Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Thursday, March 4, 2021

Key Trends from F5 State of Application Strategy Report

Get your copy: www.f5.com/stateofappstrategy

We all know how much the world has changed in the last year. And, the results of the most recent #F5​ State of Application Strategy survey make it clear, the pandemic has vastly accelerated a global digital transformation that was already underway. Progress that might normally have taken a decade has leapt forward in a single year—with respondents maturing in their journeys toward digital expansion. So let’s start the clock and take a look at the astonishing progress apparent through several key markers revealed in our seventh annual survey. #SOAS

Friday, November 6, 2020

Cloud Interconnection with F5 & Equinix

 Learn how the simplified Interconnection Oriented Architecture (IOA) from #F5 and #Equinix helps IT departments solve the need for mobile and dispersed user access to their cloud infrastructure(s) in a multi-cloud environment.

Learn more: https://www.f5.com/services/resources/use-cases/a-secure-equinix-gateway-to-the-cloud
This architecture allows for services to be deployed at the edge of, or next to the cloud resulting in Fewer hops, Dramatically lower latency, Fault-proof security & Lower Network transport costs - as much as 80% lower. This ‘edge’ architecture provides a natural point for traffic control by having centralized policy control and Security policy enforcement, access control and other services like DDoS protection, AAA and WAF.


Friday, December 13, 2019

F5 Cloud Services Early Access Program

F5's Cloud Services Team is excited to share an opportunity for customers test two new technologies! Essential App Protect is an instant, out-of-the-box protection from common web exploits, malicious IPs and coordinated attack types. Bot Protect is a bot management SaaS solution that identifies bots’ intent and prevents attacks, while maintaining access for the good bots that help your business.

Visit: https://www.f5.com/preview to help shape our roadmap and influence feature development!


Wednesday, October 2, 2019

F5's State of Application Services Survey




Since 2015, F5 has been surveying the tech industry to learn the key issues surrounding application deployment and delivery. Again for 2020, we’d love to understand your company’s current application architectures to help shape F5’s application services strategy. We will be taking responses until Oct 10, 2019.

If you are interested in taking the survey, please continue to this link:
https://f5.co1.qualtrics.com/jfe/form/SV_0JJY1SQZyiufT7v?URL_SOURCE=F5DevCentral

Friday, December 29, 2017

Blog Roll 2017

It’s that time of year when we gift and re-gift, just like this text from last year. And the perfect opportunity to re-post, re-purpose and re-use all my 2017 entries.

If you missed any of the 64 attempts including 16 videos, here they are wrapped in one simple entry. I read somewhere that lists in articles are good. I broke it out by month to see what was happening at the time and let's be honest, pure self-promotion. Check out our Featured Members for the year, dig into June's Cloud Month, catch up on some #Basics or sit back and watch some cool Lightboard videos.

I truly appreciate your engagement throughout 2017 and Have a Safe and Happy New Year!

​​​January 2017
February
March
April
May
June
July
August
September
October
November
December
ps

The History

Thursday, December 28, 2017

The Top 10, Top 10 Predictions for 2018

The time of year when crystal balls get a viewing and many pundits put out their annual predictions for the coming year. Copying off since 2012, rather than thinking up my own, I figured I’d regurgitate what many others expect to happen.

Top 10 Cyber Security Predictions for 2018 – Infosec Institute kicks off this year’s Top 10, Top 10 list with a look back at their 2017 predictions (AI, IoT, etc.) and dives head first into 2018 noting that Ransomware will be the most dangerous threat to organizations worldwide; cryptocurrency will attract fraudsters looking to mine; cloud security will (again) be a top priority; cyber insurance will explode and cyber-bullying, especially for teenagers, is at the emergency stage.

Cyber security predictions for 2018 – Information Age taps Mike McKee, CEO of insider threat management company ObserveIT, to offer his insight. Lack of security talent will lead to the outsourcing of security services. Approximately 350,000 infosec jobs are currently unfilled in the U.S. and will continue to grow. Add to that, only 11% of the world’s information security workforce are women which offers a huge opportunity according to Mike. Social engineering and human error should encourage organizations to train folks on the basics of self-preservation on the internet.

Cybersecurity trends for 2018 - For the love of ‘cyber’…or not. CSOonline reviews McAfee Inc.’s recent threats predictions report and identified five key cyber security trends to watch in 2018. There will be a machine learning arms race between attackers and defenders with IoT ransomware causing major disruptions. EU’s General Data Protection Regulation (GDPR) comes into effect in May so that could have some regulatory impact.

Five predictions for the hybrid cloud market in 2018 – Hyped for Hybrid? Then NetworkWorld has you covered with, ‘Public cloud gets all the attention, but private and hybrid clouds are set for big growth in 2018.’ As hybrid cloud strategies get clearer, 2018 could be a huge year for adoption with containers and PaaS as hybrid cloud platforms. They also note that Public cloud services come on-prem and there needs to be optimized connections from organizations to cloud providers.

Experts Reveal Predictions for Cloud Services in 2018 – eWeek queries a number of cloud experts for their predictions. Partnerships and consolidation of the cloud market is coming; they, like NetworkWorld, also see a huge increase in hybrid usage; workload portability will become critical; IoT metrics will need storage and SaaS will keep growing as organizations try to avoid large hardware investments.

IDC 2018 Predictions: If You’re Not In The Cloud, You’re Isolated From Innovation – In this interesting article, IDC also goes long term with some 2020 and 2021 predictions. For instance, by 2021, at least 50% of global GDP will be digitized, with growth driven by digitally-enhanced offerings, operations and relationships. By 2021, spend on cloud services and cloud enabling hardware, software and services doubles to over $530 billion. They also touch on areas like human-digital interfaces; blockchain services and even no-code development tools. This is a good list.

Deloitte’s tech predictions for 2018: More AI, digital subscriptions, AR, and live events – VentureBeat digs into Deloitte’s predictions as part of their 17th annual Technology, Media, & Telecommunications report. Mobile predictions include interesting nuggets like a fifth of North American homes will get all of their Internet data access via cellular mobile networks and adults actually worrying that they are on phones too much. We will try to limit usage. Yea-Right. All while 5 million phones a day are being sold worldwide. TV viewing will continue to decline while more than a billion smartphone users will be creating augmented reality content at least once during 2018, with 300 million doing so monthly and tens of millions weekly.

10 Enterprise IoT Predictions for 2018 – With endless partnerships & collaboration tied to IoT, ‘co-everything’ will drive the co-economy with customers becoming co-innovators. With that, open standards, open architectures and interoperability will be key…with government regulation not far behind. Agriculture and Healthcare will emerge as the leading adopters of IoT due to innovative use cases. IoT will shift from driving efficiencies to creating new business value. AI, fog and blockchain will become important for broad adoption.

2018 Predictions For The Data Center Industry – Applications live in data centers and as I’ve said before, the Cloud is just a Data Center somewhere. Mission Critical Magazine taps into some data center trends with the biggest being, ‘IT and data center managers around the globe will become the backbone for advanced cloud infrastructure tools that provide them with a high level of flexibility and visibility into their new mixed cloud environment – adding another layer of complexity to their role.’  It’s also become less of a ‘what if’ and more of a ‘when’ in terms of unforeseen events causing outages. With that, we’ll begin to see less of a reactive approach to one that is more proactive according to Jeff Klaus, GM Data Center Management Solutions for Intel.

Predictions As A Service – If you thought the acronym PaaS was taken, then Networking Nerd will open your eyes since he thinks the prediction business is a house of cards built on quicksand. He has his safe bet layups like - Whitebox switching will grow in revenue; Software will continue to transform networking and Cisco is going to buy companies without even stepping into 2018. And then moves on to his out-on-a-limb, far out predictions like ‘HPE will go out of business’ among others. His closing take is that he’d rather try to figure out how to use what he already has today and build that toward the future because, that’s a headline you’ll never live down.

Maybe we should heed his advice.

Are you ready for 2018?

ps

Interested to see if any of the previous year’s prognoses came true?


This article originally appeared on F5.com

Tuesday, September 12, 2017

Automatically Update your BIG-IP Pool Using the Service Discovery iApp

Let’s look at how to automatically add members to your BIG-IP pool by using the Service Discovery iApp. Whenever you deploy a BIG-IP Virtual Edition by using one of the templates on the F5 Github site, this iApp is installed on the BIG-IP.

The idea behind this iApp is you assign a tag to a virtual machine in the cloud and then BIG-IP automatically discovers it and adds it to the pool. By tagging instances in AWS and Azure, and configuring the iApp, the pool is updated based on an interval you specify. This is especially helpful if you auto-scale your application servers because they are then automatically added and removed.

