SlideShare une entreprise Scribd logo
1  sur  45
Télécharger pour lire hors ligne
Barracuda Networks
  World War Web – juin 2011
Stéphane Castagné / Sébastien Braun
Agenda
Barracuda Networks.

Un brin d'histoire.

Simplifier l'IT avec un arc !

   Administration centralisée
   Redondance des liens WAN
   Contrôle au niveau applicatif.
« Fournisseur de solutions sécurité IP »

- Création 2003 – HQ Californie – 800 Personnes.
- 145 000 Clients monde.

- Mission : Simplifier l'administration et la gestion IT
- Environnements (Appliances, VM et Cloud)
- Protection des accès, des applications et des données.
Solution globale
de sécurité IP



Accés


Applications



Données
Clients France
Un brin d'histoire …
Le client :
L'un des plus grands data center du secteur bancaire autrichien.


Le Challenge:
650 firewalls
Industrialisation du déploiement ?
2 administrateurs dédiés !

L'incubation
Le Résultat:
Technologie NG Firewall
Un design conçu pour la sécurité distribuée
Une page blanche ...
                                                                                UTM
                                               UTM
                                                                            + P2P Blocker
                       2005                + P2P Blocker
                                                                           + WAN optimizer


                                                                                                          UTM
                                                                                                      + P2P Blocker
                                                                                                     + WAN optimizer
                                                                                                         + NAC
SPI Firewall
 + IPS/IDS
+ Anti-Virus
+ Web Filter


                                                                                                                             UTM
                                              MGMT ?
                                                                                                                        + P2P Blocker
                                                                                                                       + WAN optimizer
 SPI Firewall
                                                                                                                             +NAC
  + IPS/IDS
                                                                                                                        + Link balancer
 + Anti-Virus

                                                                                                      UTM
                                    1990
                                                                                                + P2P Blocker
                                                                                               + WAN optimizer
                SPI Firewall
                                                                                                     + NAC
                 + IPS/IDS
                                                       2010: NG Firewall                        + Link balancer
                               SPI Firewall                                                  + Application control
Centralized Management
Crayonner des tunnels VPN
Création rapide de VPN
par drag & drop
Template pour les architectures
fully meshed ou hub & spoke
Simplifie le management des VPN
Architecture WAN                                                   Cloud Public
hétérogène


      •   Cloud Privé
                      Resilient Site-2-Site
                         Connections




                                              HQ-
                                              LAN
                                               HQ-LAN
            Branch
            Offices




                                                   Road warriors
Redondance des liens WAN
Intelligent Traffic Management
•Application-based                             •Per User and/or Group
•For Encrypted and Unencrypted Traffic         •Per Source and Destination
                                               •Time of day, weekday, date
                       DSL
                                 Internet:              50%
                                 Email                  50%


                      MPLS       VoIP before
                                 Business              70%
                                 VoIP before Business 100%
                                 Internet              10%
                                 Email                 20%
       Routing                                                                 Routing
                       3G        VoIP before
                                 Business                80%
     VPN Tunnel                  Internet                 5%                 VPN Tunnel
     Branch Office                                                           Headquarters
                                 Email                   15%
Contrôle au niveau applicatif

                                       Layer 7
                                       Application
                                       Control
                                                                             +

                                                                 NG      plain HTTP
                                                              Firewall   bittorrent



                                                                              +

          Plus de 800 applications détectées:
          Peer-to-Peer (P2P), Instant Messaging (IM), Standard
          Protocols, Voice over IP (VoIP), Streaming Protocols,
          Tunnel Protocols, Gaming Protocols, Business
          Protocols, Mobile Internet Protocols
Illustration du contrôle au niveau applicatif

Que fait réellement cet utilisateur




                                                            interdire
Nous pouvons maintenant ajuster le politique de sécurité…    limiter
Trois points clefs
 L'architecture Firewall NG simplifie l'IT en intégrant dans
son administration centralisée l'ensemble des
fonctionnalités d'un Firewall Next Generation :

Une redondance des liens WAN grâce à l'ADSL et/ou la
3G [Traffic Intelligence]
   le contrôle au niveau applicatif.



