SlideShare a Scribd company logo
Securely Connecting Customers’ Sites
To Your Cloud Hosted Apps – In Minutes
AWS Bootcamp #6 – May 24, 2018
Sherry Wei, Founder & CTO
Neel Kamal, Head of Field Operations
Frank Cabri, VP Product Marketing
© 2018 AVIATRIX SYSTEMS, INC. | 2
• Use Cases for App Providers
• Understanding the Challenges of
Customer On-Boarding
- Connectivity
- Operational Readiness
- Security & Compliance
• Demo
• Live Q & A
Welcome & Agenda
SHERRY WEI
Founder & CTO
NEEL KAMAL
Head of Field Operations
FEATURED SPEAKERS
© 2018 AVIATRIX SYSTEMS, INC. | 3
Check Out More Bootcamps – Available On-Demand
www.aviatrix.com/bootcamps
© 2018 AVIATRIX SYSTEMS, INC. | 4
Networking Use Cases for Hosted Apps Providers
AND
Managing Your Internal
PaaS Operation
Onboarding Your Customers
Customers
YOU
Users
© 2018 AVIATRIX SYSTEMS, INC. | 5
1. Connectivity Challenges
- Building IPsec connectivity to the customer environment
- Handling overlapping CIDR blocks
- Supporting connectivity from the hosted environment to customer environment,
which can be on-prem, AWS, Azure, Google Cloud, etc.
2. Operational Challenges
- Lack of monitoring/insights into customer experience: latency, performance
- Lack of alerting and troubleshooting ability
- Lack of automation, which leads to delays and errors
3. Security & Compliance Challenges
- Policy-based, remote user access to separate internal staff from customer staff
- Isolate and segmenting VPCs to tighten the security perimeter and reduce audit scope
Challenges in Connecting Customers’ Sites to Cloud Hosted Apps
Onboarding Your Customers
Customers
YOU
Users
© 2018 AVIATRIX SYSTEMS, INC. | 6
Challenges in Connecting Customers’ Sites to Cloud Hosted Apps
3. Security & Compliance 2. Operational Readiness
1. Connectivity
© 2018 AVIATRIX SYSTEMS, INC. | 7
Why Is It So Complex?
- Requires involving customers’ network & security teams
- Hits customers’ change control process when touching an edge device
(for IPsec) and their perimeter security appliance
- Requires your team to have expertise on a variety of customer edge routers
What Does AWS/Azure Provide Natively?
- AWS Virtual GW (VGW) & Azure VPN
What’s Missing?
- AWS VPN Gateway Limitation (supports 10 connections per VPC.)
- Azure VPN Gateway Limitation (supports only 1 VPN connection for IKEv1)
- Overlapping IP addresses
- Traffic Direction Problem
- Encryption Algorithm Mismatch
1. Connectivity Considerations
© 2018 AVIATRIX SYSTEMS, INC. | 8
Why Is It So Complex?
- No visibility into your customer’s environment
- Requires deep network expertise by the internal staff who supports connectivity to the
customer environment (BGP, IPsec)
- Committed SLAs impossible to prove
What Does AWS/Azure Provide Natively?
- No tools
What’s Missing?
- No Visibility: Cloud provider’s VPN gateway is a blackbox, there is no visibility
- Automated Configuration: manually configuring traditional vRouter for 100s of IPSEC
tunnel is not possible)
- Too Slow to Onboard a Customer: VPN runs on UDP port 500/4500 which require
opening corporate firewall ports)
- Downtime Problem: When you add new IPsec tunnel, it will reset all existing tunnels
2. Operational Considerations
© 2018 AVIATRIX SYSTEMS, INC. | 9
Why Is It So Complex?
- Giving customer users/groups limited access to your cloud-
hosted app is just hard
- SOC2-compliant reports (“who accessed what, at what time”) is
even harder
What Does AWS Provide Natively?
- No AWS-native services
What’s Missing?
- A cloud-native User VPN solution
- Profile-based access control with MFA
- Audit logs that are exportable to your tool of choice
3. Security and Compliance Considerations for Remote Users
© 2018 AVIATRIX SYSTEMS, INC. | 10
• A communication module that you can include with your product to your
customers:
• Works in every type of customer environment: data center, private cloud, etc.
• Does not require changes to edge routers or security appliances (opening ports)
• Can sit inside the DMZ
• Supports both IPsec and SSL termination
• Provisioning and configuring these modules can be automated centrally
• Does not require deep network expertise on your site as well as on your
customer site
A Better Approach for Connecting Customers’ Sites to Cloud-
Hosted Apps
© 2018 AVIATRIX SYSTEMS, INC. | 11
• You’ll receive email w/ a
link to a replay and slides
• Take 10 minutes and start
a free 14-day trial ….
https://www.aviatrix.com
• To view other bootcamps:
https://www.aviatrix.com/bootcamps
Next Steps with Aviatrix

