net1305bu introduction to vmware nsx for automation: or … · 2019-06-27 · it automation...

31
Scott Goodman Product Marketing Manager - Networking & Security, VMware Brad Skeel Sr. Manager - Enterprise Cloud Ops & Engineering, Deluxe NET1305BU #VMworld #NET1305BU Introduction to VMware NSX for Automation: Moving faster in the digital business age VMworld 2017 Content: Not for publication or distribution

Upload: others

Post on 11-Jun-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Scott GoodmanProduct Marketing Manager - Networking & Security, VMware

Brad SkeelSr. Manager - Enterprise Cloud Ops & Engineering, Deluxe

NET1305BU

#VMworld #NET1305BU

Introduction to VMware NSX for Automation:Moving faster in the digital business age

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 2: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

• This presentation may contain product features that are currently under development.

• This overview of new technology represents no commitment from VMware to deliver these features in any generally available product.

• Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind.

• Technical feasibility and market demand will affect final delivery.

• Pricing and packaging for any new technologies or features discussed or presented have not been determined.

Disclaimer

#NET1305BU CONFIDENTIAL 2

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 3: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Better utilization of IT resources for more strategic projects

Increased security and compliance

Improved service with faster time to market

“Configuration and change

management of networking gear

remains primarily a labor-intensive,

manual process... These suboptimal

network practices result in

downtime, reduce security, degrade

application performance, and waste

human and capital resources.”

Andrew Lerner

Research Director

Gartner

Business demands

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 4: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

So What’s Getting in the Way?

4

Inconsistent tooling Manual processes Complex physical infrastructure

#NET1305BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 5: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Q: How can I deliver faster, higher quality networking and security services to my business?

A: Virtualization, standardization, and automation.VMworld 2017 Content: Not fo

r publication or distri

bution

Page 6: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Compute Storage

The Data Center Networking Challenge

There has been a lot of virtualization in the data center.

Networking

Except for one area…

#NET1305BU CONFIDENTIAL 6

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 7: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Compute Storage Networking

The Data Center Networking Challenge

The lack of networking virtualization is holding back your ability to:

Keep up with the pace of business

Secure your data centers

Control cost

#NET1305BU CONFIDENTIAL 7

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 8: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Network, storage, compute

Virtualization layer

Hypervisor Hypervisor

vSwitch vSwitch

NSX value proposition

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 9: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Hypervisor

vSwitch

In-hypervisor (on-prem)

as a Service (cloud)

Hardware/Cloud independent

Network and security services

NSX value proposition

SwitchingRouting FirewallingLoadbalancing

SwitchingRouting FirewallingLoadbalancing

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 10: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Hypervisor

vSwitch

Network, storage, compute

Virtualization layer

“Network platform”

Virtual networks

NSX value proposition

SwitchingRouting FirewallingLoadbalancing

SwitchingRouting FirewallingLoadbalancing

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 11: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Network Virtualization Solves These ProblemsAbstracting networking and security from the underling infrastructure

IoTCloudData center Remote office

#NET1305BU CONFIDENTIAL 11

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 12: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

The Solution: Network Virtualization and Automation

12

Virtualized infrastructure and security controls

Automated, standardized processes

Consistent virtualization tools

VMVM

VMVM

APP

Complex physical infrastructureManual processesInconsistent tooling

#NET1305BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 13: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Automation Use Cases

IT Automation Developer Cloud Multi-Tenant Infrastructure

#NET1305BU CONFIDENTIAL 13

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 14: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

IT AutomationTraditional infrastructure provisioning

User requests new app

Request generates a ticket

Ticketing extends across multiple roles

NetOps

SecOps Admin

CloudOps

Manual work streams

Final delivery can take several

weeks

Change restarts entire process

1

2

3

Day two change

4 5

6

7

#NET1305BU CONFIDENTIAL 14

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 15: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

IT AutomationEliminating time and complexity with automation

NETWORKING

SECURITY

Accelerate workload deployment

Avoid risk from human errors

Compliance and auditability

Benefits

Cloud management

platform

IT vRealize Automation

Blueprint

vRealize

#NET1305BU CONFIDENTIAL 15

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 16: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Automation Use Cases

IT Automation Developer Cloud Multi-Tenant Infrastructure

#NET1305BU CONFIDENTIAL 16

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 17: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Developer CloudToday: Infrastructure limitations bring delays and risks

Rogue developer

PUBLIC

Not connected

Not secured

Good citizen developer

Costly

Time intensive

1

2

Challenges

Slow time-to-deliver

High costs

Complexity

Uneven security and compliance

#NET1305BU CONFIDENTIAL 17

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 18: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Developer CloudConsistent, SaaS-based delivery approach using standard APIs

