SlideShare a Scribd company logo
Not All SOA Gateways Are Created Equal
Considerations for Business Manager
                            Managers




                              Layer 7 Technologies

                  White Paper
Not All SOA Gateways Are Created Equal


Contents

Introduction ................................................................
                                             ................................................................................................
                                                                                                             .................................................. 3
Cost of Implementation ................................
                       ................................................................................................................................ 3
                                                                                                                       ................................
   Deployability ................................
                 ................................................................................................................................
                                                                                                                 ............................................. 3
       Form Factor Considerations ................................
                                  ................................................................................................
                                                                                                  .................................................. 3
   Extensibility ................................................................
                                                 ................................................................................................
                                                                                                                 ............................................... 4
       SDK ................................................................
                                           ................................................................................................
                                                                                                           ........................................................ 4
       Interoperability ................................
                        ................................................................................................................................ 4
                                                                                                                        .....................................
       Standards Commitment ................................
                            ................................................................................................
                                                                                            ........................................................ 4
Cost of Operation ................................
                  ................................................................................................................................
                                                                                                                  .......................................... 5
   Manageability ................................
                 ................................................................................................................................
                                                                                                                 ........................................... 5
   Scalability and Reliability ................................
                               ................................................................................................
                                                                                               .......................................................... 5
   Updating................................................................
                                           ................................................................................................
                                                                                                           .................................................... 5
Cost of Upgrade ................................
                ................................................................................................................................
                                                                                                                ............................................ 6
   Repurchasing Gateways ................................
                         ............................................................................................................................ 6
                                                                                                                         ............................
About Layer 7 Technologies ................................
                           ................................................................................................
                                                                                           .......................................................... 7
Contact Layer 7 Technologies ................................
                             ................................................................................................
                                                                                             ....................................................... 7
Legal Information ................................
                  ................................................................................................................................
                                                                                                                  .......................................... 7




             Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are
                                             ogies
            trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.                                    2
Not All SOA Gateways Are Created Equal


  Introduction
  SOA Gateways were originally introduced to address common security and performance issues arising from the use
               s
  of XML-based messaging protocols in a Service Oriented Architecture (SOA). Over this decade, Gateway capabilities
         based
  have been broadened to address runtime policy enforcement issues (such as regulatory compliance, SLA
  conformation, and granular privacy and access control problems), as well as integration to third party service
   onformation,
  providers, whether across organizational boundaries; across the public internet, or (increasingly) between the
  enterprise and the cloud.

  But while all Gateways provide similar features/functionality, the Total Cost of Ownership (TCO) varies widely. For
         le
  Gateways, TCO extends well beyond just the initial licensing and implementation fees to include the cost of
  deploying, customizing, and managing the solution on an ongoing basis. In today’s economic climate, organizations
                                         the
  have expanded their evaluation focus to encompass criteria that will help them avoid lock in and undue operating
                                                                                        lock-in
  costs.

  This white paper examines those factors that will have the greatest impact on total cost of ownership, namely cost
  of implementation, operation and upgrade
                                   upgrade.


  Cost of Implementation
  Beyond upfront licensing, the cost of implementation for an SOA Gateway typically includes configuration and
                                  ost
  customization expenses (a factor of the ease of extensibility of a Gateway) as well as ease of deployment. Other
                                                                     Gateway),
  costs can also include the time and resources to certify new hardware for deployment in a corporate datacenter.

Layer 7 offers hardware,
                                       Deployability
software, VMware and
                                       Deployment flexibility is key to lowering cost of implementation. Where some
Amazon Machine                         Gateway vendors offer only hardware or software solutions, Layer 7 offers multiple
Images, so customers                   form factors – including hardware, software, VMware and Amazon Machine Image
can choose the most                    (AMI) – allowing customers to choose the most appropriate solution for their
                                                                                               iate
appropriate solution for               purpose, deployment platform, budget, and/or stage of implementation.
their purpose, platform,
                                   For example, some Gateway vendors leave organizations with no flexibility when it
budget, and/or stage of            comes to purchasing a Gateway for the purposes of developing and testing a
implementation                     solution as they only offer a hardware-based solution. However, development
                                                                                                   deve
                                   organizations typically do not need the high performance of a hardware-based
                                                                                                 hardware
  solution. For this reason, Layer 7 makes available VMware
                                                     VMware-based Gateways and even pay-as-you you-go Amazon
  Machine instances, which are a better fit (and more appropriately priced) for prototyping than production-ready
                                                                                                  production
  hardware solutions.

