NetApp ONTAP VScan Technology

Where I used to come from VMware, it build an ecosystem of integration with its vendors. And have a massive interops from compute, storage and network. It does this through an extensive API within its full software stack.

When I joined NetApp earlier this year, NetApp have a Cyber Resilience Partner Ecosystem surrounding data. One of the category is Virus Detection. This was made possible with ONTAP Vscan technology which is a proprietary to NetApp. Which also means, not all AV vendor can just integrate. They need to be using ONTAP Vscan technology for that integration. 


Now the questions is won't that made it less compiling? Maybe, but for the sake of security, this is needed. Why do I say so?

Generally on the market, storage vendors all have integration to AV vendors in some way, However, most choose the "easy way out". They leverage on ICAP (Internet Content Adaptation Protocol). As ICAP is a generic protocol, it can be easily utilized. However, one issue with ICAP is, it is not filtered. Which means it requires additional network traffic sending information whether needed or not for the integration. This can affect performance and latency. Why do you need unneeded data?

And since it utilize ICAP, ICAP will require an additional server as a proxy. Which also results in higher compute resources when demand increases, especially when it scales, the additional traffic will be very demanding. This also due to the unnecessary data sent.

On security, ICAP sends the exact files to the ICAP server. Which means while protecting against virus, we just introduce a new exposure of security vulnerability.

ONTAP Vscan since its native part of the ONTAP system, everything happens within the storage without sending any traffic across the network. There is a ONTAP Antivirus Connector, to handle the request between the AV server and NetApp storage. This not only make it easy to enable but also help to scale much more easily without the complexity.

Here is a short writeup on how ONTAP Vscan works.

In summary, NetApp has been the most secure storage on the planet for a reason. Taking security at it's utmost priority to ensure purposefully addressing the needs instead of fufilling a check box.

Comments

Popular posts from this blog

Aria Operations Management Packs End of Life

VMware VCF Minimum Cores Purchases Changes

Unable to verify certificate for vCenter on Horizon View Connection Server