          … N'oubliez pas l'arc dans vos architectures !
Firmware 5.2
Web Filter
•

–Barracuda Web Filter Engine
–Included with EU -> Best value in NG Firewall market



IPS
•

–   Included with EU -> Best value in NG Firewall market
GeoMaps in CC
•

–no extra cost
–unique in NG Firewall market



DC Agent (5.2.1)
•

–   Enables clientless user <-> IP recognition
Geo Maps in Control Center (any CC and any MC)
Website: all specs and sizing information
Datasheet: -> On Website
Barracuda NG Firewall Introduction
“Next generation” firewall:                       Industry-leading centralized
●Layer 7 application profiling                       management:
●Identity aware networking                        ●Scalable and fault tolerant central management
●Dynamic Application Control Monitoring           ●Template-based management


●Network access control                           ●Distributed Firewall


●Intrusion Detection and Prevention               ●Multi-tenancy


●Integrated Content Filter (Malware Protection,   ●Compliance and Revision Control System

Web filter, Secure Web Proxy)                     ●Effective troubleshooting

●Integrated Web Cache Proxy


●Infrastructure and Application Proxies:

DHCP, FTP, SSH, DNS, SMTP, POP3
●Enterprise-class Firewall and next generation

VPN with customizable encryption
●Integrated SSL VPN


●Traffic Shaping and Quality of Service (QoS)


●Multiple uplink support
Q&A
Merci !!!

sbraun@barracuda.com
Where does the Barracuda NG Firewall come from?

Result of acquisition of phion AG

−Public European NG Firewall company
−Company HQ in Innsbruck, Austria


−10+ years experience in space


−1,000+ Enterprise customers


−15,000+ deployed appliances

(4,589 shipped in 2009)
−100,000+ licensed VPN users
The Paradigm of Next Generation Firewalls


          “Traditional“ Network Firewall   Next Generation Firewall
Why do we need “another firewall“ ?


            “Traditional“ Network Firewall   Next Generation Firewall


      + Integrated Content Security
Distributed Secure Web Access


    + Integrated Content Security for distributed environments

                                                              Caching /
                 HTTPS    Malware                    FTP                  NTP Proxy                 POP3
    HTTP Proxy                        Web filter             Forwarding               SMTP Proxy
                 Proxy   Protection                Gateway                 Service                 Gateway
                                                                DNS
Network Access Control


   + Network access control for distributed environments

   Connection    Endpoint       Policy       Guest       802.1x   Identity                Context
                                                                             Clientless             Easy of Use
     aware      protection   Enforcement   Networking   support    Aware                   Aware
Why do we need “another firewall“ ?


            “Traditional“ Network Firewall   Next Generation Firewall


      + Integrated Content

     + Network access control

     + Intelligent Traffic Management
Intelligent Traffic Management

   + Intelligent Traffic Management for distributed Environments

                   Easy
   High Secure               Visualization   Intelligence                  Multiple    Prioritizatio     Link-
                 Graphical                                  Application
      VPN                      through          Traffic                   Connection         n          & Load     Compression
                  Tunnel                                      Aware
   Technology                  NG Earth        Manager                     Handling        QoS         Balancing
                 Interface
Why do we need another firewall ?

          “Traditional“ Network Firewall   Next Generation Firewall


    + Integrated Content Security

    + Network access control
Why do we need “another firewall“ ?


            “Traditional“ Network Firewall   Next Generation Firewall


      + Integrated Content

     + Network access control

     + Intelligent Traffic Management

     + Scalability and Manageability
Industry leading centralized management


   + Scalability and Manageability

                           Template                 Superior
   Role based    Multi                  Central                                      Central log
                          and device                Revision     PKI       100%                      Powerful
   Multi User   Tenancy                 Statistic                                    and event
                            based                   Control    Service   Lifecycle                 Visualization
     Aware      support                Collection                                    processing
                            design                   System
Why do we need “another firewall“ ?

           “Traditional“ Network Firewall   Next Generation Firewall


     + Integrated Content

    + Network access control

    + Intelligent Traffic Management

    + Scalability and Manageability



           = The Next Generation Firewall designed
                 for Distributed Environments
Barracuda NG Firewall key value propositions

Reduce the number of deployed point solutions
–One product family with one management framework covering multiple topics

–Reduce maintenance cost and simplify management lifecycle
Barracuda NG Firewall key value propositions

Saving time and money for troubleshooting
–Determine issue with 2-3 mouse clicks

–Unique 5-tier information architecture (live, history, events, accounting, audit trail)

–Real-time firewall monitoring without performance degradation
Barracuda NG Firewall key value propositions

•Reduce line costs without adverse side effects
–By aggregating bandwidth from MPLS and cheaper alternatives

–3G broadband as a cheap backup line

–Detect and reduce bandwidth hogging through covert Layer 7 traffic (P2P, IM,
etc.)
Barracuda NG Firewall key value propositions

•Not every administrator has to be an expert
–Have multiple administrators work on the firewall simultaneously with clear cut
custom roles (comprising up to 90 attributes)

–A flexible administration concept supports joint administration in an outsourced
environment without the danger of compromising SLAs
Sample Reference Customers
EADS (HQ, IST, LFK, Defense Sys)
Aerospace and Defense
RAS, VPN-Site-2-Site, Firewalls
RHI
Market leader fireproof materials
130 VPN/FW Gateways
Konica Minolta Europe
VPN/FW Gateways
Schenker Germany
Logistics and Transportation
200 VPN/Firewall Gateways
German Postbank
Bank branch office security
2900 VPN/FW Gateways
The Barracuda NG Firewall Concept
                                              + Adaptive WAN Routing,
                                               Click to edit the
                                               
                                              + Bandwidth Control
                                              + Remote Access Concept
                                              outline text format
                                              + Scalability

                    + Application Profiling   Second Outline Level
                    + User Awareness
                                                Third OutlineNetwork
                                                                 WAN Level
  Ports                                                          Performance
  Protocols                                   Fourth Outline Level
                                                                 Enhancement
  Packets                              Application Control
                                       ID AwareFifth Outline savings
                                                 Network         cost
                                                                      Level
                                                Sixth Outline Level
                                          cost savings
              network firewall            NG firewall
                                                Seventh Outline Level
                                                Eighth Outline Level
                                                         Barracuda NG firewall
Barracuda NG Firewall Product Line-Up
                                                                                                                 F900


                             10Gbps
                                                                                                    F800


                                                                                           F600

                                                                                 F400
                             1 Gbps
                                                                        F300

                                                           F20x
Firewall Perform




                                               F10x
                                 F10
                      POS       small remote          remote      Small/medium     Large          Large HQ and
                      SOHO         office             office          HQ            HQ            Datacenters
Comprehensive Feature Integration
Cost Effective Central Management
Central management of
ALL functions
 FW, VPN. SSL VPN, web security, anti
spam, application control ….everything
 Underlying OS
 Patches
Multi-admin
Multi-tenant
Management Views – Barracuda NG Earth
   Are you also tired of endless „flat“ status listings?
Barracuda NG Control Center Appliances
C400 Standard Edition      C610 Enterprise Edition




   (1 Group, UL Boxes)           (UL Groups, UL Boxen)

Barracuda NG Control Center Vx Appliances
VC400 Standard Edition
VC610 Enterprise Edition
VC820 Global Edition
ding edge biotech company ensures security and availability ofof a trans-Atlantic WAN with the Barracuda NG Firewall
ading edge biotech company ensures security and availability a transcontinental WAN with the Barracuda NG Firewa




     Reference Customer: Micromet, Inc.
     Micromet , Inc. Facts and Figures:


     public   company, NASDAQ (MITI)
        phion customer since 2006
        Gateways, clients and CC standard edition deployed on two continents


                   “Leading edge biotech company ensures security and
                   availability of a trans-Atlantic WAN with the
                   Barracuda NG Firewall.”
Reference customer: Micromet, Inc.




                              50 road warriors
“…the Barracuda NG
Firewall appliances are the
dependable backbone of
our network. Admins no
longer have to get up at
night and worry about
broken IPSec tunnels. “                 One centrally managed solution:
                                        • Firewall + local Web Access
Mr. Werner Jacobs, Dir IT
                                        • Site-2-site & Client VPN,
Administration

Contenu connexe

Similaire à Barracuda - AG France IX - Juin-2011

Next Generation Security
Next Generation SecurityNext Generation Security
Next Generation Securityneoma329
 
Intoto Linley Tech Utm Architecture Presentation
Intoto Linley Tech Utm Architecture PresentationIntoto Linley Tech Utm Architecture Presentation
Intoto Linley Tech Utm Architecture Presentationsaddepalli
 
NetSafe - 11nov2011
NetSafe - 11nov2011NetSafe - 11nov2011
NetSafe - 11nov2011Agora Group
 
