Choosing a SOA Gateway
 Considerations for Business Managers
Agenda
 Introduction
 Key Functionality
  - Deployability
  - Interoperability
  - Extensibility
  - Manageability
  - etc

 Conclusions
  - Total cost of ownership
 Additional Resources
INTRODUCTION
SOA Gateway Use Cases
 SOA
 - Runtime governance (security, policy enforcement and lifecycle management)
 - Enterprise application integration
 - Sharing sensitive information between businesses/governments
 - Business rule enforcement (such as SLAs; contract-defined limits [# of downloads/day])

 Web
 - API management

 Cloud
 - Identity federation (including SSO to SaaS applications)
 - Integrating enterprise applications with cloud-based services
NOT ALL SOA GATEWAYS ARE THE SAME
Deployability




                Hardware                           Software

           Multiple form factors allow you to choose a solution
              that matches your budget and requirements




                  VMware                      Amazon Machine Image
Interoperability

                                                                    (authentication/
                                                                     authorization)


                                                      IAM system




                                                                               (customizations,
                                                                                 queues, etc)


                                                                   Appserver




                                                                     (identity federation)



              Cloud Gateway/ Cloud Broker
                                                      Secure Token Server

                   Avoid vendor lock-in by ensuring your vendor
                     can accommodate heterogeneous SOA
Platform Interoperability




                 Out-of-the-box, multi-platform support
                      decreases integration costs
Extensibility




                                                       Custom Code




                    Gateways that run custom code simplify
                customization by avoiding appserver integration
Secure Token Service, PKI & Custom Code Onboard




                An all-in-one solution speeds time to
                 deployment and decreases costs
Manageability – Local Clusters

                                   (automated replication)




                                    (clustered systems)




      Administration Console   Single point of administration
                                  simplifies management
Service Metering
         Gets 1 free TV                                                Customer
         show per month                                                Contract




Quincy



                                                                        Telco service
                                                                     provisioning system
          Gets 200 SMS
          per month
Pascal




                          IPTV           SMS                   MMS        Ringtones

                             Integrated clustering lets you
                            enforce exact contractual limits
Manageability – Global Deployments




               Central administration and visibility for all
                Gateways lowers management costs
Manageability – Migration Risk
                         IP: XXX
                              Trust relationships




    dev01LDAP     Development                                              IP: XYY
                     (Asia)                                                     Queue names




                                                                 Test / Staging
                                                                    (cloud)
                                                    test01LDAP




                                                        IP: YYY                                              IP: XXY
                                                            Certificates                                          URL links



                                                                                   prod02LDAP
                prod01LDAP
                                  Production                                                    Production
                                     (NA)                                                         (EMEA)

                                Automatically resolving dependencies
                             between environments reduces migration risk
Constrained National Service Rollout



                
                                            
                                                        



                             
                 IT time and resource constraints can
                  delay service rollout, impacting ROI
Streamlined National Service Rollout




                  
                                                 
     



                              
                   Speed time to deployment by
                   automating service migration
Upgradeability


                            Hardware Upgrade

                                Migration Path




                 Gateways that decouple hardware from
                  soft/firmware simplify upgradeability



                            Soft/Firmware Upgrade

                                Migration Path
License Portability




    Physical                   Virtual                     Cloud



                    License portability lets you avoid
                 platform lock-in and re-licensing costs
CONCLUSIONS
Total Cost of Ownership – Deployment

                                    Deployment Options
                                         Hardware Appliance
                                           Virtual Appliance
          Cost of Deployment
                                  Software (for RHEL, SUSE & Solaris)
                                       Amazon Machine Image
Total Cost of Ownership – Operations

                                     Deployment Options
                                          Hardware Appliance
                                            Virtual Appliance
           Cost of Deployment
                                   Software (for RHEL, SUSE & Solaris)
                                        Amazon Machine Image
                                         Operations
                                            Cluster Support
                                          Automated Failover
                                           Software Upgrade
           Cost of Operations
                                        Integrated Management
                                         Single point of Admin
                                           “Freedom” License
Total Cost of Ownership – Extensibility

                                        Deployment Options
                                             Hardware Appliance
                                               Virtual Appliance
             Cost of Deployment
                                      Software (for RHEL, SUSE & Solaris)
                                           Amazon Machine Image
                                            Operations
                                               Cluster Support
                                             Automated Failover
                                              Software Upgrade
              Cost of Operations
                                           Integrated Management
                                            Single point of Admin
                                              “Freedom” License
                                            Extensibility
                                            Native Java-based SDK
          Cost of Implementation                 Cloud Ready
                                      JMS, WebSphere MQ, raw TCP, etc
Additional Resources
 Contact:
  - Dana Crane, Product Marketing Manager
  - dcrane@layer7tech.com

 Download:
  - “Not all SOA Gateways are Created Equal” White Paper
  - http://www.layer7tech.com/library/

