Challenges in Deploying Public Clouds

Size: px
Start display at page:

Download "Challenges in Deploying Public Clouds"

Transcription

1 WHITE PAPER Ensuring Enterprise-grade Network Services for AWS Infoblox DDI for AWS increases cloud agility, supports consistent network policies across hybrid deployments, and improves visibility of public and hybrid cloud workloads.

2 Summary According to Gartner, by 2017 more than 50 percent of enterprises will use a hybrid cloud which typically includes traditional networks, private cloud, and/or public cloud. Over the past few years, enterprises have rapidly been moving their workloads to public clouds such as Amazon Web Services (AWS) to reduce the time to deploy new applications, consolidate their IT infrastructures for better analytical insights into their business, or just reduce infrastructure costs with a pay-for-use model among other reasons. However, while public clouds provide agility benefits, enterprises still face major challenges in reducing the complexity of operationalizing network infrastructure for public cloud. Specifically, network services such as DNS and IP address management become complicated because the need to manage multiple non-integrated point tools often causes inconsistency across enterprise-wide policies. Infoblox has extended its enterprise-grade DNS and IP address management solution to Amazon Web Services EC2. Fully integrated with our industry-leading Infoblox Grid technology, the Infoblox solution for AWS increases cloud agility, supports consistent network policies across hybrid deployments, and improves visibility of public cloud workloads. Challenges in Deploying Public Clouds Too often, public cloud services are thought of as a one-off deployment, especially in today s world of shadow IT, where lines of business deploy services in a vacuum as a way to speed deployment. However, network architects for enterprises that deploy public clouds have to create a consistent, automated, and uniform corporate-wide network in which the public cloud is merely an extension of their enterprise network. Without a consolidated, consistent network infrastructure integrated with the public cloud, organizations will not receive all of the benefits including agility, visibility, and security. To deliver a consistent network infrastructure in AWS or other public cloud platforms, a number of challenges need to be addressed. Network and IP Address Management For most hybrid cloud deployments, network and cloud administrators use separate tools to manage on-premises and public cloud networks because they have no centralized network and IP address management. Therefore, they face challenges in planning and deploying uniform networks and IP addresses, which in turn leads to increases in configuration and troubleshooting time. Secondly, a lack of discovery and tracking for the cloud-based resources reduces network visibility to the infrastructure. Trying to discover, track, and document the network and IP address assignments of AWS instances is virtually impossible with manual processes. Add the complexity of decommissioning instances, and most IT organizations have out-of-date and incorrect tracking of cloud-based resources. 1 WHITE PAPER Ensuring Enterprise-grade Network Services for AWS

3 Visibility Enterprises need a high level of visibility into network, DNS, and IP address configurations for both their on-premises and AWS infrastructure. Too often, IT teams must try and cobble together disparate, non-integrated tools to monitor their network resources for planning purposes. For compliance and security requirements, enterprises must also be able to audit and report on the use of network resources both current resources as well as historical tracking for decommissioned instances. For example, an auditor might ask to find out what instances/applications were using an IP address in the past or when a security event occurred on that particular IP address. Without complete visibility, historical views, and automation, most organizations will not have sufficient documentation to answer this request. Enterprise-grade Network Services for AWS Infoblox has been the leader in enterprise-grade network services including DNS and IP address management. And now with Infoblox DDI for AWS, organizations can leverage the integrated platform for public or hybrid cloud deployments. Infoblox DDI for AWS helps solve the network challenges described in the following sections. Enterprise-grade DNS Infoblox extends enterprise DNS into the AWS cloud so organizations have a robust, consolidated platform across traditional networks and public/hybrid clouds. As part of the Infoblox platform, enterprises can deploy Infoblox appliances into the AWS cloud by leveraging the Amazon Machine Images (AMI) into their AWS virtual private clouds (VPCs). These virtualized appliances can join an existing Infoblox Grid residing on a business s premises, thus extending DNS functionality from across the enterprise into the AWS cloud. DATA CENTER PRIMARY DNS GRID MASTER (GM) Enterprise Premises AWS Public Cloud SECONDARY DNS GRID MASTER CANDIDATE SECONDARY DNS Figure 1: Extending the Infoblox Grid for AWS 2

4 Automated Provisioning of Network, IP Addresses, and DNS Infoblox has introduced an API proxy functionality for AWS that allows enterprises to control network and IP address allocations for VPCs. Enterprises can ensure that these resources are predictably allocated, allowing for consistent and effective planning, tracking, and management of networks, IP addresses, and DNS records throughout the enterprise. AWS API Client (e.g., Ansible, Puppet, Chef scripts, etc.) VPC ID Network IP VPC-DEV / AWS API Endpoint VPC VPC ID Network IP DNS Record VPC-DEV / dev1.internal.com Typical Workflow 1. API: Create EC2 instance in VPC-Dev for network /16 2. GM reserves next available IP in network /16 for VPC-Dev and inserts into API request 3. API: create EC2 Instance in VPC-Dev 4. EC2 instance spun up with in VPC-Dev 5. API Response: Success 6. GM updates host records for EC2 instance 7. API Response: Success Figure 2: Automated provisioning of network, IP addresses, and DNS records When a new VPC/subnet/EC2 instance is created using AWS APIs, as shown in Figure 2, these APIs are directed to the API proxy software that is running on Infoblox appliances. These VPCs/subnets are stored in Infoblox database. So the next time a user makes an API call to spin up new EC2 instance, the API proxy software injects the next available IP address and signs the API call with the appropriate AWS credentials before forwarding it to the AWS endpoint. If the API call is successful in spinning up new EC2 instance, a DNS record will be automatically created so end-users can access the EC2 instance with the FQDN (fully qualified domain name) that was just created. Since the Infoblox DNS server is configured as an authoritative DNS server in AWS, the DNS records are created based on the internal zones configured in Infoblox DNS server. This also lets the enterprise enforce DNS naming as per corporate naming policy, since Infoblox serves the DNS record. The naming convention can easily be automated by supplying a prefix based on some fields and incrementally adding a number as the suffix for every new instance created. As the VPCs, subnets, and EC2 instances are deleted or spun down, Infoblox will automatically delete respective DNS records, IP addresses, and networks associated with those objects. Therefore, by using the Infoblox Grid, it is possible to always get the latest information on AWS networks, IP addresses, instances, etc. Additional value-added information like IP lease histories and usage of specific IP addresses in VPCs and subnets can also be acquired from the Grid. 3 WHITE PAPER Ensuring Enterprise-grade Network Services for AWS