More Related Content

PDF
Securing Your AWS Global Transit Network: Are You Asking the Right Questions?
PDF
Five Connectivity and Security Use Cases for Azure VNets
PDF
Seven Criteria for Building an AWS Global Transit Network
PDF
Security Requirements and Tradeoffs for Controlling VPC-to-Internet Egress Tr...
PPTX
Getting the Most Value from Your Aviatrix Controller & Gateways
PDF
Three Innovations that Define a “Next-Generation Global Transit Hub”
PDF
Secure Remote Access to AWS: Why OpenVPN & Jump Hosts Aren’t Enough
PDF
Network Troubleshooting in the Cloud: Tools, Techniques and Gotchas
Securing Your AWS Global Transit Network: Are You Asking the Right Questions?
Five Connectivity and Security Use Cases for Azure VNets
Seven Criteria for Building an AWS Global Transit Network
Security Requirements and Tradeoffs for Controlling VPC-to-Internet Egress Tr...
Getting the Most Value from Your Aviatrix Controller & Gateways
Three Innovations that Define a “Next-Generation Global Transit Hub”
Secure Remote Access to AWS: Why OpenVPN & Jump Hosts Aren’t Enough
Network Troubleshooting in the Cloud: Tools, Techniques and Gotchas

What's hot (20)

PDF
What You Need to Know About Operationalizing Your AWS Transit Hub
PDF
Understanding the New Enterprise Multi-Cloud Backbone for DevOps Engineers
PDF
How Intuit Monitors Connectivity to AWS
PDF
Demystifying Service Mesh
PDF
CDN Performance at eBay from Thousandeyes Connect
PDF
Cisco IT and ThousandEyes
PDF
Network monitoring for the modern wan webinar
PPTX
Centurylink - Acceleration and securing modern applications!
PDF
Istio Service Mesh
PPTX
The Internet of things for integration people - UKCSUG - public version
PPTX
WWT: NFV Solutions Presentation from Cisco Live 2017
PPTX
VPC and Datacenter Connectivity Options
PDF
How ThousandEyes Helps Atlassian Operate in the Public Cloud
PDF
Getting Started with Kubernetes and Consul
PDF
Layer 7 Observability and Centralized Configuration with Consul Service Mesh
PDF
apidays LIVE Paris - Serverless security: how to protect what you don't see? ...
PDF
NGINX DevSecOps Workshop
PDF
Automating Performance Monitoring at Microsoft
PPTX
Gain multi-cloud versatility with software load balancing designed for cloud-...
PDF
Visibility for a Global Network
What You Need to Know About Operationalizing Your AWS Transit Hub
Understanding the New Enterprise Multi-Cloud Backbone for DevOps Engineers
How Intuit Monitors Connectivity to AWS
Demystifying Service Mesh
CDN Performance at eBay from Thousandeyes Connect
Cisco IT and ThousandEyes
Network monitoring for the modern wan webinar
Centurylink - Acceleration and securing modern applications!
Istio Service Mesh
The Internet of things for integration people - UKCSUG - public version
WWT: NFV Solutions Presentation from Cisco Live 2017
VPC and Datacenter Connectivity Options
How ThousandEyes Helps Atlassian Operate in the Public Cloud
Getting Started with Kubernetes and Consul
Layer 7 Observability and Centralized Configuration with Consul Service Mesh
apidays LIVE Paris - Serverless security: how to protect what you don't see? ...
NGINX DevSecOps Workshop
Automating Performance Monitoring at Microsoft
Gain multi-cloud versatility with software load balancing designed for cloud-...
Visibility for a Global Network
Ad

Similar to Securely Connecting Your Customers to Their Cloud-Hosted App – In Minutes (20)

