惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
aimingoo的专栏
aimingoo的专栏
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
IT之家
IT之家
V
Visual Studio Blog
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
大猫的无限游戏
大猫的无限游戏
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
D
Docker
MyScale Blog
MyScale Blog
小众软件
小众软件
云风的 BLOG
云风的 BLOG
美团技术团队
Microsoft Azure Blog
Microsoft Azure Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】

VMware Blogs

Diagnostics for VMware Cloud Foundation (VCF) 9.1 with Old Versions of VCF Components Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1 Modernizing the Private Cloud: Why VCF 9.1 Lifecycle Management is a Game Changer Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool VCF Breakroom Chats Episode 86 – Containers Made Easy: The New “Container-as-a-Service” in VCF 9.1 Securing Your VCF 9.1 Infrastructure with the Symantec Identity Security Platform Virtually Speaking: The AI Reality Check with Dave Linthicum Zero Touch Provisioning: Activating Edge Sites with VMware Cloud Foundation Edge 9.1 VCF Breakroom Chats Episode 85 – Cloning Success at Scale: Inside VCF 9.1’s App Stack Formation VMware Cloud on AWS の使用状況を確認できる API Unlocking the Full Potential of Programmable Infrastructure with VMware Cloud Foundation 9.1 – New Features and Capabilities Smarter Patching at Scale: Vulnerability Assessment and Remediation with VMware Tanzu Platform Encrypted vMotion Offload to Intel QAT in VMware Cloud Foundation 9.1 Deepen Your Expertise: Four Key Benefits of Attending Increase Deployment Flexibility with VCF Edge Automation 1.0.3 Avi Advantage: Automating Certificate Management of VCF Workloads More Memory, Less Effort: Configuring Memory Tiering in VCF 9.1 VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale Why APJ Networking Professionals Need Private Cloud Expertise VCF 9.1 Networking: Exploring Network Services for Virtual Private Clouds VCF Networking 9.1: Seamless DDI Integration with Infoblox The Open Source Advantage: Building from Source for Ultimate Security Expand Shared VMDKs with Clustered Applications in VMware vSAN for VCF 9.1 Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend VMware vSAN Protection and Recovery Enhancements for VCF 9.1 Deliver Production SQL Server DBaaS with VMware Data Services Manager 9.1 Maximizing Profitability: VCF 9.1 Cost-Focused Approach for VMware Cloud Service Providers Modernizing Your Infrastructure: Introducing VMware Cloud Foundation 9.1 to VCSPs VCF 9.1 is Available: Explore the New Features in Hands-on Labs What’s New with vSphere in VMware Cloud Foundation 9.1?
VCF 9.1 Networking: Simpler VPC Connectivity Control
Dimitri Desmidt · 2026-05-16 · via VMware Blogs

VMware Cloud Foundation (VCF) provides a robust suite of self-service networking capabilities (as covered in our previous post: Network Services.

In this blog, we zoom in on a powerful new feature introduced in VCF 9.1: Connectivity Policy for Virtual Private Clouds (VPCs).

Note: This capability is available exclusively via the Advanced Cyber Compliance (ACC) Advanced Service add-on for VCF 9.1.
To learn more about what this add-on brings to your environment, check out our post Continuous Compliance, Integrated Cyber Recovery and Enhanced Platform Security for VCF 9.1.

Taking Control of Cross-VPC Communication

By default, applications in a VPC can communicate freely with other applications in other VPCs. Restricting this traffic used to mean relying on the vDefend Firewall Add-on.

Starting with VCF 9.1, you can natively manage cross-VPC communication using Connectivity Policy to your VPCs, and dictate their routing boundaries without any firewall.

The Three Connectivity Policies

VCF 9.1 introduces three distinct policy types to govern how your VPCs interact within a project:

  • Community: Group specific VPCs together under a shared community policy. Applications within these VPCs can communicate seamlessly with others in the exact same community, but are strictly isolated from any VPCs outside of it.
  • Promiscuous: VPCs assigned this policy act as open VPC. A promiscuous VPC is allowed to communicate with any other VPC in the project.
  • Isolated: VPCs in this group are highly restricted. An isolated VPC cannot communicate with other community VPCs; it can only communicate with VPCs designated as Promiscuous.

These connectivity policies provide a remarkably simple way to architect project environments.

For example, imagine you need a Shared Services VPC (housing DNS, Active Directory, or logging tools) that every application in their VPC needs to access, while keeping those isolated from one another.

You can simply set your Shared Services VPC to Promiscuous and set all the other VPCs to Isolated. You achieve perfect architectural isolation through simple grouping — no firewalling required.
And if you have a few applications in VPCs that need to communicate between each other, place these in a specific Community.

Summary

VCF 9.1 drastically streamlines cloud architecture by managing cross-VPC communication natively at the network level.

By eliminating the need to use firewall-based isolation for basic traffic boundaries, it keeps your VMware vDefend environment lean and your security operations highly efficient.

Seeing is believing!

Check out the quick demo below to watch these connectivity policies in action.
We will walk you through assigning Community policies to real VPCs, demonstrating exactly how simple it is to lock down your project traffic natively without touching a single firewall rule.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.