Virtualization / Cloud / SDN
What most people don’t discuss
• Wim Zandee
• Director System Enigineering North&East EMEA
© F5 Networks, Inc 2
Amazon Prime Air
Delivery in 30 minutes
© F5 Networks, Inc 55
© F5 Networks, Inc 6
© F5 Networks, Inc 7
© F5 Networks, Inc 8
$7.2 MILLION
FINANCIAL IMPACT PER SECURITY BREACH
DELAY AND CUSTOMER’S WILL ABANDON SESSION
4SECOND$110,000LOST REVENUE PER HOUR OF DOWNTIME
Source: bloomberg.com/news/2011-03-08/security-breach-costs-climb-7-to-7-2-million-per-incident.htmlSource: evolven.com/blog/downtime-outages-and-failures-understanding-their-true-costs.htmlSource: manageengine.com/products/applications_manager/business-impact-app-performance-problems.pdf
© F5 Networks, Inc 9
© F5 Networks, Inc 10
Simplify, be flexible, and deploy faster
© F5 Networks, Inc 11
Provide the services all your applications need
© F5 Networks, Inc 12
Evolution in Application Environment
F5 VISION
Applications
without constraints
SDN and
Private Cloud
Software Defined Data
Centers
Cloud and
DevOps
Cloud SLA and control
private network agility
Accelerate time
to market
Agile Development
Rapid deployment─
network and operations velocity
Speed, customer-driven,
and quality of app
development
Failed to Address:
L4–7 device sprawl and
application awareness
© F5 Networks, Inc 13
High-Performance Services Fabric
Network [Physical • Overlay • SDN]
Virtual Edition ChassisAppliance
Data Plane
Programmability
Control Plane Management Plane
On-Demand Scaling All-Active Clustering Multi-Tenancy
ScaleN
TMOS TMOS TMOS TMOS
Throughput
Connections
per second
Concurrent
connectors
Multi-tenant
instances per device
Device service
clusters
© F5 Networks, Inc 14
High-Performance Services
Fabric
Simplified
Business Models
• New licensing models
• Easy to procure
• Save by purchasing bundles
f5 Synthesis
© F5 Networks, Inc 15
Application Provisioning in Today’s Data Centers
• Lacks application agility -
requires provisioning across
different layers by different
organizations
• Time to operationalize
purchased assets is longer due
to inefficient provisioning
• Longer time to deploy
Applications with scale
and security
• Harder to achieve
application elasticity
TENANT (HR) TENANT (FINANCE)
NETWORK CONNECTIVITY
L4-L7
COMPUTE + VM
STORAGE
App x
App y
App z
App p
App q
App r
NETWORK CONNECTIVITY
L4-L7
COMPUTE + VM
STORAGE
NETWORK CONNECTIVITY
L4-L7
COMPUTE + VM
STORAGE
NETWORK CONNECTIVITY
L4-L7
COMPUTE + VM
STORAGE
NETWORK CONNECTIVITY
L4-L7
COMPUTE + VM
STORAGE
NETWORK CONNECTIVITY
L4-L7
COMPUTE + VM
STORAGE
Configure firewall rules as required by the
application
Configure Network to
insert Firewall
Configure firewall
network parameters
Configure Load Balancer as required by the
application
Configure Load Balancer and L4-7 services
Configure Router to steer traffic to/from Load
Balancer
Traditional Network Service Insertion
• Challenges
Service insertion
takes days
Network configuration
is time consuming
and error prone
Difficult to track configuration on
services
Service Insertion In traditional Networks
Server
vFW
Switch
Router
FW
Router
LB
© F5 Networks, Inc 17
10 min.
Provision VM
1-2 weeks
Request infrastructure services,
clarify/define needs (back-and-forth)
1-2 weeks
Sit in IT queue
2-4 hours
Infrastructure services
configuration complete
IT pre-defines catalog of
infrastructure services
Time to production for all
necessary infrastructure
services drops from weeks
to minutes
10 min.
