SlideShare ist ein Scribd-Unternehmen logo
1 von 33
Downloaden Sie, um offline zu lesen
Benjamin Rossignol
Security Consulting Systems Engineer
berossig@cisco.com
Simplifying Security
in the Data Center
How do we Simplify the Secure Data Center?
• Introduction
• Micro-Segmentation
• Secure VDI
• ACI-TrustSec Integration
• Security Feedback Loop with Firepower
Agenda
ACI Service Graphs Keep it Simple
ACI Web Contract
Consumer Provider
Managed/Unmanaged
Devices
Client EPG Web EPG
S
ACI Allows for Easier Services Insertion
L4-L7 Service Automation: Support for All Devices
Any Device and Cluster Manager Support
L4-L7 Service Automation L4-L7 Services
Cisco ACI™
Services Graph
L4- L7 Device Package No Device Package Service Cluster Manager
• Centralized L4-L7 service configuration and management
• Full L4-L7 service automation (with device package)
• Large ecosystem and investment protection
• Security policy follows workload
• Centralized security provisioning and visibility
• Automated service insertion and chaining
• Support for any L4-L7 device
• New support for L4-L7 cluster managers
Embedded
Security
Micro-
Segmentation
Security
Automation
Encryption Analytics
Same Policy Model across physical and any
virtualization or cloud technology
VM
1
VM
2
VM
1
VM
1
VM
2
KVM OpFlex
Agent
V(X)LAN
Open
vSwitch
ESXi Cisco
AVS
V(X)LAN
VMware
DVS
Hyper-V MSFT vSwitch
V(X)LAN
Docker OpFlex
Agent
V(X)LAN
Open
vSwitch
VM
1
VM
1
VM
2
VM
1
Docker1 Docker2
Docker1 Docker2
OpFlex OpFlex OpFlex OpFlex
Bare Metal
VLAN
Can we use Micro Segmentation within ACI to effectively
isolate application traffic?
Using Micro Segmentation
Macro Segmentation
Development
Datacenter
Production
Campus
The separation of Trusted and
Untrusted environments.
Examples:
• Internet
• Campus
• Datacenter
• Development
• Production
Service
Graphs
Firewalls
ACLs
EPGs
Internet
Micro Segmentation
Application
Web Tier
Database
Campus
Ring-fencing, or isolation
application traffic to a specific
set of servers within a
datacenter.
Examples:
• Web Tier to Application
• Application to Database
Service
Graphs
EPGs
Virtual
Firewalls
vDS Cisco AVS IP/MAC EPG Hyper-V vSwitch Open vSwitch Open vSwitch
VLAN
VLAN or
VXLAN
VLAN or
VXLAN VLANVLANVLAN
Micro-Segmentation with ACI
EPG-Web
Micro-Segmentation Across any Workload
Attributes Type
MAC Address Filter Network
IP Address Filter Network
VNic Dn (vNIC domain name) VM
VM Identifier VM
VM Name VM
Hypervisor Identifier VM
VMM Domain VM
Datacenter VM
Custom Attribute
(VMWare AVS/vDS only)
VM
Operating System VM
opflex opflex opflex
vDS Cisco AVS IP/MAC EPG Hyper-V vSwitch Open vSwitch Open vSwitch
VLAN
VLAN or
VXLAN
VLAN or
VXLAN VLANVLANVLAN
MAC-EPG Support in ACI
MAC-EPG-Web
Micro-Segmentation Across any Workload
Attributes Type
MAC Address Filter Network
IP Address Filter Network
VNic Dn (vNIC domain name) VM
VM Identifier VM
VM Name VM
Hypervisor Identifier VM
VMM Domain VM
Datacenter VM
Custom Attribute
(VMWare AVS/vDS only)
VM
Operating System VM
• MAC-EPG is a micro-segmented EPG with endpoint membership based on
MAC address attribute list which is derived from endpoints of a Base EPG
• Scoped at BD level
• MAC-EPGs can have large mac-lists
• Usecases: Migrations, Security Feedback Loop, etc …
MAC-EPG (Micro-Segmentation)
BD1/subnet1
Base EPG
MAC-EPG-1 MAC-EPG-N
Contract
Within BD traffic is Bridged
BD2/subnet2
Base EPG
MAC-EPG-1
Inter BD traffic is Routed
Contract
MicroSegmentation Demo
with ACI
User Segmentation and VDI
Campus
PC
PC
PC
Datacenter
SalesIT
HR
VDI
EPG
Server
EPG
NGFW /
NGIPS
NGFW /
NGIPSSolution provides:
Next-Generation Security (NGFW, NGIPS, AMP) with
Identity controls.
VDI Farm is one big flat subnet, with lateral blocking. Need
to provide secure access to Servers.
Secure VDI Usecase Flow:
User-Identity Micro-Segmentation with FirePower + ACI
Usecase 1 Usecase 2
Shipping
Consuming Micro-Segmentation
User-Identity Micro-Segmentation with ACI
Src-EPG Dest-EPG
Contract
Src-EPG Dest-EPG
Contract
AD based
User
Identify
Policy
Concept
Solution Intra-EPG
Isolation
ACI Service Graph w/ Firepower
Enforce User-Identity Based
Network Access Control Policy
Red User can only Access Red VMs
Green User can only Access Green VMs
ACI Policy
Model
Extension
Shipping
Secure VDI Usecase:
User-Identity Micro-Segmentation with FirePower + ACI
Campus Network
providerconsumer
Firepower 4100 / 9300
FTD Image
vPC
Contract L3out
service-graph with
FirePower
FMC Active
Directory
SF User
Agent
VDI
EPG
L3out
Users Initiate
VDI session
VDI Farm - one big flat subnet but
VMs isolated, blocking lateral
User-Identity
Network Access Control
Policy
Server
