NGFWv and ASAv in Public Cloud

Size: px
Start display at page:

Download "NGFWv and ASAv in Public Cloud"

Transcription

1 and ASAv in Amazon Web Services (AWS) and Azure Jesper Rathsach Consulting cybersecurity systems engineer, Cisco Systems 29 th August 2018

2 Introduktion til public cloud Overblik over, FMCv og ASAv Dagens Agenda & ASAv I Azure med use-cases & ASAv I AWS med use-cases Licensing og diverse Tak for I dag

3 Public cloud has great benefits Public Cloud Applications or Workload Application agility Customers Scalability Scale-up and scale-down Employees High availability Regions and Availability zones Partners Data Center Applications Or Workload Cost effectiveness Per-hour, per-minute and per-second billing options 5

4 Public cloud comes with challenges L2 abstraction Connection to Data Center (IPSEC, DX or Express Route) New Services/Environment 6

5 Shared security model in Firewall, AVC, Threat-Centric Customer Responsibility Network URL filtering, AMP & VPN NSG SG NACL ASAv Firewall & VPN Physical Infrastructure Network Infrastructure Virtualization Layer 7

6 AWS components

7 AWS components Overview Code us-east-1 us-east-2 us-west-1 us-west-2 ca-central-1 eu-central-1 eu-west-1 eu-west-2 eu-west-3 Name US East (N. Virginia) US East (Ohio) US West (N. California) US West (Oregon) Canada (Central) EU (Frankfurt) EU (Ireland) EU (London) EU (Paris) ap-northeast-1 Asia Pacific (Tokyo) ap-northeast-2 Asia Pacific (Seoul) ap-northeast-3 Asia Pacific (Osaka-Local) ap-southeast- 1 ap-southeast- 2 ap-south-1 sa-east-1 Asia Pacific (Singapore) Asia Pacific (Sydney) Asia Pacific (Mumbai) South America (São Paulo) 9

8 AWS components Overview Virtual Private Cloud inside-1c mgmt-1c Elastic IP Availability Zone VPC workload1 inside-2c outside-1c us-east-1c mgmt-2c LB Direct Connect Virtual Private Gateway IGW Subnet EC2 Instance Workload Elastic IP Load Balancer NLB, CLB and ALB Internet Gateway workload2 outside-2c us-east-2c destination Route Table: RT next-hop IGW Route Table VGW & Direct Connect 10

9 Route Table and VPC Limitations Route Table Route table is associated to a subnet User defined route can be added Route Table destination subnet next-hop /16 local CIDR /16 EC2 instance VPC More specific routes are not permit /0 IGW /24 x.x.x.x Network limitation No link local multicast or broadcast No IGPs No Proxy ARP and Gratuitous ARP Complex environment for native HA support but workarounds are available for resilient and scalable design IGW More specific route is not permitted in route table /24 Group /24 Network ACL Reference: AWS RT 17

10 Workload security in AWS Groups (SG) and Network ACL (NACL) Group SG acts as a virtual firewall for instance to control inbound and outbound traffic, only L4 rules groups are can only have allow action not deny SGs are stateful SG limit per region 50 Maximum rule per SG 100 Network ACL Same as SG but applied to subnet L4 visibility Action Allow or Deny EC2 instance /24 Group /24 Network ACL VPC Reference: AWS Service Limits 18

11 Azure components

12 Azure components Region and Availability Zone 27

13 Azure components New: Availability Zone vnet Resource Group WEB APP WEB-UDR Destination Next Hop x.x.x.x NVA (Internal) APP-UDR Destination Next Hop x.x.x.x NVA (Internal) ASAv Network Virtual Appliance (NVA) LB Virtual Network vnet Subnet Workload VM User Defined Route UDR Network Virtual Appliance NVA DB Destination x.x.x.x DB-UDR Next Hop NVA (Internal) Availability Set Virtual Network Gateway Gateway Subnet Azure Express Route Availability Set Load Balancer Internal and External Express Route 28

14 Workload security in Azure Network Group (NSG) NSG restricts traffic to resources in a virtual network Action Allow or Deny Direction Inbound and outbound L4 rules Source IP Destination IP Port Protocol NSG limit 5000 (per region per subscription) NSG rule limit 1000 (per NSG) NSG eth0 eth / /24 NSG NSG vnet Reference: Azure Limits and Quotas 29

15 Azure components Route Table and vnet Route Table Route table is associated to subnet User defined route can be added in RT UDRs takes precedence over system routes API integration with UDR Network limitation No link local multicast or broadcast No IGPs No Proxy ARP and Gratuitous ARP No native high availability support for NVA ASAv HA is available ERSPAN is not support because GRE is blocked Destination x.x.x.x Destination x.x.x.x Destination x.x.x.x WEB-UDR Next Hop NVA (Internal) APP-UDR Next Hop NVA (Internal) DB-UDR Next Hop NVA (Internal) vnet /16 Web /24 App /24 Db /24 30

16 Azure and AWS components are similar Virtual Network vnet Availability Set Subnet Azure Virtual Machine VM User Defined Route UDR ARM Template Load Balancer Internal, external and ILB Standard ExpressRoute Public IP Group NACL Network Group Virtual Private Cloud VPC Availability Zone AZ Subnet EC2 Instance Route Table RT CloudFormation Template CF template Load Balancer NLB, CLB, ALB, Internal and External Direct Connect Elastic IP EIP 37

17 and ASAv Overview

18 Why are we here? Let s begin journey towards secured cloud environment 39

19 model in public cloud is not enough Cloud Providers Customer Physical Infrastructure Network and Workload NSG SG NACL Layer 4 Visibility Network Infrastructure ASAv Virtualization Layer Firewall, AVC, NGIPS, AMP VPN and URL Filtering (L4-L7 visibility) Cisco for Stateful firewall, NAT, Routing, ACL and VPN 40

20 /FTDv overview NGIPS Firewall URL AVC AMP AVC - Application Visibility and Control NGIPS Next-Generation Intrusion Prevention System AMP Advanced Malware Protection VPN Virtual Private Network URL URL filtering VPN (IPSEC and SSL) FTD Appliance Managed by Firepower Management Center (FMC) 41

21 Firepower Management Center Centralized Management Total Visibility Real-time threat management Automation FMC Appliance 42

22 ASAv overview Stateful F/W, NAT, Routing and ACL ASAv 9.9.x VPN IPSEC and SSL REST API Route based VPN VTI ASA Appliance 44

23 ASAv Management options Cisco ASDM (on-box manager) Cisco Manager (Centralized Manager) Cisco Defense Orchestrator (Cloud Based) For easy on-box management of common security and policy tasks and CLI based configuration Helps administrators enforce consistent access policies, rapidly troubleshoot security events, and view summarized reports across the deployment For centralized cloud-based policy management of multiple deployments *only for ASA 45

