SlideShare a Scribd company logo
Design and Deploy Secure Clouds
for Financial Services – Use Cases
August 18, 2016
Copyright © PLUMgrid, Inc. 2011-2015
Introduction
Speakers
2
Principal Solutions Architect
Justin Moore
Sr. Solution Architect – OpenStack Tiger Team
Joe Antkowiak
PLUMgrid
Red Hat
Copyright © PLUMgrid, Inc. 2011-2015
Agenda
What’s will be covered today
3
1 OpenStack Infrastructure Security
- Addressing Common Security Challenges using
Red Hat OpenStack Platform
Security and compliance through automation and
micro-segmentation with OpenStack and SDN
Micro-Segmentation Demo3
2
OpenStack Infrastructure Security
Addressing Common Security Challenges
using Red Hat OpenStack Platform
Joe Antkowiak
Sr Solution Architect
August 18, 2016
Agenda
 Common OpenStack Infrastructure Security Challenges
 Addressing Challenges with Red Hat OpenStack Platform Director
 Addressing Challenges with Red Hat CloudForms
OpenStack Infrastructure Security
Common Challenges
 Many Manual Tasks
 Infrastructure Secured Post Deployment
 Detecting Change and Enforcing Policy
 Maintaining Secure Configuration and Policy
When Upgrading and Scaling
<footer>
OPENSTACK PLATFORM DIRECTOR
DAY 1 + SCALING/UPGRADING
Director is included in Red Hat OpenStack
Platform
CLOUDFORMS
DAY 2 + LIFECYCLE
CloudForms is included in Red Hat
OpenStack Platform
<footer>
Red Hat OpenStack Platform Director
DEPLOYMENTPLANNING OPERATIONS
Updates and upgrades
Scaling up and down
Change management
Deployment orchestration
Service configuration
Sanity checks
Network topology
Service parameters
Resource capacity
OpenStack Orchestration
OpenStack Platform Director (OSPd)
Advantages for OpenStack Security
USES OPENSTACK TO DEPLOY OPENSTACK
Concepts applicable to workloads running on OpenStack
are applicable to OpenStack itself
IMAGE BASED
Nodes installed from a customize-able source image
TEMPLATE BASED
Customize-able, reusable, repeatable use of Heat
templates (YAML) to install, scale, and upgrade
OSP Director Image Customization
Image Customization Examples for Security
KERNEL
Deploy a custom kernel build, or hardened kernel (with
validation)
PACKAGES
Deploy specific package versions or additional packages
LOCAL ACCOUNTS AND POLICIES
Define custom local accounts and SELinux configuration
OSP Director Template-Based Deployment
Template-Based Configuration Examples for Security
SSL/TLS ENABLED CONTROL PLANE AND ENDPOINTS
Enable transport encryption on all control plane
communication using your certificates
AAA INTEGRATION
Integrate with your AAA infrastructure (LDAP, Kerberos,
etc)
SERVICES CONFIGURATION
Configure Logging, NTP, Monitoring Tools
<footer>
Red Hat CloudForms
UNIFIED
MANAGEMENT
AND
OPERATIONS
COMPLETE
LIFECYCLE
MANAGEMENT
VISIBILITY
AND
ANALYTICS
COMPLIANCE
AND
GOVERNANCE
INTEGRATION AND
COMPOSABILITY
Unified Management for OpenStack
CloudForms Compliance and Governance
ANALYZE
Automatically perform SmartState Analysis on
OpenStack Nodes and Instances (agent-less)
TRACK AND ALERT
Report on changes and drift, automatically alert based
on defined policy
REMEDIATE
Automatically kick off defined remediation or deeper
inspection actions
Example Functions
CloudForms SmartState Analysis
Examples of Items Tracked
PACKAGES AND FILES
Package versions, new/changed files
LOCAL USERS AND ACTIONS
User actions/commands, users and groups added or
changed
COMPONENT CHANGES
Added or changed network interfaces, storage attached,
new instances or containers running
Thank you!
Please Post Questions in Webinar
Visit Red Hat at OpenStack East
August 23-24, NYC
red.ht/openstack
red.ht/cloudforms
Security and compliance through automation and
micro-segmentation with OpenStack and SDN
Justin Moore
Copyright © PLUMgrid, Inc. 2011-2015
• Regulatory Compliance
• PCI
• SOX
• Security
• Separation of concerns
• Minimize attack surface
• Strict enforcement of access control
• Operations
• Reduce manual effort through automation
• Protect against misconfiguration
