SlideShare a Scribd company logo
1 of 12
Download to read offline
SOFTWARE-BASED
NETWORKING & SECURITY
    FOR THE CLOUD

     Jae Lee, Director of Product Management
WHY USE CLOUD SERVICES?



No CAPEX, low operational cost


Fast, flexible, elastic


You can focus on business




                                                2
WHY OFFER CLOUD SERVICES?



Significant increase in demand


Faster time-to-market for new services


Higher value = greater revenue




                                             3
CLOUD NETWORKING CHALLENGES



Hardware limitations – cost, inflexibility
Scale services
Minimize latency
Connect securely to DC
Maintain security policy and compliance
Decrease complexity
Automate provisioning

                                             4
STEP 1: VIRTUALIZE



                                               BORDER ROUTER




                                                FIREWALL

                                                VPN

                                                INTRUSION PREVENTION


                                            SWITCH
                                                                       10.0.0.0/24

                                                                          WEBSERVERS




                                                                       10.3.0.0/24


                                                                        APPS & STORAGE



ENTERPRISE DATACENTER                                                  10.4.0.0/24
- UNDER-UTILIZED HARDWARE
                                                                          DATABASE
- NO AUTOMATION IN NETWORK MAINTENANCE

- EXPENSIVE TO SCALE

- HARD LIMITATIONS FORCE OVERPROVISIONING




                                                                                         5
VIRTUALIZATION STALL

                                       Web Servers                     Applications                        Database




                                                     VLAN2     VLAN1                  VLAN2        VLAN1              VLAN2
                               VLAN1



                     vSWITCH
                                                Hypervisor 1                   Hypervisor 2                       Hypervisor 3




System                                                                                                                ACCESS

                                                                                  SWITCH
Network

                                                                                                           AGGREGATION

                                                                                       SWITCH



                                                                                        FIREWALL
 LEGACY VIRTUAL DATACENTER
                                                                                                                        CORE
 - LATENCY

 - NO PROTECTION BETWEEN VLANS                                                          BORDER ROUTER

 - NOT SCALABLE

 - HARDWARE FIREWALL COSTS

 - REQUIRES NETWORK ADMIN TO INSTALL / SCALE




                                                                                                                                 6
IN-HYPERVISOR NETWORK SECURITY

                                  Web Servers                    Applications                              Database




                                          VLAN2
                                                         VLAN1                  VLAN2           VLAN1                 VLAN2
                          VLAN1




                             vNIC                           vNIC                                    vNIC

                vSWITCH
                                          Hypervisor 1                 Hypervisor 2                             Hypervisor 3




System                                                                                                                ACCESS
                                                                                           10.0.0.0/12
                                                                                SWITCH
Network


VIRTUAL DATACENTER W/ VIRTUAL APPLIANCE
ALL TRAFFIC IS INSPECTED WITHIN HYPERVISOR                                      SWITCH

- FIREWALL PROTECTS ALL TRAFFIC DIRECTIONS
               AGGREGA
                TION
 ELIMINATES LATENCY                                                             FIREWALL

 INTER-VLAN TRAFFIC INSPECTION
                                                                                BORDER ROUTER
- PER-TENANT DEDICATED NETWORK CONTROLS

 PROVISIONED ON DEMAND




                                                                                                                               7
APPLICATION ON-BOARDING


                                  Data Center                           Cloud Environment



               VM
                                                                                            App Servers   Web Servers   Database Servers
                                         VM
               VM                                   Application
                           VM                       Workload                                   VM            VM               VM
                                         VM

                           VM                                                                  VM            VM               VM

                                                                                               VM            VM               VM
               VM   Other Tools                                   WAN
               VM   TestDev
                                                                                                            vSwitch
               VM   VM Management                                                                         Hypervisor

               VM   VDI




      VM             VM
Active Directory     DNS                        Vyatta                           Vyatta
                                                                                          L2 GRE Tunnel
                                                                                                +
                                                                                   IPSec VPN or OpenVPN (SSL)




                                                                                                                                           8
APPLICATION ON-BOARDING


                                        Enterprise Data Center         Cloud Environment




                                                                                                                                  VM
                                                                                                                        VM
                                                                                                                VM
                                                                                             Database Tier


                                                                       Compliance /
                                                                                         Application Tier
                                                                       Trust Model
                                                                        Preserved                                            Web Services Tier
                                                                                             VM

                                                                                                                                    VM
                                                                                             VM

                     VM   Other Tools                                                                                               VM
                                                                 WAN                         VM