24 and ASAv In public cloud

25 , FMCv and ASAv in Instance types Instance (Marketplace) ASA instance (Marketplace) c3.xlarge, c4.xlarge c3.large, c3.xlarge FMCv Instance (Marketplace) c4. large, c4.xlarge c3.xlarge, c3.2xlarge m4.large, m4.xlarge c4.xlarge, c4.2xlarge large instance is ASAv10, xlarge instance is ASAv30 SSD storage on c3 instance and EBS storage on c4 or m4 instance Instance (Marketplace) Standard D3 and Dv2 ASAv Instance (Marketplace) Standard D3 and D3v2 D3 and D3v2 instance is ASAv30 49

26 in AWS Deploy in routed or passive mode Provides Networking, firewalling, threat-centric protection, URL filtering & AMP capabilities An elastic IP (static persistent public IP) is required for either or Cisco Firepower Management Centre Virtual remote admin access. AWS Group Access control must permit SSH/HTTPs access to your instances and 8305 for SF tunnel Two management interfaces required for AWS eth0 eth1 eth2 eth3 Interface eth0 and eth1 are mgmt. interfaces Interface eth2 and eth3 are data interfaces Instance Type Interfaces Number of vcpus RAM (GB) FMCv & FMCv c3.xlarge c4.xlarge c3.2xlarge c4.2xlarge 2 + 2*

27 in Azure Deploy in Routed Mode supports Routed mode Provides Networking, firewalling, threat-centric protection, URL filtering & AMP capabilities NSG should allow SSH/HTTPs and TCP 8305 (SF-Tunnel) access to your instances on eth0 interface for management access. Two management interfaces required for in Azure North/South, East/West traffic inspection and Microsegmentation eth0 eth1 eth2 eth3 Interface eth0 and eth1 are mgmt. interfaces Interface eth2 and eth3 are data interfaces Supported Machine Size Number of Interfaces (Subnets) NGFW Platform Number of vcpus Standard D3 & D3v2 4 (2+2*) 4 14 RAM (GB) * Management interface 53

28 & ASAv Datasheet Numbers Instance Instance type Throughput Interfaces VPN endpoint AWS c3.xlarge, c4.xlarge 1 Gbps 2 + 2* 250 FMCv c3.xlarge, c4.xlarge c3.2xlarge, c4.2xlarge (-) Management (-) ASAv c3/c4/m4.large (ASAv10) 1 Gbps 2 + 1* 250 c3/c4/m4.xlarge (ASAv30) 1 Gbps 3 + 1* 750 Azure Instance Instance type Throughput Interfaces VPN endpoint Standard D3, D3v2 1 Gbps 2 + 2* 250 ASAv Standard D3, D3v2 (ASAv30) Note: Maximum throughput is measured with traffic under ideal conditions Standard D3, D3v2 supports ASAv5, ASAv10 and ASAv30 license entitlement 100 Mbps (ASAv5) 1 Gbps (ASAv10, ASAv30) 3 + 1* 50, 250 or 750 * Management interface 58

29 Deployment modes

30 Deployment Modes in Routed mode () - AWS Passive mode () - AWS Routed mode () - Azure Passive mode is only applicable to in AWS 60

31 ASAv Deployment Modes in Routed mode (ASAv) - AWS Routed mode (ASAv) - Azure 61

32 in Azure Routed Mode Deployment Deploy in routed mode (L3) available in Azure marketplace Next hop for workloads in Azure vnet Internal Management Managed by FMC or FMCv Public or private IP for Management Use cases VPN (S2S and RA VPN) Firewall, NGIPS, URL-filtering & AMP integration eth1 (diagnostic interface) Internet & RA users eth3 eth2 External Internet FMC 62

33 ASAv in Azure Routed Mode Deployment Deploy in routed mode (L3) ASAv is available in Azure marketplace (ASAv30) Next hop for workloads in AWS ASAv HA (Active/Standby) vnet Inside Management Management interface can be used as a data interface DMZ2 ASAv DMZ2 Use cases Management VPN (S2S and RA VPN) and Firewall Option of installing license for 250 or 750 VPN endpoint Internet & RA users Internet 63

34 in AWS Routed Mode Deployment Deploy in routed mode (L3) and FMCv available in AWS marketplace Next hop for workloads in AWS VPC Internal Management Managed by FMC or FMCv Elastic or private IP for Management Mgmt FMC Use cases VPN (S2S and RA VPN) Firewall, IPS, URL & AMP integration Internet & RA users External IGW 64

35 in AWS Passive Mode Deployment Deploy in Passive Mode Management Managed by FMC or FMCv Elastic or private IP for Management VPC Internal Passive mode requirement Cisco Cloud Services Router forward copy of the traffic to passively inspects traffic sent over ERSPAN session sets interface type as ERSPAN and sets MTU 1600 and assigns IP address Internet & RA users CSRv External IGW 65

36 ASAv in AWS Routed Mode Deployment Deploy ASAv in routed mode (L3) Next hop for workloads in AWS VPC Inside Management Elastic or private IP for Management Managed using CLI, Cisco Manager, ASDM, REST-API and Cisco Defense Orchestrator (CDO) Use cases VPN (S2S and RA VPN) Inter-subnet filtering DMZ1 Internet & RA users ASAv Management/Outside IGW DMZ2 66

37 Management access

38 Management access AWS vnet Azure Internet Internet Manage using private IP (AWS Direct Connect DX) IGW Manage using public IP (Internet) FMC Manage using private IP (Azure Express Route) Manage using public IP (Internet) FMC Direct Connect Data Center Virtual Network Gateway Gateway Subnet Azure Express Route Data Center 68

39 Use cases (Azure)

40 Azure User defined route (UDR) Traffic is forwarded based on the routes in the UDR UDR overrides system routes Destination Default route Default gateway on WebServer01 is WEB-UDR Next Hop ASAv Inside WebServer01 WEB /24 Associated to a subnet APP, DB ASAv Inside Next-hop option (virtual appliance, VNG, vnet, Internet and none) APP ASAv DB vnet API integration to modify routes Internet 72

41 E/W traffic inspection - vnet Youtube: Demo Destination WEB-UDR Next Hop Highlighted routes are required for Micro Segmentation WEB Internet, WEB, DB & DC WEB (Internal) (Internal) Internet & RAVPN users APP-UDR Destination Internet, WEB, DB & DC Next Hop (Internal) Internal External Internet APP APP (Internal) SF tunnel between FMC and (management) DB-UDR GW-Subnet-UDR FMC DB Destination Internet, WEB, APP & DC DB Next Hop (Internal) (Internal) Destination WEB, APP & DB Next Hop (Internal) Azure Express Route Virtual Network Gateway Gateway Subnet Data Center 73

42 E/W traffic inspection - ASAv vnet WEB WEB-UDR Destination Next Hop Internet, WEB, DB & DC ASAv (Inside) DB ASAv (Inside) Highlighted routes are required for Micro Segmentation Internet & RAVPN users APP-UDR Destination Internet, WEB, DB & DC Next Hop ASAv (Inside) Inside ASAv Outside Internet APP DB ASAv (Inside) DB-UDR GW-Subnet-UDR DB Destination Internet, WEB, APP & DC DB Next Hop ASAv (Inside) ASAv (Inside) Destination WEB, APP & DB Next Hop ASAv (Inside) Azure Express Route Virtual Network Gateway same-security-traffic permit intra-interface command is required on ASA for hairpinning Gateway Subnet Data Center 74

