• No results found

Infrastructure for more security and flexibility to deliver the Next-Generation Data Center

N/A
N/A
Protected

Academic year: 2021

Share "Infrastructure for more security and flexibility to deliver the Next-Generation Data Center"

Copied!
21
0
0

Loading.... (view fulltext now)

Full text

(1)

Infrastructure for more security and flexibility

to deliver the Next-Generation Data Center

Stefan Volmari

(2)

Today's trends turn into major challenges…

(3)

© 2014 Citrix. Confidential. 3

…and lead to Data Center Transformation

• More mobile devices

• More applications

• More data volume

• More cloud services

• Fast

• Secure and Scalable

• Network Analytics

• Consolidation

• Automation

• Flexible

• Mobile Optimization

• Clustering

• Big Data

• Virtualization

• SDN Orchestration

• Service Chaining &

Overlay Networks

Trends

Demands placed on

Network

(4)

From static to elastic

Legacy Datacenter

Constantly behind

Network-focused

Overprovisioned

Console-managed

Complex to change

DMZ for security

Cloud Datacenter

Constantly redefined

Application-focused

Click-to-update

Automated and orchestrated

Services-oriented

(5)

© 2014 Citrix. Confidential. 5

So why keep anything on-premise?

Scale

– When you have scale that makes on premise

cheaper than cloud based

Security

– When you have unique security or

regulatory requirements

(6)

Attributes of Datacenter.next

What does success look like?

Leverages

cloud

where it makes clear sense

Managed services and

service levels

– not simply systems and networks

Application-focused

networking and

service chaining

SLA’s define minimum service requirements –

frugal, not cheap

Trust

and predictable behavior persists through

multiple state changes

(7)
(8)

What’s needed for Datacenter.next security?

Confidentiality, Integrity , Availability and Management

Keep the Lights On

Thwart Advanced Attacks

Optimize Service Delivery

Provide Business Value

Support mobile/global workforce

Run anywhere, optimized local performance

Physical to virtual, enterprise to cloud

Mesh networking, delegated admin

End-to-end encryption / Always-on SSL

Use of public cloud services

Amazon, Azure, ShareFile Cloud directory and identity

Automated and orchestrated

(9)

© 2014 Citrix. Confidential. 9

Keep the Lights On

Ensure service availability

• Global Server Load Balancing (GSLB) • Clustering and high availability

• Priority Queuing for application-level QoS management

Protect critical services

(10)

Advanced Threats

Block web-specific attacks

• Web Application Firewall

- Protects HTTP, XML, SQL, dynamic content and session state (including cookies)

• HTTP re-write and Responder

- Custom request/response policies tuned to application and security needs

• Enable Always-on SSL protection!

Stop modern malware

• Integrated protection from anti-malware to IDS/IPS - and beyond

(11)

© 2014 Citrix. Confidential. 11

Optimize Service Delivery

Satisfy the need for speed!

• SSL acceleration and SPDY • Caching and compression

Control enterprise access

• Full Proxy Gateway

- Provides SSL/VPN and mobility enablement, including SmartAccess and micro-VPN for XenMobile

• AAA, SAML and enterprise directory integration

- SSO and interoperability across enterprise and SaaS apps

• Centralized policy enforcement across distributed apps and services

• NITRO RESTful API

(12)

Prove Business Value

A holistic view of web properties

• AppFlow and HDX Insight

- Application-level telemetry and analytics

• Integrated PCI DSS config and compliance reports • Multitenant service delivery with SDX

Enabling enterprise agility

• Connect public and private clouds with CloudBridge • Run web properties in the cloud with VPX

(13)

How to:

(14)
(15)

© 2014 Citrix. Confidential. 15

ADC: Accelerate, Scale, Optimize Applications

Signalling Load Balancing

Scale performance of PCRF, OCS, SPR, AAA, DNS and SIP

servers Scale performance of

web servers, in-line proxies and data bases

Balance load across data centers for performance and availability Global Server Load Balancing Application Load Balancing DNS Caching Enhance performance DNS servers and protect against DDoS

Enhance performance of ADNS infrastructure

Authoritative DNS

SPDY

Streamlines web object downloads for non SPDY server endpoints

Multipath TCP

Maintains TCP sessions when moving between

WiFi & 3G/4G

Web Compression

Consolidate SSL transactions to accelerate and scale

SSL Offload

Speed up web page downloads and decrease bytes

TCP protocol level tuning for quicker application transport

(16)

Cloudification Models for Datacenter.next

Private

Hardware Appliance Main drivers: - Security - Cost - Bursting - Multitenancy - Data proximity - Services orchestration

Hybrid

Multi-Tenant Appliance Main drivers: - Security - Cost - Bursting - Multitenancy - Data proximity - Services orchestration

Public

Virtual Software Appliance

(17)

© 2014 Citrix. 17

Simplified framework to mange capacity for

mobile networks

5 Gbps 120 Gbps 50 Gbps 3.2Tbps

Data Center/Application Plane

Telco.com Directory Remote Desktop Online Video M2M Customer Care Control Plane SIP/IMS DNS 3GPPAAA PCRF OCS SPR/UDR

Mobile Core/Data Plane Adaptive Traffic Manager WAP Push Proxy Parental Control/ Personalization

Firewall Transparent Cache Messaging

Content

(18)

Services for Datacenter.next

Authentication

• IAM, RBAC, MFA, privileged account mgmt

Automation

• Service chaining, SDN

Delivery

• DaaS, Micro-VPN, SSL/VPN

DevOps

• NITRO, RISE

Elasticity

• PayGrow, Burst Packs, services chaining

Optimization

• Services balancing, power & cost-balancing

Resiliency

• GSLB

Telemetry

• AppFlow, HDX Insights

Threat Protection

(19)

© 2014 Citrix. Confidential. 19

Key Value Proposition for Operators

19

Application Performance and Traffic Management

Ideal for Virtualized and Automated Networks

Scale out capacity on-demand Leverage cloud economics

Network Flexibility

Enhance performance and availability of applications in the S/Gi-LAN, control plane and data center

Manage IPv6, intelligently steer traffic Simplify transition to virtual ADCs

(20)

Capabilities and Tools for Network Transition

Hardware Appliance Software-based Identical Functions Across Platforms Automation Framework

=

=

Integration with Orchestration Systems and Controllers

(21)

© 2014 Citrix. Confidential. 21

References

Related documents

The Cisco Email Security portfolio - including the Cisco Email Security Appliance (ESA), Cisco Virtual Email Security Appliance (ESAV), and Cisco Cloud Email Security (CES)

The Cisco Email Security portfolio―including the Cisco Email Security Appliance (ESA; see Figure 1), Cisco Email Security Virtual Appliance (ESAV), and Cisco Cloud Email Security

IEDIS Implementing Enterprise Data Center Infrastructure Security 5 Curso bajo demanda ACEAP Cisco Application Control Engine Appliance 4 22 al 25.. ACNS Application &

Note: To ensure proper sizing, Trend Micro recommends that customers use peak loads (the highest number of active users and peak throughput) when calculating the number of

Recapitulative play is a category of play that is difficult to discern as it often overlaps with other play types, and Hughes ( 2002 ) felt that it occurs primarily when children

Professional artist of initial letter finger tattoos as small designs are always represent your partner or whale tattoo experience that looks something like tattoos are generally

This Note contends that by increasing school flexibility and control over vendor awards, farm-to-school procurement legislation can help schools access fresh, healthy foods for

Therefore, this study evaluated patients who have ever breast cancer screening before a diagnosis of breast cancer for determining the frequency of reported ICs,