23.12.2012 Views

Wer ist Radware?

Wer ist Radware?

Wer ist Radware?

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Hochverfügbarkeit für IPv6,<br />

Exchange und in virtuellen<br />

Umgebungen<br />

Uwe Lindmüller<br />

(Regional Sales Manager)<br />

UweL@radware.com<br />

Benjamin Radtke<br />

(Senior SE North/East Germany)<br />

BenjaminR@radware.com


• Wir sind ein Spezial<strong>ist</strong> für die Verfügbarkeit von Applikationen<br />

• Wir unterstützen beim Aufbau von Netzwerken, die auf<br />

Geschäftsprozesse ausgerichtet sind und garantieren:<br />

• absolute Verfügbarkeit<br />

• maximale Geschwindigkeit<br />

• umfassende Sicherheit<br />

für die geschäftskritischen Applikationen rund um die Uhr<br />

<strong>Wer</strong> <strong>ist</strong> <strong>Radware</strong>?<br />

• Unsere Business smarten Lösungen unterstützen das Netzwerk den<br />

Anforderungen & Prozessen gerecht zu werden, um die Produktivität<br />

zu steigern und die Infrastrukturkosten zu senken


Aktiengesellschaft – Sept. 1999<br />

(NASDAQ: RDWR) gegründet in 1997<br />

Mitglied der RAD Gruppe<br />

14 Firmen (davon 6 an der NASDAQ,<br />

über 4000 Mitarbeiter)<br />

mehr als 700 Mitarbeiter weltweit<br />

davon 340 in F&E<br />

3xTACs Tel Aviv, New Delhi, & New Jersey<br />

globale Präsenz<br />

Vertrieb in über 40 Ländern<br />

Firmeninformation<br />

stetiger Umsatzwachstum<br />

2010 Rekord Jahr<br />

Übernahme von Alteon<br />

(Nortel-Bereich) zum 01. April 2009<br />

Übernahme Protegrity


<strong>Radware</strong> Alteon Team Deutschland<br />

Martin Kroemer (Regional Director)<br />

Uwe Lindmüller (RSM Nord)<br />

Benjamin Radtke (Systems Engineer)<br />

Markus Spahn (Key Accounts + RSM West)<br />

Steffen Foitzik (RSM Mitte)<br />

Vladimir Bojkovic (Sr. Systems Engineer)<br />

Andreas Eckert (Alteon Support)<br />

Sabine Grübner (Sales Admin)<br />

Mandy Goodyear (Alteon Renewal Admin)<br />

Roland Legler (RSM Süd)<br />

Frank Hellwig (Systems Engineer)<br />

Hubertus Geuenich (Channel Manager)<br />

Michael Geigenscheder (Business Dev.)<br />

Rainer Schmier (Service Manager Europe)<br />

Günther Metelski (Alteon Trainer)<br />

Jan Ole Lorenz (Business Dev.)


<strong>Radware</strong> Alliance & OEM Ecosystem<br />

Advanced Enterprise Alliances & Technology Partnerships<br />

Advanced ADC Carrier Partnerships


Auszug aus der RDWR Kundenl<strong>ist</strong>e (Deutschland)<br />

Banken/Versicherungen Online-Medien Öffentlicher Bereich Industrie / Service<br />

Medien<br />

Gesundheitswesen/<br />

Pharma


Over 10,000 Customers Trust <strong>Radware</strong>


Business Business Processes, Processes, Applications, Applications, Users Users<br />

