ibm websphere datapower soa appliances simplify, help secure & govern your soa sidney antflick...

40
IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader [email protected]

Upload: ashley-dalton

Post on 24-Dec-2015

216 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA

Sidney Antflick

AP WebSphere Sales Leader

[email protected]

Page 2: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Agenda

• WebSphere DataPower Overview

• SOA Appliances’ Deployment & Scenario Summary

• Why an Appliance is Smart for SOA

• WebSphere DataPower SOA Appliance Portfolio: Integration Appliance XI50

XML Security Gateway XS40

XML Accelerator XA35

• Major Categories of SOA Appliance Functionality

• Summary

Page 3: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

An SOA Appliance…

WebSphere DataPower SOA Appliances redefine the boundaries of middleware extending the SOA Foundation with specialized,

consumable, dedicated SOA appliances that combine superior performance and hardened security for SOA implementations.

Simplifies SOA and accelerates time to value Helps secure SOA XML implementationsGoverns and enforces SOA/Web services policies

Creating customer value through extreme SOA connectivity, performance and security

WebSphere DataPower SOA Appliances

Page 4: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

• DataPower: Market leader in integration

and SOA appliances Accepted and supported

world-wide Leads with standards in SOA,

Security, Policy, etc.

• Used by banks, insurance cos., mutual

funds telcos, federal and local

governments, healthcare, general business

WebSphere DataPower SOA AppliancesExceptional growth and acceptance

Page 5: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

WebSphere DataPower SOA Appliances Address Critical Connectivity Issues

Simplicity Robustness

SpeedGovernance

Page 6: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Why an Appliance for SOA?

• Hardened, specialized hardware for helping to integrate, secure & accelerate SOA

• Many functions integrated into a single device: Impact: connectivity will require service level management, routing, policy,

transformation • Higher levels of security assurance certifications require hardware:

Example: government FIPS Level 3 HSM, Common Criteria• Enables run-time SOA governance and policy enforcement

Impact: dynamically control service availability, security, performance, and endpoint selection

• Higher performance with hardware acceleration: Impact: ability to perform more security checks without slow downs

• Addresses the divergent needs of different groups: Example: enterprise architects, network operations, security operations, identity

management, web services developers• Simplified deployment and ongoing management:

Impact: reduces need for in-house SOA skills & accelerates time to SOA benefits• Proven Green / IT Efficiency Value

Example: Appliance performs XML and Web services security processing as much as 72x faster than server-based systems

Impact: Same tasks accomplished with reduced system footprint and power consumption

Page 7: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Why an Appliance for SOA? TCO: DataPower Appliance vs. Software Based SolutionTop 10 Financial Services Company in North America

• Study compared expanding an existing software based solution vs. starting fresh with DataPower appliances

• Three primary drivers: 1) Reduce maintenance burden associated with software

based solution.2) Reduce overall yearly costs.3) Increase throughput and scale solution to meet growth

in business.

Cumulative Cost of Ownership over 3 years

Software Appliance

Infrastructure Operating Costs $1,728,000 $38,400

Application Development/Maintenance $118,800 $30,096

Capital Costs $1,268,640 $231,000

Product Maintenance charges $435,456 $78,000

Installation & Deployment $28,800 $2,000

Total $3,579,696 $379,496

Note: above figures obtained from cost accounting dept, not IT

Page 8: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Configuration driven Web GUI

Drag & Drop Workflow Style

Implement Complex Policies

No Programming, Less Errors

All Functions Available via CLI & SOAP Interface

Why an Appliance for SOA? Configuration vs. Programming

Page 9: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

IBM SOA Appliance Deployment Basic Examples

XMLXMLXSLXSL

InternetInternet

XMLXMLHTMLHTMLWMLWML

XA35XA35 ClientClientoror

ServerServer

XS40XS40

Tivoli Access Manager------------Federated

Identity Manager

HTTP XML REQHTTP XML REQ

HTTP XML RESPONSE HTTP XML RESPONSE

Web Services Web Services ClientClient

LEGACY REQLEGACY REQ

LEGACY RESPLEGACY RESP

REPLY

Q

REPLY

Q

XI50XI50

IP FirewallIP FirewallInternetInternet

AccelerationAcceleration

SecuritySecurity

Integration & GovernanceIntegration & Governance

Application ServerApplication Server

Application Server Web ServerApplication Server Web Server

DataPower XS40

DataPower XS40

Tivoli Access Manager

WebSphere App Server

MQ Server

Web service client

Nortel L7 Module

Tivoli NetView

DataPower XS40

DataPower XS40

Tivoli Access Manager

WebSphere App Server

MQ Server

Web service client

Nortel L7 Module

Tivoli NetView

DataPower XS40

DataPower XS40

Tivoli Access Manager

WebSphere App Server

MQ Server

Web service client

Nortel L7 Module

Tivoli NetView

ITCAM for SOA

`

Client

WSRR

Page 10: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

WebSphere DataPower SOA Appliance Product Line

XML Accelerator XA35 Offload XML processing No more hand-optimizing XML Lowers development costs

