SlideShare a Scribd company logo
Cisco Public 1© 2011 Cisco and/or its affiliates. All rights reserved.
Securing the Cloud Infrastructure –
from Hypervisorto the Edge
Gaweł Mikołajczyk
gmikolaj@cisco.com
Security Consulting Systems Engineer
EMEA Central Core Team
CCIE #24987, CISSP-ISSAP, CISA
PLNOG8, March 5, 2012, Warsaw, Poland
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Policy
Corporate Border
Branch Office
Applications
and Data
Corporate Office
Home Office
Attackers
Coffee
ShopCustomers
Airport
Mobile
User Partners
Platform
as a Service
Infrastructure
as a Service
X
as a Service
Software
as a Service
Trzy wymiary : dla Infrastruktury w chmurze, dla dostępu do chmury, komercyjne
usługi bezpieczeństwa w chmurze.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Prywatny VPN
MPLS lub IPSec / SSL
NEXUS 1000v
NAS
Data Center
Core
Tenant
A
Tenant B
Sub Tenant
B1 i B2
WAN
Compute
Dostęp
Usługi
Agregacja
Edge
Dostęp L2 lub L3
Tenant per VRF
Mapowanie VRF / VLAN do vFW/LB
VRF do unikalnego VLAN
Mapowanie do VM
Cisco Public 4© 2011 Cisco and/or its affiliates. All rights reserved.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
VMNIC #1
vEth vEth
Virtualization
Security
V-Motion
(Memory)
V-Storage
(VMDK)
VM
Segmentation
Hypervisor
Security
Role
Based
Access
Physical
Security
VM OS
Hardening
Patch
Management
VM
Sprawl
VMNIC #2
Real case: [...] It looks the O&M firewall is not filtering the ARP traffic
the right way. This allows a VM to connect to any other VM through the
O&M network after injecting malicious ARP traffic. This happens even
if the destination VM belongs to a different tenant VDC [...]
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Warstwa dostępu wirtualnego powinna
oferować przynajmniej takie same
mechanizmy bezpieczeństwa Layer-2 jak w
fizycznym DataCenter :
Access Lists, Dynamic ARP Inspection,
DHCP Snooping, IP Source Guard, Port
Security, Private VLANs, Layer-2 storm
control, Rate-Limiters, VXLAN
Bez tych mechanizmów, konsekwencje
ataków na infrastruktuę sieciową, (biorąc
pod uwagę skalę - tysiące VM) są
katastrofalne.
Widoczność w warstwie 2 można osiągnąć
przez:
NetFlow Collection
SPAN, RSPAN or ERSPAN
1/
7
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
port-profile vm180
vmware port-group pg180
switchport mode access
switchport access vlan 180
ip flow monitor ESE-flow input
ip flow monitor ESE-flow output
no shutdown
state enabled
interface Vethernet9
inherit port-profile vm180
interface Vethernet10
inherit port-profile vm180
Port Profile –> Port Group
vCenter API
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
10.20.20.50 10.20.30.10110.20.20.51
vPC Peer-link
VSL
vPC
Service VLANs
Nexus 1000V and VSG
Nexus 7000
Nexus 5000
ESX Server
ASA 5585
Cat 6500
monitor session 2 type erspan-
source
description N1k ERSPAN –session 2
monitor session 4 type erspan-
destination
description N1k ERSPAN to IDS1
monitor session 1 type erspan-
source
description N1k ERSPAN –
session 1
monitor session 3 type erspan-
destination
description N1k ERSPAN to NAM
NAM
Cisco Public 9© 2011 Cisco and/or its affiliates. All rights reserved.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Hypervisor
Appliance i moduły fizyczne
Konteksty wirtualne
VLANs
Hypervisor
Przekierowanie ruchu z VM do
fizycznych urządzeń
1
App
Server
Database
Server
Web
Server
Usługi bezpieczeństwa
na poziomie hypervisora
2
App
Server
Database
Server
Web
Server
VSN
Appliance wirtualne
VSN
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Sandwich usługowy między VDC
• ASA Service Module
Konteksty wirtualne
Tryb Transparentny / mixed
• ACE LB