Sophos utm-roadshow-south africa-2012
Sophos utm-roadshow-south africa-2012Sophos utm-roadshow-south africa-2012
Sophos utm-roadshow-south africa-2012dvanwyk30
 
Vfm palo alto next generation firewall
Vfm palo alto next generation firewallVfm palo alto next generation firewall
Vfm palo alto next generation firewallvfmindia
 
Ixia anue maximum roi from your existing toolsets
Ixia anue   maximum roi from your existing toolsetsIxia anue   maximum roi from your existing toolsets
Ixia anue maximum roi from your existing toolsetsresponsedatacomms
 
Ixia anue maximum roi from your existing toolsets
Ixia anue   maximum roi from your existing toolsetsIxia anue   maximum roi from your existing toolsets
Ixia anue maximum roi from your existing toolsetsresponsedatacomms
 
Tradeshowpreso1
Tradeshowpreso1Tradeshowpreso1
Tradeshowpreso1Simpletel
 
Clavister security for virtualized environment
Clavister security for virtualized environmentClavister security for virtualized environment
Clavister security for virtualized environmentnicolasotira
 
Core Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & BeyondCore Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & BeyondRadisys Corporation
 
Cambium networks prensent
Cambium networks prensentCambium networks prensent
Cambium networks prensentjmmypham
 
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Ari Zoldan
 
Aruba Remote Networks
Aruba Remote NetworksAruba Remote Networks
Aruba Remote Networkshypknight
 
VoIP Connectivity Table
VoIP Connectivity TableVoIP Connectivity Table
VoIP Connectivity TableBraun Mincher
 
Firetide Q4 Update
Firetide Q4 UpdateFiretide Q4 Update
Firetide Q4 UpdateFiretide
 
Rebaca Technologies Corporate Overview
Rebaca Technologies Corporate OverviewRebaca Technologies Corporate Overview
Rebaca Technologies Corporate Overviewsumitkhandelwal
 
Presentation f5 – beyond load balancer
Presentation   f5 – beyond load balancerPresentation   f5 – beyond load balancer
Presentation f5 – beyond load balancerxKinAnx
 
Lte Latin America 2011 Ims Assuming An Important Role On Lte V1.0
Lte Latin America 2011   Ims Assuming An Important Role On Lte V1.0Lte Latin America 2011   Ims Assuming An Important Role On Lte V1.0
Lte Latin America 2011 Ims Assuming An Important Role On Lte V1.0Alberto Boaventura
 

Similaire à Barracuda - AG France IX - Juin-2011 (20)

Next Generation Security
Next Generation SecurityNext Generation Security
Next Generation Security
 
Intoto Linley Tech Utm Architecture Presentation
Intoto Linley Tech Utm Architecture PresentationIntoto Linley Tech Utm Architecture Presentation
Intoto Linley Tech Utm Architecture Presentation
 
NetSafe - 11nov2011
NetSafe - 11nov2011NetSafe - 11nov2011
NetSafe - 11nov2011
 
Sophos utm-roadshow-south africa-2012
Sophos utm-roadshow-south africa-2012Sophos utm-roadshow-south africa-2012
Sophos utm-roadshow-south africa-2012
 
S series presentation
S series presentationS series presentation
S series presentation
 
Vfm palo alto next generation firewall
Vfm palo alto next generation firewallVfm palo alto next generation firewall
Vfm palo alto next generation firewall
 
Ixia anue maximum roi from your existing toolsets
Ixia anue   maximum roi from your existing toolsetsIxia anue   maximum roi from your existing toolsets
Ixia anue maximum roi from your existing toolsets
 
Ixia anue maximum roi from your existing toolsets
Ixia anue   maximum roi from your existing toolsetsIxia anue   maximum roi from your existing toolsets
Ixia anue maximum roi from your existing toolsets
 
Tradeshowpreso1
Tradeshowpreso1Tradeshowpreso1
Tradeshowpreso1
 
Clavister security for virtualized environment
Clavister security for virtualized environmentClavister security for virtualized environment
Clavister security for virtualized environment
 
Core Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & BeyondCore Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & Beyond
 
Cambium networks prensent
Cambium networks prensentCambium networks prensent
Cambium networks prensent
 
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
 
Aruba Remote Networks
Aruba Remote NetworksAruba Remote Networks
Aruba Remote Networks
 
VoIP Connectivity Table
VoIP Connectivity TableVoIP Connectivity Table
VoIP Connectivity Table
 
