SlideShare a Scribd company logo
April, 2014
F5 Synthesis
Information Session
Agenda
• Welcome and Introduction to Customer Technology Challenges
• Software Defined Application Services
• Reference Architectures for Today’s Customer Challenges
• Total Cost of Ownership and New Business Models
• Multi-network Environment and Partner Ecosystem
• Making it Happen with Global Services
• Q & A
© F5 Networks, Inc 3
Mobility
SDDC/Cloud
Advanced
threats
Internet of
Things
“Software defined”
everything
HTTP is the
new TCP
© F5 Networks, Inc 4
Impact on Data Center Architecture: Applications
MICRO-ARCHITECTURES
Each service is isolated and requires its own:
• Load balancing
• Authentication / authorization
• Security
• Layer 7 Services
• May be API-based, expanding services required
API DOMINANCE
Proxies are used in emerging API-centric
architectures for:
• API versioning
• Client-based steering
• API Load balancing
• Metering & billing
• API key management
Service A
Service C
Service B Service D
API v1
API v2
More intelligence needed in servicesMore applications need services
© F5 Networks, Inc 5
Impact on Data Center Architecture: Network
SOLUTION SPRAWL
Increasing threats and client platforms result in
need for:
• Mobile device management
• Mobile access management
• Mobile security
• DDoS
• Application layer threats
• Malware
OPERATIONAL INCONSISTENCY
Introduction of off-premise cloud solutions without
architectural parity results in:
• Inconsistent enforcement of business and
operational policies
• Unpredictable application performance and
security
• Increased OpEx as new management paradigms
are introduced
SaaS
“Leave No Application Behind”
© F5 Networks, Inc 7
DDoS WAF SSL LTE
1000
Average number of
applications deployed
within an enterprise
Applications
require services
Acceleration
© F5 Networks, Inc 8
The selected few
© F5 Networks, Inc 9
ADC ADC ADC ADC ADC ADC
© F5 Networks, Inc 10
High-Performance
Fabric Application
Services
BIG-IP BIG-IP BIG-IP BIG-IP BIG-IP BIG-IP
© F5 Networks, Inc 11© F5 Networks, Inc. 11
© F5 Networks, Inc 12
Software Defined Application Services4
The 4th Phase of the Evolution
Application Delivery Controller1
Broadened Application Services2
Cloud Ready3
© F5 Networks, Inc. 12
© F5 Networks, Inc 13
Software Defined Application Services Elements
High-Performance
Services Fabric
Simplified
Business Models
© F5 Networks, Inc 14
Software Defined Application Services Elements
High-Performance
Services Fabric
High-Performance Services Fabric
Network [Physical • Overlay • SDN]
Virtual Edition ChassisAppliance
High-Performance Services Fabric
On-Demand Scaling All-Active Clustering Multi-Tenancy
ScaleN
TMOS TMOS TMOS TMOS
Network [Physical • Overlay • SDN]
High-Performance Services Fabric
Throughput Connections
per second
Concurrent
connections
Multi-tenant
instances per device
Device service
clusters
Network [Physical • Overlay • SDN]*40K when combining
admin instances with vCMP
High-Performance Services Fabric
Network [Physical • Overlay • SDN]
Virtual Edition ChassisAppliance
Data Plane
Programmability
Control Plane Management Plane
High-Performance Services Fabric
Network [Physical • Overlay • SDN]
Virtual Edition ChassisAppliance
Data Plane
Programmability
Control Plane Management Plane
Software Defined Application Services
© F5 Networks, Inc 21
Software Defined Application Services
F5 Software Defined
Application Services (SDAS)
A rich set of services that address
the delivery challenges faced by
businesses today.
© F5 Networks, Inc 22
Software Defined Application Services
Availability
Authoritative DNS
Cloud Bursting
CGNAT
Disaster Recovery
Business
Continuity
Global Load Balancing
Intelligent EPC node selection
Global Server LB
Global
Server LB
DNS Caching
& Resolving
Load
Balancing
© F5 Networks, Inc 23
Software Defined Application Services
PerformanceAccelerationCaching
Optimization
SPDY Gateway
Application Optimization
Traffic Shaping and QoS
Compression
Web Performance Optimization
Traffic
Management
© F5 Networks, Inc 24
Software Defined Application Services
Access &
Identity
Cloud Federation
Endpoint Inspection
Single Sign-OnAccess Control
SAML Federation
SSL VPNAnti-Malware
Web Access Management
Active Sync Proxy
Secure Web Gateway
.
© F5 Networks, Inc 25
Software Defined Application Services
Security
DNSSEC
ADF
Anti-Fraud
WAF
DDoS
SSL VPN
Anti-Phishing
DNS Security
SSL intelligence
SSL Inspection
Programmability
© F5 Networks, Inc 26
Software Defined Application Services Elements
Fabric Connectors
Module Connectors
Cloud Connectors
Orchestration
Connectors
Intelligent Services Orchestration
BIG-IQ
•Rest API
Completing the SDN Stack
F5 BIG-IQ
OPEN
REST APIs
LAYER 2-3 LAYER 4-7
SDN Controller
BIG-IQ
Security™
BIG-IQ
Cloud™
BIG-IQ
Device™
NBI NBI
NVGRE VXLAN ETC…
Control Plane
Application Plane
Data Plane
Software-DefinedDataCenter
Virtual Networks
Service Chaining
Public CloudHybrid Cloud
BIG-IP
BIG-IP
Data Center
Centralized Management Platform
BIG - IQBIG - IQ
Application Services Modules
Software Defined Application Services Elements
Simplified
Business Models
Good | Better | Best
Flexibility
Make it easier to adopt
advanced F5
functionality
Simplicity
Consolidate into fewer
common configurations
BestValue
Save when purchasing
bundles
Good Better Best
VE Price
Comparison
Bought As Bundle Bought As Components
Good Better Best
Appliance
Comparison
BIG-IP Local Traffic Manager   
BIG-IP Global Traffic Manager  
Application Acceleration Manager  
BIG-IP Application Protection  
SDN Service  
Advanced Routing  
BIG-IP Access Policy Manager 
BIG-IP Application Security Manager 
Reference
Architectures
For Today’s Customer Challenges
© F5 Networks, Inc 34
Reference Architectures
Device, Network, Applications
Bill of Materials • White Paper (Business)
• Solution diagram(s)
• Architecture diagram(s)
• Product map diagram(s)
• Customer Presentation
• Solution Animation/Video
• White paper (Technical)
• Placemat leave-behind
© F5 Networks, Inc.
DDoS
Protection
S/Gi Network
Simplification
Security for
Service Providers
Application
Services
Migration to
Cloud DevOps
LTE
Roaming
Intelligent
DNS Scale
Cloud
Federation
Cloud
Bursting
© F5 Networks, Inc 35
Reference Architectures
Solution Documents…
© F5 Networks, Inc 36
DDoS Protection Reference Architecture
Legitimate
Users
Threat Feed Intelligence
DDoS
Attacker
ISPa/b
Cloud
Scrubbing
Service
Scanner Anonymous
Proxies
Anonymous
Requests
Botnet Attackers
Network attacks:
ICMP flood,
UDP flood,
SYN flood
DNS attacks:
DNS amplification,
query flood,
dictionary attack,
DNS poisoning
IPS
Next-Generation
Firewall
Tier 2
SSL attacks:
SSL renegotiation,
SSL flood
HTTP attacks:
Slowloris,
slow POST,
recursive POST/GET
Application
Corporate Users
Financial
Services
E-Commerce
Subscriber
Tier 2
Threat Feed Intelligence
Strategic Point of Control
Multiple ISP
strategy
Network
and DNS
Tier 1
© F5 Networks, Inc 37
DDoS Protection Reference Architecture
Legitimate
Users
Threat Feed Intelligence
DDoS
Attacker
ISPa/b
Cloud
Scrubbing
Service
Scanner Anonymous
Proxies
Anonymous
Requests
Botnet Attackers
Network attacks:
ICMP flood,
UDP flood,
SYN flood
DNS attacks:
DNS amplification,
query flood,
dictionary attack,
DNS poisoning
IPS
Next-Generation
Firewall
Tier 2
SSL attacks:
SSL renegotiation,
SSL flood
HTTP attacks:
Slowloris,
slow POST,
recursive POST/GET
Application
Corporate Users
Financial
Services
E-Commerce
Subscriber
Tier 2
Threat Feed Intelligence
Strategic Point of Control
Multiple ISP
strategy
Network
and DNS
Tier 1
• The first tier at the
perimeter is layer 3
and 4 network firewall
services
• Simple load balancing
to a second tier
• IP reputation database
• Mitigates volumetric and
DNS DDoS attacks
