STORMY WEATHER SECURING CLOUD COMPUTING. Russell Skingsley Director of Advanced Technology Data Centre and Cloud, APAC Juniper Networks



Similar documents
Secure Cloud-Ready Data Centers Juniper Networks

Expert Reference Series of White Papers. vcloud Director 5.1 Networking Concepts

White Paper. Juniper Networks. Enabling Businesses to Deploy Virtualized Data Center Environments. Copyright 2013, Juniper Networks, Inc.

Lecture 02b Cloud Computing II

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

Cloud Networking From Theory to Practice" Ivan Pepelnjak NIL Data Communications"

White Paper. Protect Your Virtual. Realizing the Benefits of Virtualization Without Sacrificing Security. Copyright 2012, Juniper Networks, Inc.

Data Center Network Virtualisation Standards. Matthew Bocci, Director of Technology & Standards, IP Division IETF NVO3 Co-chair

VXLAN Overlay Networks: Enabling Network Scalability for a Cloud Infrastructure

Securely Architecting the Internal Cloud. Rob Randell, CISSP Senior Security and Compliance Specialist VMware, Inc.

AGENDA. 資 訊 網 路 發 展 趨 勢 Juniper Cloud Solution Cloud Security 解 決 方 案 共 同 供 應 契 約 採 購 建 議 為 何 選 擇 Juniper

雲 端 發 展 與 安 全 趨 勢. 陳 建 宏 Jovi Chen 技 術 顧 問 2011 Check Point Software Technologies Ltd. [Unrestricted] For everyone

Achieving a High-Performance Virtual Network Infrastructure with PLUMgrid IO Visor & Mellanox ConnectX -3 Pro

Expert Reference Series of White Papers. VMware vsphere Distributed Switches

Analysis of Network Segmentation Techniques in Cloud Data Centers

Virtual Firewalls. Ivan Pepelnjak NIL Data Communications

VXLAN: Scaling Data Center Capacity. White Paper

Palo Alto Networks. Security Models in the Software Defined Data Center

5 Best Practices to Protect Your Virtual Environment

Secure Cloud Computing with a Virtualized Network Infrastructure

Using LISP for Secure Hybrid Cloud Extension

VMware vsphere-6.0 Administration Training

Virtual Machine in Data Center Switches Huawei Virtual System

VMware Network Virtualization Design Guide. January 2013

Network Troubleshooting & Configuration in vsphere VMware Inc. All rights reserved

Virtualization, SDN and NFV

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

VXLAN, Enhancements, and Network Integration

ConnectX -3 Pro: Solving the NVGRE Performance Challenge

Ethernet-based Software Defined Network (SDN) Cloud Computing Research Center for Mobile Applications (CCMA), ITRI 雲 端 運 算 行 動 應 用 研 究 中 心

TRILL for Data Center Networks

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

Nutanix Tech Note. VMware vsphere Networking on Nutanix

JUNIPER NETWORKS CLOUD SECURITY

DEPLOYMENT GUIDE Version 1.2. Deploying the BIG-IP v10.2 to Enable Long Distance Live Migration with VMware vsphere vmotion

SDN CONTROLLER. Emil Gągała. PLNOG, , Kraków

VLAN 802.1Q. 1. VLAN Overview. 1. VLAN Overview. 2. VLAN Trunk. 3. Why use VLANs? 4. LAN to LAN communication. 5. Management port

AN INTEGRATED SECURITY SOLUTION FOR THE VIRTUAL DATA CENTER AND CLOUD

Virtual LANs. or Raj Jain

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

SOLUTIONS FOR DEPLOYING SERVER VIRTUALIZATION IN DATA CENTER NETWORKS

Protecting Physical and Virtual Workloads

VMware. NSX Network Virtualization Design Guide

DMZ Virtualization Using VMware vsphere 4 and the Cisco Nexus 1000V Virtual Switch

NVGRE Overlay Networks: Enabling Network Scalability for a Cloud Infrastructure

Software Defined Network (SDN)

Architecting and Building a Secure and Compliant Virtual Infrastructure and Private Cloud

VLANs. Application Note

VMware Software Defined Network. Dejan Grubić VMware Systems Engineer for Adriatic

DEPLOYMENT GUIDE Version 1.0. Deploying the BIG-IP v10.2 to Enable Long Distance VMotion with VMware vsphere

Network Virtualization and Data Center Networks Data Center Virtualization - Basics. Qin Yin Fall Semester 2013

How To Orchestrate The Clouddusing Network With Andn

Microsegmentation Using NSX Distributed Firewall: Getting Started

Secure Virtual Network Configuration for Virtual Machine (VM) Protection

How to Configure an Initial Installation of the VMware ESXi Hypervisor

How to Create VLANs Within a Virtual Switch in VMware ESXi

Install Guide for JunosV Wireless LAN Controller

JUNIPER. One network for all demands MICHAEL FRITZ CEE PARTNER MANAGER. 1 Copyright 2010 Juniper Networks, Inc.

VM-Series for VMware. PALO ALTO NETWORKS: VM-Series for VMware

JUNIPER NETWORKS FIREFLY HOST FIREWALL PERFORMANCE

Virtualized Access Layer. Petr Grygárek

CLOUD NETWORKING FOR ENTERPRISE CAMPUS APPLICATION NOTE

How Network Virtualization can improve your Data Center Security

VMware NSX Network Virtualization Design Guide. Deploying VMware NSX with Cisco UCS and Nexus 7000

Implementing and Troubleshooting the Cisco Cloud Infrastructure **Part of CCNP Cloud Certification Track**

How To Set Up A Virtual Network On Vsphere (Vsphere) On A 2Nd Generation Vmkernel (Vklan) On An Ipv5 Vklan (Vmklan)

BUILDING A NEXT-GENERATION DATA CENTER

Programmable Networking with Open vswitch

NEC SigmaSystemCenter 3.0 highlights

Virtual Subnet: A Scalable Cloud Data Center Interconnect Solution

Introduction...3. Scope...3. Design Considerations...3. Hardware Requirements...3. Software Requirements...3. Description and Deployment Scenario...

Ixia Phantom vtap. Overview. Virtual Taps Phantom Monitoring Solution DATA SHEET

VMware ESX Server Q VLAN Solutions W H I T E P A P E R

Cross-vCenter NSX Installation Guide

Enabling Solutions in Cloud Infrastructure and for Network Functions Virtualization

Security Design.

What is VLAN Routing?

Configuring Virtual Switches for Use with PVS. February 7, 2014 (Revision 1)

Multitenancy Options in Brocade VCS Fabrics

Extending Networking to Fit the Cloud

Huawei Enterprise A Better Way VM Aware Solution for Data Center Networks

Introduction to Virtual Datacenter

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Top-Down Network Design

Apache CloudStack 4.x (incubating) Network Setup: excerpt from Installation Guide. Revised February 28, :32 pm Pacific

vshield Quick Start Guide

Cloud Networking: Framework and VPN Applicability. draft-bitar-datacenter-vpn-applicability-01.txt

Active Fabric Manager (AFM) Plug-in for VMware vcenter Virtual Distributed Switch (VDS) CLI Guide

Walmart s Data Center. Amadeus Data Center. Google s Data Center. Data Center Evolution 1.0. Data Center Evolution 2.0

NVO3: Network Virtualization Problem Statement. Thomas Narten IETF 83 Paris March, 2012

About the VM-Series Firewall

Secure Virtual Network Configuration for Virtual Machine (VM) Protection

WHITE PAPER. Network Virtualization: A Data Plane Perspective

Adopting Software-Defined Networking in the Enterprise

An Oracle White Paper April Network Isolation in Private Database Clouds

Transcription:

STORMY WEATHER SECURING CLOUD COMPUTING Russell Skingsley Director of Advanced Technology Data Centre and Cloud, APAC Juniper Networks

DISCLAIMER These are not necessarily the views of Juniper Networks even though I have pilfered some of their slides for my own nefarious purposes. 2 Copyright 2012 Juniper Networks, Inc. www.juniper.net

TRADITIONAL DC NETWORK SECURITY Big Bad World Security Complex 802.1Q Switching Complex VLAN A VLAN B VLAN C Server 1 Server 2 Server 3 3 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE PRINCIPLE OF CONSOLIDATION PER SERVER Waste Waste Waste Waste Waste Physical Servers Virtualised Server 4 Copyright 2012 Juniper Networks, Inc. www.juniper.net

LARGER POOL, MORE CONSOLIDATION Waste Waste Waste Waste Waste Physical Servers Virtualised Servers 5 Copyright 2012 Juniper Networks, Inc. www.juniper.net

SAME PRINCIPLE, FOR WHOLE DATA CENTERS Small DCs Consolidated DCs 6 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE ECONOMICS OF THE DATA CENTER Physical Server Installed Base (Millions) Logical Server Installed Base (Millions) Complexity and Operating Costs Capital Savings Millions Installed Servers 80 60 40 20 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 0 Source: IDC 7 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE ECONOMICS OF THE DATA CENTER 8 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE NEW EDGE Physical Network 802.1Q 802.1Q 802.1Q VMKernel VMKernel VMKernel vds VM1 VM2 VM3 VM4 VM5 VM6 VM7 VM8 VM9 ESX1 ESX2 ESX3 9 Copyright 2012 Juniper Networks, Inc. www.juniper.net

VLAN LIMITATIONS DA SA 802.1Q Type or Length Data FCS 32 Bits Tag Protocol Identifier (0x8100) Priority (802.1p) Canonical Format Indicator VLAN ID 16 Bits 3 Bits 1 Bit 12 Bits 10 Copyright 2012 Juniper Networks, Inc. www.juniper.net

