ua hybrid cloud - internet2

41
UA HYBRID CLOUD OPTIMIZING MULTI-CLOUD CONNECTIVITY SECURE/FLEXIBLE INTEGRATIONS FOR CAMPUS

Upload: others

Post on 28-Dec-2021

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: UA HYBRID CLOUD - Internet2

UA HYBRID CLOUDOPTIMIZING MULTI-CLOUD CONNECTIVITY

SECURE/FLEXIBLE INTEGRATIONS FOR CAMPUS

Page 2: UA HYBRID CLOUD - Internet2

INTRO

Jason SullivanNetwork Security Architect @ UITS

CCIE #60763

CCDPCCNP x2AWS Network SpecialistAWS Associate Architect

Page 3: UA HYBRID CLOUD - Internet2

AGENDA

o Define basic network constructs of IaaS (AWS/Azure)

o IaaS Networking basics

o UA's Simple beginnings

o Policy/Route/Transito East/West performance considerations

o Multi-Cloud integration

o TGW

o Converged Cloudo DC integration/remote sites

Page 4: UA HYBRID CLOUD - Internet2

AWS/AZURE NETWORK STACK

¡ AWS Network

VPC (Virtual Private Cloud)

Subnets

Route-Table

CGW (Customer Gateway)

VGW (Virtual Gateway)

Route Propagation

TGW (Transit Gateway)

VPC-Peering

Direct-Connect

¡ Azure Network

Resource Group

VNet (Virtual Networks)

Subnets (Gateway Subnet)

VNetGW (Virtual Network Gateway)

LNG (Local Network Gateway)

Connection

Public IP address

Route Table (optional)

Express-Route

Page 5: UA HYBRID CLOUD - Internet2

SUBNETS/ROUTING

ROUTE-TABLES AS SECURITY BOUNDARY;

IGW (PUBLIC)ENI (PUBLIC)

NAT-GW (PRIVATE)NAT-GW/TGW (PRIVATE)

nat-id

tgw-id

Page 6: UA HYBRID CLOUD - Internet2

Policy-Based VPN• Unidirectional Security Associations

Page 7: UA HYBRID CLOUD - Internet2

Route-Based

Page 8: UA HYBRID CLOUD - Internet2

DC-A DC-BLo:200.2.2.2/32 (WAN)Lo0:100.1.1.1/32 (WAN)

WAN 1.1.1.1BGP Peer: 1

WAN 2.2.2.2BGP Peer: 2

WAN 1.1.1.1BGP Peer: 3

WAN 2.2.2.2BGP Peer: 4

Campus Networks

Tunnel xxaddr x.x.1.1/30Src Lo0Dst 1.1.1.1

Tunnel yyaddr x.x.1.5/30

Src Lo0Dst 2.2.2.2

Lo0:200.2.2.2/32 (WAN)

Tunnel xxaddr x.x.2.1/30Src Lo0Dst 1.1.1.1

Tunnel yyaddr x.x.2.5/30

Src Lo0Dst 2.2.2.2

Page 9: UA HYBRID CLOUD - Internet2

CGW (ROUTED) VGW SITE-TO-SITE

Page 10: UA HYBRID CLOUD - Internet2

S2S VPN TUNNEL DETAILS

Page 11: UA HYBRID CLOUD - Internet2

ROUTE PROPAGATION

¡ Dynamic/Static Route Installation

¡ VPC routing selection/rules

Page 12: UA HYBRID CLOUD - Internet2

WHAT IS A TGW

Transit Gateway

-Routing Table (multiple routing tables)-Logical Attachments (receive/inject routes)-RAM (resource access manager)-ACT/ACT (ECMP) BGP paths-Deprecates need for Transit VPC

Page 13: UA HYBRID CLOUD - Internet2

AZURE NETWORKING (CONNECTIVITY) COMPONENTS

Page 14: UA HYBRID CLOUD - Internet2

AZURE RESOURCE MANAGERhttps://resources.azure.com/

Page 15: UA HYBRID CLOUD - Internet2

INITIAL INTEGRATION (POLICY VPN)

• S2S configuration (Vendor specific)

• Inflexible after instantiation

• Fault Tolerance considerations

• Almost everyone starts here

Page 16: UA HYBRID CLOUD - Internet2

SECURITY APPLIANCE BENEFITS/LIMITATION

¡ Security appliance benefits;

¡ Crypto performance

¡ General placement/availability

¡ Easy of deployment

¡ Policy enforcement

¡ Security appliance limitations;

¡ Virtual Tunnels (required for routing)

¡ VRF (virtual routing forwarding)

¡ MPLS

¡ Cost

vs.