  Form Factor Considerations
  Hardware – Most SOA Gateway vendors offer hardware accelerated network appliances featuring dedicated chip
  sets to accelerate/offload common XML processes. By optimizing XML performance using a Gateway,
  organizations can reduce the load on their application servers, reducing the cost and frequency of server upgrades.
                                                                               cost

  Software/VMWare – While hardware-based Gateways are key in production settings, they are often an
                                          -based
  impractical (and costly) solution for development, testing or staging environments where software or VMware-
                                                                                             software-
  based appliances are the preferred form factor. Layer 7 is one of the few vendors to offer both a VMWare and
               nces
  software Gateway at an economical price tag, while delivering identical feature/functionality as the hardware
                                                                  identical
  appliance.




           Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are
                                           ogies
           trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.   3
Not All SOA Gateways Are Created Equal

Additionally, Layer 7’s software Gateway can be implemented on customer
                                    eway                          customer-defined hardware – hardware that has
already been tested and approved for use in their datacenter – eliminating the cost of testing and implementing a
new hardware platform, while significantly decreasing support and maintenance costs.

Virtual – Public and private clouds are gaining acceptance in the marketplace for their ability to convert CapEx to
OpEx by offering cost-effective computing resources on
                       effective                      on-demand. As a result, organizations have begun redesigning
                                                                                     ations
their own datacenters as private clouds, and consuming public cloud resources on a utility basis. Layer 7’s virtual
cloud Gateway offerings (including both our Virtual Appliance and AMI) have made it possible for these
organizations to spin up SOA Gateway instances in a multi-tenant environment in order to guard access to their
                                                            tenant
cloud-based services and APIs. Hardware based vendors are unable to accommodate these changing IT
       based                     Hardware-based
requirements.

Extensibility
As the advent of the cloud so clearly co
                                      confirms, IT environments change. While Layer 7’s support for multiple form
factors has been one way to help insulate customers against changes in the datacenter, accommodating business
change requires extensibility – the ability to quickly and cost-effectively customize a solution to match evolving
                                                                effectively
business needs based on specific industry traits, existing corporate guidelines, and the organization’s unique
business processes.


Layer 7’s Custom Policy                  SDK
Assertion SDK gives                      Layer 7’s Custom Policy Assertion SDK gives developers the ability to extend the
developers the ability to                Gateway’s functionality in order to accommodate their specific requirements
extend the Gateway’s                     using standard Java programming. Custom Assertions can be created for
                                         proprietary message processing, pattern recognition and filtering, as well as
functionality in order to
                                         interfacing to third party products, such as identity management infrastructure,
                                                        third-party                                        infrastructure
accommodate their
                                         network monitoring applications, or anti
                                                                               anti-virus systems.
specific requirements
using standard Java             In contrast, the extensibility of many other Gateways is limited. For example, to
                                                                                         limited
programming                     accommodate the kinds of customization listed above would typically require
                                either the skills of an XSLT programmer (expensive compared to the ubiquity of
Java programmers) and/or the addition of an application server ((such as WebSphere) to run the custom code.

Interoperability
Independent Gateway vendors like Layer 7 do not benefit from lock
 ndependent                                                   lock-in, but rather design from the ground up to
accommodate a heterogeneous SOA environment based on Web services standards. As a result, Layer 7’s
                                                                         standards.
Gateways interoperate with a wide range of products, including (for example) a wide range of leading identity,
  ateways
access, SSO and federation systems, such as LDAP, Microsoft Active Directory/Federated Services, Oracle Access
Manager, IBM Tivoli (TAM and TFIM), CA SiteMinder and TransactionMinder, Sun Java Access Manager and Novell
Access Manager.

Standards Commitment
One of the best guarantees against vendor or platform lock in is wide support for Web services standards. Any
                                                         lock-in
credible vendor in the SOA Gateway market should be able to demonstrate a history of active participation in the
standards bodies that govern Web services. This includes both authoring the standards and participating in regular
                                                           both
interops. Layer 7 has been an active participant in the OASIS, W3C and WS-I standards consortiums, and has
helped drive key standards like WS-Policy, WS
                                    Policy, WS-SecurityPolicy, WS-Trust, WS-Federation, WS-I BSP to name a few.
                                                                                              SP



         Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are
                                         ogies
         trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.   4
Not All SOA Gateways Are Created Equal


Cost of Operation
While implementation costs represent a key factor in the TCO equation, they’re typically only a one-time cost.
                                                                                                one
Operational costs – including ongoing Gateway management, administration and updating – represent a far
greater impact on total cost of ownership over time.

Manageability
Most SOA Gateways are implemented as a series of discrete functional units rather than as a cluster. While this can
                     s                                         functional
provide some flexibility when it comes to deployment, it also dramatically raises administration costs as each
Gateway must be separately configured, updated and managed. In contrast, Layer 7 Gateways feature true
clustering capabilities and can be centrally administered as if they were a single device.

