Top Banner
Sikker adgang fra alle devices edgemo summit CPH maj 2014
26
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Sikker adgang fra alle devices

edgemo summit CPHmaj 2014

Page 3: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

NetScaler GatewayNetScaler Access Gateway Enterprise Edition (AGEE)

Citrix Access Gateway (CAG)

Citrix Secure Gateway

NetScaler ADC

Citrix Advanced Access Gateway (CAG)

Page 4: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Citrix NetScaler overview

Page 5: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Citrix NetScaler overview

Cloud Infrastructure

Enterprise Datacenter

PerformanAcAcAccelerate Offload SecurityAvailability

• World-class load balancing

• Health monitoring

• Caching

• Compression

• Optimization

• TCP Connection Management

• SSL processing

• SSL VPN

• Application firewall

• AAA

Page 6: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Layer 4 Load Balancing

• Source IP• Cookie• SSL Session ID• Server-ID in URL Query• Customer Server-ID• Token (header or body)

Maintaining UserSessions

Distributing Traffic

• Least Connections• Lowest Response Time• Round Robin• SNMP-based• Hash-based• Many more…

Monitoring Server Health and Availability

• TCP Connection• HTTPS Connection• Extended Content Verification• Scriptable Health Checks

TCP and UDP Client Requests

Page 7: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Global Server Load Balancing

Site B

Site A

Page 8: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

HTTP Requests

• Anything in request body• Device Type• Language• Cookie• Browser Capability• XML XPath support

Client Attributes

• Any TCP Request• HTTP Get• HTTP Post

Request Protocol

Request Method

• Any TCP payload value• Any HTTP payload value• Domain• Wildcard URL

Content Switching: Load Balancing on Steroids

Page 9: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Optimering

Page 10: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

TCP Connection Multiplexing

1. NetScaler terminates connection

2. Client transmits requests

3. NetScaler establishes server connection

4. NetScaler transmits client requests

5. Other clients follow same procedure

6. Multiple client requests are transmitted across common server connection

Web Server

Page 11: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

AppCache

• Memory or flash disk based cache• Reduce time to first packet• Significantly reduce back-end server workloads• Dynamic caching for frequently changing content• Flash cache support for realtime updates

Page 12: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

AppCache – Non-Caching proxy

Deliver it one time

Get the web page

Page 13: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

AppCache – Caching proxy

Deliver it many times

Get the web page once

Page 14: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

AppCompress

• Standard based compression – GZIP/DEFLATE• Works with all browsers, including mobile• Applies to HTML, JavaScript, CSS and Documents• 3:1 to 5:1 Compression Ratio

Page 15: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

AppCompress

1 GbyteFile

1 GbyteFile

1 Gbps Throughput200-300Mbps Throughput

Page 16: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Sikkerhed

Page 17: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

AAA - Authentication

Page 18: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Multi-factor authenticationREQ.SSL.CLIENT.CERT = EXISTSREQ.BROWSER-TYPE = Internet ExplorerREQ.SSL.CLIENT.CERT != EXISTS

REQ.SSL.CLIENT.CERT = EXISTS

+ LDAP

Page 19: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

NetScaler Insight Center

Page 20: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Insight Center

Internet

!

!!

!WAN Data Center Network

XenDesktop/ XenApp

? ?

?

Page 21: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Insight CenterO

ldN

ew

USER

Help-Desk Desktop Admin

Network Admin

Citrix SupportSoftware

Citrix Support

Citrix SupportEscalation

USER

Help-Desk Network Admin

IT Department

Citrix Support

IT dept calls Citrix Support

Page 22: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

NetScaler Insight Center

Internet NetScaler

XenDesktop/ XenApp

NetScaler Insight Center

3rd PartyAnalysis Tools

AppF

low

AppF

low

Page 23: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Insight Center

Application or Network?

Which Part of Network?

Bandwidth Taken Up?Users Affected

Servers Causing Trouble

Page 24: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Insight Center

ICA Analytics

DC & WAN Latency

Active /Inactive Session Data

ICA RTT

Host Delay

Client/ Server IP

Virtual Channels

Page 25: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

?

Page 26: Sikker adgang fra alle devices edgemo summit CPH maj 2014.

Tak for jeres tid!