SlideShare uma empresa Scribd logo
1 de 33
Baixar para ler offline
SD-WAN Architecture:
Secure Your Network
for Scale and the Cloud
Steve Woo
VP of Products & Co-founder
Security Key Value for SD-WAN
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Title
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN Security Advantages
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch
Edges
Cloud Gateways
SaaS
Zero touch & secure deployments,
simplified operations, one-click
service insertion
Direct cloud access with
performance, reliability and
security
Simplified & Automated
WAN Management
Managed on-ramp
to the cloud
Datacenter Edges
Transport independent performance &
security for the most demanding apps,
leverages economical bandwidth
SD-WAN Overlay
Assured Application
Performance & Security
SD-WAN Security Checklist
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Secure connectivity [ ] ANY and ALL transport
[ ] Enterprise AND cloud datacenters
[ ] Scalable, automated
Segmentation [ ] Intra enterprise, Multi-tenant
Security services insertion [ ] Branch, distributed, cloud, multi-
vendor
Secure deployment [ ] Branch provisioning
[ ] SD-WAN infrastructure
Visibility [ ] User and application activity
[ ] Compliance and security analytics
Unified Secure Overlay
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site Enterprise DC
Hub Edge
Branch
Edge
Enterprise DC
Traditional
Private
Datacenters
INTERNET
Cloud Gateways
Private - MPLS
IPsec VPN
Unified VPN over all transports
Cloud VPN eliminates backhaul
Automated VPN to cloud via gateway
eliminates NxN manual tunnels
Traditional Key Architecture - i
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Centralized
Distributed Centralized
Orchestration
Difficult  Easy 
Control Plane Attack Surface
Small – Uncommon to attack the Hub  Large – Key Server single point of attack 
Data plane Attack Surface
Small – Just a pair-wise key  Large – Entire Group sharing the same keys 
Distributed
Traditional Key Architecture - ii
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Pre-shared PKI
Complexity
Integrated  Requires a separate Certificate Authority 
Scalability
Manual configured key-pair  Centrally provisioned by the CA server 
Automation workflows No
Not Integrated 
- Secure onboarding
- CRL + Tunnel Integrity
Pre-shared Keys PKI
SD-WAN Key Arch Advantages
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site
Enterprise DC
Branch
Edge
Enterprise DC
Hybrid Cloud
Traditional
Private
Datacenters
INTERNET
Cloud Gateways
Orchestrator
Private - MPLSDynamic
branch to branch
Edge device’s Public key pinned
Preferred Attributes 
Centralized Orchestration
Small control plane attack
surface due to pinning of Edge
public keys
Small data plane attack surface
due to Pair-wise keys
Integrated PKI + Orchestration
High Scalability with PKI
Integrated Automation of:
- CRL with Tunnel integrity
- Secure onboarding
IKE+IPsecsession
CRL distribution
+
Automatic tunnel
integrity check
Integrated CA
Hub
Edge
SD-WAN Segmentation
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Enterprise A
VLAN 1
VLAN 2
VLAN 3
VLAN 4
Enterprise B VRF A
VLAN 1
VLAN 2
VLAN 3
VLAN 4
Multi-Tenant
SD-WAN Cloud
Gateway
VRF 3
VRF 4
• Services by Enterprise – VRF mapping
• Services granularity by VLAN tag
VRF B-4
VRF B-3
SP NFV Orchestrator
SD-WAN
Edge
SD-WAN Security Checklist
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Secure connectivity [ ] ANY and ALL transport
[ ] Enterprise AND cloud datacenters
[ ] Scalable, automated
Segmentation [ ] Intra enterprise, Multi-tenant
Security services insertion [ ] Branch, distributed, cloud, multi-
vendor
Secure deployment [ ] Branch provisioning
[ ] SD-WAN infrastructure
Visibility [ ] User and application activity
[ ] Compliance and security analytics




