June 2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications Firewall Virtualization for Grid Applications BOF

Slides:



Advertisements
Similar presentations
© 2006 Open Grid Forum GHPN-RG Status update co-chairss:Cees de Laat Dimitra Simeonidou GGF22, Boston, February 2008.
Advertisements

© 2006 Open Grid Forum JSDL 1.0: Parameter Sweeps OGF 23, June 2008, Barcelona, Spain.
© 2006 Open Grid Forum Network Services Interface OGF30: Connection Services Guy Roberts, 27 th Oct 2010.
© 2006 Open Grid Forum Ellen Stokes, IBM Michel Drescher, Fujitsu Information Model, JSDL and XQuery: A proposed solution OGF-19 Chapel Hill, NC USA.
© 2006 Open Grid Forum Network Services Interface Introduction to NSI Guy Roberts.
© 2006 Open Grid Forum JSDL 1.0: Parameter Sweeps: Examples OGF 22, February 2008, Cambridge, MA.
© 2006 Open Grid Forum OGF19 Federated Identity Rule-based data management Wed 11:00 AM Mountain Laurel Thurs 11:00 AM Bellflower.
© 2007 Open Grid Forum JSDL-WG Session OGF27 – General Session 10:30-12:00, 14 October 2009 Banff, Canada.
©2010Open Grid Forum OGF28 OGSA-DMI Status Chairs: Mario Antonioletti, EPCC Stephen Crouch, Southampton Shahbaz Memon, FZJ Ravi Madduri, UoC.
Oct, 26 th, 2010 OGF 29, FVGA-WG: Firewall Virtualization for Grid Applications Firewall Virtualization for Grid Applications - Status update
© 2006 Open Grid Forum Joint Session on Information Modeling for Computing Resources OGF 20 - Manchester, 7 May 2007.
© 2007 Open Grid Forum JSDL-WG Session OGF21 – Activity schema session 17 October 2007 Seattle, U.S.
© 2006 Open Grid Forum 2 nd March 09 Enterprise Grid Requirements Research Group OGF25 EGR-RG Session Group.
© 2006 Open Grid Forum OGSA Next Steps Discussion Providing Value Beyond the Specifications.
Oct 15 th, 2009 OGF 27, Infrastructure Area: Status of FVGA-WG Status of Firewall Virtualization for Grid Applications - Working Group
© 2006 Open Grid Forum OGSA Profiles Interoperability Testing Dr. David Snelling Fujitsu Laboratories of Europe.
© 2006 Open Grid Forum OGSA Profiles Interoperability Testing Dr. David Snelling Fujitsu Laboratories of Europe.
© 2008 Open Grid Forum Resource Selection Services OGF22 – Boston, Feb
© 2006 Open Grid Forum Network Services Interface OGF29: Working Group Meeting Guy Roberts, 19 th Jun 2010.
Feb OGF22NML-WG: Welcome and Introduction Welcome and Introduction Paola Grosso - UvA Martin Swany - UDelaware.
© 2007 Open Grid Forum JSDL-WG Session 1 OGF25 – General Session 11:00-12:30, 3 March 2009 Catania.
© 2006 Open Grid Forum JSDL Optional Elements OGF 24 Singapore.
© 2007 Open Grid Forum OGSA-RUS Specification Update, Adoption and WS-RF Profile Discussions (Molly Pitcher) Morris Riedel (Forschungszentrum Jülich –
© 2006 Open Grid Forum Grid Resource Allocation Agreement Protocol GRAAP-WG working session 2 Wenesday, 17 September, 2008 Singapore.
© 2006 Open Grid Forum Joint Session on Information Modeling for Computing Resources (OGSA Modeling Activities) OGF 21 - Seattle, 16 October 2007.
September 17 th, 2008 OGF 24, FVGA-WG: Firewall Virtualization for Grid Applications Firewall Virtualization for Grid Applications - Work Group
© 2006, 2007 Open Grid Forum Michel Drescher, FujitsuOGF-20, Manchester, UK Andreas Savva, FujitsuOGF-21, Seattle, US (update) Extending JSDL 1.0 with.
