SlideShare a Scribd company logo
Using VNS3’s plugin system and Datadog to create a
secure, distributed, monitored layer 3 network
@
Bob Smetana
Network Solutions Architect
Who we are / what we do
2
software-only virtual appliance
Who we are / what we do
3
VNS3 provides an flat, encrypted, overlay network which can be spread across multiple regions and
clouds.
This network is entirely yours, and provides a layer of separation between the hypervisor and your
layer3 network.
Management of distributed applications’ networks becomes easy to understand and implement.
VNS3 Controller
VNS3:ms
Public Cloud
West Europe
Public Cloud
East US
Overlay Network
Peered Mesh
Overlay IP: 172.31.1.100 Overlay IP: 172.31.1.100
Primary Application Resource Network Subnet
VNS3 plugin system
4
Customers can run networking applications “on top” of VNS3 controllers
Containers can provide services such as:
NIDS / WAF
SSL termination
Monitoring services
Proxy / reverse proxy services
Application host load balancing
Application host HA / failover
Active IPsec Tunnel
VNS3 Controller 1 VNS3 Controller 2 VNS3 Controller 3
VNS3 Overlay Network - 172.31.1.0/24
Peered Peered
Overlay IP: 172.31.1.1
Cloud Server A
Overlay IP: 172.31.1.2
Cloud Server B
Overlay IP: 172.31.1.3
Cloud Server C
Overlay IP: 172.31.1.4
Primary DB
Overlay IP: 172.31.1.5
Backup DB
us-west-2 eu-central-1
Data Center 2
London
Data Center 1
Seattle, WA
Failover IPsec Tunnel
vpc 1 vpc 2 vpc 3
VNS3:ha 1
us-west-1
Example VNS3 topology
5
Example: DataDog monitoring plugin
6
• Hosts the DataDog agent
• Gathers information via SNMP and the VNS3 API
• Reports custom metrics to DataDog
• Offers users an “at-a-glance” overview of overlay network and appliance health
• Alerts can be configured based on predefined conditions or abnormal statistics
• Can predict network issues so that proactive action can be taken
overlay network in AWS with failover
network device failover in overlay network
server failover in overlay network
Example network health dashboard
10

More Related Content

PDF
Secure SDN
PPT
PDF
Connecting two linksys wifi routers wirelessly
PPTX
Wireless network security
PPTX
Wireless network security
PPTX
Final presentation
PPTX
How Hack WiFi through Aircrack-ng in Kali Linux Cyber Security
PPTX
Virtual Private Network
Secure SDN
Connecting two linksys wifi routers wirelessly
Wireless network security
Wireless network security
Final presentation
How Hack WiFi through Aircrack-ng in Kali Linux Cyber Security
Virtual Private Network

What's hot (13)

PPTX
Virtual Private Network (VPN)
PPTX
Wireless Network security
PPTX
DOCX
Eaack—a secure intrusion detection system for manets
DOCX
Eaack—a secure intrusion detection system for manets ns2
PPTX
Wireless Security
PPTX
Wireless hacking
PPT
Security Issues of 802.11b
PPT
Security Issues of IEEE 802.11b
PPTX
Wireless Network Security
PPTX
Wireless Network Thesis in NS2
DOC
Network security
PPT
Cevn Vibert. Thales UK. 28th January
Virtual Private Network (VPN)
Wireless Network security
Eaack—a secure intrusion detection system for manets
Eaack—a secure intrusion detection system for manets ns2
Wireless Security
Wireless hacking
Security Issues of 802.11b
Security Issues of IEEE 802.11b
Wireless Network Security
Wireless Network Thesis in NS2
Network security
Cevn Vibert. Thales UK. 28th January
Ad

Similar to Bob Smetana's talk "Monitoring VNS3 infrastructure health and status with DataDog" (20)

