SlideShare a Scribd company logo
The DNS of Things 
Peter Silva 
Sr. Technical Marketing Manager 
@psilvas 
Q. WHERE IS 
WWW.F5.COM? 
A. 
2001:19b8:10 
1:2::f5f5:1d
SDDC/Cloud 
Mobility 
Advanced 
threats 
Internet of 
Things 
“Software defined” 
everything 
HTTP is the 
new TCP 
© F5 Netw©or kFs5, INnectworks, Inc Confidential 2
Internet Foundation? DNS 
DNS DEMANDS 
More 
People 
Mobile 
devices/apps 
Complex 
sites 
Cloud 
implementation 
s 
IPv6 added 
with IPv4 
WHEN DNS BREAKS EVERYTHING 
BREAKS 
DOMAIN NAME SYSTEM (DNS) 
Translates a domain name… 
http://www.google.com 
into an IP address: 
74.125.227.64 (IPv4) 
http://www.f5.com = 
2001:19b8:101:2::f5f5:1d 
(IPv6) 
Increased 
latency 
DDoS 
attacks 
© F5 Networks, Inc 3
Everything: DNS 
• Internet of Things needs scalable DNS 
services* 
• Combination = 5 to 10 times Internet 
revolution** 
• 10bil devices in 2014 = 77bil mobile apps** 
• 35% Y/Y DNS query increase*** 
• Ensure really fast connections and responses* 
DNS 
Look 
Ups 
© F5 Networks, Inc 4
Demand: DNS 
AVERAGE DAILY LOAD FOR DNS (.COM/.NET 
TLDS) QUERIES IN BILLIONS 
82 
77 
43 
50 
57 
‘09 ‘10 ‘11 ‘12 ‘13 
DNSSEC DEPLOYMENT EXPANDING 
TYPICAL FOR A SINGLE WEB PAGE TO 
CONSUME 100+ DNS QUERIES FROM ACTIVE 
CONTENT, ADVERTISING, AND ANALYTICS 
SECOND MOST ATTACKED PROTOCOL 
GLOBAL MOBILE DATA (4G/LTE) IS DRIVING 
THE NEED FOR FAST, AVAILABLE DNS 
18X Growth 2011-2016 
4G LTE 
2.4GB 
/mo 
DISTRIBUTED, AVAILABLE, HIGH-PERFORMANCE 
GSLB FOR 
MULTIPLE DATA CENTERS 
Non-4G LTE 
86MB 
/mo 
Reflection/amplification DDoS 
Cache poisoning attacks 
Drive for DNSSEC adoption 
Total service availability 
Geographically dispersed DCs 
DNS capacity close to subscribers 
82 
© F5 Networks, Inc 5
Growth of Nouns 
2013:80 
2014:100 
2020:250 
152 
Million 
Cars 
© F5 Networks, Inc 6
Growth of Sensors 
© F5 Networks, Inc 7
The Earth’s Connected Devices 
© F5 Networks, Inc 8
Critical: DNS 
76% are willing to wait 
10 seconds or less 
for a single web page 
to load on Mobile phone 
before leaving. 
Every 100ms delay 
Costs Amazon 
1% in sales. 
As of December 2013, 
there were over 
184 million active websites, 
a growth of 157% 
over the last 5 years. 
2013 
2013 
2009 157% 
2009 DNS has grown 
over 91% 
in the last 5 years. 
© F5 Networks, Inc 9
DNS Deployments 
• Performance = Add DNS 
boxes 
• Weak DoS/DDoS Protection 
• Firewall is THE bottleneck 
• Massive performance over 
10M RPS! 
• Best DoS/DDoS protection 
• Lower CapEx and OpEx 
CONVENTIONAL DNS 
THINKING 
External 
Firewall 
DNS DELIVERY 
REIMAGINED 
Internet 
DNS Load 
Balancing 
Array of DNS 
Servers 
Internal 
Firewall 
Hidden 
Master DNS 
DMZ Datacenter 
DNS Firewall 
DNS DDoS Protection 
Protocol Validation 
Authoritative DNS 
Caching Resolver 
Transparent Caching 
High Performance DNSSEC 
DNSSEC Validation 
Intelligent GSLB 
PARADIGM SHIFT 
Internet 
Master DNS 
Infrastructure 
BIG-IP 
© F5 Networks, Inc 10
• Delivers High-speed response & DDoS protection with in-memory 
• Authoritative DNS served out of RAM. 