• Dev/Test pointed to Prod
• Incorrect or invalid firewall rule
• Server placed on wrong network
• Rapidly scale
Technology Challenges in FSI
Copyright © PLUMgrid, Inc. 2011-2015
• Too slow
• Ticket based manual workflows take days or weeks
• New methodologies demand on-demand
infrastructure, and tight integration with the SDLC
• Agile
• CI/CD
• Micro-services
• Error prone
• Lack of automation and standardization leads to
errors
• Incomplete or inadequate de-comission processes
• Too expensive
• Scale-up Access Control devices/Forklift upgrades
• Highly skilled and highly paid engineers performing
trivial ticket based activities
Traditional Approaches No Longer Work
18
Copyright © PLUMgrid, Inc. 2011-2015
• Cloud!
• Ok – it’s not really that simple. What about all of
that security stuff?
• SDN!
• Again – it’s not really as simple as buying an
SDN.
• How will we design the system to ensure that
security is baked into the end-to-end environment?
• Micro-segmentation
• Great – another buzzword!
• Micro-segmentation is the process of controlling
access to and from a service based on the
combination of security boundary and attack foot-
print
• Don’t we already do that?
• Not really!
So How Do We Keep Up?
19
Copyright © PLUMgrid, Inc. 2011-2015
Virtual Domains
Your Private Virtual Data Center
20
• Tenant Virtual Domains
• Isolation & segmentation of workloads
• Self-service provision of all functions
• Service Virtual Domains
• Owned by Cloud Operator
• Used to apply common services or security
policies
• Hosts external connectivity
• Virtual Domain Chaining
• Decouple changes from physical
infrastructure
• Fully distributed within IO Visor layer on
each compute node
DNS
Service Virtual Domain
Tenant Virtual Domains
Copyright © PLUMgrid, Inc. 2011-2015
PLUMgrid Virtual Domains
Components of a Virtual Domain
21
Virtual Domain
DistributedPolicy
EnforcementZone
Edge Policy
Enforcement Point
Virtual Domain (VD) — ISOLATION
• Secure Tenant Isolation for multi-tenant clouds
Contains all Network definitions for that Project
• Rich set of analytics and monitoring
• Option to encrypt traffic on a per VD basis
Topology — Overlay based fully
Distributed Network Functions
• Network topology view
• DVS/DVR/NAT/DNS/DHCP functions
• Fully Distributed (No hairpin or network nodes)
• Integration with external VTEP Gateways
• Topology based Service Insertion (FW/LB/IPS)
Policy boundary — SEGMENTATION
• Group Based Policies & Micro-segmentation
• All traffic in-out of VD goes through Policy Engine
• Used for Security Groups (L2-4 stateless or state-
full security)
• Policy based VTAP (traffic capture)
• Policy based Service Insertion (FW/LB/IPS)
• Support for Service Chains or single Service
Function
Copyright © PLUMgrid, Inc. 2011-2015
PLUMgrid ONS Components
22
Internet
IO Visor Gateway
IO Visor Edges (Compute Nodes)
PLUMgrid Directors
VXLAN-based
Overlay
PLUMgrid CloudApex & OpsVM
Copyright © PLUMgrid, Inc. 2011-2015
Example Application – Customer Service Tool
23
DNS
Global Cloud Policy
Prod CSTDev CST
Copyright © PLUMgrid, Inc. 2011-2015
Three-Tier Architecture
Presentation tier
Logic tier
Data tier
Database Storage
GET LIST OF ALL SALES
MADE LAST YEAR
ADD ALL SALES
TOGETHER
> GET SALES
TOTAL
> GET SALES
TOTAL
4 TOTAL SALES
QUERY
SALE 1
SALE 2
SALE 3
SALE 4
Copyright © PLUMgrid, Inc. 2011-2015
PLUMgrid Policy Path
25
Group
Classification
(source &
destination End
Point classification)
Packets
- sMAC / .1Q
- src_IP/dst_IP
- Application / Ports
- Protocols
Meta Data
- Tenant ID / App ID
- VM UUID / Name
- End Point Type / Group
- Location / physical Server
Behavior
- Traffic Profile
- Sys Call profile
- Storage Access Profile
Stateful
Security
Groups
Security
Logs &
Alerts
Policy
based
VTAP
Traffic
mirroring
Policy
based
Service
Insertion
VNF
1
VNF
2
VNF
3
- Service Chains
- Distributed Service Insertion
- Local Affinity
Micro-Segmentation Demo
26
Q&A
Please use the Q&A panel to ask questions
Copyright © PLUMgrid, Inc. 2011-2015
THANK YOU!