Provision
VM
10 min.
Select correct
infrastructure policy
from catalog
5 min.
Auto-configure
infrastructure
services
Time to Market
Deploying apps in the Datacenter
with
Cisco Application Centric
Infrastructure (ACI) and F5 synthesis
Application Centric Infrastructure (ACI) Vision
Rapid Deployment of Applications onto Networks with Scale, Security and Full Visibility
Cisco Nexus 9500
and 9300
Application Centric
Policy Controller
ACI
Building blocks of ACI
ACI Building Blocks Accelerate Application Deployments
F5 BIG-IPCONTROLLER POLICY MODEL NEXUS 9000 FABRIC
APPLICATION
NETWORK PROFILE
Traditional
3-Tier
Application
FW
ADC
WEB ACC APP DB
Physical + Virtual
Policy extended to L4-L7
Application: 3-tier application (WEB-APP-DB)  This may use ADC, FW services
End point Group (EPG): Grouping of application Components
Policy model: Define QOS, Security, Network, L4-L7 and monitoring policies to be applied to EPG
© F5 Networks, Inc. 21
Return
APIC
Application visibility
A Single View of your Application
HEALTH SCORE
LATENCY
DROP COUNT
VISIBILITY
VMs Physical
Load Balancer
Firewall
21
96%
Microsecond(s)
Packets Dropped
5
25
8 5
Deploying apps in the Datacenter
with
Vmware (NSX) and F5 synthesis
© F5 Networks, Inc 23
F5 Reference Architecture for VMware NSX
NSX
Manager
NSX Management
Generic
Platform
iApps
NSX
Edge
NSX
vSwitch
User
Generic
Platform
Admin
Cloud Management
& Orchestration
Cloud Management
& Orchestration
Application Services
BIG-IP
Platform
Deploying L3–L7 Services
Application
Workloads
BIG-IQ Cloud and BIG-IQ Device
BIG-IP Local Traffic Manager
Simplified Business Models
• Operational agility at the network services (Application
Delivery Networking [ADN]) layer
• Operational agility for application-specific services for
acceleration, availability, and security (a rich Layer 7
protocol)
• Delivering a consistent consumer experience without
consuming IT resources better spent
on strategic projects
NSX / F5 Management Plane Integration
VM VM
Logical
Networks
NSX Logical
Router
INTERNET
User
VMVMVM
BIG-IQ
vCENTER
Server
Server Pool
F5 VE
VM
Configuration1
Management
NSX
Manager
One-time registration of
BIG-IQ with NSX
Manager
BIG-IQ publishes catalog
of iApps to NSX Manager
Cloud Admin specifies
ADC service template
and location for service
instantiation
© F5 Networks, Inc 26
Complete Hybrid App Services Portfolio
Available in all app architectures
LAYER 4-7
STATEFUL
SERVICES
Network
Firewall
Identity and
Access
DDoS
Protection
Global Load
Balancing
Malware
Detection
Application
Security
Local Load
Balancing
Application
Performance
Secure Web
Gateway
DNS Services
SSL VPNWeb Application
Firewall
IPv6 Services
HIGH PERFORMANCE SERVICES FABRIC
VIPRION BIG-IP Virtual Edition Silverline
Silverline
Deploying apps in the Public Cloud
with
F5 synthesis
© F5 Networks, Inc 28
• F5-verified BIG-IP Virtual Edition within
a growing list of cloud providers
• Volume and variety of providers across
the globe and across industries
• Flexible cloud licensing across utility,
BYOL, or subscription
• Support for Microsoft Azure now
available
Expand Industry-leading App Delivery to Public Cloud
F5 verifies cloud service providers
© F5 Networks, Inc 29
• Broadest set of app and security services in public cloud providers
• Including support for Microsoft Azure
• Dynamic scaling of app services in the cloud
• Integration of BIG-IP Virtual Edition (VE) with AWS Auto Scaling
• First and only ADC with SSL Crypto Offload
• SSL scalability for hybrid data centers, freeing up 66% capacity
• Enhanced virtualisation control
• Per-guest SSL and network rate limiting for ultimate flexibility in private clouds