43 /ASAv scalable design using Azure ILB with HA ports Azure ILB standard with HA ILB is next hop in UDR ILB load balances complete IP traffic ILB is design to provide traffic symmetry WEB / Nva-subnet /24 Destination APP Destination WEB WEB-UDR Next Hop ILB VIP APP-UDR Next Hop ILB VIP Azure ILB with HA ports APP / FWv01 ilb-ha-fw1 FWv02 ilb-ha-fw2 FWv03 ilb-ha-fw3 FWv04 ilb-ha-fw4 Default route on FWs

44 Service vnet and ASAv Scalable design vnet01 Multiple Subnet Destination All-Subnets All-Subnets-UDR Next Hop ILB VIP Spoke Destination All-Subnets All-Subnets-UDR Next Hop ILB VIP Multiple Subnet vnet02 service vnet Gateway Subnet Virtual Network Gateway Hub ILB HA Default route on FWs FWv01 ilb-ha-fw1 FWv02 ilb-ha-fw2 Nva-Subnet /24 FWv03 ilb-ha-fw3 FWv04 ilb-ha-fw4 83

45 Interconnecting vnet UDR detail FMC Internal vnet1 vnet2 Internal External Site to Site VPN Tunnel External Internal-UDR Internal-UDR Destination Next Hop Destination Next Hop Internet (Inside) Internet (Inside) vnet2 subnets (Inside) vnet1 subnets (Inside) 84

46 Site-to-site and RAVPN UDR detail Internal Internal-UDR RA VPN Users Destination Internet RAVPN Pool Datacenter (DC) Next Hop (Inside) (Inside) (Inside) External Site to Site VPN Tunnel Internet and RAVPN Internet ASAv USE cases Network Address Translation (NAT) Site to Site Tunnel NGFW vnet Access Control Policy, IPS Policy and AMP policy Networking, Firewalling and AVC Data Centre 85

47 Inter subnet filtering APP USE cases Network Address Translation (NAT) Site to Site Tunnel Access Control Policy, IPS Policy and AMP policy Networking, Firewalling and AVC WEB Internet Internet users APP-UDR WEB-UDR Destination Next Hop Destination Next Hop Internet (Inside) Internet -edge(inside) vnet WEB (Inside) WEB -Internal(Outside) 86

48 and ASAv scalable design Azure internal load balancer (ILB) standard & external load balancer WEB APP Destination Default/Internet DB, APP and DC Destination Default/Internet DB, WEB and DC WEB-UDR APP-UDR Next Hop ILB VIP ILB VIP Next Hop ILB VIP ILB VIP ILB Standard x (VIP) HA Port FW01 FW02 FW..n Firewalls in Availability Set ExternalL B vnet Internet Stateless Switchover Internet Users DB DB-UDR Destination Next Hop Default/Internet ILB VIP APP, WEB & DC ILB VIP NVA Subnet (inside) Destination WEB, APP & DB GW-UDR Next Hop ILB VIP Azure Express Route Virtual Network Gateway Gateway Subnet Youtube: overview FMC Data Center 87

49 ARM template deployment

50 Azure Resource Manager (ARM) Template JSON based template for deploying and ASAv Multiple/repeated deployments Add firewall to exiting resource group Add additional attributes for scalable deployment i.e. Availability Set Publish tested templates Deploy multiple Azure resources using single ARM template Create following resources before deploying ASA or using template Resource group, availability set, vnet, subnet and storage account ASAv ASAv ASAv ASAv 89

51 Azure Resource Manager Template ARM templates and demo videos ARM Template: Youtube: Demo ASAv ARM Template: Youtube: Demo ARM Template (LB Sandwich): coming soon Youtube: coming soon 90

52 Use cases (AWS)

53 CloudFormation Template CF template deploys resources in AWS Group of resources in template are called stack Resources are added using JSON object Publish CF template using S3 bucket Advantage of using CF template Simplified infrastructure management Repeated or multiple deployment Reduced human errors Version control using template Update stack and track changes 92

54 Intersubnet filtering VPC CIDR /16 DB /24 CIDR has a local route for VPC Specific route is not allowed in route table Default route will not cover local network Host routes are required to enable Intersubnet filtering destination subnet RT-DB next-hop /16 local /0 eningfwv(internal) destination subnet RT-WEB next-hop /16 local /0 eni-asav(inside) WEB ASAv External IGW 93

55 Secure Transit VPC - VPC A VPC B Spoke VPC AZ1 AZ2 CSRv CSRv Internet RT Transit VPC 94

56 Scalable design

57 scalable design using AWS NLB Network Load Balancer (NLB) VPC inside-1c management-1c FMCv Elastic IP outside-1c Stateless switchover WebServer01 us-east-1c inside-1d management-1d NLB IGW WebServer02 outside-1d us-east-1d Route Table: RT subnet next-hop IGW Youtube: Demo 96

58 scalable design using AWS NLB Network Load Balancer (NLB) VPC inside-1c management-1c FMCv Elastic IP outside-1c Stateless switchover WebServer01 us-east-1c inside-1d management-1d NLB IGW WebServer02 outside-1d Route Table: RT subnet next-hop IGW us-east-1d Multiple firewalls can be added per Availability Zone to provide AZ level scalability Youtube: Demo 97

59 Advanced Malware protection in Azure and AWS

60 integration with AMP AWS and Azure integrates with AMP solution and provide following features VPC CIDR /16 DB /24 AMP for network Continuous analysis Retrospective security Reduce event notifications Integrated malware analysis WEB Malware is detected and dropped by File capture allows you to store and retrieve files for further analysis. The integration of Threat Grid allows you to examine unknown and suspicious files in a safe, highly secure sandbox environment, either in the cloud or locally IGW 99

61 Licensing

62 Licensing Base License (Firewall and AVC) Standard License (Firewall and throughput) NGFW Term based (Threat, URL and AMP) ASA Anyconnect Apex License (SSL and IPSEC) AWS Cisco Smart Licensing Bring your own license (BYOL) Pay as you go model Hourly and annual license Azure Cisco Smart Licensing Bring your own license (BYOL) Note: No Cisco TAC support from AWS pay-as-you-go model license model but you can purchase one year TAC support from listed partner: 101

63 Important Resources

64 YouTube Channel Youtube Channel: 103

65 and ASAv Marketplace Listings Product Marketplace listing BYOL Marketplace listing Hourly & Annual FMCv Marketplace listing BYOL ASAv Marketplace listing BYOL, Hourly & Annual Product Marketplace listing BYOL ASAv Marketplace listing BYOL ASAv HA Marketplace listing - BYOL AWS Marketplace Listing Azure Marketplace Listing