5 Greater Network Visibility for the Enterprise Through the use of Infoblox vdiscovery, instances, networks, and VPCs are now visible in the Infoblox GUI just like the physical and other virtual resources. Network teams have single-pane-of-glass visibility to DNS configurations and IP address utilization in AWS, allowing them to verify security and compliance for their networks. A discovery solution for the AWS network (regions/vpc/ec2) is required on a periodic basis to update any external DNS/IPAM solution so its internal database is constantly updated to ensure consistency with the AWS configuration at all times. This solution is implemented in Infoblox by using AWS APIs with the supplied user credentials to learn about VPCs, subnets, instances, IP addresses, and associated metadata information. Figure 3: Infoblox GUI for cloud network resources Users also get additional (computed) information such as IP address lease histories, so they have historic correlations between IP addresses and AWS instances. They can also verify network access compliance rules of workloads such as what network(s) do any specific kind of workload live on? The hybrid Grid deployment model provides users a single unified view of their private cloud and AWS in one pane of glass. Infoblox has a reporting capability that can be used for analytics on AWS discovered data. Secure DNS Traditional general-purpose DNS server approaches often have major security risks, including extensive patches and multiple open ports. A networking best practice is to deploy hardened DNS servers to address all vulnerabilities of any standard operating system that DNS servers run on in addition to the vulnerabilities of the DNS protocol itself. The Infoblox appliance is a hardened Linux system that exposes services via standard ports such as https (443) and DNS (53), depending on the services enabled by the end-user. Remote command-line interface (CLI) access is optionally provided via ssh (22) to access a captive CLI interface. This CLI does not provide the end-user with access to a standard Linux shell. During operation, the root file system of this appliance is mounted read-only to guard against introduction of arbitrary code into the system. In addition, Infoblox has also implemented a security solution that guards against malware, botnets, and other malicious software, which can be added to the Infoblox DDI for AWS solution. Deployment Models There are essentially two models for deploying Infoblox DDI for AWS hybrid or full public deployment. Within these two models are a number of considerations that factor into how users design their implementations. The figures below explain these two most common deployment models. 4

6 AWS AWS REGION VPC 2 ON-PREMISES DATA CENTER GRID MASTER VPC 1 GRID MASTER SHARED SERVICE MANAGEMENT VPC Figure 4: Hybrid deployment of the Infoblox Grid Hybrid deployment means that there is a NIOS Grid on the corporate premises, and that deployment is extended into the AWS cloud. On the corporate premises, a NIOS appliance (either physical or virtual) functions as the Grid Master. In addition to this, there might be other NIOS appliances on the corporate premises linked as Grid members and providing different services such as DNS, IPAM, and reporting. Deploying an instance of vnios into AWS extends these functions locally into a given VPC. This Grid member, when deployed, automatically joins the existing Grid. A VPN connection to the AWS VPC is required to provide the needed connectivity between this member and the Grid Master on the premises. Existing instances, VPCs, and subnets will be discovered by either the Grid Master or the vnios instances by setting up the appliance to request discovery from an AWS endpoint. AWS REGION 1 VPC 2 REGION 2 VPC 2 PRIMARY DNS GM VPC 1 VPC 1 SECONDARY DNS Figure 5: Public cloud deployment 5 WHITE PAPER Ensuring Enterprise-grade Network Services for AWS

7 The second deployment model is a full public cloud deployment. As implied, the deployment of the NIOS Grid in its entirety will be in the AWS cloud. In this model the best practice is to use a shared-service VPC model with other VPC peers to the shared-service VPC. In this design the shared-service VPC where the Grid Master is located has VPN connections to provide the ability to manage them securely from the corporate environment. Additional appliances are deployed per region to provide service with the best performance in mind. VPCs, subnets, and instances are discovered using vdiscovery, and their data populated into the Grid Master GUI. Infoblox DDI Value over Traditional Solutions Enterprises use two solutions to try and solve the challenges for DNS and IPAM in the AWS cloud AWS Route 53 and Microsoft DNS/DHCP. These solutions solve some of the challenges, but neither can solve them completely. Route 53 Route 53 provides scalable and highly available DNS in the AWS Cloud. In addition to being able to route users to various AWS services, including EC2 instances, Route 53 also enables AWS customers to route users to non-aws infrastructure. Route 53 servers are distributed throughout the world. While this solution is comprehensive, it cannot address completely the challenges faced by the enterprise for IPAM and DNS, namely: DNS service only, not used for IPAM Good for externally facing DNS, but difficult to integrate with an enterprise s current internal DNS solution Still challenging to provide network teams with simple visibility into DNS and IPAM to ensure compliance on an ongoing basis needed for securing the networks AWS focus with no correlated views of hybrid networks Microsoft DNS and DHCP Microsoft DNS and DHCP services are widely used by enterprises for traditional networks and can be deployed as a virtual instance in AWS. Management of these services becomes more challenging as the number of devices added to the network grows at an accelerated rate. The tools available are cumbersome to use, forcing manual processes to take place and potentially introducing human error. Enterprises choosing to use Microsoft will find it very difficult to meet the challenges faced by deploying workloads into the public cloud. Microsoft DNS and DHCP services: Provide basic functions but lack easy integration across a diverse enterprise that has Microsoft DNS and BIND Rely heavily on the use of DHCP, which is not available in AWS Can introduce latency and out-of-synch issues in synchronizing databases across the enterprise and AWS Cannot provide single-pane-of-glass visibility across the enterprise and into the AWS cloud 6

