PowerPoint Presentation
Citrix CloudBridge 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute1AgendaThe Challenges of using Public Cloud for computeThe solution!Citrix CloudBridge in a nut-shellHow it worksHow to configure itCloudBridge 2.0: NetScaler Branch Repeater comboUse cases
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeWhat is CloudBridge?In short, CloudBridge allows us extend a Layer 2 network over the WAN.Requires two NetScalers (VPX or MPX)Builds upon the IP Tunnel feature (which you can find in 9.2)(IP Tunnel has now moved under the Cloud Bridge node)Feature released in version 9.3 build 48.6 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute
Cloud EraPC Era 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute
People, Content & Devices
Apps, Desktops & DataSaaS, PaaS & IaaS
Cloud Networking Fabric
Connect it all together 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeFront DoorGatewayBack DoorBridge
Cloud Networking Fabric
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeThe Problem 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeEnterprise PremiseCloud ProviderLDAP
Database Server
StorageWebAppNetwork XNetwork YApplication requires access to web server, DB and LDAPBefore Leveraging the Cloud 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute8Enterprise PremiseCloud ProviderLDAP
Database Server
StorageAppNetwork XNetwork YWeb
Application still requires access to web server, DB and LDAPNo knowledge of premise datacenter.Different subnet configuration than premise datacenterWithout A Connection Back to the Datacenter 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute9Cloud ProviderNetwork XEnterprise PremiseLDAP
Database Server
StorageAppNetwork XWebCloud BridgeSecure bridge enabling network transparencyEnable connectivity back to premise datacenter With A Connection Back to the Datacenter 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute10The Solution 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeEnterprise customers want to leverage low-cost compute in the cloud, while keeping their data and directory services in a secure, on-premise location.Citrix CloudBridge is the Solution 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute
Infinite capacity & elastic efficiency 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute
Cloud Provider
TraditionalDatacenterRequirementsL2 Tunnel and BridgingL3 Secured TunnelSeamless networkWAN Optimized
Network YNetwork XCitrix CloudBridge Requirements
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeL2 GRE TunnelIPSec TunnelCloudBridge
Cloud Provider
TraditionalDatacenterNetwork XCitrix CloudBridge in a NutshellProvides a seamless extension of the Enterprise network into the Cloud
Provides secure connectivity from the Enterprise network into the Cloud
Together, IPSec and L2 tunneling provide network transparency 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeL2 GRE TunnelIPSec TunnelCloudBridgeCitrix CloudBridge in a Nutshell
Cloud Provider
TraditionalDatacenterProvides a seamless extension of the Enterprise network into the Cloud
Network XA truly network-transparent WAN optimization solution that doesnt rely on disruptive tunneling techniques
Optimizes application availability through advanced L4-7 load balancing and traffic management 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeL2 GRE TunnelIPSec TunnelCloudBridge
Cloud Provider
TraditionalDatacenterProvides a seamless extension of the Enterprise network into the Cloud
Together, IPSec and L2 tunneling provide network transparencyProvides secure connectivity from the Enterprise network into the Cloud
Citrix CloudBridge in a NutshellA truly network-transparent WAN optimization solution that doesnt rely on disruptive tunneling techniques
Provides a seamless extension of the Enterprise network into the Cloud
Network XOptimizes application availability through advanced L4-7 load balancing and traffic management 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge 2.0NetScaler + Branch Repeater 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute18What is in CloudBridge 2.0? New options in GUI for automated setupNetScaler and Branch Repeater now run on Amazons cloudDynamic Routing option added to CloudBridge packagingIncreased throughput for Branch Repeater (Max 100 Mpbs BRVPX-100)
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloud Bridge 2.0 Packaging
Available as physical (MPX) and virtual (VPX) form factorsWANop included in packageNS Platinum already has CloudBridge functionality Easy upgrade 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute20What is CloudBridge in AWS? Private connectivity between datacenter and AWS datacentersSeamless extension of your enterprise networkEncrypted connection for added security using IPSecOptimized tunnel using Branch Repeater
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge AWS SetupSetup appliances in datacenter and AWSSetup NetScaler appliance in enterprise datacenterDeploy AMI in VPC for desired AWS region/Availability Zone2 vCPUs minimum At least 2 GB RAM Configure IPs and external accessNSIPSNIP/MIPVIPsBind EIPs accordinglyDefine Internet Gateway for external connectivity
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge AWS SetupBridge Configuration
On enterprise appliance, select the option for AWSProvide AWS access and secret keyEnter IP and credentials information for AWS instanceSelect local and remote endpoints with corresponding subnet IPsChoose the encryption/hash algorithm and the key to be used
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge AWS SetupVerify the bridge statusTunnel status is shown in IP Tunnels pageOn the cli: show ipTunnelsNew CloudBridge dashboard provides additional information on tunnel performanceIPSec bytes sent/receivedCPU and memory usage