• Configuration size for tens of millions of records. 
• Scale and consolidate DNS servers. 
DNS in DMZ 
Answer 
DNS 
Query 
Answer 
DNS 
Query 
Answer 
DNS 
Query 
Answer 
DNS 
Query 
DNS Server 
Answer 
DNS 
Query 
Efficient DNS 
DNS. 
Clients 
Internet 
OS 
Manage 
DNS 
Records 
Admin 
Auth 
Roles 
NIC 
Dynamic 
DNS 
DHCP 
© F5 Networks, Inc 12
Optimized DNS 
Easy integration into existing 
DNS infrastructure for high 
availability and security 
Support over 10 million DNS 
responses per second (RPS) 
Manageable and predictable 
data center utilization 
© F5 Networks, Inc 13
The DNS Value 
SCALABLE UP TO 20X 
6 
3 
0 
Low Query Query Growth Query Spike Query Decline 
Max 
DNS 
DENIAL OF SERVICE MITIGATION 
SUPPORT CLIENT REQUESTS AND CONSOLIDATE IT 
IPv6 to IPv4 
COMPLETE DNS CONTROL 
Access 
Denied: 
ROUTE BASED ON GEOLOCATION 
SECURE DNS QUERY RESPONSES 
http://f5.com 
© F5 Networks, Inc 14
Market Pulse Research: Managing DNS Capacity 
Key Findings 
• Respondents most frequently cite improved application availability and application performance 
(speed) as highly important benefits of DNS. 
• A majority (63%) report that their organizations’ DNS volume has increased over the past year. 
• Contributing factors: rollout of new services, applications. Cloud migration and traffic spikes. 
• Most often, organizations manage DNS capacity by adding more servers (53%) and/or adding 
more bandwidth (36%). Average of 24 DNS servers in use. 
• With regard to current DNS implementations, outages are the top concern (70% highly 
concerned). 
• Most concerning consequences: loss of productivity and a poor customer experience. 
• Nearly one-third of respondents (29%) report their organizations have experienced DNS outages 
in the past 12 months. Culprit? One-quarter of these (25%) report a traffic surge. 
• Among those who indicate their organizations are planning to expand DNS services to the cloud, 
increasing capacity is the most common driver. On-premise DNS primary case over the next year. Use of 
public cloud DNS slight increase in next 12 months. 
© F5 Networks, Inc 16
The Five Takeaways 
Scalability: In times of high traffic, enterprises’ DNS servers must be able to handle shifting volumes of traffic. 
Security: Denial-of-service attacks frequently target IP addresses that cause DNS server outages. 
Intelligence: To be protective, IT must be proactive. That means being able to pinpoint application or service delivery 
accuracy, based on location of users, with geolocation services. 
Manageability: Enterprises need visibility into DNS services across cloud and on-premises networks, in order to ensure 
uptime and performance. IT also needs to be able to identify unusual activity that may indicate probing for vulnerabilities. 
Reliability: With more customers accessing corporate web sites, DNS server performance has the potential to impact user 
experience and employee productivity. Given these trends, DNS servers must be extremely reliable. 
© F5 Networks, Inc 17
Story Arch 
deviantart.net 
© F5 Networks, Inc 18
admissions.tufts.edu 
© F5 Networks, Inc 19
DNS Story Arc 
Complication 
Introduction 
Denouement 
Climax 
Body 
Add Infrastructure 
DNS Traffic 
Market Conditions 
ADC 
Peace of Mind 
© F5 Networks, Inc 20
Intelligent & Secure DNS that Scales 
• Scale and manage DNS and apps globally 
• Improve application performance and availability 
• Robust, Flexible and Secure DNS Infrastructure 
• Mitigate DNS DDoS Attacks 
• Support hybrid IP Environments 
• Complete DNS Security 
© F5 Networks, Inc 21
Intelligent DNS Scale 
PROTECTS 
Web Properties and 
Brand Reputation. 
LOWERS 
Stress of DNS Outages. 
DIRECTS 
Customers to the best data 
center or cloud. 
REDUCES 
Data center costs. 
IMPROVES 
Web application 
performance. 
© F5 Networks, Inc 22
The F5 DNS Reference 
Architecture 
f5.com/solutions 
@f5networks 
Explore 
© F5 Networks, Inc 23
The DNS of Things

More Related Content

PPTX
F5 DNS Solution for CSPs
PPTX
F5 Networks Intelligent DNS Scale
PPTX
DNS Security (DNSSEC) With BIG-IP Global Traffic Manager
PPTX
F5 and Infoblox deliver complete secured DNS infrastructure
PPTX
F5's Dynamic DNS Services
PDF
PLNOG15 :Scale and Secure the Internet of Things with Intelligent DNS Services
PPTX
How to Reduce Latency with Cloudflare Argo Smart Routing
PPT
BIG IP F5 GTM Presentation
F5 DNS Solution for CSPs
F5 Networks Intelligent DNS Scale
DNS Security (DNSSEC) With BIG-IP Global Traffic Manager
F5 and Infoblox deliver complete secured DNS infrastructure
F5's Dynamic DNS Services
PLNOG15 :Scale and Secure the Internet of Things with Intelligent DNS Services
How to Reduce Latency with Cloudflare Argo Smart Routing
BIG IP F5 GTM Presentation

What's hot (20)

PDF
Big Ip Global Traffic Manager Ds
PDF
F5 GTM HEALTH CHECKS
PDF
65% Performance Gains at Cryptocurrency Platform CoinGecko: An Argo Smart Rou...
PDF
Wp ipam infoblox
PDF
F5 Synthesis Toronto February 2014 Roadshow
PDF
Presentation network design and security for your v mware view deployment w...
PDF
How CDNs Can improve Mobile Application Performance
PPTX
Big Data for Security
PPTX
How to choose the right IPAM for your organization final
PDF
Why Many Websites are still Insecure (and How to Fix Them)
PPTX
F5 Solutions for Service Providers
PPTX
Managed dns webinar 2015 internap
PPTX
Filling the Gaps in Your DDoS Mitigation Strategy
PPTX
F5 Meetup presentation automation 2017
PDF
What You Should Know Before The Next DDoS Attack
PPTX
Latest Trends in Web Application Security
PDF
F5 DDoS Protection
PDF
ThousandEyes Alerting Essentials for Your Network
PPTX
IP Address Conflict
PDF
New Products Overview: Use Cases and Demos
Big Ip Global Traffic Manager Ds
F5 GTM HEALTH CHECKS
65% Performance Gains at Cryptocurrency Platform CoinGecko: An Argo Smart Rou...
Wp ipam infoblox
F5 Synthesis Toronto February 2014 Roadshow
Presentation network design and security for your v mware view deployment w...
How CDNs Can improve Mobile Application Performance
Big Data for Security
How to choose the right IPAM for your organization final
Why Many Websites are still Insecure (and How to Fix Them)
F5 Solutions for Service Providers
Managed dns webinar 2015 internap
Filling the Gaps in Your DDoS Mitigation Strategy
F5 Meetup presentation automation 2017
What You Should Know Before The Next DDoS Attack
Latest Trends in Web Application Security
F5 DDoS Protection
ThousandEyes Alerting Essentials for Your Network
IP Address Conflict
New Products Overview: Use Cases and Demos
Ad

Similar to The DNS of Things (20)

PPTX
The DNS of Things
PPTX
Intelligent DNS Scale
PPTX
F5 Intelligent DNS Scale
PDF
Building Resilient Applications with Cloudflare DNS
PDF
DNS Made Easy Sales Brochure
PPTX
IT-as-a-Service - BlueCat @ NUBIT 2017
PPT
Ultra Dns Overview Presentation
PDF
f5_synthesis_cisco_connect.pdf
PDF
Thinking about SDN and whether it is the right approach for your organization?
PDF
Plnog 3: Zbigniew Skurczyński - Wirtualizacja i optymalizacja infrastruktury
PPTX
Spider & F5 Round Table - Application Centric Security
PPTX
DNS and Infrastracture DDoS Protection
PPTX
F5 Networks - парадная дверь в облака
PDF
Akamai Korea - Tech Day (2015/03/11) DNS
PPT
Presentation riverbed steelhead appliance main 2010
PPT
ABCD's of WAN Optimization
PPTX
How to Guarantee High Performance for Application Data in the Cloud
PDF
EfficientIP webinar mitigate dns zero day vulnerability
PPTX
F5 GOV Round Table - Application Centeric Security
PDF
Denial of Service - Service Provider Overview
The DNS of Things
Intelligent DNS Scale
F5 Intelligent DNS Scale
Building Resilient Applications with Cloudflare DNS
DNS Made Easy Sales Brochure
IT-as-a-Service - BlueCat @ NUBIT 2017
Ultra Dns Overview Presentation
f5_synthesis_cisco_connect.pdf
Thinking about SDN and whether it is the right approach for your organization?