Integration Appliance XI50 Hardware ESB “Any-to-Any” Conversion at Wirespeed Bridges multiple protocols Integrated message-level security

XML Security Gateway XS40 Enhanced Security Capabilities Centralized Policy Enforcement Fine-grained authorization Rich authentication

Page 11: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Provide Service EnrichmentThe ESB

An Enterprise Service Bus (ESB) is a flexible connectivity infrastructure for integrating applications and services.

Shape = Transport protocol

Color = Data format

An ESB performs the following between requestor and service

CONVERTS between different transport protocols

MATCHES & ROUTES communications between services

TRANSFORMS between different data formats

IDENTIFIES & DISTRIBUTES business events

ESBESB

Page 12: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Integration Appliance XI50Purpose-built hardware ESB for simplified deployment and hardened security

• Redefines the boundaries of middleware with specialized hardware

• Many functions integrated into a single device

• Simplified deployment and ongoing management

• Routes messages based on content and policy

• Captures and emits events to facilitate web services management and enable business visibility in Business Activity Monitoring solutions

• Enables transformation between a wide range of data formats, including XML, legacy, and industry standards, and custom formats

• Optimized to bridge between leading standard protocols at wirespeed, including web services, messaging, files, and database access

• Secures services on the network with sophisticated web services access control, policy enforcement, message filtering, and field-level encryption

Page 13: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Extend your ESB to partners and customersWebSphere DataPower XML Security Gateway XS40

• XML firewall and filtering helps stop SOA threats

• Message-level encryption and access control enforcement

• Web services Authentication, Authorization & Auditing

• Helps promote Compliance (e.g. PCI, Sarbanes, etc)

ServiceMessageWebSphere DataPower XML

Security Gateway XS40

ESBESB

Page 14: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

XML Security Gateway XS40Web service threat protection and message security

• Centralizes XML security and policy enforcement

• Hardened security appliance for DMZ deployments

• Configuration-driven interface reduces need for specialized SOA skill sets

• Heterogeneous interoperability enables secure integrations with partners, customers, and/or vendors

• Supports a variety of access control mechanisms, and can control access by rejecting unsigned messages and verifying signatures within SAML assertions.

• Provides field-level XML security through encryption/decryption and signing/verification of entire messages or individual XML fields.

• Validates XML schemas and messages, protecting against XML attacks, buffer overflows, or vulnerabilities in malformed XML documents.

• Secures next-generation applications with an XML and SOAP firewall that filters any content, metadata, or network variables at wirespeed.

Page 15: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

• Accelerates XML processing and SSL termination/acceleration, increasing throughput, decreasing latency, and reducing server workload.

• Performs XML schema validation to ensure incoming/outgoing XML documents are legitimate and properly structured.

• Innovative XML pipeline processing and XML caching reduce impact of increased XML traffic, improving scalability of resource intensive applications.

• Fully integrated with industry standard IDEs such as Altova XML Spy and Eclipse allows developers to design, debug and deploy against a single XML and XSLT processor, saving valuable cycles from pilot to production.

XML Accelerator XA35Centralized XSLT Management, Offload XML Processing

• Wirespeed XML/XSLT/XPath Processing

• Schema validation, XML compression, XML caching

• SSL termination and acceleration

• Easy configuration and administration

Page 16: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

WebSphere DataPower Appliances Benefits

• Flexible Connectivity: an XML appliance shields the applications from security requirements, protocol changes and service versioning - no application modifications needed

• Reduce Complexity: Replace software servers functionality with an XML appliance, reduce infrastructure footprint, and off-load heavy processes to dedicated XML appliances

• Lower TCO: Dedicated XML appliances have shown to reduce operational costs by as much as 50%

• Improved Agility by Reduced Time to Market: dramatically decrease the testing time and amount of development required to upgrade your environment, most policies are configuration driven as opposed to development driven

