Re: Third party certifications for LB
Omachonu Ogali <[email protected]>
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
Perhaps, I'm way off base here, but the career track also has an impact on the operational perspective of the devices and indirectly on how the product is certified. In the past few years, positions have been slowly been getting aggregated, to the point where your current network engineer has to be a jack-of-all trades (see job postings titled 'network engineer' that also call for Windows/UNIX, BES, and/or programming experience, or 'system administrator' that calls for IOS, LTM, and/or BGP experience). The network person, traditionally dealt with network and only network. But now, in a load balanced environment, they have to understand the characteristics of the network, the servers, and the applications, and how to accurately troubleshoot said items. Sure, you can separate the functions of a device (network team controls IP addressing/VLANs, systems team controls pool membership and some health checks, security controls firewall/IDS/etc, and developers/operations control pool membership and other health checks) but you end up with needing 3-4 different teams and various change management procedures to administer 1 or 2 devices, which makes no sense on paper. Third-party certification is an indirect way of preventing encroachment/territory wars (e.g. this is an approved security device, this is an approved server virtualization platform,etc.), but what do you do when multiple third parties certify a product, or worse one third party certifies multiple aspects of a product (show me a non-vendor industry participant that deals with network, systems, security, and application certifications and I'm willing to bet that party is largely ignored). Plus, with "official" product certification, you're threatening the hardware, software, support, professional services, and training revenue streams of switch, router, firewall, IDS, and virtualization vendors, and that won't go over lightly (you've awaken not one sleeping giant -- but at least ten), who will call an all out marketing blitz to keep you at bay. Then again, I may be way off base. oo On Mar 26, 2009 9:55 AM, "Kenneth Salchow" <[email protected]> wrote: Absolutely—there is no separating these things from security. In fact—looking at the landscape—I’ve published a couple papers and done several presentations about what I might call the “dynamic perimeter”. Basically—when you attempt to access an application, something like an ADC is the intermediary which determines where your request will be serviced (load distribution across datacenters—clouds—as well as servers), how your request will be serviced (do you need compression, what priority is the traffic, etc.), and finally what the security requirements of your request are (is it allowed, does it need to be encrypted, should it be run through IDS). So—for every application—you get a dynamically created perimeter that stretches from the server all the way to your device and it is context aware of the user, device, network, resource and business objectives. If you’re interested (http://www.f5.com/pdf/white-papers/unifiedaccess-wp.pdf) is one of the original papers from 3 years ago—it’s fairly high-level and vendor neutral; there should be others shortly. So—back to question at hand though—this is what I meant about the difficulty in creating an ADC certification. Some vendors might decide that IDS functionality belongs directly in the ADC whereas others might feel that it should be a separate device that the ADC routes traffic through on a dynamic, ad-hoc and policy driven basis. There are really good arguments either way—but the question is that if one vendor decides to put IDS in the box—does that mean the ADC certification needs to include IDS testing? The same thing would go for AV, firewalls, WAF, routing, etc. What happens if a vendor provides a platform and opens it up for 3rd-party plug-ins to run on the ADC (something that becomes even more likely with virtualization technologies—like Cisco ISRs running MS Domain controllers)? Who would be the final arbiter of ‘what constitutes an ADC’? Anyway—I totally agree with you that, especially from the customer perspective, there continues to be a need for 3rd-party certification/verification; I’m just not convinced that we will ever see a complete, soup-to-nuts ‘ADC’ certification. For the foreseeable future, I think it is still too much of a moving target. But—that’s just one nuts opinion, right? J KJ (Ken) Salchow, Jr. | Manager, Technical Marketing *From:* [email protected] [mailto:[email protected]] *On Behalf Of *Ravi Kumar *Sent:* Thursday, March 26, 2009 12:17 AM *To:* Load Balancing Mailing List Subject: Re: [load balancing] Third party certifications for LB Hi Ken, I agree with you. As of now, the individual modules like application firewall, protoc... _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki