The High Availability and Resiliency of the Pertino Cloud Network Engine
Executive summary The emergence of cloud network architectures can be directly attributed to the evolution of business IT. As the number of switches, routers and firewalls has increased to meet growing demand for access to distributed workforce, workloads and applications, the IT response time to enable that access has also increased. It can take days or even weeks to make the changes sufficient to securely enable application access and remote connectivity. Pertino recognizes the challenges IT organizations face trying to meet business demands and offers a solution to this problem that includes a high degree of resilience and redundancy to secure communications for remote and in-house users. Business network background Traditional IT networks evolved to meet communication needs within localized workgroups, usually in a corporate office. With the rise of the Internet, those workgroups needed to be connected to other workgroups who were often located remotely. At the same time, computing and applications evolved from centralized mainframe orientation to client/server and then toward distributed workloads. Meanwhile, workers became increasingly mobile, requiring access to network resources and applications from new devices such as laptops, phones and tablets, securely and around the clock. In effect, these three forces have combined, resulting in the extension of the LAN and a dissolution of the LAN/WAN border. The plethora of network devices routers, switches, firewalls, application delivery controllers, load balancers, IDS/IPS and so on that must be deployed to meet the needs of workers accessing applications or requiring distributed workloads can be a configuration and management nightmare. According to Enterprise Management Associates, as many as 1,000 network devices can be under management at smaller companies (250-999 employees). Imagine the difficulty of reacting quickly to user needs and enabling application access via a traditional network at a company of this size, let alone any larger. The rise of the cloud Cloud networks arose because traditional IT networks could not react fast enough to business and user demands. Employees, consultants and guests are using new devices and requiring access to an increasing number of applications. Those users need increasing access to applications from outside traditional, on-premise IT networks. IT, in turn, is faced with enabling access to those applications while requiring increased levels of security that, in effect, can actually restrict access to those same applications. Virtualization technologies have reduced the effort to develop and deploy applications by making it easier to allocate compute resources, but connecting users to those application resources securely and accurately is often problematic. Many midsize enterprises today have some sort of hybrid cloud where resources can be dynamically allocated to users on a variety of devices. However, this requires a significant investment to deploy and maintain. For example, enabling application access for one person may involve touching multiple routers and switches, modifying firewall rules or router ACLs, updating web authentication portals and ensuring all those changes don t cause outages elsewhere. Multiply those changes by the increasing numbers of user requests, and it can be a daunting task to quickly enable remote access to those who need it or to integrate different applications or systems with proper addressing, management and security. With the widespread availability of high-speed Internet access, it is often a more prudent business decision to outsource application deployment and distributed workloads to cloud service providers such as Amazon Web Services or Rackspace. There are distinct advantages of moving toward cloud services hardened data facilities, vertically and horizontally scalable systems, redundant software, automated change control, continual upgrades and best-ofbreed hardware. Moreover, cloud services offer a myriad of configuration and pricing options that can be tailored 2
to business needs, allowing services to be purchased cost effectively, based on throughput or usage, and scaled up or down as needed. Combined, cloud service features offer a level of specialization and focus that allows IT teams to focus on more pressing, localized issues. However, cloud deployments have limitations. Traffic is typically not encrypted within the datacenter, and configuration errors at the network access layer (firewall or ACL rules) can prevent users from accessing applications or remote IT departments from spinning up new instances. Routing and NAT addressing misconfigurations can affect availability as well. Then, hardware failures, such as disk, fan or power supplies, can render multiple virtual instances dark. And wholesale power failures are not unheard of, taking out entire data centers and multiple customers at the same time. Delivering high availability and redundancy Pertino s belief is that customers must be able to create secure, optimized cloud networks in minutes, add people and devices instantly and deploy network services on demand. To that end, Pertino is a provider of cloud-based networking services that deliver an entirely new way to build and manage networks, adding numerous highavailability and resilient features not available with cloud deployments and traditional networks. Our architecture begins with a redundant, resilient system designed to offer seamless connectivity and security between clients. Two or more clients connect through the Pertino Cloud Network Engine, which leverages the horizontal scalability of IaaS (ability to add more instances) and vertical scalability of Network Virtualization (dynamically adding more compute resources). This elastic infrastructure is composed of off-the-shelf