More Related Content

What's hot (20)

PPTX
How to Quickly Implement a Secure Cloud for Government and Military | Webinar
PLUMgrid
 
PPTX
Securing Micro Services in Cloud Foundry
PLUMgrid
 
PDF
Why OpenDaylight
Lumina Networks
 
PDF
How to Implement SDN Technology in ITB
SDNRG ITB
 
PDF
CSTA - Cisco Security Technical Alliances, New Ecosystem Program Built on the...
Cisco DevNet
 
PPTX
Nuage Networks for Dynamic Network Orchestration
Jonas Vermeulen
 
PDF
OpenStack (projects 101)
Hazzim Anaya
 
PDF
OpenStack and Application Delivery: Joy and Pain of an Intricate Relationship
PLUMgrid
 
PDF
Hope, fear, and the data center time machine
Cisco Canada
 
PPTX
7 - Introduction to OpenStack & SDN by Ady Saputra
SDNRG ITB
 
PPTX
OpenStack Telco Cloud Challenges, David Fick, Oracle
Sriram Subramanian
 
PDF
The Changing Data Center Landscape
Cisco Canada
 
PDF
【Cisco OpenStack Seminar 2015.10.26】 OpenStack as Strategy for future growth
シスコシステムズ合同会社
 
PPTX
Discover the benefits of Kubernetes to host a SaaS solution
Scaleway
 
PDF
OpenStack for EDGE computing
Hazzim Anaya
 
PDF
Expanding your impact with programmability in the data center
Cisco Canada
 
PPTX
Modernizing Application Deployments with HashiCorp Consul on Microsoft Azure
Mitchell Pronschinske
 
PPTX
Protect Kubernetes Environments with Cisco Stealthwatch Cloud
Robb Boyd
 
PDF
The Evolution of the Data Centre
Cisco Canada
 
PDF
1 - SDNRG ITB, 10 minutes intro by Affan Basalamah
SDNRG ITB
 
How to Quickly Implement a Secure Cloud for Government and Military | Webinar
PLUMgrid
 
Securing Micro Services in Cloud Foundry
PLUMgrid
 
Why OpenDaylight
Lumina Networks
 
How to Implement SDN Technology in ITB
SDNRG ITB
 
CSTA - Cisco Security Technical Alliances, New Ecosystem Program Built on the...
Cisco DevNet
 
Nuage Networks for Dynamic Network Orchestration
Jonas Vermeulen
 
OpenStack (projects 101)
Hazzim Anaya
 
OpenStack and Application Delivery: Joy and Pain of an Intricate Relationship
PLUMgrid
 
Hope, fear, and the data center time machine
Cisco Canada
 
7 - Introduction to OpenStack & SDN by Ady Saputra
SDNRG ITB
 
OpenStack Telco Cloud Challenges, David Fick, Oracle
Sriram Subramanian
 
The Changing Data Center Landscape
Cisco Canada
 
【Cisco OpenStack Seminar 2015.10.26】 OpenStack as Strategy for future growth
シスコシステムズ合同会社
 