TIER 1 KEY FEATURES
© F5 Networks, Inc 38
DDoS Protection Reference Architecture
Legitimate
Users
Threat Feed Intelligence
DDoS
Attacker
ISPa/b
Cloud
Scrubbing
Service
Scanner Anonymous
Proxies
Anonymous
Requests
Botnet Attackers
Network attacks:
ICMP flood,
UDP flood,
SYN flood
DNS attacks:
DNS amplification,
query flood,
dictionary attack,
DNS poisoning
IPS
Next-Generation
Firewall
Tier 2
SSL attacks:
SSL renegotiation,
SSL flood
HTTP attacks:
Slowloris,
slow POST,
recursive POST/GET
Application
Corporate Users
Financial
Services
E-Commerce
Subscriber
Tier 2
Threat Feed Intelligence
Strategic Point of Control
Multiple ISP
strategy
Network
and DNS
Tier 1
• The second tier is for
application-aware,
CPU-intensive defense
mechanisms
• SSL termination
• Web application firewall
• Mitigate asymmetric and
SSL-based DDoS attacks
TIER 2 KEY FEATURES
© F5 Networks, Inc 39
Recommended Practices Configuration Guide
2.3.2.5 Throttle GET Request Floods via Script
The F5 DevCentral community has developed several powerful iRules that automatically throttle
GET requests. Customers are continually refining these to keep up with current attack
techniques.
Here is one of the iRules that is simple enough to be represented in this document. The live
version can be found at this DevCentral page: HTTP-Request-Throttle
when RULE_INIT {
# Life timer of the subtable object. Defines how long this object exist in the subtable
set static::maxRate 10
# This defines how long is the sliding window to count the requests.
# This example allows 10 requests in 3 seconds
set static::windowSecs 3
set static::timeout 30
}
when HTTP_REQUEST {
if { [HTTP::method] eq "GET" } {
set getCount [table key -count -subtable [IP::client_addr]]
if { $getCount < $static::maxRate } {
incr getCount 1
table set -subtable [IP::client_addr] $getCount "ignore" $static::timeout $static::windowSecs
} else {
HTTP::respond 501 content "Request blockedExceeded requests/sec limit."
return
}
}
}
Another iRule, which is in fact descended from the above, is an advanced version that also
includes a way to manage the banned IPs address from within the iRule itself:
· URI-Request Limiter iRule – Drops excessive HTTP requests to specific URIs or from an IP
2.3.2.4 Enforce Real Browsers
Besides authentication and tps-based detection (section Error! Reference source not found.),
there are additional ways that F5 devices can separate real web browsers from probable bots.
The easiest way, with ASM, is to create a DoS protection profile and turn on the “Source IP-
Based Client Side Integrity Defense” option. This will inject a JavaScript redirect into the client
stream and verify each connection the first time that source IP address is seen.
Figure 1. Insert a Javascript Redirect to verify a real browser
32 Page Detailed Guide…
Cisco Partnership
© F5 Networks, Inc 41
Completing the SDN Stack
F5 BIG-IQ
OPEN
REST APIs
LAYER 2-3 LAYER 4-7
SDN Controller
BIG-IQ
Security™
BIG-IQ
Cloud™
BIG-IQ
Device™
NBI NBI
NVGRE VXLAN ETC…
Control Plane
Application Plane
Data Plane
Software-DefinedDataCenter
Virtual Networks
Service Chaining
© F5 Networks, Inc 42
F5 Platforms
Hardware | Software | Cloud
Programmability
F5 SDAS Service
Fabric
Programmability
BIG IQ Cloud
Provisioning and orchestration
of BIG-IP in AWS
Two-way communication
Configure application networking services
Automated network and service provisioning
Auto-scaling, application
provisioning, and
automated system
maintenance and
patching.
