VMworld disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no

Similar documents
OVH: How We Changed the vsphere Cloud Paul Stephenson Staff SE Neal Elinski Technical Product Manager

AUTOMATE CLOUD RECOVERY it s the only way to be sure Ashley Neely Sr. Solution Strategist 2017 Proprietary and Confidential

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Open your mind : mix Private Cloud, Hybridity and Elasticity all together On Prem/Off Prem, Dedicated Cloud infrastructure on both side, automated siz

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

The Virtualisation Security Journey: Beyond Endpoint Security with VMware and Symantec

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

IBM Cloud for VMware Solutions

21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal. By Adeyemi Ademola E. Cloud Engineer

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

A Practitioner s Guide to Migrating Workloads to VMware Cloud on AWS

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Securing VMware NSX-T J U N E 2018

Ordering and deleting Single-node Trial for VMware vcenter Server on IBM Cloud instances

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

1V0-642.exam.30q.

IBM Cloud IBM Cloud for VMware Solutions Zeb Ahmed Senior Offering Manager and BCDR Leader VMware on IBM Cloud VMworld 2017 Content: Not for publicati

IBM Cloud for VMware Solutions NSX Edge Services Gateway Solution Architecture

Private Cloud Public Cloud Edge. Consistent Infrastructure & Consistent Operations

Disclaimer CONFIDENTIAL 2

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

IBM Cloud for vmware Infrastructure design

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Customer Onboarding with VMware NSX L2VPN Service for VMware Cloud Providers

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Securing VMware NSX MAY 2014

VMworld 2018 Content: Not for publication or distribution

VMware Cloud Provider Platform

Workload Mobility and Disaster Recovery to VMware Cloud IaaS Providers

EBOOK: VMware Cloud on AWS: Optimized for the Next-Generation Hybrid Cloud

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Recommended Configuration Maximums. NSX for vsphere Updated on August 08, 2018

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

TECHNICAL WHITE PAPER - MAY 2017 MULTI DATA CENTER POOLING WITH NSX WHITE PAPER

Introducing VMware Validated Designs for Software-Defined Data Center

Introducing VMware Validated Designs for Software-Defined Data Center

Introducing VMware Validated Designs for Software-Defined Data Center

DISASTER RECOVERY- AS-A-SERVICE FOR VMWARE CLOUD PROVIDER PARTNERS WHITE PAPER - OCTOBER 2017

Redefining Hybrid Cloud Management with vcenter Hybrid Linked Mode

VMware Cloud on AWS. A Closer Look. Frank Denneman Senior Staff Architect Cloud Platform BU

vcloud Director Tenant Portal Guide vcloud Director 8.20

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Agenda Basecamp The Journey So Far Enhancements Into the Fear Zone Climbing The VM-Series Performance Peak New VM-Series Models and Licensing Best Pra

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Introducing VMware Validated Design Use Cases. Modified on 21 DEC 2017 VMware Validated Design 4.1

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC)

VMWARE CLOUD FOUNDATION: INTEGRATED HYBRID CLOUD PLATFORM WHITE PAPER NOVEMBER 2017

F5 VMware Virtual Community Roundtable. VMware Alliance F5

Recommended Configuration Maximums

VMware Cloud on AWS The Next Generation Hybrid Cloud Architecture

NSX Data Center Load Balancing and VPN Services

Improve Existing Disaster Recovery Solutions with VMware NSX


SoftLayer Security and Compliance:

What s New in VMware vcloud Director 8.20

Cato Cloud. Software-defined and cloud-based secure enterprise network. Solution Brief

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

DEFINING SECURITY FOR TODAY S CLOUD ENVIRONMENTS. Security Without Compromise

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

IBM Cloud Lessons Learned: VMware Cloud Foundation on IBM Cloud VMworld 2017 We are a cognitive solutions and cloud platform company that leverages th

vcloud Air Advanced Networking Services Guide

VMware Cloud on AWS Networking and Security. 5 September 2018 VMware Cloud on AWS