Plnog 3: Zbigniew Skurczyński - Wirtualizacja i optymalizacja infrastruktury
Spider & F5 Round Table - Application Centric Security
DNS and Infrastracture DDoS Protection
F5 Networks - парадная дверь в облака
Akamai Korea - Tech Day (2015/03/11) DNS
Presentation riverbed steelhead appliance main 2010
ABCD's of WAN Optimization
How to Guarantee High Performance for Application Data in the Cloud
EfficientIP webinar mitigate dns zero day vulnerability
F5 GOV Round Table - Application Centeric Security
Denial of Service - Service Provider Overview
Ad

Recently uploaded (20)

PDF
Tenda Login Guide: Access Your Router in 5 Easy Steps
PPTX
presentation_pfe-universite-molay-seltan.pptx
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PPTX
Introduction to Information and Communication Technology
DOCX
Unit-3 cyber security network security of internet system
PPTX
QR Codes Qr codecodecodecodecocodedecodecode
PDF
Sims 4 Historia para lo sims 4 para jugar
PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PDF
Triggering QUIC, presented by Geoff Huston at IETF 123
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PPTX
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
PPTX
Internet___Basics___Styled_ presentation
PPTX
SAP Ariba Sourcing PPT for learning material
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PPT
tcp ip networks nd ip layering assotred slides
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PPTX
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
PPTX
Funds Management Learning Material for Beg
Tenda Login Guide: Access Your Router in 5 Easy Steps
presentation_pfe-universite-molay-seltan.pptx
The New Creative Director: How AI Tools for Social Media Content Creation Are...
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
Introduction to Information and Communication Technology
Unit-3 cyber security network security of internet system
QR Codes Qr codecodecodecodecocodedecodecode
Sims 4 Historia para lo sims 4 para jugar
Decoding a Decade: 10 Years of Applied CTI Discipline
Triggering QUIC, presented by Geoff Huston at IETF 123
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
Internet___Basics___Styled_ presentation
SAP Ariba Sourcing PPT for learning material
Introuction about ICD -10 and ICD-11 PPT.pptx
tcp ip networks nd ip layering assotred slides
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
introduction about ICD -10 & ICD-11 ppt.pptx
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
Funds Management Learning Material for Beg

The DNS of Things

  • 1. The DNS of Things Peter Silva Sr. Technical Marketing Manager @psilvas Q. WHERE IS WWW.F5.COM? A. 2001:19b8:10 1:2::f5f5:1d
  • 2. SDDC/Cloud Mobility Advanced threats Internet of Things “Software defined” everything HTTP is the new TCP © F5 Netw©or kFs5, INnectworks, Inc Confidential 2
  • 3. Internet Foundation? DNS DNS DEMANDS More People Mobile devices/apps Complex sites Cloud implementation s IPv6 added with IPv4 WHEN DNS BREAKS EVERYTHING BREAKS DOMAIN NAME SYSTEM (DNS) Translates a domain name… http://www.google.com into an IP address: 74.125.227.64 (IPv4) http://www.f5.com = 2001:19b8:101:2::f5f5:1d (IPv6) Increased latency DDoS attacks © F5 Networks, Inc 3
  • 4. Everything: DNS • Internet of Things needs scalable DNS services* • Combination = 5 to 10 times Internet revolution** • 10bil devices in 2014 = 77bil mobile apps** • 35% Y/Y DNS query increase*** • Ensure really fast connections and responses* DNS Look Ups © F5 Networks, Inc 4
  • 5. Demand: DNS AVERAGE DAILY LOAD FOR DNS (.COM/.NET TLDS) QUERIES IN BILLIONS 82 77 43 50 57 ‘09 ‘10 ‘11 ‘12 ‘13 DNSSEC DEPLOYMENT EXPANDING TYPICAL FOR A SINGLE WEB PAGE TO CONSUME 100+ DNS QUERIES FROM ACTIVE CONTENT, ADVERTISING, AND ANALYTICS SECOND MOST ATTACKED PROTOCOL GLOBAL MOBILE DATA (4G/LTE) IS DRIVING THE NEED FOR FAST, AVAILABLE DNS 18X Growth 2011-2016 4G LTE 2.4GB /mo DISTRIBUTED, AVAILABLE, HIGH-PERFORMANCE GSLB FOR MULTIPLE DATA CENTERS Non-4G LTE 86MB /mo Reflection/amplification DDoS Cache poisoning attacks Drive for DNSSEC adoption Total service availability Geographically dispersed DCs DNS capacity close to subscribers 82 © F5 Networks, Inc 5
