Networks for Applications: Next generation of application delivery & security



Similar documents
Enabling Application Aware Networks The Next Generation Data Centre with Citrix NetScaler & Cisco Nexus. Ralph W. Lorkins Lead Systems Engineer

More than just Layer 2-7 Load Balancing Citrix NetScaler & CloudGateway

Cisco Prime Network Services Controller. Sonali Kalje Sr. Product Manager Cloud and Virtualization, Cisco Systems

Cisco-Citrix Alliance

Cisco and Citrix Solution

NetScaler: A comprehensive replacement for Microsoft Forefront Threat Management Gateway

Unleash the power of Cisco ACI and F5 Synthesis for Accelerated Application deployments. Ravi Balakrishnan Senior Marketing Manager, Cisco Systems

Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera VERSION May, 2015

Infrastructure for more security and flexibility to deliver the Next-Generation Data Center

Cisco ACI and F5 LTM Integration for accelerated application deployments. Dennis de Leest Sr. Systems Engineer F5

Cisco and Citrix: Building Application Centric, ADC-enabled Data Centers

Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure

ADC의 진화 WDC (Workspace Delivery Controller) 시트릭스 코리아 허재홍 부장 September 17, 2015

Datacenter Networking. Joy ABOIM Consulting System Engineer

Cisco and Citrix: Building Application Centric, ADC-enabled Data Centers

Citrix NetScaler Best Practices. Claudio Mascaro Senior Systems Engineer BCD-Sintrag AG

Understanding Cisco Cloud Fundamentals CLDFND v1.0; 5 Days; Instructor-led

Cisco Nexus 1000V Switches

CNS Implementing NetScaler 11.0 For App and Desktop Solutions

Deliver the Next Generation Intelligent Datacenter Fabric with the Cisco Nexus 1000V, Citrix NetScaler Application Delivery Controller and Cisco vpath

HAWAII TECH TALK SDN. Paul Deakin Field Systems Engineer

Simplify IT. With Cisco Application Centric Infrastructure. Barry Huang Nov 13, 2014

Palo Alto Networks. Security Models in the Software Defined Data Center

Zenoss for Cisco ACI: Application-Centric Operations

Sean Bennett. Cloud Platforms & Networking Group

CNS-207 Implementing Citrix NetScaler 10.5 for App and Desktop Solutions

Cisco Unified Network Services: Overcome Obstacles to Cloud-Ready Deployments

From the datacenter to the client: Virtualization Solutions from Dell & Citrix. Jürgen Wand, Systems Engineering Citrix Systems GmbH

Score your ACE in Business and IT Efficiency

Stretched Active- Active Application Centric Infrastructure (ACI) Fabric

2013 ONS Tutorial 2: SDN Market Opportunities

Thank you for joining us today! The presentation will begin shortly. Thank you for your patience.

The Advantages of Cloud Services

"Charting the Course... Implementing Citrix NetScaler 11 for App and Desktop Solutions CNS-207 Course Summary

Cisco Virtualization Experience Infrastructure: Secure the Virtual Desktop

Network Services Orchestration Software Defined Networks, Network Function Virtualization - TODAY

Enabling Application Defined Networking with F5 Synthesis and Cisco Application Centric Infrastructure

Virtualized Multiservice Data Center with Virtualized Services Cisco and/or its affiliates. All rights reserved.

F5 Intelligent DNS Scale. Philippe Bogaerts Senior Field Systems Engineer mailto: Mob.:

CNS-208 Citrix NetScaler 10.5 Essentials for ACE Migration

Federated Application Centric Infrastructure (ACI) Fabrics for Dual Data Center Deployments

MANAGE SECURE ACCESS TO APPLICATIONS BASED ON USER IDENTITY. EMEA Webinar July 2013

Orchestrating the next generation data center

Cisco Intercloud Fabric Security Features: Technical Overview

Availability Acceleration Access Virtualization - Consolidation

VMware NSX A Perspective for Service Providers part 2

Evolution of Software Defined Networking within Cisco s VMDC

How Network Virtualization can improve your Data Center Security

NetScaler VPX FAQ. Table of Contents

Business Values of Network and Security Virtualization

Securing the Virtualized Data Center With Next-Generation Firewalls

Citrix XenServer 7 Feature Matrix

Set Up a VM-Series Firewall on the Citrix SDX Server

SDN PARTNER INTEGRATION: SANDVINE

Installation Guide Avi Networks Cloud Application Delivery Platform Integration with Cisco Application Policy Infrastructure