8 Conclusion The automation of DNS, DHCP, and IPAM for AWS is essential for a complete enterprise public/hybrid cloud solution. Fully integrated with our industry-leading Grid technology, the Infoblox solution for AWS increases cloud agility, supports consistent network policies across hybrid deployments, and improves visibility of public cloud workloads. Infoblox DDI for AWS offers virtual appliances as AMI images, which can be deployed inside VPCs as Grid member appliances. These members are auto-provisioned, and managed centrally from a Grid Master that can be either deployed on an enterprise s premises or AWS. Thus, this solution offers a simple, unified hybrid cloud experience to the enterprise. By extending Infoblox DDI into the AWS cloud, enterprises can solve the challenges of providing an enterprise DNS across corporate and cloud infrastructure, giving network teams consistent and meaningful visibility into public cloud environments, and ensuring compliance with corporate network and IP address allocation and DNS policies. About Infoblox Infoblox (NYSE:BLOX) delivers critical network services that protect Domain Name System (DNS) infrastructure, automate cloud deployments, and increase the reliability of enterprise and service provider networks around the world. As the industry leader in DNS, DHCP, and IP address management, the category known as DDI, Infoblox ( reduces the risk and complexity of networking. 7 WHITE PAPER Ensuring Enterprise-grade Network Services for AWS

9 CORPORATE HEADQUARTERS: (toll-free, U.S. and Canada) EMEA HEADQUARTERS: APAC HEADQUARTERS: Infoblox, Inc. All rights reserved. Infoblox-WP Ensuring Enterprise-grade Network Services for AWS Sept 2015

WHITE PAPER. Automating Network Provisioning for Private Cloud

WHITE PAPER. Automating Network Provisioning for Private Cloud WHITE PAPER Automating Network Provisioning for Private Cloud Executive Summary Roughly 80 percent of all enterprise IT today is virtualized. Virtualization is a key enabler in deploying private clouds

More information

Infoblox Grid TM. Automated Network Control for. Unifying DNS Management and Extending the Infoblox Grid TM to the F5 Global Traffic Manager

Infoblox Grid TM. Automated Network Control for. Unifying DNS Management and Extending the Infoblox Grid TM to the F5 Global Traffic Manager Key Differentiators Application Layer Availability Minimizes downtime and improves the user experience by determining health at the application layer for every user. Management Automation: Provides automated

More information

WHITE PAPER. Infoblox IPAM Integration with Microsoft AD Sites and Local Services

WHITE PAPER. Infoblox IPAM Integration with Microsoft AD Sites and Local Services WHITE PAPER Infoblox IPAM Integration with Microsoft AD Sites and Local Services Infoblox IPAM Integration with Microsoft AD Sites and Local Services Today s enterprise infrastructure is dynamic, with

More information

Infoblox vnios Software for CISCO AXP

Infoblox vnios Software for CISCO AXP Summary Infoblox vnios for Cisco consolidates core network services such as DNS, DHCP and IPAM and others onto the Cisco Integrated Services Router (ISR) running the Application Extension Platform (AXP)

More information

Automated Network Control for

Automated Network Control for Key Differentiators Application Layer Availability: Minimizes downtime and improves the user experience by determining health at the application layer for every user. Management Automation: Provides automated

More information

Reliable DNS and DHCP for Microsoft Active Directory

Reliable DNS and DHCP for Microsoft Active Directory WHITEPAPER Reliable DNS and DHCP for Microsoft Active Directory Protecting and Extending Active Directory Infrastructure with Infoblox Appliances Microsoft Active Directory (AD) is the distributed directory

More information

How To Create A Virtual Private Cloud On Amazon.Com

How To Create A Virtual Private Cloud On Amazon.Com Amazon Web Services Hands-On Virtual Private Computing 1 Overview Amazon s Virtual Private Cloud (VPC) allows you to launch AWS resources in a virtual network that you define. You can define an environment

More information

Simplifying Private Cloud Deployments through Network Automation

Simplifying Private Cloud Deployments through Network Automation WHITE PAPER Simplifying Private Cloud Deployments through Network Automation Build and Manage Agile, Scalable, and Reliable Private Clouds with Minimal Management Overhead Simplifying Private Cloud Deployments

More information

TECHNICAL WHITE PAPER. Infoblox and the Relationship between DNS and Active Directory

TECHNICAL WHITE PAPER. Infoblox and the Relationship between DNS and Active Directory TECHNICAL WHITE PAPER Infoblox and the Relationship between DNS and Active Directory Infoblox DNS in a Microsoft Environment Infoblox is the first, and currently only, DNS/DHCP/IP address management (DDI)

More information

Grid and Multi-Grid Management

Grid and Multi-Grid Management Key Benefits High Availability, Massive Scalability Infoblox Provides always on network services through scalable, redundant, reliable and faulttolerant architecture Guarantees data integrity and availability

More information

STARTER KIT. Infoblox DNS Firewall for FireEye

STARTER KIT. Infoblox DNS Firewall for FireEye STARTER KIT Introduction Infoblox DNS Firewall integration with FireEye Malware Protection System delivers a unique and powerful defense against Advanced Persistent Threats (APT) for business networks.

More information

RemoteApp Publishing on AWS

RemoteApp Publishing on AWS RemoteApp Publishing on AWS WWW.CORPINFO.COM Kevin Epstein & Stephen Garden Santa Monica, California November 2014 TABLE OF CONTENTS TABLE OF CONTENTS... 2 ABSTRACT... 3 INTRODUCTION... 3 WHAT WE LL COVER...

More information

Installing and Using the vnios Trial

Installing and Using the vnios Trial Installing and Using the vnios Trial The vnios Trial is a software package designed for efficient evaluation of the Infoblox vnios appliance platform. Providing the complete suite of DNS, DHCP and IPAM

More information

Managing Your Microsoft Windows Server Fleet with AWS Directory Service. May 2015

Managing Your Microsoft Windows Server Fleet with AWS Directory Service. May 2015 Managing Your Microsoft Windows Server Fleet with AWS Directory Service May 2015 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved. Notices This document is provided for informational

More information

Reliable DNS and DHCP for Microsoft Active Directory Protecting and Extending Active Directory Infrastructure with Infoblox Appliances

Reliable DNS and DHCP for Microsoft Active Directory Protecting and Extending Active Directory Infrastructure with Infoblox Appliances Reliable DNS and DHCP for Protecting and Extending Active Directory Infrastructure with Infoblox Appliances Reliable DNS and DHCP for (AD) is the distributed directory service and the information hub of

More information

Integrated IP Address Management Solution WHITEPAPER. Private Cloud Without Network Automation. Can it be done?