• Reduce Risk: the XML appliance provides the connectivity layer without requiring application modification, and delivers improved security and audit support

• Configuration Driven: The XML appliance is configuration driven to do policy definitions, it does not involve development to support your infrastructure

Page 17: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

WebSphere DataPower Base Qualities & Features

Consumability

Connectivity / Integration

Performance

Security

Governance

Interoperability

Mas

low

’s H

iera

rchy

of

Ent

erpr

ise

Nee

ds

WS-SecurityWS-SecurityPolicy

Role-Based Management

WS-Policy

WS-MQ

XG3XG4

Off-box Management

Tibco EMS

WS-SIBDataGlue

WS-TX

HTTP 1.1 .Net SKI

Web GUI

CLI

Hardware & Firmware Tightly Coupled

Monolithic, Secured Firmware

SOAP Management

ITCAM for SOA

SNMP v3

Enterprise Service Bus

Smart SOA

Hardened

Flexible

TAM / TFIM

Database Connectivity

XACML

WS-Federation

LDAP

Strategic Theme

Major Quality

Specific Feature

diagram key

Multistep

WS-* Standards de facto Standards

WS-I Basic Profile

XSD SchemaSOAP

XMLXSLT

WS-SecureConversation

WSDLWSRR

UDDI

Service Level Management

FTP/ FTPS

SSL / TLS

Web App Firewall

Eclipse Plug-In

IBM patented technologyCrypto Acceleration

Optimally tuned firmware

Clustering and High Availability

Page 18: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Consumability

Connectivity / Integration

Performance

Security

Governance

Interoperability

WebSphere DataPower 3.7.1 Feature Additions

Strategic Theme

Major Quality

Specific Feature

diagram key

WSRR / WS-Policy Integration

MQ Ordered Messaging

WS-Policy interop with BEA and MSFT

Customer-driven enhancements

Improved WTX interop

Enhanced Tibco connectivity

Improved Database Connectivity

Configuration Profiler

RBM integration

CLI Install WizardOut of the box SNMP configuration

Updated WS-SecurityPolicy

Updated XACML support

WS-Policy GUI Improvements

MQ Tibco

Updated MQ sync point support

Locator beacon

Mas

low

’s H

iera

rchy

of

Ent

erpr

ise

Nee

ds

Page 19: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Consumability

Connectivity / Integration

Performance

Security

Governance

Interoperability

Strategic Theme

WebSphere DataPower 3.7.1 Feature Additions

Governance integration

Further improvements in

central policy controlSpecific Feature

WSRR / WS-Policy Integration

MQ Ordered Messaging

WS-Policy interop with BEA and MSFT

Usability improvements

Improved WTX interop

Enhanced Tibco connectivity

Database Stored Procedure return value

Configuration Profiler

Better RBM LDAP integration

CLI Install Wizard

Policy-driven SSL cert validation

GUI Improvements

Tibco enhancements

Updated MQ support

AAA cache invalidation control

LDAP bind-search-rebind

MQ Ordered Messaging

Configuration Mediations

Broader applications for MQ

More business problems can be

solved in existing MQ environments

Centralized security policy enhancements

Easily enable and disable users from

one central location

Locator beacon

Major Quality

diagram key

Even easier to operate and manage

For handling larger deployments

and new users alike

Interop for fast time to value

Testing and validation

Mas

low

’s H

iera

rchy

of

Ent

erpr

ise

Nee

ds

Page 20: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

WebSphere DataPower SOA Appliances v3.7.1 – Latest Innovations in Firmware

• Centralized policy and governance between WSRR and DataPower WSRR administrator submits WS-Policy and WSDL DataPower subscribes to and enforces Policy on WSDL endpoints

• Policy-driven security and flexibility improvements Policy-driven SSL client cert validation

AAA cache invalidation improvements for performance and policy enforcement LDAP bind-search-rebind semantics useful for large LDAP repositories (for example)

• WebSphere family enhancements to satisfy a greater class of applications (financial services, etc.)

MQ Ordered messaging improvements MQ browse, better sync point support, more automated ReplyQ behavior, better backout queue support WTX interop

• Configuration file handling for better production elevations Profiler to identify non-standard practices Environment-specific configuration mediation components (IP addresses, variables)

• Interoperability with other products for even better heterogeneous environment support Database stored procedure return value support WS-Security Policy interop testing and validation with Microsoft .net and BEA WL 10 ActiveDirectory search improvements for role-based management

• Tibco support improvements Active/passive server config Improved LB/failover behavior

• Connectivity enhancements Better url-open timeout control, per-transaction timeout, non-XML input size reporting

• Other Usability, Serviceability improvements for better operations MOTD and banner support, CLI Wizard, SNMP ease-of-use etc.

