ESG Solution Showcase Citrix: NetScaler and CloudBridge Solutions on AWS Date: September 2015 Author: Mark Bowker, Senior Analyst; and Leah Matuson, Research Analyst Abstract: With exploding data growth, application modernization, and increasing system complexity, organizations are looking to the cloud for financial, operational, and general business benefits. And, while many enterprises live in the hybrid cloud (a combination of public and private cloud infrastructures), IT still must address the challenges of dealing with system and data security, manageability, performance, and reliable network access challenges that have IT scrambling to find the most appropriate, cost-effective solutions. So how can organizations address these challenges? With a combination of complementary Citrix technology solutions, NetScaler and CloudBridge, working with Amazon Web Services (AWS) and Amazon Direct Connect. AWS Direct Connect enables an organization to establish a dedicated network connection between its network and AWS, establishing private connectivity between AWS and its on-premises data center. Citrix NetScaler and CloudBridge offer security, performance, manageability, high availability, and governance for organizations deploying applications in the cloud, helping to implement a secure, high-performance hybrid cloud between an organization s data center and AWS. Overview In today s data centers, organizations aren t just consuming local, on-premises infrastructure; they re increasingly taking advantage of the numerous benefits of cloud consumption models, and using them to create a reliable and performant network infrastructure that will withstand their performance expectations. With exploding data growth, rising application demand, and increasing system complexity, more organizations are looking to the cloud for its financial, operational, and general business benefits. Enterprises can enjoy the economics of the cloud without giving up operational control. From easily augmenting production through attaining the agility needed for development and testing, to having the ability for quick and positive resolution in disaster recovery scenarios, the benefits of the cloud for infrastructure are apparent. It s very common for businesses and, therefore, IT organizations to rapidly respond to changes. Production systems must ramp up and down quickly, so scalability and network connectivity is essential. In the world of dev/test, project teams need to be agile, developers can t afford to wait out delays for IT to provision systems, and systems need to quickly scale to production loads (as dev/test workloads are transitory by nature, spikey in usage, and don t contain a high volume of data subject to governance/compliance). On a larger scale, organizations need to think carefully about application lifecycle management. Developers, application architects, and IT all need to consider what they will require in an application platform so that it can be used efficiently in every stage of the lifecycle from development to test/qa, and stage to production. In addition, application availability and level of performance need to be taken into consideration as IT formulates disaster recovery (DR) plans. This ESG Solution Showcase was commissioned by Citrix and is distributed under license from ESG.
Solution Showcase: Citrix: NetScaler and CloudBridge Solutions on the AWS Cloud 2 Disaster recovery is one of the primary motivators for cloud consumption. The potential ability to be able to throw a switch and use the public cloud in a DR scenario is invaluable. IT organizations need to consider geographical and application interdependencies and networking architecture to ensure a high-quality DR failover experience for end-users. Applications, data, and even desktop environments can all be made available in this scenario. In fact, as discovered in previously conducted ESG research, data protection is one of the most common IaaS use cases among those organizations currently leveraging cloud infrastructure services. 1 Specifically, nearly half of these users report storing backup and archive data in the cloud (44%) and/or utilizing these services as offsite disaster recovery targets (44%) (see Figure 1). Figure 1. Cloud Infrastructure Service Use Cases For which of the following purposes does your organization use cloud infrastructure services? (Percent of respondents, N=187, multiple responses accepted) Data backup and archive Disaster recovery Test and development 44% 44% 43% Business intelligence/analytics Primary storage for files Run internally/externally-facing Web servers Additional resource to accommodate spikes in workload Run internal production applications Use as temporary compute resources for timelimited projects Use for high-performance and/or scientific computing applications Application bursting 37% 36% 35% 33% 33% 30% 28% 27% 0% 10% 20% 30% 40% 50% Deploying the Hybrid Cloud the Performance and Networking Challenge Source: Enterprise Strategy Group, 2015. Today, many enterprises live in the hybrid cloud, a combination of public and private cloud infrastructures. By doing so, organizations leverage the best of both clouds relying on the public cloud for non-sensitive operations, and on the private cloud for business-critical ones. No longer must organizations rip and replace their existing hardware and software footprints as their requirements change; they can link old and new, offering substantial CapEx and OpEx savings as well as providing IT with the agility to scale up or down as business requirements change. 1 Source: ESG Research Report, 2014 Public Cloud Computing Trends, March 2014.