                                   For distributed organizations that span diverse development, test, staging,
 Layer 7 embeds these
                                   production and even cloud environments – worldwide – management becomes
 kinds of enterprise-
                                   even more costly and complex. Pain points arise around policy migration,
 scale management
                                   Gateway and service performance monitoring, and policy lifecycle
                                             and
 capabilities directly
                                   management (from authoring to deployment to change management). Layer 7
 within the Gateway
                                   embeds these kinds of enterprise scale management capabilities directly within
                                                           enterprise-scale
 itself – there’s no need          the Gateway itself – there’s no need to deploy, manage and upgrade a separate
                                                                                      nage
 to deploy, manage and             product. For example, IBM typically recommends deploying “ITCAM for SOA” to
 upgrade a separate                provide enterprise management capabilities for their DataPower products. And
 product                           while Layer 7 allows global management of all Gateways from a single locati
                                                                                                          location,
TCAM is typically required to be deployed in multiple locations to support regional deployments.

For those organizations that already have a monitoring and management infrastructure in place, Layer 7 offers
out-of-the-box connectors to leading agent sed management products, as well as a robust API for integration
           box                        agent-based
with monitoring, auditing and KPI tracking software.

Scalability and Reliability
Scalability and reliability should go hand in hand. While simply placing a load balancer in front of a series of
Gateways can be a cheap and easy way to scale, solutions that offer built in clustering and failover can go a long
                                                                       built-in
way to ensuring reliability by providing fault tolerance and high availability. As load increases, the ability to scale
cost-effectively without affecting performance is key.
     effectively

Layer 7’s true clustering capabilities (i.e., the ability to exchange information, load balance and automati
                                                                                                    automatically fail
over) gives them the edge over other Gateways when it comes to horizontal scaling. Additionally, Layer 7’s
software-based appliances give organizations the choice to scale vertically (which may be more cost effective) by
          based
adding more processors to the server.

Updating
In an ideal setting, policies are developed, tested and implemented in production never to change. The reality,
however, is that policies must change to keep up with evolving business needs, regulatory requirements and
                                                                                      ory
market demands. The ability to implement changes on the fly (without having to bring down the Gateway) is key to
                  s.
ensuring business as usual.

Layer 7 provides the ability to implement changed/new policies in production without incurring downtime. In a
cluster, policies are updated centrally, and then replicated between devices in real time without requiring off-
                                                                                real-time                   off



         Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are
                                         ogies
         trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.   5
Not All SOA Gateways Are Created Equal

lining, making for easy change management. Additionally, any Gateway/cluster worldwide can be backed up and
restored from a centralized console, simplifying disaster recovery and ensuring business continuity.
                                                 disaster

In contrast, other SOA Gateways typically do not support cluster-wide administration, and thus requires
                                                                 wide
administrators to manually replicate policies on each Gateway. In addition, policy changes usually cannot be
                                                                                                   canno
implemented on the fly – rather, Gateways must be brought offline before updates can occur.


Cost of Upgrade
                                         For hardware
                                             hardware-only Gateways, migrating between versions typically requires a
 Because some
                                         complete forklift upgrade. In effect, this means returning the existing Gateway;
 Gateway vendors are
                                         repurchasing new hardware; re implementing existing configurations and
                                                                        re-implementing
 hardware-dependent,
                                         policies; and re
                                                       re-training on the new systems – all of which can be an expensive
 migrating between
                                         undertaking at a time when IT is experiencing more pressure on their budgets
 versions requires a                     than ever.
 complete forklift
 upgrade                           In contrast, Layer 7 offers an SOA Gateway whose hardware can be upgraded
                                   independently, giving customers the choice of remaining on their currently
supported version of the product while upgrading (not migrating) to the latest hardware to take advantage of
performance benefits. And not only can the new hardware be purchased for a nominal fee (a fraction of the initial
purchase price), the original hardware can be repurposed as a general use server, affording total investment
protection.

Repurchasing Gateways
In order to remain supported, customers are forced to repurchase new Gateways every three to five years when
                                                                                           hree f
the original hardware is retired. Despite paying a significant yearly support and maintenance fee, the repurchase
price is typically (depending on your bargaining power) close to the initial purchase price, leading to an
unreasonably high total cost of ownership for Gateway customers after just one or two hardware refreshes.

A comparable deployment of Layer 7 hardware Gateways is significantly less expensive – as little as one third the
cost. When considering development and test environments where most Layer 7 customers have t flexibility to
                                                                                                    the
deploy software or VMware Gateways, the savings are even more dramatic. As long as Layer 7 customers remain
                                       ,
current on Support and Maintenance, the cost to upgrade between Layer 7 hardware platforms is nominal, with no
charge for soft appliances. This represents a significant difference in total cost of ownership between Layer 7 and
                   liances.
other Gateways over just one or two refresh periods.