Automate network and
service provisioning,
Integrate network
virtualization and
ADN services
Partner Integration with Synthesis
Cisco ACI Design Philosophy
Why Cisco/ACI matters for Customers
• Cisco and F5 share a common vision for simplifying networking end to
end by taking an application-centric approach to solving key pain points
in customer’s next generation data centers while meeting their critical
data center requirements today.
• Working with Cisco on Application Centric Infrastructure, F5 has a
unique opportunity to deliver on vision of shaping infrastructure to the
needs of the applications.
• Cisco ACI integrates F5 Big-IP appliances (physical and virtual) to deliver
application-centric, ADC-enabled network automation in existing and
next generation data centers
© F5 Networks, Inc.
Benefits
Drive Increase Reduce Future
45
SDDC/Cloud
Thinking about SDN and whether it is the right approach for your organization?

More Related Content

PPTX
BIG-IP ADCs and ADF
PPTX
Top 10 Reasons Why F5 Makes Sense
PPTX
Get more versatile and scalable protection with F5 BIG-IP
PDF
The F5 Networks Application Services Reference Architecture (White Paper)
PPTX
F5 Value For Virtualization
PDF
Plnog 3: Zbigniew Skurczyński - Wirtualizacja i optymalizacja infrastruktury
PDF
Using Docker container technology with F5 Networks products and services
PPTX
Intelligent DNS Scale
BIG-IP ADCs and ADF
Top 10 Reasons Why F5 Makes Sense
Get more versatile and scalable protection with F5 BIG-IP
The F5 Networks Application Services Reference Architecture (White Paper)
F5 Value For Virtualization
Plnog 3: Zbigniew Skurczyński - Wirtualizacja i optymalizacja infrastruktury
Using Docker container technology with F5 Networks products and services
Intelligent DNS Scale

What's hot (19)

PPTX
Cisco ACI & F5 Integrate to Transform the Data Center
PPTX
F5’s VMware Horizon View Reference Architecture
PPTX
F5’s VMware Horizon View Reference Architecture
PPTX
F5 Networks Intelligent DNS Scale
PPTX
F5 Application Delivery Optimization
PDF
F5 beyond load balancer (nov 2009)
PDF
管理向云的迁移过程
PDF
F5 Synthesis Toronto February 2014 Roadshow
PDF
Automate and customise application services and deployment
PPTX
The DNS of Things
PPTX
F5 Networks: Introduction to Silverline WAF (web application firewall)
PDF
Bluemix Cloud Platform - dominopoint
PPTX
IBM DataPower Gateways - What's new in 2016 v7.5.2
PDF
11 19 stephan pfister_citrix day - xen_app 6.5 whats new
PPTX
Services @ vfm
PDF
VMworld 2013: VMware Compliance Reference Architecture Framework Overview
PDF
F5 Scale n and BIG-IP v11 3 for Scalar Partner Event June 4 2013 Toronto
PPTX
F5’s VMware Horizon View Reference Architecture
PPTX
F5 iHealth Presentation 10 22-10
Cisco ACI & F5 Integrate to Transform the Data Center
F5’s VMware Horizon View Reference Architecture
F5’s VMware Horizon View Reference Architecture
F5 Networks Intelligent DNS Scale
F5 Application Delivery Optimization
F5 beyond load balancer (nov 2009)
管理向云的迁移过程
F5 Synthesis Toronto February 2014 Roadshow
Automate and customise application services and deployment
The DNS of Things
F5 Networks: Introduction to Silverline WAF (web application firewall)
Bluemix Cloud Platform - dominopoint
IBM DataPower Gateways - What's new in 2016 v7.5.2
11 19 stephan pfister_citrix day - xen_app 6.5 whats new
Services @ vfm
VMworld 2013: VMware Compliance Reference Architecture Framework Overview
F5 Scale n and BIG-IP v11 3 for Scalar Partner Event June 4 2013 Toronto
F5’s VMware Horizon View Reference Architecture
F5 iHealth Presentation 10 22-10
Ad

Similar to Thinking about SDN and whether it is the right approach for your organization? (20)

PPSX
Virtualization / Cloud / SDN
PPTX
F5 Networks - парадная дверь в облака
PDF
Presentation network design and security for your v mware view deployment w...