                     VM   TestDev                                                                                                   VM
Physical                                                                                                      vSwitch
 N-Tier              VM   VM Management
                                                                                                             Hypervisor
                     VM   VDI




            VM             VM
      Active Directory     DNS                       Vyatta                     Vyatta
                                                                                         L2 GRE Tunnel
                                                                                               +
                                                                                  IPSec VPN or OpenVPN (SSL)




                                                                                                                                                 9
LEVERAGING AMAZON



                              VPN
                              Cloud Bridge
                s             NAT + Firewall
              er
            rv
        Se



                                                                                             Remote Workers
     eb
 W




                    Public


                                                                                              Enterprise Datacenter
                                                      Internet
      Vyatta AMI                                                                               VM   VM
                                      VPC
               s
             er




                                                                                               VM   VM
                                      Internet
           rv
        Se




                                      Gateway                                                       V
        e




                                                                                               VM
                                                                                                    M
    bas
 ta




                    Private
Da




                                                                                              Private or Public Cloud




                                VYATTA AMI – COMPLETE NETWORKING IN AMAZON VPC
                                                               AGGREGAT
                                - NO LIMIT TO # OF VPN TUNNELS
                                                               ION
                                - SECURELY CONNECT INTO MULTIPLE VPCs FROM A SINGLE

                                - CREATE FULL VPN MESH BETWEEN MULTIPLE VPCs

                                - SECURELY BRIDGE CLOUD TO CLOUD OR DATACENTER TO CLOUD

                                - SINGLE INTEGRATED PACKAGE OF FW, VPN, IPS, URL FILTERING, FULL LAYER 3


                                                                                                                        10
Vyatta Enterprise With Vyatta



            ROUTER
            FIREWALL
            VPN
            IPS




   SWITCH
                             10.0.0.0/24

                                   WEBSERVERS




                              10.3.0.0/24


                                 APPS & STORAGE

                             10.3.0.0/24
                  VYATTA ENTERPRISE DATACENTER
                         10.4.0.0/24
                  NETWORK EDGE AND LAN COMPRISED OF STANDARD x86-
                  BASED SYSTEMS APPS & STORAGE
                                and VYATTA SOFTWARE

                  - LEVERAGE STANDARD x86 SERVER HARDWARE
                                    DATABASE
                  - MODERN QUAD CORE + SYSTEMS DELIVER 10Gbps
                  PERFORMANCE 10.4.0.0/24
                  - SYSTEM SCALABILITY USING STANDARD COMPONENTS
                  - SOFTWARE – BASED UPGRADE PATH
                  - COST A FRACTION OF COMPARABLE CISCO / JNPR GEAR
                                  DATABASE



                                                                      11
12

More Related Content

What's hot

Meraki Cloud Wireless Lan
Meraki Cloud Wireless LanMeraki Cloud Wireless Lan
Meraki Cloud Wireless LanChikPea
 
Brocade/VMware Customer Presentation
Brocade/VMware Customer Presentation Brocade/VMware Customer Presentation
Brocade/VMware Customer Presentation Brocade
 
Meraki Solution Overview
Meraki Solution OverviewMeraki Solution Overview
Meraki Solution OverviewClaudiu Sandor
 
Motorola Wing 5.6 specification sheet
Motorola  Wing 5.6 specification sheetMotorola  Wing 5.6 specification sheet
Motorola Wing 5.6 specification sheetAdvantec Distribution
 
WiMAX Network Security
WiMAX Network SecurityWiMAX Network Security
WiMAX Network Securitysashar86
 
Juniper Networks SRX Branch Solutions
Juniper Networks SRX Branch SolutionsJuniper Networks SRX Branch Solutions
Juniper Networks SRX Branch SolutionsAltaware, Inc.
 
POE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048P
POE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048PPOE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048P
POE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048Pjuet-y
 
Indian railways presentation
Indian railways presentationIndian railways presentation
Indian railways presentationgps2012
 
Integration of pola alto and v mware nsx to protect virtual and cloud environ...
Integration of pola alto and v mware nsx to protect virtual and cloud environ...Integration of pola alto and v mware nsx to protect virtual and cloud environ...
Integration of pola alto and v mware nsx to protect virtual and cloud environ...David kankam
 
Hosted Solutions Hi-Touch Services Guide
Hosted Solutions Hi-Touch Services GuideHosted Solutions Hi-Touch Services Guide
Hosted Solutions Hi-Touch Services GuideHosted Solutions
 

What's hot (16)

