SlideShare a Scribd company logo
1 of 20
Download to read offline
Hoe ontwerp en realiseer je een
‘digitale wasstraat’?
Basis
Browsing
Introductie
Conclusie & Contact
Context
Hosting
Wie zijn wij
Jeroen van der Meer
 In IT sinds 1984
 CTO
 Systems programming
 Datacenter design & Automated
operations
 Outsourcing achtergrond
Marc Guardiola
 In IT sinds 1997
 Lead Engineer & Manager Innovation
 Engineering & architecture met Linux,
Networking & Security
 CISSP-ISSAP, CEH
Bitbrains is
gespecialiseerd in
high performance
computing en
ultrasnelle levering van
PoC’s
ASP4all is
gespecialiseerd in
migratie, hosting
en beheer van
bedrijfskritische
applicaties.
ASP4all Bitbrains
Top 3
175+
Personeel
3000+
Servers
Marktontwikkelingen
 Werkveld is veranderd van Managed Hosting
naar “Reputation Hosting”
 Security technologie “versnipperd”
 Patriot Act en NSA
 DDoS
Context
REPUTATIONSecured
zones
Secured
mail
Secured
web
Secured
systems
Content
scanning
Reverse
proxy
Encryption
Disaster
recovery
Infra
scaling
Bandwidth
mgmt
DDoS
Intrusion
prevention
Klant
Basis infra
Public
Internet
Trusted
partners
Internal
WAN
Zonering
Public
Internet
Trusted
partners
Internal
WAN
Zonering
DC1 DC2
Encryption
Encryption
Encryption
Encryption
External
Internal
A
A
A
A
A
Zonering en componenten
Zonefirewall
Diensten
11
12
13
VLAN TL2: Besloten
31
32
33
21
22
23
34
35
36
37
Mail
Forward Proxy
Resolving DNS
Authoritative
DNS
VLAN TL1: PubliekVLAN AL1: Beperkt
File
24
25
Mail
Forward Proxy
26
Forward Proxy AV
NTP
10G 10G
27
Authoritative
DNS
Zonefirewall
Diensten
11
12
13
VLAN TL2: Besloten
31
32
33
21
22
23
34
35
36
37
Mail
Forward Proxy
Resolving DNS
Authoritative
DNS
VLAN TL1: PubliekVLAN AL1: Beperkt
File
24
25
Mail
Forward Proxy
26
Forward Proxy AV
NTP
10G 10G
27
Authoritative
DNS
Zonefirewall
Diensten
11
12
13
VLAN TL2: Besloten
31
32
33
21
22
23
34
35
36
37
Mail
Forward Proxy
Resolving DNS
Authoritative
DNS
VLAN TL1: PubliekVLAN AL1: Beperkt
File
24
25
Mail
Forward Proxy
26
Forward Proxy AV
NTP
10G 10G
27
Authoritative
DNS
Zone firewall
Diensten
10G 10G
AL1: Beperkt
Scheiding
Fysieke versus logische scheiding
 Snijverliezen, investering
End-to-end logische scheiding
 Zone firewall
 Switch
 Compute
 Virtualization
Scheiding
FEX A
FIA FIB
FEX B
Besloten Beperkt Publiek
A1 A2 B1 B2
1 2 3 456 7 8 9
Portchannel Portchannel
Secondary path
Primary path
256 vNICs
OS / Hypervisor
Visibility
4
3
2
1
4
3
2
1
1240 VIC
VN-TAG Trunk
802.1Q Trunk
1
16 Host ports 16 Host ports
2 1 2
1 2Zone firewall
1 2 3 4 5 6
Scheiding
FEX A
FIA FIB
FEX B
21
22
23
11
12
13
1
2
3
VLAN
Publiek
VLAN
Beperkt
VLAN
BeslotenVmware server 1
A1 A2 B1 B2
1 2 3 456 7 8 9
Portchannel Portchannel
Secondary path
Primary path
256 vNICs
FC1 FC2
vSwitch
TL2
vSwitch
TL1
vSwitch
AL1
NFS
OS / Hypervisor
Visibility
4
3
2
1
4
3
2
1
1240 VIC
VN-TAG Trunk
802.1Q Trunk
1
16 Host ports 16 Host ports
2 1 2
VMware server 1
1 2 3 4 5 6
Design for failure
Webbrowsing
Customer Wasstraat Internet
Anti-Virus
App check
CONNECT
www.google.nl:443
ACL
Blacklisting
Categorize App check
App check Anti-Virus
Anti-Malware
App check
Anti-Virus
Anti-Malware
Mail
Customer Wasstraat Internet
App check
DKIM
SPF
DMARC App check
App check DKIM
SPF
DMARC
Anti-Virus
Anti-Malware
Blacklisting
Quarantaine
App check
Anti-DDoS
Anti-Virus
Anti-Malware
Hosting
Webserver Wasstraat Internet
Anti-Virus
Anti-Malware
Anti-Vulnerability
Loadbalancing
WAF
Caching
SSL Offloading
App check
DDoS check
Anti-Virus
Anti-Malware
App check Caching App check
Conclusie: Defence in-depth!
Policies, Procedures,
Awareness
Physical
Perimeter
Internal network
Host
Application
Data
ISO27001, ISAE3402 type II
Tier3+ Datacenters
Anti-DDoS, L7 Firewall / IDP
WAF, Zoning/IDP, Web&Mail
security
Hardened OS & Middleware
Standard frameworks, patched &
audited
Enterprise storage
“Een ontwerp kan
sterven in schoonheid…”
Conclusie
Conclusie
Maar… ASP4all & Securelink
hebben dit daadwerkelijk
gerealiseerd!
 >36000 end users
 400 servers
 75 koppelingen met externe
netwerken
 70 TB raw storage
Binnen budget, binnen tijd
Meer weten ?
 Jeroen van der Meer: jmeer@asp4all.nl
 Marc Guardiola: mguardiola@asp4all.nl
Voorbeeld klantcase:
http://www.asp4all.nl/over-asp4all/klantervaringen/
ministerie-van-veiligheid-en-justitie
Bedankt voor uw aandacht!