EPG
Users (AD Group:
VDI Session)
Destination
Network (Server
EPG)
Group A
1.0.0.1 <= VDI IP
1.0.0.2
Destination Subnet
10.0.0.0/30
Group B
3.0.0.1
Destination
20.0.0.1
SourceFire Policy
Shipping
Secure VDI
Demonstration
User Segmentation
Campus
Control of which systems or
applications within a datacenter
a user or group can connect to.
PC
PC
PC
8 SGT / Sales
3 SGT/ HR
99 SGT / IT
Trustsec / Security Group Tags
VLAN Assignment
Passive Identity from Active Directory
Datacenter
Problem: Disjointed Identity & Security Policy Domains
Between Campus and Data Center
TrustSec domain
Voice Employee Supplier BYOD
Campus / Branch / Non-Fabric
TrustSec Policy Domain
Voic
e
VLA
N
Data
VLAN
Web App DB
ACI Fabric
Data Center
APIC Policy Domain
APIC
WAN
Disjoint: Identity, Grouping
Policy Domains
TrustSec Policy Domain APIC Policy Domain
• Today customer has two disjointed identity and security policy domains in Campus and Data Center:
• TrustSec User Identity, SGT and SGACL in Campus
• APIC App Endpoint Identity, EPG and Contract in Data Center
• Customer Requirement:
• Need Common “Identity,” Tagging and “Security Policy” between TrustSec and ACI domains
TrustSec/ISE Policy Domain
CMD/SGT
ACI Policy Domain
TrustSec
Border Router
(ASR1K Initially)
Higher Scale Data Plane Solution
SXP
SGT <-> EPG
translation
WA
N
IPSec, DMVPN,
GETVPN, OTP
Policy Plane (REST API)
Routing Plane (MP-BGP EVPN)
“Trusted Mode”
Data Plane (GBP VXLAN)
ISE Builds Translation Table
1. GET: VRF-ID, Class-ID
2. SGT <==> VRF-ID, Class-ID
Download
Translation
Table
EPG Starts on ASR1k
2
3
4
Target
Q2-CY17
1
ASR1k(config)# cts sg-epg translations
Golf L3out
Leaf: -EX only
TrustSec/ISE Policy Domain
CMD/SGT
ACI Policy Domain
TrustSec
Border Router
(ASR1K Initially)
Campus to ACI Flow
SXP
SGT <-> EPG
translation
WA
N
IPSec, DMVPN,
GETVPN, OTP SGT-EPG
iVXLAN
Contract Applied on Leaf
Lookup:s-class, d-class, policy
APP-EPG
Golf L3out
Target
Q2-CY17
TrustSec/ISE Policy Domain
CMD/SGT
ACI Policy Domain
TrustSec
Border Router
(ASR1K Initially)
ACI to Campus Flow
SXP
SGT <-> EPG
translation
WA
N
IPSec, DMVPN,
GETVPN, OTP
SGT-EPG
iVXLAN
VzAny Contract
Permit-all or filter ports
APP-EPG
Golf L3out
Target
Q2-CY17
Per-Host Policy
in ASR1k
TrustSec
Domain
Phase 1
Identity and Policy Propagation between
ISE and APIC
No SGT tags sent to ACI
Enforcement at N9300 border leaf
Leverage IP address as User identifier
Scale: ~10k/Leaf
Works with existing ACI infra: N9300
leafs and N9500 Spines
Target Timeframe: Shipping now
Solution: Normalize Identity and SGT/EPG
Phase 2
Policy Mapping between ISE and APIC AND Data
plane Integration (ASR1K or ACI Spine)
ASR1K DCI translates SGT  EPG-Class-ID
Enforcement at N9300 leaf
Scale: SGT/ EPG namespace
Works with existing N9300 leafs, requires upgrade
of N9500 spines (line card/ fabric module available
mid CY16)
Target Timeframe: Q2 CY17
TrustSec
Domain
ACI
Domain
SGT  EPG
SGT  EPG
ACI
Domain
iVXLANSGT
ASR1k
Shipping Q2-CY17
Security Feedback Loop
Firepower, in all its forms, supports:
Correlation Polices and Remediation Modules,
allowing us to take a customized action based on defined
behavior on the network.
Example:
If a server is attacked by host in my PCI network, I want to block the attacker.
Security Feedback Loop
Consuming Micro-Segmentation
ACI and SourceFire – Security Closed Feedback Loop
CORP
EPG
FW
NGIPS
10.1.0.234
Attack
Web
EPG
REM
EPG
QUA
EPG
FW
FireSIGHT
Management
Center
REST Calls to
APIC NB API
Move VM
To Quarantine
Quarantine for RemediationPost Remediation Move Cleaned VM
Status:
1. Cisco on Cisco solution (ACI + Security BU)
2. Remediation module in FMC used for security
feedback loop (no, device package required)
3. Productization for VMware vDS, AVS and BM
is shipping
• Quarantine IP-EPG creation
• Quarantine bad endpoints using IP-
EPG only
4. Tested 150 IP-EPG creation and TBD
endpoints
5. NGIPS stitching has no dependencies on
Remediation module. NGIPS Stitching can we
with device package or not. Both options
supported.
Demo Video: https://youtu.be/zSfDT1-47Hg
Security Feedback Loop, continued…
Security Feedback Loop, continued…
Cisco has just released the
new ACI Remediation Module
for Firepower!
Security Feedback Loop, continued…
Security Feedback Loop
Demonstration
• FMC Remediation Module for ACI Documentation
http://www.cisco.com/c/dam/en/us/td/docs/security/asa/apic/quick-start/guide/fmc-rm-qsg1x.pdf
• FMC Remediation Module for ACI YouTube Video
https://www.youtube.com/watch?v=zSfDT1-47Hg&feature=youtu.be
• Micro Segmentation Demo on YouTube
https://youtu.be/EEs7B1dKVjE
Additional Resources
Simplifying the secure data center

