Download
global site selector n.
Skip this Video
Loading SlideShow in 5 Seconds..
Global Site Selector PowerPoint Presentation
Download Presentation
Global Site Selector

Global Site Selector

206 Vues Download Presentation
Télécharger la présentation

Global Site Selector

- - - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript

  1. Global Site Selector ADBU Product Management

  2. Global Site Selector Product update

  3. Highlights • 3X R&D headcount increase YoY! • Release 4.1 (Q4CY11) • New Feature: GeoIP Support • IPv6Support • Support for Existing HWGSS4492R • Concept Committing Release 5.1 (HW refresh, DNSSEC) in 1HCY11

  4. 2012 GSS Planning • Release 5.0 (Planning) • DNSSec with FIPS • SOA & NS Record • HW Refresh • Release 4.1 (Q4CY11) • IPv6 Support (AAAA) • Full GeoIP GSLB 2011 • Release 3.3 • Available as private image – not on CCO • Configuration Scalability (8K Answers) • Proximity Enhanced with GeoIP • GUI Makeover (Cisco Kubric) • Release 3.2 (Feb, 2011) • HTTPs KAL • DNSSec Forwarding • Critical Bug Fixes 2010

  5. GSS Road to IPv6 Release 3.2 - HTTPs KAL - Workaround DNSSEC - Bug Fixes Release 3.3 (Private Only) - Geo IP Proximity - 8K Answers Support - ANM support for 8K Answers Release 4.1.1 - IPv6 dot.ONE release - Bug Fixes 2011 2012 Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Release 4.1 - IPv6 Support - Geo IP GSLB - ANM support for 8K Answers

  6. GSS 4.1 – Q4CY11 • GeoIP based GSLB • GeoIP based proximity • GeoIP based DNS Rules and Sticky • (b) IPv6 • Support for AAAA response • Support for persistence • IPv6 Management over IPv6 interface • (c) New GUI Design (Kubric Look & Feel) • (d) Configuration Scalability • 8000 answers GSSNetwork SLB Datacenter A a LDNS d SLB c Datacenter B User 2001:0DB8:AC10:FE01:: b

  7. Rel 4.0 Q4CY11 GSS Roadmap Rel 5.0 1HCY12 • DNS Services • IPv6: Support for AAAA, A6, CNAME DNS Records • DNS Services • DNSSEc with FIPS • SOA & NS Record Support 1 1 GSS Network SLB • Operation Optimization • Audit Logs • Log Source IP • Sync CLI and GUI User • View KAL logs through GUI • Operational Optimization • Authentication using AD • Automated Backup • Activate/Suspend Answers • Enhanced Reporting • Alerts/Alarms 2 2 Datacenter A LDNS 1 2 • GSLB Services • Geo IP based Proximity • GSLB Services • Share KAL Status Among Peers • KAL-AP with VIP Capacity/Load 4 3 3 SLB Datacenter B User 3 • DCI Services • Automation to support Vmotion over DCI 4 4 • DCI Services • Automation through integration with ANM • Exploring LISP Support • Hardware Platform • GSS-4492R 5 5 • Hardware Platform • Hardware Refresh with FIPS compliance

  8. Cisco GSS in a Nutshell Upto 16 GSSes can work in conjunction to meet the needs of large Enterprise and Service Provider. ACE GSS4492R-K9HW SF-GSS-V1.3-K9 SW SF-GSS-DDOSLICDDoS SF-GSS-GIPLICFXGeoIPGSLB Support SF-GSS-V6LICFXIPv6 Support • IPv6 Support • DDoS Protection • Geographical and Resource Affinity • Supports Cisco ACE/CSS/CSM http://cio.cisco.com/en/US/products/hw/contnetw/ps4162/products_installation_and_configuration_guides_list.html

  9. Global Site Selector Product overview

  10. Types of GSLB Solutions GSS is a DNS based GSLB Solution

  11. More specifically … GSS participates in your DNS Infrastructure to enforce BCDR, GSLB, DNS Security policies. • Provides Universal DNS-based Disaster Recovery – redirects clients to back-up data center for any device that support SNMP MIB and uses DNS • Protects the DNS infrastructure with DNS-based DDOS mitigation software • Delivers Advance Global Traffic Management • Global Server Load Balancing (GSLB) for geographically dispersed Server Load Balancers and Caches • Connect clients to the best server based on: • Network topology • Server load • Availability of content and devices

  12. DNS 4 5 1 3 2 Data Center #2 Data Center #1 Ease of Deployment GSS participates in the DNS infrastructure – Lower Latency Intermediate Name Server Supporting: .com GSS becomes the Authoritive Name Server for the entire Zone supporting all applications for the SP Root Name Server DNS Global Control Plane IP Control/Forwarding Plane CNR QIP ISP#1 Client Name servers (D-proxy) BIND ISP#3 ISP#2 Clients Requesting Web Sites DNS Requests DNS Response Layer 3 Communications Fixed Wireless Dedicated/ ATM/FR Mobile ISDN/Dial DSL Cable DNS DNS Resolvers (DNSR): IE, Firefox, etc.