Tryb transparentny
• Web Application Firewall
Farma firewalli
• Network IPS/IDS
Inline lub promiscuous
N7k1-VDC1
N7k1-VDC2
ASA-SM 2
ASA-SM 1
ACE
hsrp.1
IPS
162
161
163,164
WAF
190
SS1
SVI-151
vrf1 vrf2
Cisco Public 12© 2011 Cisco and/or its affiliates. All rights reserved.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Security
Administrator
Port
Group
Service
Administrator
Virtual Network
Management Center
Virtual Security
Gateway - VSG
Cisco Nexus® 1000V
z mechanizmem vPath
• Rozproszony przełącznik
• Część hypervisora
Host
• Cisco UCS
• Other x86 server
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Nexus 1000V
Distributed Virtual Switch
VM VM VM
VM VM
VM
VM VM VM
VM
VM
VM VM VM
VM VM VMVM
VM
vPath
VNMC
Log/Audit
Początkowy flow
VSG
1
Początkowa
ewaluacja polityki
2
Cache
decyzji 3
4
1
2
3
4
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Nexus 1000V
Distributed Virtual Switch
VM VM VM
VM VM
VM
VM VM VM
VM
VM
VM VM VM
VM VM VMVM
VM
vPath
VNMC
Log/Audit
VSG
Pozostałe pakiety
ACL offload do
Nexus 1000V
(wymuszenie polityki)
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
VSG: Security Profile to Port Profile
Cisco Public 17© 2011 Cisco and/or its affiliates. All rights reserved.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Egress
SGT=100
Pracownik,
grupa HR
HR (SGT=100)
Ingress SGT
Finance (SGT=4)
802.1X/MAB/Web Auth
HR SGT = 100 SGACL
• TrustSec to rozwiązanie o charakterze systemowym
• Overlayowe tagowanie SGT na wejściu do sieci LAN/WAN/VPN
• Wymuszenie polityki bezpieczeństwa przez SGACL na wyjściu
• Centralnie przechowywane reguły SGT/SGACL dają spójność
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
TAG oparty o rolę:
1. Urządzenie uwierzytelnia się
do sieci via 802.1X
2. ISE wysyła TAG jako wynik
autoryzacji – bazuje on na roli
użytkownika/urządzenia
3. Przełącznik dostępowy
aplikuje TAG do ruchu
użytkownika
4. Dodatkowe pola w ramkach L2
Ethernet lub propagacja
mapowania OOB przez
protokół SXP
Cisco Public 20© 2011 Cisco and/or its affiliates. All rights reserved.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Chmura prywatna / publiczna
Pracownik Spacely Sprockets
SPACELY SPROCKETS
Central Office
Database
Server
ASA Appliance
ASA1000V
VSGWeb
Server
Cisco Public 22© 2011 Cisco and/or its affiliates. All rights reserved.
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
v
Catalyst
6500
SERVICES
Centralized Security and Application
Service Modules and Appliances can be applied per zone
ASA ACE
IPS
Nexus 7018 Nexus 7018
Data Center
Distribution
Data Center Core
Internet
Edge
Nexus
5000
Series
10Gig Server Rack
Nexus
2100
Series
vPC
Zone Multi-Zone
VDC
Nexus
7000
Series
10Gig Server Rack
vPC
Unified
Computing
System
Nexus
1000V
Zone
Unified Compute
NAM
vPC vPC
vPC vPCvPCvPC
VSS
Stateful Packet
Filtering
Network Intrusion
Prevention
Server Load
Balancing
Flow Based Traffic Analysis –
Network Analysis Module
Access Edge Security
ACL, Dynamic ARP
Inspection, DHCP Snooping,
IP Source Guard, Port
Security, Private VLANs, QoS
Web and Email
Security
SAN
Network Foundation Protection
Virtual Service
Nodes
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
PLNOG 8: Gaweł Mikołajczyk - Securing the Cloud Infrastructure -  from Hypervisor to the Edge

More Related Content

PPTX
#CiscoLiveLA 2017 Presentacion de Jerome Henry
PDF
Развитие решений для коммутации в корпоративных сетях Cisco
PDF
Meraki Cloud Networking Workshop
PDF
Network Function Virtualization (NFV) using IOS-XR
PPTX
Kendel Avaya-Fabric connect - Demo Lab Guide – Macsec-9
PDF
Presentation asa 5585-x next generation multi-service adaptive security app...