Expand Control with F5 App Services in the Cloud
New capabilities across hybrid environments
© F5 Networks, Inc 30
• F5 services and support
• Supports Cloud Licensing Program and Volume
Licensing Subscription software models
• F5 Security Operations Center (SOC) ensures
24x7 threat monitoring and responses
• F5 community ecosystem
• DevCentral portal where 200,000+ community
experts contribute depth content and support
• F5 Partners leverage depth and expertise of F5
partner ecosystem
Expansive Community of Experts for Greater ROI
Optimise
Maximise
performance,
health,
security
Architect
Design for best
practices
deployments
Implement
Deploy quickly
and optimally
Maintain
Ensure
continued
availability
F5 Services
© F5 Networks, Inc 31
Apps
F5 for the App-centric Strategy
DDoS protection Access and identity
Management and orchestration
SSL enablement
Load balancing
Application security
Programmability
Business continuity
Data Center Private Cloud Public Cloud
DNS
services
Fraud protection
© F5 Networks, Inc 32

Virtualization / Cloud / SDN

  • 1.
    Virtualization / Cloud/ SDN What most people don’t discuss • Wim Zandee • Director System Enigineering North&East EMEA
  • 2.
  • 3.
  • 5.
  • 6.
  • 7.
  • 8.
    © F5 Networks,Inc 8 $7.2 MILLION FINANCIAL IMPACT PER SECURITY BREACH DELAY AND CUSTOMER’S WILL ABANDON SESSION 4SECOND$110,000LOST REVENUE PER HOUR OF DOWNTIME Source: bloomberg.com/news/2011-03-08/security-breach-costs-climb-7-to-7-2-million-per-incident.htmlSource: evolven.com/blog/downtime-outages-and-failures-understanding-their-true-costs.htmlSource: manageengine.com/products/applications_manager/business-impact-app-performance-problems.pdf
  • 9.
  • 10.
    © F5 Networks,Inc 10 Simplify, be flexible, and deploy faster
  • 11.
    © F5 Networks,Inc 11 Provide the services all your applications need
  • 12.
    © F5 Networks,Inc 12 Evolution in Application Environment F5 VISION Applications without constraints SDN and Private Cloud Software Defined Data Centers Cloud and DevOps Cloud SLA and control private network agility Accelerate time to market Agile Development Rapid deployment─ network and operations velocity Speed, customer-driven, and quality of app development Failed to Address: L4–7 device sprawl and application awareness
  • 13.
    © F5 Networks,Inc 13 High-Performance Services Fabric Network [Physical • Overlay • SDN] Virtual Edition ChassisAppliance Data Plane Programmability Control Plane Management Plane On-Demand Scaling All-Active Clustering Multi-Tenancy ScaleN TMOS TMOS TMOS TMOS Throughput Connections per second Concurrent connectors Multi-tenant instances per device Device service clusters
  • 14.
    © F5 Networks,Inc 14 High-Performance Services Fabric Simplified Business Models • New licensing models • Easy to procure • Save by purchasing bundles f5 Synthesis
  • 15.
    © F5 Networks,Inc 15 Application Provisioning in Today’s Data Centers • Lacks application agility - requires provisioning across different layers by different organizations • Time to operationalize purchased assets is longer due to inefficient provisioning • Longer time to deploy Applications with scale and security • Harder to achieve application elasticity TENANT (HR) TENANT (FINANCE) NETWORK CONNECTIVITY L4-L7 COMPUTE + VM STORAGE App x App y App z App p App q App r NETWORK CONNECTIVITY L4-L7 COMPUTE + VM STORAGE NETWORK CONNECTIVITY L4-L7 COMPUTE + VM STORAGE NETWORK CONNECTIVITY L4-L7 COMPUTE + VM STORAGE NETWORK CONNECTIVITY L4-L7 COMPUTE + VM STORAGE NETWORK CONNECTIVITY L4-L7 COMPUTE + VM STORAGE
  • 16.
