Building Blocks for a Migration to a Secure Cloud€¦ · Let’s resume … Lift & Shift Migrate &...

Post on 25-Jun-2020

0 views 0 download

transcript

Kappa Data 2020 - all rights reserved ©

Building Blocks for a Migration to a Secure Cloud

Koert MartensDirector of Technology

koert.martens@kappadata.be

Kappa Data 2020 - all rights reserved ©

Building Blocksfor a Migration to a Secure Cloud

Kappa Data 2020 - all rights reserved ©

Migration is of all Times

It’s not the strongest of the species that survives,

nor the most intelligent. It is the one that is most

adaptable to change”

Charles Darwin ®

Evolution must not feel like

Revolution

Kappa Data 2020 - all rights reserved ©

shocking

Evolution must not feel like

Revolution

but …adapting to the ”next new thing”

can be quite ….

Kappa Data 2020 - all rights reserved ©

shocking technology

Making the right

Business Decisions

N° 1 Competitive Unique

Kappa Data 2020 - all rights reserved ©

Business Decisions

Hype vs TrendVisibility

Time

Peak of inflated expectations

Plateau of Productivity

Slope of Enlightenment

Trough of Disillusionment

Technology Trigger

Gartner Hype Cycle

Kappa Data 2020 - all rights reserved ©

Business Decisions

Learning Curve

Demo

Small tests

FirstProjects Expert

Veteran

Kappa Data 2020 - all rights reserved ©

Business Decisions

Team up with

–Vendor

–Value Add Distributor

–3rd Parties

–Alliances

Kappa Data 2020 - all rights reserved ©

not only technologydrives changes

Everything, Everyone, Everywhere

Time to market is key

OPEX instead of CAPEX

More for less

Mobility

demands & requirements

Evolving expectations

Kappa Data 2020 - all rights reserved ©

History repeats itself

“History repeats itself,

first as tragedy,

second as farce”

Karl Marx®

From Mainframe Centralized Compute

to Distributed Compute and Back Again-ish

(or at least hybrid ;-)

Kappa Data 2020 - all rights reserved ©

Same Same but different

“The lamps are different,

but the light is the same”

Jalaluddin Rumi®

Still another means

to achieve the same goal

Kappa Data 2020 - all rights reserved ©

Achieving the same goal

From Physical to Virtual

over Private Cloud

to Public Cloud

Kappa Data 2020 - all rights reserved ©

migrateAnywhere to Anywhere

Kappa Data 2020 - all rights reserved ©

migrateWhat you expect

–Minimise Downtime (instant cut-over)

–Minimise Risk (testing is key prior to cut-over)

–Minimise Complexity (use 1 tool)

–Maximise Predictability (strict planning)

–Minimise Cost (automation)

Kappa Data 2020 - all rights reserved ©

what tools are you using?

Kappa Data 2020 - all rights reserved ©

We present you

Kappa Data 2020 - all rights reserved ©

Platespin Migration

– Migration tool: anywhere to anywhere

– Planning tool with automation

– Initial copy & incremental replication

– Up to 32 revisions on a single target

– Zero service downtime during replication

– Integrate testing moments

– Minimal service downtime during cutover

– Failsafe / Rollback

Kappa Data 2020 - all rights reserved ©

Lift & ShiftNew Challenges for your Hybrid Environment

Connectivity

Security

Kappa Data 2020 - all rights reserved ©

Connectingin a Hybridworld

AD

C

ADAPT

BANDW

MP

LS

SD-WAN

WAN

OPT

VPN

TIN

A

DY

NA

MIC

ME

SH

$$

Kappa Data 2020 - all rights reserved ©

Cloud Load Balancing

Balance the Workload

L4/L7

Kappa Data 2020 - all rights reserved ©

Cloud Load Balancing

GEO Balance the Workload

Kappa Data 2020 - all rights reserved ©

Cloud Load Balancing

GEO Failover

Disaster Recovery

Kappa Data 2020 - all rights reserved ©

This is

Kappa Data 2020 - all rights reserved ©

LoadMaster

–Intelligent LoadBalancing (L4 & L7)–resource based / least connections / response times / …

–Application based / Content based / …

–GEO based Load Balancing

–Security features

Application Delivery

Kappa Data 2020 - all rights reserved ©

What is the Most Critical part of your Network?