  13. Ease of Management GSS network is managed as a system – reduces number of touchpoints Ease of Management • GSS is a system not a device • Self synchronization of upto 16 GSSes • Single Point of management via GUI • Does not sacrifice device level access (SSH to box) • Any GSS can run GUI and a 2nd GSS serves as standby • Easy to use Interface • IOS Syntax • 100 new CLI commands since v1.3 • Single interface for monitoring, troubleshooting and configuration • Supports Import/Export of Configuration in industry standard formats • Role based Access Control • Remote Syslog Support • Management Integration with ANM • ANM - support the activation and suspension of a DNS rules and answers • ANM – communicates to the primary GSS manager (PGSSM) via CLI, RMI and SSH. Configuration parameters to establish this communication is the GSS IP address and SSH credentials • Four of eight Administrators Logon consumed by ANM • ANM issues commands to the PGSSM then the PGSSM relays these commands to the rest of the GSSs in the cluster. GSS Network ANM GSS GUI

  14. DNS DNS Use Case: Policy based GSLB GSLB policy enables redirection based on proximity, site health, server load and user preferences www.fifa.com nameserver.fifa.com www.fifa.com“NS” Record 10.86.191.150 “NS” Record 10.86.191.134 Add DNS Rules + SAL + DDL + Qtype + Add Clauses Create Mesh Link Add NS Record for both GSSes 3 2 1 GSLB Can Redirect Traffic Based On SLB SLB DNS Query www.fifa.com 10.86.191.134 • Proximity • Selects Answer based on lowest RTT. • RTT measured between client’s d-proxy and a probing device (Cisco Router and/or GSS) • GSS uses DRP to communicate with probes • Disaster Recovery • Site Health Check • Datacenter Load • KAL-AP • Ratio based GLSB VIP=10.86.191.131 P-DNS2 16.1.1.1 Datacenter B Datacenter A GSS Milan 10.86.191.134 A” Record 10.86.191.147 DNS Query, www.fifa.com Mesh Link DNS query www.fifa.com GSS Johannesburg 10.86.191.150 User VIP=10.86.191.147

  15. Use Case: BCDR Mobile Fixed Wireless Cable DSL Dedicated/ ATM/FR ISDN/Dial DNS Global Control Plane GSS Cluster Resolver DNS Name Servers IP Control/Forwarding Plane • Recovering Service Availability after Failure • Active-Passive Design • Network fail-over can happen within 10s Application/Server • Recovery time is based on the time it take to complete data Synchronization of back-end data base, application servers and Web servers • Supported by Cisco’s Solutions • GSS, CSS, CSM, ACE NJ Back-upData Center #3 TokyoData Center #2 Chicago Data Center #1

  16. Use Case: Securing DNS Infrastructure Mobile Fixed Wireless Cable DSL Dedicated/ ATM/FR ISDN/Dial DNS Global Control Plane Resolver Rate limits these specific DNS Request IP Control/Forwarding Plane Compromised DNS Name Servers or DNS bots Provides Security Focused, highly available, DNS/DHCP/TFTP infrastructure for one or more data centers. Automatically identifies DNS-based DDOS attack and mitigates the attacks NJ Back-upData Center #3 TokyoData Center #2 Chicago Data Center #1

  17. GSS Release 3.1.2 Before After GSS Network SLB No support for IDNA IDNA Support 1 1 Datacenter A LDNS 1 Limited Integration with SLB Management (ANM) Integration with SLB Management (ANM) 2 2 2 4 KAL SLB 3 3 3 Bug Fixes Bug Fixes Datacenter B User KALs on HTTPs Transport KALs did not support HTTPs transport 4 4 Tentative 4

  18. GSS Release 3.2.0 Before After GSS Network SLB No HTTPs KAL HTTPs KAL 1 1 Datacenter A LDNS 4 DNSSec Deployments Break DNSSec workaround to forward A4 records 2 2 2 1 KAL SLB 3 3 3 Audit Log for GUI based Config Changes GUI based Config Changes not logged Datacenter B User Secure Communication on SSL SSL Vulnerabilities 4 4