  • 6. Growth of Nouns 2013:80 2014:100 2020:250 152 Million Cars © F5 Networks, Inc 6
  • 7. Growth of Sensors © F5 Networks, Inc 7
  • 8. The Earth’s Connected Devices © F5 Networks, Inc 8
  • 9. Critical: DNS 76% are willing to wait 10 seconds or less for a single web page to load on Mobile phone before leaving. Every 100ms delay Costs Amazon 1% in sales. As of December 2013, there were over 184 million active websites, a growth of 157% over the last 5 years. 2013 2013 2009 157% 2009 DNS has grown over 91% in the last 5 years. © F5 Networks, Inc 9
  • 10. DNS Deployments • Performance = Add DNS boxes • Weak DoS/DDoS Protection • Firewall is THE bottleneck • Massive performance over 10M RPS! • Best DoS/DDoS protection • Lower CapEx and OpEx CONVENTIONAL DNS THINKING External Firewall DNS DELIVERY REIMAGINED Internet DNS Load Balancing Array of DNS Servers Internal Firewall Hidden Master DNS DMZ Datacenter DNS Firewall DNS DDoS Protection Protocol Validation Authoritative DNS Caching Resolver Transparent Caching High Performance DNSSEC DNSSEC Validation Intelligent GSLB PARADIGM SHIFT Internet Master DNS Infrastructure BIG-IP © F5 Networks, Inc 10
  • 11. • Delivers High-speed response & DDoS protection with in-memory • Authoritative DNS served out of RAM. • Configuration size for tens of millions of records. • Scale and consolidate DNS servers. DNS in DMZ Answer DNS Query Answer DNS Query Answer DNS Query Answer DNS Query DNS Server Answer DNS Query Efficient DNS DNS. Clients Internet OS Manage DNS Records Admin Auth Roles NIC Dynamic DNS DHCP © F5 Networks, Inc 12
  • 12. Optimized DNS Easy integration into existing DNS infrastructure for high availability and security Support over 10 million DNS responses per second (RPS) Manageable and predictable data center utilization © F5 Networks, Inc 13
  • 13. The DNS Value SCALABLE UP TO 20X 6 3 0 Low Query Query Growth Query Spike Query Decline Max DNS DENIAL OF SERVICE MITIGATION SUPPORT CLIENT REQUESTS AND CONSOLIDATE IT IPv6 to IPv4 COMPLETE DNS CONTROL Access Denied: ROUTE BASED ON GEOLOCATION SECURE DNS QUERY RESPONSES http://f5.com © F5 Networks, Inc 14
  • 14. Market Pulse Research: Managing DNS Capacity Key Findings • Respondents most frequently cite improved application availability and application performance (speed) as highly important benefits of DNS. • A majority (63%) report that their organizations’ DNS volume has increased over the past year. • Contributing factors: rollout of new services, applications. Cloud migration and traffic spikes. • Most often, organizations manage DNS capacity by adding more servers (53%) and/or adding more bandwidth (36%). Average of 24 DNS servers in use. • With regard to current DNS implementations, outages are the top concern (70% highly concerned). • Most concerning consequences: loss of productivity and a poor customer experience. • Nearly one-third of respondents (29%) report their organizations have experienced DNS outages in the past 12 months. Culprit? One-quarter of these (25%) report a traffic surge. • Among those who indicate their organizations are planning to expand DNS services to the cloud, increasing capacity is the most common driver. On-premise DNS primary case over the next year. Use of public cloud DNS slight increase in next 12 months. © F5 Networks, Inc 16
  • 15. The Five Takeaways Scalability: In times of high traffic, enterprises’ DNS servers must be able to handle shifting volumes of traffic. Security: Denial-of-service attacks frequently target IP addresses that cause DNS server outages. Intelligence: To be protective, IT must be proactive. That means being able to pinpoint application or service delivery accuracy, based on location of users, with geolocation services. Manageability: Enterprises need visibility into DNS services across cloud and on-premises networks, in order to ensure uptime and performance. IT also needs to be able to identify unusual activity that may indicate probing for vulnerabilities. Reliability: With more customers accessing corporate web sites, DNS server performance has the potential to impact user experience and employee productivity. Given these trends, DNS servers must be extremely reliable. © F5 Networks, Inc 17