Business-Smart<br />

Network<br />

Packet Packet Network Network<br />

Business-Smart Networks<br />

Business-Smart Services:<br />

• Verfügbarkeit<br />

• Skalierbarkeit<br />

• Antwortzeitoptimierung<br />

• Beschleunigung d. Applikation<br />

• Applikations- & Netzwerksicherheit<br />

• Steuerung n. Geschäftsprozessen<br />

• Priorisierung von Daten nach<br />

Benutzer und Applikation<br />

• übersichtlich und einfach zu<br />

Managen


Partner<br />

WAN Customers Link Optimizer /<br />

LoadBalancer<br />

LinkProof Branch<br />

Mitarbeiter<br />

Router<br />

Router<br />

HTTP Monitor<br />

Inflight<br />

LinkProof<br />

Intrusion Prevention<br />

DefensePro<br />

Virtual Director<br />

VM Ware Support<br />

AppXML<br />

AppDirector<br />

ADC-VX<br />

AppWall<br />

Data Center<br />

Produktübersicht<br />

Web Services und XML<br />

Gateway<br />

Message Queuing<br />

System<br />

ESB<br />

LoadBalancer<br />

Application Delievery Controller<br />

Web & Portal<br />

Servers<br />

Web Application<br />

Firewall<br />

Application Servers<br />

Mainframe<br />

Database<br />

servers


Web<br />

Server<br />

Datenbank<br />

Datenbank<br />

z.B. OCS<br />

Server<br />

Loadbalancing – was sind die Herausforderungen?<br />

HTTP / HTTPS<br />

Health Check<br />

z.B. ICMP<br />

Health Check<br />

Datenbank<br />

Check<br />

AppDirector<br />

or<br />

or


Next Generation Backbone<br />

1. IPv4 – IPv6 Dual Stack Umgebung


Pure IPv6 Environment<br />

IPv6<br />

IPv6<br />

Client<br />

Service VIP<br />

S1 S2 S3 S4<br />

Supported Topologies


IPv4 Clients<br />

IPv4, IPv6 or mixed Servers IPv4<br />

IPv4<br />

Client<br />

Service VIP<br />

S1 S2 S3 S4<br />

IPv6<br />

Supported Topologies


IPv6 Clients<br />

IPv4, IPv6 or mixed Servers IPv6<br />

IPv4<br />

Client<br />

Service VIP<br />

S1 S2 S3 S4<br />

IPv6<br />

Supported Topologies


ADC-VX – Virtual ADC mit <strong>Radware</strong> Hypervisor !


Traditionelle RZ im Vergleich zur Zukunft<br />

“The ability to deploy capacity and server images virtually increases<br />

speed of deployment Static Data by Center a factor of approximately Virtual Data Center 30”<br />