PPTX
Citrix Synergy 2014 - Syn231 Why cloud projects fail
PDF
Primend Praktiline Konverents - Rakenduse keskne IT infrastruktuur / Cisco Ap...
PPTX
VM Farms Thrive with Dedicated IP Storage Networks
PDF
Check Point and Accenture Webinar
PPTX
Faster, simpler, more secure remote access to apps in aws
PPTX
What's New? ThousandEyes Product Features and Highlights
PDF
CNCF On-Demand Webinar_ LitmusChaos Project Updates.pdf
PPTX
Nieuwe onderwijs- en onderzoekstoepassingen door slimme wifi-netwerken - Roy ...
PDF
ciscothousandeyesusecase
PPTX
Getting Started With ThousandEyes Proof of Concepts: End User Digital Experience
PDF
Get the Most Out of Kubernetes with NGINX
PDF
VMworld 2013: NSX PCI Reference Architecture Workshop Session 3 - Operational...
PPTX
From Pivotal to VMware Tanzu: What you need to know
PPTX
APJC Introduction to ThousandEyes Webinar
PPTX
PCI DSS Compliance in the Cloud
PPTX
Getting Started with ThousandEyes Proof of Concepts
PDF
VMware Workspace ONE a synergie s Microsoftem
PDF
2025-07-15 EMEA Volledig Inzicht Dutch Webinar
PPTX
Getting Started with ThousandEyes Proof of Concepts
PDF
Cisco Connect Ottawa 2018 multi cloud
Citrix Synergy 2014 - Syn231 Why cloud projects fail
Primend Praktiline Konverents - Rakenduse keskne IT infrastruktuur / Cisco Ap...
VM Farms Thrive with Dedicated IP Storage Networks
Check Point and Accenture Webinar
Faster, simpler, more secure remote access to apps in aws
What's New? ThousandEyes Product Features and Highlights
CNCF On-Demand Webinar_ LitmusChaos Project Updates.pdf
Nieuwe onderwijs- en onderzoekstoepassingen door slimme wifi-netwerken - Roy ...
ciscothousandeyesusecase
Getting Started With ThousandEyes Proof of Concepts: End User Digital Experience
Get the Most Out of Kubernetes with NGINX
VMworld 2013: NSX PCI Reference Architecture Workshop Session 3 - Operational...
From Pivotal to VMware Tanzu: What you need to know
APJC Introduction to ThousandEyes Webinar
PCI DSS Compliance in the Cloud
Getting Started with ThousandEyes Proof of Concepts
VMware Workspace ONE a synergie s Microsoftem
2025-07-15 EMEA Volledig Inzicht Dutch Webinar
Getting Started with ThousandEyes Proof of Concepts
Cisco Connect Ottawa 2018 multi cloud
Ad

Recently uploaded (20)

PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
Big Data Technologies - Introduction.pptx
PDF
Approach and Philosophy of On baking technology
PDF
Machine learning based COVID-19 study performance prediction
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Electronic commerce courselecture one. Pdf
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
MIND Revenue Release Quarter 2 2025 Press Release
Building Integrated photovoltaic BIPV_UPV.pdf
Network Security Unit 5.pdf for BCA BBA.
20250228 LYD VKU AI Blended-Learning.pptx
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
The AUB Centre for AI in Media Proposal.docx
Chapter 3 Spatial Domain Image Processing.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Review of recent advances in non-invasive hemoglobin estimation
Big Data Technologies - Introduction.pptx
Approach and Philosophy of On baking technology
Machine learning based COVID-19 study performance prediction
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Per capita expenditure prediction using model stacking based on satellite ima...
Empathic Computing: Creating Shared Understanding
Electronic commerce courselecture one. Pdf
Dropbox Q2 2025 Financial Results & Investor Presentation
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
The Rise and Fall of 3GPP – Time for a Sabbatical?