Today, we’ll look how to do this in Azure but you can also do this in AWS.

First, we’re going to add a tag to the application sever in Azure. You can assign the tag to either the virtual machine or to the NIC. For auto-scaling you’d tag the scale set. This can we’ll simply add it to the virtual machine.

When you click through the virtual machine, on the left you’ll get the ‘Tags’ option.

This entry can be any name/value pair you want and for this we’ll use ‘mytag’ and ‘addme.’

And we’ll click Save.
 For this exercise, we have two application servers in the resource group and already added the tags for that one. So at this point, we’re ready to get into the BIG-IP and configure the iApp.

Once in, go to Application Services>Applications>Create.

Next, we give it a name and choose f5_service_discovery from the list.

Scroll down the same page and fill out the open fields. Under Cloud Provider, we select Azure. Depending on your provider, there are additional questions. Add the Azure resource group and the Subscription ID. The next 3 fields (for the Azure selection) are security related: Tenant ID, Client ID and Service Principal Secret. Rather than using your own credentials to create and modify resources in Azure, you can create an Azure Active Directory application and assign permissions to that. Details are included on the Github ReadMe or the Azure documentation about service Principal.

Under the Pool area, is where you enter the name/value pair that we used for the tags in Azure. We leave the rest default. In this instance, you may notice the update interval at 60 seconds. By default, 60 seconds is the interval that BIG-IP will query Azure to see if there is a resource with the tags you specified. Under Application Health, select ‘http’ as the health monitor. Click Finished.

When complete, we can see we got a pool with two active members in it.

If you take the tags off one of the instances, it’ll leave the pool. Of note however, there must be two members in the pool before you remove tags from an instance. If you remove the tags from all the application servers, the pool will not be updated. BIG-IP must see at least one set of tags to update the pool because it doesn’t want to leave you with an empty pool.

Here’s the before and after of removing a tag.

One final note. This example configuration has the BIG-IP in one resource group and the application servers in another resource group but they are all on the same Vnet. If you have separate networks in Azure, you’ll need to create a peering so they can communicate. Similarly, in AWS, you need to make sure the networking is set up so the BIG-IP can see the application servers. But, once the initial set up is working, there’s no manual intervention required.

You can use the Service Discovery method to add and remove application servers all day long without having to manually update the BIG-IP. Again, and as always, thanks to our Technical Communications team for the great material and watch the video demo here.


ps

Related:

Thursday, August 31, 2017

Lightboard Lessons: What is BIG-IQ?

In this Lightboard Lesson, I light up many of the tasks you can do with BIG-IQ, BIG-IQ centralizes management, licensing, monitoring, and analytics for your dispersed BIG-IP infrastructure. If you have more than a few F5 BIG-IP's within your organization, managing devices as separate entities will become an administrative bottleneck and slow application deployments.  Deploying cloud applications, you're potentially managing thousands of systems and having to deal with traditionally monolithic administrative functions is a simple no-go. 

Enter BIG-IQ.



ps

Related:

Wednesday, August 30, 2017

Is 2017 Half Empty or Half Full?

Ransomware seems to be this year’s huge trend

With 2017 crossing the half way point, let's look at some technology trends thus far.
Breaches: Many personal records are half empty due to the continued rash of intrusions while the crooks are half full of our personal information along with some ransom payments. According to the Identity Theft Resource Center (ITRC), there have been 7,689 breaches since 2005 (when they started tracking) compromising – get this – 900,315,392 records. Almost 3 times the U.S. population. In 2016, 56% of all Data Breaches began with a user clicking on a phishing email. The big story for 2017 I think, is the rise of ransomware. Kaspersky reports a 250% increase in ransomware for the first few months of 2017. From WannaCry to Petya to Fusob, criminals are holding systems hostage until a ransom is paid…or not. Ransomware seems to be this year’s big trend with backups saving some from total embarrassment.

Cloud Computing: RightScale 2017 State of the Cloud Report notes that Hybrid Cloud Is the preferred enterprise strategy, with 85 percent of enterprises have a multi-cloud strategy (up from 82 percent in 2016) and Cloud Users Are Running Applications in Multiple Clouds. An interesting stat from the report says, cloud users are running applications in an average of 1.8 public clouds and 2.3 private clouds. We got hybrid cars, hybrid corn, hybrid cats and hybrid clouds but The Cloud is Still just a Datacenter Somewhere so no need to freak out. Cloud seems to be more than half full as the security and expertise challenges decline.

