Building Blocks for a Migration to a Secure Cloud€¦ · Let’s resume … Lift & Shift Migrate &...
Transcript of Building Blocks for a Migration to a Secure Cloud€¦ · Let’s resume … Lift & Shift Migrate &...
Kappa Data 2020 - all rights reserved ©
Building Blocks for a Migration to a Secure Cloud
Koert MartensDirector of Technology
Kappa Data 2020 - all rights reserved ©
Building Blocksfor a Migration to a Secure Cloud
Kappa Data 2020 - all rights reserved ©
Migration is of all Times
It’s not the strongest of the species that survives,
nor the most intelligent. It is the one that is most
adaptable to change”
Charles Darwin ®
Evolution must not feel like
Revolution
Kappa Data 2020 - all rights reserved ©
shocking
Evolution must not feel like
Revolution
but …adapting to the ”next new thing”
can be quite ….
Kappa Data 2020 - all rights reserved ©
shocking technology
Making the right
Business Decisions
N° 1 Competitive Unique
Kappa Data 2020 - all rights reserved ©
Business Decisions
Hype vs TrendVisibility
Time
Peak of inflated expectations
Plateau of Productivity
Slope of Enlightenment
Trough of Disillusionment
Technology Trigger
Gartner Hype Cycle
Kappa Data 2020 - all rights reserved ©
Business Decisions
Learning Curve
Demo
Small tests
FirstProjects Expert
Veteran
Kappa Data 2020 - all rights reserved ©
Business Decisions
Team up with
–Vendor
–Value Add Distributor
–3rd Parties
–Alliances
Kappa Data 2020 - all rights reserved ©
not only technologydrives changes
Everything, Everyone, Everywhere
Time to market is key
OPEX instead of CAPEX
More for less
Mobility
demands & requirements
Evolving expectations
Kappa Data 2020 - all rights reserved ©
History repeats itself
“History repeats itself,
first as tragedy,
second as farce”
Karl Marx®
From Mainframe Centralized Compute
to Distributed Compute and Back Again-ish
(or at least hybrid ;-)
Kappa Data 2020 - all rights reserved ©
Same Same but different
“The lamps are different,
but the light is the same”
Jalaluddin Rumi®
Still another means
to achieve the same goal
Kappa Data 2020 - all rights reserved ©
Achieving the same goal
From Physical to Virtual
over Private Cloud
to Public Cloud
Kappa Data 2020 - all rights reserved ©
migrateAnywhere to Anywhere
Kappa Data 2020 - all rights reserved ©
migrateWhat you expect
–Minimise Downtime (instant cut-over)
–Minimise Risk (testing is key prior to cut-over)
–Minimise Complexity (use 1 tool)
–Maximise Predictability (strict planning)
–Minimise Cost (automation)
Kappa Data 2020 - all rights reserved ©
what tools are you using?
Kappa Data 2020 - all rights reserved ©
We present you
Kappa Data 2020 - all rights reserved ©
Platespin Migration
– Migration tool: anywhere to anywhere
– Planning tool with automation
– Initial copy & incremental replication
– Up to 32 revisions on a single target
– Zero service downtime during replication
– Integrate testing moments
– Minimal service downtime during cutover
– Failsafe / Rollback
Kappa Data 2020 - all rights reserved ©
Lift & ShiftNew Challenges for your Hybrid Environment
Connectivity
Security
Kappa Data 2020 - all rights reserved ©
Connectingin a Hybridworld
AD
C
ADAPT
BANDW
MP
LS
SD-WAN
WAN
OPT
VPN
TIN
A
DY
NA
MIC
ME
SH
$$
Kappa Data 2020 - all rights reserved ©
Cloud Load Balancing
Balance the Workload
L4/L7
Kappa Data 2020 - all rights reserved ©
Cloud Load Balancing
GEO Balance the Workload
Kappa Data 2020 - all rights reserved ©
Cloud Load Balancing
GEO Failover
Disaster Recovery
Kappa Data 2020 - all rights reserved ©
This is
Kappa Data 2020 - all rights reserved ©
LoadMaster
–Intelligent LoadBalancing (L4 & L7)–resource based / least connections / response times / …
–Application based / Content based / …
–GEO based Load Balancing
–Security features
Application Delivery
Kappa Data 2020 - all rights reserved ©
What is the Most Critical part of your Network?
