Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Similar documents
Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Private Cloud Public Cloud Edge. Consistent Infrastructure & Consistent Operations

CNA1699BU Running Docker on your Existing Infrastructure with vsphere Integrated Containers Martijn Baecke Patrick Daigle VMworld 2017 Content: Not fo

VMworld 2017 Content: Not for publication #CNA1699BE CONFIDENTIAL 2

DEFINING SECURITY FOR TODAY S CLOUD ENVIRONMENTS. Security Without Compromise

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

VMware Cloud on AWS Technical Deck VMware, Inc.

CONFIDENTLY INTEGRATE VMWARE CLOUD ON AWS WITH INTELLIGENT OPERATIONS

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

NET1821BU THE FUTURE OF NETWORKING AND SECURITY WITH NSX-T Bruce Davie CTO, APJ 2

VMWARE CLOUD FOUNDATION: INTEGRATED HYBRID CLOUD PLATFORM WHITE PAPER NOVEMBER 2017

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

VMware Hybrid Cloud Solution

VMWARE CLOUD FOUNDATION: THE SIMPLEST PATH TO THE HYBRID CLOUD WHITE PAPER AUGUST 2018

The Virtualisation Security Journey: Beyond Endpoint Security with VMware and Symantec

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Management Product Overview and Glimpse into the Future

What You Need to Know About OpenStack + VMware

SECURING THE MULTICLOUD

Securing the Modern Data Center with Trend Micro Deep Security

EBOOK: VMware Cloud on AWS: Optimized for the Next-Generation Hybrid Cloud

AWS Reference Design Document

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

REDUCE TCO AND IMPROVE BUSINESS AND OPERATIONAL EFFICIENCY

AGENDA Introduction Pivotal Cloud Foundry NSX-V integration with Cloud Foundry New Features in Cloud Foundry Networking NSX-T with Cloud Fou

VMworld disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no

Please give me your feedback

Getting Started Guide. VMware NSX Cloud services

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Qualys Cloud Platform

VMware Cloud on AWS. A Closer Look. Frank Denneman Senior Staff Architect Cloud Platform BU

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Virtual Tech Update Intercloud Fabric. Michael Petersen Systems Engineer, Cisco Denmark

Disclaimer CONFIDENTIAL 2

ANIKET DAPTARI & RANJINI RAJENDRAN CONTRAIL TEAM

VMworld 2015 Track Names and Descriptions

VMworld 2013 Overview

10 QUESTIONS, 10 ANSWERS. Get to know VMware Cloud on AWS The Best-in-Class Hybrid Cloud Service

How Microsoft Azure Stack Streamlines Bi-Modal IT

VMware vrealize Network Insight Arkin Messaging Document

Cisco Cloud Application Centric Infrastructure

Agenda Basecamp The Journey So Far Enhancements Into the Fear Zone Climbing The VM-Series Performance Peak New VM-Series Models and Licensing Best Pra

Speaker Introduction Who Mate Barany, VMware Manuel Mazzolin, VMware Peter Schmitt, Deutsche Bahn Systel Why VMworld 2017 Understanding the modern sec

Service Description VMware NSX Cloud

VMWARE ENTERPRISE PKS

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

VMware vrealize Suite and vcloud Suite

Automated Security for the Real-time Enterprise with VMware NSX and Trend Micro Deep Security Chris Van Den Abbeele, Global Solution Architect, Trend

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Getting Hybrid IT Right. A Softchoice Guide to Hybrid Cloud Adoption

VMware Cloud on AWS The Next Generation Hybrid Cloud Architecture

The intelligence of hyper-converged infrastructure. Your Right Mix Solution

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

DATA SHEET AlienVault USM Anywhere Powerful Threat Detection and Incident Response for All Your Critical Infrastructure

The Three Data Challenges

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco

Cisco Container Platform

Cisco HyperFlex and the F5 BIG-IP Platform Accelerate Infrastructure and Application Deployments

VMWARE PKS. What is VMware PKS? VMware PKS Architecture DATASHEET

Redefining Hybrid Cloud Management with vcenter Hybrid Linked Mode

A Practitioner s Guide to Migrating Workloads to VMware Cloud on AWS

HARNESSING THE HYBRID CLOUD TO DRIVE GREATER BUSINESS AGILITY

PUBLIC AND HYBRID CLOUD: BREAKING DOWN BARRIERS

How Security Policy Orchestration Extends to Hybrid Cloud Platforms

No Limits Cloud Introducing the HPE Helion Cloud Suite July 28, Copyright 2016 Vivit Worldwide

Improve Existing Disaster Recovery Solutions with VMware NSX

Moving to the Cloud: Making It Happen With MarkLogic

Cloud Technologies Public and Private Cloud Interconnection

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

REACTIVE TO PROACTIVE TO INNOVATIVE. The Guide to Successful Digital Transformation with Intelligent Operations

Customer Case Studies on Accelerating Their Path to Hybrid Cloud

Managed Platform for Adaptive Computing mpac

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

VMworld 2015 Track Names and Descriptions

Connecting your Microservices and Cloud Services with Oracle Integration CON7348

Migrating Enterprise Applications to the Cloud Session 672. Leighton L. Nelson

AWS Agility + Splunk Visibility = Cloud Success. Splunk App for AWS Demo. Laura Ripans, AWS Alliance Manager

Microsoft Azure for AWS Experts

IBM Cloud for VMware Solutions

What is Dell EMC Cloud for Microsoft Azure Stack?

