ipSpace.net » Case Studies » Replacing the Central Firewall
ACME Inc. has a data center hosting several large-scale web applications. Their existing data center design uses traditional enterprise approach:
The networking engineers designing next-generation data center for ACME would like to replace the central firewalls with iptables deployed on application servers, but are reluctant to do so due to potential security implications.
The document describes a summary of design challenges sent by readers of ipSpace.net blog and discussed in numerous ExpertExpress engagements. It’s based on real-life queries and network designs but does not represent an actual customer network. Complete document is available as downloadable PDF to ipSpace.net subscribers.
The ACME engineers have to find the optimal mix of traffic filtering solutions that will:
Effectively, they’re looking for a scale-out solution, which will ensure approximately linear growth, with minimum amount of state to reduce the complexity and processing requirements.
While designing the overall application security architecture, they could use the following tools:
The case study describes the roles of these tools in a scale-out network security architecture, and lists various design options, from WAN edge packet filters with VM NIC firewalls to layered stateful defense.
Complete case study, including design and deployment guidelines and sample configuration snippets is available to ipSpace.net subscribers. Select the Case studies tab after logging into the webinar management system.