Weitere ähnliche Inhalte

Was ist angesagt?

Hosted Security as a Service - Solution Architecture Design
Hosted Security as a Service - Solution Architecture DesignHosted Security as a Service - Solution Architecture Design
Hosted Security as a Service - Solution Architecture DesignCisco Canada
 
Secure collab on prem hikmat
Secure collab on prem   hikmatSecure collab on prem   hikmat
Secure collab on prem hikmatCisco Canada
 
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network IntuitiveCisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network IntuitiveCisco Canada
 
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...Cisco Canada
 
Cisco contact center
Cisco contact centerCisco contact center
Cisco contact centerCisco Canada
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaCisco Canada
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Canada
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingCisco Canada
 
Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...
Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...
Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...Cisco Canada
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityRobb Boyd
 
Data Center Security
Data Center SecurityData Center Security
Data Center SecurityCisco Canada
 
F5 Networks: Introduction to Silverline WAF (web application firewall)
F5 Networks: Introduction to Silverline WAF (web application firewall)F5 Networks: Introduction to Silverline WAF (web application firewall)
F5 Networks: Introduction to Silverline WAF (web application firewall)F5 Networks
 
VMworld 2014: Virtualize your Network with VMware NSX
VMworld 2014: Virtualize your Network with VMware NSXVMworld 2014: Virtualize your Network with VMware NSX
VMworld 2014: Virtualize your Network with VMware NSXVMworld
 
NSO: Network Service Orchestrator enabled by Tail-f Hands-on Lab
NSO: Network Service Orchestrator enabled by Tail-f Hands-on LabNSO: Network Service Orchestrator enabled by Tail-f Hands-on Lab
NSO: Network Service Orchestrator enabled by Tail-f Hands-on LabCisco Canada
 
Magical meeting experiences
Magical meeting experiences Magical meeting experiences
Magical meeting experiences Cisco Canada
 

Was ist angesagt? (20)

Hosted Security as a Service - Solution Architecture Design
Hosted Security as a Service - Solution Architecture DesignHosted Security as a Service - Solution Architecture Design
Hosted Security as a Service - Solution Architecture Design
 
Secure collab on prem hikmat
Secure collab on prem   hikmatSecure collab on prem   hikmat
Secure collab on prem hikmat
 
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network IntuitiveCisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
 
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
 
Cisco contact center
Cisco contact centerCisco contact center
Cisco contact center
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC Networking
 
Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...
Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...
Cisco Connect Toronto 2017 - Cloud and On Premises Collaboration Security Exp...
 