  • 16. Story Arch deviantart.net © F5 Networks, Inc 18
  • 17. admissions.tufts.edu © F5 Networks, Inc 19
  • 18. DNS Story Arc Complication Introduction Denouement Climax Body Add Infrastructure DNS Traffic Market Conditions ADC Peace of Mind © F5 Networks, Inc 20
  • 19. Intelligent & Secure DNS that Scales • Scale and manage DNS and apps globally • Improve application performance and availability • Robust, Flexible and Secure DNS Infrastructure • Mitigate DNS DDoS Attacks • Support hybrid IP Environments • Complete DNS Security © F5 Networks, Inc 21
  • 20. Intelligent DNS Scale PROTECTS Web Properties and Brand Reputation. LOWERS Stress of DNS Outages. DIRECTS Customers to the best data center or cloud. REDUCES Data center costs. IMPROVES Web application performance. © F5 Networks, Inc 22
  • 21. The F5 DNS Reference Architecture f5.com/solutions @f5networks Explore © F5 Networks, Inc 23

Editor's Notes

  • #3: Key Points: IT challenges are growing at exponential rates Most of these challenges are external forces pushing in on IT The challenges are a mix of both apps and infrastructure – mobile apps and BYoD tax both the app and network infrastructure However the solutions are typically siloed, focused on solving very specific issues without addressing the larger problems as a whole These technology shifts, many of which are creating market transitions. Creating a great opportunity for solutions. For example, Users no longer work from the office. Today, they work for anywhere, at any time, one any device, and corporations needs solutions for a mobile work force The rise of the Cloud and Software Define Data Center….means that applications are equally portable and require a new set of solutions to ensure they’re fast, secure and available With such changes, there are new forms or threats…from simple FW solutions, to DDoS (volumetric and application centric), to malware, fraud and much more Lets not forget Software Defined “Everything”, customer want a much more agile infrastructure and orchestration and manageability. At a push of a button they want to orchestrate the whole stack. Clearly, there will be more devices and traffic. Demanding more diameter signaling, security and QoE And last, let not forget the HTTP is the new TCP. HTTP is the web protocol and therefore your network infrastructure needs to be aware of the session flows and messages, which requires intelligence beyond the traditional layer 3 solutions All these solutions are having dramatic implications on applications an the users that access them.
  • #4: The Domain Name System (DNS) is arguably the core technology enabling the Internet. DNS translates the names people type into a browser into an IP address so the requested service can be found on the Internet. It is one of the most important components in networking infrastructure that enables people and services to find and access applications. If DNS goes down, most web applications will fail to function properly. Since DNS is a critical component for available applications, answering every query on how to find your favorite web sites, it is critical to have an available, intelligent, secure and scalable DNS infrastructure. The Domain Name System (DNS) is a hierarchical distributed naming system for computers, services, or any resource connected to the Internet or a private network. It associates various information with domain names assigned to each of the participating entities. A Domain Name Service translates queries for domain names (which are meaningful to humans) into IP addresses for the purpose of locating computer services and devices worldwide. An often-used analogy to explain the Domain Name System is that it serves as the phone book for the Internet by translating human-friendly computer hostnames into IP addresses. For example, the domain name www.example.com translates to the addresses 192.0.43.10 (IPv4) and 2620:0:2d0:200::10 (IPv6).