PDF
MPP Phone Roadmap
#CiscoLiveLA 2017 Presentacion de Jerome Henry
Развитие решений для коммутации в корпоративных сетях Cisco
Meraki Cloud Networking Workshop
Network Function Virtualization (NFV) using IOS-XR
Kendel Avaya-Fabric connect - Demo Lab Guide – Macsec-9
Presentation asa 5585-x next generation multi-service adaptive security app...
MPP Phone Roadmap

What's hot (20)

PPTX
Cisco asa cx firwewall
PDF
Innovations in the Enterprise Routing & Switching Space
PDF
Secure collab on prem hikmat
PPT
Meg asys isms
PDF
Cisco ACI and_Ansible
PDF
10G/40G gen to 25G/100G gen, and go forward (HPVI community meetup)
PDF
Рекомендации по настройке контроллеров БЛВС Cisco
DOCX
PIX vs ASA_firewall
PDF
Maximizing Firewall Performance (2012 San Diego)
PDF
Развитие решений для маршрутизации в корпоративных сетях Cisco
PDF
Présentation cisco aci in action fundamentals - fcouderc - v6
DOCX
Cisco asa 5500 x series migration options-asa 5555-x, asa 5525-x & asa 55...
PDF
Cisco asa 5515 datasheet
PPTX
mbed Connect Asia 2016 Developing IoT devices with mbed OS 5
DOCX
Cisco catalyst 9200 series platform spec, licenses, transition guide
PDF
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
PDF
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
PPTX
Catalyst 6500 ASA Service Module
PPT
Chapter 8 overview
PDF
Application Engineered Routing: Allowing Applications to Program the Network
Cisco asa cx firwewall
Innovations in the Enterprise Routing & Switching Space
Secure collab on prem hikmat
Meg asys isms
Cisco ACI and_Ansible
10G/40G gen to 25G/100G gen, and go forward (HPVI community meetup)
Рекомендации по настройке контроллеров БЛВС Cisco
PIX vs ASA_firewall
Maximizing Firewall Performance (2012 San Diego)
Развитие решений для маршрутизации в корпоративных сетях Cisco
Présentation cisco aci in action fundamentals - fcouderc - v6
Cisco asa 5500 x series migration options-asa 5555-x, asa 5525-x & asa 55...
Cisco asa 5515 datasheet
mbed Connect Asia 2016 Developing IoT devices with mbed OS 5
Cisco catalyst 9200 series platform spec, licenses, transition guide
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
Catalyst 6500 ASA Service Module
Chapter 8 overview
Application Engineered Routing: Allowing Applications to Program the Network
Ad

Similar to PLNOG 8: Gaweł Mikołajczyk - Securing the Cloud Infrastructure - from Hypervisor to the Edge (20)

PDF
Presentation cisco data center security deep dive
PPTX
Cisco Virtualized Network Services
PDF
Cisco at v mworld 2015 theater presentation brfarnha
PDF
[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
PDF
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
PDF
Brkaci 1002
PPTX
PLNOG14: Application Centric Infrastructure Introduction - Nick Martin
PPTX
Cisco Prime infrastructure 3.0
PPTX
Show and Tell: VIRL for Network Programmability and Development
PDF
Security & Virtualization in the Data Center
PPTX
The Data Center Network Evolution
PDF
CiscoACI-BRKACI-3004presentationUploaded.pdf
PDF
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
PDF
PLNOG16: Automatyzacja kreaowania usług operatorskich w separacji od rodzaju ...
