GMI CLOUD SERVICES Deployment, Migration, Security, Management SOLUTION OVERVIEW BUSINESS SERVICES CLOUD MIGRATION Founded in 1983, General Microsystems Inc. (GMI) is a holistic provider of product and services for cloud and enterprise deployment, migration, security, authentication, and management. GMI s approach to pre-migration assessment includes translating business services down to applications, and then the infrastructure supporting those applications down to individually monitored elements. This top down approach to infrastructure assessment and organization lends itself directly to a bottom up approach for proactive monitoring and management of the production environment once the migration is complete. During the entire migration process, the following GMI executive directives were maintained: Increased reliability Enhanced security Improved flexibility Simplicity of daily operations Higher efficiency for lowered TCO and increased bottom line revenue GMI Business Services To Be Migrated: CRM Accounting & Finance ERP Email and Marketing Integration Essential network services & security Backup and restore services Marketing, Pre-sales, post sales, HR, & support systems End user workstation migration from internal to cloud resources 3220 118th Avenue Southeast Bellevue, WA 98005 Phone: (425) 644-2233 Fax: (425) 644-7244 Email: sales@gmi.com
GMI Cloud Migration Phases Overview The GMI cloud migration not only provides advancements in security, efficiency, and performance, but also saves money by eliminating much of the time consuming workflow seen in typical IT environments around network, server, and other MIS functions as these tasks are passed to the cloud provider. This feature is one of the first places the benefit of ROI and more is recognized company-wide. Phase Migrated Services Notes I II III IV Network DNS/AD/LDAP/DHCP Cloud tunneling Firewall services ERP Backup / Restore LAN & cloud services Deploy Cloud CRM home directory file server migration for all end users to e:\home (windows) Phase I services are placed in collocation. Order of deployment is DNS first, AD second, Firewall third, lastly LDAP Collocate backup hardware to reduce or even eliminate bandwidth costs over WAN Third party with email and marketing integrations. GMI end user will use existing laptop & desktop options. Existing windows machines will be migrated to GMI cloud apps & storage for backup availability V End User Training ERP, CRM, User Desktop Navigation The Security, efficiency, reliability, flexibility, and simplicity are realized from 4 primary design goals: Standardization of technology Integration of business services Familiarization and ease of use for end users Repeatability of business processes with high availability The order of the deployment steps in phase I is directly related to the ability of the deployment team to verify connectivity for production delivery of mission critical applications. Physical layer through application layer are deployed in order, resulting in a successful application rollout as the applications begin to answer end user requests. Secure application delivery (Layer 7) is the ultimate goal of the underlying cloud infrastructure. End user, network, servers, databases, and storage all come together to form a business service that can be monitored for SLA compliance and root cause issue analysis post migration.
Leveraging Private and Public Clouds The GMI cloud migration is designed to provide network efficiencies and increased security by physically and logically dividing production devices from 3 rd party cloud providers and other internal GMI resources. Office and remote end users access email from any device while receiving marketing leads automatically within the cloud-based CRM. Services include mailchimp, web hosted pages and other social and direct media campaigns. Cloud services at GMI directly support business growth, provide immediate savings, and a competitive advantage that is also available to GMI cloud customers. The Net-A-Production network and Net-B-DR/DevOps networks are independently hosted on separate Layer 3 switches. This network segmentation provides a secure environment that protects GMI customers and employees from outside security issues. The production IP host count at GMI allows for a single VLAN that can be utilized for IP application and resolution services traffic, alternatively backup/restore traffic is configured for a
GMI Cloud Enabled Domains Since the GMI virtual network fabric is allowing complete IP address resolution, access to and from the cloud in the GMI office and remote offices is seamless and existing internal resolution servers can be used post cloud migration. This self-contained cloud enterprise meets or exceeds all of the requirements around standardization, work flow integration, familiarization through strict change control, and repeatability of successful business daily processes. Authentication for helpdesk, CRM, and disaster recovery systems are handled by the cloud provider and integrated via secure tunnels, further reducing the daily admin load on GMI IT staff. GMI can provide a highly secure foundation that connects your corporate headquarters, data centers, branch offices, small offices and mobile workers to each other, and to the applications they use to be productive. With GMI virtual datacenter services, you can converge multiple networks into a single logical network that allows GMI and its customers to rely on a single solution to add services such as voice over IP capabilities, collaboration or cloud applications, and cloud deployments or migrations. GMI cloud security practices filter, protect and manage network traffic. Host connectivity restrictions can be narrowed to only ports and services on your hosted nodes that are needed, a security measure that will add tremendous strength to your overall network security.