Integrated IP Address Management Solution WHITEPAPER. Private Cloud Without Network Automation. Can it be done? Integrated IP Address Management Solution WHITEPAPER Private Cloud Without Network Automation Can it be done? WHITEPAPER The Advent of Private Cloud The motivations for adopting new technology like Private

More information

Cloud Provision Widget 1.41

Cloud Provision Widget 1.41 Cloud Provision Widget is a simple web-based widget for demonstrating the Infoblox Cloud Automation plug-ins functionality as well as WAPI functionality. The widget has been designed for service delivery

More information

Virtualized Domain Name System and IP Addressing Environments. White Paper September 2010

Virtualized Domain Name System and IP Addressing Environments. White Paper September 2010 Virtualized Domain Name System and IP Addressing Environments White Paper September 2010 Virtualized DNS and IP Addressing Environments As organizations initiate virtualization projects in their operating

More information

Quick Start Guide. for Installing vnios Software on. VMware Platforms

Quick Start Guide. for Installing vnios Software on. VMware Platforms Quick Start Guide for Installing vnios Software on VMware Platforms Copyright Statements 2010, Infoblox Inc. All rights reserved. The contents of this document may not be copied or duplicated in any form,

More information

Securing Your Business with DNS Servers That Protect Themselves

Securing Your Business with DNS Servers That Protect Themselves Summary: The Infoblox DNS security product portfolio mitigates attacks on DNS/DHCP servers by intelligently recognizing various attack types and dropping attack traffic while responding only to legitimate

More information

Securing External Name Servers

Securing External Name Servers WHITEPAPER Securing External s Cricket Liu, Vice President of Architecture This white paper discusses the critical nature of external name servers and examines the practice of using common makes of name

More information

Deploying Virtual Cyberoam Appliance in the Amazon Cloud Version 10

Deploying Virtual Cyberoam Appliance in the Amazon Cloud Version 10 Deploying Virtual Cyberoam Appliance in the Amazon Cloud Version 10 Document version 1.0 10.6.2.378-13/03/2015 Important Notice Cyberoam Technologies Pvt. Ltd. has supplied this Information believing it

More information

Alfresco Enterprise on AWS: Reference Architecture

Alfresco Enterprise on AWS: Reference Architecture Alfresco Enterprise on AWS: Reference Architecture October 2013 (Please consult http://aws.amazon.com/whitepapers/ for the latest version of this paper) Page 1 of 13 Abstract Amazon Web Services (AWS)

More information

Every Silver Lining Has a Vault in the Cloud

Every Silver Lining Has a Vault in the Cloud Irvin Hayes Jr. Autodesk, Inc. PL6015-P Don t worry about acquiring hardware and additional personnel in order to manage your Vault software installation. Learn how to spin up a hosted server instance

More information

RED HAT CLOUDFORMS ENTERPRISE- GRADE MANAGEMENT FOR AMAZON WEB SERVICES

RED HAT CLOUDFORMS ENTERPRISE- GRADE MANAGEMENT FOR AMAZON WEB SERVICES TECHNOLOGY DETAIL RED HAT CLOUDFORMS ENTERPRISE- GRADE MANAGEMENT FOR AMAZON WEB SERVICES ABSTRACT Do you want to use public clouds like Amazon Web Services (AWS) to flexibly extend your datacenter capacity,

More information

Beyond Quality of Service (QoS) Preparing Your Network for a Faster Voice over IP (VoIP)/ IP Telephony (IPT) Rollout with Lower Operating Costs

Beyond Quality of Service (QoS) Preparing Your Network for a Faster Voice over IP (VoIP)/ IP Telephony (IPT) Rollout with Lower Operating Costs Beyond Quality of Service (QoS) Preparing Your Network for a Faster Voice over IP (VoIP)/ IP Telephony (IPT) Rollout with Lower Operating Costs Beyond Quality of Service (QoS) Cost Savings Unrealized THE

More information

PROJECT SUMMARY ROWAN UNIVERSITY REQUIREMENTS

PROJECT SUMMARY ROWAN UNIVERSITY REQUIREMENTS PROJECT SUMMARY The goal of this project is to migrate Rowan University from their current DNS and DHCP infrastructure at Camden Campus and Stratford Campus to an existing Infoblox Grid managed solution,

More information

IBM Cloud Security Draft for Discussion September 12, 2011. 2011 IBM Corporation

IBM Cloud Security Draft for Discussion September 12, 2011. 2011 IBM Corporation IBM Cloud Security Draft for Discussion September 12, 2011 IBM Point of View: Cloud can be made secure for business As with most new technology paradigms, security concerns surrounding cloud computing

More information

Application Security Best Practices. Matt Tavis Principal Solutions Architect

Application Security Best Practices. Matt Tavis Principal Solutions Architect Application Security Best Practices Matt Tavis Principal Solutions Architect Application Security Best Practices is a Complex topic! Design scalable and fault tolerant applications See Architecting for

More information

Automation Change Manager

Automation Change Manager Business Benefits Reduce the time, effort and risk of human error involved in making configuration changes to network devices Enable the network infrastructure become dynamically supportive of virtualization

More information

WHITEPAPER. Designing a Secure DNS Architecture

WHITEPAPER. Designing a Secure DNS Architecture WHITEPAPER Designing a Secure DNS Architecture Designing a Secure DNS Architecture In today s networking landscape, it is no longer adequate to have a DNS infrastructure that simply responds to queries.