Discover the benefits of Kubernetes to host a SaaS solution
Scaleway
 
OpenStack for EDGE computing
Hazzim Anaya
 
Expanding your impact with programmability in the data center
Cisco Canada
 
Modernizing Application Deployments with HashiCorp Consul on Microsoft Azure
Mitchell Pronschinske
 
Protect Kubernetes Environments with Cisco Stealthwatch Cloud
Robb Boyd
 
The Evolution of the Data Centre
Cisco Canada
 
1 - SDNRG ITB, 10 minutes intro by Affan Basalamah
SDNRG ITB
 

Viewers also liked (14)

PDF
What manufacturing teaches about DevOps
Gordon Haff
 
PDF
Cloudforms Workshop
Scalar Decisions
 
PDF
Cloud nfv intro at UoG
Affan Syed
 
PPTX
Testing the limits of cloud networks
PLUMgrid
 
PDF
How to grow a vegetable garden
natalie_0302
 
PPTX
Q1 - evaluation
jjsmaje
 
PDF
Capstone Presentation _ NND
Nisel Desai
 
PPTX
Building a Scalable Federated Hybrid Cloud
PLUMgrid
 
PPTX
Método de proyecto para la educación en tecnología
David Ruiz
 
DOCX
Tiffanie Pierce Vitae
Tiffanie Pierce
 
PPT
Communicable disease
frattelo
 
PPTX
Federation manager demo
PLUMgrid
 
PPTX
Managing Multi-hypervisor OpenStack Cloud with Single Virtual Network
PLUMgrid
 
What manufacturing teaches about DevOps
Gordon Haff
 
Cloudforms Workshop
Scalar Decisions
 
Cloud nfv intro at UoG
Affan Syed
 
Testing the limits of cloud networks
PLUMgrid
 
How to grow a vegetable garden
natalie_0302
 
Q1 - evaluation
jjsmaje
 
Capstone Presentation _ NND
Nisel Desai
 
Building a Scalable Federated Hybrid Cloud
PLUMgrid
 
Método de proyecto para la educación en tecnología
David Ruiz
 
Tiffanie Pierce Vitae
Tiffanie Pierce
 
Communicable disease
frattelo
 
Federation manager demo
PLUMgrid
 
Managing Multi-hypervisor OpenStack Cloud with Single Virtual Network
PLUMgrid
 
Ad

Similar to Design and Deploy Secure Clouds for Financial Services Use Cases (20)

PDF
MSST-2013 Openstack in the Land of Guilder
Joshua McKenty
 
PDF
Txlf2012
Joe Brockmeier
 
PDF
Microservices Architectures with Docker Swarm, etcd, Kuryr and Neutron
Fawad Khaliq
 
PDF
OpenStack networking - Neutron deep dive with PLUMgrid
Kamesh Pemmaraju
 
PDF
NFV_vCPE
Affan Syed
 
PPTX
Cloud stack overview
howie YU
 
PPT
OpenStack - Security Professionals Information Exchange
Cybera Inc.
 
PDF
Immutable Infrastructure Security
Ricky Sanders
 
PPTX
Architecture Best Practices
AWS Germany
 
PPTX
Containers and workload security an overview
Krishna-Kumar
 
PDF
Five Years of EC2 Distilled
Grig Gheorghiu
 
PPTX
Cloud Security Architecture.pptx
Moshe Ferber
 
PPTX
Cloud computing and innovations
SPIN Chennai
 
PPTX
Sanger, upcoming Openstack for Bio-informaticians
Peter Clapham
 
PPTX
Flexible compute
Peter Clapham
 
PPTX
Service Discovery and Registration in a Microservices Architecture
PLUMgrid
 
PPTX
Openstack Summit Tokyo 2015 - Building a private cloud to efficiently handle ...
Pierre GRANDIN
 
PDF
Big Data and OpenStack, a Love Story: Michael Still, Rackspace
OpenStack
 
PDF
AWS Pentesting
MichaelRodriguesdosS1
 
PDF
Securing Microservices in Containerized Environments
DevOps.com
 
MSST-2013 Openstack in the Land of Guilder
Joshua McKenty
 
Txlf2012
Joe Brockmeier
 
Microservices Architectures with Docker Swarm, etcd, Kuryr and Neutron
Fawad Khaliq
 
OpenStack networking - Neutron deep dive with PLUMgrid
Kamesh Pemmaraju
 
NFV_vCPE
Affan Syed
 
Cloud stack overview
howie YU
 
OpenStack - Security Professionals Information Exchange
Cybera Inc.
 
