The Everything Feed - All Packet Pushers Pods

The Everything Feed - All Packet Pushers Pods

By Packet PushersTechnology
Download on the App Store

The Everything Feed - All Packet Pushers Pods episodes

  • Datanauts 139: Getting AWS Security Right
    AWS security issues show up in tech news fairly often. Today, we talk with someone who wrote about AWS services other than S3 that were found exposed to the public. Could that be some of your services?
    Could be. The numbers are pretty impressive. Stay tuned, and find out how to determine whether or not your EBS snapshots, RDS snapshots, AMIs, or ElasticSearch clusters are accidentally public.
    Our guest is Scott Piper, an AWS security consultant for Summit Route. You can follow him on Twitter at @0xdabbad00.
    We start by exploring the types of AWS resources that can be unintentionally exposed to the public Internet, how to find them, and how to lock them down.
    Then we talk about general practices such as vulnerability scanning, how to minimize human error when configuring AWS services, and drill into options such as CloudMapper and Security Monkey, open-source tools to help administrators find and control AWS resources.
    Show Links:
    Scott Piper on Twitter
    Scott Piper’s blog – Duo.com
    Scott Piper on GitHub – GitHub
    Beyond S3: Exposed Resources on AWS – Duo.com

    flAWS Challenge
    CloudMapper – GitHub
    CloudTracker – GitHub
    Netflix Security Monkey – GitHub
    Datanauts 086: AWS Identity & Access Management Policies – Packet Pushers
    Datanauts 106: Controlling AWS Costs – Packet Pushers
    0 min
  • BiB 045: Rubrik Alta 4.2 AWS Native Protection For EC2
    A transcript of the audio you can listen to above follows.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary.
    I’m Ethan Banks, it’s June 13, 2018, and here’s what’s happening. I had a briefing with Rubrik’s technical marketing team on June 5th.
    Who Is Rubrik?
    Rubrik is an explosively growing data protection company. Gartner positions them in the Data Center Backup & Recovery Solutions category. If you have been reviewing your multi-cloud, hybrid cloud, and on premises backup schemes and haven’t evaluated Rubrik, you should. They are winning a lot of deals.
    In this briefing, Rubrik discussed many aspects of their Alta 4.2 software release. The feature expansion, improved service offering, and overall enhancement list is quite long. One highlight is that of Rubrik’s ecosystem expansion, where Alta 4.2 offers AWS native protection for EC2, VMware vCloud Director integration, Windows full volume protection, as well as AIX & Solaris support. All of that feeds into Rubrik’s core value proposition of protecting your data no matter where it is.
    Let’s Drill Into Alta 4.2’s AWS Native Protection For EC2 Instances
    What Rubrik’s done here is take their history of using native APIs to backup hypervisor-based platforms from VMware and Microsoft, as well as apps like SQL Server, and apply that native API philosophy to AWS EC2. Rubrik is using AWS’s native abilities to take snapshots of block volumes. This works whether the Rubrik instance is on premises, or in your cloud.
    The big deal here is that this helps automate lifecycle management for EC2 snapshots, formerly something that had to be done manually. Backing up? AWS makes that easy enough. But tracking each snapshot…up to you, which is what Rubrik is helping with here.
    With Rubrik managing the EC2 snapshots, you have the benefit of a management system that can rapidly assist with recovery. Rubrik knows about your EC2 snapshots and what’s in them, meaning you can use Rubrik to quickly do a restore. In fact, Rubrik demoed a simple restore from a snapshot of just a couple of clicks through the GUI dashboard familiar to Rubrik customers, compared to at least 5 discreet CLI steps required within AWS if a customer were to perform this task by hand.
    A related simplification is that of file-level recovery. Rubrik demoed being able to search their index of EC2 snapshots for a specific file and restore it. This is a major enhancement over the AWS method of file restoration, where an EC2 snapshot would have to be individually mounted and searched manually for the lost file.
    Another benefit of using Rubrik to manage these snapshots is the ability to put EC2 instances where you need them. Want to replicate an instance in a different availability zone or region? You can do that without a lot of drama via the Rubrik interface.
    You might have thought of this already, but yet another benefit is that you’re gaining the ability to manage all of your data across your IT environment in one place. If Rubrik can manage the data in question, you don’t have to go to multiple toolsets to handle backups, restores, queries, and so on. Rubrik is doing their very best to make sure that no matter where your data is, they can protect it and unify the management of it. Just because some data is in the cloud and some other data is on premises, the process shouldn’t have to be different, according to the Rubrik philosophy.
    For More Information
    For more information about Rubrik, AWS Native Protection for EC2 Instances, and the rest of the long list of new features available in Alta 4.2, visit rubrik.com. Right on the front page, they’ve got a splash about the Alta 4.2 announcement. I barely scratched the surface of e…
    0 min
  • Datanauts 138: What’s Up With Ethernet Fabrics?
    Today on the Datanauts podcast, we review the state of Ethernet fabrics in 2018.
    Between 2010 and 2012, before SDN became the new marketing hotness, it seemed like vendors were churning out Ethernet fabric products for the data center. Everyone had at least one fabric, and some had two or three.
    As time has marched on, many of those Ethernet fabrics have dropped off the map. To catch us up and review what Ethernet fabric means today is Stefan Fouant. Stefan is the Chief Architect at Copper River Technologies, a Juniper Ambassador, a quadruple JNCIE, and author of the book Day One: Junos Fusion Data Center Up and Running.
    We look at the status of Ethernet fabric protocols such as TRILL and SPB. We also dig into BGP EVPN, the latest hot fabric.
    We also discuss the characteristics of a fabric, look at reasons why a fabric might make sense in your data center, and explore inter-fabric connectivity.
    Show Links:
    Day One: Junos Fusion Data Center Up and Running – Stefan Fouant