Global IP Network (GIN) Connects You to the World

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

VM-SERIES FOR VMWARE VM VM

Exam Name: VMware Certified Associate Network Virtualization

5 STEPS TO BUILDING ADVANCED SECURITY IN SOFTWARE- DEFINED DATA CENTERS

SAFEGUARDING YOUR VIRTUALIZED RESOURCES ON THE CLOUD. May 2012

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

NSX Administration Guide. Update 3 Modified on 20 NOV 2017 VMware NSX for vsphere 6.2

WEBSCALE CONVERGED APPLICATION DELIVERY PLATFORM

Cato Cloud. Solution Brief. Software-defined and Cloud-based Secure Enterprise Network NETWORK + SECURITY IS SIMPLE AGAIN

vshield Administration Guide

What s next for your data center? Power Your Evolution with Physical and Virtual ADCs. Jeppe Koefoed Wim Zandee Field sales, Nordics

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

VMware Hybrid Cloud Extension Architecture Field Guide

VMware vcloud Networking and Security Overview

VMware Cloud Foundation Real-World Success with Professional Services

HCX SERVER PRODUCT BRIEF & TECHNICAL FEATURES SUMMARY

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

68% 63% 50% 25% 24% 20% 17% Credit Theft. DDoS. Web Fraud. Cross-site Scripting. SQL Injection. Clickjack. Cross-site Request Forgery.

Introducing VMware Validated Designs for Software-Defined Data Center

Planning and Preparation. VMware Validated Design 4.0 VMware Validated Design for Remote Office Branch Office 4.0

1V0-602.exam. Number: 1V0-602 Passing Score: 800 Time Limit: 120 min. Vmware 1V VMware Certified Associate 6 Hybrid Cloud Fundamentals

VMware Cloud on AWS Getting Started. 18 DEC 2017 VMware Cloud on AWS

Intermedia. CX-E Cloud Hosting Provider. Introduction. Why Intermedia for CX-E Cloud? Cost of Ownership

PUT DATA PROTECTION WHERE YOU NEED IT

SECURING THE MULTICLOUD

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Dedicated Hosted Cloud with vcloud Director

Cisco HyperFlex and the F5 BIG-IP Platform Accelerate Infrastructure and Application Deployments

VMware Cloud on AWS Adoption in the Enterprise

Stop Cyber Threats With Adaptive Micro-Segmentation. Chris Westphal Head Of Product Marketing

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Automated Security for the Real-time Enterprise with VMware NSX and Trend Micro Deep Security Chris Van Den Abbeele, Global Solution Architect, Trend

SECURING THE NEXT GENERATION DATA CENTER. Leslie K. Lambert Juniper Networks VP & Chief Information Security Officer July 18, 2011

Dell EMC. VxBlock Systems for VMware NSX 6.2 Architecture Overview

Transcription:

LHC3296BUS OVH: Shields Up! Building a True Security Barrier in the Cloud Chris Romano, Principal Systems Engineer #VMworld #LHC3296BUS

VMworld disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitment from VMware or OVH to deliver these features in any generally available product. Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind. Technical feasibility and market demand will affect final delivery. Pricing and packaging for any new technologies or features discussed or presented have not been determined. 3

AGENDA 1 OVH Who We Are 2 OVH Product Overview 3 Defense at the PERIMETER DDOS Mitigation 4 Defense WITHIN the Virtual Data Center 6 Securing the Extended Data Center 7 Q & A 4

WHO IS OVH

INTRODUCING OVH GLOBAL HYPER-SCALE CLOUD PROVIDER Own 11+ Tbps Network with 32Points of Presence VMworld 2017 Content: Not for 5 th Largest Cloud Provider in the world* Data center capacity: 1.3 million physical servers; 260,000 already deployed publication Over 1.2 Million Business Clients in 138 Countries 19 years experience building & managing servers + data centers 2016 20 data centers in 5 countries 2017 27 data centers in 11 countries 2020 50 data centers * https://www.netcraft.com/internet-data-mining/hosting-analysis/ 6

OVH BUILDS ITS OWN DATA CENTERS 7

OVH MANUFACTURES SERVERS & USES GREEN TECHNOLOGY VMworld 2017 Content: Not for 30% natural air cooling + 70% water cooling = 0% air conditioning publication 8