Security Service Insertion
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site Enterprise DC
Hub Edge
Branch
Edge
Enterprise DC
Hybrid Cloud
Traditional
Private
Datacenters
INTERNET
Cloud Gateways
Orchestrator
Private - MPLS
Controllers
Private & Internet circuits, Enterprise & SaaS applications, On premise & Cloud deployments
Service
Insertion Points
Branch Security Service Insertions
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
vCPE platform
OS + HW
SD-WAN
VNF
FW
VNF
WOC
VNF
Orchestration
General Purpose
Virtual CPE
3
= Cloud Delivered
SDWAN
SDWAN Virtual
Services Platform
SDWAN
FW
VNF
X
VNF
SDWAN Orchestration
SD-WAN Virtual
Services Platform
L7
Fire
wall
Dyn
Multi
Path
VPN NAT
SDWAN
SD-WAN CPE
with virtualized services
Embedded Services
 Services on / off
 Granular policies by L7 traffic profile
Multiple CPE options:
SD-WAN Service Chaining
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN
SaaS / IaaS
Enterprise DC
Branch
Web
Cloud
Gateways
Policy based service insertion:
Different service chains applied by policy
Services can be at branch only or dual ended
SD-WAN Edge
SD-WAN
Edge
VPN
Fire
wall
Dyn
Multi
Path
Internet Backhaul Challenge
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Complex with Traditional WAN
 Not performance-aware
 Policy definition at L3 only
 Require touching every branch
 Per-application tuning difficult
 More complex with multiple links
Branch
Headend
Advertise
0.0.0.0/0
(Preferred)
Advertise
0.0.0.0/0
Policy-based Internet Backhaul to DCs
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch
Edge
Primary
Hub Edge
Secondary
Hub Edge
Primary path Secondary path
 Backhaul ALL or subset of Internet traffic
 Flexible link steering policy
SD-WAN Distributed Security Insertion
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site
Distributed Regional Mini-
Datacenters
On Premise
Email DLP
Firewalls
Enterprise
Applications
Enterprise Datacenters
Distributed Service Insertion
• SDWAN one-click app aware service insertion
• Enables disaggregation and distribution of services to
multiple regional mini-datacenters
• Same or different service chains by DC
• SDWAN optimal for SDN instantiated virtual services in DC
• Reduces branch complexity and attack surface
SD-WAN
Edges
SD-WAN
Edges
Branch to Branch Service Insertion
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site
Distributed Regional Mini-
Datacenters
Firewalls
Distributed Service Insertion
• Regionalize services even for branch to branch traffic
• Next gen firewall can apply rules by application
SD-WAN
Edges
Multi-DC Services Insertion
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site
Datacenter 1
Multi-DC Service Insertion
• Dynamic routing for service insertion
Datacenter 2
SD-WAN
Edges
SD-WAN
Edge
SD-WAN
Edge
Email DLP
Firewalls
SD-WAN Hybrid Security Insertion
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site
Enterprise Hub
On Premises
Security
Other Web traffic
Salesforce.com
Web email
Internet
• Backhaul to on-premises services
– Regional and central
• SD-WAN performance service chained to cloud security services
• One-click, by application Cloud
Security
Services
SD-WAN service chaining for hybrid services
SD-WAN
Edge
SD-WAN Security Checklist
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Secure connectivity [ ] ANY and ALL transport
[ ] Enterprise AND cloud datacenters
[ ] Scalable, automated
Segmentation [ ] Intra enterprise, Multi-tenant
Security services insertion [ ] Branch, distributed, cloud, multi-
vendor
Secure deployment [ ] Branch provisioning
[ ] SD-WAN infrastructure
Visibility [ ] User and application activity
[ ] Compliance and security analytics





