Wednesday, October 23, 2013

Network Visibility Controller



Virtualized network traffic Visibility
https://www.youtube.com/watch?v=pzSU7feB-I4

  • ·         Traffic on the physical host can be tapped from a physical port on the host or by spanning

  • ·         Netoptics phanthom vTap: monitoring at kernel level instead of SPAN or port mirror traffic from the port.







Saturday, October 19, 2013

FPGA vs Network Processor

http://www.nallatech.com/
http://www.aliathon.com/

vFabric VMWare

VMWare have a vFabric appinsignt product for network monitoring used for performance management
  • A probeVM  has to be installed into each host (ESXi) where the application component is installed
  • These probes send DPI information on network traffic and sends the information to AppInsight server
  • Login into app insight as admin and install probe into the host
  • Choose the proper switch and switch to monitor traffic

SOAP vs REST

My take on REST vs SOAP

REST
  • REST can be consumed by any client, web browser with ajax and javascript
  • REST is lightweight
    • No XML parsing required
    • Has less bandwidth, SOAP headers are heavy payload
  • HTTP GET operations are safe in REST
  • REST are mostly stateless 
  • Good for web services, light weight no xml parsing systems
  • Exposes data over internet
 SOAP

  • SOAP is more like a RPC, where REST is not
  • SOAP / WSDL  can be used to generate client side code unlike REST where HTTP code has to be developed
  • SOAP can be asynchronous in nature, REST are http based and need asynchronous implementation
  • HTTP/HTTPS layer  need not be developed like REST
  • REST have no contract - prone to go wrong in integration of systems
  • SOAP have contract - can be discovered easily
  • Good for enterprise services - system integrations
  • Asynchronous processing
  • Stateful with contract to systems

SOA - An Architect View

SOA [ Service Oriented Architecture ]
"SOA = Loose Coupling"

Trying to pen down my important markings of SOA and how to approach.
  1. Architects  mostly uses an existing product(s) to build solution to address an specific problem
  2. Said that, mostly uses existing products(s) , at times have to fill in the requirements from BA (business analyst ) and provide an overall high level needs for building newer products - which goes to the product engineering teams
  3. Data Layer is the most important of below - always insisted to use standardized data format for communication
  4. Technology Layers  SOAP/HTTP with JSON/XML brings values to standardize
  5. LOOSE COUPLING of systems and components are key here as i had quoted right above in the first
  6. Note : Key SOA solutions are not just ESBs
Read  carefully below diagram two layers of solution design, before that always remember



































Technology Layer Break down of components
  1. Service Container : where data is translated (if needed) to meaningful relational information an example is to translate multi-system information into standardized representation for services, Adapters are used for this translation of data
  2. Broker : is an adapter to ship data from one system to another
  3. Process coordinator : processing or warehousing of data and flow are handled here
Costly Mistake
  1. Many a times the processing of data like business logic are done by broker instead of service container
  2. Also at times broker used in place of process co-ordinator
Loose Coupling
  1. Data in one system means different in another system, always represent the data and the meta data for specific system
  2. Map domain data to message data
  3. Eliminate unnecessary dependencies

Monday, October 7, 2013

Following Arista

I have following arista for last year and jotting down their product scope and my understanding for future references.


  • Arista a spun out from cisco-Ex, have good presence in the market and heard quite a bit times often
  • Arista EOS is equivalent or better than Cisco IOS / Nx-OS
    • I have personally not any experienced the usage difference, but i am a Nx-OS guy
    • Will evaluate and report - when i get a chance
  • Artista moved from switch to relevant areas in market space similar and aligning to their business
  • Arista Introduces Next Generation 7050X Products,Provides Telemetry and Cloud Network Leaf
  • http://www.aristanetworks.com/en/news/pressrelease/630-pr-20131002-01

Bigdata Market share

"Every dog has it day", said that , here is the piece of pie for each big data , official report.

Splunk                 $186 million        Turns machine data into valuable insights
Opera Solutions $118                     Data-Science-as-a-Service
Mu Sigma            $114                       Data-Science-as-a-Service
Palantir                 $78                         Big data software
Cloudera              $61                         Apache Hadoop-based software, services and training
Actian                   $46                         Big data applications, analytics engine, and Ingres database
1010data              $37                         Cloud-based analytics
10gen                    $36                         MongoDB (open-source, document database)
Alteryx                 $36                         Big data analytics platform
Guavus                 $35                         Big data analytics solutions

Tuesday, September 24, 2013

Big data Analytics

Tricky and tricker

I was wondering what is happening to this era of technology and see i a paradigm shift.
Ha nope, today's cloud / distributed computing = 50 year old mainframe
And BDA big data is nothing different than the data in mainframes.

I see it as , when data getting bigger and bigger, there are cheaper memory and powerful hardware available these days, the way of storing data is changing , map based, graph based all in-memory.

Relation in data are not represented in relational databases , data persistence are claimed to be secured in remote cloud.