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge AWS SetupOptimize tunnel with Branch RepeaterAt this point, tunnel is fully functionalTunnel can be optimized with Branch RepeaterDe-duplicationFlow controlQoSCloudBridge package includes BR licensesA virtual or physical appliance can be used 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge AWS SetupBranch Repeater SetupDeploy BR on each tunnel endpointAWS AMI available from the marketplace in each regionSince a virtual inline setup is used, only one interface is neededIf BR is a physical appliance, do not connect the second interfaceConfigure BR for virtual inline modeTCP MSS 1300Return to Ethernet senderAWS AMI already pre-configured with these values
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge Setup LimitationsNetScaler instance in VPC can only forward traffic to only one Branch Repeater InstanceBranch Repeater only supports m1.large instance typesDynamic addition of ENIs is not supported. VPX instance must be restarted 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge Demo Topology
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeOptimized ResultsSpeed Test2 VPCsAsia East (Singapore)US East (Virginia)FTP transfer150MBActive modeBR default service class policies
1st attempt: 42.3 secs2nd attempt: 8.22 secs3rd attempt: 6.74 secs 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeOptimized ResultsCompression performance
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute30Use-Case Examples 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeCloudBridge Basic Use-CaseLDAP
DB Server
Storage
Web ServerPremise DatacenterCloudPrivatePublic
PublicPrivate
Network: 10.2.1.0Subnet: 255.255.254.0CloudBridge 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not DistributeEth0 (External): 174.36.133.10Eth1 (Internal): 192.168.1.99LDAP
DB Server
PrivatePublic
PublicPrivate
Web ServerPremise DatacenterCloudCloudBridgeNetwork: 10.2.1.0Subnet: 255.255.254.0Network: 192.168.1.0Subnet: 255.255.254.0
Storage
L2 TunnelIPSec TunnelCloudBridgeConnection: L2 TunnelSecurity: IPSec VPNRoutes: IP/IP, IPv6, non-IPCloudBridge Basic Use-CaseEth0 (External): 74.86.170.99Eth1 (Internal): 192.168.1.89CloudBridge 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute33LDAP
DB Server
PrivatePublic
PublicPrivate
Web ServerPremise DatacenterCloudCloudBridge
Storage
L2 TunnelIPSec TunnelCloudBridgeWeb ServerIP: 192.168.1.100Subnet: 255.255.254.0Reqs: DB and LDAPMigration / On-BoardingCloudBridge Basic Use-CaseCloudBridge 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute34More Use-Cases 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute
HypervisorLDAP
DB Server
PrivatePublic
PublicPrivate
Premise DatacenterCloudCloudBridge Web App Use-CasevSwitch
HypervisorvSwitchSwitchSwitch
Storage
IP: 192.168.1.100Subnet: 255.255.254.0Reqs: MySQL, Web & LDAPNetwork: 10.2.1.0Subnet: 255.255.254.0= BR VPX
= Cloud Bridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute36
HypervisorLDAP
DB Server
PrivatePublicPublicPrivatePremise DatacenterCloudCloudBridge Web App Use-CasevSwitch
HypervisorvSwitchSwitchSwitch
Storage
Eth0 (External): 174.36.133.10Eth1 (Internal): 192.168.1.99Eth0 (External): 74.86.170.99Eth1 (Internal): 192.168.1.89Network: 192.168.1.0Subnet: 255.255.254.0Network: 10.2.1.0Subnet: 255.255.254.0L2 TunnelIPSec TunnelCloudBridgeConnection: L2 TunnelSecurity: IPSec VPNRoutes: IP/IP, IPv6, non-IP= BR VPX
= CloudBridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute37
HypervisorLDAP
DB Server
PrivatePublicPublicPrivatePremise DatacenterCloudCloudBridge Web App Use-CasevSwitch
HypervisorvSwitchSwitchSwitch
Storage
L2 TunnelIPSec TunnelCloudBridgeMigration / On-BoardingIP: 192.168.1.100Subnet: 255.255.254.0Reqs: DB, Web and LDAP= BR VPX
= CloudBridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute38Specific Use-Case Examples 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute
HypervisorvSwitchLDAP
DB Server
Storage
Premise DatacenterCloudPublicPrivate
CloudBridge: Proximity GSLB
HypervisorvSwitchSwitch
PublicPrivate
Switch
IntranetWorld Wide Web
Client 1RequestResponseCloudBridgeRequestResponseRequestResponseClient 2RequestResponseRequestResponseRequestResponseLocation: BostonApplication: XenAppLocation: OfficeApplication: XenApp
= CloudBridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute40
HypervisorvSwitchLDAP
DB Server
Storage
PublicPrivate
HypervisorvSwitchSwitch
PublicPrivate
Switch
CloudBridge: Site Capacity GSLBPremise DatacenterCloudIntranetWorld Wide WebCloudBridgeResponseRequestResponseN ClientsLocation: OfficeApplication: XenAppMaximum ThresholdRequestResponseRequestRequest
= CloudBridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute41
HypervisorvSwitchLDAP
DB Server
Storage
PublicPrivate
HypervisorvSwitchSwitch
PublicPrivate
Switch
CloudBridge: Site Capacity GSLBPremise DatacenterCloudIntranetWorld Wide WebCloudBridgeRequestResponseN ClientsLocation: OfficeApplication: XenAppRequestResponseRequestResponseRequestResponseRequestResponseRequestResponse
= Netscaler Cloud Bridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute42
HypervisorvSwitchLDAP
DB Server
Storage
PublicPrivate
HypervisorvSwitchSwitch
PublicPrivate
Switch
CloudBridge: DR for GSLBPremise DatacenterCloudIntranetWorld Wide WebCloudBridgeRequestN ClientsRequestRequestResponseServer FailureResponseResponseRequestResponseRequestResponse
= Netscaler Cloud Bridge
2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute43Work better. Live better.Work better. Live better. 2012 Citrix | Confidential Do Not Distribute 2012 Citrix | Confidential Do Not Distribute44