66 Importance Links in public cloud Youtube channel Cisco, ASAv and FMC Chalk talk in Technical Decision Maker Deck (TDM) (Partner level access required) Cisco ASAv licensing (BYOL) Cisco licensing (BYOL) ARM Template ASAv ARM Template 105

67

NGFWv & ASAv in Public Cloud (AWS & Azure)

NGFWv & ASAv in Public Cloud (AWS & Azure) & in Public Cloud (AWS & Azure) Anubhav Swami, CCIE# 21208 Technical Marketing Engineer Your Speaker Anubhav Swami answami@cisco.com Technical Marketing Engineer 5 years in Cisco TAC 2 years in ASA BU

More information

Advanced CSR Lab with High Availability and Transit VPC

Advanced CSR Lab with High Availability and Transit VPC Advanced CSR Lab with High Availability and Transit VPC Fan Yang, Cisco, Engineer, Technical Marketing Nikolai Pitaev, Cisco, Engineer, Technical Marketing LTRVIR-3004 Agenda Slides (30 Min.): CSR 1000V

More information

Deploy the Firepower Management Center Virtual On the AWS Cloud

Deploy the Firepower Management Center Virtual On the AWS Cloud Deploy the Firepower Management Center Virtual On the AWS Cloud Amazon Virtual Private Cloud (Amazon VPC) enables you to launch Amazon Web Services (AWS) resources into a virtual network that you define.

More information

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme LHC2384BU VMware Cloud on AWS A Technical Deep Dive Ray Budavari @rbudavari Frank Denneman - @frankdenneman #VMworld #LHC2384BU Disclaimer This presentation may contain product features that are currently

More information

Cisco Next Generation Firewall and IPS. Dragan Novakovic Security Consulting Systems Engineer

Cisco Next Generation Firewall and IPS. Dragan Novakovic Security Consulting Systems Engineer Cisco Next Generation Firewall and IPS Dragan Novakovic Security Consulting Systems Engineer Cisco ASA with Firepower services Cisco TALOS - Collective Security Intelligence Enabled Clustering & High Availability

More information

Transit Network VPC. AWS Reference Deployment Guide. Last updated: May 10, Aviatrix Systems, Inc. 411 High Street Palo Alto, CA USA

Transit Network VPC. AWS Reference Deployment Guide. Last updated: May 10, Aviatrix Systems, Inc. 411 High Street Palo Alto, CA USA Transit Network VPC AWS Reference Deployment Guide Last updated: May 10, 2017 Aviatrix Systems, Inc. 411 High Street Palo Alto, CA 94301 USA http://www.aviatrix.com Tel: +1 844.262.3100 TABLE OF CONTENTS

More information

NGF0502 AWS Student Slides

NGF0502 AWS Student Slides NextGen Firewall AWS Use Cases Barracuda NextGen Firewall F Implementation Guide Architectures and Deployments Based on four use cases Edge Firewall Secure Remote Access Office to Cloud / Hybrid Cloud

More information

Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers

Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers Speaker: Mun Hossain Director of Product Management - Security Business Group Cisco Twitter: @CiscoDCSecurity 2 Any

More information

EdgeConnect for Amazon Web Services (AWS)

EdgeConnect for Amazon Web Services (AWS) Silver Peak Systems EdgeConnect for Amazon Web Services (AWS) Dinesh Fernando 2-22-2018 Contents EdgeConnect for Amazon Web Services (AWS) Overview... 1 Deploying EC-V Router Mode... 2 Topology... 2 Assumptions

More information

LTRDCN-2100 Cloud networking solutions with Cisco Cloud Services Router (CSR 1000V) on AWS and Azure

LTRDCN-2100 Cloud networking solutions with Cisco Cloud Services Router (CSR 1000V) on AWS and Azure LTRDCN-2100 Cloud networking solutions with Cisco Cloud Services Router (CSR 1000V) on AWS and Azure Fan Yang, Cisco, Engineer, Technical Marketing Raghavendra K S, Cisco, Engineer, Technical Marketing

More information

MyIGW Main. Oregon. MyVPC /16. MySecurityGroup / us-west-2b. Type Port Source SSH /0 HTTP

MyIGW Main. Oregon. MyVPC /16. MySecurityGroup / us-west-2b. Type Port Source SSH /0 HTTP MyIGW Main Oregon MyVPC 10.0.0.0/16 10.0.1.0/24 10.0.1.0 -- us-west-2a MySecurityGroup 10.0.2.0/24 10.0.2.0 -- us-west-2b MyWebServer1 MyDBServer DMZ MyInternetRouteTable 0.0.0.0/0 IGW Type Port Source

More information

Security: Michael South Americas Regional Leader, Public Sector Security & Compliance Business Acceleration

Security: Michael South Americas Regional Leader, Public Sector Security & Compliance Business Acceleration Security: A Driving Force Behind Moving to the Cloud Michael South Americas Regional Leader, Public Sector Security & Compliance Business Acceleration 2017, Amazon Web Services, Inc. or its affiliates.

More information

AWS Networking Fundamentals

AWS Networking Fundamentals AWS Networking Fundamentals Tom Adamski Specialist Solutions Architect, AWS Traditional Network WAN VPN VPN Fiber Applications Applications AWS Network VPN WAN (AWS Direct Connect) VPN Fiber Applications

More information

Next-Generation Security Platform on Azure Reference Architecture

Next-Generation Security Platform on Azure Reference Architecture t n e g i l l e nt i ES UR T C E T I ARCH Next-Generation Security Platform on Azure Reference Architecture Release 2 February 2018 Contents. Introduction................................................

More information

Firepower Techupdate April Jesper Rathsach, Consulting Systems Engineer Cisco Security North April 2017

Firepower Techupdate April Jesper Rathsach, Consulting Systems Engineer Cisco Security North April 2017 Firepower 6.2.1 Techupdate April 2017 Jesper Rathsach, Consulting Systems Engineer Cisco Security North April 2017 Firepower 6.2.1 Nr. 1 most important!! Firepower 6.2.1 BUGFIXES!!!!! Alle kendte severity

More information

Extending Enterprise Security to Multicloud and Public Cloud

Extending Enterprise Security to Multicloud and Public Cloud Extending Enterprise Security to Multicloud and Public Cloud Paul Kofoid Sr. Consulting Engineer: Security & Cloud This statement of direction sets forth Juniper Networks current intention and is subject

More information

Overview. AWS networking services including: VPC Extend your network into a virtual private cloud. EIP Elastic IP

Overview. AWS networking services including: VPC Extend your network into a virtual private cloud. EIP Elastic IP Networking in AWS 2017 Amazon Web Services, Inc. and its affiliates. All rights served. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon Web Services,

More information

Transit VPC Deployment Using AWS CloudFormation Templates. White Paper

Transit VPC Deployment Using AWS CloudFormation Templates. White Paper Transit VPC Deployment Using AWS CloudFormation Templates White Paper Introduction Amazon Web Services(AWS) customers with globally distributed networks commonly need to securely exchange data between