Meraki Cloud Wireless Lan
Meraki Cloud Wireless LanMeraki Cloud Wireless Lan
Meraki Cloud Wireless Lan
 
Brocade/VMware Customer Presentation
Brocade/VMware Customer Presentation Brocade/VMware Customer Presentation
Brocade/VMware Customer Presentation
 
Nx9000 spec sheet
Nx9000 spec sheetNx9000 spec sheet
Nx9000 spec sheet
 
1000281 en 2
1000281 en 21000281 en 2
1000281 en 2
 
Meraki Solution Overview
Meraki Solution OverviewMeraki Solution Overview
Meraki Solution Overview
 
Motorola Wing 5.6 specification sheet
Motorola  Wing 5.6 specification sheetMotorola  Wing 5.6 specification sheet
Motorola Wing 5.6 specification sheet
 
TFI2014 Session I - State of SDN - Gary Hemminger
TFI2014 Session I - State of SDN - Gary HemmingerTFI2014 Session I - State of SDN - Gary Hemminger
TFI2014 Session I - State of SDN - Gary Hemminger
 
WiMAX Network Security
WiMAX Network SecurityWiMAX Network Security
WiMAX Network Security
 
Cisco1000v Net Optics Solution Brief
Cisco1000v Net Optics Solution BriefCisco1000v Net Optics Solution Brief
Cisco1000v Net Optics Solution Brief
 
Wimax security
Wimax securityWimax security
Wimax security
 
Juniper Networks SRX Branch Solutions
Juniper Networks SRX Branch SolutionsJuniper Networks SRX Branch Solutions
Juniper Networks SRX Branch Solutions
 
POE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048P
POE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048PPOE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048P
POE+ L2 switches HPE FlexNetwork 5130 vs Dell Networking N2048P
 
Indian railways presentation
Indian railways presentationIndian railways presentation
Indian railways presentation
 
Wajahat Hussain cv
Wajahat Hussain cvWajahat Hussain cv
Wajahat Hussain cv
 
Integration of pola alto and v mware nsx to protect virtual and cloud environ...
Integration of pola alto and v mware nsx to protect virtual and cloud environ...Integration of pola alto and v mware nsx to protect virtual and cloud environ...
Integration of pola alto and v mware nsx to protect virtual and cloud environ...
 
Hosted Solutions Hi-Touch Services Guide
Hosted Solutions Hi-Touch Services GuideHosted Solutions Hi-Touch Services Guide
Hosted Solutions Hi-Touch Services Guide
 

Similar to Software-Based Networking & Security for the Cloud

Policy Based SDN Solution for DC and Branch Office by Suresh Boddapati
Policy Based SDN Solution for DC and Branch Office by Suresh BoddapatiPolicy Based SDN Solution for DC and Branch Office by Suresh Boddapati
Policy Based SDN Solution for DC and Branch Office by Suresh Boddapatibuildacloud
 
MassTLC Cloud summit keynote presentation from CTO of VMWare, Scott Davis
MassTLC Cloud summit keynote presentation from CTO of VMWare, Scott DavisMassTLC Cloud summit keynote presentation from CTO of VMWare, Scott Davis
MassTLC Cloud summit keynote presentation from CTO of VMWare, Scott DavisMassTLC
 
Alcatellucentsdn2013
Alcatellucentsdn2013Alcatellucentsdn2013
Alcatellucentsdn2013deepersnet
 
VMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use casesVMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use casesAngel Villar Garea
 
Cisco Virtualized Network Services
Cisco Virtualized Network ServicesCisco Virtualized Network Services
Cisco Virtualized Network ServicesSoumen Chatterjee
 
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...Ixia
 
Cisco nexus 1000v
Cisco nexus 1000vCisco nexus 1000v
Cisco nexus 1000vikewu83
 
[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With ContrailOpenStack Korea Community
 
Cisco vWaaS talk
Cisco vWaaS talkCisco vWaaS talk
Cisco vWaaS talkramdurairaj
 
Virtualization presentation
Virtualization presentationVirtualization presentation
Virtualization presentationMangesh Gunjal
 
Cloud Computing, SDN, Big Data and Internet of Everything - Lew Tucker
Cloud Computing, SDN, Big Data and Internet of Everything - Lew TuckerCloud Computing, SDN, Big Data and Internet of Everything - Lew Tucker
Cloud Computing, SDN, Big Data and Internet of Everything - Lew TuckerLew Tucker
 
Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...
Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...
Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...CloudOps Summit
 
