Build application-centric data centers to meet modern business user needs

Similar documents
Integrating NetScaler ADCs with Cisco ACI

Cisco CloudCenter Solution with Cisco ACI: Common Use Cases

is also based on Citrix NetScaler support for the Cisco Nexus 1110-S Virtual Services Appliance and related Cisco vpath traffic-steering technology.

Cisco Cloud Application Centric Infrastructure

The ADC Guide to Managing Hybrid (IT and DevOps) Application Delivery. Citrix.com ebook Align Cloud Strategy to Business Goals 1

Service Insertion with ACI using F5 iworkflow

F5 Reference Architecture for Cisco ACI

Cisco HyperFlex and the F5 BIG-IP Platform Accelerate Infrastructure and Application Deployments

DEFINING SECURITY FOR TODAY S CLOUD ENVIRONMENTS. Security Without Compromise

Pulse Secure Application Delivery

How your network can take on the cloud and win. Think beyond traditional networking toward a secure digital perimeter

VMWARE CLOUD FOUNDATION: INTEGRATED HYBRID CLOUD PLATFORM WHITE PAPER NOVEMBER 2017

The Need In today s fast-paced world, the growing demand to support a variety of applications across the data center and help ensure the compliance an

Optimizing your network for the cloud-first world

VMWARE CLOUD FOUNDATION: THE SIMPLEST PATH TO THE HYBRID CLOUD WHITE PAPER AUGUST 2018

Automate Application Deployment with F5 Local Traffic Manager and Cisco Application Centric Infrastructure

Title DC Automation: It s a MARVEL!

Safeguard Application Uptime and Consistent Performance

Cisco Application Centric Infrastructure

Introducing Avaya SDN Fx with FatPipe Networks Next Generation SD-WAN

Features. HDX WAN optimization. QoS

Modelos de Negócio na Era das Clouds. André Rodrigues, Cloud Systems Engineer

Cisco Application Centric Infrastructure (ACI) Simulator

and public cloud infrastructure, including Amazon Web Services (AWS) and AWS GovCloud, Microsoft Azure and Azure Government Cloud.

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

F5 and Nuage Networks Partnership Overview for Enterprises

Multi-Tenancy Designs for the F5 High-Performance Services Fabric

21ST century enterprise. HCL Technologies Presents. Roadmap for Data Center Transformation

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002

SteelConnect. The Future of Networking is here. It s Application- Defined for the Cloud Era. SD-WAN Cloud Networks Branch LAN/WLAN

Optimizing Pulse Secure Access Suite with Pulse Secure Virtual Application Delivery Controller solution

CHARTING THE FUTURE OF SOFTWARE DEFINED NETWORKING

SteelConnect. The Future of Networking is here. It s Application-Defined for the Cloud Era. SD-WAN Cloud Networks Branch LAN/WLAN

Transformation Through Innovation

MODERNIZE YOUR DATA CENTER. With Cisco Nexus Switches

Design and deliver cloud-based apps and data for flexible, on-demand IT

The Programmable Network

How to Leverage Containers to Bolster Security and Performance While Moving to Google Cloud

Cisco Unified Data Center Strategy

Cisco Unified Computing System Delivering on Cisco's Unified Computing Vision

MAKING THE CLOUD A SECURE EXTENSION OF YOUR DATACENTER

Networking for a dynamic infrastructure: getting it right.

The Oracle Trust Fabric Securing the Cloud Journey

I D C T E C H N O L O G Y S P O T L I G H T. V i r t u a l and Cloud D a t a Center Management

VMware vcloud Networking and Security Overview

Transition Your Windows Server 2003 Infrastructure to a Modern Cisco and Microsoft Solution

SteelConnect. The Future of Networking is here. It s Application-Defined for the Cloud Era. SD-WAN Cloud Networks Branch LAN/WLAN

Cisco ONE Enterprise Cloud Suite

Accelerate Your Enterprise Private Cloud Initiative

Data Center and Cloud Automation

DC: Le Converged Infrastructure per Software Defined e Cloud Cisco NetApp - Softway. Luigi MARCOCCHIA SOFTWAY

Flex Tenancy :48:27 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

Cisco Start. IT solutions designed to propel your business

Citrix SD-WAN for Optimal Office 365 Connectivity and Performance

The McAfee MOVE Platform and Virtual Desktop Infrastructure

Transform to Your Cloud

ACCENTURE & RED HAT ACCENTURE CLOUD INNOVATION CENTER

The F5 Application Services Reference Architecture

Enabling Efficient and Scalable Zero-Trust Security

Enabling Fast IT. In the IoE era. Alberto Degradi DCV Sales Leader. November 2014

White paper. Keys to Oracle application acceleration: advances in delivery systems.