More information

VM-SERIES ON GOOGLE CLOUD DEPLOYMENT GUIDELINES

VM-SERIES ON GOOGLE CLOUD DEPLOYMENT GUIDELINES SERIES ON GOOGLE CLOUD DEPLOYMENT GUIDELINES Organizations are adopting Google Cloud Platform to take advantage of the same technologies that drive common Google services. Many business initiatives, such

More information

How to Deploy the Barracuda NG Firewall in an Amazon Virtual Private Cloud

How to Deploy the Barracuda NG Firewall in an Amazon Virtual Private Cloud How to Deploy the Barracuda NG Firewall in an Amazon Virtual Private Cloud The Barracuda NG Firewall can run as a virtual appliance in the Amazon cloud as a gateway device for Amazon EC2 instances in an

More information

Data Center Security. Fuat KILIÇ Consulting Systems

Data Center Security. Fuat KILIÇ Consulting Systems Data Center Security Fuat KILIÇ Consulting Systems Engineer @Security Data Center Evolution WHERE ARE YOU NOW? WHERE DO YOU WANT TO BE? Traditional Data Center Virtualized Data Center (VDC) Virtualized

More information

Networking in AWS. Carl Simpson Technical Architect, Zen Internet Limited

Networking in AWS. Carl Simpson Technical Architect, Zen Internet Limited Networking in AWS Carl Simpson Technical Architect, Zen Internet Limited carl.simpson@zeninternet.co.uk About Me: About Me: Technical Architect Cloud & Hosting @ Zen Internet Limited About Me: Technical

More information

Cisco Firepower Thread Defence. Claudiu Boar

Cisco Firepower Thread Defence. Claudiu Boar Cisco Firepower Thread Defence Claudiu Boar Security everywhere Stop threats at the edge Control who gets onto your network Find and contain problems fast Protect users wherever they work Simplify network

More information

Deploying Transit VPC for Amazon Web Services

Deploying Transit VPC for Amazon Web Services This section contains the following topics: How to Deploy Transit VPC for DMVPN, page 1 How to Deploy Transit VPC for DMVPN Information About Deploying Transit VPC This is a summary about the deploying

More information

AWS Direct Connect Deep Dive

AWS Direct Connect Deep Dive AWS Direct Connect Deep Dive Steve Seymour Principal Specialist Solutions Architect, AWS @sseymour What is AWS Direct Connect? AWS Direct Connect Dedicated, private connection into AWS Create private (VPC)

More information

Best Practices for Extending the WAN into AWS (IaaS) with SD-WAN

Best Practices for Extending the WAN into AWS (IaaS) with SD-WAN Best Practices for Extending the WAN into AWS (IaaS) with SD-WAN Ariful Huq Product Management @arifulhuq & Rob McBride Marketing @digitalmcb Industry trends impacting networking Cloud Mobile Social 2

More information

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme LHC2103BU NSX and VMware Cloud on AWS: Deep Dive Ray Budavari, Senior Staff Technical Product Manager NSX @rbudavari #VMworld #LHC2103BU Disclaimer This presentation may contain product features that are

More information

Microsoft Networking Academy

Microsoft Networking Academy Microsoft Networking Academy with the C+E Global Black Belts Olivier Martin (@omartin) Networking TSP GBB Jaime Schmidtke (@jaimesc) ExpressRoute Partners GBB Bryan Woodworth (@brwoodwo) Networking TSP

More information

Microsoft Networking Academy

Microsoft Networking Academy Microsoft Networking Academy with the C+E Global Black Belts Olivier Martin (@omartin) Networking TSP GBB Kevin Lopez (@kevlopez) ER Partner Sales Executive GBB Jaime Schmidtke (@jaimesc) ER Partner Sales

More information

Security on AWS(overview) Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance

Security on AWS(overview) Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance Security on AWS(overview) Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance Agenda: Overview AWS Regions Availability Zones Shared Responsibility Security Features Best Practices

More information

2013 AWS Worldwide Public Sector Summit Washington, D.C.

2013 AWS Worldwide Public Sector Summit Washington, D.C. Washington, D.C. VPC Construction Nathan McCourtney Senior Consultant, Professional Services What is a Amazon Virtual Private Cloud (VPC)? A virtual private cloud (VPC) is a virtual network that closely

More information

Segmentation. Threat Defense. Visibility

Segmentation. Threat Defense. Visibility Segmentation Threat Defense Visibility Establish boundaries: network, compute, virtual Enforce policy by functions, devices, organizations, compliance Control and prevent unauthorized access to networks,

More information

MarkLogic Cloud Service Pricing & Billing Effective: October 1, 2018

MarkLogic Cloud Service Pricing & Billing Effective: October 1, 2018 MarkLogic Cloud Service Pricing & Billing Effective: October 1, 2018 MARKLOGIC DATA HUB SERVICE PRICING COMPUTE AND QUERY CAPACITY MarkLogic Data Hub Service capacity is measured in MarkLogic Capacity

More information

Private Cloud Public Cloud Edge. Consistent Infrastructure & Consistent Operations

Private Cloud Public Cloud Edge. Consistent Infrastructure & Consistent Operations Hybrid Cloud Native Public Cloud Private Cloud Public Cloud Edge Consistent Infrastructure & Consistent Operations VMs and Containers Management and Automation Cloud Ops DevOps Existing Apps Cost Management

More information

Compute - 36 PCPUs (72 vcpus) - Intel Xeon E5 2686 v4 (Broadwell) - 512GB RAM - 8 x 2TB NVMe local SSD - Dedicated Host vsphere Features - vsphere HA - vmotion - DRS - Elastic DRS Storage - ESXi boot-from-ebs

More information

How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT

How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT Table of Contents TABLE OF CONTENTS... 1 TEST NETWORK DIAGRAM... 2 PREPARING YOUR VPC... 3 IP addressing... 3 Virtual Private Cloud (VPC)...

More information

SECURING THE MULTICLOUD

SECURING THE MULTICLOUD SECURING THE MULTICLOUD Bahul Harikumar and Ali Bidabadi Juniper Networks This statement of direction sets forth Juniper Networks current intention and is subject to change at any time without notice.

More information

Firebox Cloud. Deployment Guide. Firebox Cloud for AWS and Microsoft Azure

Firebox Cloud. Deployment Guide. Firebox Cloud for AWS and Microsoft Azure Firebox Cloud Deployment Guide Firebox Cloud for AWS and Microsoft Azure About This Guide The Firebox Cloud Deployment Guide is a guide for deployment of a WatchGuard Firebox Cloud virtual security appliance.

More information

25 Best Practice Tips for architecting Amazon VPC

25 Best Practice Tips for architecting Amazon VPC 25 Best Practice Tips for architecting Amazon VPC 25 Best Practice Tips for architecting Amazon VPC Amazon VPC is one of the most important feature introduced by AWS. We have been using AWS from 2008 and

More information

Introduction to Amazon Cloud & EC2 Overview

Introduction to Amazon Cloud & EC2 Overview Introduction to Amazon Cloud & EC2 Overview 2015 Amazon Web Services, Inc. and its affiliates. All rights served. May not be copied, modified, or distributed in whole or in part without the express consent

More information

WHITEPAPER AMAZON ELB: Your Master Key to a Secure, Cost-Efficient and Scalable Cloud.