    Configure firewall rulesas required by the application Configure Network to insert Firewall Configure firewall network parameters Configure Load Balancer as required by the application Configure Load Balancer and L4-7 services Configure Router to steer traffic to/from Load Balancer Traditional Network Service Insertion • Challenges Service insertion takes days Network configuration is time consuming and error prone Difficult to track configuration on services Service Insertion In traditional Networks Server vFW Switch Router FW Router LB
  • 17.
    © F5 Networks,Inc 17 10 min. Provision VM 1-2 weeks Request infrastructure services, clarify/define needs (back-and-forth) 1-2 weeks Sit in IT queue 2-4 hours Infrastructure services configuration complete IT pre-defines catalog of infrastructure services Time to production for all necessary infrastructure services drops from weeks to minutes 10 min. Provision VM 10 min. Select correct infrastructure policy from catalog 5 min. Auto-configure infrastructure services Time to Market
  • 18.
    Deploying apps inthe Datacenter with Cisco Application Centric Infrastructure (ACI) and F5 synthesis
  • 19.
    Application Centric Infrastructure(ACI) Vision Rapid Deployment of Applications onto Networks with Scale, Security and Full Visibility Cisco Nexus 9500 and 9300 Application Centric Policy Controller ACI
  • 20.
    Building blocks ofACI ACI Building Blocks Accelerate Application Deployments F5 BIG-IPCONTROLLER POLICY MODEL NEXUS 9000 FABRIC APPLICATION NETWORK PROFILE Traditional 3-Tier Application FW ADC WEB ACC APP DB Physical + Virtual Policy extended to L4-L7 Application: 3-tier application (WEB-APP-DB)  This may use ADC, FW services End point Group (EPG): Grouping of application Components Policy model: Define QOS, Security, Network, L4-L7 and monitoring policies to be applied to EPG
  • 21.
    © F5 Networks,Inc. 21 Return APIC Application visibility A Single View of your Application HEALTH SCORE LATENCY DROP COUNT VISIBILITY VMs Physical Load Balancer Firewall 21 96% Microsecond(s) Packets Dropped 5 25 8 5
  • 22.
    Deploying apps inthe Datacenter with Vmware (NSX) and F5 synthesis
  • 23.
    © F5 Networks,Inc 23 F5 Reference Architecture for VMware NSX NSX Manager NSX Management Generic Platform iApps NSX Edge NSX vSwitch User Generic Platform Admin Cloud Management & Orchestration Cloud Management & Orchestration Application Services BIG-IP Platform Deploying L3–L7 Services Application Workloads BIG-IQ Cloud and BIG-IQ Device BIG-IP Local Traffic Manager Simplified Business Models • Operational agility at the network services (Application Delivery Networking [ADN]) layer • Operational agility for application-specific services for acceleration, availability, and security (a rich Layer 7 protocol) • Delivering a consistent consumer experience without consuming IT resources better spent on strategic projects
  • 24.
    NSX / F5Management Plane Integration VM VM Logical Networks NSX Logical Router INTERNET User VMVMVM BIG-IQ vCENTER Server Server Pool F5 VE VM Configuration1 Management NSX Manager One-time registration of BIG-IQ with NSX Manager BIG-IQ publishes catalog of iApps to NSX Manager Cloud Admin specifies ADC service template and location for service instantiation
  • 25.
    © F5 Networks,Inc 26 Complete Hybrid App Services Portfolio Available in all app architectures LAYER 4-7 STATEFUL SERVICES Network Firewall Identity and Access DDoS Protection Global Load Balancing Malware Detection Application Security Local Load Balancing Application Performance Secure Web Gateway DNS Services SSL VPNWeb Application Firewall IPv6 Services HIGH PERFORMANCE SERVICES FABRIC VIPRION BIG-IP Virtual Edition Silverline Silverline
  • 26.