Solution Showcase: Citrix: NetScaler and CloudBridge Solutions on the AWS Cloud 3 But what about system and data security, manageability, and reliable network access? This eternal question has IT scrambling to find the most appropriate, cost-effective solutions. And while securing and managing data are certainly high on the list of IT concerns, these concerns are generally invisible to end-users. Performance is also one of IT s top concerns; but unlike securing and managing data, performance outwardly affects every group within an organization. This means IT must be able to ensure optimum application performance and high availability for end-users to consistently receive a quality experience in which productivity is not impacted. And don t forget network latency that also adds to IT s performance challenge. So how can organizations effectively address these challenges? With a combination of complementary Citrix technology solutions in conjunction with Amazon Web Services (AWS). Amazon Web Services With its wide ranging set of services for compute, storage, database, analytics, deployment, and apps, AWS enables organizations to securely configure, control, and manage everything from operating systems to applications, with the ability to build hybrid cloud architectures, spin up new servers in minutes, scale capacity, and ensure compliance. As IT organizations embrace these services they also have to plan for enterprise-scale networks to be architected with application deployment in the cloud in mind. The benefits of AWS are numerous, but how can an organization ensure a secure connection between its network and AWS? Enter AWS Direct Connect. AWS Direct Connect AWS Direct Connect enables an organization to establish a dedicated network connection between its network and AWS. With AWS Direct Connect, an organization can establish private connectivity between AWS and its data center inclusive of a colocation environment, reducing costs, increasing network throughput, and providing a consistent network experience. Using industry-standard 802.1g VLANS, the dedicated connection can be partitioned into multiple virtual interfaces, which means organizations can use the same connection to access public resources using public IP address space, and the same connection to access private resources using private IP space, all while maintaining network separation between public and private environments. Most organizations are constantly looking for ways to reduce network costs and latency. Direct Connect can help. Running bandwidth-heavy workloads in the cloud? AWS Direct Connect may reduce network costs. By transferring data to and from the cloud directly, an organization may be able to reduce its bandwidth commitment to its Internet service provider since data transferred over the organization s dedicated connection is charged at reduced AWS Direct Connect data transfer rates, not at Internet data transfer rates. Direct Connect also reduces network latency and throughput by allowing IT to select which data should be using the dedicated connection and how that data is routed providing a more consistent network experience over Internet-based connections. Citrix Networking Solutions for AWS Many enterprises have similar business and IT challenges and needs. How can we increase application performance and availability? Improve security? Decrease downtime? Lower operational expenses, leverage the public cloud, and plan for growth? It probably sounds familiar, albeit somewhat daunting. But it doesn t have to be. Citrix NetScaler and CloudBridge help to solve the pain points for enterprise customers who are looking to the cloud or are already using the cloud. These solutions offer security, performance, manageability, high availability, and governance for organizations in the cloud, helping to implement a secure, high-performance hybrid cloud between the organization s data center and AWS. NetScaler and CloudBridge offer value to AWS by providing organizations with streamlined global load
Solution Showcase: Citrix: NetScaler and CloudBridge Solutions on the AWS Cloud 4 balancing and high availability. While AWS offers some basic firewalling and load balancing capabilities, Citrix extends the architecture into the on-premises data center. Citrix NetScaler Citrix NetScaler is an all-in-one application delivery controller that optimizes, secures, and controls the delivery of enterprise and cloud services. The solution provides a scalable and highly available platform for organizations to run applications and services, enabling an enhanced user experience for all users, including mobile clients. NetScaler provides visibility and centralized management; optimizes virtual desktop/application environments; simplifies management and support; and reduces the complexity generally associated with using multiple vendors for remote access. NetScaler offers: Accelerated performance and quick applications delivery. NetScaler s advanced web compression (for both static and dynamically generated data) reduces network bandwidth requirements, resulting in quicker response times. An integrated cache provides in-memory storage, so users can receive content swiftly and simply. Caches for static and dynamic content can be set up easily to store and serve content by Web and application servers. Security, in the form of secured network, systems, and applications. With NetScaler s web application firewall, device vulnerabilities from any number of threats are blocked, including DDoS, SQL injection, web services applications, cross-site scripting, and buffer overflow threats. Increased availability. To improve the efficiency of server and network resources, NetScaler provides optimum application and service availability using load balancing and content switching. Load balancing gives IT the option to choose how the network load is distributed between back-end resources, such as web servers. For example, say you have three identical web servers with the same content loaded on each of them for redundancy. NetScaler can direct traffic to those servers evenly to ensure that one server doesn t get inundated with requests that could cause a slowdown or crash the site. Streamlined traffic management. Most organizations restrict web access to valid users, controlling the level of access of each user. NetScaler provides security for a distributed Internet environment, incorporating authentication, authorization, and auditing for all applications. Time and resources are saved by allowing IT to manage access controls using only NetScaler (rather than having to dedicate countless hours managing every control for every application separately). Reduced load time and web page render time. Both load time and render time are reduced by simplifying and optimizing HTML content, including cascading style sheets (CSS), JavaScripts, and images embedded within HTML content. In essence, Citrix NetScaler on AWS enables enterprises to rapidly and cost-effectively leverage NetScaler application delivery capabilities within their AWS deployments. NetScaler on AWS combines the elasticity and flexibility of the AWS cloud with the same optimization, security, and control that NetScaler provides for websites and applications. Businesses can achieve the same level of application performance in cloud but the architecture and design requires additional consideration. NetScaler helps with the design, deployment and management of a hybrid cloud solution. IT can operate across on-premises infrastructure and in cloud services. By designing the network to embrace hybrid cloud, IT can deliver a seamless and transparent user experience no matter where the user is or where the apps are running.