Immutable Infrastructure Security
Ricky Sanders
 
Architecture Best Practices
AWS Germany
 
Containers and workload security an overview
Krishna-Kumar
 
Five Years of EC2 Distilled
Grig Gheorghiu
 
Cloud Security Architecture.pptx
Moshe Ferber
 
Cloud computing and innovations
SPIN Chennai
 
Sanger, upcoming Openstack for Bio-informaticians
Peter Clapham
 
Flexible compute
Peter Clapham
 
Service Discovery and Registration in a Microservices Architecture
PLUMgrid
 
Openstack Summit Tokyo 2015 - Building a private cloud to efficiently handle ...
Pierre GRANDIN
 
Big Data and OpenStack, a Love Story: Michael Still, Rackspace
OpenStack
 
AWS Pentesting
MichaelRodriguesdosS1
 
Securing Microservices in Containerized Environments
DevOps.com
 
Ad

More from PLUMgrid (10)

PPTX
In-kernel Analytics and Tracing with eBPF for OpenStack Clouds
PLUMgrid
 
PDF
Networking For Nested Containers: Magnum, Kuryr, Neutron Integration
PLUMgrid
 
PPTX
Implementing vCPE with OpenStack and Software Defined Networks
PLUMgrid
 
PDF
Docker Networking in Swarm, Mesos and Kubernetes [Docker Meetup Santa Clara |...
PLUMgrid
 
PDF
Unified Underlay and Overlay SDNs for OpenStack Clouds
PLUMgrid
 
PPTX
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
PLUMgrid
 
PDF
EBPF and Linux Networking
PLUMgrid
 
PPTX
Network Monitoring and Analytics
PLUMgrid
 
PPTX
Navigating OpenStack Networking
PLUMgrid
 
PPTX
Docker Networking in OpenStack: What you need to know now
PLUMgrid
 
In-kernel Analytics and Tracing with eBPF for OpenStack Clouds
PLUMgrid
 
Networking For Nested Containers: Magnum, Kuryr, Neutron Integration
PLUMgrid
 
Implementing vCPE with OpenStack and Software Defined Networks
PLUMgrid
 
Docker Networking in Swarm, Mesos and Kubernetes [Docker Meetup Santa Clara |...
PLUMgrid
 
Unified Underlay and Overlay SDNs for OpenStack Clouds
PLUMgrid
 
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
PLUMgrid
 
EBPF and Linux Networking
PLUMgrid
 
Network Monitoring and Analytics
PLUMgrid
 
Navigating OpenStack Networking
PLUMgrid
 
Docker Networking in OpenStack: What you need to know now
PLUMgrid
 

Recently uploaded (20)

PDF
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
PDF
Blockchain Transactions Explained For Everyone
CIFDAQ
 
PDF
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
PDF
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PPTX
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
PPTX
From Sci-Fi to Reality: Exploring AI Evolution
Svetlana Meissner
 
PDF
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
PDF
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
PDF
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
PDF
LLMs.txt: Easily Control How AI Crawls Your Site
Keploy
 
PDF
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
PDF
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
PPTX
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
Blockchain Transactions Explained For Everyone
CIFDAQ
 
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
From Sci-Fi to Reality: Exploring AI Evolution
Svetlana Meissner
 
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
LLMs.txt: Easily Control How AI Crawls Your Site
Keploy
 