Sichere Applikations- dienste

Achieving Digital Transformation: FOUR MUST-HAVES FOR A MODERN VIRTUALIZATION PLATFORM WHITE PAPER

Cisco Application Centric Infrastructure

Pasiruoškite ateičiai: modernus duomenų centras. Laurynas Dovydaitis Microsoft Azure MVP

Micro Focus Network Operations Management Suite Supports SDN and Network Virtualization Engineering and Operations

Cloud Services. Infrastructure-as-a-Service

A10 HARMONY CONTROLLER

Simplify Hybrid Cloud

F5 Networks in the Software Defined DataCenter Era. Paolo Pambianco System Engineer CSP

The Next Opportunity in the Data Centre

Self-driving Datacenter: Analytics

MODERNIZE INFRASTRUCTURE

SIEM Solutions from McAfee

AWS Reference Design Document

Cisco Enterprise Cloud Suite Overview Cisco and/or its affiliates. All rights reserved.

Hitachi Enterprise Cloud Container Platform

Efficience de l IT & croissance?

Solution Overview Cisco Tetration Analytics and AlgoSec: Business Application Connectivity Visibility, Policy Enforcement, and Business-Based Risk and

How Security Policy Orchestration Extends to Hybrid Cloud Platforms

Cloud, SDN and BIGIQ. Philippe Bogaerts Senior Field Systems Engineer

Dell Software Defined Enterprise

AKAMAI CLOUD SECURITY SOLUTIONS

Enterprise Cloud Computing. Eddie Toh Platform Marketing Manager, APAC Data Centre Group Cisco Summit 2010, Kuala Lumpur

White Paper. Why choose NetScaler. Discover 9 ways NetScaler outperforms the competition. citrix.com

That Set the Foundation for the Private Cloud

A Better Approach to Leveraging an OpenStack Private Cloud. David Linthicum

Service Delivery Platform

BUILDING the VIRtUAL enterprise

TALK THUNDER SOFTWARE FOR BARE METAL HIGH-PERFORMANCE SOFTWARE FOR THE MODERN DATA CENTER WITH A10 DATASHEET YOUR CHOICE OF HARDWARE

Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack

NTT Com Press Conference March 1, 2016 #enterprisecloud

Deliver Data Protection Services that Boost Revenues and Margins

Cisco CloudCenter Solution Use Case: Application Migration and Management

Introduction. Delivering Management as Agile as the Cloud: Enabling New Architectures with CA Technologies Virtual Network Assurance Solution

Cisco CloudCenter Solution with VMware

Hybrid Cloud Management: Transforming hybrid cloud delivery

The Why, What, and How of Cisco Tetration

Networking for a smarter data center: Getting it right

Making hybrid IT simple with Capgemini and Microsoft Azure Stack

Transcription:

Build application-centric data centers to meet modern business user needs Citrix.com

Table of contents Meeting current business challenges...3 Device package integration...5 Policy-based service insertion...6 Deployment flexibility and choice...6 Seamless cloud orchestration...8 The business benefits of automation...9 Security...9 Agility...9 Scalability..............................................................9 Conclusion... 10 Learn more... 10 2