Thomas Bittman, Gartner<br />

• Es werden selten<br />

Änderungen<br />

durchgeführt<br />

•<br />

take Eli Lilly seven wenig and a half weeks to deploy a server internally”<br />

Kommunikation<br />

Dave Powers, at Eli Lilly and Company<br />

zwischen den Teams<br />

• Änderungen werden<br />

manuell durchgeführt<br />

• dynamisch<br />

• häufige Updates<br />

“A new server can be up and running in three minutes - it used to<br />

• betrifft alle<br />

Bereiche:Netzwerk,<br />

Storage,<br />

Applikationen,<br />

Server<br />

Folie 16


Dedicated ADC<br />

ADC Computing Resources in the Virtualized Data<br />

Center<br />

• Dedicated physical ADC device running a single vADC<br />

- “Siloed” data center architecture<br />

Why are 3 form factors required?<br />

- Hybrid (virtualized and physical) data center<br />

• Application SLA requirements<br />

- Applications requiring high performance predictability<br />

• Number of required vADC instances<br />

• Throughput capacity each vADC requires<br />

<strong>Radware</strong> ADC-VX<br />

• Cost savings objectives<br />

• ADC hypervisor running multiple vADCs on a<br />

specialized ADC hardware<br />

• Data center footprint limitations<br />

• Application deployment model<br />

- ADC consolidation projects<br />

- Virtualized data center requiring high ADC agility<br />

- Applications requiring high performance predictability<br />

<strong>Radware</strong> Soft ADC<br />

• vADC on a general server virtualization infrastructure<br />

- Cloud providers & virtualized data center requiring high ADC agility<br />

- Development, testing and QA environments<br />

- Applications requiring only best-effort performance


Dynamic vADC<br />

resource allocation<br />

vADC migration<br />

by orchestration<br />

system<br />

Virtualized Application Delivery Infrastructure Unique Services<br />

Instant provisioning<br />

through orchestration<br />

system<br />

Virtualized Application Delivery Infrastructure<br />

Network & Storage<br />

Virtualized Data Center<br />

SAN<br />

Slide 18


<strong>Radware</strong>’s ADC-VX<br />

The Agility of Virtual; The Predictability of Physical


Infrastructure<br />

D<br />

C<br />

-<br />

vADC – A V Shared/public Applications<br />

Shared/public X<br />

Applications<br />

Customer Data Center<br />

vADC - B<br />

Executive only Applications<br />

Executive only Applications<br />

Internal application<br />

vADC – C<br />

Internal application<br />

vADC – D<br />

Business Unit Specific<br />

Business Unit Specific<br />

<strong>Radware</strong> ADC-VX<br />

• ADC-VX is the industry’s first ADC hypervisor<br />

• ADC-VX runs multiple virtual ADC instances on one physical device<br />

• Each virtual ADC instance is called vADC<br />

• vADCs provide the same functionality as traditional physical ADC devices


Global SLB, Security,<br />

Application<br />

acceleration<br />

Fully featured ADC<br />

Health Checks, Layer<br />

7 Configurations, etc.<br />

Vlans, ARP tables,<br />

Virtual routing and<br />

forwarding tables<br />

Physical Resources<br />

(CPU, Memory, SSL)<br />

Customer Managed<br />

On Demand<br />

Global SLB<br />

Services<br />

Layer SharePoint 4-7 Services<br />

IP Network Domain 1<br />

Private:<br />

config file<br />

Infrastructure 1Gbps<br />

logging<br />

stat<strong>ist</strong>ics<br />

Full Encapsulation of vADC Instance<br />

Customer “Monitor Only” Provider Managed<br />

On Demand<br />

Acceleration<br />

Services<br />

Layer Oracle 4-7 Services<br />

IP Network Domain 2<br />

Private:<br />

config file<br />

Infrastructure 2Gbps<br />

logging<br />

stat<strong>ist</strong>ics<br />

ADC-VX Hypervisor<br />

On Demand<br />

Security<br />

Services<br />

Marketing<br />

Layer 4-7 Services<br />

Applications<br />

IP Network Domain 3<br />

Private:<br />

config file<br />

Infrastructure 2Gbps<br />

logging<br />

stat<strong>ist</strong>ics


h<br />

The Agility y of Virtual; The Predictability of Physical<br />

R<br />

a<br />

d<br />

w<br />

a<br />

r<br />

e<br />

A<br />

D<br />

C<br />

-<br />

V<br />

X<br />

• Fault isolation<br />

• Network isolation<br />

• Management isolation<br />

• Resource reservation<br />

• SLA assurance<br />

• Instant provisioning<br />

• OnDemand scalability<br />

• Resource abstraction<br />

• Central management


Virtualized Application Delivery Infrastructure<br />

• Reduce ADC CAPEX and OPEX through real ADC consolidation and<br />

virtualization<br />

• Full DC virtualization agility across the application delivery layer<br />

• Accommodate any application: SLA, performance predictability and<br />

resilience needs<br />

• Reduce P2V risks and enable smooth migration<br />

• Enable integration of ADC services into the virtual DC through open API<br />

Slide 23


<strong>Radware</strong> All vADC VADI instances extends provide the virtual data<br />

center similar agility functionality through and a set are of virtual<br />

remotely infrastructure controlled services<br />

Orchestration system -<br />

Manages and operates all data center elements<br />

Virtualized Application Delivery Infrastructure<br />

Virtualized Application Delivery Infrastructure<br />

Network & Storage<br />

Virtualized Data Center<br />

SAN<br />

Slide 24


SSL Acceleration Demo


Microsoft SharePoint Server 2007<br />

• Better Quality of Experience (QoE) for end users<br />

The Result: Certified to Optimize Leading Applications<br />

• 300% improvement in page load time for remote (WAN) users<br />

• Reduce OPEX<br />

• 65% reduction in bandwidth consumption<br />

• 40% reduction in CPU utilization<br />

• 30% increase in TPS per server<br />

Oracle E-Business Suite (EBS) 12<br />

Slide 26


~40% drop in server<br />

CPU utilization<br />

More TPS can be served by<br />

each server resulting in reduced<br />

CAPEX & OPEX<br />

Demo Conclusions


Content Acceleration Demo using Cache & Compression


~355% improvement<br />

in page load time<br />

Users’ QoE significantly<br />

Improved and bandwidth<br />

consumption and costs<br />

reduced<br />

Demo Conclusions


Inflight – real-time Event Monitoring


Inflight - Implementierung


Client HTTP request<br />

GET /wps/portal/UserCentric HTTP/1.0<br />

Raw HTTP<br />

Analysis System<br />

Compliance<br />

Inflight Generated Audit Event:<br />

Page title: User-Centric Experience<br />

Client IP: 10.210.8.14<br />

Client UID: 1202138491566-0<br />

User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5...)<br />

Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, … Country: Germany<br />

Referer: http://www1.alcatel-lucent.com/us/industries...<br />

City: Bonn<br />

Accept-Language: en-us<br />

Server IP: 84.53.133.82<br />

User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; …) Inflight<br />

Response code: 200<br />

Cookie: JSESSIONID=00002HgoBbll62bR1xV2znWdY08:11c8tbtl5… URL: /wps/portal/!ut/p/kcxml/04_S…<br />