 Attend our next webinar: Managing API Security in SaaS and Cloud
  Presented by Scott Morrison, Layer 7 CTO & Liam Lynch, eBay Chief Security Strategist
  - Security challenges posed by SOAP, REST and Odata APIs
  - Approaches to addressing data and access security
  - Ways to leverage existing security investments
  - Methods for enrolling third-party developers
  - Examples from the real world of how cloud providers use and secure APIs

How to Choose A SOA Gateway from Layer 7

  • 1.
    Choosing a SOAGateway  Considerations for Business Managers
  • 2.
    Agenda  Introduction  KeyFunctionality - Deployability - Interoperability - Extensibility - Manageability - etc  Conclusions - Total cost of ownership  Additional Resources
  • 3.
  • 4.
    SOA Gateway UseCases  SOA - Runtime governance (security, policy enforcement and lifecycle management) - Enterprise application integration - Sharing sensitive information between businesses/governments - Business rule enforcement (such as SLAs; contract-defined limits [# of downloads/day])  Web - API management  Cloud - Identity federation (including SSO to SaaS applications) - Integrating enterprise applications with cloud-based services
  • 5.
    NOT ALL SOAGATEWAYS ARE THE SAME
  • 6.
    Deployability Hardware Software Multiple form factors allow you to choose a solution that matches your budget and requirements VMware Amazon Machine Image
  • 7.
    Interoperability (authentication/ authorization) IAM system (customizations, queues, etc) Appserver (identity federation) Cloud Gateway/ Cloud Broker Secure Token Server Avoid vendor lock-in by ensuring your vendor can accommodate heterogeneous SOA
  • 8.
    Platform Interoperability Out-of-the-box, multi-platform support decreases integration costs
  • 9.
    Extensibility Custom Code Gateways that run custom code simplify customization by avoiding appserver integration
  • 10.
    Secure Token Service,PKI & Custom Code Onboard An all-in-one solution speeds time to deployment and decreases costs
  • 11.
    Manageability – LocalClusters (automated replication) (clustered systems) Administration Console Single point of administration simplifies management
  • 12.
    Service Metering Gets 1 free TV Customer show per month Contract Quincy Telco service provisioning system Gets 200 SMS per month Pascal IPTV SMS MMS Ringtones Integrated clustering lets you enforce exact contractual limits
  • 13.
    Manageability – GlobalDeployments Central administration and visibility for all Gateways lowers management costs
  • 14.
    Manageability – MigrationRisk IP: XXX Trust relationships dev01LDAP Development IP: XYY (Asia) Queue names Test / Staging (cloud) test01LDAP IP: YYY IP: XXY Certificates URL links prod02LDAP prod01LDAP Production Production (NA) (EMEA) Automatically resolving dependencies between environments reduces migration risk
  • 15.
    Constrained National ServiceRollout      IT time and resource constraints can delay service rollout, impacting ROI
  • 16.
    Streamlined National ServiceRollout      Speed time to deployment by automating service migration
  • 17.
    Upgradeability Hardware Upgrade Migration Path Gateways that decouple hardware from soft/firmware simplify upgradeability Soft/Firmware Upgrade Migration Path
  • 18.
    License Portability Physical Virtual Cloud License portability lets you avoid platform lock-in and re-licensing costs
  • 19.
  • 20.
    Total Cost ofOwnership – Deployment Deployment Options  Hardware Appliance  Virtual Appliance Cost of Deployment  Software (for RHEL, SUSE & Solaris)  Amazon Machine Image
  • 21.
    Total Cost ofOwnership – Operations Deployment Options  Hardware Appliance  Virtual Appliance Cost of Deployment  Software (for RHEL, SUSE & Solaris)  Amazon Machine Image Operations  Cluster Support  Automated Failover  Software Upgrade Cost of Operations  Integrated Management  Single point of Admin  “Freedom” License
  • 22.
    Total Cost ofOwnership – Extensibility Deployment Options  Hardware Appliance  Virtual Appliance Cost of Deployment  Software (for RHEL, SUSE & Solaris)  Amazon Machine Image Operations  Cluster Support  Automated Failover  Software Upgrade Cost of Operations  Integrated Management  Single point of Admin  “Freedom” License Extensibility  Native Java-based SDK Cost of Implementation  Cloud Ready  JMS, WebSphere MQ, raw TCP, etc
  • 23.
    Additional Resources  Contact: - Dana Crane, Product Marketing Manager - dcrane@layer7tech.com  Download: - “Not all SOA Gateways are Created Equal” White Paper - http://www.layer7tech.com/library/  Attend our next webinar: Managing API Security in SaaS and Cloud Presented by Scott Morrison, Layer 7 CTO & Liam Lynch, eBay Chief Security Strategist - Security challenges posed by SOAP, REST and Odata APIs - Approaches to addressing data and access security - Ways to leverage existing security investments - Methods for enrolling third-party developers - Examples from the real world of how cloud providers use and secure APIs