PDF
App to Cloud: Patrick Kerpan's DataCenter Dynamics Converged Keynote
PPTX
F5 9.x to 10.x Upgrade Customer Presentation
PPSX
VMware: my jsme “software defined”
PPTX
F5 Distributed Cloud.pptx
PPTX
F5 and HashiCorp Multi-Cloud
PDF
VMworld 2013: Moving Beyond Infrastructure: Meeting Demands on App Lifecycle ...
PPTX
Customer Highleveloverview
PPTX
Citrix Synergy 2014 - Syn231 Why cloud projects fail
PPT
IBM Softlayer Bluemix Marketplace
PDF
WEB SERVERS
PPTX
Spider & F5 Round Table - The Flexible Data Center
PDF
F5 Networks: architecture and risk management
PPTX
IT Automation With CFEngine - Business Value and Basic Concepts
PPTX
Brocade Software Networking Presentation at Interface 2016
PDF
VMworld 2014: Virtualization 101
PPTX
VMworld 2015: No App is An Island
PDF
Cloud Tools for Connected Communities
Virtualization / Cloud / SDN
F5 Networks - парадная дверь в облака
Presentation network design and security for your v mware view deployment w...
App to Cloud: Patrick Kerpan's DataCenter Dynamics Converged Keynote
F5 9.x to 10.x Upgrade Customer Presentation
VMware: my jsme “software defined”
F5 Distributed Cloud.pptx
F5 and HashiCorp Multi-Cloud
VMworld 2013: Moving Beyond Infrastructure: Meeting Demands on App Lifecycle ...
Customer Highleveloverview
Citrix Synergy 2014 - Syn231 Why cloud projects fail
IBM Softlayer Bluemix Marketplace
WEB SERVERS
Spider & F5 Round Table - The Flexible Data Center
F5 Networks: architecture and risk management
IT Automation With CFEngine - Business Value and Basic Concepts
Brocade Software Networking Presentation at Interface 2016
VMworld 2014: Virtualization 101
VMworld 2015: No App is An Island
Cloud Tools for Connected Communities
Ad

More from Cisco Canada (20)

PDF
Cisco connect montreal 2018 net devops
PDF
Cisco connect montreal 2018 iot demo kinetic fr
PPTX
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
PDF
Cisco connect montreal 2018 secure dc
PDF
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
PDF
Cisco connect montreal 2018 vision mondiale analyse locale
PDF
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
PDF
Cisco connect montreal 2018 collaboration les services webex hybrides
PDF
Integration cisco et microsoft connect montreal 2018
PDF
Cisco connect montreal 2018 compute v final
PDF
Cisco connect montreal 2018 saalvare md-program-xr-v2
PDF
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
PDF
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
PDF
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
PDF
Cisco Connect Toronto 2018 DevNet Overview
PDF
Cisco Connect Toronto 2018 DNA assurance
PDF
Cisco Connect Toronto 2018 network-slicing
PDF
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
PDF
Cisco Connect Toronto 2018 sixty to zero
Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco connect montreal 2018 collaboration les services webex hybrides
Integration cisco et microsoft connect montreal 2018
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018 sixty to zero

Recently uploaded (20)

PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
A Presentation on Artificial Intelligence
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Encapsulation theory and applications.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
Cloud computing and distributed systems.
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Modernizing your data center with Dell and AMD
Building Integrated photovoltaic BIPV_UPV.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Unlocking AI with Model Context Protocol (MCP)
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
A Presentation on Artificial Intelligence
The Rise and Fall of 3GPP – Time for a Sabbatical?
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Digital-Transformation-Roadmap-for-Companies.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Encapsulation_ Review paper, used for researhc scholars
20250228 LYD VKU AI Blended-Learning.pptx
Encapsulation theory and applications.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Cloud computing and distributed systems.
Network Security Unit 5.pdf for BCA BBA.
Agricultural_Statistics_at_a_Glance_2022_0.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Modernizing your data center with Dell and AMD

Thinking about SDN and whether it is the right approach for your organization?