F5 Cloud Story
F5 Cloud StoryF5 Cloud Story
F5 Cloud Story
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
 
Azure F5 Solutions
Azure F5 SolutionsAzure F5 Solutions
Azure F5 Solutions
 
Data Center Security
Data Center SecurityData Center Security
Data Center Security
 
F5 Networks: Introduction to Silverline WAF (web application firewall)
F5 Networks: Introduction to Silverline WAF (web application firewall)F5 Networks: Introduction to Silverline WAF (web application firewall)
F5 Networks: Introduction to Silverline WAF (web application firewall)
 
VMworld 2014: Virtualize your Network with VMware NSX
VMworld 2014: Virtualize your Network with VMware NSXVMworld 2014: Virtualize your Network with VMware NSX
VMworld 2014: Virtualize your Network with VMware NSX
 
NSO: Network Service Orchestrator enabled by Tail-f Hands-on Lab
NSO: Network Service Orchestrator enabled by Tail-f Hands-on LabNSO: Network Service Orchestrator enabled by Tail-f Hands-on Lab
NSO: Network Service Orchestrator enabled by Tail-f Hands-on Lab
 
F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)
 
Magical meeting experiences
Magical meeting experiences Magical meeting experiences
Magical meeting experiences
 

Andere mochten auch

Secure collab on premise
Secure collab on premiseSecure collab on premise
Secure collab on premiseCisco Canada
 
Secure Data Center Solution with FP 9300 - BDM
Secure Data Center Solution with FP 9300 - BDMSecure Data Center Solution with FP 9300 - BDM
Secure Data Center Solution with FP 9300 - BDMBill McGee
 
Making the most of Jabber
Making the most of JabberMaking the most of Jabber
Making the most of JabberCisco Canada
 
Cisco hyperflex software defined storage and ucs unite
Cisco hyperflex software defined storage and ucs uniteCisco hyperflex software defined storage and ucs unite
Cisco hyperflex software defined storage and ucs uniteCisco Canada
 
Cisco amp for meraki
Cisco amp for merakiCisco amp for meraki
Cisco amp for merakiCisco Canada
 
OVNC 2015-Software-Defined Networking: Where Are We Today?
OVNC 2015-Software-Defined Networking: Where Are We Today?OVNC 2015-Software-Defined Networking: Where Are We Today?
OVNC 2015-Software-Defined Networking: Where Are We Today?NAIM Networks, Inc.
 
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...CA Technologies
 
CCNA practice quiz student
CCNA practice quiz studentCCNA practice quiz student
CCNA practice quiz studentYaser Rahmati
 
Cisco Study: State of Web Security
Cisco Study: State of Web Security Cisco Study: State of Web Security
Cisco Study: State of Web Security Cisco Canada
 
Open Systems Interconnection (OSI) model
Open Systems Interconnection (OSI) modelOpen Systems Interconnection (OSI) model
Open Systems Interconnection (OSI) modelYaser Rahmati
 
Demystifying TrustSec, Identity, NAC and ISE
Demystifying TrustSec, Identity, NAC and ISEDemystifying TrustSec, Identity, NAC and ISE
Demystifying TrustSec, Identity, NAC and ISECisco Canada
 
Simplifier le deploiement d'applications dans le nuage hybride
Simplifier le deploiement d'applications dans le nuage hybrideSimplifier le deploiement d'applications dans le nuage hybride
Simplifier le deploiement d'applications dans le nuage hybrideCisco Canada
 
Expanding your impact with programmability in the data center
Expanding your impact with programmability in the data centerExpanding your impact with programmability in the data center
Expanding your impact with programmability in the data centerCisco Canada
 
Jabber making the most of
Jabber making the most ofJabber making the most of
Jabber making the most ofCisco Canada
 
What’s new in Veeam Availability Suite v9
What’s new in Veeam Availability Suite v9What’s new in Veeam Availability Suite v9
What’s new in Veeam Availability Suite v9Digicomp Academy AG
 

Andere mochten auch (17)