Firetide Q4 Update
Firetide Q4 UpdateFiretide Q4 Update
Firetide Q4 Update
 
Rebaca Technologies Corporate Overview
Rebaca Technologies Corporate OverviewRebaca Technologies Corporate Overview
Rebaca Technologies Corporate Overview
 
F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)
 
Presentation f5 – beyond load balancer
Presentation   f5 – beyond load balancerPresentation   f5 – beyond load balancer
Presentation f5 – beyond load balancer
 
Lte Latin America 2011 Ims Assuming An Important Role On Lte V1.0
Lte Latin America 2011   Ims Assuming An Important Role On Lte V1.0Lte Latin America 2011   Ims Assuming An Important Role On Lte V1.0
Lte Latin America 2011 Ims Assuming An Important Role On Lte V1.0
 

Plus de France IX Services

IXP Best Common Practices trilogy - for the Infrastructure
IXP Best Common Practices trilogy -  for the InfrastructureIXP Best Common Practices trilogy -  for the Infrastructure
IXP Best Common Practices trilogy - for the InfrastructureFrance IX Services
 
Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...
Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...
Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...France IX Services
 
Hurricane Electric - Ipv6 implementation in Europe
Hurricane Electric - Ipv6 implementation in EuropeHurricane Electric - Ipv6 implementation in Europe
Hurricane Electric - Ipv6 implementation in EuropeFrance IX Services
 
France-IX - Presentation for the general meeting 2012
France-IX - Presentation for the general meeting 2012France-IX - Presentation for the general meeting 2012
France-IX - Presentation for the general meeting 2012France IX Services
 
Extreme networks - Multi-Pathing L2 & SDN
Extreme networks - Multi-Pathing L2 & SDNExtreme networks - Multi-Pathing L2 & SDN
Extreme networks - Multi-Pathing L2 & SDNFrance IX Services
 
Case Study France-IX InterCloud
Case Study France-IX InterCloudCase Study France-IX InterCloud
Case Study France-IX InterCloudFrance IX Services
 
Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...
Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...
Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...France IX Services
 
White Paper on Peering in France
White Paper on Peering in FranceWhite Paper on Peering in France
White Paper on Peering in FranceFrance IX Services
 
Etude cas France-IX InterCloud
Etude cas France-IX InterCloudEtude cas France-IX InterCloud
Etude cas France-IX InterCloudFrance IX Services
 
Le livre Blanc du Peering en France
Le livre Blanc du Peering en FranceLe livre Blanc du Peering en France
Le livre Blanc du Peering en FranceFrance IX Services
 
Brocade - AG France IX - 30 Juin 2011
Brocade - AG France IX - 30 Juin 2011Brocade - AG France IX - 30 Juin 2011
Brocade - AG France IX - 30 Juin 2011France IX Services
 
Integra - AG France IX - 30 Septembre 2011
Integra - AG France IX - 30 Septembre 2011Integra - AG France IX - 30 Septembre 2011
Integra - AG France IX - 30 Septembre 2011France IX Services
 
LU-CIX - AG France IX - 30 Septembre 2011
LU-CIX - AG France IX - 30 Septembre 2011LU-CIX - AG France IX - 30 Septembre 2011
LU-CIX - AG France IX - 30 Septembre 2011France IX Services
 
Cube optics - AG France IX - 30 Septembre 2011
Cube optics - AG France IX - 30 Septembre 2011Cube optics - AG France IX - 30 Septembre 2011
Cube optics - AG France IX - 30 Septembre 2011France IX Services
 

Plus de France IX Services (20)

IXP Best Common Practices trilogy - for the Infrastructure
IXP Best Common Practices trilogy -  for the InfrastructureIXP Best Common Practices trilogy -  for the Infrastructure
IXP Best Common Practices trilogy - for the Infrastructure
 
Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...
Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...
Africa Internet Summit 2013 - France-IX - challenges of setting up a new IXP ...
 