More information

BEST PRACTICES WHITE PAPER. Best Practices for Successful IP Address Management (IPAM)

BEST PRACTICES WHITE PAPER. Best Practices for Successful IP Address Management (IPAM) BEST PRACTICES WHITE PAPER Best Practices for Successful IP Address Management (IPAM) Introduction Corporate and datacenter network complexity is growing beyond the reach of the historically available

More information

Infoblox Grid Technology

Infoblox Grid Technology WHITEPAPER Infoblox Grid Technology Delivering Next-Generation Solutions for Nonstop Core Network Services Executive Summary Infoblox appliances deliver network core network services including DNS, DNSSEC,

More information

SOLUTION WHITE PAPER. Managing AWS. Using BMC Cloud Management solutions to enhance agility with control

SOLUTION WHITE PAPER. Managing AWS. Using BMC Cloud Management solutions to enhance agility with control SOLUTION WHITE PAPER Managing AWS Using BMC Cloud Management solutions to enhance agility with control Holden pulled himself a shot of espresso, flipped his bangs out of his eyes, and brushed a few stray

More information

Infoblox Education Services Course Catalog

Infoblox Education Services Course Catalog Infoblox Education Services Course Catalog Enhance Your Contribution to the Business, Earn Industry-recognized Accreditations, and Develop Skills that Help You Advance in Your Career SEPTEMBER 2015 training.infoblox.com

More information

Networking Configurations for NetApp Cloud ONTAP TM for AWS

Networking Configurations for NetApp Cloud ONTAP TM for AWS Technical Report Networking Configurations for NetApp Cloud ONTAP TM for AWS Kris Lippe, NetApp November 2014 TR-4352 TABLE OF CONTENTS 1 Introduction...3 1.1 Glossary of Terms:...3 1.2 Overview...4 1.3

More information

Active Directory Domain Services on the AWS Cloud: Quick Start Reference Deployment Mike Pfeiffer

Active Directory Domain Services on the AWS Cloud: Quick Start Reference Deployment Mike Pfeiffer Active Directory Domain Services on the AWS Cloud: Quick Start Reference Deployment Mike Pfeiffer March 2014 Last updated: September 2015 (revisions) Table of Contents Abstract... 3 What We ll Cover...

More information

Infoblox Education Services Course Catalog

Infoblox Education Services Course Catalog Infoblox Education Services Course Catalog Enhance Your Contribution to the Business, Earn Industry-recognized Accreditations, and Develop Skills that Help You Advance in Your Career FEBRUARY 2016 training.infoblox.com

More information

Securing Privileges in the Cloud. A Clear View of Challenges, Solutions and Business Benefits

Securing Privileges in the Cloud. A Clear View of Challenges, Solutions and Business Benefits A Clear View of Challenges, Solutions and Business Benefits Introduction Cloud environments are widely adopted because of the powerful, flexible infrastructure and efficient use of resources they provide

More information

Data Collection and Analysis: Get End-to-End Security with Cisco Connected Analytics for Network Deployment

Data Collection and Analysis: Get End-to-End Security with Cisco Connected Analytics for Network Deployment White Paper Data Collection and Analysis: Get End-to-End Security with Cisco Connected Analytics for Network Deployment Cisco Connected Analytics for Network Deployment (CAND) is Cisco hosted, subscription-based

More information

Implementing Software- Defined Security with CloudPassage Halo

Implementing Software- Defined Security with CloudPassage Halo WHITE PAPER Implementing Software- Defined Security with CloudPassage Halo Introduction... 2 Implementing Software-Defined Security w/cloudpassage Halo... 3 Abstraction... 3 Automation... 4 Orchestration...

More information

Virtualization Success Depends on Network Automation

Virtualization Success Depends on Network Automation WHITEPAPER Virtualization Success Depends on Network Automation The Advent of Virtualization The Advent of Virtualization Organizations of all sizes are transitioning to virtualization technology at a

More information

The Importance of a Resilient DNS and DHCP Infrastructure

The Importance of a Resilient DNS and DHCP Infrastructure White Paper The Importance of a Resilient DNS and DHCP Infrastructure DNS and DHCP availability and integrity increase in importance with the business dependence on IT systems The Importance of DNS and

More information

Deploy Remote Desktop Gateway on the AWS Cloud

Deploy Remote Desktop Gateway on the AWS Cloud Deploy Remote Desktop Gateway on the AWS Cloud Mike Pfeiffer April 2014 Last updated: May 2015 (revisions) Table of Contents Abstract... 3 Before You Get Started... 3 Three Ways to Use this Guide... 4

More information

Deploy XenApp 7.5 and 7.6 and XenDesktop 7.5 and 7.6 with Amazon VPC

Deploy XenApp 7.5 and 7.6 and XenDesktop 7.5 and 7.6 with Amazon VPC XenApp 7.5 and 7.6 and XenDesktop 7.5 and 7.6 Deploy XenApp 7.5 and 7.6 and XenDesktop 7.5 and 7.6 with Amazon VPC Prepared by: Peter Bats Commissioning Editor: Linda Belliveau Version: 5.0 Last Updated:

More information

How to Grow and Transform your Security Program into the Cloud

How to Grow and Transform your Security Program into the Cloud How to Grow and Transform your Security Program into the Cloud Wolfgang Kandek Qualys, Inc. Session ID: SPO-207 Session Classification: Intermediate Agenda Introduction Fundamentals of Vulnerability Management

More information

VMware vcloud Networking and Security Overview

VMware vcloud Networking and Security Overview VMware vcloud Networking and Security Overview Networks and Security for Virtualized Compute Environments WHITE PAPER Overview Organizations worldwide have gained significant efficiency and flexibility

More information

Designing and Implementing a Server Infrastructure

Designing and Implementing a Server Infrastructure Course 20413C: Designing and Implementing a Server Infrastructure Course Details Course Outline Module 1: Planning Server Upgrade and Migration This module explains how to plan a server upgrade and migration

More information

Freedom for Servers, Drives & Desktops

Freedom for Servers, Drives & Desktops a cloud commerce marketplace THE CLOUD REVOLUTION: Freedom for Servers, Drives & Desktops...cloud computing is enabling small and medium businesses (SMBs) to compete with the upper echelon of corporate

More information

I D C T E C H N O L O G Y S P O T L I G H T. S e r ve r S e c u rity: N o t W h a t It U s e d t o Be!