CNISP - Platform Introduction 071511pks
CNISP - Platform Introduction 071511pksCNISP - Platform Introduction 071511pks
CNISP - Platform Introduction 071511pkslucpaquin
 
Vmware Seminar Security & Compliance for the cloud with Trend Micro
Vmware Seminar Security & Compliance for the cloud with Trend MicroVmware Seminar Security & Compliance for the cloud with Trend Micro
Vmware Seminar Security & Compliance for the cloud with Trend MicroGraeme Wood
 
Vss Security And Compliance For The Cloud
Vss Security And Compliance For The CloudVss Security And Compliance For The Cloud
Vss Security And Compliance For The CloudGraeme Wood
 
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'OpenStack Korea Community
 
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...VMworld
 
Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...
Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...
Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...Nuage Networks
 

Similar to Software-Based Networking & Security for the Cloud (20)

Policy Based SDN Solution for DC and Branch Office by Suresh Boddapati
Policy Based SDN Solution for DC and Branch Office by Suresh BoddapatiPolicy Based SDN Solution for DC and Branch Office by Suresh Boddapati
Policy Based SDN Solution for DC and Branch Office by Suresh Boddapati
 
MassTLC Cloud summit keynote presentation from CTO of VMWare, Scott Davis
MassTLC Cloud summit keynote presentation from CTO of VMWare, Scott DavisMassTLC Cloud summit keynote presentation from CTO of VMWare, Scott Davis
MassTLC Cloud summit keynote presentation from CTO of VMWare, Scott Davis
 
Alcatellucentsdn2013
Alcatellucentsdn2013Alcatellucentsdn2013
Alcatellucentsdn2013
 
VMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use casesVMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use cases
 
Contrail Enabler for agile cloud services
Contrail Enabler for agile cloud servicesContrail Enabler for agile cloud services
Contrail Enabler for agile cloud services
 
Cisco Virtualized Network Services
Cisco Virtualized Network ServicesCisco Virtualized Network Services
Cisco Virtualized Network Services
 
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
 
Cisco nexus 1000v
Cisco nexus 1000vCisco nexus 1000v
Cisco nexus 1000v
 
[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail
 
Cisco vWaaS talk
Cisco vWaaS talkCisco vWaaS talk
Cisco vWaaS talk
 
What is a virtual tap?
What is a virtual tap?What is a virtual tap?
What is a virtual tap?
 
Virtualization presentation
Virtualization presentationVirtualization presentation
Virtualization presentation
 
Cloud Computing, SDN, Big Data and Internet of Everything - Lew Tucker
Cloud Computing, SDN, Big Data and Internet of Everything - Lew TuckerCloud Computing, SDN, Big Data and Internet of Everything - Lew Tucker
Cloud Computing, SDN, Big Data and Internet of Everything - Lew Tucker
 
Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...
Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...
Windows Azure: Verbinden, erweitern, integrieren Sie ihr Firmennetzwerk in di...
 
CNISP - Platform Introduction 071511pks
CNISP - Platform Introduction 071511pksCNISP - Platform Introduction 071511pks
CNISP - Platform Introduction 071511pks
 
Vmware Seminar Security & Compliance for the cloud with Trend Micro
Vmware Seminar Security & Compliance for the cloud with Trend MicroVmware Seminar Security & Compliance for the cloud with Trend Micro
Vmware Seminar Security & Compliance for the cloud with Trend Micro
 
Vss Security And Compliance For The Cloud
Vss Security And Compliance For The CloudVss Security And Compliance For The Cloud
Vss Security And Compliance For The Cloud
 
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
 
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
 
Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...
Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...
Nuage Networks: Delivering Datacenter Networks As Consumable as Computee_scot...
 

Recently uploaded

Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 

Recently uploaded (20)

DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 

Software-Based Networking & Security for the Cloud

  • 1. SOFTWARE-BASED NETWORKING & SECURITY FOR THE CLOUD Jae Lee, Director of Product Management
  • 2. WHY USE CLOUD SERVICES? No CAPEX, low operational cost Fast, flexible, elastic You can focus on business 2
  • 3. WHY OFFER CLOUD SERVICES? Significant increase in demand Faster time-to-market for new services Higher value = greater revenue 3
  • 4. CLOUD NETWORKING CHALLENGES Hardware limitations – cost, inflexibility Scale services Minimize latency Connect securely to DC Maintain security policy and compliance Decrease complexity Automate provisioning 4
  • 5. STEP 1: VIRTUALIZE BORDER ROUTER FIREWALL VPN INTRUSION PREVENTION SWITCH 10.0.0.0/24 WEBSERVERS 10.3.0.0/24 APPS & STORAGE ENTERPRISE DATACENTER 10.4.0.0/24 - UNDER-UTILIZED HARDWARE DATABASE - NO AUTOMATION IN NETWORK MAINTENANCE - EXPENSIVE TO SCALE - HARD LIMITATIONS FORCE OVERPROVISIONING 5
  • 6. VIRTUALIZATION STALL Web Servers Applications Database VLAN2 VLAN1 VLAN2 VLAN1 VLAN2 VLAN1 vSWITCH Hypervisor 1 Hypervisor 2 Hypervisor 3 System ACCESS SWITCH Network AGGREGATION SWITCH FIREWALL LEGACY VIRTUAL DATACENTER CORE - LATENCY - NO PROTECTION BETWEEN VLANS BORDER ROUTER - NOT SCALABLE - HARDWARE FIREWALL COSTS - REQUIRES NETWORK ADMIN TO INSTALL / SCALE 6
  • 7. IN-HYPERVISOR NETWORK SECURITY Web Servers Applications Database VLAN2 VLAN1 VLAN2 VLAN1 VLAN2 VLAN1 vNIC vNIC vNIC vSWITCH Hypervisor 1 Hypervisor 2 Hypervisor 3 System ACCESS 10.0.0.0/12 SWITCH Network VIRTUAL DATACENTER W/ VIRTUAL APPLIANCE ALL TRAFFIC IS INSPECTED WITHIN HYPERVISOR SWITCH - FIREWALL PROTECTS ALL TRAFFIC DIRECTIONS AGGREGA TION ELIMINATES LATENCY FIREWALL INTER-VLAN TRAFFIC INSPECTION BORDER ROUTER - PER-TENANT DEDICATED NETWORK CONTROLS PROVISIONED ON DEMAND 7
  • 8. APPLICATION ON-BOARDING Data Center Cloud Environment VM App Servers Web Servers Database Servers VM VM Application VM Workload VM VM VM VM VM VM VM VM VM VM VM VM Other Tools WAN VM TestDev vSwitch VM VM Management Hypervisor VM VDI VM VM Active Directory DNS Vyatta Vyatta L2 GRE Tunnel + IPSec VPN or OpenVPN (SSL) 8
  • 9. APPLICATION ON-BOARDING Enterprise Data Center Cloud Environment VM VM VM Database Tier Compliance / Application Tier Trust Model Preserved Web Services Tier VM VM VM VM Other Tools VM WAN VM VM TestDev VM Physical vSwitch N-Tier VM VM Management Hypervisor VM VDI VM VM Active Directory DNS Vyatta Vyatta L2 GRE Tunnel + IPSec VPN or OpenVPN (SSL) 9
  • 10. LEVERAGING AMAZON VPN Cloud Bridge s NAT + Firewall er rv Se Remote Workers eb W Public Enterprise Datacenter Internet Vyatta AMI VM VM VPC s er VM VM Internet rv Se Gateway V e VM M bas ta Private Da Private or Public Cloud VYATTA AMI – COMPLETE NETWORKING IN AMAZON VPC AGGREGAT - NO LIMIT TO # OF VPN TUNNELS ION - SECURELY CONNECT INTO MULTIPLE VPCs FROM A SINGLE - CREATE FULL VPN MESH BETWEEN MULTIPLE VPCs - SECURELY BRIDGE CLOUD TO CLOUD OR DATACENTER TO CLOUD - SINGLE INTEGRATED PACKAGE OF FW, VPN, IPS, URL FILTERING, FULL LAYER 3 10
  • 11. Vyatta Enterprise With Vyatta ROUTER FIREWALL VPN IPS SWITCH 10.0.0.0/24 WEBSERVERS 10.3.0.0/24 APPS & STORAGE 10.3.0.0/24 VYATTA ENTERPRISE DATACENTER 10.4.0.0/24 NETWORK EDGE AND LAN COMPRISED OF STANDARD x86- BASED SYSTEMS APPS & STORAGE and VYATTA SOFTWARE - LEVERAGE STANDARD x86 SERVER HARDWARE DATABASE - MODERN QUAD CORE + SYSTEMS DELIVER 10Gbps PERFORMANCE 10.4.0.0/24 - SYSTEM SCALABILITY USING STANDARD COMPONENTS - SOFTWARE – BASED UPGRADE PATH - COST A FRACTION OF COMPARABLE CISCO / JNPR GEAR DATABASE 11
  • 12. 12