are protected by the NSX Gateways . MicrosegmentationThe NSX Distributed Firewall is included with every Azure VMware Solution. This firewall provides microsegmentation capabilities by inspecting and controlling traffic at the VM network interface. Unlike a traditional firewall, this allows control of network traffic between workloads on the same network segment, as well as from other sources. Network Egress ControlsThe public IP address network service allows you to connect from the internet to a workload virtual machine (VM), a management appliance, or a load balancer running in your private cloud. Console AccessMany organizations adopt a mindset for vCenter Server & Azure portal access that is taken directly from traditional data center practices. Intrusion Detection & PreventionThe NSX Advanced Firewall Add On provides a distributed IDS/IPS, L7 FW and DNS filtering that enhance the capabilities of the existing distributed firewall, providing a distributed, scalable security solution that is fully integrated with the Private Cloud and vRealize Log Insight Cloud for monitoring, and can help address many of the considerations in this document. VMware ToolsVMware Tools are an important component for virtual machines, supplying drivers for paravirtual devices like the vmxnet3 network interface and the pvscsi virtual SCSI controller, as well as a communications channel between ESXi and the guest operating system. In-Guest ControlsSecurity controls inside workloads are the responsibility of the customer in the Shared Responsibility Model. In-Guest Data-at-Rest ProtectionsVMware Cloud uses vSAN Data-at-Rest encryption to store data in a public cloud provider’s storage. Storage PoliciesAs discussed in the Infrastructure Design section, virtual machines can be assigned different vSAN storage policies which have an impact on performance and storage usage. MulticastL3 Multicast is not supported (e.g. PIM, IGMP snooping). However, and L2 multicast traffic is treated as a broadcast and sent to all ports on the network segment. This enables applications that use multicast to communicate in the same network segment, but does not support the optimization of having the network send traffic only subscribed devices. Workload ResilienceVMware Cloud offers many of the same resilience features found in local cloud versions of vSphere and Cloud Foundation. Parent topic: Endpoint and Workload Security for Azure VMware Solution