Re: Third party certifications for LB

Omachonu Ogali <[email protected]>
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
Perhaps, I'm way off base here, but the career track also has an impact on
the operational perspective of the devices and indirectly on how the product
is certified.

In the past few years, positions have been slowly been getting aggregated,
to the point where your current network engineer has to be a jack-of-all
trades (see job postings titled 'network engineer' that also call for
Windows/UNIX, BES, and/or programming experience, or 'system administrator'
that calls for IOS, LTM, and/or BGP experience).

The network person, traditionally dealt with network and only network. But
now, in a load balanced environment, they have to understand the
characteristics of the network, the servers, and the applications, and how
to accurately troubleshoot said items.

Sure, you can separate the functions of a device (network team controls IP
addressing/VLANs, systems team controls pool membership and some health
checks, security controls firewall/IDS/etc, and developers/operations
control pool membership and other health checks) but you end up with needing
3-4 different teams and various change management procedures to administer 1
or 2 devices, which makes no sense on paper.

Third-party certification is an indirect way of preventing
encroachment/territory wars (e.g. this is an approved security device, this
is an approved server virtualization platform,etc.), but what do you do when
multiple third parties certify a product, or worse one third party certifies
multiple aspects of a product (show me a non-vendor industry participant
that deals with network, systems, security, and application certifications
and I'm willing to bet that party is largely ignored).

Plus, with "official" product certification, you're threatening the
hardware, software, support, professional services, and training revenue
streams of switch, router, firewall, IDS, and virtualization vendors, and
that won't go over lightly (you've awaken not one sleeping giant -- but at
least ten), who will call an all out marketing blitz to keep you at bay.

Then again, I may be way off base.

oo

On Mar 26, 2009 9:55 AM, "Kenneth Salchow" <[email protected]> wrote:

 Absolutely—there is no separating these things from security.  In
fact—looking at the landscape—I’ve published a couple papers and done
several presentations about what I might call the “dynamic perimeter”.
Basically—when you attempt to access an application, something like an ADC
is the intermediary which determines where your request will be serviced
(load distribution across datacenters—clouds—as well as servers), how your
request will be serviced (do you need compression, what priority is the
traffic, etc.), and finally what the security requirements of your request
are (is it allowed, does it need to be encrypted, should it be run through
IDS).  So—for every application—you get a dynamically created perimeter that
stretches from the server all the way to your device and it is context aware
of the user, device, network, resource and business objectives.  If you’re
interested (http://www.f5.com/pdf/white-papers/unifiedaccess-wp.pdf) is one
of the original papers from 3 years ago—it’s fairly high-level and vendor
neutral; there should be others shortly.



So—back to question at hand though—this is what I meant about the difficulty
in creating an ADC certification.  Some vendors might decide that IDS
functionality belongs directly in the ADC whereas others might feel that it
should be a separate device that the ADC routes traffic through on a
dynamic, ad-hoc and policy driven basis.  There are really good arguments
either way—but the question is that if one vendor decides to put IDS in the
box—does that mean the ADC certification needs to include IDS testing?  The
same thing would go for AV, firewalls, WAF, routing, etc.  What happens if a
vendor provides a platform and opens it up for 3rd-party plug-ins to run on
the ADC (something that becomes even more likely with virtualization
technologies—like Cisco ISRs running MS Domain controllers)? Who would be
the final arbiter of ‘what constitutes an ADC’?



Anyway—I totally agree with you that, especially from the customer
perspective, there continues to be a need for 3rd-party
certification/verification; I’m just not convinced that we will ever see a
complete, soup-to-nuts ‘ADC’ certification.  For the foreseeable future, I
think it is still too much of a moving target.



But—that’s just one nuts opinion, right?  J

  KJ (Ken) Salchow, Jr.  |  Manager, Technical Marketing

*From:* [email protected] [mailto:[email protected]] *On Behalf Of
*Ravi Kumar
*Sent:* Thursday, March 26, 2009 12:17 AM
*To:* Load Balancing Mailing List

Subject: Re: [load balancing] Third party certifications for LB

  Hi Ken,   I agree with you. As of now, the individual modules like
application firewall, protoc...

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.