© 2006 Open Grid Forum Network Services Interface OGF30: Working Group Meeting Guy Roberts, Inder Monga, Tomohiro Kudoh 27 th Oct 2010.
1 ©2013 Open Grid Forum OGF Working Group Sessions Security Area – FEDSEC Jens Jensen, OGF Security Area.
© 2006 Open Grid Forum DCI Federation Protocol BoF Alexander Papaspyrou, TU Dortmund University Open Grid Forum March 15-18, 2010, Munich, Germany.
© 2007 Open Grid Forum Data Grid Management Systems: Standard API - community development Arun Jagatheesan, San Diego Supercomputer Center & iRODS.org.
© 2006 Open Grid Forum Service Level Terms Andrew Grimshaw.
© 2010 Open Grid Forum Standards All Hands Meeting OGF28, München, March 2010.
OGF DMNR BoF Dynamic Management of Network Resources Documents available at: Guy Roberts, John Vollbrecht.
© 2006 Open Grid Forum Network Services Interface OGF 32, Salt Lake City Guy Roberts, Inder Monga, Tomohiro Kudoh 16 th July 2011.
© 2007 Open Grid Forum Enterprise Best (Community) Practices Workshop OGF 22 - Cambridge Nick Werstiuk February 25, 2007.
© 2010 Open Grid Forum OCCI Status Update Alexander Papaspyrou, Andy Edmonds, Thijs Metsch OGF31.
© 2007 Open Grid Forum JSDL-WG Session OGF22 – General Session (11:15-12:45) 25 February 2008 Boston, U.S.
© 2006 Open Grid Forum FEDSEC-CG Andrew Grimshaw and Jens Jensen.
© 2006 Open Grid Forum Network Services Interface OGF 33, Lyon Guy Roberts, Inder Monga, Tomohiro Kudoh 19 th Sept 2011.
© 2015 Open Grid Forum ETSI CSC activities Wolfgang Ziegler Area Director Applications, OGF Fraunhofer Institute SCAI Open Grid Forum 44, May 21-22, 2015.
© 2006 Open Grid Forum GridRPC Working Group 15 th Meeting GGF22, Cambridge, MA, USA, Feb
OGSA-RSS Face-to-Face Meeting Sunnyvale, CA, US Aug 15-16, 2005.
© 2008 Open Grid Forum OGSA-DMI WSDL Renderings & Interop OGF23 OGSA-DMI session Michel Drescher 2 June, 2008 Barcelo Sants Hotel.
© 2006 Open Grid Forum OGSA-WG: EGA Reference Model GGF18 Sept. 12, 4-5:30pm, #159A-B.
© 2006 Open Grid Forum Remote Instrumentation Services in Grid Environment Introduction Marcin Płóciennik Banff, OGF 27 Marcin Płóciennik.
© 2006 Open Grid Forum Grid High-Performance Networking Research Group (GHPN-RG) Dimitra Simeonidou
© 2006 Open Grid Forum NML Progres OGF 28, München.
© 2007 Open Grid Forum OGF Management Area Meeting OGF20 7 May, am-12:30pm Manchester, UK.
© 2006 Open Grid Forum 1 Application Contents Service (ACS) ACS-WG#1 Monday, September 11 10:30 am - 12:00 am (158A-B) ACS-WG#2 Wednesday, September 13.
© 2008 Open Grid Forum Production Grid Infrastructure WG State Model Discussions PGI Team.
© 2007 Open Grid Forum JSDL-WG Session OGF26 – General Session 11:00-12:30, 28 May 2009 Chapel Hill, NC.
Network Services Interface
SLIDES TITLE Your name Session Name, OGSA-WG #nn
Welcome and Introduction
RISGE-RG use case template
Grid Resource Allocation Agreement Protocol
OGF session PMA, Florence, 31 Jan 2017.
Network Services Interface
Network Services Interface Working Group
OGSA-Workflow OGSA-WG.
Information Model, JSDL and XQuery: A proposed solution
Network Measurements Working Group
WS Naming OGF 19 - Friday Center, NC.
Activity Delegation Kick Off
SAGA: Java Language Binding
Network Services Interface Working Group
SAGA: Java Language Binding
Proposed JSDL Extension: Parameter Sweeps
OGF 40 Grand BES/JSDL Andrew Grimshaw Genesis II/XSEDE
Presentation transcript:

June 2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications Firewall Virtualization for Grid Applications BOF

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 2 OGF IPR Policies Apply I acknowledge that participation in this meeting is subject to the OGF Intellectual Property Policy. Intellectual Property Notices Note Well: All statements related to the activities of the OGF and addressed to the OGF are subject to all provisions of Appendix B of GFD-C.1, which grants to the OGF and its participants certain licenses and rights in such statements. Such statements include verbal statements in OGF meetings, as well as written and electronic communications made at any time or place, which are addressed to: the OGF plenary session, any OGF working group or portion thereof, the OGF Board of Directors, the GFSG, or any member thereof on behalf of the OGF, the ADCOM, or any member thereof on behalf of the ADCOM, any OGF mailing list, including any group list, or any other list functioning under OGF auspices, the OGF Editor or the document authoring and review process Statements made outside of a OGF meeting, mailing list or other function, that are clearly not intended to be input to an OGF activity, group or function, are not subject to these provisions. Excerpt from Appendix B of GFD-C.1: Where the OGF knows of rights, or claimed rights, the OGF secretariat shall attempt to obtain from the claimant of such rights, a written assurance that upon approval by the GFSG of the relevant OGF document(s), any party will be able to obtain the right to implement, use and distribute the technology or works when implementing, using or distributing technology based upon the specific specification(s) under openly specified, reasonable, non-discriminatory terms. The working group or research group proposing the use of the technology with respect to which the proprietary rights are claimed may assist the OGF secretariat in this effort. The results of this procedure shall not affect advancement of document, except that the GFSG may defer approval where a delay may facilitate the obtaining of such assurances. The results will, however, be recorded by the OGF Secretariat, and made available. The GFSG may also direct that a summary of the results be included in any GFD published containing the specification. OGF Intellectual Property Policies are adapted from the IETF Intellectual Property Policies that support the Internet Standards Process.

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 3 What Problems? Control Plane (ex. Web Services) vs. the Data Plane CP using port 80 works seamlessly but Data Plane gets blocked Manual vs. Automated Document the ports per middleware, grid protocol deployed or authorize the CP to provide a level of automation Static vs. Transient Related issues as above

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 4 Proposed Solution Virtualized control of firewall Control the opening/closing of data path End-to-end applicability Local authorization/authentication Independence of the Firewall vendor/implementation Capabilities may be different

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 5 WebServices based FW opening principle design Client at A Auth server B Apps Server C FW I want a connection from A(4711) to C(1174) and here is my host A certificate There is A and it wants a connection to your port OK, go on, I am waiting OK service and certificate checked, go on Message includes server certificate of B Check certificate of A Request firewall to open port CLI, SNMP, special protocol, whatever done Communication starts Including client authorization at C

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 6 WebServices based FW opening Multiple local, remote and external FWs Client at A Auth server B Apps Server C FW

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 7 Administrative Issues Group Abbreviation: fvga-wg Group Name: Firewall Virtualization for Grid Applications - Working Group Area: Infrastructure

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 8 Group Summary Grid Computing vision of applications having on-demand, ubiquitous access to distributed services running on diverse, managed resources like computation, storage, instruments, and networks among others, that are owned by multiple administrators. dynamic, seamless Virtual Organizations (VOs) using distributed resources application driven transport privileges from the network pre-existing security policies within the network (firewalls, NAT, ALG, VPN- GW) administrator/manual intervention to work. fi-rg has documented use cases & issues that Grid applications face (GFD.83) fvga-wg will leverage the application requirements from FI-RG standardize a set of service definitions for a virtualized control interface into firewalls and other midboxes allowing grid applications to securely and dynamically request application/workflow-specific services

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 9 Goals/Deliverables Produce a standard set of service definitions that provide an abstract interface for an authorized grid application to specify its data-path traversal requirements: Port opening/closing service Data Plane and Service Plane interactions Requests from within and outside the security domain A set of security recommendations surrounding the application interacting with the Firewall service at the control and data plane including AAA of the service requests A best practices document for the network-administrator and a grid- administrator to understand the architecture and security implications of this deployment including: Deployment scenarios and use-cases Interactions between various Grid components Examples of successful prototype deployments The resulting standards from the working-group will enable Grid- Middleware/Network services developers to implement a virtualized firewall service, integrate with Grid-middleware security and provide a dynamic firewall service to the Grid applications. The working group will ensure that it is compatible with the OGSA architecture and leverages the security infrastructure and standards for Grid Applications.

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 10 Group Milestones OGF23: Charter discussion and group volunteers OGF24: Discussion on requirements to define the standardized service interface for virtualized Firewalls OGF25: Draft on Firewall-Virtualization-Service Discussion on Security, AAA and Grid-Security aspects OGF26: Firewall Virtualization-Service draft version 2 First draft on Security recommendations (v1) for FVGA OGF27: Finalized Firewall Virtualization-Service draft Security Recommendations v2 Two implementations and demonstration Discussion on Best Practices draft OGF28: WG-Last-Call for Firewall Virtualization-Service Final version of Security Recommendations First draft on Best Practices OGF 29: WG-Last-Call Security Recommendations Finalize Best Practices draft OGF 30: WG-Last-Call Best Practices Draft.

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 11 Future contributions Mailing list: Projects page: Contacts: Inder Monga: Ralph Niederberger: Thijs Metsch:

June 2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications Questions and discussion

June2 nd, 2008 OGF 23, FVGA-WG-BoF: Firewall Virtualization for Grid Applications 13 Questions and discussion Questions and discussion