A guide: SD-WAN as a tool for your cloud-first strategy

Following a cloud-first strategy is great for IT budgets and business agility but places new demands on the network. Cloud first can significantly impact network operations, as an increasing percentage of traffic flows directly to, from, and between clouds.

Unfortunately, the traditional MPLS architecture simply cannot support the economics or agility required for a cloud-first strategy. MPLS can be costly and time-consuming to configure and requires that Internet-bound traffic be backhauled to a centralized data center for inspection. Backhauling slows performance significantly for branch offices and remote users, who require direct Internet access for their cloud services. Providing direct-to-net access means re-architecting the network with security in mind.

In support of cloud first strategies, many organizations are turning to software-defined WAN (SD-WAN). SD-WAN provides secure local or regional breakouts to the cloud, enabling traffic to flow directly to the Internet from the closest available link. If additional levels of security are needed, SD-WAN technologies can segment and route sensitive data to cloud security providers for further inspection.

First, make the network virtual

The solution sounds simple, virtualizing the network as you have computing and storage and integrating the cloud, data center, WAN, and wired and wireless LAN into a unified fabric. The resulting cloud network has tremendous flexibility and scalability, with consistent policy deployment across the entire set.

If everyone in the organization worked from the same location at the same time, then provisioning networks for a cloud-based world might not be such a big problem – a couple of big pipes to the Internet for backup and load balancing would serve most organizations. However, when dealing with multiple locations, mobile users, and rapidly growing network traffic, that same centralized network architecture creates bottlenecks that drive up costs and compromise performance. By virtualizing the network, administrators can centrally manage traffic flows and their internal and third-party cloud networks more effectively and efficiently.

Second, automate network management and orchestration

Re-architecting the network could be done with manual configuration changes on the routers or custom scripts, as long as the set of cloud services is stable, workloads always execute from the same locations, and users do not change locations. Of course, none of these conditions are realistic, and MPLS provisioning can take months to add capacity or connect new locations. An effective SD-WAN must deliver the necessary business agility to get the maximum benefit from cloud services.

SD-WAN supports cloud first strategies by intelligently routing traffic based on business policies. Users can automatically connect to the cloud or between cloud services across the best available linkand removes the manual configuration headache from network administrators. Policies – not manual scripting – define which traffic is routed over which path based on business needs, security requirements, and current network health. Traffic can be appropriately segmented, such as voice data over MPLS and SaaS applications over broadband. Best of all, traffic flows more evenly across the entire organization’s network, reducing bottlenecks and improving application delivery.

Third, deliver security in the cloud

All of the benefits of cloud services and software-defined WANs are of little consolation if there is a security breach. Manually replicating and maintaining security appliances across tens or hundreds of locations is just not feasible. Instead, SD-WAN enables organizations to leverage cloud security providers, selectively directing traffic flows to the appropriate security service while providing embedded security such as firewalls, VPNs, and user segmentation.

For example, an engineering services company uses a variety of online apps, such as Box and Office 365, along with their cloud services. Since these applications involve mostly smaller but still confidential files, they choose to direct all of the related SaaS traffic back to the data center for inspection.

However, their engineering tools, which generate very large files, run on a cloud service so that they are accessible to authorized employees and partners around the world. Running this traffic through central security causes too many performance issues and drives up connectivity costs, so instead they route the traffic to a cloud access security broker (CASB), such as Zscaler.

With just a few clicks, the CASB provides worldwide access control, malware detection, and inline data protection. The CASB scales and distributes the load as needed to handle the large data requirements. Traffic is secured in an IPSec tunnel, and InfoSec policies are enforced with integrated functions such as data loss prevention (DLP).

Cloud first needs cloud networking

At the end of the day, cloud-first strategies are designed to provide the best possible user experience. The network is of limited value if the user experience is poor or inconsistent. Effective SD-WAN tools provide deep visibility into application performance, network flows, congested areas, and which users and devices are connected to the network, enabling IT to effectively deploy and manage their applications and the underlying infrastructure.

As cloud computing continues to grow and evolve, the majority of organizations will adopt cloud-first strategies. Whether using leading IaaS offerings such as AWS and Azure, or something from the vast set of SaaS applications, software-defined WANs are essential to corporate agility and security. Optimizing applications by rapidly establishing and tearing down connections, simply cannot be done without centralized network management and orchestration. Cloud first needs cloud networking.  

Your guide to Facebook Workplace


Steve Cassidy

1 Mar, 2018

We’ve tried Facebook before. It was hard to keep coming up with new content to post, and it didn’t seem to benefit us much.

You’re echoing the experience of many organisations who have tried using Facebook as a marketing tool. The fact is, while Facebook’s potential for promotion and relationship-building can be formidable, it’s not right for everyone. “Workplace by Facebook” is something quite different: simply put, it’s a custom version of the Facebook environment for messaging between co-workers.

This sounds like a terrible idea – won’t people be distracted by chit-chat and memes when they’re supposed to be working?

It must be admitted, the Workplace vision of what people get up to at work isn’t universal. I certainly wouldn’t suggest that a company of forestry workers or a brass band try to use Facebook on the job.