  • #5: *Internet of Things and DNS (Lori Mac Vittie, F5 Networks, 2014) https://devcentral.f5.com/articles/the-internet-of-things-and-dns#.Us9hUJCA1eh **Cisco’s John Chambers interview at CES 2014: http://www.forbes.com/sites/connieguglielmo/2014/01/07/ces-live-cisco-ceo-chambers-to-deliver-keynote/ ***Last 5 years, DNS queries 100% growth (.com/.net) – VeriSign, 2011/12
  • #6: http://www.verisigninc.com/assets/infographic-dnib-Q12014.pdf http://www.verisigninc.com/en_US/innovation/dnib/index.xhtml
  • #10: Source: “most (76%) mobile users will wait 10 seconds for a page to load on their smartphone..” http://www.bizreport.com/2013/06/study-mobile-users-will-wait.html – SOASTA 2013 Website and Mobile App Report Source: Every 100ms delay costs Amazon 1% in sales. – Greg Lindon, Amazon Source: Last 5 years, DNS queries 91% growth (.com/.net) – VeriSign, The Domain Name Industry Brief 2013 (Q4 2013 and FY 2013 highlights), http://www.verisigninc.com/en_US/innovation/dnib/index.xhtml Source: Active Websites, December 2013 Web Server Survey: http://news.netcraft.com/archives/category/web-server-survey/ - 861 million total sites, 184 million active sites.
  • #11: Conventional DNS deployments require several layers of infrastructure and can only handle up to 200,000 DNS queries per second per server. Organizations that need higher DNS performance must add more DNS servers. Often, there is weak DNS DoS/DDoS protection and the protection that is in place, a network firewall, can be a traffic bottleneck itself. In addition, this solution often requires manual intervention for changes and traditional DNS servers are patched frequently, primarily for vulnerabilities. Any errors could have a high impact on site availability. The F5 Intelligent DNS Scale reference architecture is leaner, faster, and more secure on top of offering massive performance. BIG-IP can handle over 10 million query RPS; that’s 123 requests per day from every person on earth. Additionally, it offers unmatched DNS D/DoS protection and since BIG-IP is ICSA firewall certified, organizations can collapse multiple firewall tiers in the DMZ. Less equipment to purchase, manage and support. Plus, BIG-IP offers easy DNS management that integrates with your existing infrastructure. Error checking, auto population of protocols, and importation of zones help eliminate any downtime from DNS errors. The paradigm shift message is about challenging the conventional thinking of placing a DNS in a DMZ sandwiched by firewalls. The F5 DNS solution is ICSA certified and allows you to place it on the outside of your firewall. It performs firewall functionality and can serve authoritatively by zone transferring from your existing DNS server. You can retain the DNS server for management, making it an easy migration (use your existing DNS tools, etc). The customer benefits from an ultra-high performance solution which incorporates a firewall and DNS services. Unlike the conventional model, it does not suffer from firewall bottlenecks. The F5 solution scales, in a single box, to 20M query RPS. This results in much lower OpEx and CapEx while delivering much higher performance and protection.
  • #12: BIND is an open-source project maintained by Internet Systems Consortium (ISC). ISC is a non-profit organization with a for-profit consulting arm called DNS-CO, which offers five levels of subscription that range from $10,000 to $100,000 annually. Despite its popularity, BIND requires significant maintenance multiple times a year primarily due to vulnerabilities, patches, and upgrades. It can be downloaded freely, but needs servers (an additional cost, including support contracts) and an operating system. In addition, BIND typically scales to only 50,000 responses per second (RPS), making it vulnerable to both legitimate and malicious DNS surges.
  • #13: BIG-IP GTM is a full DNS server and handles requests on behalf of the main DNS server. DNS Express manages authoritative DNS queries by transferring zones to its own RAM. In this architecture, BIG-IP GTM only has to open the DNS query packet as long as the request is for an address that is in the zone that was transferred to DNS Express. DNS Express simplifies a single processing instance of the DNS query to significantly improve the performance of your DNS. With DNS Express, BIG-IP can handle to 10 million query responses per second, over 12X the capacity of what a primary DNS server can handle and about 3X what the competition can offer. The F5 Intelligent DNS Scale reference architecture allows organizations to place BIG-IP in the DMZ. It performs firewall functionality and can serve authoritatively by zone transferring from your existing DNS server. You can retain the DNS server for management, making this an easy migration.