Expanded support for native code sets. Data traffic can be sent in DBCS and other code sets. (http://www-306.ibm.com/software/globalization/icu/index.jsp)

Domain deletion safety Ethernet interface disable control Better workflow with in-situ file viewer / edit Internal Load Balancer programmatic control

Page 21: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Deployment Scenarios for Advanced Connectivity

Pack

et

Filt

er

internaluser

XS40

Pack

et

Filt

er

Demilitarized Zone

Internetuser

Internet

Demilitarized Zone

Pack

et

Filt

er

Pack

et

Filt

er

SOAPenabled

enterpriseapplication

SOA platform

legacyenterprise

application

intranetInternetfederated extranet

XS40XS40

1. Helps protect against incoming attacks; Incoming

access control

3. Internalsecurity

2. Outgoing access control, SAML injection, role mappings

XI505. Legacy

transformation

XI50

4. Web servicesmanagement

Page 22: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Hardware superiority

• High reliability (swappable redundant components, whole-box VRRP-style failover, careful design, RAID 1 for HDD options, non-HDD options avail)

• High security assurance physical intrusion detectioncrypto accelerationsigned firmwareonly Ethernet and serial portsXS40 and XI50

locked-down structure (undergoing CC EAL4) HSM option (FIPS-140-2 Level 3)

• High performance (dedicated tightly optimized HW and FW engineering, XG4 available, crypto, low latency and high throughput, patented technology)

• Monitoring and management (self-monitoring and self-healing, rich remote monitoring and administrative capabilities)

“The DataPower [XS40]... is the most hardened ... it looks and feels like a datacenter appliance, with no extra ports or buttons exposed… " - InfoWorld

Page 23: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Simplicity without sacrifice

• WSDL-based policy creation• Hierarchical policies applied at WSDL, service, port, operation level• Drag & drop policy creation screen allows flexible chaining of

operations • Configure and install in minutes

Ease of Use Example – Graphical User Interface providing drag and drop services, in order desired, for XML filtering, signing, verification, schema validation, encryption, decryption, transformation, routing, access control, service level monitoring, and advanced operations

Page 24: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

DataPower’s Unique Appliance AgilityHardware Performance + Highly Customizable Configuration

• More future-proof solution required for today's emerging SOAs: Evolving specifications, varied corporate policies, changing security

requirements Efficient Processing needed for XML Web services integration High Customization required for broad-based SOA

• DataPower Agility (“DA”) Architecture Enables Flexibility & Performance: Advanced Patented XML Processing Engine for wirespeed performance Customizable XML configuration files for highly flexible configuration Easily adapts to changes in standards, service requirements and

customer needs • Benefits:

No need to wait for software or hardware code change, QA, and patch upgrade

Quicker time to market and reduced maintenance cost

Page 25: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Integration across the IBM Software Portfolio

• Mature integration within WebSphere software portfolio WebSphere MQ with WebSphere DataPower: 4+ years, numerous customers Industry-leading SOA Runtime Governance with WSRR + DataPower Many more examples: WTX for data maps, WS-Security for WMB Auto-configure XML firewall by importing WebSphere service descriptors

• Complete SOA Security and Management solution with Tivoli products• Robust enterprise integration through native DB2 and IMSConnect

Deliver data as Web services into new or existing SOA solutions with DataPower/Data Studio integration

• IBM Autonomic Integration – CBE/CEI Certified

TAM, TFIM,ITCAM4SOA

,WS-Trust,

SAML,XACML

SQL, Xquery,Data Studio

IMSConnect

WebSphere MQ,HTTP,JMS,

Web Services

LDAP,SNMP,Syslog,AMP,

NetView

WSRR,WTX,

WS-SecurityWS-Policy

RAD, Eclipse

Page 26: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Integration with the Competition

• Standards-based integration with third party vendors• Tighter integration with some key competitors• No platform dependencies – hardware or software• Exceptional interoperability through industry profiles and testing

LDAP, OCSPXKMS

HTTPUDDI

SNMPXML

HTTP EMS

HTTP/SOAP

HTTPSQL

LDAPSAML

XACML

LDAPSAMLSNMP

HTTP/SOAPSQL

HTTP/SOAP, MQ

HTTP/SOAP

SQL

Page 27: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Customer Success Stories