Cisco Application Centric Infrastructure (ACI) integrates Citrix application delivery controller (ADC) appliances to reduce deployment complexity and better align applications with dynamic business requirements in existing and nextgeneration data centers. Meeting current business challenges New approaches are redefining IT as the web economy shifts to mobile and application-centric services. IT consumption models are increasingly becoming cloud-based, with a do-it-yourself (DIY) stance and increasing focus on development and operations integration (DevOps) and the concept of anything as a service (XaaS). With the changing character of applications and the evolving requirements for the development and management of these applications, enterprise and service provider IT leaders are seeking and expecting a simple, flexible, automated, and agile infrastructure that better aligns with the needs of the entire application lifecycle from development to deployment. To address these changing requirements in the data center, Cisco offers a new architecture and operation model based on application-centric infrastructure. With tight integration between physical and virtual elements, an open ecosystem model, and innovation spanning application-specific integrated circuits (ASICs), hardware, and software, Cisco ACI takes a holistic system-based approach to IT. This unique approach uses a common policy-based operating model across network, computing, storage, and security elements, overcoming isolated infrastructure and drastically reducing cost and complexity. With Cisco ACI, applications guide networking behavior, not the other way around. This approach redefines the power of IT, making IT more responsive to changing business and application needs, enhancing agility, and adding business value. A Shared Vision Cisco and Citrix share a common vision for network simplification and rapid network service provisioning. Both companies support an application-centric approach that helps address critical customer challenges in both traditional and next-generation data centers. The benefits Cisco ACI can provide to a customer s environment are greatly amplified by the use of Layer 4 through 7 services between the network and the application. integration truly enhances Cisco ACI by enabling best-inclass use of services tightly coupled with the network. 3

A secure, policy-driven architecture Achieving the vision of a truly agile, application-based data center requires a flexible infrastructure that can rapidly provision and configure the necessary resources independent of their location in the data center. With Cisco ACI, this is achieved with the Cisco Application Policy Infrastructure Controller (), a centralized policy management and control point for the entire infrastructure (Figure 1). Figure 1. The Cisco ACI and solution Physical Environments Virtual Environments Container Environments Traditional 3-tier application Web App Database Cisco Administrator Cisco ACI Fabric The Cisco addresses the two main requirements for achieving the application-centric data center vision: Policy-based automation framework Policy-based service insertion technology A policy-based automation framework enables resources to be dynamically provisioned and configured according to application requirements. As a result, core services such as firewalls and Layer 4 through 7 switches can be consumed by applications and made ready to use in a single automated step. A policy-based service insertion solution automates the step of routing network traffic to the correct services based on application policies. The automated addition, removal, and reordering of services allows applications to quickly change the resources that they require without the need to rewire and reconfigure the network or relocate the services. For example, if a business decides to use an application firewall found in a modern ADC as a more economical way of achieving Payment Card Industry (PCI) compliance, administrators simply need to redefine the policy for the services to be used for the related applications. The can dynamically distribute new policies to the infrastructure and service nodes in minutes, without requiring manual changes to the network. 4

Figure 2. device package functions ADC Device Package Policy Manager Script Engine The provides an extendable policy model using device packages. administrator can import device packages. Each device package contains an XML file defining the device configuration model. Using the device package, the configures functions and parameters. Device scripts translate API callouts into device-specific callouts. Device package integration A key benefit of the and Cisco ACI solution is tight integration. Using a full-featured device package, a rich set of ADC features and deployment templates are exposed to and controlled by the. The and are integrated using Representational State Transfer (REST)-based open APIs. A device package uploaded to the enables it to perform detailed, feature-level configuration of Citrix ADC services (Figure 2). These services include: Authentication, authorization, and accounting (AAA) Application firewall Cache redirection Compression Content acceleration Content switching DataStream Domain Name Service (DNS) Global server load balancing Integrated caching Load balancing Secure Sockets Layer (SSL) offload SSL virtual private network (VPN) 5

Policy-based service insertion The Cisco policy-based service insertion solution automates the step of routing network traffic to the correct services based on application policies. This approach enables Layer 4 through 7 resources to be dynamically provisioned and configured according to application requirements on a per-tenant basis. The offers a drag-and-drop graphical user interface (GUI) to easily create Layer 4 through 7 service graphs that specify network traffic routing. All Layer 4 through 7 ADC features available in the device package can be included in a service graph definition, allowing complete integration with the. Once created, a service graph can be assigned to an application profile and contracted to a data center tenant, thereby defining the network traffic flow for that specific application and tenant. Cisco s application-centric service insertion framework allows the to dynamically distribute new policies to the infrastructure and service nodes in minutes, without requiring manual changes to the network. Deployment flexibility and choice Cisco and Citrix offer three deployment modes for the Cisco ACI and solution, so you can choose the automation strategy that works best for your organization today and as needs change over time (Figure 3). Figure 3. Cisco ACI and solution deployment modes NETWORK POLICY/UNMANAGED MODE SERVICE POLICY/MANAGED MODE SERVICE MANAGER/HYBRID MODE L2-L3 network automation L2-L7 ADC automation Centralized L2-L7 automation L2-L3 network automation with service insertion L2-L7 ADC automation ADM Device Package Mini Device Packages ADM Cisco ACI Fabric Cisco ACI Fabric Cisco ACI Fabric L2-L3 automation using existing operational playbook Application policy-driven L2-L3 automation of ACI fabric only L4-L7 services managed outside ACI by service device controller Leverages existing operational roles and playbooks Fully automated stack with centralized control using Cisco Full stack (L2-L7) automation of ACI fabric L4-L7 services dictated by device package and managed by Comprehensive, industry-leading device package integration Full stack automation with operational flexibility Application policy-driven L2-L7 automation of ACI fabric L4-L7 services managed jointly by and Citrix ADM Leverages existing operational roles and playbooks 6