SOLUTIONS TO SUIT YOUR NEEDS Hosted Private Cloud + Dedicated Cloud + Virtual Private Cloud + Disaster Recovery + VMware SDDC Public Cloud + Open API + Automation Compatibility + Scalability Dedicated Servers Bare Metal + Bring you own License + Non-Virtual Workloads + Proprietary Software OVH s Fiber Optic Network (11+ Tbps) + Anti-DDoS + Private LAN High Touch Customer Support & Services Global Hyper-Scale Reach

NETWORK CAPACITY 11+ Tbps 10

WHY WE ARE HERE

DEFENSE AT THE PERIMETER

DYN DDOS ATTACK - OCTOBER 21, 2016 Domain name provider Dyn suffered the largest DDoS attack in history on Oct. 21 13

MEANWHILE IN ROUBAIX 1 MONTH EARLIER. 1 Tbps DDoS Attack Launched from 152,000 Hacked Smart Devices This is likely the largest DDoS attack ever reported. Each day OVH detects and mitigates over 1500 attacks against its customers servers. About one third of these attacks are "SYN flood" attacks. Reference Article: https://www.ovh.com/us/news/articles/a2367.the-ddos-that-didnt-break-the-camels-vac 14

DDOS ATTACKS INCREASE 125% ANNUALLY In 2016 we saw 19 attacks over 100 Gbps Source: Akamai: Q1 2016 State of the Internet - Security Report 15

TARGETS AND TYPES OF ATTACKS 16

STAGES OF MANAGING AN ATTACK 1 The server is operational - no attack Internet-based services are used without any problems. VMworld 2017 Content: Not for 3 4 2 The DDoS attack begins the attack is launched via the internet and on the backbone. publication Mitigation of the attack Between 15 and 120 seconds after the attack has started, the mitigation is activated. End of the attack. Auto-mitigation is maintained for 26 hours after the attack has ended 17

VAC OVH S ANSWER TO DDOS VAC Architecture Pre-Firewall OVH Managed Firewall Firewall Network Customer Configurable per IP address Shield Armor VAC Pre-Firewall Firewall Shield Armor UDP reflexion/amplification attacks filtering Profiles based mitigation Does the grunt of the work : SYN Authentication, Zombie detection, payload patterns, Only enabled when we detect an attack 18

OVH MITIGATION TECHNIQUES Traffic Analysis and Attack Detection Netflow analysis of 1/2000 of the traffic that passes through routers. The Armor boxes analyze this and compare it to the attack signatures. If the comparison is positive, mitigation is ACTIVATED WITHIN SECONDS! VMworld 2017 Detection Content: Not for publication 19

LEVERAGING A GLOBAL NETWORK SBG RBX GRA BHS VAC VAC VAC Reference Article: https://www.ovh.com/us/news/articles/a2367.the-ddos-that-didnt-break-the-camels-vac VAC 20

ADDITIONAL PROTECTION Remotely Triggered Black Hole (RTBH) A fully redundant global network Redundancy of all components Fire risk management High security Data Centers VAC Human presence in all Data Centers Anti-Hack Anti-Spam Anti-Phishing Measures to counteract any failure of the electrical supply network. 21

DEFENSE WITHIN THE VIRTUAL DATA CENTER

EDGE SECURITY NSX EDGE GATEWAY (vcloud Air Network) (vcloud Air Network) Stateful Inspection Firewall Network Address Translations (NAT) DHCP Site to Site VPN (IPSec) Static Routing Dynamic Routing OSPF, BGP Load Balancer L4/L7 SSL Certificate Offloading SSL VPN (Client to Server) 200 Sub-Interfaces Distributed Firewall 23

DISTRIBUTED FIREWALL CHARACTERISTICS Runs in Kernel Space Internet Full vcenter Integration (VC Containers, vmotion) VMworld 2017 Zero-trust Security Micro-Segmentation Spoofguard Content: Not for publication Distributed Line Rate Enable traffic redirection to 3 rd party services Fully programmable (REST API) 24