TouIX
TouIXTouIX
TouIX
 
Top-IX
Top-IX Top-IX
Top-IX
 
Hurricane Electric - Ipv6 implementation in Europe
Hurricane Electric - Ipv6 implementation in EuropeHurricane Electric - Ipv6 implementation in Europe
Hurricane Electric - Ipv6 implementation in Europe
 
France-IX - Presentation for the general meeting 2012
France-IX - Presentation for the general meeting 2012France-IX - Presentation for the general meeting 2012
France-IX - Presentation for the general meeting 2012
 
Extreme networks - Multi-Pathing L2 & SDN
Extreme networks - Multi-Pathing L2 & SDNExtreme networks - Multi-Pathing L2 & SDN
Extreme networks - Multi-Pathing L2 & SDN
 
Case Study France-IX InterCloud
Case Study France-IX InterCloudCase Study France-IX InterCloud
Case Study France-IX InterCloud
 
Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...
Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...
Résilience de l'internet, point de vue de l'opérateur de point d'échange Fran...
 
White Paper on Peering in France
White Paper on Peering in FranceWhite Paper on Peering in France
White Paper on Peering in France
 
Etude cas France-IX InterCloud
Etude cas France-IX InterCloudEtude cas France-IX InterCloud
Etude cas France-IX InterCloud
 
Le livre Blanc du Peering en France
Le livre Blanc du Peering en FranceLe livre Blanc du Peering en France
Le livre Blanc du Peering en France
 
Brocade - AG France IX - 30 Juin 2011
Brocade - AG France IX - 30 Juin 2011Brocade - AG France IX - 30 Juin 2011
Brocade - AG France IX - 30 Juin 2011
 
France IX - AG Juin 2011
France IX - AG Juin 2011France IX - AG Juin 2011
France IX - AG Juin 2011
 
France IX - AG Septembre 2011
France IX - AG Septembre 2011France IX - AG Septembre 2011
France IX - AG Septembre 2011
 
Integra - AG France IX - 30 Septembre 2011
Integra - AG France IX - 30 Septembre 2011Integra - AG France IX - 30 Septembre 2011
Integra - AG France IX - 30 Septembre 2011
 
LU-CIX - AG France IX - 30 Septembre 2011
LU-CIX - AG France IX - 30 Septembre 2011LU-CIX - AG France IX - 30 Septembre 2011
LU-CIX - AG France IX - 30 Septembre 2011
 
Cube optics - AG France IX - 30 Septembre 2011
Cube optics - AG France IX - 30 Septembre 2011Cube optics - AG France IX - 30 Septembre 2011
Cube optics - AG France IX - 30 Septembre 2011
 
France IX - FRnOG 18
France IX - FRnOG 18France IX - FRnOG 18
France IX - FRnOG 18
 
France IX - Presentation
France IX - PresentationFrance IX - Presentation
France IX - Presentation
 

Dernier

08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdfChristopherTHyatt
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 

Dernier (20)