WHITEPAPER AMAZON ELB: Your Master Key to a Secure, Cost-Efficient and Scalable Cloud. WHITEPAPER AMAZON ELB: Your Master Key to a Secure, Cost-Efficient and Scalable Cloud www.cloudcheckr.com TABLE OF CONTENTS Overview 3 What Is ELB? 3 How ELB Works 4 Classic Load Balancer 5 Application

More information

Getting started with AWS security

Getting started with AWS security Getting started with AWS security Take a prescriptive approach Stella Lee Manager, Enterprise Business Development $ 2 0 B + R E V E N U E R U N R A T E (Annualized from Q4 2017) 4 5 % Y / Y G R O W T

More information

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme LHC2673BU Clearing Cloud Confusion Nick King and Neal Elinski #VMworld #LHC2673BU Disclaimer This presentation may contain product features that are currently under development. This overview of new technology

More information

VMware Cloud on AWS Adoption in the Enterprise

VMware Cloud on AWS Adoption in the Enterprise HYP3920BUS VMware Cloud on AWS Adoption in the Enterprise Kit Colbert, VMware, Inc. Sandy Carter, Amazon Web Services Chuck Hoppenrath, Discovery Communications #vmworld #HYP3920BUS Disclaimer This presentation

More information

The Great Azure Networking Tour. Morgan Simonsen Innofactor

The Great Azure Networking Tour. Morgan Simonsen Innofactor The Great Azure Networking Tour Morgan Simonsen Innofactor About Your Speaker: Morgan Simonsen Cloud Evangelist@Innofactor P-TSP@Microsoft MCSE, MCSA, MCT MVP Twitter: @msimonsen Email: morgan.simonsen@innofactor.com

More information

How to Configure Azure Route Tables (UDR) using Azure Portal and ARM

How to Configure Azure Route Tables (UDR) using Azure Portal and ARM How to Configure Azure Route Tables (UDR) using Azure Portal and ARM Azure Route Tables, or User Defined Routing, allow you to create network routes so that your F-Series Firewall VM can handle the traffic

More information

Data Sheet Gigamon Visibility Platform for AWS

Data Sheet Gigamon Visibility Platform for AWS Data Sheet Gigamon Visibility Platform for Overview The rapid evolution of Infrastructure-as-a-Service (IaaS), or public clouds, brings instant advantages of economies of scale, elasticity, and agility

More information

Azure Compute. Azure Virtual Machines

Azure Compute. Azure Virtual Machines Azure Compute Azure Virtual Machines Virtual Machines Getting started Select image and VM size New disk persisted in storage Management portal Windows Server Boot VM from new disk >_ Scripting (Windows,

More information

AWS Networking & Hybrid Cloud Connectivity

AWS Networking & Hybrid Cloud Connectivity AWS Networking & Hybrid Cloud Connectivity Gold Coast AWS User Group Nov 2015 Kent Plummer - VPN Solutions Managed Private IP Networks for Business vpnsolutions.com.au AWS Networking & Hybrid Cloud Connectivity

More information

ExpressRoute Fridays. with the C+E Black Belts

ExpressRoute Fridays. with the C+E Black Belts ExpressRoute Fridays with the C+E Black Belts Olivier Martin (@omartin) Azure Networking Black Belt Kevin Lopez (@kevlopez) ER Partner Sales Executive Jaime Schmidtke (@jaimesc) ER Partner Sales Executive

More information

AGENDA Introduction Pivotal Cloud Foundry NSX-V integration with Cloud Foundry New Features in Cloud Foundry Networking NSX-T with Cloud Fou

AGENDA Introduction Pivotal Cloud Foundry NSX-V integration with Cloud Foundry New Features in Cloud Foundry Networking NSX-T with Cloud Fou NET1523BE INTEGRATING NSX AND CLOUD FOUNDRY Usha Ramachandran Staff Product Manager, Pivotal Sai Chaitanya Product Line Manager, VMware VMworld 2017 Content: Not for publication #VMworld AGENDA 1 2 3 4

More information

Cisco Firepower NGFW. Anticipate, block, and respond to threats

Cisco Firepower NGFW. Anticipate, block, and respond to threats Cisco Firepower NGFW Anticipate, block, and respond to threats You have a mandate to build and secure a network that supports ongoing innovation Mobile access Social collaboration Public / private hybrid

More information

Nuts & Bolts of Networking in Azure. Pracheta Budhwar Technology Evangelist, Microsoft

Nuts & Bolts of Networking in Azure. Pracheta Budhwar Technology Evangelist, Microsoft Learn. Connect. Explore. Nuts & Bolts of Networking in Azure Pracheta Budhwar Technology Evangelist, Microsoft India @prachetab Agenda Must know concepts of networking on Azure Scenarios - Most commonly

More information

Amazon Virtual Private Cloud Deep Dive

Amazon Virtual Private Cloud Deep Dive Amazon Virtual Private Cloud Deep Dive Steve Seymour, Solutions Architect, Networking Specialist 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved aws vpc -expert-mode Topics today

More information

Security & Compliance in the AWS Cloud. Amazon Web Services

Security & Compliance in the AWS Cloud. Amazon Web Services Security & Compliance in the AWS Cloud Amazon Web Services Our Culture Simple Security Controls Job Zero AWS Pace of Innovation AWS has been continually expanding its services to support virtually any

More information

Amazon Web Services and Feb 28 outage. Overview presented by Divya

Amazon Web Services and Feb 28 outage. Overview presented by Divya Amazon Web Services and Feb 28 outage Overview presented by Divya Amazon S3 Amazon S3 : store and retrieve any amount of data, at any time, from anywhere on web. Amazon S3 service: Create Buckets Create

More information

Security & Compliance in the AWS Cloud. Vijay Rangarajan Senior Cloud Architect, ASEAN Amazon Web

Security & Compliance in the AWS Cloud. Vijay Rangarajan Senior Cloud Architect, ASEAN Amazon Web Security & Compliance in the AWS Cloud Vijay Rangarajan Senior Cloud Architect, ASEAN Amazon Web Services @awscloud www.cloudsec.com #CLOUDSEC Security & Compliance in the AWS Cloud TECHNICAL & BUSINESS

More information

Security Aspekts on Services for Serverless Architectures. Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance

Security Aspekts on Services for Serverless Architectures. Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance Security Aspekts on Services for Serverless Architectures Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance Agenda: Security in General Services in Scope Aspects of Services for

More information

Silver Peak EC-V and Microsoft Azure Deployment Guide

Silver Peak EC-V and Microsoft Azure Deployment Guide Silver Peak EC-V and Microsoft Azure Deployment Guide How to deploy an EC-V in Microsoft Azure 201422-001 Rev. A September 2018 2 Table of Contents Table of Contents 3 Copyright and Trademarks 5 Support

More information

CloudEdge SG6000-VM Installation Guide

CloudEdge SG6000-VM Installation Guide Hillstone Networks, Inc. CloudEdge SG6000-VM Installation Guide Version 5.5R1 Copyright 2015Hillstone Networks, Inc.. All rights reserved. Information in this document is subject to change without notice.