PDF
PLNOG16: Kreowanie usług przez operatorów – SP IWAN, Krzysztof Konkowski
PDF
Simplifying the secure data center
PDF
End-to-End Data Center Virtualization
PDF
Next Generation Campus Switching: Are You Ready
PPTX
Nexus 1000V Support for VMWare vSphere 6
PDF
7th SDN Expert Group Seminar - Session2
Presentation cisco data center security deep dive
Cisco Virtualized Network Services
Cisco at v mworld 2015 theater presentation brfarnha
[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Brkaci 1002
PLNOG14: Application Centric Infrastructure Introduction - Nick Martin
Cisco Prime infrastructure 3.0
Show and Tell: VIRL for Network Programmability and Development
Security & Virtualization in the Data Center
The Data Center Network Evolution
CiscoACI-BRKACI-3004presentationUploaded.pdf
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
PLNOG16: Automatyzacja kreaowania usług operatorskich w separacji od rodzaju ...
PLNOG16: Kreowanie usług przez operatorów – SP IWAN, Krzysztof Konkowski
Simplifying the secure data center
End-to-End Data Center Virtualization
Next Generation Campus Switching: Are You Ready
Nexus 1000V Support for VMWare vSphere 6
7th SDN Expert Group Seminar - Session2
Ad

Recently uploaded (20)

PPTX
Introduction-to-Food-Packaging-and-packaging -materials.pptx
PDF
Module 7 guard mounting of security pers
PPTX
Kompem Part Untuk MK Komunikasi Pembangunan 5.pptx
PPTX
chapter8-180915055454bycuufucdghrwtrt.pptx
PPTX
Phylogeny and disease transmission of Dipteran Fly (ppt).pptx
PPTX
ART-APP-REPORT-FINctrwxsg f fuy L-na.pptx
PDF
MODULE 3 BASIC SECURITY DUTIES AND ROLES.pdf
PDF
natwest.pdf company description and business model
PPTX
Research Process - Research Methods course
PDF
Unnecessary information is required for the
PDF
6.-propertise of noble gases, uses and isolation in noble gases
PPTX
PurpoaiveCommunication for students 02.pptx
PPTX
INDIGENOUS-LANGUAGES-AND-LITERATURE.pptx
PPTX
Module_4_Updated_Presentation CORRUPTION AND GRAFT IN THE PHILIPPINES.pptx
PPTX
Sustainable Forest Management ..SFM.pptx
PPTX
Bob Difficult Questions 08 17 2025.pptx
PPTX
power point presentation ofDracena species.pptx
PDF
public speaking for kids in India - LearnifyU
PDF
Tunisia's Founding Father(s) Pitch-Deck 2022.pdf
PDF
Yusen Logistics Group Sustainability Report 2024.pdf
Introduction-to-Food-Packaging-and-packaging -materials.pptx
Module 7 guard mounting of security pers
Kompem Part Untuk MK Komunikasi Pembangunan 5.pptx
chapter8-180915055454bycuufucdghrwtrt.pptx
Phylogeny and disease transmission of Dipteran Fly (ppt).pptx
ART-APP-REPORT-FINctrwxsg f fuy L-na.pptx
MODULE 3 BASIC SECURITY DUTIES AND ROLES.pdf
natwest.pdf company description and business model
Research Process - Research Methods course
Unnecessary information is required for the
6.-propertise of noble gases, uses and isolation in noble gases
PurpoaiveCommunication for students 02.pptx
INDIGENOUS-LANGUAGES-AND-LITERATURE.pptx
Module_4_Updated_Presentation CORRUPTION AND GRAFT IN THE PHILIPPINES.pptx
Sustainable Forest Management ..SFM.pptx
Bob Difficult Questions 08 17 2025.pptx
power point presentation ofDracena species.pptx
public speaking for kids in India - LearnifyU
Tunisia's Founding Father(s) Pitch-Deck 2022.pdf
Yusen Logistics Group Sustainability Report 2024.pdf

PLNOG 8: Gaweł Mikołajczyk - Securing the Cloud Infrastructure - from Hypervisor to the Edge

  • 1. Cisco Public 1© 2011 Cisco and/or its affiliates. All rights reserved. Securing the Cloud Infrastructure – from Hypervisorto the Edge Gaweł Mikołajczyk gmikolaj@cisco.com Security Consulting Systems Engineer EMEA Central Core Team CCIE #24987, CISSP-ISSAP, CISA PLNOG8, March 5, 2012, Warsaw, Poland
  • 2. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 2 Policy Corporate Border Branch Office Applications and Data Corporate Office Home Office Attackers Coffee ShopCustomers Airport Mobile User Partners Platform as a Service Infrastructure as a Service X as a Service Software as a Service Trzy wymiary : dla Infrastruktury w chmurze, dla dostępu do chmury, komercyjne usługi bezpieczeństwa w chmurze.