As a result, the total cost of ownership for a Layer 7 solution is dramatically lower than other Gateway
deployments, with initial purchase costs as little as one
              ,                                       one-third of the re-purchase price, and one quarter of the 3-5
                                                                                                                 3
year TCO.




         Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are
                                         ogies
         trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.   6
Not All SOA Gateways Are Created Equal


About Layer 7 Technologies
With more than 150 customers across 6 continents, and successful partnerships with some of the largest ISVs and
resellers in the industry, Layer 7 Technologies is the leader in SOA and cloud security and governance. Our award
                                                                                                              award-
winning SecureSpan™ family of SOA Gateways feature sophisticated runtime governance, enterprise-scale
                                       Gateways                                              enterprise
management and industry-leading XML security. Our CloudSpan™ family enables enterprises and service providers
                             leading
to securely consume cloud services, as well as protect and control their own applications deployed in public and
                                                                          own
private clouds. Founded in 2002, Layer 7 has a history of helping organizations address their security, visibility and
governance issues by enabling them to control, manage and adapt their Web services, no matter the deployment
model – in the enterprise or in the cloud
                                     cloud.


Contact Layer 7 Technologies
Layer 7 Technologies welcomes your questions, comments, and general feedback.

Email:
info@layer7tech.com

Web Site:
www.layer7tech.com

Phone:
(+1) 604-681-9377
1-800-681-9377 (toll free within North America)
           9377

Fax:
604-681-9387

Address:
Layer 7 Technologies
1200 G Street, NW, Suite 800
Washington, DC 20005

Layer 7 Technologies
Suite 405-1100 Melville Street
Vancouver, BC
V6E 4A6 Canada


Legal Information
Copyright © 2011 by Layer 7 Technologies, Inc. (www.layer7tech.com). Contents confidential. All rights reserved.
SecureSpan™ is a registered trademark of Layer 7 Technologies, In All other mentioned trade names and/or
                                                               Inc.
trademarks are the property of their respective owners.




         Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are
                                         ogies
         trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.   7

More Related Content

PDF
Dell Data Migration A Technical White Paper
PDF
Informatica installation guide
PDF
Conbp200709
PDF
Citrix virtual desktop handbook (7x)
PDF
Force dotcom apex code developers guide
PDF
Design And Implementation Of A Phone Card Company
PDF
PDF
Creating a VMware Software-Defined Data Center Reference Architecture
 
Dell Data Migration A Technical White Paper
Informatica installation guide
Conbp200709
Citrix virtual desktop handbook (7x)
Force dotcom apex code developers guide
Design And Implementation Of A Phone Card Company
Creating a VMware Software-Defined Data Center Reference Architecture
 

What's hot (20)

PDF
Presentation data center deployment guide
PDF
Eta design-guide-2019oct
PDF
R handbook - from Installation to Text Analytics
PDF
Eta nonfab-deploy-guide-2019oct
PDF
وثيقة النموذج المرجعي للتطبيقات الوطنية
PDF
Oracle 11g release 2
PDF
Microsoft retail sdd bo_v01
DOC
White Paper: Look Before You Leap Into Google Apps
DOCX
Interoperable Seafood Traceability Technology Architecture Issues Brief 11 6 ...
PDF
Machine Vision Toolbox for MATLAB (Relese 3)
PDF
plasma tv
PDF
PowerVR performance recommendations
PDF
Design sparktutorial
PDF
FCC Interop Board Final Report 05 22 12
PDF
Tools Users Guide
PDF
Best practices for running Microsoft sql server on xtremIO X2_h16920
PDF
Datacolor 650 600 400 Users Guide 4230 0395 M Rev 1
PDF
Oracle pl-sql user's guide & reference
PDF
actix lte
Presentation data center deployment guide
Eta design-guide-2019oct
R handbook - from Installation to Text Analytics
Eta nonfab-deploy-guide-2019oct
وثيقة النموذج المرجعي للتطبيقات الوطنية
Oracle 11g release 2
Microsoft retail sdd bo_v01
White Paper: Look Before You Leap Into Google Apps
Interoperable Seafood Traceability Technology Architecture Issues Brief 11 6 ...
Machine Vision Toolbox for MATLAB (Relese 3)
plasma tv
PowerVR performance recommendations
Design sparktutorial
FCC Interop Board Final Report 05 22 12
Tools Users Guide
Best practices for running Microsoft sql server on xtremIO X2_h16920
Datacolor 650 600 400 Users Guide 4230 0395 M Rev 1
Oracle pl-sql user's guide & reference
actix lte
Ad

Viewers also liked (13)

