Broadcom has announced new versions of VMware vDefend and VMware Avi Load Balancer, expanding the security capabilities of VMware Cloud Foundation (VCF) 9.1. The updates range from fully on-premises malware prevention and support for air-gapped environments to API protection, enhanced distributed firewall performance, and new AI tools to assist with network and security operations.
Your quick overview of VMware vDefend and Avi Load Balancer in 20 seconds
- vDefend now includes complete on-premises malware prevention and full support for air-gapped environments.
- Avi adds native API protection for virtual machines, Kubernetes, and AI workloads.
- The distributed firewall reaches up to 75 Gbps per server with 100 GbE interfaces, according to Broadcom.
- The distributed IDPS offers up to 17 Gbps per server.
- vDefend and Avi incorporate an AI assistant for diagnosis and operations.
These enhancements are included with vDefend SSP 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4, and vACT 3.0, compatible with VMware Cloud Foundation 9.1. Beyond performance metrics, Broadcom emphasizes an increasingly important aspect for organizations managing critical private cloud infrastructure: the ability to deploy multiple security layers without relying solely on external services.
The company also connects these updates to the growth of AI workloads and the increasing use of APIs, although some references to threats related to “frontier AI” are part of Broadcom’s marketing positioning and should not be interpreted as a separate technical vulnerability category.
vDefend extends malware protection to the local environment
One of the most significant changes for sysadmins involves vDefend Security Services Platform (SSP).
Broadcom asserts that all vDefend capabilities can now operate completely on-premises. This includes malware sandboxing, enabling static and dynamic analysis of files within the infrastructure without sending samples to cloud services.
This feature is especially relevant for organizations with strict data residency requirements, industrial networks, public administrations, defense sectors, or facilities that do not permit certain systems direct Internet access.
Support now extends specifically to air-gapped environments—networks deliberately isolated from external systems.
Broadcom has developed a mechanism to provide threat intelligence updates offline. Thus, air-gapped installations can update their detection data without establishing a permanent connection to cloud services.
A new feature called vDefend 1-2-3 for Advanced Threat Prevention (ATP) offers a guided, three-stage deployment workflow designed to simplify the deployment of advanced threat prevention functions.
This tool works in conjunction with the Distributed Firewall (DFW) and uses workload visibility to display security status, recommend rules, and guide configuration.
Broadcom claims this approach can reduce deployment times from months to just a few weeks, depending on the complexity of each infrastructure.
Enhanced performance for distributed firewalls and IDPS
These updates also improve the performance of security functions running in a distributed manner within VMware Cloud Foundation.
Based on Broadcom’s testing, vDefend Distributed Firewall can reach up to 22 Gbps per server equipped with 25 GbE interfaces, representing up to a 129% increase over previous reference performance.
For servers with 100 GbE interfaces, maximum throughput is announced at 75 Gbps, up from earlier benchmarks, an increase of up to 241%.
When scaling the architecture, Broadcom mentions capabilities of up to 75 Tbps of distributed firewall capacity per VCF instance.
The distributed Intrusion Detection and Prevention System (IDPS) also sees performance improvements. The maximum throughput is now up to 17 Gbps per server, an 89% increase, and can handle up to 17 Tbps aggregated per VCF instance.
One application of this IDPS is virtual patching.
Instead of waiting solely for official patches, certain rules can block traffic attempting to exploit known vulnerabilities at the virtualization layer. This provides a temporary mitigation measure until the security update is applied.
Broadcom has also reduced the minimum infrastructure requirements for SSP via a new two-node configuration, which can lower the necessary physical hardware by up to 33% compared to the previous architecture.
Avi Load Balancer adds API protection
Another key aspect of this update is VMware Avi Load Balancer.
APIs are now ubiquitous in distributed applications, microservices, and AI platforms. An insecure or misconfigured API can expose internal data and functions that should remain protected.
Avi now offers native API protection for virtual machines, vSphere Kubernetes Services (VKS), and AI workloads.
This security feature integrates with Web Application Firewall (WAF) within a WAAP (Web Application and API Protection) framework, combining web and API security measures.
Broadcom’s goal is to have a single layer overseeing and securing this traffic, avoiding the need to deploy multiple separate tools for load balancing, WAF, and API protection.
Performance of the load balancer itself is also improved, with announced maximums of 12.25 Tbps per controller instance, up to 88% higher than previous benchmarks.
Note that these are maximum theoretical figures from the manufacturer; actual performance will depend on hardware, configuration, traffic types, and security features enabled.
AI integration in managing vDefend and Avi
Broadcom is also introducing an AI Assistant feature within both vDefend Distributed Firewall and Avi Load Balancer.
This is not intended to replace application security with a new AI-driven detection method but to assist administrators with operational tasks.
The AI Assistant can provide contextual information, aid in troubleshooting, and support remediation and configuration workflows. Broadcom aims to reduce manual workload in environments combining virtualization, security, networking, and load balancing.
Additionally, the company has updated vDefend and Avi Conversion Tool (vACT).
Version 3.0 automates some migration processes from traditional agent-based firewall solutions to vDefend Distributed Firewall. This feature could be valuable for organizations consolidating multiple security tools within VMware Cloud Foundation, though the complexity of any migration will depend on existing rules, applications, and architecture.
All these updates reflect Broadcom’s vision for security within VCF: bringing controls closer to workloads and distributing security functions across the virtualized infrastructure.
This approach enables lateral segmentation, intrusion detection, and mitigation near virtual machines and containers, while Avi handles web and API traffic, which are particularly exposed areas.
For sysadmins, another important aspect is Broadcom’s effort to ensure these capabilities work in both large-scale connected deployments and fully on-premises private clouds and isolated networks, scenarios where external security consoles or cloud services might be impractical.
Frequently Asked Questions
What versions include these new VMware vDefend features?
The updates are available via vDefend SSP 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4, and vACT 3.0. Broadcom states these are compatible with VMware Cloud Foundation 9.1.
Can vDefend operate offline?
Broadcom confirms that all vDefend capabilities now support fully air-gapped environments, including offline mechanisms for updating threat intelligence.
What is virtual patching in vDefend?
It uses the distributed IDPS to block exploitation attempts of certain vulnerabilities within the virtualized infrastructure. It’s a temporary mitigation and does not replace applying official security patches.
What does Avi WAAP protect?
It combines Web Application Firewall and API protection. Broadcom has expanded this capability to cover APIs used by virtual machines, vSphere Kubernetes Services, and AI workloads.