Complex & Insecure Legacy Deployments
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
“IT Visit”
 No security risk if box lost
X IT visit to site required
1-Ship
2-Install
3-Config
 No IT visit required
X Drop ship not possible
X Configure and track every box
X Security risk if mis-ship
“Pre-stage”
2-Ship
3-Install
1-Config
Simple & Secure SD-WAN Activation
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
“Pull Activation Key”
1-Ship
3-Install +
pull config
2-Create config + send key
“Call Home Push Activation”
1-Ship
2-Install +
Call Home
3-Push Config
 No IT visit required
 No security risk if box lost
 No pre-staging required
 No device tracking needed
 Two factor – key and device
 No IT visit required
 No security risk if box lost
 No pre-staging required
 Independent physical install
> Requires knowledge of device to site
Flexible Deployment Options
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch Site Enterprise DC
Datacenter
Edge
Edge
Enterprise DC
SaaS
Hybrid Cloud
Cloud DC
Traditional
Private
Datacenters
INTERNET
Cloud Gateways
Orchestrator
Private - MPLS
• On-premises in Enterprise
• Hosted in secure cloud datacenters
On-Premise SD-WAN Deployment
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SaaS / IaaS
INTERNET and MPLS
VeloCloud
Edge
Enterprise DC
 Edges in “hub” role at enterprise datacenters and
regional hubs
 On-premise Orchestrator and Controllers
 One-click granular traffic backhaul to regional hubs
 Direct breakout to Internet for non-backhaul traffic
VeloCloud
Orchestrator
Regional Hubs
VeloCloud
Edge
VeloCloud
Edge
Regional Hubs
Internet
VeloCloud
Controllers
Policy Based Link Steering Overrides
 Pin an application to a path
even when the link fails
e.g. > PCI to compliant provider
 Prefer application on a path but
steer away if cannot meet SLA
e.g. > Prefer high bandwidth
video conferencing on broadband
 Prefer application on a path but
steer away if the link fails
e.g. > Wired to wireless
 Add metered usage of wireless
 Abstract actual interface/WAN links from the
business policy
Mandatory
Private
Available
Public Wired
Preferred
Public
Internet
Public-Wireless
Private
Public
Public-Wired
Private
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Managed SD-WAN / Security
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN
MPLS/Private
Cloud SP
Datacenter
PE
CE
Router
PE
Virtual
CPE with
SD-WAN
Enterprise
DatacenterBranch
SDWAN
Gateway
SDWAN
Gateway
SDWAN
Orchestrator
SD-WAN
MPLS/Private
Cloud SP
Datacenter
SDWAN
Edge
Enterprise
Datacenter
Branch
SDWAN
Orchestrator
SDWAN
Edge
“Over The Top”“Integrated”
SD-WAN Security Checklist
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Secure connectivity [ ] ANY and ALL transport
[ ] Enterprise AND cloud datacenters
[ ] Scalable, automated
Segmentation [ ] Intra enterprise, Multi-tenant
Security services insertion [ ] Branch, distributed, cloud, multi-
vendor
Secure deployment [ ] Branch provisioning
[ ] SD-WAN infrastructure
Visibility [ ] User and application activity
[ ] Compliance and security analytics







App Usage Visibility
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
App Usage & Categories
• ALL applications by category identifies risk
• Organize by category or volume
• One-click drill down to sources, destinations
Compliance Monitoring
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Policy compliance monitoring
• Central orchestrator view across enterprise
• At-a-glance monitoring of site deviations from policy
• One-click drill down into policy details
SIEM Analytics
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Branch
Edges
Cloud Gateways SaaS
Datacenter Edges
SD-WAN Overlay
Orchestrator
SD-WAN to SIEM:
• Events, flow data and logs from
Edges and Orchestrator
• Visibility before encrypted tunneling
• Across on-premises and cloud
• Multi-tenant
SIEM
Event Collectors /
Processors
IPFIX (Netflow v10)
SNMP v2c/v3
Packet capture
Security logs
and alerts Syslog
API / SDK
SD-WAN Security Checklist
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Secure connectivity [ ] ANY and ALL transport
[ ] Enterprise AND cloud datacenters
[ ] Scalable, automated
Segmentation [ ] Intra enterprise, Multi-tenant
Security services insertion [ ] Branch, distributed, cloud, multi-
vendor
Secure deployment [ ] Branch provisioning
[ ] SD-WAN infrastructure
Visibility [ ] User and application activity
[ ] Compliance and security analytics









Q&A
www.velocloud.com/sd-wan-dummies

Mais conteúdo relacionado

Mais procurados

VMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined NetworkingVMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined NetworkingCumulus Networks
 
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...apidays
 
SD WAN Overview | What is SD WAN | Benefits of SD WAN
SD WAN Overview | What is SD WAN | Benefits of SD WAN SD WAN Overview | What is SD WAN | Benefits of SD WAN
SD WAN Overview | What is SD WAN | Benefits of SD WAN Ashutosh Kaushik
 
Tutorial on SDN and OpenFlow
Tutorial on SDN and OpenFlowTutorial on SDN and OpenFlow
Tutorial on SDN and OpenFlowKingston Smiler
 
SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?Haris Chughtai
 
Red Hat Openshift Fundamentals.pptx
Red Hat Openshift Fundamentals.pptxRed Hat Openshift Fundamentals.pptx
Red Hat Openshift Fundamentals.pptxssuser18b1c6
 
Software-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success StorySoftware-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success StoryCisco Enterprise Networks
 
China Telecom Americas: SD-WAN Overview
China Telecom Americas:  SD-WAN OverviewChina Telecom Americas:  SD-WAN Overview
China Telecom Americas: SD-WAN OverviewVlad Sinayuk
 
Colt's evolution from MPLS to Cloud Networking
Colt's evolution from MPLS to Cloud Networking Colt's evolution from MPLS to Cloud Networking
Colt's evolution from MPLS to Cloud Networking Colt Technology Services
 
SD-WAN 2.0: Building a Better SD-WAN
SD-WAN 2.0: Building a Better SD-WANSD-WAN 2.0: Building a Better SD-WAN
SD-WAN 2.0: Building a Better SD-WANADVA
 
VMware Cloud Foundation - PnP presentation 8_6_18 EN.pptx
VMware Cloud Foundation - PnP presentation 8_6_18 EN.pptxVMware Cloud Foundation - PnP presentation 8_6_18 EN.pptx
VMware Cloud Foundation - PnP presentation 8_6_18 EN.pptxBradLai3
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?Phani Kumar
 
Service Mesh - Why? How? What?
Service Mesh - Why? How? What?Service Mesh - Why? How? What?
Service Mesh - Why? How? What?Orkhan Gasimov
 
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptxAvi Networks
 
삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...
삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...
삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...Amazon Web Services Korea
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAmazon Web Services
 
Part 01: Azure Virtual Networks – An Overview
Part 01: Azure Virtual Networks – An OverviewPart 01: Azure Virtual Networks – An Overview
Part 01: Azure Virtual Networks – An OverviewNeeraj Kumar
 

Mais procurados (20)

VMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined NetworkingVMware NSX + Cumulus Networks: Software Defined Networking
VMware NSX + Cumulus Networks: Software Defined Networking
 
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
 
SD WAN Overview | What is SD WAN | Benefits of SD WAN
SD WAN Overview | What is SD WAN | Benefits of SD WAN SD WAN Overview | What is SD WAN | Benefits of SD WAN
SD WAN Overview | What is SD WAN | Benefits of SD WAN
 
The Future of SD-WAN: WAN Transformation in the Cloud and Mobile Era
The Future of SD-WAN: WAN Transformation in the Cloud and Mobile EraThe Future of SD-WAN: WAN Transformation in the Cloud and Mobile Era
The Future of SD-WAN: WAN Transformation in the Cloud and Mobile Era
 
Tutorial on SDN and OpenFlow
Tutorial on SDN and OpenFlowTutorial on SDN and OpenFlow
Tutorial on SDN and OpenFlow
 
SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?
 
Red Hat Openshift Fundamentals.pptx
Red Hat Openshift Fundamentals.pptxRed Hat Openshift Fundamentals.pptx
Red Hat Openshift Fundamentals.pptx
 
Software-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success StorySoftware-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success Story
 
China Telecom Americas: SD-WAN Overview
China Telecom Americas:  SD-WAN OverviewChina Telecom Americas:  SD-WAN Overview
China Telecom Americas: SD-WAN Overview
 
Colt's evolution from MPLS to Cloud Networking
Colt's evolution from MPLS to Cloud Networking Colt's evolution from MPLS to Cloud Networking
Colt's evolution from MPLS to Cloud Networking
 
SD-WAN 2.0: Building a Better SD-WAN
SD-WAN 2.0: Building a Better SD-WANSD-WAN 2.0: Building a Better SD-WAN
SD-WAN 2.0: Building a Better SD-WAN
 
Aws VPC
Aws VPCAws VPC
Aws VPC
 
VMware Cloud Foundation - PnP presentation 8_6_18 EN.pptx
VMware Cloud Foundation - PnP presentation 8_6_18 EN.pptxVMware Cloud Foundation - PnP presentation 8_6_18 EN.pptx
VMware Cloud Foundation - PnP presentation 8_6_18 EN.pptx
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?
 