Solution Showcase: Citrix: NetScaler and CloudBridge Solutions on the AWS Cloud 5 If an application should fail, the business is protected since IT has replicated the application in two different AWS Zones and business operations can continue as the other zone seamlessly takes over. For some enterprises, this is not enough. One region can have multiple zones. What if a region fails? This organization will want cross-region high availability however, this poses a technical challenge for the application designer. This is where NetScaler adds additional value with GLSB to achieve a high level of availability in the AWS cloud across regions. NetScaler enables enterprises to deploy business applications in HA mode within the same availability zone to protect from an application failure. However if the zone fails, both applications fail. Therefore, they can deploy across zones or regions for different levels of reliability. In this case, NetScaler can use GSLB to support HA across zones or Regions. In this hybrid model, applications can be deployed in the cloud and on-premises supported by GSLB with HA. Citrix CloudBridge With business being transacted anywhere, anytime, and on any device, IT needs to ensure the performance and reliability of mission-critical applications for the remote workforce. Citrix CloudBridge can help virtualize your organization s WAN and make it ready to connect to the cloud. CloudBridge can increase WAN throughput capacity, decrease bandwidth requirements, improve scalability, and reduce costs, while improving the performance of business-critical applications like VDI, application virtualization, VoIP, video conferencing, ERP, and CRM. How? By optimizing and encrypting connections between the enterprise data center, branch locations, and AWS, CloudBridge secures the connection, speeds data transfer, and minimizes network costs, optimizing the data transfer and synchronization between various on-premises data centers and AWS environments. CloudBridge can: Expand WAN capacity through WAN virtualization with low-cost broadband connections. This ensures consistent application performance without having to provision dedicated network connections Improve the virtual desktop experience for users, accelerating traditional enterprise applications including Microsoft Exchange and SharePoint, as well as ERP, CRM, CAD, SSL, e-mail, file transfers, storage replication, and data backup. Maintain high performance for business-critical apps, regardless of a failing network connection. Ensure data is protected by supporting cloud connectivity with integrated security. Manage the user experience by gaining visibility into application delivery from the cloud. Reduce the server footprint with integrated Windows Server options. Citrix CloudBridge also helps build hybrid clouds across enterprise data centers and the public cloud via an internal feature, the CloudBridge Connector. Using Citrix CloudBridge Connector in the data center with AWS, an enterprise can build a cloud-extended data center, creating bridges to connect one or more virtual private clouds (VPCs) to its network without the inconvenience of having to reconfigure its data center. Cloud-hosted applications look as though they are running on a single enterprise network, with seamless connectivity between the existing data center and applications hosted in the private cloud infrastructure, or between the two cloud frameworks. In addition, networks connected by a CloudBridge Connector function like a single network, and appear transparent to the user.