Host: www.alcatel-lucent.com<br />

Connection: keep-alive<br />

Raw HTTP


• Konfiguration Transformer Output<br />

4 Schritte zum Erfolg (2/4)<br />

Folie 33


Beispiel Feed


Beispiel Feed


• Enable Transfomer<br />

4 Schritte zum Erfolg (4/4)


Page Title<br />

SysLog Events generiert durch Inflight


einheitliche Benutzer ID<br />

(beschreibt eine Benutzer Session – auch für anonyme Benutzer)<br />

SysLog Events generiert durch Inflight


Priorität<br />

Datum & Zeit<br />

Host Name<br />

Message (kann angepasst werden)


Web Servers Farm 1<br />

Zentralisierung von Log-Informationen<br />

Web Servers Farm 2 Web Servers Farm 3<br />

ein Log-File enthält alle 4 Log-Informationen<br />

Web Servers Farm 4


Standard IIS 6.0 log<br />

erweiterte Informationen<br />

– die nicht in Web Logs verfügbar sind<br />

Date/Time Client IP Method URL Server IP User Agent Response Code<br />

2008-02-04 10:21:57 10.210.8.14 GET /wps/portal/!ut/p/kcxml/04_Sj…- 80 - 84.53.155.82 Mozilla/4.0+(compatible;+MSIE+7.0;+…) 200 0 0<br />

Business Critical Communications France Paris 1202115078561-0 Processing Success User Account Updated<br />

Event Type GEO IP User ID Success/Fail Affected Data<br />

Inflight kann zusätzliche Informationen hinzufügen, z.B. für PCI compliance


Inflight Event-Informationen:<br />

• Datum / Zeit<br />

• Client IP<br />

• HTTP Methode<br />

• URL<br />

• Server IP<br />

• User Agent<br />

• Response Code<br />

• Event Type<br />

• Geo Location<br />

• User ID<br />

• Success / Failure<br />

• Auswahl spezifischer Daten<br />

Event Informationen in Real-Time<br />

• Verknüpfung von Datenmenge und Kosten (in USD)<br />

• wiederkehrende Events in den vergangenen 30 Minuten


Standard Logging für alle Web Plattformen<br />

standardisiertes Log Format


• passive Appliance, einfach zu integrieren<br />

• keine Veränderung der Web Applikation notwendig<br />

• Logging wird als Dienst geliefert<br />

• keine Auswirklungen auf die Produktionsumgebung<br />

• kein Einfluß auf den Benutzer / Kunde<br />

• Verbesserung der Performance für die Web Server,<br />

kein eigenes Sever Logging mehr notwendig<br />

• Non-Human Aktionen werden in Real-Time erkannt (scraping)<br />

• betrügerische Aktionen können analysiert werden<br />

und für eine Profilerstellung genutzt werden<br />

Inflight Vorteile


Partners<br />

Customers<br />

Employees<br />

Enables creating enhanced audit logs from a central<br />

location tracking each individual user activities (Req.<br />

10.1-5)<br />

Inflight<br />

DefensePro<br />

Firewall<br />

Provides the most up-to-date<br />

protection from known vulnerabilities<br />

as well as zero-day attacks and<br />

enforces security policies and<br />

accurate access control (Req. 11.4,<br />

7)<br />

Constitutes a best of breed ADC<br />

solution for addressing PCI DSS<br />

requirement 6.x<br />

AppXML<br />

AppDirector<br />

AppWall<br />

Data Center<br />

Lösungsübersicht<br />

Enforces security policies and accurate<br />

access control for web services (Req.7)<br />

Message Queuing<br />

System<br />

ESB<br />

Encrypts cardholder data and enforcing<br />

security policies and access control<br />

(Req. 4, 7)<br />

Web & Portal<br />

Servers<br />

Application Servers<br />

Mainframe<br />

Database<br />

servers


Vielen Dank !

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!