  • 2. Agenda • Welcome and Introduction to Customer Technology Challenges • Software Defined Application Services • Reference Architectures for Today’s Customer Challenges • Total Cost of Ownership and New Business Models • Multi-network Environment and Partner Ecosystem • Making it Happen with Global Services • Q & A
  • 3. © F5 Networks, Inc 3 Mobility SDDC/Cloud Advanced threats Internet of Things “Software defined” everything HTTP is the new TCP
  • 4. © F5 Networks, Inc 4 Impact on Data Center Architecture: Applications MICRO-ARCHITECTURES Each service is isolated and requires its own: • Load balancing • Authentication / authorization • Security • Layer 7 Services • May be API-based, expanding services required API DOMINANCE Proxies are used in emerging API-centric architectures for: • API versioning • Client-based steering • API Load balancing • Metering & billing • API key management Service A Service C Service B Service D API v1 API v2 More intelligence needed in servicesMore applications need services
  • 5. © F5 Networks, Inc 5 Impact on Data Center Architecture: Network SOLUTION SPRAWL Increasing threats and client platforms result in need for: • Mobile device management • Mobile access management • Mobile security • DDoS • Application layer threats • Malware OPERATIONAL INCONSISTENCY Introduction of off-premise cloud solutions without architectural parity results in: • Inconsistent enforcement of business and operational policies • Unpredictable application performance and security • Increased OpEx as new management paradigms are introduced SaaS
  • 7. © F5 Networks, Inc 7 DDoS WAF SSL LTE 1000 Average number of applications deployed within an enterprise Applications require services Acceleration
  • 8. © F5 Networks, Inc 8 The selected few
  • 9. © F5 Networks, Inc 9 ADC ADC ADC ADC ADC ADC
  • 10. © F5 Networks, Inc 10 High-Performance Fabric Application Services BIG-IP BIG-IP BIG-IP BIG-IP BIG-IP BIG-IP
  • 11. © F5 Networks, Inc 11© F5 Networks, Inc. 11
  • 12. © F5 Networks, Inc 12 Software Defined Application Services4 The 4th Phase of the Evolution Application Delivery Controller1 Broadened Application Services2 Cloud Ready3 © F5 Networks, Inc. 12
  • 13. © F5 Networks, Inc 13 Software Defined Application Services Elements High-Performance Services Fabric Simplified Business Models
  • 14. © F5 Networks, Inc 14 Software Defined Application Services Elements High-Performance Services Fabric
  • 15. High-Performance Services Fabric Network [Physical • Overlay • SDN] Virtual Edition ChassisAppliance
  • 16. High-Performance Services Fabric On-Demand Scaling All-Active Clustering Multi-Tenancy ScaleN TMOS TMOS TMOS TMOS Network [Physical • Overlay • SDN]
  • 17. High-Performance Services Fabric Throughput Connections per second Concurrent connections Multi-tenant instances per device Device service clusters Network [Physical • Overlay • SDN]*40K when combining admin instances with vCMP
  • 18. High-Performance Services Fabric Network [Physical • Overlay • SDN] Virtual Edition ChassisAppliance Data Plane Programmability Control Plane Management Plane
  • 19. High-Performance Services Fabric Network [Physical • Overlay • SDN] Virtual Edition ChassisAppliance Data Plane Programmability Control Plane Management Plane
  • 21. © F5 Networks, Inc 21 Software Defined Application Services F5 Software Defined Application Services (SDAS) A rich set of services that address the delivery challenges faced by businesses today.
  • 22. © F5 Networks, Inc 22 Software Defined Application Services Availability Authoritative DNS Cloud Bursting CGNAT Disaster Recovery Business Continuity Global Load Balancing Intelligent EPC node selection Global Server LB Global Server LB DNS Caching & Resolving Load Balancing
  • 23. © F5 Networks, Inc 23 Software Defined Application Services PerformanceAccelerationCaching Optimization SPDY Gateway Application Optimization Traffic Shaping and QoS Compression Web Performance Optimization Traffic Management
  • 24. © F5 Networks, Inc 24 Software Defined Application Services Access & Identity Cloud Federation Endpoint Inspection Single Sign-OnAccess Control SAML Federation SSL VPNAnti-Malware Web Access Management Active Sync Proxy Secure Web Gateway .
  • 25. © F5 Networks, Inc 25 Software Defined Application Services Security DNSSEC ADF Anti-Fraud WAF DDoS SSL VPN Anti-Phishing DNS Security SSL intelligence SSL Inspection Programmability
  • 26. © F5 Networks, Inc 26 Software Defined Application Services Elements
  • 27. Fabric Connectors Module Connectors Cloud Connectors Orchestration Connectors Intelligent Services Orchestration BIG-IQ •Rest API
  • 28. Completing the SDN Stack F5 BIG-IQ OPEN REST APIs LAYER 2-3 LAYER 4-7 SDN Controller BIG-IQ Security™ BIG-IQ Cloud™ BIG-IQ Device™ NBI NBI NVGRE VXLAN ETC… Control Plane Application Plane Data Plane Software-DefinedDataCenter Virtual Networks Service Chaining
  • 29. Public CloudHybrid Cloud BIG-IP BIG-IP Data Center Centralized Management Platform BIG - IQBIG - IQ
  • 31. Software Defined Application Services Elements Simplified Business Models
  • 32. Good | Better | Best Flexibility Make it easier to adopt advanced F5 functionality Simplicity Consolidate into fewer common configurations BestValue Save when purchasing bundles Good Better Best VE Price Comparison Bought As Bundle Bought As Components Good Better Best Appliance Comparison BIG-IP Local Traffic Manager    BIG-IP Global Traffic Manager   Application Acceleration Manager   BIG-IP Application Protection   SDN Service   Advanced Routing   BIG-IP Access Policy Manager  BIG-IP Application Security Manager 
  • 34. © F5 Networks, Inc 34 Reference Architectures Device, Network, Applications Bill of Materials • White Paper (Business) • Solution diagram(s) • Architecture diagram(s) • Product map diagram(s) • Customer Presentation • Solution Animation/Video • White paper (Technical) • Placemat leave-behind © F5 Networks, Inc. DDoS Protection S/Gi Network Simplification Security for Service Providers Application Services Migration to Cloud DevOps LTE Roaming Intelligent DNS Scale Cloud Federation Cloud Bursting
  • 35. © F5 Networks, Inc 35 Reference Architectures Solution Documents…
  • 36. © F5 Networks, Inc 36 DDoS Protection Reference Architecture Legitimate Users Threat Feed Intelligence DDoS Attacker ISPa/b Cloud Scrubbing Service Scanner Anonymous Proxies Anonymous Requests Botnet Attackers Network attacks: ICMP flood, UDP flood, SYN flood DNS attacks: DNS amplification, query flood, dictionary attack, DNS poisoning IPS Next-Generation Firewall Tier 2 SSL attacks: SSL renegotiation, SSL flood HTTP attacks: Slowloris, slow POST, recursive POST/GET Application Corporate Users Financial Services E-Commerce Subscriber Tier 2 Threat Feed Intelligence Strategic Point of Control Multiple ISP strategy Network and DNS Tier 1
  • 37. © F5 Networks, Inc 37 DDoS Protection Reference Architecture Legitimate Users Threat Feed Intelligence DDoS Attacker ISPa/b Cloud Scrubbing Service Scanner Anonymous Proxies Anonymous Requests Botnet Attackers Network attacks: ICMP flood, UDP flood, SYN flood DNS attacks: DNS amplification, query flood, dictionary attack, DNS poisoning IPS Next-Generation Firewall Tier 2 SSL attacks: SSL renegotiation, SSL flood HTTP attacks: Slowloris, slow POST, recursive POST/GET Application Corporate Users Financial Services E-Commerce Subscriber Tier 2 Threat Feed Intelligence Strategic Point of Control Multiple ISP strategy Network and DNS Tier 1 • The first tier at the perimeter is layer 3 and 4 network firewall services • Simple load balancing to a second tier • IP reputation database • Mitigates volumetric and DNS DDoS attacks TIER 1 KEY FEATURES
  • 38. © F5 Networks, Inc 38 DDoS Protection Reference Architecture Legitimate Users Threat Feed Intelligence DDoS Attacker ISPa/b Cloud Scrubbing Service Scanner Anonymous Proxies Anonymous Requests Botnet Attackers Network attacks: ICMP flood, UDP flood, SYN flood DNS attacks: DNS amplification, query flood, dictionary attack, DNS poisoning IPS Next-Generation Firewall Tier 2 SSL attacks: SSL renegotiation, SSL flood HTTP attacks: Slowloris, slow POST, recursive POST/GET Application Corporate Users Financial Services E-Commerce Subscriber Tier 2 Threat Feed Intelligence Strategic Point of Control Multiple ISP strategy Network and DNS Tier 1 • The second tier is for application-aware, CPU-intensive defense mechanisms • SSL termination • Web application firewall • Mitigate asymmetric and SSL-based DDoS attacks TIER 2 KEY FEATURES