I D C T E C H N O L O G Y S P O T L I G H T. S e r ve r S e c u rity: N o t W h a t It U s e d t o Be! I D C T E C H N O L O G Y S P O T L I G H T S e r ve r S e c u rity: N o t W h a t It U s e d t o Be! December 2014 Adapted from Worldwide Endpoint Security 2013 2017 Forecast and 2012 Vendor Shares by

More information

Talari Virtual Appliance CT800. Getting Started Guide

Talari Virtual Appliance CT800. Getting Started Guide Talari Virtual Appliance CT800 Getting Started Guide March 18, 2015 Table of Contents About This Guide... 2 References... 2 Request for Comments... 2 Requirements... 3 AWS Resources... 3 Software License...

More information

Amazon EFS (Preview) User Guide

Amazon EFS (Preview) User Guide Amazon EFS (Preview) User Guide Amazon EFS (Preview): User Guide Copyright 2015 Amazon Web Services, Inc. and/or its affiliates. All rights reserved. Amazon's trademarks and trade dress may not be used

More information

Leveraging Best Practices for SolarWinds IP Address Manager

Leveraging Best Practices for SolarWinds IP Address Manager Leveraging Best Practices for SolarWinds IP Address Manager Share: Leveraging Best Practices for SolarWinds IPAM SolarWinds IP Address Manager (IPAM) is a comprehensive IP address management solution that

More information

Secret Server Qualys Integration Guide

Secret Server Qualys Integration Guide Secret Server Qualys Integration Guide Table of Contents Secret Server and Qualys Cloud Platform... 2 Authenticated vs. Unauthenticated Scanning... 2 What are the Advantages?... 2 Integrating Secret Server

More information

How To Deploy Sangoma Sbc Vm At Amazon Cloud Service (Awes) On A Vpc (Virtual Private Cloud) On An Ec2 Instance (Virtual Cloud)

How To Deploy Sangoma Sbc Vm At Amazon Cloud Service (Awes) On A Vpc (Virtual Private Cloud) On An Ec2 Instance (Virtual Cloud) Sangoma VM SBC AMI at AWS (Amazon Web Services) SBC in a Cloud Based UC/VoIP Service. One of the interesting use cases for Sangoma SBC is to provide VoIP Edge connectivity between Soft switches or IPPBX's

More information

ECM AS A CLOUD PLATFORM:

ECM AS A CLOUD PLATFORM: ECM AS A CLOUD PLATFORM: KEEP IT SIMPLE TABLE OF CONTENTS ECM as a Cloud Platform 2 What is a Cloud Platform? 2 What is a Cloud Application? 3 SpringCM The World s Leading ECM Cloud Platform Provider 6

More information

Build Your Knowledge!

Build Your Knowledge! About this Course Get hands-on instruction and practice configuring and implementing new features and functionality in Windows Server, including Windows Server R2, in this five-day Microsoft Official Course.

More information

Web Application Firewall

Web Application Firewall Web Application Firewall Getting Started Guide August 3, 2015 Copyright 2014-2015 by Qualys, Inc. All Rights Reserved. Qualys and the Qualys logo are registered trademarks of Qualys, Inc. All other trademarks

More information

DNS Security: New Threats, Immediate Responses, Long Term Outlook. 2007 2008 Infoblox Inc. All Rights Reserved.

DNS Security: New Threats, Immediate Responses, Long Term Outlook. 2007 2008 Infoblox Inc. All Rights Reserved. DNS Security: New Threats, Immediate Responses, Long Term Outlook 2007 2008 Infoblox Inc. All Rights Reserved. A Brief History of the Recent DNS Vulnerability Kaminsky briefs key stakeholders (CERT, ISC,

More information

WHITE PAPER. Creating a Best-of-Breed DDI Solution in a Microsoft Environment

WHITE PAPER. Creating a Best-of-Breed DDI Solution in a Microsoft Environment WHITE PAPER Creating a Best-of-Breed DDI Solution in a Microsoft Environment Introduction Best-of-breed solutions, by nature, are hybrid solutions that take the superior elements of multiple vendors and

More information

KeyControl Installation on Amazon Web Services

KeyControl Installation on Amazon Web Services KeyControl Installation on Amazon Web Services Contents Introduction Deploying an initial KeyControl Server Deploying an Elastic Load Balancer (ELB) Adding a KeyControl node to a cluster in the same availability

More information

Cisco and Visual Network Systems: Implement an End-to-End Application Performance Management Solution for Managed Services

Cisco and Visual Network Systems: Implement an End-to-End Application Performance Management Solution for Managed Services Cisco and Visual Network Systems: Implement an End-to-End Application Performance Management Solution for Managed Services What You Will Learn In today s economy, IT departments are challenged to decide

More information

DNS Appliance Architecture: Domain Name System Best Practices

DNS Appliance Architecture: Domain Name System Best Practices WHITEPAPER DNS Appliance Architecture: Domain Name System Best Practices A Practical Look at Deploying DNS Appliances in the Network to Increase Simplicity, Security & Scalability Cricket Liu, Chief Infrastructure

More information

Infoblox Core Network Services solution

Infoblox Core Network Services solution Infoblox Core Network Services solution Table of contents: 1. INFOBLOX - AUTOMATION AND RESILIENCE FOR CORE NETWORK SERVICES 3 2. ISSUES OF CORE NETWORK SERVICES ON AD HOC PC SYSTEMS 3 Management and maintenance

More information

MCSA Instructor-led Live Online Training Program. Course Outline MCSA 70-410. Deploying and Managing Windows Server 2012

MCSA Instructor-led Live Online Training Program. Course Outline MCSA 70-410. Deploying and Managing Windows Server 2012 Course Outline MCSA 70-410 Deploying and Managing Windows Server 2012 Windows Server 2012 Overview Overview of Windows Server 2012 Management Installing Windows Server 2012 Post-Installation Configuration

More information

Pega as a Service. Kim Singletary, Dir. Product Marketing Cloud Matt Yanchyshyn, Sr. Mgr., AWS Solutions Architect

Pega as a Service. Kim Singletary, Dir. Product Marketing Cloud Matt Yanchyshyn, Sr. Mgr., AWS Solutions Architect 1 Pega as a Service Kim Singletary, Dir. Product Marketing Cloud Matt Yanchyshyn, Sr. Mgr., AWS Solutions Architect This information is not a commitment, promise or legal obligation to deliver any material,

More information

10974B: Deploying and Migrating Windows Servers

10974B: Deploying and Migrating Windows Servers 10974B: Deploying and Migrating Windows Servers Course Details Course Code: Duration: Notes: 10974B 3 days This course syllabus should be used to determine whether the course is appropriate for the students,

More information

Horizontal Integration - Unlocking the Cloud Stack. A Technical White Paper by FusionLayer, Inc.