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 

Design and Deploy Secure Clouds for Financial Services Use Cases

  • 1. Design and Deploy Secure Clouds for Financial Services – Use Cases August 18, 2016
  • 2. Copyright © PLUMgrid, Inc. 2011-2015 Introduction Speakers 2 Principal Solutions Architect Justin Moore Sr. Solution Architect – OpenStack Tiger Team Joe Antkowiak PLUMgrid Red Hat
  • 3. Copyright © PLUMgrid, Inc. 2011-2015 Agenda What’s will be covered today 3 1 OpenStack Infrastructure Security - Addressing Common Security Challenges using Red Hat OpenStack Platform Security and compliance through automation and micro-segmentation with OpenStack and SDN Micro-Segmentation Demo3 2
  • 4. OpenStack Infrastructure Security Addressing Common Security Challenges using Red Hat OpenStack Platform Joe Antkowiak Sr Solution Architect August 18, 2016
  • 5. Agenda  Common OpenStack Infrastructure Security Challenges  Addressing Challenges with Red Hat OpenStack Platform Director  Addressing Challenges with Red Hat CloudForms
  • 6. OpenStack Infrastructure Security Common Challenges  Many Manual Tasks  Infrastructure Secured Post Deployment  Detecting Change and Enforcing Policy  Maintaining Secure Configuration and Policy When Upgrading and Scaling
  • 7. <footer> OPENSTACK PLATFORM DIRECTOR DAY 1 + SCALING/UPGRADING Director is included in Red Hat OpenStack Platform CLOUDFORMS DAY 2 + LIFECYCLE CloudForms is included in Red Hat OpenStack Platform
  • 8. <footer> Red Hat OpenStack Platform Director DEPLOYMENTPLANNING OPERATIONS Updates and upgrades Scaling up and down Change management Deployment orchestration Service configuration Sanity checks Network topology Service parameters Resource capacity OpenStack Orchestration
  • 9. OpenStack Platform Director (OSPd) Advantages for OpenStack Security USES OPENSTACK TO DEPLOY OPENSTACK Concepts applicable to workloads running on OpenStack are applicable to OpenStack itself IMAGE BASED Nodes installed from a customize-able source image TEMPLATE BASED Customize-able, reusable, repeatable use of Heat templates (YAML) to install, scale, and upgrade
  • 10. OSP Director Image Customization Image Customization Examples for Security KERNEL Deploy a custom kernel build, or hardened kernel (with validation) PACKAGES Deploy specific package versions or additional packages LOCAL ACCOUNTS AND POLICIES Define custom local accounts and SELinux configuration
  • 11. OSP Director Template-Based Deployment Template-Based Configuration Examples for Security SSL/TLS ENABLED CONTROL PLANE AND ENDPOINTS Enable transport encryption on all control plane communication using your certificates AAA INTEGRATION Integrate with your AAA infrastructure (LDAP, Kerberos, etc) SERVICES CONFIGURATION Configure Logging, NTP, Monitoring Tools
  • 13. CloudForms Compliance and Governance ANALYZE Automatically perform SmartState Analysis on OpenStack Nodes and Instances (agent-less) TRACK AND ALERT Report on changes and drift, automatically alert based on defined policy REMEDIATE Automatically kick off defined remediation or deeper inspection actions Example Functions
  • 14. CloudForms SmartState Analysis Examples of Items Tracked PACKAGES AND FILES Package versions, new/changed files LOCAL USERS AND ACTIONS User actions/commands, users and groups added or changed COMPONENT CHANGES Added or changed network interfaces, storage attached, new instances or containers running
  • 15. Thank you! Please Post Questions in Webinar Visit Red Hat at OpenStack East August 23-24, NYC red.ht/openstack red.ht/cloudforms
  • 16. Security and compliance through automation and micro-segmentation with OpenStack and SDN Justin Moore
  • 17. Copyright © PLUMgrid, Inc. 2011-2015 • Regulatory Compliance • PCI • SOX • Security • Separation of concerns • Minimize attack surface • Strict enforcement of access control • Operations • Reduce manual effort through automation • Protect against misconfiguration • Dev/Test pointed to Prod • Incorrect or invalid firewall rule • Server placed on wrong network • Rapidly scale Technology Challenges in FSI