Presented by Philippe Bogaerts Senior Field Systems Engineer Securing application delivery in the cloud

Getting More Performance and Efficiency in the Application Delivery Network

SOFTWARE DEFINED NETWORKING

Citrix NetScaler 10.5 Essentials for ACE Migration CNS208; 5 Days, Instructor-led

SOLUTION BRIEF Citrix Cloud Solutions Citrix Cloud Solution for On-boarding

The Evolving Data Center. Past, Present and Future Scott Manson CISCO SYSTEMS

Cisco Network Services Manager 5.0

White Paper. SDN 102: Software Defined Networks and the Role of Application Delivery Network Services. citrix.com

How To Manage A Netscaler On A Pc Or Mac Or Mac With A Net Scaler On An Ipad Or Ipad With A Goslade On A Ggoslode On A Laptop Or Ipa On A Network With

Application centric Datacenter Management. Ralf Brünig, F5 Networks GmbH Field Systems Engineer March 2014

White Paper. SDN 101: An Introduction to Software Defined Networking. citrix.com

Apache CloudStack 4.x (incubating) Network Setup: excerpt from Installation Guide. Revised February 28, :32 pm Pacific

Vyatta Network OS for Network Virtualization

CNS-208 Citrix NetScaler 10 Essentials for ACE Migration

How To Build A Software Defined Data Center

APV9650. Application Delivery Controller

Building an Open, Adaptive & Responsive Data Center using OpenDaylight

Building the Internet of Things Jim Green - CTO, Data & Analytics Business Group, Cisco Systems

Cisco Application Centric Infrastructure. Silvo Lipovšek Sistemski inženjer

Palo Alto Networks Cyber Security Platform for the Software Defined Data center. Zekeriya Eskiocak Security Consultant Palo Alto Networks

Introduction to the EIS Guide

Strategies for Getting Started with IPv6

Features. Key benefits. HDX WAN optimization. QoS

VMware vcloud Networking and Security Overview

Designing Virtual Network Security Architectures Dave Shackleford

Securing Virtual Applications and Servers

A Case for Overlays in DCN Virtualization Katherine Barabash, Rami Cohen, David Hadas, Vinit Jain, Renato Recio and Benny Rochwerger IBM

5 Key Reasons to Migrate from Cisco ACE to F5 BIG-IP

Deploy XenApp 7.5 and 7.6 and XenDesktop 7.5 and 7.6 with Amazon VPC

Definition of a White Box. Benefits of White Boxes

CVE-401/CVA-500 FastTrack

App Orchestration Setup Checklist

Software Defined Environments

Cisco Application Networking for IBM WebSphere

Solution Brief. Deliver Production Grade OpenStack LBaaS with Citrix NetScaler. citrix.com

Securing Virtualization with Check Point and Consolidation with Virtualized Security

Don't outsource IT! Bring your own Cloud with SDN

Cisco Hybrid Cloud Solution: Deploy an E-Business Application with Cisco Intercloud Fabric for Business Reference Architecture

CNS-208 CITRIX NETSCALER 10.5 ESSENTIALS FOR ACE MIGRATION

Cisco Certified Security Professional (CCSP)

Virtualization, SDN and NFV

SDN Applications in Today s Data Center

Network Technologies for Next-generation Data Centers

Transcription:

Networks for Applications: Next generation of application delivery & security Cisco and Citrix Damjan Mirtič, Channel Manager Citrix SEE Ondrej Krkoska, Lead Networking Engineer Citrix EE Grega Zoubek, Lead Mobility Engineer Citrix SEE

Agenda Next generation of application delivery & security in modern cloud environments Integrated solutions Cisco & Citrix Cisco / Citrix NetScaler capabilities Mobile workstyle solutions Demo 2

