10. 10
管理和預測資料中心使用情況
• Citrix ADC提供DNS服務和應用程式名稱查詢
• 可達成彈性資料中心 : Active/Active, Active/DR Only
• 單一程式/伺服器或是整個資料中心故障都可復原
Local DNS
Users
Passive
Active
Citrix ADC SLB/LLB
Citrix ADC SLB/LLB
Citrix ADC SLB/LLB App Server
App Server
App Server
Active
雙資料中心/異地備援方案
服務不中斷
台北
台中
高雄
26. 26
• Bad IPs are blocked. Very low risk, easy to turn on, and positive impact.
Do it.
• Webroot-provided – same functionality as IP Reputation in WAF
– 6 categories collected
• Webroot updates its Malicious IP DB every 5 minutes, with full DB release
every 12 hours
– Hosted on brightcloud.com
– If ADC outbound traffic is blocked, the customer need to whitelist outbound traffic to
brightcloud.com to receive updates
IP Reputation 信譽評等
Actions Available
Drop
Redirect
Log
Stats (automatic)
28. 28
• Characteristics
– Monitor user experiences in realtime
– Monitor experiences in huge traffic flow
– Centralized monitoring
– Bundled monitoring tool (NS Insight Center) or
integrated with 3rd party tool (Splunk,
Solarwinds)
• Threshold and alerting based on
network conditions
• SLA management with proactive
notifications sent to admins when
SLAs are breached
使用者效能監控
40. 40
ICAP
• For antimalware, DLP and content scrubbing system integration
• Secure ICAP policy support
• ICAP policy support (coming soon)
Inline Device Integration (L2)
• IPS, Next-Gen Firewall and ATP integration
• SSL Offloading of single or multiple inline devices
• Better solution than sandwich mode
Port Mirroring
• IDS, Monitoring and Analytics system integration
• TLS 1.3, HTTP/2, ECC visibility
• Target release Q2’19
Content Inspection Capabilities
41. 41
• What is SSL Orchestrator?
– Ability to break outbound encrypted traffic (forward proxy) and do
content inspection.
• Is SSL Orchestrator supported in ADC license?
– It will be supported in Premium Edition (Platinum Edition) of all
VPX/MPX/SDX from Q2’19 (target).
• Is it same as Citrix SWG?
– While Citrix SWG is a standalone model, SSL Orchestrator is a module in
ADC. Citrix SWG will be discontinued.
– SSL Orchestrator is more focused on security service chaining.
• What is sizing recommendation?
– Sell bigger platform license for SSL Orchestrator use case.
Example: 8930 instead of 8910.
Customer N/w
SSL Orchestrator for Outbound Traffic Security
42. 42
Customer N/w
App1
App2
Citrix ADC
Client to server traffic
API traffic
If API call is over web, then do
forward proxy (SSL Orchestrator)
App3
If API call is in same network, do
reverse proxy
• When servers make API calls in same network, traditional reverse proxy works because the private keys are
available for decryption and inspection.
• When servers make API calls over web, SSL Orchestrator capability is needed on ADC.
Why is SSL Orchestrator Functionality Needed on ADC?
For API Control
43. 43
• Dedicated research team of 3 people
• Regular signature updates as needed for new CVEs
• Signature update alert through Citrix support site – Customers have to subscribe
WAF – Objections Addressed
Signature Updates
• Available in 12.1 onwards
• Ability to log up to 6K bytes of request for violations
• Configured using log expressions
Extended Logging
• Available in x.y onwards
• Ability to disable dropping/blocking for RFC check violations
• Applicable to traffic that applies to appfw profile or not
RFC Check Issues
44. 44
擴展Citrix ADC產品形態的選擇– Virtual VPX, Container CPX, Physical MPX, Multi Tenant SDX
Citrix ADC BLX: Bare Metal ADC
BLX
Citrix ADC
没有虚擬機或容器開銷
以軟體为中心,訂閱為基礎
為混合多雲構建
與其它ADC產品形態的操作一致性
VM
ADC release 13已支持
55. 55
Pooled Capacity 組合
Support for Every Form Factor and 3rd Party
Citrix Application Delivery Management(ADM)
Zero-Capacity Hardware
• 硬體
• 基於性能需求選擇
• 頻寬pool 被所有產品型態
所共享: MPX, SDX, VPX and
CPX
• 包括標準版,進階版,白
金版
• 虛擬產品形態所共享: VPX
on SDX, stand-alone VPX
and CPX
Bandwidth Pool Software Instance Pool
軟硬體去耦合
bandwidth和instance pool 被所有
Citrix ADC 產品型態共享
+ + =
56. 56
Packaging - MPX
SDX
Bandwidth Pool with Editions Instances
訂閱
Zero-Capacity Hardware
買斷
VPX
CPX
MPX
Zero capacity hardware
purchase required Subscribe to bandwidth pool
57. 57
Packaging - SDX
SDX
Bandwidth Pool with Editions Instances
訂閱
Zero-Capacity Hardware
買斷
VPX
CPX
MPX
Zero capacity hardware
purchase required Subscribe to bandwidth pool
58. 58
Packaging – VPX or CPX
SDX
Bandwidth Pool with Edition Software Instance Pool
訂閱
VPX
CPX
MPX
Hardware
Subscribe to a number of instances
59. 59
總結-配置方式
MPX SDX VPX CPX
Zero Capacity硬體
硬體服务(gold/gold+ only)
● ●
起始Bandwidth和Instances pool訂閱 ● ● ● ●
追加 Bandwidth 訂閱 (可選 ) ● ● ● ●
追加Instance訂閱 (可選 ) ● ● ●
• Pooled Capacity bandwidth和instance的訂閱可用1年,3年或5年期限
• 可以從 永久許可升級/轉換為 Pooled Capacity
eg.Citrix ADC Pooled Capacity 3-year On Premise Subscription Premium Edition Upgrade from MPX 8905
Premium Editon (3021912)
• 也可以把zero capacity的硬體轉為 perpetual
eg. Citrix ADC 8900Z Hardware Transition to Perpetual ADC MPX 8905 Standard Edition(3022048)
• 需要Citrix ADM作為 Pooled Capacity的許可Server(免费)
65. 65
Scale up
Scale out
Scale in
Citrix TriScale
Scale up, Scale in and Scale out
簡易管理多合一虛擬化平台
依實際需求付費
強大的叢集擴展性
最大成長 5x.
不需更換硬體平台.
“ ”
最大支援115:1
”
“
”
叢集擴展最高 32x
“
Learn More About TriScale:
http://www.citrix.com/content/dam/citrix/en_us/documents/pro
ducts-solutions/a-revolution-in-cloud-networking-citrix-triscale-
technology.pdf