  • 3. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 3 Prywatny VPN MPLS lub IPSec / SSL NEXUS 1000v NAS Data Center Core Tenant A Tenant B Sub Tenant B1 i B2 WAN Compute Dostęp Usługi Agregacja Edge Dostęp L2 lub L3 Tenant per VRF Mapowanie VRF / VLAN do vFW/LB VRF do unikalnego VLAN Mapowanie do VM
  • 4. Cisco Public 4© 2011 Cisco and/or its affiliates. All rights reserved.
  • 5. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 5 VMNIC #1 vEth vEth Virtualization Security V-Motion (Memory) V-Storage (VMDK) VM Segmentation Hypervisor Security Role Based Access Physical Security VM OS Hardening Patch Management VM Sprawl VMNIC #2 Real case: [...] It looks the O&M firewall is not filtering the ARP traffic the right way. This allows a VM to connect to any other VM through the O&M network after injecting malicious ARP traffic. This happens even if the destination VM belongs to a different tenant VDC [...]
  • 6. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 6 Warstwa dostępu wirtualnego powinna oferować przynajmniej takie same mechanizmy bezpieczeństwa Layer-2 jak w fizycznym DataCenter : Access Lists, Dynamic ARP Inspection, DHCP Snooping, IP Source Guard, Port Security, Private VLANs, Layer-2 storm control, Rate-Limiters, VXLAN Bez tych mechanizmów, konsekwencje ataków na infrastruktuę sieciową, (biorąc pod uwagę skalę - tysiące VM) są katastrofalne. Widoczność w warstwie 2 można osiągnąć przez: NetFlow Collection SPAN, RSPAN or ERSPAN 1/ 7
  • 7. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 7 port-profile vm180 vmware port-group pg180 switchport mode access switchport access vlan 180 ip flow monitor ESE-flow input ip flow monitor ESE-flow output no shutdown state enabled interface Vethernet9 inherit port-profile vm180 interface Vethernet10 inherit port-profile vm180 Port Profile –> Port Group vCenter API
  • 8. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 8 10.20.20.50 10.20.30.10110.20.20.51 vPC Peer-link VSL vPC Service VLANs Nexus 1000V and VSG Nexus 7000 Nexus 5000 ESX Server ASA 5585 Cat 6500 monitor session 2 type erspan- source description N1k ERSPAN –session 2 monitor session 4 type erspan- destination description N1k ERSPAN to IDS1 monitor session 1 type erspan- source description N1k ERSPAN – session 1 monitor session 3 type erspan- destination description N1k ERSPAN to NAM NAM
  • 9. Cisco Public 9© 2011 Cisco and/or its affiliates. All rights reserved.