Service Mesh - Why? How? What?
Service Mesh - Why? How? What?Service Mesh - Why? How? What?
Service Mesh - Why? How? What?
 
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
 
삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...
삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...
삼성전자 5G Core CNF를 위한 클라우드 여정 이야기 - 최우형 AWS 솔루션즈 아키텍트 / 구동영 프로, 삼성전자 :: AWS Su...
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
 
Part 01: Azure Virtual Networks – An Overview
Part 01: Azure Virtual Networks – An OverviewPart 01: Azure Virtual Networks – An Overview
Part 01: Azure Virtual Networks – An Overview
 

Semelhante a Secure Your Network for Scale & the Cloud

Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityMarketingArrowECS_CZ
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
Under the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloudUnder the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloudVeloCloud Networks, Inc.
 
SD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloudSD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloudVeloCloud Networks, Inc.
 
A Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloudA Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloudVeloCloud Networks, Inc.
 
SD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital TransformationSD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital TransformationRalph Santitoro
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Intelligence at the Edge: How SD-WAN can Enable a Smarter Network
Intelligence at the Edge: How SD-WAN can Enable a Smarter NetworkIntelligence at the Edge: How SD-WAN can Enable a Smarter Network
Intelligence at the Edge: How SD-WAN can Enable a Smarter NetworkQOS Networks
 
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloudCloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloudVeloCloud Networks, Inc.
 
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013Amazon Web Services
 
SD-WAN_MoD.pptx for SD WAN networks connectivity
SD-WAN_MoD.pptx for SD WAN networks connectivitySD-WAN_MoD.pptx for SD WAN networks connectivity
SD-WAN_MoD.pptx for SD WAN networks connectivitybayusch
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS CloudDEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS CloudAmazon Web Services
 
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...SWITCHPOINT NV/SA
 
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...VMworld
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...Cisco Canada
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionCisco Canada
 
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...ThousandEyes
 

Semelhante a Secure Your Network for Scale & the Cloud (20)

Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivity
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
Under the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloudUnder the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloud
 
SD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloudSD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloud
 
A Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloudA Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloud
 
SD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital TransformationSD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital Transformation
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Cloud connected Solutions
Cloud connected SolutionsCloud connected Solutions
Cloud connected Solutions
 
Intelligence at the Edge: How SD-WAN can Enable a Smarter Network
Intelligence at the Edge: How SD-WAN can Enable a Smarter NetworkIntelligence at the Edge: How SD-WAN can Enable a Smarter Network
Intelligence at the Edge: How SD-WAN can Enable a Smarter Network
 
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloudCloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloud
 
Evolving the WAN for the Cloud, using SD-WAN & NFV
Evolving the WAN for the Cloud, using SD-WAN & NFV Evolving the WAN for the Cloud, using SD-WAN & NFV
Evolving the WAN for the Cloud, using SD-WAN & NFV
 
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
 
SD-WAN_MoD.pptx for SD WAN networks connectivity
SD-WAN_MoD.pptx for SD WAN networks connectivitySD-WAN_MoD.pptx for SD WAN networks connectivity
SD-WAN_MoD.pptx for SD WAN networks connectivity
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS CloudDEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
 
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
 
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
 

Mais de VeloCloud Networks, Inc.

SD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloud
SD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloudSD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloud
SD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloudVeloCloud Networks, Inc.
 
Amplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloudAmplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloudVeloCloud Networks, Inc.
 
The Power to Declare Network Independence - VeloCloud
The Power to Declare Network Independence - VeloCloudThe Power to Declare Network Independence - VeloCloud
The Power to Declare Network Independence - VeloCloudVeloCloud Networks, Inc.
 