Our Beliefs The Entire Network must be intelligent 7 6 3 2 1 Networks exist to deliver applications Context trumps connectivity Virtualization 5 user app service will device / is location disruptive 4 The transport network will be flat 3

A LOT of Different Applications 4

Applications Have Different Owners and Needs Desktop Admin Throughput Finance Commerce Collaboration Manufacturing Commerce Sales/ Service Functionality Administration Sales/ Service Finance LoB Specialists LoB Specialists LoB Specialists LoB Specialists Policies Sales/ Service Collaboration Network Comms Manufacturing Service Levels Commerce Commerce 5

Pair per Application/Tenant LB 6

Networks are Evolving Traditional Cloud Centric Virtualized Datacenter = Consolidation 7

Virtualized Data Centers Drive Flat Networks Traditional Pod per App Inefficient Cloud centric Any App, Any Pod Segmented Hierarchical Network Most data flows North/South Network services deployed by pod Much East/West traffic Network Services Layer must Span Pods Driving virtualization and consolidation App A App B App C 8

Consolidation Challenges Application Independence App Requirements throughput, functionality, policies, service levels Tenant Independence Lifecycle requirements maintenance windows, infrastructure change frequency, app change frequency, new features Compliance requirements government regulations, network instability / service interruption, security risks, dmz best practices Separation Policy Organizational Efficiency Financial requirements time-to-revenue, operational cost, capital expense 9

Partition per App/Tenant Shared Instance 10

And L4 7 is Different Resource consumption is independent of number and size of packets Pushing Packets Processing Payloads 11

Partitions / Contexts Fail for True Isolation All tenants Share a single instance Rate limits, RBA and ACLs partition the instance Partitions NOT fully isolated No CPU or memory isolation No version independence No high availability independence No lifecycle independence 12

NetScaler SDX CPU, memory, IO virtualization XenServer Service VM NetScaler VPX NetScaler VPX Palo Alto VM Series XenServer + Intel + SR IOV NICs Independent instances, versions Direct hardware access Service VM Single point for management NetScaler Hardware HW level SSL isolation 13 2012 Citrix Confidential Do Not Distribute HA across devices

NetScaler SDX Isolated instance per tenant Memory, CPU hardwalling Separate entity spaces Version independence Maintenance independence Hardware level SSL isolation Completely isolated networks Single point of control (SVM) HA across devices Fully contained networking appliance 14

3 rd Party Support Now open for 3 rd party services 15

Cisco and Citrix work together to enable SDN and data center transformation 16

NetScaler 1000V Cisco OEM Virtual NetScaler Nexus 1000v vpath Virtual Network Overlay Nexus 7000 RISE Integration Nexus 9000 ACI APIC VMDC CVD VSA 1.0 VMDC CVD DCI 1.0 Mobile Workspaces CVD 1.0 Prime Network Services Open Daylight FlexPod Cisco, Citrix NetApp VCE Vblock Cisco, Citrix, EMC 17

NetScaler 1000V Sold and Supported by Cisco NetScaler 1000V Cisco OEM Virtual NetScaler

Citrix NetScaler 1000V ADC from Cisco Virtual NetScaler ADC Available as Cisco software Sold and supported by Cisco Sold and supported by Cisco ADC for Nexus 1000V Virtualized Data Center 19

Citrix NetScaler 1000V Platform Options Citrix NetScaler 1000V on ESXi (e.g. UCS) Up to 4 Gbps throughput Works on any commodity server Citrix NetScaler 1000V on Nexus 1110 Nexus 1110 Cloud Services Platform (CSP) Platform for multiple Virtualized Network Services NetScaler SW + Nexus HW = Cisco ADC NetScaler 1000V 20

Nexus 1000V Integration using vpath Virtual Network Overlay through Service Chaining Nexus 1000v vpath Virtual Network Overlay