VMs within multiple top-tier data centers around the world but includes resilient and highly available features to ensure communication is always available. Within each data center, the VMs are attached to a high-speed network fabric that s connected to the Internet backbone on redundant, multi-gigabit trunks spanning multiple carriers. The result is an overlay network that seamlessly integrates with the data center routing infrastructure, creating a virtual LAN-like network. Moreover, Pertino deploys full AES 256-bit encryption, isolating and securing traffic between tenants. Combining the elastic and redundant nature of cloud computing with a multi-provider footprint ensures that communication remains seamless should any single VM, data center or cloud provider fail. Network selection and configuration are done via a multi-factor, proximal selection of the optimal data center, taking geography, historical network performance and capacity under consideration before determining where to host the virtual network. Once the network is identified, Pertino s control lane allocates resources in as little as 60-90 seconds. It then maintains an understanding of the network topologies, user identities, policies and entitlements (who can connect to whom or what and access which services). This illustrates the benefits of a software-defined network (SDN) where separating the control plane (where traffic is sent) from the underlying data plane (how the traffic is sent) simplifies the process of building a network and adapting it to the needs of specific users and services. 3
During network sessions, the Pertino Network Engine s distributed data plane acts as a real-time network sensor, constantly measuring the uptime and performance of the underlying cloud data center infrastructure. Since configurations are stored centrally and continuous monitoring is inherent to the architecture, if an element of the virtual network experiences performance degradation or an outage, Pertino has the ability to failover to a different virtual network within the same data center or to an entirely different data center within seconds. Indeed, it is possible that this failover occurs within the sliding window time frame that TCP/IP uses for connection delay. Pertino s beat the stack functionality means that communication within a virtual network is seamless and users are unaffected by (and unaware of) any reconfiguration or failover within a data center or between data centers. This reconfiguration takes only seconds, and sessions don t degrade or terminate. For example, an RDP session between two users will continue uninterrupted even though a data center may have experienced an outage. Finally, it is important to note that the Pertino Cloud Network Engine never stores packets. Data transits through our platform, and resources are dynamically allocated prior to (or during) the transaction for optimal performance and resiliency. Secure Sockets Layer (SSL) is used to secure the traffic, and no passwords or IDs are delivered as clear text. Moreover, customer networks are fully isolated from one another the associated address space is abstracted from the data center network and from the Internet, providing top security and isolation. Benefits of SAAS and cloud Today s IT infrastructure with the variety of network devices and user requirements isn t as resilient and responsive to user demands for application access and communication. IT departments need to act quickly to allow users or workgroups access to servers or enable ad hoc remote teams to collaborate on issues, but IT workloads often prevent effective reaction time. The Pertino Cloud Network Engine offers rapid deployment to enable private networks for midsize enterprises where IT resources are at a premium. It offers unique resiliency, high availability and redundancy features, born 4
from Pertino s deep understanding of networks, which leverage standard virtualization and cloud technologies. Companies electing to move to cloud technologies lower network management costs and realize higher uptime and security returns. Pertino can help reduce those costs while enabling companies to see lasting benefits such as increased uptime, reliability, flexibility and resilience in communication and collaboration. 5
About Pertino Pertino is a modern way to network designed for the mobile and cloud era simple, secure and delivered as a service. Mobile and cloud technologies are transforming IT, resulting in a hybrid IT model where mobile workforces and cloud applications and workloads are reliant on public Internet connectivity. Our Cloud Network Engine enables any size business to build and manage a private cloud network that overlays the public Internet, securely connecting people, devices and resources anywhere. With AppScape, our network services app store, Pertino cloud networks can be extended with enterprise-level visibility, security and control services. This modern approach to networking combines the power and pervasiveness of the cloud with SDN and virtualization technologies, eliminating the cost and complexity of traditional hardware-based networks. Finally, a wide-area network that is cloud-agile and works the way businesses work today, without hardware, hassles, or high costs. Founded in 2011, Pertino is venture funded by premier firms and headquartered in Los Gatos, Calif. For more information or to try Pertino free, please visit pertino.com. The Pertino Cloud Network Engine enables any size business to build and manage a private cloud network that overlays the public Internet, securely connecting people, devices and resources anywhere. Simple. Secure. Software-defined. Visit pertino.com to get started for free. Contact Us Pertino.com 973 University Ave., Los Gatos, CA 95032 408-354.3900 info@pertino.com 6 Try Pertino Free > Copyright @ 2015, @ 2015, Pertino, Pertino, Inc. Inc.