Page 28: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Major Credit Card ProviderStandard Security Across All Platforms

Challenge• Consistently & securely deliver online services to members that

could be shared, integrated & flexible to meet specific needs• Web services infrastructure needed to support highly secure data

routing with daily high volume & sensitive nature of information

Solution• Implemented WebSphere DataPower XML Security

Gateway XS40 to form the backbone of Web services infrastructure

Content-based message routing

Security policy enforcement & data encryption

Helps to ensure safe & efficient flow of confidential customer data

• Integrated seamlessly into existing heterogeneous environment increasing interoperability & promoting reuse

Benefits Secure SOA on standards-based platform Easily reuse Web services throughout enterprise Boosts productivity of IT staff Substantially shorten time to market for new services

• WebSphere DataPower XML Security Gateway XS40

• WebSphere Application Server

Page 29: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Top 5 BankContent Based Load Balancing

Challenge• Existing shared integration infrastructure for Retail Bank unstable and

unscalable (120 servers, 480 JVM’s!!!)

• Require content-based load balancing solution to be extended to

offload functionality from existing solution

Solution• Implemented WebSphere DataPower Integration Appliance XI50:

Primary function of XI50 is content-based load balancer for

HTTP(s) and MQ traffic

• Additional tier of XI50’s planned for proxying to backend

services (MQ, HTTP and IMSConnect)

Benefits• Able to handle traffic bursts from third party partners

• Enhanced security on existing message flows

• Sophisticated mechanism for proactive identification and “route

away” from degrading JVM’s

• Broken through their “scaling barrier”, able to do more with less

cost

• WebSphere DataPower Integration Appliance XI50

• WebSphere MQ

Providers

Clients

5 12

Page 30: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Online Service ProviderScalable & Secure Online Transactions

Challenge• To deploy a more scalable infrastructure for supporting secure online

transactions and enhancing the scalability, manageability & reliability of IT environment.

Solution• Implemented WebSphere DataPower Integration Appliance XI50

& WebSphere DataPower XML Security Gateway XS40.

The XI50 provides message and protocol mediation functions and interfaces with the TIBCO messaging bus.

The XI50 secures, transforms & routes web services calls to the appropriate service providers.

The XS40 is deployed in the DMZ for web services security-enforcement by performing a full range of security functions.

Benefits• Increased scalability and security for high volume online

income tax preparation as well as credit card authorization services.

• Faster to implement than software-only solution with significantly lower maintenance costs.

• WebSphere DataPower Integration Appliance XI50

• WebSphere DataPower XML Security Gateway XS40

Page 31: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

WebSphere DataPower Integration Appliance XI50

WachoviaSecure SOA Integration of Web Services and Legacy Systems

Challenge• High profile Check 21 initiative to leverage SOA

• Enhance ATM message integration

• Replace legacy system reducing cost, enhancing security

Solution• Deployed WebSphere DataPower Integration

Appliance XI50

• Message-level security & XML threat protection

Benefits• Improved efficiency with on-demand routing of remote

deposits from branch office ATMs

• SOA message-level security, content validation, & threat protection

• Reduced VAN charges by using HTTP without sacrificing security compliance

• Reallocated resources to focus on core business tasks

Page 32: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Challenge• 1) New web services security for internal and external applications

and 2) replace existing ESB/RR Bus

• Previous home-grown ESB (called RR Bus) was unmanageable with 48 servers at end of 2007, with dramatically increased loads expected in 2008

Solution• Implemented WebSphere DataPower XML Security Gateway XS40

and WebSphere DataPower Integration Appliance XI50

• 2 DataPower XS40 XML Security Gateway Appliances provide standards-based web services security for Internet and intranet applications

• RR Bus – 4 DataPower XI50 Integration Appliance XI50s replaced 48 servers

Benefits• Offered new service to business partners: Secure Web Services

• Simplification of the home grown routing solution – easier to support and maintain 4 appliances vs. 48 servers

• Forecasted ROI with break even mid way through year one

• High-performing routing of transactions to mainframe

SOP/HTTP

• WebSphere DataPower Integration Appliance XI50

• WebSphere DataPower XML Security Gateway XS40

• WebSphere MQ

`

SOAP/HTTP

System z

Client

XS40

XI50

Charles SchwabESB Infrastructure

Page 33: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

RouteOne LLC Leveraged SOA to Integrate & Connect People, Process and Finance Information