PDF
Cloud Security Best Practices - Part 1
PDF
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
PDF
Cohesive Networks Support Docs: Welcome to VNS3 3.5
PDF
Cloud networking use cases with VNS3
PDF
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
PDF
AWS Chicago User Group presentation: Connecting Docker Containers over the In...
PDF
Docker meetup talk - chicago March 2014
PDF
Comparison: VNS3 vs Vyatta
PDF
Cohesive Networks Support Docs: VNS3 Configuration Guide
PDF
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
PDF
CohesiveFT and IBM joint EMEA Webinar - 20Jun13
PDF
Cloud Security Best Practices - Part 2
PPTX
Dave Chandler Presents SDN at World Wide Technology's TECday - St. Louis
PDF
App to Cloud: Patrick Kerpan's DataCenter Dynamics Converged Keynote
PPTX
Operators experience and perspective on SDN with VLANs and L3 Networks
PDF
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
PDF
Asterisk as a Virtual Network Function Part 1
PDF
Kubernetes networking in AWS
PDF
Comparison: VNS3 and Openswan
PDF
Chris Swan's Cloud World Forum 2015 Presentation: Reperimiterisation in the C...
Cloud Security Best Practices - Part 1
Microsoft Infopedia webinar "Secure Your Azure Cloud Deployments with VNS3 Ov...
Cohesive Networks Support Docs: Welcome to VNS3 3.5
Cloud networking use cases with VNS3
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
AWS Chicago User Group presentation: Connecting Docker Containers over the In...
Docker meetup talk - chicago March 2014
Comparison: VNS3 vs Vyatta
Cohesive Networks Support Docs: VNS3 Configuration Guide
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
CohesiveFT and IBM joint EMEA Webinar - 20Jun13
Cloud Security Best Practices - Part 2
Dave Chandler Presents SDN at World Wide Technology's TECday - St. Louis
App to Cloud: Patrick Kerpan's DataCenter Dynamics Converged Keynote
Operators experience and perspective on SDN with VLANs and L3 Networks
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
Asterisk as a Virtual Network Function Part 1
Kubernetes networking in AWS
Comparison: VNS3 and Openswan
Chris Swan's Cloud World Forum 2015 Presentation: Reperimiterisation in the C...
Ad

More from AWS Chicago (20)

PPTX
Kathie Kinde Clark - Elevate Your Professional Footprint: LinkedIn Masterclass
PDF
Jason Anderson From Dirt Roads to Highways: Simplifying DevOps and Cloud Inf...
PDF
Aman Sardana and Vijay Kumar Soni - Navigating Hybrid Cloud Challenges for ...
PDF
Ben Blair Operating Safely in a Vibe Coding World
PPTX
Joseph Morotti Enhancing customer experience through Amazon Connect and Gene...
PPTX
Craig Johnson When VPCs Attack: Real-Life Cloud Networking Fails (and Fixes)
PDF
Peter Sankauskas Access Denied: Understanding & Debugging AWS IAM
PDF
Shuen Mei Parth Sharma Boost Productivity, Innovation and Efficiency wit...
PDF
Bob Fornal The Impact of Testing on a DevOps Pipeline
PDF
Jason Butz Chaos Engineering with FIS and Lambda Functions
PPTX
Automated VPC migration into centralized inspection architecture with AWS Gat...
PDF
Julia Furst Morgado The Lazy Guide to Kubernetes with EKS Auto Mode + Karpenter
PDF
Bob Fornal - Active Career Management AWS Community Day Midwest 2025
PDF
Edwin Moedano Monitoring and Observability of Lambdas with Cloudwatch and Po...
PPTX
Darren Mills The Migration Modernization Balancing Act: Navigating Risks and...
PPTX
Nathan Hiscock Architecting secure, scalable, cost-efficient computer vision...
PDF
AWS Community Day Midwest 2025 Julia Furst Morgado The Lazy Guide to Kuberne...
PDF
Steven Seaney - Simplifying and Streamlining AWS Control Tower Deployments
PDF
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
PPTX
Paul Chin Jr. Data Gone in 60 Seconds: A Serverless ETL Heist
Kathie Kinde Clark - Elevate Your Professional Footprint: LinkedIn Masterclass
Jason Anderson From Dirt Roads to Highways: Simplifying DevOps and Cloud Inf...
Aman Sardana and Vijay Kumar Soni - Navigating Hybrid Cloud Challenges for ...
Ben Blair Operating Safely in a Vibe Coding World
Joseph Morotti Enhancing customer experience through Amazon Connect and Gene...
Craig Johnson When VPCs Attack: Real-Life Cloud Networking Fails (and Fixes)
Peter Sankauskas Access Denied: Understanding & Debugging AWS IAM
Shuen Mei Parth Sharma Boost Productivity, Innovation and Efficiency wit...
Bob Fornal The Impact of Testing on a DevOps Pipeline
Jason Butz Chaos Engineering with FIS and Lambda Functions
Automated VPC migration into centralized inspection architecture with AWS Gat...
Julia Furst Morgado The Lazy Guide to Kubernetes with EKS Auto Mode + Karpenter
Bob Fornal - Active Career Management AWS Community Day Midwest 2025
Edwin Moedano Monitoring and Observability of Lambdas with Cloudwatch and Po...
Darren Mills The Migration Modernization Balancing Act: Navigating Risks and...
Nathan Hiscock Architecting secure, scalable, cost-efficient computer vision...
AWS Community Day Midwest 2025 Julia Furst Morgado The Lazy Guide to Kuberne...
Steven Seaney - Simplifying and Streamlining AWS Control Tower Deployments
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
Paul Chin Jr. Data Gone in 60 Seconds: A Serverless ETL Heist