PDF
Value of SOA Governance for Cloud Computing
PDF
Enable Secure Mobile & Web Access to Microsoft SharePoint
PDF
Single Sign-On for Mobile
PDF
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
PDF
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
PDF
Reusable APIs
PDF
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
PDF
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
PPTX
API Monetization: Unlock the Value of Your Data
PDF
Mastering Digital Channels with APIs
PDF
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
PDF
Api architectures for the modern enterprise
PDF
Takeaways from API Security Breaches Webinar
Value of SOA Governance for Cloud Computing
Enable Secure Mobile & Web Access to Microsoft SharePoint
Single Sign-On for Mobile
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Reusable APIs
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API Monetization: Unlock the Value of Your Data
Mastering Digital Channels with APIs
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
Api architectures for the modern enterprise
Takeaways from API Security Breaches Webinar
Ad

Similar to Not all XML Gateways are Created Equal (20)

PDF
Junipe 1
PDF
Deployment guide series ibm tivoli access manager for e business v6.0 sg247207
PDF
Deployment guide series ibm tivoli access manager for e business v6.0 sg247207
PDF
Stopping Malware
PDF
BOOK - IBM Sterling B2B Integration and Managed File Transfer Solutions
PDF
Extending your business to mobile devices with ibm worklight
PDF
CONTINUOUS SYSTEMS, NONSTOP OPERATIONS WITH JUNOS
PPTX
Intel Cloud Summit 2012 ODCA + NAB
PDF
Cloud Computing Sun Microsystems
PDF
Whats-New-VMware-vCloud-Director-15-Technical-Whitepaper
PDF
This is
PDF
Intel Cloud Summit ODCA - NAB Customer presentation
PDF
Deployment guide series ibm tivoli identity manager 5.0 sg246477
PDF
Deployment guide series ibm tivoli identity manager 5.0 sg246477
PDF
BEA_SOA_Domains_WP.290214359
PDF
Everything You Need To Know About Cloud Computing
PPTX
WinWire_azure_session
PPTX
Testing cloud services - EuroSTAR
PDF
MISA Cloud Workshop_ Roadmap to a municipal community cloud in canada
Junipe 1
Deployment guide series ibm tivoli access manager for e business v6.0 sg247207
Deployment guide series ibm tivoli access manager for e business v6.0 sg247207
Stopping Malware
BOOK - IBM Sterling B2B Integration and Managed File Transfer Solutions
Extending your business to mobile devices with ibm worklight
CONTINUOUS SYSTEMS, NONSTOP OPERATIONS WITH JUNOS
Intel Cloud Summit 2012 ODCA + NAB
Cloud Computing Sun Microsystems
Whats-New-VMware-vCloud-Director-15-Technical-Whitepaper
This is
Intel Cloud Summit ODCA - NAB Customer presentation
Deployment guide series ibm tivoli identity manager 5.0 sg246477
Deployment guide series ibm tivoli identity manager 5.0 sg246477
BEA_SOA_Domains_WP.290214359
Everything You Need To Know About Cloud Computing
WinWire_azure_session
Testing cloud services - EuroSTAR
MISA Cloud Workshop_ Roadmap to a municipal community cloud in canada

More from CA API Management (20)

PDF
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
PDF
Enabling the Multi-Device Universe
PDF
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
PDF
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
PPTX
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
PDF
Adapting to Digital Change: Use APIs to Delight Customers & Win
PPTX
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
PDF
5 steps end to end security consumer apps
PPTX
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
PPTX
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
PDF
Using APIs to Create an Omni-Channel Retail Experience
PPTX
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
PDF
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
PPTX
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
PPTX
Is there an API in that (IoT)?
PPTX
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
PDF
Your New Digital Business & APIs
PDF
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
PPTX
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
PPTX
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Enabling the Multi-Device Universe
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
Adapting to Digital Change: Use APIs to Delight Customers & Win
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
5 steps end to end security consumer apps
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Using APIs to Create an Omni-Channel Retail Experience
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
Is there an API in that (IoT)?
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
Your New Digital Business & APIs
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...

Recently uploaded (20)

PPTX
sap open course for s4hana steps from ECC to s4
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Cloud computing and distributed systems.
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
Machine Learning_overview_presentation.pptx
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
sap open course for s4hana steps from ECC to s4
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
Dropbox Q2 2025 Financial Results & Investor Presentation
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Cloud computing and distributed systems.
Building Integrated photovoltaic BIPV_UPV.pdf
Machine Learning_overview_presentation.pptx
A comparative analysis of optical character recognition models for extracting...
Unlocking AI with Model Context Protocol (MCP)
20250228 LYD VKU AI Blended-Learning.pptx
Machine learning based COVID-19 study performance prediction
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Digital-Transformation-Roadmap-for-Companies.pptx
Review of recent advances in non-invasive hemoglobin estimation
Mobile App Security Testing_ A Comprehensive Guide.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
The AUB Centre for AI in Media Proposal.docx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf

Not all XML Gateways are Created Equal

  • 1. Not All SOA Gateways Are Created Equal Considerations for Business Manager Managers Layer 7 Technologies White Paper
  • 2. Not All SOA Gateways Are Created Equal Contents Introduction ................................................................ ................................................................................................ .................................................. 3 Cost of Implementation ................................ ................................................................................................................................ 3 ................................ Deployability ................................ ................................................................................................................................ ............................................. 3 Form Factor Considerations ................................ ................................................................................................ .................................................. 3 Extensibility ................................................................ ................................................................................................ ............................................... 4 SDK ................................................................ ................................................................................................ ........................................................ 4 Interoperability ................................ ................................................................................................................................ 4 ..................................... Standards Commitment ................................ ................................................................................................ ........................................................ 4 Cost of Operation ................................ ................................................................................................................................ .......................................... 5 Manageability ................................ ................................................................................................................................ ........................................... 5 Scalability and Reliability ................................ ................................................................................................ .......................................................... 5 Updating................................................................ ................................................................................................ .................................................... 5 Cost of Upgrade ................................ ................................................................................................................................ ............................................ 6 Repurchasing Gateways ................................ ............................................................................................................................ 6 ............................ About Layer 7 Technologies ................................ ................................................................................................ .......................................................... 7 Contact Layer 7 Technologies ................................ ................................................................................................ ....................................................... 7 Legal Information ................................ ................................................................................................................................ .......................................... 7 Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are ogies trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 2
  • 3. Not All SOA Gateways Are Created Equal Introduction SOA Gateways were originally introduced to address common security and performance issues arising from the use s of XML-based messaging protocols in a Service Oriented Architecture (SOA). Over this decade, Gateway capabilities based have been broadened to address runtime policy enforcement issues (such as regulatory compliance, SLA conformation, and granular privacy and access control problems), as well as integration to third party service onformation, providers, whether across organizational boundaries; across the public internet, or (increasingly) between the enterprise and the cloud. But while all Gateways provide similar features/functionality, the Total Cost of Ownership (TCO) varies widely. For le Gateways, TCO extends well beyond just the initial licensing and implementation fees to include the cost of deploying, customizing, and managing the solution on an ongoing basis. In today’s economic climate, organizations the have expanded their evaluation focus to encompass criteria that will help them avoid lock in and undue operating lock-in costs. This white paper examines those factors that will have the greatest impact on total cost of ownership, namely cost of implementation, operation and upgrade upgrade. Cost of Implementation Beyond upfront licensing, the cost of implementation for an SOA Gateway typically includes configuration and ost customization expenses (a factor of the ease of extensibility of a Gateway) as well as ease of deployment. Other Gateway), costs can also include the time and resources to certify new hardware for deployment in a corporate datacenter. Layer 7 offers hardware, Deployability software, VMware and Deployment flexibility is key to lowering cost of implementation. Where some Amazon Machine Gateway vendors offer only hardware or software solutions, Layer 7 offers multiple Images, so customers form factors – including hardware, software, VMware and Amazon Machine Image can choose the most (AMI) – allowing customers to choose the most appropriate solution for their iate appropriate solution for purpose, deployment platform, budget, and/or stage of implementation. their purpose, platform, For example, some Gateway vendors leave organizations with no flexibility when it budget, and/or stage of comes to purchasing a Gateway for the purposes of developing and testing a implementation solution as they only offer a hardware-based solution. However, development deve organizations typically do not need the high performance of a hardware-based hardware solution. For this reason, Layer 7 makes available VMware VMware-based Gateways and even pay-as-you you-go Amazon Machine instances, which are a better fit (and more appropriately priced) for prototyping than production-ready production hardware solutions. Form Factor Considerations Hardware – Most SOA Gateway vendors offer hardware accelerated network appliances featuring dedicated chip sets to accelerate/offload common XML processes. By optimizing XML performance using a Gateway, organizations can reduce the load on their application servers, reducing the cost and frequency of server upgrades. cost Software/VMWare – While hardware-based Gateways are key in production settings, they are often an -based impractical (and costly) solution for development, testing or staging environments where software or VMware- software- based appliances are the preferred form factor. Layer 7 is one of the few vendors to offer both a VMWare and nces software Gateway at an economical price tag, while delivering identical feature/functionality as the hardware identical appliance. Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are ogies trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 3
  • 4. Not All SOA Gateways Are Created Equal Additionally, Layer 7’s software Gateway can be implemented on customer eway customer-defined hardware – hardware that has already been tested and approved for use in their datacenter – eliminating the cost of testing and implementing a new hardware platform, while significantly decreasing support and maintenance costs. Virtual – Public and private clouds are gaining acceptance in the marketplace for their ability to convert CapEx to OpEx by offering cost-effective computing resources on effective on-demand. As a result, organizations have begun redesigning ations their own datacenters as private clouds, and consuming public cloud resources on a utility basis. Layer 7’s virtual cloud Gateway offerings (including both our Virtual Appliance and AMI) have made it possible for these organizations to spin up SOA Gateway instances in a multi-tenant environment in order to guard access to their tenant cloud-based services and APIs. Hardware based vendors are unable to accommodate these changing IT based Hardware-based requirements. Extensibility As the advent of the cloud so clearly co confirms, IT environments change. While Layer 7’s support for multiple form factors has been one way to help insulate customers against changes in the datacenter, accommodating business change requires extensibility – the ability to quickly and cost-effectively customize a solution to match evolving effectively business needs based on specific industry traits, existing corporate guidelines, and the organization’s unique business processes. Layer 7’s Custom Policy SDK Assertion SDK gives Layer 7’s Custom Policy Assertion SDK gives developers the ability to extend the developers the ability to Gateway’s functionality in order to accommodate their specific requirements extend the Gateway’s using standard Java programming. Custom Assertions can be created for proprietary message processing, pattern recognition and filtering, as well as functionality in order to interfacing to third party products, such as identity management infrastructure, third-party infrastructure accommodate their network monitoring applications, or anti anti-virus systems. specific requirements using standard Java In contrast, the extensibility of many other Gateways is limited. For example, to limited programming accommodate the kinds of customization listed above would typically require either the skills of an XSLT programmer (expensive compared to the ubiquity of Java programmers) and/or the addition of an application server ((such as WebSphere) to run the custom code. Interoperability Independent Gateway vendors like Layer 7 do not benefit from lock ndependent lock-in, but rather design from the ground up to accommodate a heterogeneous SOA environment based on Web services standards. As a result, Layer 7’s standards. Gateways interoperate with a wide range of products, including (for example) a wide range of leading identity, ateways access, SSO and federation systems, such as LDAP, Microsoft Active Directory/Federated Services, Oracle Access Manager, IBM Tivoli (TAM and TFIM), CA SiteMinder and TransactionMinder, Sun Java Access Manager and Novell Access Manager. Standards Commitment One of the best guarantees against vendor or platform lock in is wide support for Web services standards. Any lock-in credible vendor in the SOA Gateway market should be able to demonstrate a history of active participation in the standards bodies that govern Web services. This includes both authoring the standards and participating in regular both interops. Layer 7 has been an active participant in the OASIS, W3C and WS-I standards consortiums, and has helped drive key standards like WS-Policy, WS Policy, WS-SecurityPolicy, WS-Trust, WS-Federation, WS-I BSP to name a few. SP Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are ogies trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 4
  • 5. Not All SOA Gateways Are Created Equal Cost of Operation While implementation costs represent a key factor in the TCO equation, they’re typically only a one-time cost. one Operational costs – including ongoing Gateway management, administration and updating – represent a far greater impact on total cost of ownership over time. Manageability Most SOA Gateways are implemented as a series of discrete functional units rather than as a cluster. While this can s functional provide some flexibility when it comes to deployment, it also dramatically raises administration costs as each Gateway must be separately configured, updated and managed. In contrast, Layer 7 Gateways feature true clustering capabilities and can be centrally administered as if they were a single device. For distributed organizations that span diverse development, test, staging, Layer 7 embeds these production and even cloud environments – worldwide – management becomes kinds of enterprise- even more costly and complex. Pain points arise around policy migration, scale management Gateway and service performance monitoring, and policy lifecycle and capabilities directly management (from authoring to deployment to change management). Layer 7 within the Gateway embeds these kinds of enterprise scale management capabilities directly within enterprise-scale itself – there’s no need the Gateway itself – there’s no need to deploy, manage and upgrade a separate nage to deploy, manage and product. For example, IBM typically recommends deploying “ITCAM for SOA” to upgrade a separate provide enterprise management capabilities for their DataPower products. And product while Layer 7 allows global management of all Gateways from a single locati location, TCAM is typically required to be deployed in multiple locations to support