SCALING BEYOND 4K TENANTS BRIDGE DOMAINS VDC 1 Core VDC Switch 2 VDC 3 1-4000 1-4000 1-4000 Distribution Switch Distribution Switch Distribution Switch Access Switch Access Switch Access Switch Access Switch Access Switch Access Switch Mobility Extent Mobility Extent Mobility Extent 11 Copyright 2012 Juniper Networks, Inc. www.juniper.net

SCALING BEYOND 4K TENANTS VCD-NI DC Switching Access Access Access Access VLAN 5 VLAN 5 VLAN 5 VLAN 5 MAC 1 MAC 2 MAC 3 MAC 4 ESXi ESXi ESXi ESXi MAC 1:1 MAC 1:2 MAC 2:1 MAC 3:1 MAC 4:1 MAC 4:2 VM1 VM1 VM2 VM2 VM3 VM3 Mobility Extent 12 Copyright 2012 Juniper Networks, Inc. www.juniper.net

VCD-NI PORTGROUP LABELS dvs.<vcenterid><ds#><vcd#><vlan><network ID><Name> <Network ID> is a 24 bit value expressed in Hexadecimal (This is sometime referred to as a fence ID) For Example: dvs.vc1012345678dvs3cm1-v32-c2e-coke Org1 13 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE NEW EDGE WITH TUNNELS Physical Network 802.1Q 802.1Q 802.1Q VMKernel VMKernel VMKernel vds VM1 VM2 VM3 VM4 VM5 VM6 VM7 VM8 VM9 ESX1 ESX2 ESX3 14 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE BROADCAST RADIATION WILL KILL US ALL Physical Network 802.1Q 802.1Q 802.1Q X VMKernel X VMKernel X VMKernel vds X X VM1 VM2 VM3 VM4 VM5 VM6 VM7 VM8 VM9 ESX1 ESX2 ESX3 15 Copyright 2012 Juniper Networks, Inc. www.juniper.net

REMEMBER THESE RULES OF THUMB? Max IP hosts per subnet 500 Max IPX Hosts per subnet 256 Max Appletalk hosts per subnet - 128 http://docwiki.cisco.com/wiki/internetwork_design_guide_--_broadcasts_in_switched_lan_internetworks 16 Copyright 2012 Juniper Networks, Inc. www.juniper.net

TIMES CHANGE SparcStation 2 28 MIPS 0.000392 MIPS used per host 500 Hosts Cost 0.7% of CPU Ivy Bridge Xeon 180,000 MIPS 0.000392 MIPS used per host 3.2 Million Hosts cost 0.7% of CPU 17 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE BROADCAST RADIATION WONT KILL US ALL Physical Network 802.1Q 802.1Q 802.1Q X VMKernel X VMKernel X VMKernel vds X X VM1 VM2 VM3 VM4 VM5 VM6 VM7 VM8 VM9 ESX1 ESX2 ESX3 18 Copyright 2012 Juniper Networks, Inc. www.juniper.net

SECURITY IMPLICATION OF VIRTUALIZATION Physical Network Virtual Network VM1 VM2 VM3 Virtual Switch ESX Host HYPERVISOR Security Complex Sees/Protects All Traffic Between Servers Physical Security is Blind to Traffic Between Virtual Machines 19 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THIS IS HOW WE HAVE BUILT DATA CENTRES WAN Routing 3840 Gbps Security 120 Gbps Switching 40900 Gbps Compute 122000 Gbps 20 Copyright 2012 Juniper Networks, Inc. www.juniper.net

NETWORK THROUGHPUT IS A DIFFERENT STORY WAN Routing Switching Compute 21 Copyright 2012 Juniper Networks, Inc. www.juniper.net

APPROACHES TO SECURING VIRTUAL NETWORKS 1. VLAN Segmentation 2. Agent-based 3. Kernel-based VMs segmented into separate VLANs; Inter-VM communications must route through the firewall Drawbacks: Complex VLAN networking; Lacks hypervisor visibility; High overhead VM1 VM2 VM3 Each VM has a software firewall Drawbacks: Significant performance implications; Huge management overhead of maintaining software and signature on 1000s of VMs VM1 VM2 VM3 Inter-VM traffic always protected; Micro-segmenting capabilities High-Performance from implementing firewall in the kernel Secures Hypervisor connections VM1 VM2 VM3 VS ESX Host VS ESX Host FW as Kernel Module ESX Host HYPERVISOR HYPERVISOR VS HYPERVISOR FW Agents 22 Copyright 2012 Juniper Networks, Inc. www.juniper.net

THE NEW EDGE OPPORTUNITIES AND CHALLENGES FOR ALL Physical Network 802.1Q 802.1Q 802.1Q VMKernel VMKernel VMKernel vds VM1 VM2 VM3 VM4 VM5 VM6 VM7 VM8 VM9 ESX1 ESX2 ESX3 23 Copyright 2012 Juniper Networks, Inc. www.juniper.net

Russell Skingsley skingsrw@juniper.net