Securely Connecting Your Customers to Their Cloud-Hosted App – In Minutes

  • 1. Securely Connecting Customers’ Sites To Your Cloud Hosted Apps – In Minutes AWS Bootcamp #6 – May 24, 2018 Sherry Wei, Founder & CTO Neel Kamal, Head of Field Operations Frank Cabri, VP Product Marketing
  • 2. © 2018 AVIATRIX SYSTEMS, INC. | 2 • Use Cases for App Providers • Understanding the Challenges of Customer On-Boarding - Connectivity - Operational Readiness - Security & Compliance • Demo • Live Q & A Welcome & Agenda SHERRY WEI Founder & CTO NEEL KAMAL Head of Field Operations FEATURED SPEAKERS
  • 3. © 2018 AVIATRIX SYSTEMS, INC. | 3 Check Out More Bootcamps – Available On-Demand www.aviatrix.com/bootcamps
  • 4. © 2018 AVIATRIX SYSTEMS, INC. | 4 Networking Use Cases for Hosted Apps Providers AND Managing Your Internal PaaS Operation Onboarding Your Customers Customers YOU Users
  • 5. © 2018 AVIATRIX SYSTEMS, INC. | 5 1. Connectivity Challenges - Building IPsec connectivity to the customer environment - Handling overlapping CIDR blocks - Supporting connectivity from the hosted environment to customer environment, which can be on-prem, AWS, Azure, Google Cloud, etc. 2. Operational Challenges - Lack of monitoring/insights into customer experience: latency, performance - Lack of alerting and troubleshooting ability - Lack of automation, which leads to delays and errors 3. Security & Compliance Challenges - Policy-based, remote user access to separate internal staff from customer staff - Isolate and segmenting VPCs to tighten the security perimeter and reduce audit scope Challenges in Connecting Customers’ Sites to Cloud Hosted Apps Onboarding Your Customers Customers YOU Users
  • 6. © 2018 AVIATRIX SYSTEMS, INC. | 6 Challenges in Connecting Customers’ Sites to Cloud Hosted Apps 3. Security & Compliance 2. Operational Readiness 1. Connectivity
  • 7. © 2018 AVIATRIX SYSTEMS, INC. | 7 Why Is It So Complex? - Requires involving customers’ network & security teams - Hits customers’ change control process when touching an edge device (for IPsec) and their perimeter security appliance - Requires your team to have expertise on a variety of customer edge routers What Does AWS/Azure Provide Natively? - AWS Virtual GW (VGW) & Azure VPN What’s Missing? - AWS VPN Gateway Limitation (supports 10 connections per VPC.) - Azure VPN Gateway Limitation (supports only 1 VPN connection for IKEv1) - Overlapping IP addresses - Traffic Direction Problem - Encryption Algorithm Mismatch 1. Connectivity Considerations
  • 8. © 2018 AVIATRIX SYSTEMS, INC. | 8 Why Is It So Complex? - No visibility into your customer’s environment - Requires deep network expertise by the internal staff who supports connectivity to the customer environment (BGP, IPsec) - Committed SLAs impossible to prove What Does AWS/Azure Provide Natively? - No tools What’s Missing? - No Visibility: Cloud provider’s VPN gateway is a blackbox, there is no visibility - Automated Configuration: manually configuring traditional vRouter for 100s of IPSEC tunnel is not possible) - Too Slow to Onboard a Customer: VPN runs on UDP port 500/4500 which require opening corporate firewall ports) - Downtime Problem: When you add new IPsec tunnel, it will reset all existing tunnels 2. Operational Considerations
  • 9. © 2018 AVIATRIX SYSTEMS, INC. | 9 Why Is It So Complex? - Giving customer users/groups limited access to your cloud- hosted app is just hard - SOC2-compliant reports (“who accessed what, at what time”) is even harder What Does AWS Provide Natively? - No AWS-native services What’s Missing? - A cloud-native User VPN solution - Profile-based access control with MFA - Audit logs that are exportable to your tool of choice 3. Security and Compliance Considerations for Remote Users
  • 10. © 2018 AVIATRIX SYSTEMS, INC. | 10 • A communication module that you can include with your product to your customers: • Works in every type of customer environment: data center, private cloud, etc. • Does not require changes to edge routers or security appliances (opening ports) • Can sit inside the DMZ • Supports both IPsec and SSL termination • Provisioning and configuring these modules can be automated centrally • Does not require deep network expertise on your site as well as on your customer site A Better Approach for Connecting Customers’ Sites to Cloud- Hosted Apps
  • 11. © 2018 AVIATRIX SYSTEMS, INC. | 11 • You’ll receive email w/ a link to a replay and slides • Take 10 minutes and start a free 14-day trial …. https://www.aviatrix.com • To view other bootcamps: https://www.aviatrix.com/bootcamps Next Steps with Aviatrix