NSX SECURITY IN THE CLOUD Physical Virtual Compute Cluster Compute Cluster Perimeter Firewall (Physical) NSX EDGE Service Gateway WAN Internet Compute Cluster Compute Cluster DFW DFW DFW VMworld 2017 Content: Not for DFW: E-W EDGE: N-S SDDC (Software Defined DC) Edge Service Gateway positioned to protect border of the Cloud Instance or SDDC: North South traffic protection publication Distributed Firewall positioned for internal traffic protection: East West traffic protection 25

SPOOFGUARD Ensuring the IP of a VM cannot be altered without intervention IP address does not match the IP address on record vnic is prevented from accessing the network entirely. Prevents rogue virtual machines from assuming the IP address of an existing VM Guarantees distributed firewall (DFW) rules cannot be bypassed 26

3 RD PARTY INTEGRATION Hytrust Encryption at Rest VM + HyTrust Admin 1 Key Controller 1 Key Controller 2 Private Cloud / vsphere Data Center Admin 2 Key Controller 3 Key Controller 4 VM + HyTrust vcloud Air VM + HyTrust Encrypt and re-key without taking applications offline Transparent to users and admins Customer retention of keys (Bring Your Own Keys) Encryption travels with the VM, regardless of location 27

3 RD PARTY INTEGRATION 28

SECURING THE EXTENDED DATA CENTER

UNIQUE HYBRID CAPABILITIES Migrate Virtual Machines On-Prem to vcloud Air with Zero Downtime Active On-Premises Hybrid Cloud Zero-Downtime Migration Secure Tunnel Replicating vcloud Air Compatibility Portability Security Secure VM migration or vmotion with IPSec and Suite- B Encryption Flow entropy with FOU tunneling Authentication required for migration NAT d vmotion Traffic Overview HCX will available upon release from VMware 30

SECURITY POLICY MIGRATION The VMware SDDC Private Cloud Untether workloads from the physical data center for increased flexibility and agility Security Policy Migration Support data center migration and consolidation projects without need for maintenance windows The VMware Public Cloud Simplify transition to cloud by carrying existing security and networking policies with the virtual machine 31

vrack (VIRTUAL RACK) Secure Private connection of all OVH infrastructures around the world. vrack Enables private connectivity between Data Centers Customer has the ability to make changes themselves Allows extending layer 2 networks Interconnects different environment types on the same VLAN Once enabled, your services communicate with each other across a virtual network (vlan). 32

CONNECTIVITY SIMPLIFIED Dedicated Server Customer Managed Networks & vrack Customer DC Open Stack OVH POP vsphere-asa-service vsphere-asa-service Roubaix Hillsboro Vint Hill 33

SUMMARY OVH is a global hyper-scale cloud provider with a rich 20 year history. OVH ustomers have more options for data center locations, more direct connection points to get to the OVH network, more choices & product selection. Industry leading anti-ddos protection frontends your OVH based assets whether they are dedicated servers, private cloud computing, or public cloud instances. Behind that industry leading DDOS protection is security in depth under your control. 34

HOW TO CONTACT US VMworld Booth Location 406 ovh.com/us @ovh_us and @vcloudair_ovh @ovhus and @vcloudair.ovh OVH and vcloud Air powered by OVH 35

OVH AT VMWORLD Session ID Session Title Time LHC3295BUS OVH: Why Optimizing Layer 0 matters Tuesday, Aug 29, 11:30 a.m. - 12:30 p.m. LHC3297BES How far is too far? The Hybrid Cloud Distance Factor. Monday, Aug 28, 1:00 p.m. - 2:00 p.m. LHC3296BUS Shields Up! Building a True Security Barrier in the Cloud Wednesday, Aug 30, 2:30 p.m. - 3:30 p.m. LHC1951BU Automate Cloud Recovery For When You Are Nuked From Orbit: It s the Only Way to Be Sure VMworld 2017 Content: Not for publication Tuesday, Aug 29, 3:30 p.m. - 4:30 p.m. LHC2673BU Clearing Cloud Confusion Wednesday, Aug 30, 2:00 p.m. - 3:00 p.m. GRC2676BU Building a Paper Trail: How to Secure and Audit a Public Cloud Monday, Aug 28, 11:00 a.m. - 12:00 p.m 36