Kappa Data 2020 - all rights reserved ©

Most Critical

http://blogs.gartner.com/andrew-lerner/2016/05/01/sd-wan-turns-2/

Kappa Data 2020 - all rights reserved ©

What is theMost Expensive part

of your Network?

Kappa Data 2020 - all rights reserved ©

WAN Cost

http://blogs.gartner.com/andrew-lerner/2016/05/01/sd-wan-turns-2/

Kappa Data 2020 - all rights reserved ©

MPLS and/or VPN infrastructure

Traditional WAN does not scale!

Servers and Apps are

moved to the Cloud

IaaSSaaSLocal installed Apps are

moved to the Cloud

Internet

FW

Kappa Data 2020 - all rights reserved ©

WAN architecture for the Hybrid!

MPLS and/or VPN infrastructure

Kappa Data 2020 - all rights reserved ©

WAN architecture for the Hybrid!

Kappa Data 2020 - all rights reserved ©

WAN architecture for the Hybrid!

Centralized

Management

CC

Kappa Data 2020 - all rights reserved ©

Connecting yourIaaS

We

b T

ier

Ap

p T

ier

Da

tab

ase

Tie

r

Express Route

MPLS

Expensive – No QoS

No visibility (App / Users)

Kappa Data 2020 - all rights reserved ©

Connecting yourIaaS

We

b T

ier

Ap

p T

ier

Da

tab

ase

Tie

r

Internet

Kappa Data 2020 - all rights reserved ©

Connecting yourIaaS

We

b T

ier

Ap

p T

ier

Da

tab

ase

Tie

r

Internet

VPN

Kappa Data 2020 - all rights reserved ©

Connecting yourIaaS

We

b T

ier

Ap

p T

ier

Da

tab

ase

Tie

r

Internet

VPN

Express Route

Kappa Data 2020 - all rights reserved ©

Connecting yourIaaS

We

b T

ier

Ap

p T

ier

Da

tab

ase

Tie

r VPN

Internet

Internet

Kappa Data 2020 - all rights reserved ©

Connecting yourIaaS

We

b T

ier

Ap

p T

ier

Da

tab

ase

Tie

r VPN

Internet

Internet

FW

Kappa Data 2020 - all rights reserved ©

We present you

Kappa Data 2020 - all rights reserved ©

NextGen-F Firewall

–Physical / Virtual / Cloud Firewall

–Centralized Management (Control Center)

–TINA VPN

–Dynamic / Full Mesh VPN

–Visibility (Users / Applications)

–Quality of Service

Kappa Data 2020 - all rights reserved ©

Can I Really go WithoutMPLS?

Kappa Data 2020 - all rights reserved ©

And use Internet For myBackbone?

Kappa Data 2020 - all rights reserved ©

SD-WANThe new Trend

« The emergence of public cloud computing has rederedtraditional enterprise WAN architectures to be suboptimal, from a price and performance perspective »

« SD-WAN is a new approach to support branch office connectivityin a simplified and cost-effective manner ».

Kappa Data 2020 - all rights reserved ©

SD-WANThe new Trend

… SD-WAN is the optimum replacement for MPSL …

Kappa Data 2020 - all rights reserved ©

SD-WAN Key Components

Lightweight replacement of traditionalWAN routers to terminate carriers

(MPLS / LTE / Internet / …)1http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/

Kappa Data 2020 - all rights reserved ©

SD-WAN Key Components

Load sharing traffic across multiple VPN / WAN Connections, dynamically, basedon policies & application requirements2

http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/

Kappa Data 2020 - all rights reserved ©

SD-WAN Key Components

Easy management, configuration and orchestrations of WANs3

http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/

Kappa Data 2020 - all rights reserved ©

SD-WAN Key Components

Provides Secure VPN and integratesadditional network services

(Firewall / WAN Optimization / …)4http://blogs.gartner.com/andrew-lerner/2015/07/07/sdwan/