regional deployments. For those organizations that already have a monitoring and management infrastructure in place, Layer 7 offers out-of-the-box connectors to leading agent sed management products, as well as a robust API for integration box agent-based with monitoring, auditing and KPI tracking software. Scalability and Reliability Scalability and reliability should go hand in hand. While simply placing a load balancer in front of a series of Gateways can be a cheap and easy way to scale, solutions that offer built in clustering and failover can go a long built-in way to ensuring reliability by providing fault tolerance and high availability. As load increases, the ability to scale cost-effectively without affecting performance is key. effectively Layer 7’s true clustering capabilities (i.e., the ability to exchange information, load balance and automati automatically fail over) gives them the edge over other Gateways when it comes to horizontal scaling. Additionally, Layer 7’s software-based appliances give organizations the choice to scale vertically (which may be more cost effective) by based adding more processors to the server. Updating In an ideal setting, policies are developed, tested and implemented in production never to change. The reality, however, is that policies must change to keep up with evolving business needs, regulatory requirements and ory market demands. The ability to implement changes on the fly (without having to bring down the Gateway) is key to s. ensuring business as usual. Layer 7 provides the ability to implement changed/new policies in production without incurring downtime. In a cluster, policies are updated centrally, and then replicated between devices in real time without requiring off- real-time off Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are ogies trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 5
  • 6. Not All SOA Gateways Are Created Equal lining, making for easy change management. Additionally, any Gateway/cluster worldwide can be backed up and restored from a centralized console, simplifying disaster recovery and ensuring business continuity. disaster In contrast, other SOA Gateways typically do not support cluster-wide administration, and thus requires wide administrators to manually replicate policies on each Gateway. In addition, policy changes usually cannot be canno implemented on the fly – rather, Gateways must be brought offline before updates can occur. Cost of Upgrade For hardware hardware-only Gateways, migrating between versions typically requires a Because some complete forklift upgrade. In effect, this means returning the existing Gateway; Gateway vendors are repurchasing new hardware; re implementing existing configurations and re-implementing hardware-dependent, policies; and re re-training on the new systems – all of which can be an expensive migrating between undertaking at a time when IT is experiencing more pressure on their budgets versions requires a than ever. complete forklift upgrade In contrast, Layer 7 offers an SOA Gateway whose hardware can be upgraded independently, giving customers the choice of remaining on their currently supported version of the product while upgrading (not migrating) to the latest hardware to take advantage of performance benefits. And not only can the new hardware be purchased for a nominal fee (a fraction of the initial purchase price), the original hardware can be repurposed as a general use server, affording total investment protection. Repurchasing Gateways In order to remain supported, customers are forced to repurchase new Gateways every three to five years when hree f the original hardware is retired. Despite paying a significant yearly support and maintenance fee, the repurchase price is typically (depending on your bargaining power) close to the initial purchase price, leading to an unreasonably high total cost of ownership for Gateway customers after just one or two hardware refreshes. A comparable deployment of Layer 7 hardware Gateways is significantly less expensive – as little as one third the cost. When considering development and test environments where most Layer 7 customers have t flexibility to the deploy software or VMware Gateways, the savings are even more dramatic. As long as Layer 7 customers remain , current on Support and Maintenance, the cost to upgrade between Layer 7 hardware platforms is nominal, with no charge for soft appliances. This represents a significant difference in total cost of ownership between Layer 7 and liances. other Gateways over just one or two refresh periods. As a result, the total cost of ownership for a Layer 7 solution is dramatically lower than other Gateway deployments, with initial purchase costs as little as one , one-third of the re-purchase price, and one quarter of the 3-5 3 year TCO. Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are ogies trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 6
  • 7. Not All SOA Gateways Are Created Equal About Layer 7 Technologies With more than 150 customers across 6 continents, and successful partnerships with some of the largest ISVs and resellers in the industry, Layer 7 Technologies is the leader in SOA and cloud security and governance. Our award award- winning SecureSpan™ family of SOA Gateways feature sophisticated runtime governance, enterprise-scale Gateways enterprise management and industry-leading XML security. Our CloudSpan™ family enables enterprises and service providers leading to securely consume cloud services, as well as protect and control their own applications deployed in public and own private clouds. Founded in 2002, Layer 7 has a history of helping organizations address their security, visibility and governance issues by enabling them to control, manage and adapt their Web services, no matter the deployment model – in the enterprise or in the cloud cloud. Contact Layer 7 Technologies Layer 7 Technologies welcomes your questions, comments, and general feedback. Email: info@layer7tech.com Web Site: www.layer7tech.com Phone: (+1) 604-681-9377 1-800-681-9377 (toll free within North America) 9377 Fax: 604-681-9387 Address: Layer 7 Technologies 1200 G Street, NW, Suite 800 Washington, DC 20005 Layer 7 Technologies Suite 405-1100 Melville Street Vancouver, BC V6E 4A6 Canada Legal Information Copyright © 2011 by Layer 7 Technologies, Inc. (www.layer7tech.com). Contents confidential. All rights reserved. SecureSpan™ is a registered trademark of Layer 7 Technologies, In All other mentioned trade names and/or Inc. trademarks are the property of their respective owners. Copyright © 2011 Layer 7 Technologies Inc. All rights reserved. SecureSpan and the Layer 7 Technologies design mark are ogies trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 7