Page 17: UA HYBRID CLOUD - Internet2

ROUTE BASED VPN (2ND ATTEMPT)

BGP Peers 1-2

BGP Peers 3-4

Page 18: UA HYBRID CLOUD - Internet2

HEADEND PEERING –HUB/SPOKE DESIGN

Page 19: UA HYBRID CLOUD - Internet2

EAST/WEST VPC COMMUNICATION

UA

On-Prem A

On-Prem B

UA

On-Prem A

On-Prem B

Page 20: UA HYBRID CLOUD - Internet2

TRANSIT VPC

Azure

Page 21: UA HYBRID CLOUD - Internet2
Page 22: UA HYBRID CLOUD - Internet2

DIRECT HEADEND PEERING INTO AN ISOLATED ROUTING CONTEXT• Minimal East/West connectivity

• Segmentation (MPLS/VPNV4 enabled campus)

• Multiple VGWs are not cost effective

Clear Text

MPLS CAMPUS FABRIC

UA College A

UA College B

UA College C

DEPT/MPLS FW

Page 23: UA HYBRID CLOUD - Internet2

TGW ANNOUNCEMENTInitial Release @ Re:Invent 2018 (Nov)

Page 24: UA HYBRID CLOUD - Internet2

TGW (CURRENT/LATEST ITERATION OF HYBRID CLOUD)

UA

Page 25: UA HYBRID CLOUD - Internet2

TGW THROUGHPUT SCALING

(6) 1.25Gb = 7.5Gb/sec

Page 26: UA HYBRID CLOUD - Internet2

TGW PERFORMANCE (EAST/WEST INTRA-VPC)

TGWRTR-PRIV RTR-PRIVC5N-4XL C5N-4XL

50Gb/sec 50Gb/sec

VPC-Peering TGW

Page 27: UA HYBRID CLOUD - Internet2

PERFORMANCE VIA TGW ~25GB/SEC

Page 28: UA HYBRID CLOUD - Internet2

Azure (originator)

CSR (transit)

AWS TWG (last-as)CMD executed via AS65202 AS65515

AS65212

AS64514

AS65202

Page 29: UA HYBRID CLOUD - Internet2

TGW MULTI-CLOUD CSR (PEERS/NAT)

Page 30: UA HYBRID CLOUD - Internet2
Page 31: UA HYBRID CLOUD - Internet2

TRANSIT VPC/CSR SECURITY ANALYTICS

BRO/ZEEK/SNORT

Page 32: UA HYBRID CLOUD - Internet2

MIRROR DELIVERED VIA ENCAP

Page 33: UA HYBRID CLOUD - Internet2

SEC TOOL OVERHEAD ~300PPS

8Core system

BRO/ZEEK/SNORT

Page 34: UA HYBRID CLOUD - Internet2

SECURITY ANALYTICS VIA BRO

Page 35: UA HYBRID CLOUD - Internet2

SECURITY ANALYTICS VIA SNORT

Page 36: UA HYBRID CLOUD - Internet2

REMOTE SITE CENTRAL CLOUD FIREWALL

Spoke Site(s)

Campus

IaaS (AWS/AZR)

IPsec/MPLS

Campus Routes (I

Psec/MPLS)

0.0.0.0/0

NGFW/Policy

Page 37: UA HYBRID CLOUD - Internet2

(SPOKE) DECOUPLED DFT GATEWAY

Crypto VTI used for VXLAN underlay /30

gateway –same subnet

Page 38: UA HYBRID CLOUD - Internet2

CISCO ACI ANYWHERE (MSO)

Common policy between on-prem and cloud

Page 39: UA HYBRID CLOUD - Internet2

ACCELERATED SITE-TO-SITE VPN (VIA TGW ATTACHED)

ISP-AISP-B

Local-ISP

Local-ISP

AWS Global Net

OnPrem

Closest edge location

ISP-C

TGW ONLY

Page 40: UA HYBRID CLOUD - Internet2

VPC INGRESS ROUTING