DNS: I’ve said it before and I’ll say it again, DNS is one of the most important components of a functioning internet. With that, it presents unique challenges to organizations. 2016 saw record-breaking DNS-based attacks and outages, which thrust DNS management into the spotlight as both a vulnerability and a critical asset. In 2016 DNS provider Dyn experienced a huge DDoS attack taking out many popular websites and internet cameras. And a new attack uncovered this year, DNSMessenger, uses DNS queries to conduct malicious PowerShell commands on compromised computers – a technique that makes the remote access trojan difficult to detect on targeted systems. The need for DNS continues to be half-full with the influx of IoT devices so it’ll continue to be a valuable target for riff-raff.

IoT: What can I say? The cup runneth over…again. Gartner has identified the Top 10 IoT technologies that should be on every organization's radar for 2017 and 2018. They include things like new security risks and challenges to the IoT devices themselves, their platforms and operating systems, their communications, and even the systems to which they're connected. Analytics to understand customer behavior, to deliver services and improve products. Device management, device processors, operating systems, platforms, standards and even the networks IoT devices use are all areas of attention. IoT is really three-quarters full both with the opportunities and potential risks. And the risks can be deadly when monitoring vital information like human vital signs.

Mobile: We are mobile, our devices are mobile and the applications we access are mobile. Mobility, in all its iterations, is a huge enabler and concern for enterprises and it'll only get worse as we start wearing our connected clothing to the office. 5G is still a couple years away but AT&T and Verizon have already lined up trials of their 5G networks for 2017. Mobile is certainly half full and there is no emptying it now.

That's what I got so far and I'm sure 2017's second half will bring more amazement, questions and wonders. We'll do our year-end reviews and predictions for 2018 as we all lament, where did the Year of the Rooster go?

There's that old notion that if you see a glass half full, you're an optimist and if you see it half empty you are a pessimist. I think you need to understand what state the glass itself was before the question. Was it empty and filled half way or was it full and poured out? There's your answer!

ps


This article originally appeared on F5.com.

Tuesday, August 8, 2017

Create a BIG-IP HA Pair in Azure

Use an Azure ARM template to create a high availability (active-standby) pair of BIG-IP Virtual Edition instances in Microsoft Azure. When one BIG-IP VE goes standby, the other becomes active, the virtual server address is reassigned from one external NIC to another.

Today, let’s walk through how to create a high availability pair of BIG-IP VE instances in Microsoft Azure. When we’re done, we’ll have an active-standby pair of BIG-IP VEs.

To start, go to the F5 Networks Github repository.


Click F5-azure-arm-templates. Then go to Supported>ha-avset and there are two options. You can deploy into an existing stack when you already have your subnets and existing IP addresses defined but to see how it works, let’s deploy a new stack.


Click new stack and scroll down to the Deploy button. If you have a trial or production license from F5, you can use the BYOL option but in this case, we’re going to choose the PAYG option.


Click Deploy and the template opens in the Azure portal. Now we simply fill out the fields. We’ll create a new Resource Group and set a password for the BIG-IP VEs.

When you get to the questions:

The DNS label is used as part of the URL.

Instance Name is just the name of the VM in Azure.

Instance Type determines how much memory and CPU you’ll have.

Image Name determines how many BIG-IP modules you can run (and you can choose the latest BIG-IP version).

Licensed Bandwidth determines the maximum throughput of the traffic going through BIG-IP.
Select the Number of External IP addresses (we’ll start with one but can add more later). For instance, if you plan on running more than one application behind the BIG-IP, then you’ll need the appropriate external IP addresses.

Vnet Address Prefix is for the address ranges of you subnets (we’ll leave at default).

The next 3 fields (Tenant ID, Client ID, Service Principal Secret) have to do with security. Rather than using your own credentials to modify resources in Azure, you can create an Active Directory application and assign permissions to it.

The last two fields also go together. Managed Routes let you route traffic from other external networks through the BIG-IPs. The Route Table Tag means that anytime this tag is found in the route table, routes that have this destination are updated so that the next hop is the IP address of the active BIG-IP VE. This is useful if you want all outbound traffic to go through the BIG-IP or if you want to send traffic from a bunch of different Vnets through the BIG-IP.