Mais de VeloCloud Networks, Inc. (7)

SD-WAN for Construction - Solution Brief
SD-WAN for Construction - Solution BriefSD-WAN for Construction - Solution Brief
SD-WAN for Construction - Solution Brief
 
SD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloud
SD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloudSD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloud
SD-WAN Architecture Matters - Dr. Jim Metzler & VeloCloud
 
Amplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloudAmplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloud
 
SD-WAN for Service Providers - VeloCloud
SD-WAN for Service Providers - VeloCloudSD-WAN for Service Providers - VeloCloud
SD-WAN for Service Providers - VeloCloud
 
The Power to Declare Network Independence - VeloCloud
The Power to Declare Network Independence - VeloCloudThe Power to Declare Network Independence - VeloCloud
The Power to Declare Network Independence - VeloCloud
 
SD-WAN Economics 101 - VeloCloud
SD-WAN Economics 101 - VeloCloudSD-WAN Economics 101 - VeloCloud
SD-WAN Economics 101 - VeloCloud
 
Turbo-boosting Hybrid WAN using SD-WAN
Turbo-boosting Hybrid WAN using SD-WANTurbo-boosting Hybrid WAN using SD-WAN
Turbo-boosting Hybrid WAN using SD-WAN
 

Último

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 

Último (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 

Secure Your Network for Scale & the Cloud

  • 1. SD-WAN Architecture: Secure Your Network for Scale and the Cloud Steve Woo VP of Products & Co-founder
  • 2. Security Key Value for SD-WAN VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 3. Title VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 4. SD-WAN Security Advantages VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Edges Cloud Gateways SaaS Zero touch & secure deployments, simplified operations, one-click service insertion Direct cloud access with performance, reliability and security Simplified & Automated WAN Management Managed on-ramp to the cloud Datacenter Edges Transport independent performance & security for the most demanding apps, leverages economical bandwidth SD-WAN Overlay Assured Application Performance & Security
  • 5. SD-WAN Security Checklist VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Secure connectivity [ ] ANY and ALL transport [ ] Enterprise AND cloud datacenters [ ] Scalable, automated Segmentation [ ] Intra enterprise, Multi-tenant Security services insertion [ ] Branch, distributed, cloud, multi- vendor Secure deployment [ ] Branch provisioning [ ] SD-WAN infrastructure Visibility [ ] User and application activity [ ] Compliance and security analytics
  • 6. Unified Secure Overlay VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Enterprise DC Hub Edge Branch Edge Enterprise DC Traditional Private Datacenters INTERNET Cloud Gateways Private - MPLS IPsec VPN Unified VPN over all transports Cloud VPN eliminates backhaul Automated VPN to cloud via gateway eliminates NxN manual tunnels
  • 7. Traditional Key Architecture - i VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Centralized Distributed Centralized Orchestration Difficult  Easy  Control Plane Attack Surface Small – Uncommon to attack the Hub  Large – Key Server single point of attack  Data plane Attack Surface Small – Just a pair-wise key  Large – Entire Group sharing the same keys  Distributed
  • 8. Traditional Key Architecture - ii VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Pre-shared PKI Complexity Integrated  Requires a separate Certificate Authority  Scalability Manual configured key-pair  Centrally provisioned by the CA server  Automation workflows No Not Integrated  - Secure onboarding - CRL + Tunnel Integrity Pre-shared Keys PKI
  • 9. SD-WAN Key Arch Advantages VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Enterprise DC Branch Edge Enterprise DC Hybrid Cloud Traditional Private Datacenters INTERNET Cloud Gateways Orchestrator Private - MPLSDynamic branch to branch Edge device’s Public key pinned Preferred Attributes  Centralized Orchestration Small control plane attack surface due to pinning of Edge public keys Small data plane attack surface due to Pair-wise keys Integrated PKI + Orchestration High Scalability with PKI Integrated Automation of: - CRL with Tunnel integrity - Secure onboarding IKE+IPsecsession CRL distribution + Automatic tunnel integrity check Integrated CA Hub Edge