Recently uploaded (20)

PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PPTX
A Presentation on Touch Screen Technology
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PDF
Web App vs Mobile App What Should You Build First.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PPTX
1. Introduction to Computer Programming.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
project resource management chapter-09.pdf
PDF
August Patch Tuesday
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Hybrid model detection and classification of lung cancer
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Approach and Philosophy of On baking technology
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
MIND Revenue Release Quarter 2 2025 Press Release
TLE Review Electricity (Electricity).pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia
A Presentation on Touch Screen Technology
Heart disease approach using modified random forest and particle swarm optimi...
Web App vs Mobile App What Should You Build First.pdf
Group 1 Presentation -Planning and Decision Making .pptx
1. Introduction to Computer Programming.pptx
Encapsulation_ Review paper, used for researhc scholars
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
project resource management chapter-09.pdf
August Patch Tuesday
Enhancing emotion recognition model for a student engagement use case through...
Hybrid model detection and classification of lung cancer
Programs and apps: productivity, graphics, security and other tools
Building Integrated photovoltaic BIPV_UPV.pdf
Approach and Philosophy of On baking technology
1 - Historical Antecedents, Social Consideration.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

Bob Smetana's talk "Monitoring VNS3 infrastructure health and status with DataDog"

  • 1. Using VNS3’s plugin system and Datadog to create a secure, distributed, monitored layer 3 network @ Bob Smetana Network Solutions Architect
  • 2. Who we are / what we do 2 software-only virtual appliance
  • 3. Who we are / what we do 3 VNS3 provides an flat, encrypted, overlay network which can be spread across multiple regions and clouds. This network is entirely yours, and provides a layer of separation between the hypervisor and your layer3 network. Management of distributed applications’ networks becomes easy to understand and implement. VNS3 Controller VNS3:ms Public Cloud West Europe Public Cloud East US Overlay Network Peered Mesh Overlay IP: 172.31.1.100 Overlay IP: 172.31.1.100 Primary Application Resource Network Subnet
  • 4. VNS3 plugin system 4 Customers can run networking applications “on top” of VNS3 controllers Containers can provide services such as: NIDS / WAF SSL termination Monitoring services Proxy / reverse proxy services Application host load balancing Application host HA / failover
  • 5. Active IPsec Tunnel VNS3 Controller 1 VNS3 Controller 2 VNS3 Controller 3 VNS3 Overlay Network - 172.31.1.0/24 Peered Peered Overlay IP: 172.31.1.1 Cloud Server A Overlay IP: 172.31.1.2 Cloud Server B Overlay IP: 172.31.1.3 Cloud Server C Overlay IP: 172.31.1.4 Primary DB Overlay IP: 172.31.1.5 Backup DB us-west-2 eu-central-1 Data Center 2 London Data Center 1 Seattle, WA Failover IPsec Tunnel vpc 1 vpc 2 vpc 3 VNS3:ha 1 us-west-1 Example VNS3 topology 5
  • 6. Example: DataDog monitoring plugin 6 • Hosts the DataDog agent • Gathers information via SNMP and the VNS3 API • Reports custom metrics to DataDog • Offers users an “at-a-glance” overview of overlay network and appliance health • Alerts can be configured based on predefined conditions or abnormal statistics • Can predict network issues so that proactive action can be taken
  • 7. overlay network in AWS with failover
  • 8. network device failover in overlay network
  • 9. server failover in overlay network
  • 10. Example network health dashboard 10