Horizontal Integration - Unlocking the Cloud Stack. A Technical White Paper by FusionLayer, Inc. Horizontal Integration - Unlocking the Cloud Stack A Technical White Paper by FusionLayer, Inc. August 2013 Copyright 2015 FusionLayer, Inc. All rights reserved. No part of this publication may be reproduced,

More information

Centrify Server Suite Management Tools

Centrify Server Suite Management Tools SERVER SUITE TECHNICAL BRIEF Centrify Server Suite Management Tools Centrify Server Suite includes - at no extra charge - a powerful set of management tools in all editions: Centrify Identity Risk Assessor

More information

VNLINFOTECH JOIN US & MAKE YOUR FUTURE BRIGHT. mcsa (70-413) Microsoft certified system administrator. (designing & implementing server infrasturcure)

VNLINFOTECH JOIN US & MAKE YOUR FUTURE BRIGHT. mcsa (70-413) Microsoft certified system administrator. (designing & implementing server infrasturcure) VNLINFOTECH JOIN US & MAKE YOUR FUTURE BRIGHT mcsa (70-413) Microsoft certified system administrator (designing & implementing server infrasturcure) www.vnlinfotech.com MODULE 1 : Considerations for Upgrades

More information

Securing Your Business with DNS Servers That Protect Themselves

Securing Your Business with DNS Servers That Protect Themselves Product Summary: The Infoblox DNS security product portfolio mitigates attacks on DNS/DHCP servers by intelligently recognizing various attack types and dropping attack traffic while responding only to

More information

How To Set Up Wiremock In Anhtml.Com On A Testnet On A Linux Server On A Microsoft Powerbook 2.5 (Powerbook) On A Powerbook 1.5 On A Macbook 2 (Powerbooks)

How To Set Up Wiremock In Anhtml.Com On A Testnet On A Linux Server On A Microsoft Powerbook 2.5 (Powerbook) On A Powerbook 1.5 On A Macbook 2 (Powerbooks) The Journey of Testing with Stubs and Proxies in AWS Lucy Chang lucy_chang@intuit.com Abstract Intuit, a leader in small business and accountants software, is a strong AWS(Amazon Web Services) partner

More information

Cloud: Bridges, Brokers and Gateways

Cloud: Bridges, Brokers and Gateways Integrating the Cloud: Bridges, Brokers, and Gateways Organizations are increasingly adopting a hybrid strategy for cloud computing to realize the benefits without compromising on control. The integration

More information

Cisco Intelligent Automation for Cloud

Cisco Intelligent Automation for Cloud Product Data Sheet Cisco Intelligent Automation for Cloud Early adopters of cloud-based service delivery were seeking additional cost savings beyond those achieved with server virtualization and abstraction.

More information

1 2014 2013 Infoblox Inc. All Rights Reserved. Talks about DNS: architectures & security

1 2014 2013 Infoblox Inc. All Rights Reserved. Talks about DNS: architectures & security 1 2014 2013 Infoblox Inc. All Rights Reserved. Talks about DNS: architectures & security Agenda Increasing DNS availability using DNS Anycast Opening the internal DNS Enhancing DNS security DNS traffic

More information

Networking with Windows Server vb. Day(s): 5. Version: Overview

Networking with Windows Server vb. Day(s): 5. Version: Overview Networking with Windows Server vb Day(s): 5 Course Code: M10970 Version: B Overview Get hands-on instruction and practice implementing networking with Windows Server 2012 and Windows Server 2012 R2 in

More information

Security Gateway Virtual Appliance R75.40

Security Gateway Virtual Appliance R75.40 Security Gateway Virtual Appliance R75.40 for Amazon Web Services VPC Getting Started Guide 5 March 2013 [Protected] 2013 Check Point Software Technologies Ltd. All rights reserved. This product and related

More information

19.10.11. Amazon Elastic Beanstalk

19.10.11. Amazon Elastic Beanstalk 19.10.11 Amazon Elastic Beanstalk A Short History of AWS Amazon started as an ECommerce startup Original architecture was restructured to be more scalable and easier to maintain Competitive pressure for

More information

When your users take devices outside the corporate environment, these web security policies and defenses within your network no longer work.

When your users take devices outside the corporate environment, these web security policies and defenses within your network no longer work. Deployment Guide Revision C McAfee Web Protection Hybrid Introduction Web Protection provides the licenses and software for you to deploy Web Gateway, SaaS Web Protection, or a hybrid deployment using

More information

VXOA AMI on Amazon Web Services

VXOA AMI on Amazon Web Services 2013 Silver Peak Systems, Inc. QUICK START GUIDE VXOA AMI on Amazon Web Services A Silver Peak Virtual Appliance (VX) can be deployed within an Amazon Web Services (AWS) cloud environment to accelerate

More information

Vblock Systems hybrid-cloud with Cisco Intercloud Fabric

Vblock Systems hybrid-cloud with Cisco Intercloud Fabric www.vce.com Vblock Systems hybrid-cloud with Cisco Intercloud Fabric Version 1.0 April 2015 THE INFORMATION IN THIS PUBLICATION IS PROVIDED "AS IS." VCE MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND

More information

Active Directory Services with Windows Server 10969B; 5 days, Instructor-led

Active Directory Services with Windows Server 10969B; 5 days, Instructor-led Active Directory Services with Windows Server 10969B; 5 days, Instructor-led Course Description Get hands on instruction and practice administering Active Directory technologies in Windows Server 2012

