June 2020| | 9is something I highly recommend. Depending on your scale, conclude vendor selection after piloting at a sampling of sites that are representative of your business. A hybrid of multiple solutions may be necessary in some environments due to M&A or cost. E.g., SD-WAN nodes plus traditional hardware VPN nodes.Hardware You might think this is obvious, but I beg to differ. There are some options. 1. Hardware from the SD-WANsoftware provider (vanillaoffering). Understandingsystem capacities is about theonly decision driver. Pros:Simple. Cons: Proprietary/dedicated hardware. Tip: Somemanaged service providers willresell the hardware from theSD-WAN software provider, under their own brand, and someplatforms, at specific hardware levels, support limited, networkfunction virtualization (NFV). E.g., Palo Alto virtual wire onVeloCloud.2. Managed service provider hardware, universal CustomerPremise Equipment (MSP uCPE). An example from AT&Tis FlexWare. This is a proprietary, container/app platformwith an app store. Essentially a closed hypervisor for NFVs.Your selected SD-WAN, firewall software, and other networkfunctions can be deployed on a single piece of hardware. NFVscan be added and subtracted using the app menu, e.g., Ciscorouter (IOS). Pros: Flexible. Cons: Locks you to the MSP,potentially higher cost.3. White BoxuCPE. Imagine a room full of the same model ofspare. As your needs or software solution template changes,just swap out NFVs, without the need to change to a differenthardware platform. In short, current-generation x86 CPU (e.g.,Intel Atom C3000 and Xenon D-2100 which both have supportfor AES-NI, PCI pass through, SR-IOV), enough RAM (e.g.,32GB), combined with multiple network ports, SSD storage,and a license-free or license paid, open hypervisor. Pros: Totalflexibility. Cons: In-house build. Examples of specific hardware:Super Micro 5019A-FTN10P and 1019D-FRN8TP. Tip:Understanding SSD endurance is vital. This can be addressedby selecting a small MLC drive (250GB) or a large TLC drive(1TB). Even though you may only use a mere 25GB, the largerthe drive, the longer it will last and is vital for life expectancy (e.g., ten years). Terabytes Written (TBW) is the measure of endurance on SSD. Plan on running your SSD at less than 10% used storage to get the full benefit from wear leveling. Consider keeping the boot device separate, e.g., 128GB SATA-DOM. This simplifies hypervisor rebuilds when the NFV datastore resides on a physically separate drive. Raid is unnecessary. When multiple NFVs reside on the same uCPE, reduce the risk of this single point of failure and deploy two uCPE with redundant NFVs. No need for things like ESXI vMotion and traditional full backups. Simple configuration backups will suffice, just like any piece of network equipment. The choice of hypervisor is relevant. Document all the platforms in your environment that support virtualization, as well as those that might occur in the future. Build a matrix of hypervisors they support. Consider the hypervisors and knowledge already in your environment. If your network vendor does not publish their platform virtualized, contact the head of the product and request it.Synergy with secure LAN Do you have internal network segmentation requirements? If so, are they based on firewalling alone (e.g., Palo Alto, Fortinet), firewalling between Virtual Routing and Forwarding instances (VRFs), or driven by policy on a fully integrated, Network-Access Control (NAC) platform? e.g., Aruba. A well-defined NAC, SD-WAN and firewall strategy,may drive platform selection, and the organization of thoseresources supporting it.Internet Access This might seem obvious, but it needs to be considered. Even though you are using internet connections to stitch together a secure and private WAN for your organization, the internet egress point for traffic will need to be defined, and sometimes with a high degree of precision, including deliberate variances for specific scenarios. This can be important as you overlay a web-content filtering solution on SD-WAN or consider the other companies you do business with, e.g., web-site access restrictions based on source IP address, and guest/BYOD egress. As previously mentioned, directly egressing to trusted partner platforms (e.g., private cloud) can unburden other security platforms, filtering traffic that does not need to be filtered. Internet DNS provider selection is a consideration that should be explored in detail. John Walshaw
<
Page 8 |
Page 10 >