We’ll leave the rest as default but the Restricted Src Address is good way to put IP addresses on my network – the ones that are allowed to connect to the BIG-IP.

We’ll agree to the terms and click Purchase.


We’re redirected to the Dashboard with the Deployment in Progress indicator. This takes about 15 minutes.


Once finished we’ll go check all the resources in the Resource Group.


Let’s find out where the virtual server address is located since this is associated with one of the external NICs, which have ‘ext’ in the name. Click the one you want.


Then click IP Configuration under Settings.


When you look at the IP Configuration for these NICs, whenever the NIC has two IP addresses that’s the NIC for the active BIG-IP. The Primary IP address is the BIG-IP Self IP and the Secondary IP is the virtual server address.


If we look at the other external NIC we’ll see that it only has one Self IP and that’s the Primary and it doesn’t have the Secondary virtual server address. The virtual server address is assigned to the active BIG-IP.


When we force the active BIG-IP to standby, the virtual server address is reassigned from one NIC to the other.

To see this, we’ll log into the BIG-IPs and on the active BIG-IP, we’ll click Force to Standby and the other BIG-IP becomes Active.


When we go back to Azure, we can see that the virtual server IP is no longer associated with the external NIC.


And if we wait a few minutes, we’ll see that the address is now associated with the other NIC.


Basically, how BIG-IP HA works in the Azure cloud is by reassigning the virtual server address from one BIG-IP to another. Thanks to our TechPubs group and check out the demo video.

ps

Tuesday, July 11, 2017

BIG-IP VE on Google Cloud Platform

Hot off Cloud Month, let’s look at how to deploy BIG-IP Virtual Edition on the Google CloudPlatform.

This is a simple single-NIC, single IP deployment, which means that both management traffic and data traffic are going through the same NIC and are accessible with the same IP address.


Before you can create this deployment, you need a license from F5. You can also get a trial license here. Also, we're using BIG-IP VE version 13.0.0 HF2 EHF3 for this example.

Alright, let’s get started.

Open the console, go to Cloud Launcher and search for F5.

Pick the version you want.

Now click Launch on Compute Engine.

I’m going to change the name so the VM is easier to find… For everything else, I’ll leave the defaults.

And then down under firewall, if these ports aren’t already open on your network, you can open 22, which you need so you can use SSH to connect to the instance, and 8443, so you can use the BIG-IP Configuration utility—the web tool that you use to manage the BIG-IP.

Now click Deploy. It takes just a few minutes to deploy.

And Deployed.

When you’re done, you can connect straight from the Google console. This screen cap shows SSH but if you use the browser window, you need to change the Linux username to admin in order to connect.

Once done, you'll get that command line.

If you choose the gcloud command line option and then run in the gcloud shell, you need to put admin@ in front of the instance name in order to connect.


We like using putty so first we need to go get the external IP address of the instance. So I look at the instance and copy the external IP.

Then we go into Metadata > SSH keys to confirm that the keys are there. (Added earlier), Whichever keys you want to use to connect, you should put them here.

BIG-IP VE grabs these keys every minute or so, so any of the non-expired keys in this list can access the instance. If you remove keys from this list, they’ll be removed from BIG-IP and will no longer have access. You do have the option to edit the VM instance and block project-wide keys if you’d like.

Because my keys are already in this list I can open Putty now, and then specify my keys in order to connect.


The reason that we're using ssh to connect is that you need to set an admin password that’s used to connect to the BIG-IP Config utility.

So I’m going to set the admin password here… (and again, you can do these same steps, no matter how you connect to the instance)

tmsh Command is: modify auth modify auth password admin
And then: save sys config to save the change.

Now we can connect and log in to the BIG-IP Config utility by using https, the external IP and port 8443. Now type admin and the password we just set.

Then we can proceed with licensing and provisioning BIG-IP VE.

A few other notes:
  • If you’re used to creating a self IP and VLAN, you don’t need to do that. In this single NIC deployment, those things are taken care of for you.
  • If you want to start sending traffic, just set up your pool and virtual server the way you normally would. Just make sure if your app is using port 443, for example, that you add that firewall rule to your network or your instance.
  • And finally, you most likely want to make your external IP address one that is static, and you can do that in the UI by choosing Networking, then External IP addresses, then Type).
  • If you need any help, here's the Google Cloud Platform/BIG-IP VE Setup Guide and/or watch the full video.

ps