  • 10. SD-WAN Segmentation VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Enterprise A VLAN 1 VLAN 2 VLAN 3 VLAN 4 Enterprise B VRF A VLAN 1 VLAN 2 VLAN 3 VLAN 4 Multi-Tenant SD-WAN Cloud Gateway VRF 3 VRF 4 • Services by Enterprise – VRF mapping • Services granularity by VLAN tag VRF B-4 VRF B-3 SP NFV Orchestrator SD-WAN Edge
  • 11. SD-WAN Security Checklist VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Secure connectivity [ ] ANY and ALL transport [ ] Enterprise AND cloud datacenters [ ] Scalable, automated Segmentation [ ] Intra enterprise, Multi-tenant Security services insertion [ ] Branch, distributed, cloud, multi- vendor Secure deployment [ ] Branch provisioning [ ] SD-WAN infrastructure Visibility [ ] User and application activity [ ] Compliance and security analytics    
  • 12. Security Service Insertion VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Enterprise DC Hub Edge Branch Edge Enterprise DC Hybrid Cloud Traditional Private Datacenters INTERNET Cloud Gateways Orchestrator Private - MPLS Controllers Private & Internet circuits, Enterprise & SaaS applications, On premise & Cloud deployments Service Insertion Points
  • 13. Branch Security Service Insertions VeloCloud Networks Proprietary & Confidential | © Copyright 2016 vCPE platform OS + HW SD-WAN VNF FW VNF WOC VNF Orchestration General Purpose Virtual CPE 3 = Cloud Delivered SDWAN SDWAN Virtual Services Platform SDWAN FW VNF X VNF SDWAN Orchestration SD-WAN Virtual Services Platform L7 Fire wall Dyn Multi Path VPN NAT SDWAN SD-WAN CPE with virtualized services Embedded Services  Services on / off  Granular policies by L7 traffic profile Multiple CPE options:
  • 14. SD-WAN Service Chaining VeloCloud Networks Proprietary & Confidential | © Copyright 2016 SD-WAN SaaS / IaaS Enterprise DC Branch Web Cloud Gateways Policy based service insertion: Different service chains applied by policy Services can be at branch only or dual ended SD-WAN Edge SD-WAN Edge VPN Fire wall Dyn Multi Path
  • 15. Internet Backhaul Challenge VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Complex with Traditional WAN  Not performance-aware  Policy definition at L3 only  Require touching every branch  Per-application tuning difficult  More complex with multiple links Branch Headend Advertise 0.0.0.0/0 (Preferred) Advertise 0.0.0.0/0
  • 16. Policy-based Internet Backhaul to DCs VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Edge Primary Hub Edge Secondary Hub Edge Primary path Secondary path  Backhaul ALL or subset of Internet traffic  Flexible link steering policy
  • 17. SD-WAN Distributed Security Insertion VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Distributed Regional Mini- Datacenters On Premise Email DLP Firewalls Enterprise Applications Enterprise Datacenters Distributed Service Insertion • SDWAN one-click app aware service insertion • Enables disaggregation and distribution of services to multiple regional mini-datacenters • Same or different service chains by DC • SDWAN optimal for SDN instantiated virtual services in DC • Reduces branch complexity and attack surface SD-WAN Edges SD-WAN Edges
  • 18. Branch to Branch Service Insertion VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Distributed Regional Mini- Datacenters Firewalls Distributed Service Insertion • Regionalize services even for branch to branch traffic • Next gen firewall can apply rules by application SD-WAN Edges
  • 19. Multi-DC Services Insertion VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Datacenter 1 Multi-DC Service Insertion • Dynamic routing for service insertion Datacenter 2 SD-WAN Edges SD-WAN Edge SD-WAN Edge Email DLP Firewalls
  • 20. SD-WAN Hybrid Security Insertion VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Enterprise Hub On Premises Security Other Web traffic Salesforce.com Web email Internet • Backhaul to on-premises services – Regional and central • SD-WAN performance service chained to cloud security services • One-click, by application Cloud Security Services SD-WAN service chaining for hybrid services SD-WAN Edge
  • 21. SD-WAN Security Checklist VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Secure connectivity [ ] ANY and ALL transport [ ] Enterprise AND cloud datacenters [ ] Scalable, automated Segmentation [ ] Intra enterprise, Multi-tenant Security services insertion [ ] Branch, distributed, cloud, multi- vendor Secure deployment [ ] Branch provisioning [ ] SD-WAN infrastructure Visibility [ ] User and application activity [ ] Compliance and security analytics     