Kappa Data 2020 - all rights reserved ©
Most Critical
http://blogs.gartner.com/andrew-lerner/2016/05/01/sd-wan-turns-2/
Kappa Data 2020 - all rights reserved ©
What is theMost Expensive part
of your Network?
Kappa Data 2020 - all rights reserved ©
WAN Cost
http://blogs.gartner.com/andrew-lerner/2016/05/01/sd-wan-turns-2/
Kappa Data 2020 - all rights reserved ©
MPLS and/or VPN infrastructure
Traditional WAN does not scale!
Servers and Apps are
moved to the Cloud
IaaSSaaSLocal installed Apps are
moved to the Cloud
Internet
FW
Kappa Data 2020 - all rights reserved ©
WAN architecture for the Hybrid!
MPLS and/or VPN infrastructure
Kappa Data 2020 - all rights reserved ©
WAN architecture for the Hybrid!
Kappa Data 2020 - all rights reserved ©
WAN architecture for the Hybrid!
Centralized
Management
CC
Kappa Data 2020 - all rights reserved ©
Connecting yourIaaS
We
b T
ier
Ap
p T
ier
Da
tab
ase
Tie
r
Express Route
MPLS
Expensive – No QoS
No visibility (App / Users)
Kappa Data 2020 - all rights reserved ©
Connecting yourIaaS
We
b T
ier
Ap
p T
ier
Da
tab
ase
Tie
r
Internet
Kappa Data 2020 - all rights reserved ©
Connecting yourIaaS
We
b T
ier
Ap
p T
ier
Da
tab
ase
Tie
r
Internet
VPN
Kappa Data 2020 - all rights reserved ©
Connecting yourIaaS
We
b T
ier
Ap
p T
ier
Da
tab
ase
Tie
r
Internet
VPN
Express Route
Kappa Data 2020 - all rights reserved ©
Connecting yourIaaS
We
b T
ier
Ap
p T
ier
Da
tab
ase
Tie
r VPN
Internet
Internet
Kappa Data 2020 - all rights reserved ©
Connecting yourIaaS
We
b T
ier
Ap
p T
ier
Da
tab
ase
Tie
r VPN
Internet
Internet
FW
Kappa Data 2020 - all rights reserved ©
We present you
Kappa Data 2020 - all rights reserved ©
NextGen-F Firewall
–Physical / Virtual / Cloud Firewall
–Centralized Management (Control Center)
–TINA VPN
–Dynamic / Full Mesh VPN
–Visibility (Users / Applications)
–Quality of Service
Kappa Data 2020 - all rights reserved ©
Can I Really go WithoutMPLS?
Kappa Data 2020 - all rights reserved ©
And use Internet For myBackbone?
Kappa Data 2020 - all rights reserved ©
SD-WANThe new Trend
« The emergence of public cloud computing has rederedtraditional enterprise WAN architectures to be suboptimal, from a price and performance perspective »
« SD-WAN is a new approach to support branch office connectivityin a simplified and cost-effective manner ».