Telecom Analytics
http://www.guavus.com/

Log Analytics
http://www.sumologic.com/

AWS Amazon web services Analytics
http://www.attribo.com/


Smaller players
http://www.sevacall.com/

Thursday, September 12, 2013

Security SDDC / Hypervisor

Collecting meaningful information here about security in virtualization solution


http://www.virtualizationpractice.com/virtualization-security-team-ups-6437/
https://www.youtube.com/watch?v=haETMMXObUA&feature=em-subs_digest

Virtual network security: A vendor comparison

For all the benefits a virtualized data center offers -- cost savings, agility and scalability -- it presents an equal number of security challenges. As server virtualization projects mature, IT organizations find that they need a new way of protecting systems from threats both inside the network -- think empowered administrators -- and outside the network. Of course, the vendor community is ready to help with a new market of virtual network security products.
“Whatever application you put in the virtual data center, the security assurance for that application data has to be exactly the same as if that application was hosted on the physical infrastructure. So whatever security properties you have for those applications -- firewall laws, network segmentation, antivirus, data-level controls -- have to be replicated in the virtualized infrastructure,” said Chenxi Wang, vice president and principal analyst with Forrester Research.
But the network security controls and practices that network admins put to use in a physical infrastructure don’t carry over to the virtual data center. For example, in a physical infrastructure, admins can segment servers with a firewall, Wang explained. A Web server may be external facing and another server can sit on the internal network. When these two servers are moved to a virtual infrastructure, they may no longer run on two separate pieces of hardware. They could be two virtual machines (VMs) on the same server, but they still need to be segmented.
“The virtual technology today, with the exception of VMware, doesn’t have built in controls, so you have to add third-party technology or do things manually to make sure they’re segmented,” said Wang.
To further complicate matters, the vendors that are addressing virtual network security in the data center each approach the problem a little bit differently. Some vendors offer virtual network security products that deploy as software on a physical server, while other products come as appliances that are deployed directly in the data center, said Wang. “Different delivery models give different operational overhead,” she said.
Only a small number of vendors currently offer virtual network security products for the data center. Among the larger players are Cisco Systems, HP Networking, Juniper Networks and VMware. Smaller players include HyTrust, Vyatta and Catbird.
Cisco’s Virtual Security Gateway and ASA 1000V
Cisco’s virtual security architecture is comprised of the Virtual Security Gateway and the ASA (Adaptive Security Appliance) 1000V Cloud Firewall. Both products integrate with the Cisco Nexus 1000v distributed virtual switch and can run as virtual appliances on an ESX or on the Cisco Nexus 1010 Virtual Services Appliance, making Cisco’s product an option only for Cisco shops. However, the Nexus 1000V supports multiple hypervisors (VMware and soon Microsoft Hyper-V), a benefit for those IT organizations that are running a multi-hypervisor data center.
The Virtual Security Gateway (VSG) is a zone-based firewall designed to protect inter-VM communications within a particular tenant. It provides access control between VMs. VSG integrates with ASA 1000V, which is Cisco’s cloud version of its physical security infrastructure firewall, the Cisco Adaptive Security Appliance (ASA). The Cisco ASA 1000V Cloud Firewall secures the tenant edge.
HP TippingPoint Secure Virtualization Framework
HP addresses virtual network security with its Secure Virtualization Framework, which consists of the HP Virtual Controller (vController), Virtual Firewall (VFW), Virtual Management Center (VMC) and the HP TippingPoint N Series IPS. The Virtual Firewall creates trust zones and performs segmentation across VMs, clusters and application groups. The vController and VFW sit within each hypervisor and apply security policies to traffic going between VMs. Together they dictate which VMs can speak to each other. The vController also sends traffic to the intrusion prevention system (IPS). The TippingPoint N Series IPS inspects traffic and either sends it back to the virtual cluster or drops it, based on policies set within the VMC.
Juniper Networks vGW
Juniper Networks’ vGW is a firewall that sits within the hypervisor and performs security processing within the kernel. It is compatible only with VMware. It is integrated with VMware’s vCenter and managed through a management console, Security Design for vGW. In addition to stateful firewall functionality, vGW includes compliance, antivirus and monitoring and reporting functionalities..  It is based on technology from Altor Networks, a virtual network security specialist that Juniper acquired in late 2010.
VMware vShield
The VMware vShield product line includes vShield App, vShield Edge and vShield Endpoint. VShield Edge is a network and security gateway that protects the virtual data center perimeter. VShield App provides segmentation of inter-VM communications. It is designed to lock down applications to only those ports and services required to make them work. VShield Endpoint offloads antivirus functionality to a dedicated virtual appliance, thereby removing the antivirus agent footprint in VMs. The three software products can be deployed independently or together in a VMware infrastructure.
Vyatta Network OS
Vyatta Network OS, the company’s virtual router software, includes traditional network security functionality -- such as stateful firewall, IPsec and SSL-based VPNs, network intrusion prevention, Web filtering and dynamic routing -- as pre-packaged virtual machines. The software runs on the hypervisor and is compatible with VMware, Xen, XenServer and Red Hat KVM. Vyatta Network OS can be managed via the command line, Vyatta’s Web-based GUI or a third-party management system.
HyTrust Appliance
The HyTrust Appliance is a virtual appliance that is deployed within the VMware infrastructure. The software intercepts administrative requests in the VMware management plane and permits or denies the requests based on defined policy. HyTrust authenticates and verifies users’ identities to prevent unauthorized access to the virtual infrastructure. However, HyTrust also provides network layer protection by helping to enforce network-level policies. For example, if a network admin attempts to connect a VM to the wrong network segment, the HyTrust Appliance will prevent that request. HyTrust can be used with VMware vShield.
Catbird vSecurity
Catbird vSecurity is comprised of a virtual appliance that is deployed inside each virtual host and a Catbird Control Center that serves as the management console. There are four elements within the virtual appliance. VCompliance monitors and enforces compliance. Hypervisor Shield monitors the server and the network to protect the hypervisor against unauthorized access, incorrect configurations and bridging with the public network. VMshield protects the VMs themselves. If a VM’s configurations are not in accordance with policy, then it is quarantined from the rest of the network until it can be remediated. Finally, TrustZones enforces the security policies for individual machines, regardless of their location. TrustZones can be used to segment the network. Catbird vSecurity is available for VMware and XenServer environments.

bee-social