Kappa Data 2020 - all rights reserved ©

Meet your

NextGen-F Cloud-

Enabled SD-WAN

Firewall

Kappa Data 2020 - all rights reserved ©

1 Replacement for WAN Router

PUBLIC CLOUDVIRTUALPHYSICAL

Small – F18 (1.0 Gbps)

Enterprise (40 Gbps)

Optional 3G / 4G

Integrated ADSL

Kappa Data 2020 - all rights reserved ©

2 Dynamic Load Sharing on Multi VPN

TINA VPN - 1 tunnel on multiple WANs Simultaneous

Become immune to bandwidth fluctuations (VOIP & VIDEO)

Dynamic Bandwidth & Latency Detection (v7.1)

Adaptive QoSBandwidth first

Latency first

Kappa Data 2020 - all rights reserved ©

3 Easy Management & VPN Orchestration

Control Center – Enterprise Centralized Management

Distributed Policies & Configurations

Graphic VPN design – Simple Dynamic / Full Mesh VPN setup

Zero Touch Deployment – Easy and Fast Rollout in Dispersed Networks

Kappa Data 2020 - all rights reserved ©

4 Additional Features besides VPN

NextGen Firewall – Users & Applications for Control & Visibility

Email & Web Security

Advanced Malware Protection – Barracuda ATP with Sandboxing

WAN Optimization

Kappa Data 2020 - all rights reserved ©

Securing theCloud

Kappa Data 2020 - all rights reserved ©your baseline security

FIREWALL

SECURITY IS NOT A SHAREDRESPONSIBILITY

Kappa Data 2020 - all rights reserved ©

Public Cloud Security

Azure / Amazon / Google

are responsible of the Cloud

You are responsible in the Cloud

Data

Application

Kappa Data 2020 - all rights reserved ©

TAKE OWNERSHIP

Kappa Data 2020 - all rights reserved ©

NextGen-F Firewall

–Intrusion Detection & Prevention

–DDoS & GEO Security

–Malware Protection

–Advanced Threat Protection

–Botnet & Spyware Protection

–Web & Email Security

–Application Control

–User Identity Awareness

Kappa Data 2020 - all rights reserved ©

Sandboxing by itselfis not efficient

Kappa Data 2020 - all rights reserved ©

Barracuda Advanced Threat Protection

Advanced Threat Signatures

Behavioral & Heuristic Analysis

Static Code Analysis

CPU Emulation-Based Sandboxing

Kappa Data 2020 - all rights reserved ©

ADVANCED THREAT

PROTECTION

Barracuda Advanced Threat Protection

Accept / Allow File

Deny / Reject File

Kappa Data 2020 - all rights reserved ©

A FIREWALL IS

Kappa Data 2020 - all rights reserved ©

Kappa Data 2020 - all rights reserved ©

LoadMaster

SSL Security (certificate)

Caching

Offloading

Reverse Proxy

WAF

Kappa Data 2020 - all rights reserved ©

Make your Web Application Secure

–WAF is Underrated

–OWASP top 10

Where Infrastructure meetsWeb Developers

Kappa Data 2020 - all rights reserved ©

Kappa Data 2020 - all rights reserved ©

Web Application Firewall

Take a LoadBalancer ADC

Focus on Web Traffic

Accelerate traffic

Add Identity & Access Management

Add Dedicated Web Security Features

Kappa Data 2020 - all rights reserved ©

Vulnerability Scanner

Scan your Customer’s website

Receive detailed Report

Inform the Customer

Sell WAF

Kappa Data 2020 - all rights reserved ©

Barracuda Automates Web Security

Recurring Scan

Scan your WAF protected

Website on a regular

basis from Barracuda

Cloud Service

MitigateWAF

Vulnerability Overview

Risk Report

Set Active or Passive Mitigation

Auto-Fixable

Reporting

Kappa Data 2020 - all rights reserved ©

Let’s resume …

Lift & Shift

Migrate & Planning

Anything to Anything

Cloud Enabled

SD-WAN

Firewall

Central Management

LoadBalancer ADC

GEO & Failover

Multi-Application

Incl. WAF

Dedicated WAF

High-End Security

Vulnerability Scan

Auto Mitigation

Kappa Data 2020 - all rights reserved ©

THANKYOU

Together Strong in a changing world

#KappaData2020