NetScaler 1000V in the Nexus 1000V Virtualized Data Center Tenant A vwaas ASA 1000V Cloud Firewall Cisco Virtual Security Gateway Cloud Services Router 1000V NetScaler 1000V Zone A Zone B Nexus 1000V Distributed Virtual Switch vpath VXLAN Multi Hypervisor (VMware, Microsoft*, RedHat*, Citrix*) Nexus 1000V vwaas ASA 1000V VSG CSR 1000V (Cloud Router) NetScaler 1000V Distributed switch NX OS consistency WAN optimization Application traffic Edge firewall, VPN Protocol Inspection VM level controls Zone based FW WAN L3 gateway Routing and VPN Citrix NetScaler Application Delivery Controller Citrix NetScaler Web App Firewall 22

vpath Service Chaining Virtual Network Overlay Policy based traffic steering through virtualized network services Cisco VSG VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM 5 4 Cisco Nexus 1000V Distributed Virtual Switch Cisco vpath 3 Citrix NetScaler 1 2 23 vpath Encapsulation Logical packet flow

Use Cases for Service Chaining Multiple Network Topologies Driven by Application Every application has its own network requirements and virtual topology Enables a policy based network topology that can vary by client and application Business Agility Changing networks to reflect new business conditions typically takes weeks to execute thus limiting how quickly a business can react A software defined topology can be imposed almost instantly without any physical reconfiguration. 24

VMDC CVD VSA 1.0 VMDC CVD DCI 1.0 Cisco Validated Designs Virtualized Multiservice Data Center (VMDC)

Cisco VMDC: Virtual Multi Service Data Center CVDs incorporating NetScaler VMDC Virtual Services Architecture (VSA) 1.0 Logical topology optimized for higher tenancy Incorporates NetScaler VPX VMDC Data Center Infrastructure (DCI) 1.0 Virtual private cloud tenant containers in shared data center Incorporates NetScaler SDX Available on www.cisco.com/go/vmdc 26 Citrix NetScaler is ADC for VMDC CVDs

Cisco Prime Network Services Controller NetScaler Integration via OpenStack Prime Network Services

Cisco Prime Network Services Controller Able to configure NetScaler using Openstack APIs 28

Cisco Prime Network Services Controller Configures NetScaler using Openstack APIs NetScaler VPX supported today Configuration from Prime NSC NetScaler 1000V Q2 2014* Configuration from Prime NSC Virtual NetScaler instance creation from Prime controller using Openstack NetScaler 1000V is part of Cisco Cloud Service Cisco Intercloud http://blogs.cisco.com/news/introducing ciscos global intercloud/ 29

Nexus 7000 RISE Integration Cisco RISE N7K Integration with Citrix NetScaler Data Center Automation

Data Center Switching and L4-L7 ADC Services L4-L7 ADC services haven t kept up with L2-L3 switching speeds Switching speeds are Terabit / sec ADC speeds are Gigabit / sec Rules out inline ADC deployments One-arm NetScaler deployments are typical 70-80% of deployments are one-arm 31

One Arm Deployment Challenges Managing traffic flows to the NetScaler is challenging Managing static routes on N7K for application or VIP traffic can be tedious to maintain Manually maintaining Policy Based Routing rules is time consuming, complex, and error prone SNAT rewrites client Source IP, causing loss of Client IP visibility Audit / compliance issue NetScaler services and Nexus switching are configured independently Increases the complexity for deploying and maintaining networks Configuring multiple appliances individually can be a burden Requires additional change control windows Challenge: Provide low touch, automated mechanism to overcome these issues 32

http://www.cisco.com/c/dam/en/us/products/collateral/switches/nexus-7000-series-switches/white-paper-c11-731370.pdf 33

NetScaler Nexus 7000 Integration Benefits Simplification Data Center Automation Simplified Out of Box Experience Signification OPEX Reduction Automated Route Updates Internet 34 Reduces Initial Deployment Steps Simplifies One Arm Mode, Optimizes Traffic Flows in DC, Preserves Client IP Improves Availability, Reduces Downtime vs Dynamic Routing Protocols Integrates L2 L3 Network and ADC in Data Center