More information

BERLIN. 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved

BERLIN. 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved BERLIN 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved Building Multi-Region Applications Jan Metzner, Solutions Architect Brian Wagner, Solutions Architect 2015, Amazon Web Services,

More information

Extending Enterprise Network into Public Cloud with Cisco CSR1000v

Extending Enterprise Network into Public Cloud with Cisco CSR1000v Extending Enterprise Network into Public Cloud with Cisco CSR1000v Fan Yang, Technical Marketing Engineer Tony Banuelos, Product Manager BRKARC-2749 Cisco Spark How Questions? Use Cisco Spark to chat with

More information

VMware Cloud on AWS The Next Generation Hybrid Cloud Architecture

VMware Cloud on AWS The Next Generation Hybrid Cloud Architecture ware Cloud on AWS The Next Generation Hybrid Cloud Architecture David Lim Head Consulting and MSP Partners, AWS APAC Frank Fan Partner Solution Architect, AWS ANZ Disclaimer This presentation may contain

More information

Cisco Firepower NGFW. Anticipate, block, and respond to threats

Cisco Firepower NGFW. Anticipate, block, and respond to threats Cisco Firepower NGFW Anticipate, block, and respond to threats Digital Transformation on a Massive Scale 15B Devices Today Attack Surface 500B Devices In 2030 Threat Actors $19T Opportunity Next 10 Years

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

Security for shared infrastructure in Cisco ONE Enterprise Cloud Suite BRKPCA-2040

Security for shared infrastructure in Cisco ONE Enterprise Cloud Suite BRKPCA-2040 Security for shared infrastructure in Cisco ONE Enterprise Cloud Suite Roxana Diaz TSA, CCIE BRKPCA-2040 @roxadiaz2 Agenda Introduction Cisco VACS Overview VACS Configuration Security Use-cases Customers

More information

Advanced Techniques for DDoS Mitigation and Web Application Defense

Advanced Techniques for DDoS Mitigation and Web Application Defense Advanced Techniques for DDoS Mitigation and Web Application Defense Dr. Andrew Kane, Solutions Architect Giorgio Bonfiglio, Technical Account Manager June 28th, 2017 2017, Amazon Web Services, Inc. or

More information

Implementing Cisco Edge Network Security Solutions ( )

Implementing Cisco Edge Network Security Solutions ( ) Implementing Cisco Edge Network Security Solutions (300-206) Exam Description: The Implementing Cisco Edge Network Security (SENSS) (300-206) exam tests the knowledge of a network security engineer to

More information

Exam : Implementing Microsoft Azure Infrastructure Solutions

Exam : Implementing Microsoft Azure Infrastructure Solutions Exam 70-533: Implementing Microsoft Azure Infrastructure Solutions Objective Domain Note: This document shows tracked changes that are effective as of January 18, 2018. Design and Implement Azure App Service

More information

Cloudera s Enterprise Data Hub on the Amazon Web Services Cloud: Quick Start Reference Deployment October 2014

Cloudera s Enterprise Data Hub on the Amazon Web Services Cloud: Quick Start Reference Deployment October 2014 Cloudera s Enterprise Data Hub on the Amazon Web Services Cloud: Quick Start Reference Deployment October 2014 Karthik Krishnan Page 1 of 20 Table of Contents Table of Contents... 2 Abstract... 3 What

More information

HOW TO PLAN & EXECUTE A SUCCESSFUL CLOUD MIGRATION

HOW TO PLAN & EXECUTE A SUCCESSFUL CLOUD MIGRATION HOW TO PLAN & EXECUTE A SUCCESSFUL CLOUD MIGRATION Steve Bertoldi, Solutions Director, MarkLogic Agenda Cloud computing and on premise issues Comparison of traditional vs cloud architecture Review of use

More information

Agenda. This Session: Azure Networking Basics, On-prem connectivity options DEMO Create VNET/Gateway Cost-estimation for VNET/Gateways

Agenda. This Session: Azure Networking Basics, On-prem connectivity options DEMO Create VNET/Gateway Cost-estimation for VNET/Gateways Onur Dogruoz Agenda Previous Sessions: Introduction to Azure Infrastructure as a Service (IaaS), Azure portal, role-based access control (RBAC), calculator overview VM Types, Azure Hybrid Use Benefits(AHUB),

More information

Amazon AWS-Solutions-Architect-Professional Exam

Amazon AWS-Solutions-Architect-Professional Exam Volume: 392 Questions Question: 1 By default, Amazon Cognito maintains the last-written version of the data. You can override this behavior and resolve data conflicts programmatically. In addition, push

More information

Azure Everywhere. Brandon Murray, Cami Williams, David Haver, Kevin Carter, Russ Henderson

Azure Everywhere. Brandon Murray, Cami Williams, David Haver, Kevin Carter, Russ Henderson Azure Everywhere Brandon Murray, Cami Williams, David Haver, Kevin Carter, Russ Henderson Agenda Azure Everywhere Workshop Brief Overview of Azure Azure Infrastructure Azure DevOps SQL in Azure SharePoint

More information

Amazon Web Services. Foundational Services for Research Computing. April Mike Kuentz, WWPS Solutions Architect

Amazon Web Services. Foundational Services for Research Computing. April Mike Kuentz, WWPS Solutions Architect Amazon Web Services Foundational Services for Research Computing Mike Kuentz, WWPS Solutions Architect April 2017 2015, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Global Infrastructure

More information

Deploying the Cisco CSR 1000v on Amazon Web Services

Deploying the Cisco CSR 1000v on Amazon Web Services Deploying the Cisco CSR 1000v on Amazon Web Services This section contains the following topics: Prerequisites, page 1 Information About Launching Cisco CSR 1000v on AWS, page 1 Launching the Cisco CSR

More information

CloudEdge Deployment Guide

CloudEdge Deployment Guide Hillstone Networks, Inc. CloudEdge Deployment Guide Version 5.5R3P1 Copyright 2016Hillstone Networks, Inc.. All rights reserved. Information in this document is subject to change without notice. The software

More information

AWS: Basic Architecture Session SUNEY SHARMA Solutions Architect: AWS

AWS: Basic Architecture Session SUNEY SHARMA Solutions Architect: AWS AWS: Basic Architecture Session SUNEY SHARMA Solutions Architect: AWS suneys@amazon.com AWS Core Infrastructure and Services Traditional Infrastructure Amazon Web Services Security Security Firewalls ACLs

More information

Cisco ASA with FirePOWER services Eric Kostlan, Technical Marketing Engineer Security Technologies Group, Cisco Systems LABSEC-2339