Yet, the evangelical slogans about embracing social media aren’t entirely off base. If you trial Workplace and get nothing more from it than a chance to remind your staff to get on with their jobs, that’s still better than souring the working environment with glowering intrusions to check up on what they’re doing online.

It sounds like my employee communications will be running inside someone else’s cloud. What about security and privacy?

At the time of writing, Workplace offers a fairly simple framework providing virtual private meeting places for people who work in different businesses. The idea is to allow discussion of mutual projects without exposing other information and resources.

To be sure, it’s hard to overlook Facebook’s historic habit of eagerly rolling out new features and letting users do the field-testing. But there are good opportunities here. You can create and tear down a collaborative group more or less on a whim. It might exist for only an afternoon; it might also be that it has only one external member, advising a whole internal team (think legal matters, or health and safety). Adapting your mindset beyond the email model is a key part of getting the most from these consumer crossover platforms.

At the end of the day, isn’t this just another online chat system?

Facebook’s communications credentials certainly started with simple chat, but have blossomed to include both audio and video connections. This means you can substitute Workplace for services such as Skype, WhatsApp and dedicated VoIP systems. Yes, there are some notable gaps in the feature set, like the absence of a POTS (analogue phone service) gateway such as Skype Out, or true multi-feed video conferencing for virtual meeting room creation. Still, Facebook brings other advantages – for example, Facebook Live sessions, which are not only streamed but stored for future reference.

What’s more, like it or not, Facebook has tremendous member loyalty. For some people it’s the first place they go in the morning, and the last at night. Harnessing that feel-good factor to foster both collaborative and productive relationships isn’t a silly thing to be doing. If you can get employees to feel more positively about work, you’ve achieved something.

That sounds good, but I’m still concerned about oversight. We have to own our own business-critical systems.

That’s not an issue on Workplace. There are at least two defined classes of super-user, namely administrators, and “IT Teams”. Administrators can define the entire environment, in terms of how existing Facebook accounts are allowed into the Workplace separate playpen, and how the Workplace system handles things such as single sign-on with mature Windows networks. What’s more, Facebook provides one-on-one help for admins, so you can always get a guided support session and ask as many questions as you need. In short, whatever arrangement works for you ought to be attainable.

And how do we handle things such as oversight and legal compliance?

This is where that second group comes in. They’re referred to in terms of IT, but they really act as compliance officers: these are the guys who make sure you’re not breaking any laws or conditions of service, and keeping paper trails as required. Over the years, we’ve seen many collaboration platforms created by brilliant but inexperienced youths, which entirely lack the oversight features a business needs. Consequently, the fact that Workplace by Facebook doesn’t fall into that trap is itself a definite recommendation.

Image: Shutterstock

Colt: Vendors have a moral duty to run green data centres


Lee Bell

28 Feb, 2018

Hybrid cloud company Colt Data Centres today announced a big push into renewable energy by opting to run its European data centres on power generated from renewable sources.

While the option isn’t available on all of its data centre sites, nine of the company’s 17 European facilities now run exclusively on renewable energy, and Colt plans to make the others renewable when possible – though this isn’t always the case.

In France, for example, the country’s reliance on nuclear power and an energy generation shortfall makes it impossible for any data centre provider to guarantee 100% renewable power, Colt claimed, althought it does hope that planned developments for renewable energy will make up the shortfall by 2023.



“The global technology industry needs to face up to its global responsibilities, not least in the area of energy usage,” said Colt CEO, Detlef Spang. “So far, most ‘green’ regulations are voluntary – such as the European Commission’s voluntary code of conduct for energy efficiency in data centres.”

He added that the firm believes that the cloud and data centre industry has “a moral and ethical duty” to go far beyond the minimum requirements for sustainability, and to deploy techniques and new infrastructure technology that “will have a major and measurable effect on the resources we use”.

This will require a lot of investment, Spang said, but by adopting the latest technologies and best practices, he believes it will be possible to deliver lower lifetime costs for its customers while ensuring “the smallest possible ecological footprint” in its territories where the company operates around the world.

“Colt’s internal design team have embarked on a project to look at all forms of green energy to see how they will best [fit] into data centre designs going forward to ensure we are minimise the impact of Colt data centres to the environment,” he added.

The announcement is part of a wider campaign by Colt to reduce the environmental impact of its worldwide network of data centres, which has also looked to kick off a strong drive internally to reduce CO2 emissions, optimising power usage effectiveness, and adopting new cooling technologies across its facilities to optimise the performance of their data centres.