  19. GSS 3.2.0 Bug Fixes

  20. GeoIP Support • (a) GeoIP based Proximity • Proximity calculations using GeoIP distances • (b) GeoRegions: GeoIP based Regions • Regions based on GeoIP database entries. (Add single country or multiple countries). Granularity down to states • Sticky support for GeoRegions • (c) GeoSAL: GeoIP based Source Address Lists • SALs can be based on GeoIP based Regions • (d) New GUI Design (Kubric Look & Feel) • GUI option to configure all GeoIP functionality Available in GSS 4.1 in Q4CY11 GSSNetwork SLB c Datacenter A a LDNS SLB Datacenter B User 2001:0DB8:AC10:FE01:: d b

  21. GSS Competitive Side by Side

  22. Questions?

  23. backup

  24. GSS Performance Limits V3.0 GSS Configuration Limits V3.0 DNS Requests / Second (Single VIP) ~30K DNS Requests / Second (Complex Config) ~13K NS Forwarding Requests / Second ~1.5K Answer Groups (100 members max per group) 2K DNS Race Content Routing Agent devices (20 max per race & answer group) 200 GSS Configuration Limits V3.0 100 Name Server addresses for NS Forwarding (30 max per answer group) DNS Rules 4K Source IP addresses configurable for DNS Rules 500 Virtual IP Addresses – Standard / Shared 2K/4K Active Server Load Balancers 256 Source Address Groups (30 members max per group) 60 Number of GSS in a Cluster 16 HTTP Probes – Standard 500 Hosted Domains - max 1000 per SLB, 128 characters max per domain 2K HTTP Probes – Fast 100 ICMP Probes – Standard 750 Hosted Domain Lists 2K Administrative Owners 500 ICMP Probes – Fast 150 Maximum Domains per Domain List 500 Administrative Regions 20 TCP Probes – Standard 1.5K Administrative Locations 1K TCP Probes – Fast 150 Scripted (SNMP) Probes – Standard 384 Max administer / user ids 256 Scripted (SNMP) Probes – Fast 120 Max concurrent GUI sessions 128 KAL AP Probes – Standard 128 Max concurrent CLI sessions (simultaneous SSH + telnet sessions) 8 KAL AP Probes – Fast 40 Answers per KAL AP Probe 1K GSS Capacity Details

  25. GSS Performance & Configuration Scalability Configuration Limits Configuration Limits

  26. Security Focused Functionality • Improves availability and resiliency of DNS infrastructure with high performance and self protecting DDOS software • Offloads and optimizes BIND/DNS processing and selects the best site based on: • Intelligent load balancing algorithms & “clauses” • Proximity to user request • Data center and server loads, availability & health • Persistence to prevent lost session information • Complete and Centralized DNS/DHCP/TFTP management for network-enabled applications • Security conscious features: • DDOS Mitigation Software • Client to GSS and GSS to GSS communication encrypted • Private DNS code base • Supports all DNS-compatible devices • Can be deployed with or without content switches

  27. Security Focused GSS deployment Un-secure DNS traffic • Why here? • Public IP and DNS Host Names • Layers of firewalls and Nating between DNS and internal servers ISP-1 ISP-2 DNS Server DMZ Cisco GSS Public Web Servers Datacenter A • Not here? • If hacked private IP available • - DNS traffic Tunneled though firewall • Violates recommend “Split DNS” Best Practices Others Secure Web Servers

  28. GSS vs F5 GTM

  29. Improving DNS Survivability • Detects and mitigates the DNS focused Distributed Denial of Service (DDoS) attacks. Multiple defenses including source verification • With the granularity and accuracy to provide new levels of business continuity by processing only legitimate DNS requests • Delivering the performance and architecture suitable for the largest enterprises and providers • Addresses DDoS attacks today, and its network-based behavioral anomaly capability will be extended to additional DNS focused threats

  30. GSLB Core Balance Functions

  31. Servers Site 1 Site 2 Servers Keepalives: TCP ICMP HTTP-Head SNMP CSS-A CSS-B CSS-A CSS-B Keep Alives (KAL) • KALs – back-end process gathers state and load information from devices within the data center such as local server load balancers, and origin servers • KAL can be grouped and logically “AND” together • V2.0 added a new KAL type --- SNMP based

  32. GlobalStrikeGSS 5.1 Concept Committed 8/22/2011 Key Asks inGlobalStrike GSSNetwork 1. Security and Compliance • (a) DNSSEC strengthens the integrity of DNS Query/Response transaction from threats such as • Forged or bogus response • Removal of Records (RRs) in responses • Incorrect application of wildcard expansion rules • (b) USGv6 and IPv6Ph 2 Logo certification • FIPS compliant or validated encryption with acceleration • Common Criteria EAL-2 2. Platfom Refresh • (c) UCS server based appliance (San Luis) • vGSS • GeoIP Enhancements • (d) Logical Grouping of Geo Regions 4. KAL- AP • Enhancements and scalability SLB Datacenter A a LDNS d SLB c Datacenter B User 2001:0DB8:AC10:FE01:: b