  • 22. Complex & Insecure Legacy Deployments VeloCloud Networks Proprietary & Confidential | © Copyright 2016 “IT Visit”  No security risk if box lost X IT visit to site required 1-Ship 2-Install 3-Config  No IT visit required X Drop ship not possible X Configure and track every box X Security risk if mis-ship “Pre-stage” 2-Ship 3-Install 1-Config
  • 23. Simple & Secure SD-WAN Activation VeloCloud Networks Proprietary & Confidential | © Copyright 2016 “Pull Activation Key” 1-Ship 3-Install + pull config 2-Create config + send key “Call Home Push Activation” 1-Ship 2-Install + Call Home 3-Push Config  No IT visit required  No security risk if box lost  No pre-staging required  No device tracking needed  Two factor – key and device  No IT visit required  No security risk if box lost  No pre-staging required  Independent physical install > Requires knowledge of device to site
  • 24. Flexible Deployment Options VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Site Enterprise DC Datacenter Edge Edge Enterprise DC SaaS Hybrid Cloud Cloud DC Traditional Private Datacenters INTERNET Cloud Gateways Orchestrator Private - MPLS • On-premises in Enterprise • Hosted in secure cloud datacenters
  • 25. On-Premise SD-WAN Deployment VeloCloud Networks Proprietary & Confidential | © Copyright 2016 SaaS / IaaS INTERNET and MPLS VeloCloud Edge Enterprise DC  Edges in “hub” role at enterprise datacenters and regional hubs  On-premise Orchestrator and Controllers  One-click granular traffic backhaul to regional hubs  Direct breakout to Internet for non-backhaul traffic VeloCloud Orchestrator Regional Hubs VeloCloud Edge VeloCloud Edge Regional Hubs Internet VeloCloud Controllers
  • 26. Policy Based Link Steering Overrides  Pin an application to a path even when the link fails e.g. > PCI to compliant provider  Prefer application on a path but steer away if cannot meet SLA e.g. > Prefer high bandwidth video conferencing on broadband  Prefer application on a path but steer away if the link fails e.g. > Wired to wireless  Add metered usage of wireless  Abstract actual interface/WAN links from the business policy Mandatory Private Available Public Wired Preferred Public Internet Public-Wireless Private Public Public-Wired Private VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 27. Managed SD-WAN / Security VeloCloud Networks Proprietary & Confidential | © Copyright 2016 SD-WAN MPLS/Private Cloud SP Datacenter PE CE Router PE Virtual CPE with SD-WAN Enterprise DatacenterBranch SDWAN Gateway SDWAN Gateway SDWAN Orchestrator SD-WAN MPLS/Private Cloud SP Datacenter SDWAN Edge Enterprise Datacenter Branch SDWAN Orchestrator SDWAN Edge “Over The Top”“Integrated”
  • 28. SD-WAN Security Checklist VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Secure connectivity [ ] ANY and ALL transport [ ] Enterprise AND cloud datacenters [ ] Scalable, automated Segmentation [ ] Intra enterprise, Multi-tenant Security services insertion [ ] Branch, distributed, cloud, multi- vendor Secure deployment [ ] Branch provisioning [ ] SD-WAN infrastructure Visibility [ ] User and application activity [ ] Compliance and security analytics       
  • 29. App Usage Visibility VeloCloud Networks Proprietary & Confidential | © Copyright 2016 App Usage & Categories • ALL applications by category identifies risk • Organize by category or volume • One-click drill down to sources, destinations
  • 30. Compliance Monitoring VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Policy compliance monitoring • Central orchestrator view across enterprise • At-a-glance monitoring of site deviations from policy • One-click drill down into policy details
  • 31. SIEM Analytics VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Branch Edges Cloud Gateways SaaS Datacenter Edges SD-WAN Overlay Orchestrator SD-WAN to SIEM: • Events, flow data and logs from Edges and Orchestrator • Visibility before encrypted tunneling • Across on-premises and cloud • Multi-tenant SIEM Event Collectors / Processors IPFIX (Netflow v10) SNMP v2c/v3 Packet capture Security logs and alerts Syslog API / SDK
  • 32. SD-WAN Security Checklist VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Secure connectivity [ ] ANY and ALL transport [ ] Enterprise AND cloud datacenters [ ] Scalable, automated Segmentation [ ] Intra enterprise, Multi-tenant Security services insertion [ ] Branch, distributed, cloud, multi- vendor Secure deployment [ ] Branch provisioning [ ] SD-WAN infrastructure Visibility [ ] User and application activity [ ] Compliance and security analytics         