08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 

Barracuda - AG France IX - Juin-2011

  • 1. Barracuda Networks World War Web – juin 2011 Stéphane Castagné / Sébastien Braun
  • 2. Agenda Barracuda Networks. Un brin d'histoire. Simplifier l'IT avec un arc !  Administration centralisée  Redondance des liens WAN  Contrôle au niveau applicatif.
  • 3. « Fournisseur de solutions sécurité IP » - Création 2003 – HQ Californie – 800 Personnes. - 145 000 Clients monde. - Mission : Simplifier l'administration et la gestion IT - Environnements (Appliances, VM et Cloud) - Protection des accès, des applications et des données.
  • 4. Solution globale de sécurité IP Accés Applications Données
  • 6. Un brin d'histoire … Le client : L'un des plus grands data center du secteur bancaire autrichien. Le Challenge: 650 firewalls Industrialisation du déploiement ? 2 administrateurs dédiés ! L'incubation Le Résultat: Technologie NG Firewall Un design conçu pour la sécurité distribuée
  • 7. Une page blanche ... UTM UTM + P2P Blocker 2005 + P2P Blocker + WAN optimizer UTM + P2P Blocker + WAN optimizer + NAC SPI Firewall + IPS/IDS + Anti-Virus + Web Filter UTM MGMT ? + P2P Blocker + WAN optimizer SPI Firewall +NAC + IPS/IDS + Link balancer + Anti-Virus UTM 1990 + P2P Blocker + WAN optimizer SPI Firewall + NAC + IPS/IDS 2010: NG Firewall + Link balancer SPI Firewall + Application control
  • 9. Crayonner des tunnels VPN Création rapide de VPN par drag & drop Template pour les architectures fully meshed ou hub & spoke Simplifie le management des VPN
  • 10. Architecture WAN Cloud Public hétérogène • Cloud Privé Resilient Site-2-Site Connections HQ- LAN HQ-LAN Branch Offices Road warriors
  • 11. Redondance des liens WAN Intelligent Traffic Management •Application-based •Per User and/or Group •For Encrypted and Unencrypted Traffic •Per Source and Destination •Time of day, weekday, date DSL Internet: 50% Email 50% MPLS VoIP before Business 70% VoIP before Business 100% Internet 10% Email 20% Routing Routing 3G VoIP before Business 80% VPN Tunnel Internet 5% VPN Tunnel Branch Office Headquarters Email 15%
  • 12. Contrôle au niveau applicatif Layer 7 Application Control + NG plain HTTP Firewall bittorrent + Plus de 800 applications détectées: Peer-to-Peer (P2P), Instant Messaging (IM), Standard Protocols, Voice over IP (VoIP), Streaming Protocols, Tunnel Protocols, Gaming Protocols, Business Protocols, Mobile Internet Protocols
  • 13. Illustration du contrôle au niveau applicatif Que fait réellement cet utilisateur interdire Nous pouvons maintenant ajuster le politique de sécurité… limiter
  • 14. Trois points clefs L'architecture Firewall NG simplifie l'IT en intégrant dans son administration centralisée l'ensemble des fonctionnalités d'un Firewall Next Generation : Une redondance des liens WAN grâce à l'ADSL et/ou la 3G [Traffic Intelligence]  le contrôle au niveau applicatif. … N'oubliez pas l'arc dans vos architectures !
  • 15. Firmware 5.2 Web Filter • –Barracuda Web Filter Engine –Included with EU -> Best value in NG Firewall market IPS • – Included with EU -> Best value in NG Firewall market GeoMaps in CC • –no extra cost –unique in NG Firewall market DC Agent (5.2.1) • – Enables clientless user <-> IP recognition
  • 16. Geo Maps in Control Center (any CC and any MC)
  • 17. Website: all specs and sizing information
  • 18. Datasheet: -> On Website
  • 19. Barracuda NG Firewall Introduction “Next generation” firewall: Industry-leading centralized ●Layer 7 application profiling management: ●Identity aware networking ●Scalable and fault tolerant central management ●Dynamic Application Control Monitoring ●Template-based management ●Network access control ●Distributed Firewall ●Intrusion Detection and Prevention ●Multi-tenancy ●Integrated Content Filter (Malware Protection, ●Compliance and Revision Control System Web filter, Secure Web Proxy) ●Effective troubleshooting ●Integrated Web Cache Proxy ●Infrastructure and Application Proxies: DHCP, FTP, SSH, DNS, SMTP, POP3 ●Enterprise-class Firewall and next generation VPN with customizable encryption ●Integrated SSL VPN ●Traffic Shaping and Quality of Service (QoS) ●Multiple uplink support
  • 20. Q&A
  • 22. Where does the Barracuda NG Firewall come from? Result of acquisition of phion AG −Public European NG Firewall company −Company HQ in Innsbruck, Austria −10+ years experience in space −1,000+ Enterprise customers −15,000+ deployed appliances (4,589 shipped in 2009) −100,000+ licensed VPN users
  • 23. The Paradigm of Next Generation Firewalls “Traditional“ Network Firewall Next Generation Firewall
  • 24. Why do we need “another firewall“ ? “Traditional“ Network Firewall Next Generation Firewall + Integrated Content Security
  • 25. Distributed Secure Web Access + Integrated Content Security for distributed environments Caching / HTTPS Malware FTP NTP Proxy POP3 HTTP Proxy Web filter Forwarding SMTP Proxy Proxy Protection Gateway Service Gateway DNS
  • 26. Network Access Control + Network access control for distributed environments Connection Endpoint Policy Guest 802.1x Identity Context Clientless Easy of Use aware protection Enforcement Networking support Aware Aware