Secure collab on premise
Secure collab on premiseSecure collab on premise
Secure collab on premise
 
Secure Data Center Solution with FP 9300 - BDM
Secure Data Center Solution with FP 9300 - BDMSecure Data Center Solution with FP 9300 - BDM
Secure Data Center Solution with FP 9300 - BDM
 
MPP Phone Roadmap
MPP Phone RoadmapMPP Phone Roadmap
MPP Phone Roadmap
 
Making the most of Jabber
Making the most of JabberMaking the most of Jabber
Making the most of Jabber
 
Cisco hyperflex software defined storage and ucs unite
Cisco hyperflex software defined storage and ucs uniteCisco hyperflex software defined storage and ucs unite
Cisco hyperflex software defined storage and ucs unite
 
Cisco amp for meraki
Cisco amp for merakiCisco amp for meraki
Cisco amp for meraki
 
OVNC 2015-Software-Defined Networking: Where Are We Today?
OVNC 2015-Software-Defined Networking: Where Are We Today?OVNC 2015-Software-Defined Networking: Where Are We Today?
OVNC 2015-Software-Defined Networking: Where Are We Today?
 
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
 
CCNA practice quiz student
CCNA practice quiz studentCCNA practice quiz student
CCNA practice quiz student
 
Cisco Study: State of Web Security
Cisco Study: State of Web Security Cisco Study: State of Web Security
Cisco Study: State of Web Security
 
Open Systems Interconnection (OSI) model
Open Systems Interconnection (OSI) modelOpen Systems Interconnection (OSI) model
Open Systems Interconnection (OSI) model
 
Demystifying TrustSec, Identity, NAC and ISE
Demystifying TrustSec, Identity, NAC and ISEDemystifying TrustSec, Identity, NAC and ISE
Demystifying TrustSec, Identity, NAC and ISE
 
Veeam backup and_replication_whats_new_in_v7
Veeam backup and_replication_whats_new_in_v7Veeam backup and_replication_whats_new_in_v7
Veeam backup and_replication_whats_new_in_v7
 
Simplifier le deploiement d'applications dans le nuage hybride
Simplifier le deploiement d'applications dans le nuage hybrideSimplifier le deploiement d'applications dans le nuage hybride
Simplifier le deploiement d'applications dans le nuage hybride
 
Expanding your impact with programmability in the data center
Expanding your impact with programmability in the data centerExpanding your impact with programmability in the data center
Expanding your impact with programmability in the data center
 
Jabber making the most of
Jabber making the most ofJabber making the most of
Jabber making the most of
 
What’s new in Veeam Availability Suite v9
What’s new in Veeam Availability Suite v9What’s new in Veeam Availability Suite v9
What’s new in Veeam Availability Suite v9
 

Ähnlich wie Simplifying the secure data center

Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...NetworkCollaborators
 
Cisco Connect Halifax 2018 Application agility and programmability with cis...
Cisco Connect Halifax 2018   Application agility and programmability with cis...Cisco Connect Halifax 2018   Application agility and programmability with cis...
Cisco Connect Halifax 2018 Application agility and programmability with cis...Cisco Canada
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network EvolutionCisco Canada
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco Canada
 
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - SegmentationVMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - SegmentationVMworld
 
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)SDNRG ITB
 
Cisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnhaCisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnhaldangelo0772
 
Security & Virtualization in the Data Center
Security & Virtualization in the Data CenterSecurity & Virtualization in the Data Center
Security & Virtualization in the Data CenterCisco Russia
 
Cozystack: Free PaaS platform and framework for building clouds
Cozystack: Free PaaS platform and framework for building cloudsCozystack: Free PaaS platform and framework for building clouds
Cozystack: Free PaaS platform and framework for building cloudsAndrei Kvapil
 
Cisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco MerakiCisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco MerakiCisco Canada
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:Cisco Canada
 
Embracing SDN in the Next Gen Network
Embracing SDN in the Next Gen NetworkEmbracing SDN in the Next Gen Network
Embracing SDN in the Next Gen NetworkNetCraftsmen
 
Cisco mds 9000 series software license packages
Cisco mds 9000 series software license packagesCisco mds 9000 series software license packages
Cisco mds 9000 series software license packagesIT Tech
 
Cisco PWR7AC
Cisco PWR7ACCisco PWR7AC
Cisco PWR7ACsavomir
 
Cisco Trustsec & Security Group Tagging
Cisco Trustsec & Security Group TaggingCisco Trustsec & Security Group Tagging
Cisco Trustsec & Security Group TaggingCisco Canada
 