Cisco ASA with FirePOWER services Eric Kostlan, Technical Marketing Engineer Security Technologies Group, Cisco Systems LABSEC-2339 Cisco ASA with FirePOWER services Eric Kostlan, Technical Marketing Engineer Security Technologies Group, Cisco Systems LABSEC-2339 Agenda Introduction to Lab Exercises Platforms and Solutions ASA with

More information

Configuring Aviatrix Encryption

Configuring Aviatrix Encryption Configuring Aviatrix Encryption For AWS Direct Connect Azure Express Route Google Cloud Interconnect Last updated: October 9, 2016 Aviatrix Systems, Inc. 4555 Great America Pkwy Santa Clara CA 95054 USA

More information

Pexip Infinity and Amazon Web Services Deployment Guide

Pexip Infinity and Amazon Web Services Deployment Guide Pexip Infinity and Amazon Web Services Deployment Guide Contents Introduction 1 Deployment guidelines 2 Configuring AWS security groups 4 Deploying a Management Node in AWS 6 Deploying a Conferencing Node

More information

Cisco Multicloud Portfolio: Cloud Connect

Cisco Multicloud Portfolio: Cloud Connect Design and Deployment Guide Cisco Multicloud Portfolio: Cloud Connect AWS Transit VPC with Cisco Cloud Services Router 1000V June 2018 2018 Cisco and/or its affiliates. All rights reserved. This document

More information

Virtual Private Cloud. User Guide

Virtual Private Cloud. User Guide Alibaba Cloud provides a default VPC and VSwitch for you in the situation that you do not have any existing VPC and VSwitch to use when creating a cloud product instance. A default VPC and VSwitch will

More information

Srinath Vaddepally.

Srinath Vaddepally. Cloud Computing Srinath Vaddepally CEO & Founder Srinath.Vaddepally@ristcall.com Cell : (816) 728 2134 www.ristcall.com Agenda Automation testing Cloud Computing Motivation factors from Distributed systems

More information

New Features and Functionality

New Features and Functionality This section describes the new and updated features and functionality included in Version 6.2.1. Note that only the Firepower 2100 series devices support Version 6.2.1, so new features deployed to devices

More information

Service Graph Design with Cisco Application Centric Infrastructure

Service Graph Design with Cisco Application Centric Infrastructure White Paper Service Graph Design with Cisco Application Centric Infrastructure 2017 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 101 Contents Introduction...

More information

Configuring a Palo Alto Firewall in AWS

Configuring a Palo Alto Firewall in AWS Configuring a Palo Alto Firewall in AWS Version 1.0 10/19/2015 GRANT CARMICHAEL, MBA, CISSP, RHCA, ITIL For contact information visit Table of Contents The Network Design... 2 Step 1 Building the AWS network...

More information

Introduction to Amazon Cloud & EC2 Overview

Introduction to Amazon Cloud & EC2 Overview Introduction to Amazon Cloud & EC2 Overview 2017 Amazon Web Services, Inc. and its affiliates. All rights served. May not be copied, modified, or distributed in whole or in part without the express consent

More information

Creating your Virtual Data Centre

Creating your Virtual Data Centre Creating your Virtual Data Centre VPC Fundamentals and Connectivity Options Paul Burne, Senior Technical Account Manager, Enterprise Support - 28 th June 2017 2016, Amazon Web Services, Inc. or its Affiliates.

More information

Introduction to the Cisco ASAv

Introduction to the Cisco ASAv Hypervisor Support The Cisco Adaptive Security Virtual Appliance (ASAv) brings full firewall functionality to virtualized environments to secure data center traffic and multitenant environments. You can

More information

Course Outline. Module 1: Microsoft Azure for AWS Experts Course Overview

Course Outline. Module 1: Microsoft Azure for AWS Experts Course Overview Course Outline Module 1: Microsoft Azure for AWS Experts Course Overview In this module, you will get an overview of Azure services and features including deployment models, subscriptions, account types

More information

Getting Started with AWS Security

Getting Started with AWS Security Getting Started with AWS Security Tomas Clemente Sanchez Senior Consultant Security, Risk and Compliance September 21st 2017 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Move

More information

S U M M I T B e r l i n

S U M M I T B e r l i n Berlin SessionID ECS + Fargate Deep Dive Ric Harvey Technical Developer Evangelist Amazon Web Services rjh@amazon.com @ric Harvey https://gitlab.com/ric_harvey/bl_practical_fargate CONTAINERS, CONTAINERS,

More information

Multicloud Networking: An Overview. Shannon McFarland CCIE #5245 Distinguished

Multicloud Networking: An Overview. Shannon McFarland CCIE #5245 Distinguished Multicloud Networking: An Overview Shannon McFarland CCIE #5245 Distinguished Engineer @eyepv6 Agenda Hybrid Cloud Networking vs Multicloud Networking - A Level Set Extending on-premises private cloud

More information

Building a Modular and Scalable Virtual Network Architecture with Amazon VPC

Building a Modular and Scalable Virtual Network Architecture with Amazon VPC Building a Modular and Scalable Virtual Network Architecture with Amazon VPC Quick Start Reference Deployment Santiago Cardenas Solutions Architect, AWS Quick Start Reference Team August 2016 (revisions)

More information

Expected Learning Outcomes Introduction To AWS

Expected Learning Outcomes Introduction To AWS Introduction To AWS Expected Learning Outcomes Introduction To AWS Understand What Cloud Computing Is Discover Why Companies Are Adopting AWS Understand How AWS Can Help Your Explore AWS Services Apply

More information

lab Highly Available and Fault Tolerant Architecture for Web Applications inside a VPC V1.01 AWS Certified Solutions Architect Associate lab title

lab Highly Available and Fault Tolerant Architecture for Web Applications inside a VPC V1.01 AWS Certified Solutions Architect Associate lab title lab lab title Highly Available and Fault Tolerant Architecture for Web Applications inside a VPC V1.01 Course title AWS Certified Solutions Architect Associate Table of Contents Contents Table of Contents...

More information

Cloud and Storage. Transforming IT with AWS and Zadara. Doug Cliche, Storage Solutions Architect June 5, 2018

Cloud and Storage. Transforming IT with AWS and Zadara. Doug Cliche, Storage Solutions Architect June 5, 2018 Cloud and Storage Transforming IT with AWS and Zadara Doug Cliche, Storage Solutions Architect June 5, 2018 What sets AWS apart? Security Fine-grained control Service Breadth & Depth; pace of innovation

More information

DocAve Online 3. Release Notes

DocAve Online 3. Release Notes DocAve Online 3 Release Notes Service Pack 16, Cumulative Update 1 Issued May 2017 New Features and Improvements Added support for new storage regions in Amazon S3 type physical devices, including: US

More information

Networking Lecture 11

Networking Lecture 11 Networking Lecture 11 Deep.Azure@McKesson Zoran B. Djordjević @Zoran B. Djordjević, Nishava, Inc. 1 Azure Networking Azure provides a variety of networking capabilities: Connectivity between Azure resources:

More information