    Deploying apps inthe Public Cloud with F5 synthesis
  • 27.
    © F5 Networks,Inc 28 • F5-verified BIG-IP Virtual Edition within a growing list of cloud providers • Volume and variety of providers across the globe and across industries • Flexible cloud licensing across utility, BYOL, or subscription • Support for Microsoft Azure now available Expand Industry-leading App Delivery to Public Cloud F5 verifies cloud service providers
  • 28.
    © F5 Networks,Inc 29 • Broadest set of app and security services in public cloud providers • Including support for Microsoft Azure • Dynamic scaling of app services in the cloud • Integration of BIG-IP Virtual Edition (VE) with AWS Auto Scaling • First and only ADC with SSL Crypto Offload • SSL scalability for hybrid data centers, freeing up 66% capacity • Enhanced virtualisation control • Per-guest SSL and network rate limiting for ultimate flexibility in private clouds Expand Control with F5 App Services in the Cloud New capabilities across hybrid environments
  • 29.
    © F5 Networks,Inc 30 • F5 services and support • Supports Cloud Licensing Program and Volume Licensing Subscription software models • F5 Security Operations Center (SOC) ensures 24x7 threat monitoring and responses • F5 community ecosystem • DevCentral portal where 200,000+ community experts contribute depth content and support • F5 Partners leverage depth and expertise of F5 partner ecosystem Expansive Community of Experts for Greater ROI Optimise Maximise performance, health, security Architect Design for best practices deployments Implement Deploy quickly and optimally Maintain Ensure continued availability F5 Services
  • 30.
    © F5 Networks,Inc 31 Apps F5 for the App-centric Strategy DDoS protection Access and identity Management and orchestration SSL enablement Load balancing Application security Programmability Business continuity Data Center Private Cloud Public Cloud DNS services Fraud protection
  • 31.

Editor's Notes

  • #3  F5 solutions for an application world
  • #7 It's an application world.   Applications drive your business, whether you are an enterprise, service provider, or cloud hosting service, your business runs on applications
  • #8 So, when your applications get hacked, don’t work, or are too slow, business stops; you lose your customer’s trust, and the cost is tremendous, in fact 
  • #10 So, what does IT do to make apply services to applications to make them work the way USERS expect them to work? [Click]
  • #17 Services are used to operating in a specific manner. We call this the “Traditional mode” of operation: In the Traditional mode, services are inserted with VRF/VLAN stitching, WCCP redirect, Policy-based routing (PBR), etc. Challenges This complexity and lack of automation can make the network services more brittle. Configuring new services for deploying a new application takes days/weeks Removing configuration from service devices, e.g. firewall rules, when an application is retired is difficult Auto scale out of services based on load
  • #18 Time to market or time to react is to long in the traditional approach and business is pressing on IT new services faster because: Economic constrains Get IT better aligned with business strategy IT should be an enabler and not a show stopper IT projects which are way out of budget, not in time or just not delivering upon expectations are starting to deliver a negative view on IT organisations, making the business sceptic
  • #24 PRESENTER: Separately, both organizations are solving significant operational issues in the data center. However, the co-developed solution between VMware & F5 eliminates the management silo’s, enabling the delivery of Software Defined Application Services.
  • #25 VMWARE PRESENTER
  • #26 [Need VMWARE PRESENTER Notes] Now let’s turn it back to [F5 Speaker] to summarize.
  • #29 Azure in addition to Amazon Web Services, VMware vCloud Air, and Cisco Intercloud to name a few On-demand utility billing available within key cloud providers for dev & test and BYOL support for production deployments
  • #30 Azure Traffic Manager offers basic load balancing and no app security.. Other ADC vendors do not have built-in integration with AWS AutoScale No other ADC vendor can scale SSL processing from virtual to hardware Other ADC vendors do not support full breadth of hypervisors and offers fewer ways to allocate resources.
  • #33  F5 solutions for an application world