  • 39. © F5 Networks, Inc 39 Recommended Practices Configuration Guide 2.3.2.5 Throttle GET Request Floods via Script The F5 DevCentral community has developed several powerful iRules that automatically throttle GET requests. Customers are continually refining these to keep up with current attack techniques. Here is one of the iRules that is simple enough to be represented in this document. The live version can be found at this DevCentral page: HTTP-Request-Throttle when RULE_INIT { # Life timer of the subtable object. Defines how long this object exist in the subtable set static::maxRate 10 # This defines how long is the sliding window to count the requests. # This example allows 10 requests in 3 seconds set static::windowSecs 3 set static::timeout 30 } when HTTP_REQUEST { if { [HTTP::method] eq "GET" } { set getCount [table key -count -subtable [IP::client_addr]] if { $getCount < $static::maxRate } { incr getCount 1 table set -subtable [IP::client_addr] $getCount "ignore" $static::timeout $static::windowSecs } else { HTTP::respond 501 content "Request blockedExceeded requests/sec limit." return } } } Another iRule, which is in fact descended from the above, is an advanced version that also includes a way to manage the banned IPs address from within the iRule itself: · URI-Request Limiter iRule – Drops excessive HTTP requests to specific URIs or from an IP 2.3.2.4 Enforce Real Browsers Besides authentication and tps-based detection (section Error! Reference source not found.), there are additional ways that F5 devices can separate real web browsers from probable bots. The easiest way, with ASM, is to create a DoS protection profile and turn on the “Source IP- Based Client Side Integrity Defense” option. This will inject a JavaScript redirect into the client stream and verify each connection the first time that source IP address is seen. Figure 1. Insert a Javascript Redirect to verify a real browser 32 Page Detailed Guide…
  • 41. © F5 Networks, Inc 41 Completing the SDN Stack F5 BIG-IQ OPEN REST APIs LAYER 2-3 LAYER 4-7 SDN Controller BIG-IQ Security™ BIG-IQ Cloud™ BIG-IQ Device™ NBI NBI NVGRE VXLAN ETC… Control Plane Application Plane Data Plane Software-DefinedDataCenter Virtual Networks Service Chaining
  • 42. © F5 Networks, Inc 42 F5 Platforms Hardware | Software | Cloud Programmability F5 SDAS Service Fabric Programmability BIG IQ Cloud Provisioning and orchestration of BIG-IP in AWS Two-way communication Configure application networking services Automated network and service provisioning Auto-scaling, application provisioning, and automated system maintenance and patching. Automate network and service provisioning, Integrate network virtualization and ADN services Partner Integration with Synthesis
  • 43. Cisco ACI Design Philosophy
  • 44. Why Cisco/ACI matters for Customers • Cisco and F5 share a common vision for simplifying networking end to end by taking an application-centric approach to solving key pain points in customer’s next generation data centers while meeting their critical data center requirements today. • Working with Cisco on Application Centric Infrastructure, F5 has a unique opportunity to deliver on vision of shaping infrastructure to the needs of the applications. • Cisco ACI integrates F5 Big-IP appliances (physical and virtual) to deliver application-centric, ADC-enabled network automation in existing and next generation data centers
  • 45. © F5 Networks, Inc. Benefits Drive Increase Reduce Future 45