Kappa Data 2020 - all rights reserved ©
SD-WANThe new Trend
… SD-WAN is the optimum replacement for MPSL …
Kappa Data 2020 - all rights reserved ©
SD-WAN Key Components
Lightweight replacement of traditionalWAN routers to terminate carriers
(MPLS / LTE / Internet / …)1http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/
Kappa Data 2020 - all rights reserved ©
SD-WAN Key Components
Load sharing traffic across multiple VPN / WAN Connections, dynamically, basedon policies & application requirements2
http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/
Kappa Data 2020 - all rights reserved ©
SD-WAN Key Components
Easy management, configuration and orchestrations of WANs3
http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/
Kappa Data 2020 - all rights reserved ©
SD-WAN Key Components
Provides Secure VPN and integratesadditional network services
(Firewall / WAN Optimization / …)4http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/
Kappa Data 2020 - all rights reserved ©
Meet your
NextGen-F Cloud-
Enabled SD-WAN
Firewall
Kappa Data 2020 - all rights reserved ©
1 Replacement for WAN Router
PUBLIC CLOUDVIRTUALPHYSICAL
Small – F18 (1.0 Gbps)
Enterprise (40 Gbps)
Optional 3G / 4G
Integrated ADSL
Kappa Data 2020 - all rights reserved ©
2 Dynamic Load Sharing on Multi VPN
TINA VPN - 1 tunnel on multiple WANs Simultaneous
Become immune to bandwidth fluctuations (VOIP & VIDEO)
Dynamic Bandwidth & Latency Detection (v7.1)
Adaptive QoSBandwidth first
Latency first
Kappa Data 2020 - all rights reserved ©
3 Easy Management & VPN Orchestration
Control Center – Enterprise Centralized Management
Distributed Policies & Configurations
Graphic VPN design – Simple Dynamic / Full Mesh VPN setup
Zero Touch Deployment – Easy and Fast Rollout in Dispersed Networks
Kappa Data 2020 - all rights reserved ©
4 Additional Features besides VPN
NextGen Firewall – Users & Applications for Control & Visibility
Email & Web Security
Advanced Malware Protection – Barracuda ATP with Sandboxing
WAN Optimization
Kappa Data 2020 - all rights reserved ©
Securing theCloud
Kappa Data 2020 - all rights reserved ©your baseline security
FIREWALL
SECURITY IS NOT A SHAREDRESPONSIBILITY
Kappa Data 2020 - all rights reserved ©
Public Cloud Security
Azure / Amazon / Google
are responsible of the Cloud
You are responsible in the Cloud
Data
Application
Kappa Data 2020 - all rights reserved ©
TAKE OWNERSHIP
Kappa Data 2020 - all rights reserved ©
NextGen-F Firewall
–Intrusion Detection & Prevention
–DDoS & GEO Security
–Malware Protection
–Advanced Threat Protection
–Botnet & Spyware Protection
–Web & Email Security
–Application Control
–User Identity Awareness
Kappa Data 2020 - all rights reserved ©
Sandboxing by itselfis not efficient
Kappa Data 2020 - all rights reserved ©
Barracuda Advanced Threat Protection
Advanced Threat Signatures
Behavioral & Heuristic Analysis
Static Code Analysis
CPU Emulation-Based Sandboxing
Kappa Data 2020 - all rights reserved ©
ADVANCED THREAT
PROTECTION
Barracuda Advanced Threat Protection
Accept / Allow File
Deny / Reject File
Kappa Data 2020 - all rights reserved ©
A FIREWALL IS
Kappa Data 2020 - all rights reserved ©
Kappa Data 2020 - all rights reserved ©
LoadMaster
SSL Security (certificate)
Caching
Offloading
Reverse Proxy
WAF
Kappa Data 2020 - all rights reserved ©
Make your Web Application Secure
–WAF is Underrated
–OWASP top 10
Where Infrastructure meetsWeb Developers
Kappa Data 2020 - all rights reserved ©
Kappa Data 2020 - all rights reserved ©
Web Application Firewall
Take a LoadBalancer ADC
Focus on Web Traffic
Accelerate traffic
Add Identity & Access Management
Add Dedicated Web Security Features
Kappa Data 2020 - all rights reserved ©
Vulnerability Scanner
Scan your Customer’s website
Receive detailed Report
Inform the Customer
Sell WAF
Kappa Data 2020 - all rights reserved ©
Barracuda Automates Web Security
Recurring Scan
Scan your WAF protected
Website on a regular
basis from Barracuda
Cloud Service
MitigateWAF
Vulnerability Overview
Risk Report
Set Active or Passive Mitigation
Auto-Fixable
Reporting
Kappa Data 2020 - all rights reserved ©
Let’s resume …
Lift & Shift
Migrate & Planning
Anything to Anything
Cloud Enabled
SD-WAN
Firewall
Central Management
LoadBalancer ADC
GEO & Failover
Multi-Application
Incl. WAF
Dedicated WAF
High-End Security
Vulnerability Scan
Auto Mitigation
Kappa Data 2020 - all rights reserved ©
THANKYOU
Together Strong in a changing world
#KappaData2020