Infrastructure for more security and flexibility to deliver the Next-Generation Data Center Stefan Volmari Manager Systems Engineering Networking & Cloud
Today's trends turn into major challenges Cloud Services Web Applications Rich Media & Videos BYO & Consumerization 2
and lead to Data Center Transformation Trends Demands placed on Network Technology More mobile devices More applications More data volume More cloud services Fast Secure and Scalable Network Analytics Consolidation Automation Flexible Mobile Optimization Clustering Big Data Virtualization SDN Orchestration Service Chaining & Overlay Networks 3
From static to elastic Legacy Datacenter Cloud Datacenter Constantly behind Network-focused Overprovisioned Console-managed Complex to change DMZ for security Constantly redefined Application-focused Click-to-update Automated and orchestrated Services-oriented Security embedded in DNA 4
So why keep anything on-premise? Scale When you have scale that makes on premise cheaper than cloud based Security When you have unique security or regulatory requirements These will become the exception 5
Attributes of Datacenter.next What does success look like? Leverages cloud where it makes clear sense Managed services and service levels not simply systems and networks Application-focused networking and service chaining SLA s define minimum service requirements frugal, not cheap Trust and predictable behavior persists through multiple state changes With abundance, latency has become more important than bandwidth 6
Next-gen security models
What s needed for Datacenter.next security? Confidentiality, Integrity, Availability and Management Keep the Lights On Thwart Advanced Attacks Optimize Service Delivery Provide Business Value Support mobile/global workforce Run anywhere, optimized local performance Physical to virtual, enterprise to cloud Mesh networking, delegated admin End-to-end encryption / Always-on SSL Use of public cloud services Amazon, Azure, ShareFile Cloud directory and identity Automated and orchestrated Enable SDN, NFV and DevOps 8
Keep the Lights On Ensure service availability Global Server Load Balancing (GSLB) Clustering and high availability Priority Queuing for application-level QoS management Protect critical services Comprehensive DNSSEC protection SurgeControl to prevent server overload Mitigate DoS and DDoS attacks 9
Advanced Threats Block web-specific attacks Web Application Firewall - Protects HTTP, XML, SQL, dynamic content and session state (including cookies) HTTP re-write and Responder - Custom request/response policies tuned to application and security needs Enable Always-on SSL protection! Stop modern malware Integrated protection from anti-malware to IDS/IPS - and beyond An ADC as a proxy inherently protects backend servers and provides for a unified and timely response to threats 10
Optimize Service Delivery Satisfy the need for speed! SSL acceleration and SPDY Caching and compression Control enterprise access Full Proxy Gateway - Provides SSL/VPN and mobility enablement, including SmartAccess and micro-vpn for XenMobile AAA, SAML and enterprise directory integration - SSO and interoperability across enterprise and SaaS apps Centralized policy enforcement across distributed apps and services NITRO RESTful API - Management integration and DevOps 11
Prove Business Value A holistic view of web properties AppFlow and HDX Insight - Application-level telemetry and analytics Integrated PCI DSS config and compliance reports Multitenant service delivery with SDX Enabling enterprise agility Connect public and private clouds with CloudBridge Run web properties in the cloud with VPX Embrace mobility with security and optimization for highlydistributed mobile web properties and services 12
How to: Cloud as a Datacenter
ADC Application Delivery Controller Hardware Appliance Multi-tenant Appliance Virtual Software Appliance Cloud Networks 14 Availability & Performance Security Optimization & Visibility
ADC: Accelerate, Scale, Optimize Applications Application Load Balancing Signalling Load Balancing Global Server Load Balancing DNS Caching Authoritative DNS Scale performance of web servers, in-line proxies and data bases Scale performance of PCRF, OCS, SPR, AAA, DNS and SIP servers Balance load across data centers for performance and availability Enhance performance DNS servers and protect against DDoS Enhance performance of ADNS infrastructure SSL Offload Web Compression TCP Optimization Multipath TCP SPDY Consolidate SSL transactions to accelerate and scale Speed up web page downloads and decrease bytes TCP protocol level tuning for quicker application transport Maintains TCP sessions when moving between WiFi & 3G/4G Streamlines web object downloads for non SPDY server endpoints 15
Cloudification Models for Datacenter.next Private Hardware Appliance Hybrid Multi-Tenant Appliance Public Virtual Software Appliance Main drivers: - Security - Cost - Bursting - Multitenancy - Data proximity - Services orchestration Main drivers: - Security - Cost - Bursting - Multitenancy - Data proximity - Services orchestration Main drivers: - Security - Cost - Bursting - Multitenancy - Data proximity - Services orchestration 16 2014 Citrix.
Simplified framework to mange capacity for mobile networks Mobile Core/Data Plane 50 Gbps 120 Gbps Adaptive Traffic Manager Messaging Content Filtering Security Caching WAP Push Proxy Parental Control/ Personalization Firewall Transparent Cache 5 Gbps 3.2Tbps Control Plane DNS 3GPP AAA PCRF OCS SPR/UDR SIP/IMS Telco.com Data Center/Application Plane Directory Remote Desktop Online Video M2M Customer Care 17 2014 Citrix.
Services for Datacenter.next Authentication IAM, RBAC, MFA, privileged account mgmt Automation Service chaining, SDN Delivery DaaS, Micro-VPN, SSL/VPN DevOps NITRO, RISE Optimization Services balancing, power & cost-balancing Resiliency GSLB Telemetry AppFlow, HDX Insights Threat Protection DoS/DDoS mitigation, WAF Elasticity PayGrow, Burst Packs, services chaining 18
Key Value Proposition for Operators Network Flexibility Scale out capacity on-demand Leverage cloud economics Ideal for Virtualized and Automated Networks Simplify transition to virtual ADCs Improve business agility and reduce costs by simplifying ADC footprint Application Performance and Traffic Management Enhance performance and availability of applications in the S/Gi-LAN, control plane and data center Manage IPv6, intelligently steer traffic 19
Capabilities and Tools for Network Transition Software-based Identical Functions Across Platforms Automation Framework Integration with Orchestration Systems and Controllers Hardware Appliance = = Multi-Tenant Appliance Virtual Software Appliance Expose APIs to full capabilities of platform Deep integration with key partners 20
WORK BETTER. LIVE BETTER. 21