More Related Content

What's hot

Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2
Warren Bent
 
Presentation network design and security for your v mware view deployment w...
Presentation   network design and security for your v mware view deployment w...Presentation   network design and security for your v mware view deployment w...
Presentation network design and security for your v mware view deployment w...
solarisyourep
 
Fortinet FortiOS 5 Presentation
Fortinet FortiOS 5 PresentationFortinet FortiOS 5 Presentation
Fortinet FortiOS 5 Presentation
NCS Computech Ltd.
 

What's hot (19)

F5 BigIP LTM Initial, Build, Install and Licensing.
F5 BigIP LTM Initial, Build, Install and Licensing.F5 BigIP LTM Initial, Build, Install and Licensing.
F5 BigIP LTM Initial, Build, Install and Licensing.
 
Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2
 
Presentation network design and security for your v mware view deployment w...
Presentation   network design and security for your v mware view deployment w...Presentation   network design and security for your v mware view deployment w...
Presentation network design and security for your v mware view deployment w...
 
PIX vs ASA_firewall
PIX vs ASA_firewallPIX vs ASA_firewall
PIX vs ASA_firewall
 
F5 Web Application Security
F5 Web Application SecurityF5 Web Application Security
F5 Web Application Security
 
Taking the Fear out of WAF
Taking the Fear out of WAFTaking the Fear out of WAF
Taking the Fear out of WAF
 
F5 EMEA Webinar Oct'15: http2 how to ease the transition
F5 EMEA Webinar Oct'15: http2 how to ease the transitionF5 EMEA Webinar Oct'15: http2 how to ease the transition
F5 EMEA Webinar Oct'15: http2 how to ease the transition
 
Страх и ненависть в телеком-операторах
Страх и ненависть в телеком-операторахСтрах и ненависть в телеком-операторах
Страх и ненависть в телеком-операторах
 
GDPR v pojetí F5
GDPR v pojetí F5GDPR v pojetí F5
GDPR v pojetí F5
 
Fortinet av
Fortinet avFortinet av
Fortinet av
 
Fortinet FortiOS 5 Presentation
Fortinet FortiOS 5 PresentationFortinet FortiOS 5 Presentation
Fortinet FortiOS 5 Presentation
 
Who needs iot security?
Who needs iot security?Who needs iot security?
Who needs iot security?
 
F5 Meetup presentation automation 2017
F5 Meetup presentation automation 2017F5 Meetup presentation automation 2017
F5 Meetup presentation automation 2017
 
What is NetFlow?
What is NetFlow?What is NetFlow?
What is NetFlow?
 