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_diveNur Shiqim Chok
 
SDN in the Enterprise: APIC Enterprise Module
SDN in the Enterprise:  APIC Enterprise Module SDN in the Enterprise:  APIC Enterprise Module
SDN in the Enterprise: APIC Enterprise Module Cisco Canada
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Cisco Russia
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco merakiCisco Canada
 

Ähnlich wie Simplifying the secure data center (20)

Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
 
Cisco Connect Halifax 2018 Application agility and programmability with cis...
Cisco Connect Halifax 2018   Application agility and programmability with cis...Cisco Connect Halifax 2018   Application agility and programmability with cis...
Cisco Connect Halifax 2018 Application agility and programmability with cis...
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - SegmentationVMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
 
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
 
Cisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnhaCisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnha
 
Security & Virtualization in the Data Center
Security & Virtualization in the Data CenterSecurity & Virtualization in the Data Center
Security & Virtualization in the Data Center
 
Cozystack: Free PaaS platform and framework for building clouds
Cozystack: Free PaaS platform and framework for building cloudsCozystack: Free PaaS platform and framework for building clouds
Cozystack: Free PaaS platform and framework for building clouds
 
Cisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco MerakiCisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
 
Embracing SDN in the Next Gen Network
Embracing SDN in the Next Gen NetworkEmbracing SDN in the Next Gen Network
Embracing SDN in the Next Gen Network
 
BRKCRS-2110.pdf
BRKCRS-2110.pdfBRKCRS-2110.pdf
BRKCRS-2110.pdf
 
Cisco mds 9000 series software license packages
Cisco mds 9000 series software license packagesCisco mds 9000 series software license packages
Cisco mds 9000 series software license packages
 
Cisco PWR7AC
Cisco PWR7ACCisco PWR7AC
Cisco PWR7AC
 
Cisco Trustsec & Security Group Tagging
Cisco Trustsec & Security Group TaggingCisco Trustsec & Security Group Tagging
Cisco Trustsec & Security Group Tagging
 
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
 
SDN in the Enterprise: APIC Enterprise Module
SDN in the Enterprise:  APIC Enterprise Module SDN in the Enterprise:  APIC Enterprise Module
SDN in the Enterprise: APIC Enterprise Module
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
 

Mehr von Cisco Canada

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco Canada
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic frCisco Canada
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco Canada
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dcCisco Canada
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla nsCisco Canada
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco Canada
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Canada
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco Canada
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Cisco Canada
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v finalCisco Canada
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco Canada
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...Cisco Canada
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kineticCisco Canada
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...Cisco Canada
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet OverviewCisco Canada
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assuranceCisco Canada
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicingCisco Canada
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zeroCisco Canada
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...Cisco Canada
 
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1Cisco Canada
 

Mehr von Cisco Canada (20)

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet Overview
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
 

Kürzlich hochgeladen

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 

Kürzlich hochgeladen (20)

