Presentation is loading. Please wait.

Presentation is loading. Please wait.

Efficient and Secure Application Delivery

Similar presentations


Presentation on theme: "Efficient and Secure Application Delivery"— Presentation transcript:

1 Efficient and Secure Application Delivery
Barracuda Application Delivery Controller Webinar

2 Agenda What is the ADC? Who is going to buy it? ADC Positioning
Sizing and Ordering

3 What is it? The Barracuda ADC Story

4 Solutions Must Focus on the Applications
There is no such thing as “downtime” Applications must always be there User experience is critical to success Applications must be fast & scalable to meet growth Application control drives user experience Must be able to customize the user experience based on users, regions, and/or devices. Security is a must Need to protect applications against cyber criminals, hacktivism, malware, bots, etc. User experience is critical to success Applications must be fast & scalable to meet growth Application control drives user experience Must be able to customize the user experience based on users, regions, and/or devices. There is no such thing as “downtime” Applications must always be there Security is a must Need to protect applications against cyber criminals, hacktivism, malware, bots, etc.

5 Introducing the Barracuda Application Delivery Controller
Designed to help organizations efficiently and securely deliver applications to their users Availability Acceleration Control Security

6 Barracuda Application Delivery Controller
Availability Acceleration Control Security

7 High Availability within Data Center
Exchange CAS #1 Exchange CAS #2 Oracle Server Group 1 L4/L7 Load Balancing Application Monitors Failover Groups Session Persistence Oracle Server Group 2 Graphics compression, caching Multiple arrows for TCP Pooling SSL Offloading on boxes Graphical representation of caching/compression?

8 What about Site-to-Site High Availability?

9 Global Server Load Balancing (by Priority)
Always go to primary site Michigan (Primary) Denver Boston San Francisco X Go to DR site only when primary is down Oregon (Secondary) Multi-same icons on both Availability – 1 Data Center Availability & DR – Multi-site/datacenter

10 Global Server Load Balancing (by Geo IP)
Always go to closest geographic location available Michigan (Primary) Denver Boston Oregon (Secondary) San Francisco X Multi-same icons on both Availability – 1 Data Center Availability & DR – Multi-site/datacenter

11 Global Server Load Balancing (by Region)
Always go to closest geographic location available Michigan (“East”) Boston Oregon (“West”) Denver San Francisco X Multi-same icons on both Availability – 1 Data Center Availability & DR – Multi-site/datacenter

12 Barracuda Application Delivery Controller
Availability Acceleration Control Security

13 Scalability & Performance Requires Acceleration
Data Center SSL Offloading Link Bonding HTTP Compression HTTP Caching TCP Pooling Connection Multiplexing Multiple arrows for TCP Pooling? Graphical representation of caching/compression?

14 Barracuda Application Delivery Controller
Availability Acceleration Control Security

15 Application Control http://www.site.com http://www.site.com/main
Main Site Content Routing URL Rewrite Rate Control IPv6/IPv4 DDoS Mobile Site X Throttle or block

16 Barracuda Application Delivery Controller
Availability Acceleration Control Security

17 Layer 7 Security Controls
Cloaks Application Error Codes Web Server Errors Credit Card Numbers SSN Numbers Inbound inspection (protect against layer 7 attacks) Outbound inspection (protect against data leakage)

18 Attack Protection & Data Loss Prevention
OWASP Top-10 SQL Injection Cross Site Scripting Cross Site Request Forgery HTTP Parameter Pollution Web Site Cloaking Integrated Anti-Virus Scanner Session Protection Cookie Encryption Parameter Tampering Denial of Service Protection Brute Force Protection Control access by Geo IP Layer 7 DDoS Attacks Data Theft Protection Credit Card number Social Security Numbers Customer Patterns SIEM Integration

19 Automatic Security Updates
150,000+ customers in 80+ countries sending Network, Web Content, Web Application, and Security information for fastest response to emerging threats

20 Certifications & Deployments

21 Application Certifications & Deployment Guides
Microsoft Exchange 2007, 2010, 2013 SharePoint 2007, 2010, 2013 Lync 2010 Office Communication Server 2007 Terminal Services Package Applications Oracle Web Servers Apache Microsoft IIS NGINX Virtual Servers VMWare XenServer Hyper-V Barracuda Networks Spam & Virus Firewall Web Application Firewall CudaTel Future VMWare View SAP Netweaver Blackboard/Moodle

22 Who is going to buy it? Customer Use Cases

23 Looking for a Great Load Balancer?
Just like the LB sales, but better Better reporting and logging Higher end models Multi GB Throughput (5 & 10 GB in initial release) Multi-Port configuration ( Up to 24 x 1GB ports on 8 series model) 10GB NIC optional connectivity Now also includes important new security functionality #1 feature request from existing LB customers Just like the LB sales, but more Multi-gig throughput (including an 8 series box) Programmable Multi-Port (including optional 10Gbit interfaces) Better logging and reporting Now also includes important new security functionality Web Application Firewall and Basic Network Firewall Number 1 “new feature ask” by exisiting customers was Application Security by a wide margin Market branding and positioning (even at low end) has been moving to ADC so this will assist as well Almost every sales inhibitor & limiter from previous LB product line sales is now removed (up to 6Gbit throughput)