  • 18. Copyright © PLUMgrid, Inc. 2011-2015 • Too slow • Ticket based manual workflows take days or weeks • New methodologies demand on-demand infrastructure, and tight integration with the SDLC • Agile • CI/CD • Micro-services • Error prone • Lack of automation and standardization leads to errors • Incomplete or inadequate de-comission processes • Too expensive • Scale-up Access Control devices/Forklift upgrades • Highly skilled and highly paid engineers performing trivial ticket based activities Traditional Approaches No Longer Work 18
  • 19. Copyright © PLUMgrid, Inc. 2011-2015 • Cloud! • Ok – it’s not really that simple. What about all of that security stuff? • SDN! • Again – it’s not really as simple as buying an SDN. • How will we design the system to ensure that security is baked into the end-to-end environment? • Micro-segmentation • Great – another buzzword! • Micro-segmentation is the process of controlling access to and from a service based on the combination of security boundary and attack foot- print • Don’t we already do that? • Not really! So How Do We Keep Up? 19
  • 20. Copyright © PLUMgrid, Inc. 2011-2015 Virtual Domains Your Private Virtual Data Center 20 • Tenant Virtual Domains • Isolation & segmentation of workloads • Self-service provision of all functions • Service Virtual Domains • Owned by Cloud Operator • Used to apply common services or security policies • Hosts external connectivity • Virtual Domain Chaining • Decouple changes from physical infrastructure • Fully distributed within IO Visor layer on each compute node DNS Service Virtual Domain Tenant Virtual Domains
  • 21. Copyright © PLUMgrid, Inc. 2011-2015 PLUMgrid Virtual Domains Components of a Virtual Domain 21 Virtual Domain DistributedPolicy EnforcementZone Edge Policy Enforcement Point Virtual Domain (VD) — ISOLATION • Secure Tenant Isolation for multi-tenant clouds Contains all Network definitions for that Project • Rich set of analytics and monitoring • Option to encrypt traffic on a per VD basis Topology — Overlay based fully Distributed Network Functions • Network topology view • DVS/DVR/NAT/DNS/DHCP functions • Fully Distributed (No hairpin or network nodes) • Integration with external VTEP Gateways • Topology based Service Insertion (FW/LB/IPS) Policy boundary — SEGMENTATION • Group Based Policies & Micro-segmentation • All traffic in-out of VD goes through Policy Engine • Used for Security Groups (L2-4 stateless or state- full security) • Policy based VTAP (traffic capture) • Policy based Service Insertion (FW/LB/IPS) • Support for Service Chains or single Service Function
  • 22. Copyright © PLUMgrid, Inc. 2011-2015 PLUMgrid ONS Components 22 Internet IO Visor Gateway IO Visor Edges (Compute Nodes) PLUMgrid Directors VXLAN-based Overlay PLUMgrid CloudApex & OpsVM
  • 23. Copyright © PLUMgrid, Inc. 2011-2015 Example Application – Customer Service Tool 23 DNS Global Cloud Policy Prod CSTDev CST
  • 24. Copyright © PLUMgrid, Inc. 2011-2015 Three-Tier Architecture Presentation tier Logic tier Data tier Database Storage GET LIST OF ALL SALES MADE LAST YEAR ADD ALL SALES TOGETHER > GET SALES TOTAL > GET SALES TOTAL 4 TOTAL SALES QUERY SALE 1 SALE 2 SALE 3 SALE 4
  • 25. Copyright © PLUMgrid, Inc. 2011-2015 PLUMgrid Policy Path 25 Group Classification (source & destination End Point classification) Packets - sMAC / .1Q - src_IP/dst_IP - Application / Ports - Protocols Meta Data - Tenant ID / App ID - VM UUID / Name - End Point Type / Group - Location / physical Server Behavior - Traffic Profile - Sys Call profile - Storage Access Profile Stateful Security Groups Security Logs & Alerts Policy based VTAP Traffic mirroring Policy based Service Insertion VNF 1 VNF 2 VNF 3 - Service Chains - Distributed Service Insertion - Local Affinity
  • 27. Q&A Please use the Q&A panel to ask questions
  • 28. Copyright © PLUMgrid, Inc. 2011-2015 THANK YOU!