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 

Simplifying the secure data center

  • 1. Benjamin Rossignol Security Consulting Systems Engineer berossig@cisco.com Simplifying Security in the Data Center
  • 2. How do we Simplify the Secure Data Center?
  • 3. • Introduction • Micro-Segmentation • Secure VDI • ACI-TrustSec Integration • Security Feedback Loop with Firepower Agenda
  • 4. ACI Service Graphs Keep it Simple ACI Web Contract Consumer Provider Managed/Unmanaged Devices Client EPG Web EPG S ACI Allows for Easier Services Insertion
  • 5. L4-L7 Service Automation: Support for All Devices Any Device and Cluster Manager Support L4-L7 Service Automation L4-L7 Services Cisco ACI™ Services Graph L4- L7 Device Package No Device Package Service Cluster Manager • Centralized L4-L7 service configuration and management • Full L4-L7 service automation (with device package) • Large ecosystem and investment protection • Security policy follows workload • Centralized security provisioning and visibility • Automated service insertion and chaining • Support for any L4-L7 device • New support for L4-L7 cluster managers Embedded Security Micro- Segmentation Security Automation Encryption Analytics
  • 6. Same Policy Model across physical and any virtualization or cloud technology VM 1 VM 2 VM 1 VM 1 VM 2 KVM OpFlex Agent V(X)LAN Open vSwitch ESXi Cisco AVS V(X)LAN VMware DVS Hyper-V MSFT vSwitch V(X)LAN Docker OpFlex Agent V(X)LAN Open vSwitch VM 1 VM 1 VM 2 VM 1 Docker1 Docker2 Docker1 Docker2 OpFlex OpFlex OpFlex OpFlex Bare Metal VLAN
  • 7. Can we use Micro Segmentation within ACI to effectively isolate application traffic? Using Micro Segmentation
  • 8. Macro Segmentation Development Datacenter Production Campus The separation of Trusted and Untrusted environments. Examples: • Internet • Campus • Datacenter • Development • Production Service Graphs Firewalls ACLs EPGs Internet
  • 9. Micro Segmentation Application Web Tier Database Campus Ring-fencing, or isolation application traffic to a specific set of servers within a datacenter. Examples: • Web Tier to Application • Application to Database Service Graphs EPGs Virtual Firewalls
  • 10. vDS Cisco AVS IP/MAC EPG Hyper-V vSwitch Open vSwitch Open vSwitch VLAN VLAN or VXLAN VLAN or VXLAN VLANVLANVLAN Micro-Segmentation with ACI EPG-Web Micro-Segmentation Across any Workload Attributes Type MAC Address Filter Network IP Address Filter Network VNic Dn (vNIC domain name) VM VM Identifier VM VM Name VM Hypervisor Identifier VM VMM Domain VM Datacenter VM Custom Attribute (VMWare AVS/vDS only) VM Operating System VM opflex opflex opflex
  • 11. vDS Cisco AVS IP/MAC EPG Hyper-V vSwitch Open vSwitch Open vSwitch VLAN VLAN or VXLAN VLAN or VXLAN VLANVLANVLAN MAC-EPG Support in ACI MAC-EPG-Web Micro-Segmentation Across any Workload Attributes Type MAC Address Filter Network IP Address Filter Network VNic Dn (vNIC domain name) VM VM Identifier VM VM Name VM Hypervisor Identifier VM VMM Domain VM Datacenter VM Custom Attribute (VMWare AVS/vDS only) VM Operating System VM
  • 12. • MAC-EPG is a micro-segmented EPG with endpoint membership based on MAC address attribute list which is derived from endpoints of a Base EPG • Scoped at BD level • MAC-EPGs can have large mac-lists • Usecases: Migrations, Security Feedback Loop, etc … MAC-EPG (Micro-Segmentation) BD1/subnet1 Base EPG MAC-EPG-1 MAC-EPG-N Contract Within BD traffic is Bridged BD2/subnet2 Base EPG MAC-EPG-1 Inter BD traffic is Routed Contract
  • 14. User Segmentation and VDI Campus PC PC PC Datacenter SalesIT HR VDI EPG Server EPG NGFW / NGIPS NGFW / NGIPSSolution provides: Next-Generation Security (NGFW, NGIPS, AMP) with Identity controls. VDI Farm is one big flat subnet, with lateral blocking. Need to provide secure access to Servers.
  • 15. Secure VDI Usecase Flow: User-Identity Micro-Segmentation with FirePower + ACI Usecase 1 Usecase 2 Shipping
  • 16. Consuming Micro-Segmentation User-Identity Micro-Segmentation with ACI Src-EPG Dest-EPG Contract Src-EPG Dest-EPG Contract AD based User Identify Policy Concept Solution Intra-EPG Isolation ACI Service Graph w/ Firepower Enforce User-Identity Based Network Access Control Policy Red User can only Access Red VMs Green User can only Access Green VMs ACI Policy Model Extension Shipping
  • 17. Secure VDI Usecase: User-Identity Micro-Segmentation with FirePower + ACI Campus Network providerconsumer Firepower 4100 / 9300 FTD Image vPC Contract L3out service-graph with FirePower FMC Active Directory SF User Agent VDI EPG L3out Users Initiate VDI session VDI Farm - one big flat subnet but VMs isolated, blocking lateral User-Identity Network Access Control Policy Server EPG Users (AD Group: VDI Session) Destination Network (Server EPG) Group A 1.0.0.1 <= VDI IP 1.0.0.2 Destination Subnet 10.0.0.0/30 Group B 3.0.0.1 Destination 20.0.0.1 SourceFire Policy Shipping