Creating a Hybrid Gateway for API Traffic. Ed Julson API Platform Product Marketing TIBCO Software

Cloud Computing: Making the Right Choice for Your Organization

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

The Why, What, and How of Cisco Tetration

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Third Party Cloud Services Its Adoption in the New Age

How to Keep UP Through Digital Transformation with Next-Generation App Development

Christopher Covert. Principal Product Manager Enterprise Solutions Group. Copyright 2016 Symantec Endpoint Protection Cloud

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Orchestration: Accelerate Deployments and Reduce Operational Risk. Nathan Pearce, Product Development SA Programmability & Orchestration Team

1560: Storage Management & Business Continuity Strategy and Futures

Transcription:

MMC1532BE Using VMware NSX Cloud for Enhanced Networking and Security for AWS Native Workloads Percy Wadia Amol Tipnis VMworld 2017 Content: Not for publication #VMworld #MMC1532BE

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitment from VMware to deliver these features in any generally available product. Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind. Technical feasibility and market demand will affect final delivery. Pricing and packaging for any new technologies or features discussed or presented have not been determined. 2

Agenda 1 VMware Cloud Services 2 Introducing NSX Cloud 3 Key Customer Challenges 4 NSX Cloud Service Approach 5 Next Steps 3

Existing Apps Reduce Costs Security Reliability Control VISIBILITY OPERATIONS AUTOMATION SECURITY GOVERNANCE VMware Cloud on AWS VMware Cloud Run, Manage, Connect, Secure Any App on Any Cloud to Any Device VIRTUAL MACHINES VMware Cloud Infrastructure for VMware VMware Cloud Services Cloud Management Cloud Native Apps Time to market Innovation Scale Differentiation CONTAINERS Public Cloud IaaS Consistent Infrastructure VM Infrastructure Container Infrastructure Consistent Operations Management and Operations Across Clouds 4

VMware Cloud Services Manage, Govern and Secure Public and Private Cloud Apps VMworld 2017 Discovery Visibility into apps and resources they consume. Analyze usage and utilization across clouds. Cost Insight Accounting and cost optimization for multiple clouds. Track and analyze your costs and trends. NSX Cloud Secure networks with micro-segmentation Create private networks within or across clouds. Network Insight Operational visibility, control, and compliance across clouds. Optimize performance, health, and availability. Wavefront Metrics-driven monitoring and real-time analytics. Content: Not for publication AppDefense Governance for running workloads. ON PREMISES DATA CENTER 5

Key Challenges In Public Clouds Extending enterprise network to cloud Lack of visibility in cloud traffic flows AWS Account 1 Cloud Network Admin VMworld 2017 Content: Not for Cloud Security Admin Security policy consistency across hybrid Dev-ops compliance to enterprise security policies publication Leverage enterprise operational tools DevOps / Developer Remain focused on Application development and deployment 6

VMware NSX Cloud Consistent networking and security for applications running natively in public clouds VNET VPC Web App DB Web App VMware NSX Cloud Visibility Security Networking DB Web Consistency VPC App DB Visibility across clouds Unified security policy Network Portability Consistent Operations 7

Visibility into your cloud environment becomes challenging DevOps 1 AWS Account 1 VPC Cloud Admin How do I consistently know what I am managing and securing Within my VPC? 8

With VPC Sprawl increasing the complexity DevOps 1 AWS Account 1 VPC A VPC B VPC C How do I consistently know what I am managing and securing VMworld 2017 Content: Not for publication Cloud Admin Across VPCs within an Account? 9

Adding the multiple cloud accounts exacerbates the challenge DevOps 3 DevOps 2 DevOps 1 AWS Account 1 VPC A AWS Account 2 AWS Account 3 VPC C VPC VPC B C Web App DB Web App DB A Web App DB Web App VPC DB VPC B C VPC A Web App DB Web App VPC B DB Web Web App App DB Web App DB Web App Web DB DB App DB Web App DB Web App Web DB App Web App Web DB Web App App DB DB Web App WebDB App DB Web App DB Web App Web Web App App DB Web App DB Web DB App Web DB App DB DB VMworld 2017 Content: Not for publication How do I consistently know what I am managing and securing Across multiple Accounts? 10

Demo: Visibility through VMware NSX Cloud Service Manager VMworld 2017 Content: Not for publication 11

1: A Single Pane of Glass across all VPCs, all accounts Single Inventory View across all accounts and all VPCs Operational network / security status of every VM enables Rapid Response 12

