What Is Nutanix Flow?
Nutanix Flow (now consisting of Flow Virtual Networking and Flow Network Security) is a software-defined networking and security solution native to the Nutanix Cloud Platform. It abstracts networking and microsegmentation from physical hardware, protecting virtual machines (VMs) and applications across on-premises and hybrid cloud environments.
Nutanix Flow is divided into two primary capabilities:
- Flow Network Security (FNS): Provides application-centric microsegmentation and distributed firewalling to prevent lateral movement of threats and ransomware. It relies on plain-language, logical grouping of VMs (using categories) rather than IP addresses or VLANs, meaning security policies follow workloads dynamically.
- Flow Virtual Networking (FVN): Delivers overlay networking capabilities, allowing administrators to create software-defined Virtual Private Clouds (VPCs), subnets, routing, and VPNs across edge, on-premise, and public cloud sites without complex physical network changes.
Flow integrates seamlessly with Nutanix Prism Central, providing a centralized interface for managing and orchestrating network security policies, network overlays, and automation workflows. The solution is designed to address modern data center requirements, offering scalable and simplified network security for both traditional and cloud-native workloads.
Key Nutanix Flow Features
Application-Centric Microsegmentation
Nutanix Flow’s microsegmentation capability allows organizations to isolate workloads at the application level, enforcing granular security policies between virtual machines (VMs) and applications. This approach ensures that only authorized traffic is allowed between specific application components, reducing the risk of lateral movement within the data center. Administrators can define policies based on application identity, tags, or other contextual attributes, enabling a security posture that adapts as applications scale or change.
By focusing on application-centric policies rather than static network constructs like VLANs or subnets, Nutanix Flow simplifies the process of segmenting and securing workloads. This supports zero-trust security models, where trust boundaries are enforced at the smallest logical unit. The result is improved threat containment and incident response, without the complexity of managing traditional firewall rules or network ACLs.
Related content: Read our guide to network microsegmentation in data centers
Virtual Private Clouds and Overlay Networking
Nutanix Flow enables the creation of virtual private clouds (VPCs) within the Nutanix environment using overlay networking technologies. These VPCs allow organizations to logically separate workloads and applications, regardless of the underlying physical network topology. Overlay networks use tunneling protocols to encapsulate traffic, enabling network segmentation that is decoupled from physical switches and routers.
This overlay approach allows administrators to provision isolated environments with their own IP address spaces and security policies. It also supports hybrid and multi-cloud strategies by extending network topologies across on-premises and cloud infrastructure. Nutanix Flow’s overlay networking capabilities reduce operational complexity for new projects and initiatives.
Multi-Tenant Network Isolation
Nutanix Flow supports multi-tenancy, providing network isolation for environments where multiple users or business units share the same infrastructure. Each tenant can have its own dedicated VPC, with separate network policies, security rules, and address spaces. This ensures that traffic and resources are separated, preventing accidental or malicious access between tenants.
Network isolation is important for service providers, managed hosting environments, and enterprises running multiple business applications on shared clusters. Nutanix Flow’s multi-tenant capabilities help organizations maintain compliance with regulatory requirements and internal security policies. It also allows administrators to delegate network control and monitoring responsibilities to different tenant owners or teams, reducing the risk of misconfiguration.
Automated Network Provisioning
Nutanix Flow automates the creation, configuration, and management of network resources. Using policy-driven templates and orchestration workflows, administrators can deploy network topologies and security policies without manual intervention. This reduces configuration errors and shortens the time required to roll out new applications or services.
Automation extends to policy enforcement, where changes to virtual machine placements or application structures automatically trigger updates to network segmentation and security rules. This ensures that the network remains consistent with organizational intent, even as workloads scale or migrate across the environment. Nutanix Flow’s automation capabilities allow IT staff to focus on higher-value activities.
Centralized Management Through Prism Central
All Nutanix Flow capabilities are managed through Prism Central, Nutanix’s unified management plane. This interface provides a single point of control for deploying, monitoring, and updating network security policies, overlays, and segmentation rules across the Nutanix environment. Administrators benefit from consistent workflows, real-time visibility, and simplified troubleshooting.
Prism Central also offers analytics and reporting for network traffic, policy compliance, and security events. This visibility helps organizations identify risks, audit changes, and demonstrate compliance with industry standards. By consolidating network management with the broader Nutanix infrastructure stack, Flow integrates network security with compute, storage, and virtualization operations.
Nutanix Flow Main Capabilities
Flow Network Security (FNS)
Flow Network Security (FNS) provides software-defined firewalls that protect applications and data across multicloud environments without requiring dedicated security hardware. Instead of relying on network topology, it uses application-centric policies that reflect application intent, making security policies easier to manage. Granular traffic controls limit communication between applications, while dynamic policy enforcement ensures protections remain in place as workloads move across the environment.
FNS provides visibility into traffic flows down to the port level:
- This visibility supports least-privilege access policies, validation of application behavior, and identification of unexpected communication patterns that may indicate security issues.
- A centralized dashboard provides policy-driven visibility into application communications and overall security posture.
The platform strengthens endpoint and workload protection by combining identity-based access controls with microsegmentation. Directory-based user identities can control access to workloads and data, while microsegmentation limits the spread of malware and ransomware by restricting lateral movement. This approach removes dependence on static network constructs that are difficult to maintain in environments where workloads frequently move.
FNS also supports compliance by enabling organizations to segment applications and data without redesigning the physical network. Features such as ring fencing, standardized policy deployment, and audit reporting help organizations enforce security controls and produce audit evidence with less manual effort. Network-level segmentation can be enforced using ports and protocols, with optional Layer 7 inspection available through partner integrations.
Flow Virtual Networking (FVN)
Flow Virtual Networking (FVN) is Nutanix’s software-defined networking (SDN) solution for creating and managing virtual private clouds (VPCs) across on-premises and public cloud environments. It brings cloud-style networking to Nutanix infrastructure by allowing organizations to build isolated virtual networks in software, without redesigning existing networks or relying on dedicated hardware segmentation. FVN:
- Provides consistent APIs and management workflows across environments.
- Supports networks that span multiple clusters.
- Can coexist with existing VLANs, including one-click migration from VLAN-based networks to VPCs.
A core capability of FVN is VPC networking, which gives administrators control over IP address ranges, subnets, routing, and gateways. Organizations can create isolated network environments with overlapping IP address spaces for different tenants, making it suitable for multi-tenant deployments. Self-service provisioning enables teams to deploy new VPCs on demand, while a centralized dashboard simplifies management.
FVN automates connectivity between VPCs running in local data centers, disaster recovery sites, and public cloud environments. Integration with Nutanix Cloud Clusters (NC2) provides native networking between on-premises infrastructure and public clouds such as AWS and Azure, allowing organizations to establish secure connections between distributed environments without extensive manual configuration.
The platform also includes network policy and connectivity services that support hybrid networking:
- Administrators can configure stateless access control policies to manage traffic between workloads, subnets, and external networks, and integrate partner security services such as next-generation firewalls, intrusion detection systems, and web application firewalls.
- Built-in NAT and VPN capabilities enable communication between private and public cloud networks and allow multi-tenant VPCs with overlapping IP addresses to communicate without address conflicts.