Nginx app protect-for-meetup-v1.0-202006_lk
Nginx app protect-for-meetup-v1.0-202006_lkNginx app protect-for-meetup-v1.0-202006_lk
Nginx app protect-for-meetup-v1.0-202006_lk
 
Firewall
FirewallFirewall
Firewall
 
Мобильная связь небезопасна. Аргументы, подкрепленные фактами
Мобильная связь небезопасна. Аргументы, подкрепленные фактамиМобильная связь небезопасна. Аргументы, подкрепленные фактами
Мобильная связь небезопасна. Аргументы, подкрепленные фактами
 
How to Gain Visibility into Encrypted Threats
How to Gain Visibility into Encrypted ThreatsHow to Gain Visibility into Encrypted Threats
How to Gain Visibility into Encrypted Threats
 
Cisco Wireless LAN Controller Palo Alto Networks Config Guide
Cisco Wireless LAN Controller Palo Alto Networks Config GuideCisco Wireless LAN Controller Palo Alto Networks Config Guide
Cisco Wireless LAN Controller Palo Alto Networks Config Guide
 

Similar to Hoe ontwerp en realiseer je een managed security cloud referentiearchitectuur?

Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
ozkan01
 
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
Cohesive Networks
 
Office Comunnications Server 2007 R2 Poster
Office Comunnications Server 2007 R2 PosterOffice Comunnications Server 2007 R2 Poster
Office Comunnications Server 2007 R2 Poster
Paulo Freitas
 

Similar to Hoe ontwerp en realiseer je een managed security cloud referentiearchitectuur? (20)

Risico op digitale bedreigingen maximaal verminderen - Bijdrage ASP4all voor ...
Risico op digitale bedreigingen maximaal verminderen - Bijdrage ASP4all voor ...Risico op digitale bedreigingen maximaal verminderen - Bijdrage ASP4all voor ...
Risico op digitale bedreigingen maximaal verminderen - Bijdrage ASP4all voor ...
 
Bezpečnostní architektura F5
Bezpečnostní architektura F5Bezpečnostní architektura F5
Bezpečnostní architektura F5
 
Consul Connect - EPAM SEC - 22nd september 2018
Consul Connect - EPAM SEC - 22nd september 2018Consul Connect - EPAM SEC - 22nd september 2018
Consul Connect - EPAM SEC - 22nd september 2018
 
Cld006 azure v_net___express_route_最新情報
Cld006 azure v_net___express_route_最新情報Cld006 azure v_net___express_route_最新情報
Cld006 azure v_net___express_route_最新情報
 
Cld006 azure v_net___express_route_最新情報
Cld006 azure v_net___express_route_最新情報Cld006 azure v_net___express_route_最新情報
Cld006 azure v_net___express_route_最新情報
 
ieeehs042204d
ieeehs042204dieeehs042204d
ieeehs042204d
 
VPC and DX PoP @ HKG
VPC and DX PoP @ HKGVPC and DX PoP @ HKG
VPC and DX PoP @ HKG
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
 
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
 
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – BarracudaProtección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
 
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
 
#CiscoLiveLA 2017 Presentacion de Jerome Henry
#CiscoLiveLA 2017 Presentacion de Jerome Henry#CiscoLiveLA 2017 Presentacion de Jerome Henry
#CiscoLiveLA 2017 Presentacion de Jerome Henry
 
NSX for vSphere Logical Routing Deep Dive
NSX for vSphere Logical Routing Deep DiveNSX for vSphere Logical Routing Deep Dive
NSX for vSphere Logical Routing Deep Dive
 
Office Comunnications Server 2007 R2 Poster
Office Comunnications Server 2007 R2 PosterOffice Comunnications Server 2007 R2 Poster
Office Comunnications Server 2007 R2 Poster
 
Don’t Get Stuck in The Encryption Stone Age: Get Decrypted Visibility with Am...
Don’t Get Stuck in The Encryption Stone Age: Get Decrypted Visibility with Am...Don’t Get Stuck in The Encryption Stone Age: Get Decrypted Visibility with Am...
Don’t Get Stuck in The Encryption Stone Age: Get Decrypted Visibility with Am...
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
 
GAMO VMware vCloud Air
GAMO VMware vCloud AirGAMO VMware vCloud Air
GAMO VMware vCloud Air
 
VMUGbe 21 Filip Verloy
VMUGbe 21 Filip VerloyVMUGbe 21 Filip Verloy
VMUGbe 21 Filip Verloy
 
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
 
2500 controller
2500 controller2500 controller
2500 controller
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 

Hoe ontwerp en realiseer je een managed security cloud referentiearchitectuur?