24 “All in One” Deployment Platform
Data Center Consolidation is the big trend Many functions moving onto a single box Basic NW Firewalling Reverse Proxy SSL Offloading Load Balancing/Performance Caching/Compression Web Application Firewalling Much cleaner and easier to implement architecture Remove 4 or 5 different boxes and vendors aka “the Konga Line” Compelling Economics: Save Lots of Money! Mid Enterprise in the sweet spot for this Currently only F5 can deliver load balancing, WAF, and NW firewall on a single ADC platform. They are spending significant resources to push this combo of features as the requirements for a “NG ADC” This is the data center consolidation story taken to the next level Now you can deploy an ADC in the DMZ without a separate firewall in front of it. NG Firewall capability is probably overkill. Basic firewall functionality to control and direct connections in probably sufficient These type of firewall deployments can be viewed as a commodity Simplify the architecture, significantly reduce cost, and actually improve security (L4 and L7 security on one box) The sweet spot for this is the mid enterprise Most Large Enterprises will not consolidate and will still keep separate firewall boxes for a variety of reasons This customer profile is not the sweet spot for F5 and F5’s premium pricing certainly takes away from the value prop significantly (the NW firewall is a 4th additional module that the customer would need to buy) So F5 educates the market and creates demand, only Barracuda can fulfill

25 Microsoft Infrastructure Deployment Platform
MS Threat Management Gateway (TMG) is end of life #1 deployment scenario was in front of MS Exchange MS back ends are most common in mid enterprises Applicability across most MS backend solutions Exchange 2010, 2013 SharePoint 2010, 2013 Lync 2010, 2013 IIS (for custom web apps) ADC will have the appropriate MS certifications & templates MS Threat Management Gateway (TMG) is end of life. Replace it with something that does even more Reverse Proxy like TMG A better network firewall than TMG “New”: Load Balancer “New”: WAF for application Security MS backends are most common in mid enterprises. Even in larger enterprises, the throughput requirements for these mainly internal apps are lower, so throughput (and our limitations here) will be a smaller factor in the decision process Cost sensitivity generally higher for internal apps as well, so our value pricing will resonate Applicability across most MS backend solutions Outlook: Protect OWA and provide load balancing (important in Outlook 2010) Sharepoint: Application Security and AV scanning for file uploading. MS Web Server: Application Security Plus the replacement for the MS TMG solution Note: ADC will be have the appropriate MS certifications (like the Outlook certification) and also have a full suite of templates for current versions of the various MS products

26 Customers in Active Buying Cycles
Cisco ACE Load Balancer End of Life $500 million replacement occurring now!

27 Positioning the ADC

28 We Have Two Product Lines
Barracuda Application Delivery Controller Official name: Barracuda Load Balancer ADC Sell to customers looking for Load Balancing Sell to Customer looking for Advanced Application Delivery Barracuda Web Application Firewall Sell to customers looking for stand alone WAF Sell to customers looking for best in class security device

29 Additional Key Triggers
Barracuda ADC Barracuda WAF GSLB DR Site Performance and Security >3GB Throughput High port density LB of MS Exchange Key Competitors: F5, A10, Citrix, Kemp Stand Alone HTTP/S or XML Security Only Requires “Positive” Security, Profiling, or Application Learning Using a WAFEC RFP Requires FIPS HSM Key Competitors: Imperva,

30 Other Important Stuff ADC vs WAF, SKUs and ordering

31 Sizing Guidelines MODELS 240 340 440 640 840 0.1 1 1 5 10 10 35 50 250
Throughput (Gbps) Real server support 10 35 50 250 500 SSL Offloading (TPS) -- 500 4,000 15,000 30,000 Caching / Compression -- -- Y Y Y Global Server Load Balancing -- -- Y Y Y Application Security -- -- -- Y Y

32 640 Hardware Platforms MODELS 640 641 642 643 8 8 8 16 -- 2 -- -- --
Configurations 8 8 8 16 1 Gb Copper 10 Gb Copper -- 2 -- -- 10 Gb Fiber -- -- 2 --

33 840 Hardware Platforms 840 841 842 MODELS 8 8 8 -- 2 -- -- -- 2
Configurations 8 8 8 1 Gb Copper 10 Gb Copper -- 2 -- 10 Gb Fiber -- -- 2 840-series can be further customized to up to 24x1G NICs and/or 4x10G Fiber/Copper. Please contact Barracuda for more details.

34 ADC Product Structure EU IR Security Subscription (Optional)
Additional Networking Options (Optional) Base Product

35 Ordering SKUs 64X Models SKU Configuration 640 BBF640b 8x1Gbps 641
BBF641a 8x1Gbps + 2x10Gbps copper 642 BBF642a 8x1Gbps + 2x10Gbps Fiber 643 BBF643a 16x1Gbps 84X Models 840 BBF840a 841 BBF841a 8x1Gbps + 2x10Gbps Copper 842 BBF842a Application Security subscription can be selected in model 640/840s with SKUs that contain. “-s1, - s3, or –s5” . For example a 640 with 1 year of EU & Application Security is BBF640b-a1-s1. Partner Only

36


Download ppt "Efficient and Secure Application Delivery"

Similar presentations


Ads by Google