Cisco ACI / APIC Nexus 9000 ACI APIC

ACI DRIVING BUSINESS TRANSFORMATION APPLICATIONS BYOD MOBILE COMMON POLICY DECOUPLE APPLICATION & POLICY FROM IP INFRASTRUCTURE CIO IP NETWORK BUSINESS DECISIONS Time Governance SLA Audit Cost 36

APPLICATION CENTRIC INFRASTRUCTURE Nexus 9500 APIC Nexus 9300 and 9500 Physical Networking Hypervisors and Virtual Networking Compute L4 L7 Services Storage Multi DC WAN and Cloud Nexus 7K Nexus 2K Integrated WAN Edge 37

APIC Application Policy Infrastructure Controller Open APIs APIC ACLs PCI Compliant Services Chaining Is Automated Manage Policy Via API and Can Export Policy via API Policy Is Separate from the Network Easy to Isolate with Full Scalability and Security Engineering / Dev and Testing Legal HR Sales Finance Marketing 38

APIC Application Policy Infrastructure Controller Cisco APIC is single point of automation and fabric element management Common policy, management and operations interface Application control and automation over both physical and virtual networking components 39 NetScaler integrates with Cisco APIC for L4 L7 ADC

CISCO APIC CITRIX NETSCALER INTEGRATION NetScaler configured from APIC, based on APIs Deep NetScaler integration for per app, per tenant L4 L7 policy configuration Cisco service chaining and service insertion Telemetry information exchange Intelligent telemetry and visibility for applications and tenants 40

Available Now. In Development. Prime Available Now. Nexus 1k Integration Available Now. Available Now. Available Now. Nexus 7k Integration In Development. ACI / 9k Available Now. Code Donated to Linux Foundation Available Now. 41

Citrix NetScaler Preferred ADC for Cisco Nexus Sold and supported by Cisco Nexus 1000v vpath Integration Nexus 7000 RISE Integration Nexus 9000 ACI Integration 42

ACE migration program Eligible Cisco Products Cisco ACE Module or Appliance Cisco Contetn Services Switch (CSS) Cisco Content Switch Module (CSM) Cisco Global Site Selector (GSS) 43

NetScaler and the 4 Feature Buckets Clients Internet NS Server 44 Acceleration Security Availability Offload TCP Optimization Web Compression Cache (Static and Dynamic) DDos Protection Content Filtering and Redirection Web Application Firewall SSL VPN Load Balancing Layer 4 and Layer 7 Global Server Load Balancing Content Rewrite and Redirection Surge Protection and Sure Connect TCP Multiplex and Reuse SSL Offload Cache (Static and Dynamic) Consolidated Web Logging TCP Buffering

Layer 4 Load Balancing TCP and UDP Client Requests Maintaining User Sessions Distributing Traffic Monitoring Server Health and Availability Source IP Cookie SSL Session ID Server-ID in URL Query Customer Server-ID Token (header or body) Least Connections Lowest Response Time SNMP-based IBM SASP Hash-based Many more TCP Connection HTTPS Connection Extended Content Verification Scriptable Health Checks 45

Content Switching: Load Balancing on Steroids HTTP Requests Client Attributes Anything in request body Device Type Language Cookie Browser Capability XML XPath support Request Protocol Any TCP Request HTTP Get HTTP Post Request Method Any TCP payload value Any HTTP payload value Domain Wildcard URL 46

Global Application Availability Site A B2C B2B Site B P2P 47

Accelerated Application Delivery CUSTOMERS SSL PARTNERS EMPLOYEES Advanced TCP Optimization Static and Dynamic Caching Hardware Compression Enhanced User Productivity 48

Reduced Load on Servers CUSTOMERS SSL PARTNERS EMPLOYEES SSL Offload TCP Multiplexing and Buffering Static and Dynamic Caching Hardware Compression Supports greater user capacity and more apps with minimal investment 49

Common issues Connection handling Ability to modify DB query contents Scalability Performance Distributing access to replicated databases Securing SQL queries against injection/other attacks Availability Databases Security Need for caching the query results 50