Solution Showcase: Citrix: NetScaler and CloudBridge Solutions on the AWS Cloud 6 Citrix NetScaler and CloudBridge Together Citrix NetScaler is a secure application, desktop, and data access solution providing IT with granular application-level and device-level policy and action controls over access to corporate content. Working together, Citrix NetScaler and Citrix CloudBridge can provide your mobile and remote workforce with an enhanced user experience. How? The CloudBridge plug-in speeds application response through the IPSec tunnel, which provides the combination of secure and accelerated access to applications, desktops, and data. Now that you ve learned about the benefits of using Citrix solutions on AWS, here are three key use cases where you could potentially apply them. Augmenting Production There may be times when you need to keep sensitive, business-critical, and proprietary data on-premises for regulatory and compliance purposes, or because of your investments in that piece of infrastructure, and the applications on which the infrastructure is relying. So what can you do to leverage the public cloud AWS? You need to split up your applications and data, keeping sensitive applications and data on-premises, with non-sensitive ones in the public cloud. You could run web servers in the cloud environment (the front-end that users see), but users will still have direct communication with data that is actually on-premises. From an IT perspective, you don t need to be concerned with having additional servers inside your data center with endusers accessing them directly. End-users can go to the web services set up on AWS, and still enjoy a direct connection to your on-premises servers. Doing this, you ve leveraged your existing resources that live in your on-premises data center. Now, you can take advantage of the flexibility the public cloud has to offer, and leverage the better economics garnered from using the public cloud. While you know what you need to do, how can you do it simply and transparently? To ease the transition of applications and workloads between on-premises and the AWS cloud, you ll need an intelligent way to perform database load balancing to improve availability; visibility into your applications; and real-time monitoring for immediate, actionable response. Using NetScaler and CloudBridge together provides enterprises with a comprehensive solution. NetScaler DataStream offers intelligent load balancing, CloudBridge AppFlow provides on-premises application visibility, and NetScaler ActionAnalytics uses data monitoring to turn mountains of real-time data into actionable information. Development and Testing Your production environment is running on-premises, but your developers can obtain access to resources much more easily from the public cloud. They may be using the AWS public cloud to run their development projects, spending time engineering and architecting, or building new applications. But the data they re using in the cloud needs to be secure, and consistent with your on-premises data. So your developers really need to be able to replicate the production, on-premises network management configuration in the cloud-based R&D environment. Working with technologies such as NetScaler and CloudBridge, AWS Direct Connect can provide enterprises with a diminished latency connection so that developers can now perform production and testing scenarios in the AWS public cloud. Disaster Recovery When it comes to disaster recovery, organizations must plan ahead and consider the amount of time it s going to take for the replication of data, as well as how long it will take for the disaster recovery process itself to complete.
Solution Showcase: Citrix: NetScaler and CloudBridge Solutions on the AWS Cloud 7 When a disaster recovery event occurs, organizations will want to make sure they can seamlessly fail over to an application architecture that sits someplace totally different, like Amazon AWS, for example. Generally, a disaster recovery scenario will happen this way: The primary data center will go offline, and IT will fail over to resources already put in the cloud. Planning ahead is essential. While an organization might not own a secondary data center, there is an advantage to keeping a disaster recovery site in the cloud. The site can be set up at any time, with storage capacity consumption based on the replication schema and the processing capacity doesn t have to be paid for until the resources are consumed. Resources on the site must be reliable, highly available, and perform consistently. At the same time, employees, customers, and partners must be able to access the resources on the site. Citrix NetScaler can help. The solution can perform global load balancing; continuously monitor availability and performance; and maintain high availability between availability zones, regions, and/or an on-premises data center and the AWS public cloud. The Bigger Truth An increasing number of organizations are moving to the cloud to enhance economics, scalability, and agility. However, the IT challenges accompanying those benefits can be numerous dealing effectively with security, lifecycle management, network performance, and reliability are just a few. And today, with more businesses taking a hybrid cloud approach, another IT challenge is dealing with how cloud and on-premises data centers can seamlessly work with each other. While encouraging, the availability of various solutions and services that seem to address these challenges doesn t make it any easier for IT to automatically know which are the most appropriate, and which will answer the needs of their particular organizations. As a result of their in-depth knowledge of this subject, Citrix (with NetScaler and CloudBridge) and Amazon Web Services (with Direct Connect) are two companies that appear to be providing enterprises with the solutions needed to simplify and secure the cloud, as well as make it more cost-effective to conduct business there or in the hybrid cloud. Because every business decision has implications, determining what will work the best with the least number of consequences is vital. Citrix and AWS appear to be delivering highly functional, innovative IT technologies for the cloud, driving substantial business benefits for their customers and helping them become, and remain, competitive. All trademark names are property of their respective companies. Information contained in this publication has been obtained by sources The Enterprise Strategy Group (ESG) considers to be reliable but is not warranted by ESG. This publication may contain opinions of ESG, which are subject to change from time to time. This publication is copyrighted by The Enterprise Strategy Group, Inc. Any reproduction or redistribution of this publication, in whole or in part, whether in hard-copy format, electronically, or otherwise to persons not authorized to receive it, without the express consent of The Enterprise Strategy Group, Inc., is in violation of U.S. copyright law and will be subject to an action for civil damages and, if applicable, criminal prosecution. Should you have any questions, please contact ESG Client Relations at 508.482.0188. Enterprise Strategy Group is an integrated IT research, analysis, and strategy firm that is world renowned for providing actionable insight and intelligence to the global IT community. www.esg-global.com 2015 by The Enterprise contact@esg-global.com Strategy Group, Inc. All Rights Reserved. P. 508.482.0188