More information

How To Monitor Hybrid It From A Hybrid Environment

How To Monitor Hybrid It From A Hybrid Environment IT Monitoring for the Hybrid Enterprise With a Look at ScienceLogic Perspective 2012 Neovise, LLC. All Rights Reserved. Report Published April, 2015 Hybrid IT Goes Mainstream Enterprises everywhere are

More information

The Hillstone and Trend Micro Joint Solution

The Hillstone and Trend Micro Joint Solution The Hillstone and Trend Micro Joint Solution Advanced Threat Defense Platform Overview Hillstone and Trend Micro offer a joint solution the Advanced Threat Defense Platform by integrating the industry

More information

Devising a Server Protection Strategy with Trend Micro

Devising a Server Protection Strategy with Trend Micro Devising a Server Protection Strategy with Trend Micro A Trend Micro White Paper Trend Micro, Incorporated» A detailed account of why Gartner recognizes Trend Micro as a leader in Virtualization and Cloud

More information

Extending your Enterprise IT with Amazon Virtual Private Cloud. Oyvind Roti Principal Solutions Architect, AWS

Extending your Enterprise IT with Amazon Virtual Private Cloud. Oyvind Roti Principal Solutions Architect, AWS Extending your Enterprise IT with Amazon Virtual Private Cloud Oyvind Roti Principal Solutions Architect, AWS Three Things Some AWS Concepts Let s build a Virtual Private Cloud together Three New Services

More information

Training Name Installing and Configuring Windows Server 2012

Training Name Installing and Configuring Windows Server 2012 Training Name Installing and Configuring Windows Server 2012 Exam Code 70 410 At Course Completion After completing this course, students will be able to: Install and configure Windows Server 2012. Describe

More information

IaaS Configuration for Cloud Platforms

IaaS Configuration for Cloud Platforms vrealize Automation 6.2.3 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions

More information

White Paper. Deployment Practices and Guidelines for NetScaler 10.5 on Amazon Web Services. citrix.com

White Paper. Deployment Practices and Guidelines for NetScaler 10.5 on Amazon Web Services. citrix.com Deployment Practices and Guidelines for NetScaler 10.5 on Amazon Web Services Citrix NetScaler on Amazon Web Services (AWS) enables enterprises to rapidly and cost-effectively leverage world-class NetScaler

More information

Accenture Cloud Platform Unlocks Agility and Control

Accenture Cloud Platform Unlocks Agility and Control Accenture Cloud Platform Unlocks Agility and Control 2 Accenture Cloud Platform Unlocks Agility and Control The Accenture Cloud Platform is at the heart of today s leading-edge, enterprise cloud solutions.

More information

MICROSTRATEGY ON AWS

MICROSTRATEGY ON AWS MICROSTRATEGY ON AWS Presented by: MicroStrategy World 2015 Tuesday, January 27th 3:30 4:30 PM Track 8 Session 3 WWW.IOLAP.COM 1 INTRODUCTIONS iolap Data Warehousing and Business Intelligence consultancy

More information

Increased Security, Greater Agility, Lower Costs for AWS DELPHIX FOR AMAZON WEB SERVICES WHITE PAPER

Increased Security, Greater Agility, Lower Costs for AWS DELPHIX FOR AMAZON WEB SERVICES WHITE PAPER Increased Security, Greater Agility, Lower Costs for AWS DELPHIX FOR AMAZON WEB SERVICES TABLE OF CONTENTS Introduction... 3 Overview: Delphix Virtual Data Platform... 4 Delphix for AWS... 5 Decrease the

More information

White Paper. Prepared by: Neil Shah Director, Product Management March, 2014 Version: 1. Copyright 2014, ezdi, LLC.

White Paper. Prepared by: Neil Shah Director, Product Management March, 2014 Version: 1. Copyright 2014, ezdi, LLC. White Paper ezcac: HIPAA Compliant Cloud Solution Prepared by: Neil Shah Director, Product Management March, 2014 Version: 1 Copyright 2014, ezdi, LLC. TECHNICAL SAFEGUARDS Access Control 164.312 (a) (1)

More information

IBM 000-281 EXAM QUESTIONS & ANSWERS

IBM 000-281 EXAM QUESTIONS & ANSWERS IBM 000-281 EXAM QUESTIONS & ANSWERS Number: 000-281 Passing Score: 800 Time Limit: 120 min File Version: 58.8 http://www.gratisexam.com/ IBM 000-281 EXAM QUESTIONS & ANSWERS Exam Name: Foundations of

More information

TechNote. Configuring SonicOS for Amazon VPC

TechNote. Configuring SonicOS for Amazon VPC Network Security SonicOS Contents Overview... 1 System or Network Requirements / Prerequisites... 3 Deployment Considerations... 3 Configuring Amazon VPC with a Policy-Based VPN... 4 Configuring Amazon

More information

Optimally Manage the Data Center Using Systems Management Tools from Cisco and Microsoft

Optimally Manage the Data Center Using Systems Management Tools from Cisco and Microsoft White Paper Optimally Manage the Data Center Using Systems Management Tools from Cisco and Microsoft What You Will Learn Cisco is continuously innovating to help businesses reinvent the enterprise data

More information

Devising a Server Protection Strategy with Trend Micro

Devising a Server Protection Strategy with Trend Micro Devising a Server Protection Strategy with Trend Micro A Trend Micro White Paper» Trend Micro s portfolio of solutions meets and exceeds Gartner s recommendations on how to devise a server protection strategy.

More information

TRIPWIRE PURECLOUD. TRIPWIRE PureCloud USER GUIDE

TRIPWIRE PURECLOUD. TRIPWIRE PureCloud USER GUIDE TRIPWIRE PURECLOUD TRIPWIRE PureCloud USER GUIDE 2001-2015 Tripwire, Inc. All rights reserved. Tripwire and ncircle are registered trademarks of Tripwire, Inc. Other brand or product names may be trademarks

More information

White Paper. Getting the most out of your cloud deployment

White Paper. Getting the most out of your cloud deployment White Paper Getting the most out of your cloud deployment Contents Introduction...3 Moving your application into the cloud...3 Securing your application in the cloud...4 Traditional security pitfalls...4

More information