 

delaPlex to Exhibit @CloudEXPO NY | @delaPlexSoftwar #DevOps #API #Monitoring #FinTech #IoT

delaPlex is a global technology and software development solutions and consulting provider, deeply committed to helping companies drive growth, revenue and marketplace value. Since 2008, delaPlex’s objective has been to be a trusted advisor to its clients. By redefining the outsourcing industry’s business model, the innovative delaPlex Agile Business Framework brings an unmatched alliance of industry experts, across industries and functional skillsets, to clients anywhere around the world.

read more

Comprobar disponibilidad de protocolos SSL

Para un determinado servicio SSL podemos verificar mediante openssl s_client. Vamos a ver cómo:

El subcomando s_client dispone de opciones para indicar el protocolo a usar:

echo | openssl s_client -connect systemadmin.es:443 -ssl3
echo | openssl s_client -connect systemadmin.es:443 -tls1_2
echo | openssl s_client -connect systemadmin.es:443 -tls1_1
echo | openssl s_client -connect systemadmin.es:443 -tls1

Por lo tanto simplemente buscando si se establece la sesión podemos ver si el protocolo esta soportado en el lado servidor:

# echo | openssl s_client -connect systemadmin.es:443 -tls1_2 2>&1 | grep "Session-ID: "
    Session-ID: AA27E5EAC09CF474E38E8934B81CAE0D5759BFDAFAA0274AB37B38D6715F84EB
# echo | openssl s_client -connect systemadmin.es:443 -ssl3 2>&1 | grep "Session-ID: "

Por lo tanto, podemos ver que en este caso TLS 1.2 esta soportado mientras SSLv3 no

Tags:

The risks to Dropbox’s approaching IPO


Clare Hopping

28 Feb, 2018

Dropbox filed for an IPO last week, and while it’s the natural next step for a company dominating the cloud storage space, the filing also revealed a number of risks that could put a whole lot of pressure on the organisation if things go wrong.

By law, IPO filings must detail the risks to a company’s success so investors are able to make a considered investment, knowing all the facts. Dropbox’s filing is no different, and it has highlighted areas the company may struggle with when it goes public.

We’ve rounded up the main risks to Dropbox’s IPO filing and how it could affect the company’s potential to raise the investment it expects to achieve.

Number of Dropbox users and upgrading customers

At the moment, Dropbox has 500 million registered users around the world, but many of these are using the company’s free storage option rather than taking advantage of the extra storage offered in its premium options. In fact, only 11 million customers (2.2%) pay for a Dropbox subscription.

To ensure it can be profitable, Dropbox needs to convince as many of its free-tier customers – or those on a free trial of Dropbox for Business for example – to start paying for the use of its service.

The company must also focus on attracting new users. It explained in the filing that the number of unique users (those that have only registered one account) is a lot lower than its total active users and so its figures may be even more skewed than the initial numbers suggest. This also means there’s likely to be fewer customers it can convert to paying users, because each will only pay for one account.

Revenue vs profit

As a result of its failure to persuade customers on free trials and those making use of the free service to commit to a paid subscription, Dropbox’s revenue growth is slowing. The company explained in the filing that the major reasons its revenues aren’t growing as fast as previous periods include that there’s more competition now than there was previously, less demand for the platform, an overall decline in the content collaboration market and the company’s inability to maxmise growth opportunities. It also noted the business has matured and so saturation is higher than it previously was. 

Profits are also on course to decline as Dropbox invests more to scale its business, including supporting the infrastructure to support its customers and research and development. The company notes that these investments may not directly result in increased revenues or profit, making it likey both will slow, or start to fall.

No outbound salesforce

Dropbox also revealed that it doesn’t have a specific outbound salesforce on the ground hard-selling to businesses or other volume users. It has instead relied upon organic adoption and viral growth rather than actively selling its services to new prospects.

The company does believe it will be able to scale to reach new markets without a large outbound salesforce, but it also accepts that its current word-of-mouth and user referral marketing model may not continue to work as effectively as it has over the last few years.

However, there’s a significant cost and time investment attached to recruiting a specialised sales team, which could adversely affect the company’s profitability in the future.

“Further, adding more sales personnel would change our cost structure and results of operations, and we may have to reduce other expenses in order to accommodate a corresponding increase in sales and marketing expenses,” the company noted.

The filing can be read in full here.

Main image credit: Shutterstock

Ed Featherston Joins @CloudEXPO NY Faculty | #BigData #IoT #IIoT #SmartCities

When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things’). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the massive amount of information associated with these devices. Ed presented sought out sessions at CloudEXPO Silicon Valley 2017 and CloudEXPO New York 2017. He is a regular contributor to Cloud Computing Journal.

read more

Three Pillars of DevOps Success in 2018 | @DevOpsSummit @CollabNet #DevOps

I love the beginning of the year. It is always enjoyable to see people’s predictions for trends in the coming year. Publications like Fortune, CNN Money, Washington Post and the Atlantic speculate about what gadgets and technologies are going to take off in popularity this year, psychics predict which celebrities will have babies and fall in love, and I start to think about trends like DevOps and where the software delivery industry is headed next.CollabNet, Eric Robertson, predicted.

read more

Yung Chou Joins @CloudEXPO NY Faculty | @Azure #Serverless #DevOps #Jenkins #Github #Docker

CI/CD is conceptually straightforward, yet often technically intricate to implement since it requires time and opportunities to develop intimate understanding on not only DevOps processes and operations, but likely product integrations with multiple platforms. This session intends to bridge the gap by offering an intense learning experience while witnessing the processes and operations to build from zero to a simple, yet functional CI/CD pipeline integrated with Jenkins, Github, Docker and Azure.

read more

The cloud news categorized.