Network Policy/Unmanaged Mode In Network Policy or Unmanaged Mode, the Cisco only manages and automates the network until network traffic reaches the device. Layer 4 through 7 servers are managed outside Cisco ACI by the service device controller. Once the device has performed its tasks, the network traffic generated is again managed by the. This mode requires manual network stitching. As a result, you must provide information about: Which port the service device connects to Which ports are part of a cluster The device operation mode: routed/go-to mode, transparent/go-through mode, or onearm mode Overall, Network Policy Mode leverages existing operational roles and playbooks to automate Layers 2 through 3, while Layers 4 through 7 are managed by the service device controller. Service Policy/Managed Mode In Service Policy or Managed Mode, the entire Layer 2 through 7 stack is controlled and automated using the Cisco. Network services are dictated by the device package and managed by the. The device package is provided by the device vendor, who decides which features are exposed, and uploaded to the. We are excited by the direction Citrix has taken with their ADC and their integration with Cisco ACI. We believe that a concrete SDN solution with L4-7 automation is a game-changer in how nextgeneration data centers will operate and deploy applications. Matt Chamley Head of Global Infrastructure Major Retailer Overall, this mode delivers comprehensive, industry-leading device package integration and a fully automated stack with centralized control. Citrix is an industry leader with this mode. The is the only device to support complete manageability, using the latest ACI Cloud Orchestrator mode, simplifying integrations to orchestrators Northbound to. Service Manager/Hybrid Mode This is the most valuable and common mode of integration. Most businesses moving to Software Defined Networking with ACI identify this mode as the one that most adequately fits their needs. In Service Manager or Hybrid Mode, Layer 4 through 7 services are managed jointly by the Cisco and the Application and Delivery Management (ADM). ADM further simplifies L4-L7 deployments by allowing different lines of business to automate their deployments in ACI using Stylebooks - giving control to provision services to the application owners without the need or knowledge of how to configure a. Layer 2 and 3 network services are configured and automated by the. Using a specialized device package, more nuanced Layer 4 through 7 feature configuration is possible. As with Service Policy Mode, Hybrid Mode also requires a device package to be uploaded to the. However, the function of the device package differs. Hybrid Mode allows the device package developer to customize and manage a subset of Layer 4 through 7 feaures through the using a version of the device package that enables communication between the and the service device controller. As a result, you can manage service devices through the while keeping the full native functionality and customizable parameters available from the service device vendor. For example, security device management is enhanced. A security administrator can manage security policies through a dedicated security controller while configuring network parameters and assigning security policies to a network using the. Overall, Hybrid Mode leverages existing operations roles and playbooks to provide a compromise between Service Policy and Network Policy Modes with both full-stack automation and operational flexibility. 7

Figure 4. Cloud orchestration CLOUD ORCHESTRATION Microsoft Azure Stack OpenStack Cisco ACI Fabric Device Package CITRIX ADC WITH CISCO ACI FABRIC Seamless cloud orchestration The Cloud Orchestrator Mode feature in Cisco enables Layer 2 through 7 automation for private, hybrid, and public clouds and ensures smooth operations. This mode is particularly useful in scenarios where Cisco works with Cloud Orchestrators such as Microsoft Azure Stack. In this mode, the Cloud Orchestrators need not be aware of the configuration semantics of Citrix ADC application delivery controllers. The Cloud Orchestrator mode provides a standard set of parameters that create a unified interface for provisioning in the Cisco ACI fabric. exposes a set of ADC attributes as ADC schema and these attributes are mapped in Citrix Device Package Function Profiles. The cloud administrator can set values for these attributes while provisioning the ADC service via the cloud orchestrator. This solution is not specific to a particular orchestrator, and hence the administrator is free to pick any orchestrator depending on their business need and the Device Package works seamlessly to provision and configure. 8