  • #14: When a user requests a web page, the requests access local DNS services and these in turn communicate with the main DNS servers. This is not a problem until a hacker floods the server with DNS requests. Instead of purchasing additional DNS servers, put BIG-IP GTM in front of your main DNS server. The F5 Intelligent DNS Scale reference architecture also helps keep your content and applications available by responding to DNS queries from the edge of the network, rather than from deep within your critical infrastructure. When you offload DNS responses to the BIG-IP platform, no request reaches the back end of your network, which greatly increases your ability to scale and respond to DNS surges along with protecting your DNS infrastructure. By increasing the speed, availability, scalability, and security of your DNS infrastructure, the F5 Intelligent DNS Scale reference architecture ensures that your customers—and your employees—can access your critical web, application, and database services whenever they need them. Instead of worrying about DNS outages and purchasing additional DNS infrastructure to combat surges, simply place BIG-IP in front of your primary DNS server. It’s a full DNS server and handles requests on behalf of your main DNS server. The architecture of the F5 Intelligent and Scalable DNS services is optimized by the specifically designed DNS Express query response module. DNS Express manages authoritative DNS queries by transferring zones to its own RAM. In this architecture, F5 DNS Services only has to open the DNS query packet once, as long as the request is for an address that is in the zone that was transferred to DNS Express. DNS Express simplifies a single processing instance of the DNS query to significantly improve the performance of F5 DNS Services. With DNS Express, each individual core of each BIG-IP device can answer approximately 125,000 to 200,000 requests per second, scaling up to 10 million query RPS. This can be over 12X the capacity of what a typical primary DNS server can handle. This gives F5 customers a unique opportunity to scale dramatically to DNS query responses. If you have high volume DNS coming into your data center, it is more advantageous to respond to those queries from the DMZ rather than from deep within the infrastructure, potentially affecting the back end primary DNS servers along with other critical servers. Instead of responding from deep within the infrastructure, respond using BIG-IP from the DMZ so that no request touches the back end which greatly increases the primary server’s ability can scale. Offload DNS to BIG-IP. With these large scale capabilities, even if a site is flooded due to some unexpected event, DNS can respond to all queries, good or bad. This keeps all your critical web, application and database services available. Organizations can secure DNS while achieving high scale. There is less equipment to purchase, manage and support. Plus, BIG-IP offers easy DNS management that integrates with your existing infrastructure. Error checking, auto population of protocols and importation of zones help eliminate any downtime from DNS errors. Organizations can make their applications fast, available and secure but if DNS is not responding, it doesn’t really matter since no one can get to it anyway. F5 DNS Services is leaner, faster, and more secure and offers massive performance over any other DNS solution. DNS is the internet’s phonebook and is essential for every web property on the Internet. It helps people find your web presence. It helps websites deliver the content you want visitors to see. If DNS is slow, then you entire infrastructure is slow and your bounce rate jumps. If your website takes longer than 3 seconds to load, you are losing revenue. If your DNS is attacked, then your web presence is severely limited. If your DNS cannot scale, then you cannot accommodate additional visitors. If your DNS is compromised, then your brand suffers. If DNS doesn’t work, you lose revenue. If you have an antiquated DNS infrastructure, you’re spending too much money and putting the business at risk. If people cannot find you, they will go somewhere else. If your DNS is resilient, people will find you. If people can find you, they will engage. If they engage, your brand gets exposure. If your web properties respond quickly, people are more likely to stay. If people stay, business will grow. The F5 Intelligent DNS Scale reference architecture can help protect your brand and grow your business. Intelligent means that BIG-IP, based on the context of the request (like location or reputation), can determine if the query is valid. Scale means that BIG-IP will be able to handle any surge of DNS queries keeping your applications available for your customers.
  • #15: DNS is the internet’s phonebook and essential for every web property on the internet. It helps people find your web presence. It helps websites deliver the content you want visitors to see. If DNS is slow, then you entire infrastructure is slow and your bounce rate jumps. If your website takes longer than 3 seconds to load, you are losing revenue. If your DNS is attacked, then your web presence is severely limited. If your DNS cannot scale, then you cannot accommodate additional visitors. If your DNS is compromised, then your brand suffers. If DNS doesn’t work, you lose revenue. If you have an antiquated DNS infrastructure, you’re spending too much money and putting the business at risk. If people cannot find you, they will go somewhere else. If your DNS is resilient, people will find you. If people can find you, they will engage. If they engage, your brand gets exposure. If your web properties respond quickly, people are more likely to stay. If people stay, business will grow. F5 DNS Services can help protect your brand and grow your business. Intelligent means that BIG-IP, based on the context of the request (like location or reputation), can determine if the query is valid. Scale means that BIG-IP will be able to handle any surge of DNS queries keeping your applications available for your customers.
  • #16: • Is DNS management error prone and cumbersome? • Do you follow a multi-step manual failover process? • Are your end users experiencing 404 errors, poor performance, broken sessions, or lost/corrupted data?
  • #23: See slide