  • 27. Why do we need “another firewall“ ? “Traditional“ Network Firewall Next Generation Firewall + Integrated Content + Network access control + Intelligent Traffic Management
  • 28. Intelligent Traffic Management + Intelligent Traffic Management for distributed Environments Easy High Secure Visualization Intelligence Multiple Prioritizatio Link- Graphical Application VPN through Traffic Connection n & Load Compression Tunnel Aware Technology NG Earth Manager Handling QoS Balancing Interface
  • 29. Why do we need another firewall ? “Traditional“ Network Firewall Next Generation Firewall + Integrated Content Security + Network access control
  • 30. Why do we need “another firewall“ ? “Traditional“ Network Firewall Next Generation Firewall + Integrated Content + Network access control + Intelligent Traffic Management + Scalability and Manageability
  • 31. Industry leading centralized management + Scalability and Manageability Template Superior Role based Multi Central Central log and device Revision PKI 100% Powerful Multi User Tenancy Statistic and event based Control Service Lifecycle Visualization Aware support Collection processing design System
  • 32. Why do we need “another firewall“ ? “Traditional“ Network Firewall Next Generation Firewall + Integrated Content + Network access control + Intelligent Traffic Management + Scalability and Manageability = The Next Generation Firewall designed for Distributed Environments
  • 33. Barracuda NG Firewall key value propositions Reduce the number of deployed point solutions –One product family with one management framework covering multiple topics –Reduce maintenance cost and simplify management lifecycle
  • 34. Barracuda NG Firewall key value propositions Saving time and money for troubleshooting –Determine issue with 2-3 mouse clicks –Unique 5-tier information architecture (live, history, events, accounting, audit trail) –Real-time firewall monitoring without performance degradation
  • 35. Barracuda NG Firewall key value propositions •Reduce line costs without adverse side effects –By aggregating bandwidth from MPLS and cheaper alternatives –3G broadband as a cheap backup line –Detect and reduce bandwidth hogging through covert Layer 7 traffic (P2P, IM, etc.)
  • 36. Barracuda NG Firewall key value propositions •Not every administrator has to be an expert –Have multiple administrators work on the firewall simultaneously with clear cut custom roles (comprising up to 90 attributes) –A flexible administration concept supports joint administration in an outsourced environment without the danger of compromising SLAs
  • 37. Sample Reference Customers EADS (HQ, IST, LFK, Defense Sys) Aerospace and Defense RAS, VPN-Site-2-Site, Firewalls RHI Market leader fireproof materials 130 VPN/FW Gateways Konica Minolta Europe VPN/FW Gateways Schenker Germany Logistics and Transportation 200 VPN/Firewall Gateways German Postbank Bank branch office security 2900 VPN/FW Gateways
  • 38. The Barracuda NG Firewall Concept + Adaptive WAN Routing, Click to edit the  + Bandwidth Control + Remote Access Concept outline text format + Scalability + Application Profiling Second Outline Level + User Awareness Third OutlineNetwork WAN Level Ports Performance Protocols Fourth Outline Level Enhancement Packets Application Control ID AwareFifth Outline savings Network cost Level Sixth Outline Level cost savings network firewall NG firewall Seventh Outline Level Eighth Outline Level Barracuda NG firewall
  • 39. Barracuda NG Firewall Product Line-Up F900 10Gbps F800 F600 F400 1 Gbps F300 F20x Firewall Perform F10x F10 POS small remote remote Small/medium Large Large HQ and SOHO office office HQ HQ Datacenters
  • 41. Cost Effective Central Management Central management of ALL functions FW, VPN. SSL VPN, web security, anti spam, application control ….everything Underlying OS Patches Multi-admin Multi-tenant
  • 42. Management Views – Barracuda NG Earth Are you also tired of endless „flat“ status listings?
  • 43. Barracuda NG Control Center Appliances C400 Standard Edition C610 Enterprise Edition (1 Group, UL Boxes) (UL Groups, UL Boxen) Barracuda NG Control Center Vx Appliances VC400 Standard Edition VC610 Enterprise Edition VC820 Global Edition
  • 44. ding edge biotech company ensures security and availability ofof a trans-Atlantic WAN with the Barracuda NG Firewall ading edge biotech company ensures security and availability a transcontinental WAN with the Barracuda NG Firewa Reference Customer: Micromet, Inc. Micromet , Inc. Facts and Figures: public company, NASDAQ (MITI)  phion customer since 2006  Gateways, clients and CC standard edition deployed on two continents “Leading edge biotech company ensures security and availability of a trans-Atlantic WAN with the Barracuda NG Firewall.”
  • 45. Reference customer: Micromet, Inc. 50 road warriors “…the Barracuda NG Firewall appliances are the dependable backbone of our network. Admins no longer have to get up at night and worry about broken IPSec tunnels. “ One centrally managed solution: • Firewall + local Web Access Mr. Werner Jacobs, Dir IT • Site-2-site & Client VPN, Administration