  • 10. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 10 Hypervisor Appliance i moduły fizyczne Konteksty wirtualne VLANs Hypervisor Przekierowanie ruchu z VM do fizycznych urządzeń 1 App Server Database Server Web Server Usługi bezpieczeństwa na poziomie hypervisora 2 App Server Database Server Web Server VSN Appliance wirtualne VSN
  • 11. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 11 Sandwich usługowy między VDC • ASA Service Module Konteksty wirtualne Tryb Transparentny / mixed • ACE LB Tryb transparentny • Web Application Firewall Farma firewalli • Network IPS/IDS Inline lub promiscuous N7k1-VDC1 N7k1-VDC2 ASA-SM 2 ASA-SM 1 ACE hsrp.1 IPS 162 161 163,164 WAF 190 SS1 SVI-151 vrf1 vrf2
  • 12. Cisco Public 12© 2011 Cisco and/or its affiliates. All rights reserved.
  • 13. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 13 Security Administrator Port Group Service Administrator Virtual Network Management Center Virtual Security Gateway - VSG Cisco Nexus® 1000V z mechanizmem vPath • Rozproszony przełącznik • Część hypervisora Host • Cisco UCS • Other x86 server
  • 14. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 14 Nexus 1000V Distributed Virtual Switch VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VMVM VM vPath VNMC Log/Audit Początkowy flow VSG 1 Początkowa ewaluacja polityki 2 Cache decyzji 3 4 1 2 3 4
  • 15. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 15 Nexus 1000V Distributed Virtual Switch VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VMVM VM vPath VNMC Log/Audit VSG Pozostałe pakiety ACL offload do Nexus 1000V (wymuszenie polityki)
  • 16. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 16 VSG: Security Profile to Port Profile
  • 17. Cisco Public 17© 2011 Cisco and/or its affiliates. All rights reserved.
  • 18. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 18 Egress SGT=100 Pracownik, grupa HR HR (SGT=100) Ingress SGT Finance (SGT=4) 802.1X/MAB/Web Auth HR SGT = 100 SGACL • TrustSec to rozwiązanie o charakterze systemowym • Overlayowe tagowanie SGT na wejściu do sieci LAN/WAN/VPN • Wymuszenie polityki bezpieczeństwa przez SGACL na wyjściu • Centralnie przechowywane reguły SGT/SGACL dają spójność
  • 19. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 19 TAG oparty o rolę: 1. Urządzenie uwierzytelnia się do sieci via 802.1X 2. ISE wysyła TAG jako wynik autoryzacji – bazuje on na roli użytkownika/urządzenia 3. Przełącznik dostępowy aplikuje TAG do ruchu użytkownika 4. Dodatkowe pola w ramkach L2 Ethernet lub propagacja mapowania OOB przez protokół SXP
  • 20. Cisco Public 20© 2011 Cisco and/or its affiliates. All rights reserved.
  • 21. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 21 Chmura prywatna / publiczna Pracownik Spacely Sprockets SPACELY SPROCKETS Central Office Database Server ASA Appliance ASA1000V VSGWeb Server
  • 22. Cisco Public 22© 2011 Cisco and/or its affiliates. All rights reserved.
  • 23. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 23 v Catalyst 6500 SERVICES Centralized Security and Application Service Modules and Appliances can be applied per zone ASA ACE IPS Nexus 7018 Nexus 7018 Data Center Distribution Data Center Core Internet Edge Nexus 5000 Series 10Gig Server Rack Nexus 2100 Series vPC Zone Multi-Zone VDC Nexus 7000 Series 10Gig Server Rack vPC Unified Computing System Nexus 1000V Zone Unified Compute NAM vPC vPC vPC vPCvPCvPC VSS Stateful Packet Filtering Network Intrusion Prevention Server Load Balancing Flow Based Traffic Analysis – Network Analysis Module Access Edge Security ACL, Dynamic ARP Inspection, DHCP Snooping, IP Source Guard, Port Security, Private VLANs, QoS Web and Email Security SAN Network Foundation Protection Virtual Service Nodes
  • 24. © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 24