  • 19. User Segmentation Campus Control of which systems or applications within a datacenter a user or group can connect to. PC PC PC 8 SGT / Sales 3 SGT/ HR 99 SGT / IT Trustsec / Security Group Tags VLAN Assignment Passive Identity from Active Directory Datacenter
  • 20. Problem: Disjointed Identity & Security Policy Domains Between Campus and Data Center TrustSec domain Voice Employee Supplier BYOD Campus / Branch / Non-Fabric TrustSec Policy Domain Voic e VLA N Data VLAN Web App DB ACI Fabric Data Center APIC Policy Domain APIC WAN Disjoint: Identity, Grouping Policy Domains TrustSec Policy Domain APIC Policy Domain • Today customer has two disjointed identity and security policy domains in Campus and Data Center: • TrustSec User Identity, SGT and SGACL in Campus • APIC App Endpoint Identity, EPG and Contract in Data Center • Customer Requirement: • Need Common “Identity,” Tagging and “Security Policy” between TrustSec and ACI domains
  • 21. TrustSec/ISE Policy Domain CMD/SGT ACI Policy Domain TrustSec Border Router (ASR1K Initially) Higher Scale Data Plane Solution SXP SGT <-> EPG translation WA N IPSec, DMVPN, GETVPN, OTP Policy Plane (REST API) Routing Plane (MP-BGP EVPN) “Trusted Mode” Data Plane (GBP VXLAN) ISE Builds Translation Table 1. GET: VRF-ID, Class-ID 2. SGT <==> VRF-ID, Class-ID Download Translation Table EPG Starts on ASR1k 2 3 4 Target Q2-CY17 1 ASR1k(config)# cts sg-epg translations Golf L3out Leaf: -EX only
  • 22. TrustSec/ISE Policy Domain CMD/SGT ACI Policy Domain TrustSec Border Router (ASR1K Initially) Campus to ACI Flow SXP SGT <-> EPG translation WA N IPSec, DMVPN, GETVPN, OTP SGT-EPG iVXLAN Contract Applied on Leaf Lookup:s-class, d-class, policy APP-EPG Golf L3out Target Q2-CY17
  • 23. TrustSec/ISE Policy Domain CMD/SGT ACI Policy Domain TrustSec Border Router (ASR1K Initially) ACI to Campus Flow SXP SGT <-> EPG translation WA N IPSec, DMVPN, GETVPN, OTP SGT-EPG iVXLAN VzAny Contract Permit-all or filter ports APP-EPG Golf L3out Target Q2-CY17 Per-Host Policy in ASR1k
  • 24. TrustSec Domain Phase 1 Identity and Policy Propagation between ISE and APIC No SGT tags sent to ACI Enforcement at N9300 border leaf Leverage IP address as User identifier Scale: ~10k/Leaf Works with existing ACI infra: N9300 leafs and N9500 Spines Target Timeframe: Shipping now Solution: Normalize Identity and SGT/EPG Phase 2 Policy Mapping between ISE and APIC AND Data plane Integration (ASR1K or ACI Spine) ASR1K DCI translates SGT  EPG-Class-ID Enforcement at N9300 leaf Scale: SGT/ EPG namespace Works with existing N9300 leafs, requires upgrade of N9500 spines (line card/ fabric module available mid CY16) Target Timeframe: Q2 CY17 TrustSec Domain ACI Domain SGT  EPG SGT  EPG ACI Domain iVXLANSGT ASR1k Shipping Q2-CY17
  • 26. Firepower, in all its forms, supports: Correlation Polices and Remediation Modules, allowing us to take a customized action based on defined behavior on the network. Example: If a server is attacked by host in my PCI network, I want to block the attacker. Security Feedback Loop
  • 27. Consuming Micro-Segmentation ACI and SourceFire – Security Closed Feedback Loop CORP EPG FW NGIPS 10.1.0.234 Attack Web EPG REM EPG QUA EPG FW FireSIGHT Management Center REST Calls to APIC NB API Move VM To Quarantine Quarantine for RemediationPost Remediation Move Cleaned VM Status: 1. Cisco on Cisco solution (ACI + Security BU) 2. Remediation module in FMC used for security feedback loop (no, device package required) 3. Productization for VMware vDS, AVS and BM is shipping • Quarantine IP-EPG creation • Quarantine bad endpoints using IP- EPG only 4. Tested 150 IP-EPG creation and TBD endpoints 5. NGIPS stitching has no dependencies on Remediation module. NGIPS Stitching can we with device package or not. Both options supported. Demo Video: https://youtu.be/zSfDT1-47Hg
  • 28. Security Feedback Loop, continued…
  • 29. Security Feedback Loop, continued… Cisco has just released the new ACI Remediation Module for Firepower!
  • 30. Security Feedback Loop, continued…
  • 32. • FMC Remediation Module for ACI Documentation http://www.cisco.com/c/dam/en/us/td/docs/security/asa/apic/quick-start/guide/fmc-rm-qsg1x.pdf • FMC Remediation Module for ACI YouTube Video https://www.youtube.com/watch?v=zSfDT1-47Hg&feature=youtu.be • Micro Segmentation Demo on YouTube https://youtu.be/EEs7B1dKVjE Additional Resources