The business benefits of automation Through data center automation, the Cisco ACI and solution delivers many benefits and IT advantages, including security, agility, and scalability. Security Implement comprehensive security while ensuring compliance with industry standards using native Cisco ACI security and security services. Defend your business using a multilayered, zero-trust, whitelistbased approach to security. Increase network defenses with multiple layers of ACI security. Quarantine malwareaffected servers and virtual machines based on their attributes with microsegmentation. Detect threats faster with extensive network visibility. Simplify security enforcement and monitoring with AAA. Protect your users with a solution that combines policy-based management with SSL, VPN, and application firewalls. Defend applications by provisioning security services with the Cisco. Provide deeper protection for application by integrating new security capabilities from an open ecosystem. Easily change and apply new security settings using policy tracking. Maintain compliance through policybased control, micro-segmentation, and multi-tenancy services that simplify management and administration. Conform to industry security requirements using systemwide policies. Organize sensitive resource and data easily with multitenancy and microsegmentation. Anticipate, detect, and respond to compliance risks with continuous policy monitoring. Agility Rapidly address business changes with infrastructure management tools that feature uncompromising integration between and Cisco ACI. Boost system reliability with monitoring services that intuitively present network health information to enable proactive network management. Enable data-driven improvements with monitoring and logging. Reduce mean time to repair by up to 80% with automated remediation. Easily adapt to change through comprehensive policy-based management of Layer 4 through 7 services. Enhance network flexibility with policy-based insertion that automatically attributes the right resources to applications. Protect your investment with open protocols. Adopt DevOps with a collaborative policy model that enables developers and operations to work together. Deploy quickly by easily propagating policies and services across physical, virtual, and container environments using a common platform. Reduce deployment time by 90% with Cisco services and technical support. Lower risk with a tried, tested, and validated reference architecture used by enterprise customers today. Improve flexibility with multiple deployment modes to choose from. Scalability Maintain uncompromised performance across multiple applications even as demands fluctuate through services that work directly with Cisco ACI. Optimize infrastructure assets using multiple, dynamic load-balancing techniques managed and automated by the Cisco. Improve backend server performance by offloading encryption and decryption tasks to. Reduce server costs by 60% and provide 100% availability with Layer 4 through 7 loadbalancing features. Enhance application performance with data caching techniques including Cache Redirection and inmemory Integrated Caching that lower the overhead associated with repeated content demands. Reduce administrative costs through centralized, policy-based management and automated full-stack provisioning. Speed service delivery with predefined policies and service graphs. Easily scale out network capacity by 32x with TriScale clustering. Simplify network management with multi-tenancy features that let you place up to 115 virtual instances and 512 partitions on a single device. 9

Conclusion As businesses quickly move to make their data centers more agile, application-centric automation and virtualization of both hardware and software infrastructure become increasingly important. The Cisco ACI and solution can help you transform your infrastructure with accelerated application delivery, scalability, security, and ease of management, so you can better meet modern business needs. Learn more Find solutions guides, technical documentation, and videos at: www.cisco.com/go/acicitrix www.citrix.com/products/citrix-adc/resources/cisco About Citrix Citrix (NASDAQ:CTXS) aims to power a world where people, organizations and things are securely connected and accessible to make the extraordinary possible. We help customers reimagine the future of work by providing the most comprehensive secure digital workspace that unifies the apps, data and services people need to be productive, and simplifies IT s ability to adopt and manage complex cloud environments. With 2017 annual revenue of $2.82 billion, Citrix solutions are in use by more than 400,000 organizations including 99 percent of the Fortune 100 and 98 percent of the Fortune 500. Learn more at www.citrix.com. About Cisco Cisco designs and sells broad lines of products, provides services and delivers integrated solutions to develop and connect networks around the world. Over the last 30 years, we have been the world s leader in connecting people, things, and technologies, changing the way the world works, lives, plays, and learns in an increasingly digital world. To find out more, visit www.cisco.com. 2018 Citrix Systems, Inc. All rights reserved. Citrix, the Citrix logo, and other marks appearing herein are property of Citrix Systems, Inc. and/or one or more of its subsidiaries, and may be registered with the U.S. Patent and Trademark Office and in other countries. All other marks are the property of their respective owner(s). 10