Backup and Restore Across GMI Cloud Hosts and Storage Backup and restore means business service assurance. Compliance standards across PCI, HIPPA, SCADA, and others, require a solid disaster recovery infrastructure and compliance confirmation for GMI and our customers. Deployment procedures Build out BU/DR for GMI Add agents to servers and desktops Build backup file tree across GMI Specify compression scheme Specify retention scheme Notes Cloud collocation Verify firewall ports Server, file system, file, file contents specified for backup High Medium Low (impacts restore time) Quarterly, Annually, Always Cloud backup and restore resources means lower risk, lower cost, and higher availability GMI Service Assurance Backup / Recovery Implement data store collocation of storage space to decrease bandwidth charges and host restore times Full system backup and restore Incremental backup and restore only files that have changed Differential backup and restore only file contents that have changed Variable retention and compression rules Email only and email to helpdesk integration Live application backup ability to backup without stopping application Full storage services Notes Traffic is VLAN directed to avoid impacting production traffic For essential network services and servers with high OS customization For file servers, desktops For servers or file systems that host databases Retention length of time to keep data Compression higher compression, slower restore Notification of backup and restore process completion and alarms. Email subject is support ticket title. Additional ticketing provided SNMP trap integration. This feature ensures that business services are not interrupted for backup service. This is especially critical in database environments and any application that utilizes file locks during execution. Storage provider ensures data security and availability with strict service levels. *By aligning the proper backup approach for each server and application, GMI dramatically extends the available budgeted storage
GMI Cloud Security and Performance Awareness From the edge of each private cloud, down to each server host, GMI s security approach not only protects against outside attacks, but also ensures that security anomalies can be detected without the need for signature updates. All of GMI s edge cloud connectivity devices are hardened with the assurance they can even be placed outside the firewall for virtual data center connectivity. A single point firewall configuration at GMI s headquarters provides confidence there are no data leaks from rogue network ports, and automated operating updates are monitored for failure to make sure vendor updates are applied frequently. All of this security awareness is brought together by the introduction of sflow technology within the collocated Layer 3 switches that gives GMI visibility into all traffic between hosts, traffic pattern anomalies for security, and host to host restrictions with threshold alarms for compliance needs around PCI in GMI s finance and accounting domains. Visibility for communications between virtual servers on virtual network segments Visibility into the performance of individual node host resources Visibility into running process on each managed node Real-time and analytical security assurance that does not depend on signature updates Visibility is required into bandwidth utilization at the application layer Security assurance is required that enforces limits between node to node communications
Cloud, Performance, & Availability Management As infrastructure devices, applications, voice servers, backups, and more move to the GMI cloud, the ability for a monitoring platform to gain viable visibility becomes increasingly difficult due to security access restrictions imposed by the cloud providers and other connectivity issues. Examples of dark spots come in the form of no access to cloud provided network switches, or ESX virtual host managers for virtual host traffic and performance information. The primary goal of the GMI monitoring platform is to manage fault, performance, availability, issue avoidance & resolution in a predictive and root cause way that supports business services. To facilitate visibility into the dark corners of cloud environments, flow technology is implemented in conjunction with other collection practices giving near real-time information into every conversation on the network. Algorithms like deviation from normal identify security issues quickly; furthermore, flow reporting lends itself to application layer visibility which aligns IT resources with business services with little manual modification. In addition, SNMP is leveraged for KPI (key performance indicator) data collection with WMI for detailed and granular reporting of the Windows server and desktop environments as they relate to overall cloud service delivery. Cloud Monitoring Security and Performance Matrix GMI Service Reporting Classification Authentication Notes ERP Health, Availability, Synthetic, WMI, windows Oracle DB monitoring added agent CRM Health, Availability, Synthetic port 80 hosted Test login 5 min Email host - local Health, Availability, Synthetic port/snmp, LDAP GMI.com agent Active Directory Availability, WMI / AD log scrape, windows Domain.local agent File Svr/Sharepoint Availability, WMI windows Domain.local Backup Availability, WMI/SNMP/logs, windows Domain.local agent Net SW - Backbone Health, Availability, sflow/snmp, syslog SNMP Comm. string Net SW NetA - Pr Health, Availability, sflow/snmp, syslog SNMP Comm. string Net SW - NetB Health, Availability, Flow/SNMP, syslog SNMP Comm. string GMI cloud services provides: Business-wide view of inefficiencies and security awareness Top down or bottom up issue resolution workflow Predictive service assurance that allows SLA management and business goal setting Real-time visibility into issues as they are happening Impact analysis to quickly know what is impacted when problems arise Root cause analysis that reduces resolution time from hours to minutes Integration to ticketing systems and/or other monitoring platforms and reporting engines
Conclusion This business service cloud migration positions GMI for future growth, enables increased service opportunities for our customers, and ensures GMI is operating at top efficiency and profitability. GMI provides customers with cloud deployments, migrations, security, and management using the same practices and care used to deploy our own cloud infrastructure with. GMI has extensive vendor and technology relationships, architected into complete customer solutions, and deployed for high availability production operations. GMI s continued investment in our internal human and technical resources means customers always benefit from relevant experience and industry best practice experience. GMI s own cloud migration included network, server, application, database, and storage services deployed with the goal of end to end visibility for proactive service assurance, reporting, and issue resolution. The same cloud services used internally by GMI are available to our customers Our Philosophy At GMI, we believe in establishing and maintaining integrity, consistency, and quality with all of our customer interactions. Our staff will take time to listen to your unique challenges, map out a distinct plan of action, and follow through to make sure your goals are met.