Challenge• Deploy a single highly secure, scalable & flexible credit

system

Solution• Deployed WebSphere DataPower XML Security

Gateway XS40 to simplify, help secure & accelerate

• Service based integration of backend systems with on-line & Web services

• Connected 22,000 franchised Automotive Dealers, including DaimlerChrysler, Ford Motor Co, General Motors & Toyota, to a single highly secure, scalable and flexible credit application management system

Benefits• Reduced function in numerous existing heterogeneous

systems

• SOA Appliance architecture offers central point of control, manageability & scale

• Dynamic credit applications shorten processing times

WebSphere DataPower XML Security Gateway XS40

Page 34: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Commonwealth of Massachusetts Executive Office of Health & Human ServicesSOA Governance & Interaction Among Heterogeneous Applications

Challenge• Introducing “synchronous” messages of existing services for

both internal and external users Threat protection risk for Web services SLA imposed high performance requirements Ease of integration with existing platform

Solution• Implemented WebSphere DataPower Integration Appliance

XI50 for easy Web services management, wirespeed performance & flexibility

• Deployed as a reverse proxy, providing schema validation & trust formations

• Augmented existing in-house service bus & WebSphere MQ

Benefits• WebSphere DataPower reduces EOHHS’s monthly total

cost of ownership expenses• Satisfied EOHHS’ security & reliability concerns• Centralized Web services management• No measurable impact on existing infrastructure• Accelerated SOA adoption across the enterprise• Effectively integrates emerging standards with legacy

systems and data

• WebSphere DataPower Integration Appliance XI50

• WebSphere MQ

Page 35: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

• WebSphere DataPower Integration Appliance XI50

• WebSphere MQ

SprintESB for Policy Enforcement of SOA

Challenge• To deploy an ESB that provides message security &

mediation functions in a highly reliable & scalable fashion, while keeping capital expenditures, development & minimal ongoing management costs

Solution• Implemented WebSphere DataPower Integration

Appliance XI50 in the DMZ & the Enterprise Network• The XI50s accept HTTP/SOAP traffic and provide

policy enforcement for external users Filtering & validating incoming XML traffic Authentication & authorizing users Routing messages to appropriate end points

based on defined rules Converting XML to binary Mediating between HTTP, SOAP, MQ

Benefits• ESB that is scalable, easy-to-deploy, quick to

configure & simple to manage• Faster time to market enables Sprint to meet project

deadlines

Page 36: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

MIB Group, Inc. SOA Security & Integration

Challenge• Difficult to modify home-grown custom software application

• Adopt SOA to increase revenues, while reducing costs & increasing the security of the service

Solution• Deployed WebSphere DataPower Integration Appliance

XI50 for SOA security and to transform & route messages

• Acts as a gateway by forwarding messages to System z mainframe to be checked against database

• Integrates ACORD XML services with existing WebSphere MQ

• Integrates SchemaTron validate to generate XSLT to load the generated XSLT onto the XI50 for runtime execution & filtering

Benefits• More than 10 times faster than internally developed

custom software• Fraud-protection processes are faster, more secure &

less error prone• Web service allows MIB to offer more services to

customers while reducing overhead cost

• WebSphere DataPower Integration Appliance XI50

• WebSphere MQ

• System z

Page 37: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Customer Testimonials

“IBM’s sophisticated WebSphere integration software, DB2 database and REST Web services are enabling us to maintain our leadership position by building a secure and powerful SOA on our zSeries enterprise server, thereby protecting our existing investments in technology while building a foundation for the future.”

- Alexander Klevitsky

"What DataPower brought to the table for us was an extremely high performance level for the exact same function at, honestly, a better price point…They’re a full order of magnitude faster than our software-based solution was…It’s really reduced the amount of additional time that’s incurred in processing our security functions.”

- Lincoln Fellingham

Page 38: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Summary – IBM Specialized Hardware for Smart SOA Connectivity• Hardened, specialized product for helping integrate, secure &

accelerate SOA• Many functions integrated into a single device• Broad integration with both non-IBM and IBM software• Higher levels of security assurance certifications require hardware• Higher performance with hardware acceleration • Simplified deployment and ongoing management

http://www.ibm.com/software/integration/datapower/

Integrates SOA with specialized devices Accelerates SOA with faster XML throughputHelps secure SOA XML implementations

SOA Appliances: Creating customer value through extreme SOA performance and security

Page 39: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com
Page 40: IBM WebSphere DataPower SOA Appliances Simplify, Help Secure & Govern Your SOA Sidney Antflick AP WebSphere Sales Leader antflick@au1.ibm.com

Thank you