Developer Infrastructure

templates

Benefits

Agile development

Continuous deployment

Infrastructure as code

Consistent security

NETWORKING

SECURITY

API

OpenStack

APIs

Heat Terraform

#NET1305BU CONFIDENTIAL 18

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 19: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Developer CloudConsistent, SaaS-based delivery approach using infrastructure as code

DevOps Configuration

templatesNSX API

Benefits

Consistent configuration

Ease of replication

Faster deployments

Use of existing toolsets

Ansible

Chef

Puppet

Configuration

management tools

NETWORKING

SECURITY

#NET1305BU CONFIDENTIAL 19

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 20: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Automation Use Cases

IT Automation Developer Cloud Multi-Tenant Infrastructure

#NET1305BU CONFIDENTIAL 20

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 21: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Challenges

Multi-Tenant Infrastructure

21

Traditional managed services cloud models limit scalability

IT Organization or

Service Provider

Dedicated tenant

cloud environments

Multiple cloud instances

TENANT A

TENANT B

TENANT C

Costly to scale

Inefficient resource utilization

Complex to upgrade, secure

#NET1305BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 22: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

Multi-Tenant Infrastructure

22

Realizing new service opportunities

IT Organization

or Service

Provider

Virtual Machines

Network virtualization

Security services

Service Catalog

Provider

Service provider model

Tenants

TENANT A

TENANT A

TENANT A

Single-cloud instance

Opportunities

Cost efficiencies

Security for provider and

consumer

“Zero Touch” service model

#NET1305BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 23: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

© Deluxe Enterprise Operations, LLC. Proprietary and Confidential.

• HQ in Shoreview, MN

• Largest Check Printer in US

• 6,000 employees across the US

• 4.5 million small business customers

• Largest provider of marketing and other services to small business

• 100th Anniversary in 2015!

• $1.9 billion in annual revenue, market cap $2.95 billion

Intro to Deluxe

#NET1305BU CONFIDENTIAL 23

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 24: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

© Deluxe Enterprise Operations, LLC. Proprietary and Confidential.

• Began in early 2013 w/Azure adoption (Hint: it didn’t go well…)

• Private cloud discussions started in May 2014

• Private cloud launched in Jan 2015 w/ migrations starting thereafter

• Infrastructure can’t lead the cloud transformation…

• A drive to modernize a legacy cash cow.

• New acquisitions are cloud ready.

• Cloud native development beginning w/ bi-modal strategy

The Deluxe Cloud Journey

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 25: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

© Deluxe Enterprise Operations, LLC. Proprietary and Confidential.

• Software defined networking was discussed early

• Multiple solutions were evaluated… NSX won

• NSX is core to our ability to drive cloud flexibility

• Security is in the DNA of the Deluxe cloud strategy

• NSX gives us the ability to seamlessly bridge clouds securely

• NSX and virtual Palo Alto firewalls make up the whole solution

• Automating NSX drives the fast delivery of secure workloads

NSX at Deluxe

#NET1305BU CONFIDENTIAL 25

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 26: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

© Deluxe Enterprise Operations, LLC. Proprietary and Confidential.

• Based on vRealize Automation/Orchestrator

• Phase 1 started with simple VM build

• Service Now hosts service catalog

• Phase 2 layered in additional services

• Phase 3 introduced NSX automation

Automation at Deluxe

#NET1305BU CONFIDENTIAL 26

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 27: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

© Deluxe Enterprise Operations, LLC. Proprietary and Confidential.

• Starts with the workload order

• Questions in our catalog items drive the NSX VM configuration

• NSX tags are applied at build time

• Leveraged Power NSX for VM deployments and migrating workloads

• Automated V2V workload migrations w/ NSX tags

Automating NSX

#NET1305BU CONFIDENTIAL 27

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 28: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

© Deluxe Enterprise Operations, LLC. Proprietary and Confidential.

• Request NSX load balancers via service catalog

• Add/edit NSX tags post deployment

• Creation of virtual switches

• Creation of isolated test networks

• Deployment of entire development stack

• Deployment of new ESX hosts

Future Opportunities with NSX & vRA/vRO

#NET1305BU CONFIDENTIAL 28

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 29: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

• Accelerated, self-

serve deployments

• Compliance and

auditability

IT Automation

AutomationMoving faster in the digital business age

• API-driven development

and deployment

• Cost efficiencies

• Infrastructure treated as

code and templated

• “Zero Touch” service

model

Developer Cloud Multi-Tenant Infrastructure

• IT staff can focus on

strategic projects

• End-to-end automation

across DevOps lifecycle

• Security applied to

provider and tenant

#NET1305BU CONFIDENTIAL 29

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 30: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 31: NET1305BU Introduction to VMware NSX for Automation: or … · 2019-06-27 · IT Automation Eliminating time and complexity with automation NETWORKING SECURITY Accelerate workload

VMworld 2017 Content: Not fo

r publication or distri

bution