This image cannot currently be displayed. This image cannot currently be displayed. This image cannot currently be displayed. This image cannot currently be displayed. NetScaler DataStream in Database Tier Web/App Tier DB Tier NetScaler DataStream TM TDS Protocol aware Internet Custom Scripts Connection Scale Up Optimal Scale Out Native HTTPSQL TCP Improved Availability High Availability Scalability Conn Multiplexing App Security Content Switching High High Performance Availability No Simple HA HA Simple No LB LB Custom Monitors Microsoft SQL Server HTTP NetScaler ADC ADC TCP Load Balancer 51

Expanded IPv6 Support Best IPv6 performance IPv4 IPv6 Gateway Facilitates transition from IPv4 to IPv6 Mixed IPv4/IPv6 Support 52

Action Analytics NetScaler Insight Center Visibility and Control NetScaler App Delivery Fabric Mobile Devices Netscaler Command Center Management and Orchestration Virtual desktops Web apps Cloud services Data services 53

Achieving Application Visibility with NetScaler 3 rd Party Analysis Tools NetScaler Insight Center Cloud Enterprise Combining NetScaler with Analysis Tools NetScaler generates a wealth of application visibility data by way of AppFlow NetScaler Insight Center is the best way to view Citrix specific data Desktop 54

Web Insight Analytics for Enterprise Applications Break down detailed reporting on enterprise application use, even for SSL encrypted traffic Correlate network metrics with application behavior Determine end user experience without agents NetScaler Insight Center AppFlow 55

NetScaler WAF Web application security & DDoS protection Comprehensive ICSA certified web application security solution Hybrid security model PCI compliance and auditing requirements Protection vs XML based threats Integration with 3rd party vulnerability testing tools for simplified deployment Cenzic Qualys Whitehat IBM AppScan 56 56

Physical Price Performance Virtual Run Anywhere Platform Multi Service Multi Tenant 57

Cisco / Citrix Mobile Workspaces CVD Mobile Workspaces CVD 1.0

Cisco Mobility Workspace Solution with Citrix Infrastructure ShareFile Managed StorageZone CT 5760 NAT Shared Svcs. 6500 Core 6500 AD ISE CA UCS C Series 1 UCS C Series 2 Remote Users ASA Out Remote users appear to be local when AC Client used. AC Client required for access to WorxStore and StoreFront. XenMobile Device Mgr ASA In & SSLVPN I Edge 6500 Dist 6500 DC Core/Agg 7000 XenMobile App Ctl used for AD SSO with ShareFile StoreFront 2.0 XenDesktop 7.0 XenMobile 8.6 App Cntl ShareFile 2.0 Local SZ Ctl Local Users Access 59

This image cannot currently be displayed. This image cannot currently be displayed. This image cannot currently be displayed. Cisco Mobility Workspace Solution w/citrix 1.0 Components AnyConnect SZ CTL ShareFile StorageZone XenMobile Enterprise Edition NAT ASA Firewall External Firewall NAT translation for SAML Asserts Internal Firewall AnyConnect Remote Access VPN Clientless WEBVPN Full Access both cert and AD required for AuthC Partial Access via AD for AuthC DMZ MDM XenDesktop 7.0 Accessed via StoreFront 2.0 Server OS Machine Catalogs Providing ShareFile access per desktop Role Based Apps Access from: Internal Users External Users via ASA/AnyConnect StoreFront PAN StoreFront 2.0 Access to XenDesktop 7.0 Receiver Client Several Windows Apps MnT ISE Deployment XenDesktop XenDesktop 7.0 Block with App Store PSN Data Center XenMobile Ent 8.6 Device Management Mobile application deployment Device Management Redirects device for AC download, pushes profile and cert for Auth App Controller 2.9 Providing: SAML AD integration for ShareFile Access to: ShareFile Evernote StoreFront Apps/Receiver Access from: Internal Users External Users via ASA/AnyConnect APP CTL SZ CTL CA AD BYOD Services ShareFile SAML FS with App Ctl. ShareFile StorageZone RSA DNS DHCP ShareFile 2.0 Enterprise File Sharing for XenDesktop VDI AD integration through App Contl 2.9 60

Demo Mobile Workstyles 61

Work better. Live better.