And eventually, across all clouds FUTURES Manage and Monitor your cloud across AWS and Azure from a single, consolidated inventory view in NSX Cloud 13

Cloud Security controls are different with their own limitations Cloud Admin AWS VPC 3 Security Groups AWS VPC 2 Security Groups AWS VPC 1 Security Groups VPC 1 AWS Account 1 VPC 2 VPC 3 Multiple VPCs create multiple security touch-points Cloud Security Resource Limitations inhibit consolidation Static Group membership and IP-address rules require coordination at deployment Cloud Operational framework Inconsistent from On-premise 14

2: A Single Security Posture Across your hybrid cloud VPC 1 VPC 2 Security Group 1 Cloud Admin Security Group 2 Security Policy VNET 1 Security Group 3 Single Security Policy Rich set of abstractions Dynamic security group membership No cloud-resource limitations 15

3: Real Time Operational Visibility Into Firewall Rule Invocations AWS Account 1 VPC Web App DB SYSLOG Route firewall logs to industry-standard syslog, leverage SIEM tool of your choice Real-time Operational visibility into your cloud security posture Operationally consistency with your on-premise security environment 16

Demo: Decoupling Application Deployment and Security VMworld 2017 Content: Not for publication 17

4: Defense in Depth through Default Quarantine NSX Managed Test and Dev NSX Unmanaged Multi-layered security through NSX and AWS security groups managed by NSX Fully Configurable to each VPC with exclusion lists + NSX Managed Production Quarantined Best of Both Worlds Greater agility for test&dev, higher structural integrity for production 18

Demo: Multi-layered Security through Default Quarantine 19

5: Extend Enterprise Network Policy to Cloud VPC A NSX Logical Network Topology VPC N Single network policy, deploy anywhere Full control of IP addresses Stretch subnets across public cloud availability zones Static VPC Network Topology 20

6: Network Trace and Visibility VMworld 2017 Content: Not for East-west traffic visibility within VPCs publication Trouble-shooting ease in cloud environments Consistency with onprem operational tools 21

Demo: Troubleshooting through NSX Traceflow VMworld 2017 Content: Not for publication 22

NSX on - premise and in the cloud NSX on-premises We give you bits You install On your servers / In your network You patch, upgrade Perpetual license (usually) NSX Cloud Just log in and use No installation Runs in cloud We take care of patches/ upgrades Pay per use Features are (mostly) the same 23

A Dedicated NSX instance for your Cloud Environment NSX CLOUD DASHBOARD CUSTOMER NSX MANAGERS CUSTOMER COMPUTE VPCs NSX Manager NSX cloud gateway CUSTOMER 1 CUSTOMER 2 Cloud Service Manager NSX cloud gateway NSX Manager NSX cloud gateway Cloud Service Manager NSX cloud gateway VPC -1 VPC -N VPC -1 VPC -N 24

VMware NSX Cloud Under the Covers Architecture NSX CLOUD DASHBOARD MANAGEMENT PLANE CONTROL PLANE CLOUD GATEWAY DATA PLANE NSX Manager Linux VM NSX Controller Cluster NSX Cloud Gateway Cloud Service Manager Windows VM VMware AWS Account Customer AWS Account Public cloud infrastructure with hypervisor (ex: AWS) 25

Operational Control Without Infrastructure Management NSX Operations VMware Customer NSX Cloud Deployment Onboard Compute VPCs Manage Security, Network policies NSX Maintenance / Upgrades 26

NSX Cloud Summary Defines Network Topology And IP Addressing Cloud Network Admin VMworld 2017 Content: Not for DevOps / Developer Cloud Security Admin Focuses on App Development and Deployment Mandates Security Policies and Ensures Compliance publication Decoupling maintains Agility Control Cloud Networking & Security 27

Getting Started with VMware NSX Cloud is Easy Request Access @ https://cloud.vmware.com 28

Learn more about VMware Cloud Services All 3 Days Solutions Exchange Talk to our experts and learn more about VMware Cloud Services Hands On Labs Self services Experience: Try out VMware Cloud Services yourself Tuesday MMC1532BE MMC3164BE Wednesday MMC2888GE MMC3074BE Thursday Continue the NSX Cloud journey! Using VMware NSX for Enhanced Networking and Security for AWS Native Workloads Take the Hands-on Lab for NSX Cloud HOL-1822-01-NET VMware NSX Cloud - Secure Native Workloads in AWS! How Data Science is Transforming Operations: Introduction to Wavefront by VMware How We ve Accelerated Innovation While Keeping Our Cloud Spending in Check Three Ways to Use New VMware Cross-Cloud Services to Efficiently Run Workloads Across AWS, Azure, and vsphere: VMware and Customer Technical Session MMC2820BE MMC3066BE Live Demo: 3 Best Practices for Deploying, Managing and Securing AWS EC2 Apps with VMware Cloud Services How Do You Use Network Insights' SaaS to Secure Multitier Hybrid Apps Running on vsphere, VMware Cloud on AWS, and AWS Native? 29