    Shortest Path First – Stefan Fouant’s blog
    Stefan Fouant on Twitter
    Transparent Interconnection of Lots of Links (TRILL) – IETF
    Shortest Path Bridging (SPB) – Wikipedia
    BGP MPLS-Based Ethernet VPN – IETF
    Datanauts 011: Understanding Leaf-Spine Networks – Packet Pushers
    Show 366: Inside Cisco EVPN (Sponsored) – Packet Pushers
    0 min
  • BiB 044: Juniper Announces MX Series 5G Universal Routing Platform
    A transcript of the audio you can play above follows.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary.
    I’m Ethan Banks, it’s June 12th, 2018, and here’s what’s happening.
    I had a briefing with Donyel Jones-Williams, Director of Product Marketing Management at Juniper Networks last week.
    Juniper is one of the largest networking companies in the world with several divisions. This news was focused on Juniper’s service provider customers. Juniper made some forward looking announcements regarding upcoming hardware aimed at making the packet onslaught caused by IoT sensor data and 5G deployments easier to cope with.
    All of these announcements center around a new MX Series 5G Universal Routing platform.
    First up is the announcement of the MX10008 and MX10016 Universal Chassis. These join the existing PTX and QFX Universal Chassis products, meaning that the same chassis can run line cards from 3 different product lines, making it easier for customers to reposition the roles of these chassis without having to do a full rip and replace.
    The MX10008 and MX10016 will be available during the second half of 2018.
    Secondly, we have new silicon in the works. Penta chipsets will be 50% more power efficient when compared to Junos Trio chipsets. Penta silicon will also feature MACSEC and a native IP-Sec inline crypto engine, which Juniper claims is an industry first. Penta will also support flexible native Ethernet support (FlexE).
    Juniper says that Penta-powered line cards for the familiar MX960, MX480 and MX240 chassis’ will be available in Q1 2019.
    The final bit of news has to do with Control User-Plane Separation (CUPS) hardware acceleration. Juniper says that the MX Series 5G will support a standards-based 5G user-plane on the MX platform. This will allow for wireless and wireline services on the same box, but also allowing for third-party 5G control planes. What’s the big deal here? Scaling. Juniper is pushing the idea that hardware-accelerated CUPS matters, rather than doing CUPS virtualized. The bet is that large 5G deployments will require high performance to be successful, therefore, hardware acceleration will drive 5G scaling.
    New CUPS support will be available in the first half of 2019.
    Although these are forward looking announcements, Juniper states that they have demoed interoperability already, and plan to release some of that information in the coming months.
    For More Information
    Head over to http://newsroom.juniper.net/ and find additional details on this announcement.
    0 min
  • PQ 150: HCI Networking With Big Switch’s Big Cloud Fabric (Sponsored)
    One promise of hyperconverged infrastructure (HCI) is ease of management. Break down the silos, put all the components into a unified whole displayed on a single pane of glass, and voila! Apps are served.
    But networking hasn’t been integrated as effectively into HCI as the other components of the IT stack. Networking, even in an HCI world, tends be difficult. And with the dynamic needs of HCI, networking just isn’t keeping up.
    The days of standing up the network and letting it run are past, because a best effort, rough approximation of how the network should behave isn’t something you have to settle for anymore.
    Discussing integration of HCI with networking is Big Switch Networks, our sponsor for today’s Priority Queue. Prashant Gandhi, Chief Product Officer at Big Switch, is our guest.
    We talk about why “best-effort” networking isn’t suited for HCI, and look at HCI-specific operational issues and use cases including container networking and multi-tenancy.
    For hands-on experience with Big Cloud Fabric, register for BSN Labs, a demo environment in the cloud that lets you experience the technical differentiation, management CLI, and GUI of Big Cloud Fabric.
    Show Links:
    Solution Brief: Scale Out Networking for Scale Out HCI
    Tech Demo video: BCF Nutanix AHV Integration
    Deployment guide: BCF + vSAN
    Deployment guide: BCF + ScaleIO
    Demo Video: vSAN
    Blog: Big Cloud Fabric, the Ideal SDN Fabric for Nutanix HCI, Achieves Nutanix-Ready Core Validation
    Big Switch on YouTube
    Big Switch on Twitter
    Big Switch on LinekdIn
    Big Switch on Facebook
    Big Switch on Instagram
    0 min
  • Datanauts 137: Automating Infrastructure As Code With Terraform
    The robotic production facilities on board the Datanauts’ dreadnought cruiser are really great at making scout drones for identifying rich mineral deposits. Sadly, our probe production numbers are fairly low right now, because every single build is done by hand.
    Blasphemy! We need a way to simply define the end state of our drone creation and then let an orchestration engine handle all of the building. Plus, if the design changes, we need to make sure all of the existing drones are retrofitted to take advantage of the new improvements! What can be done?!
    Our guest today is Ned Bellavance. We pick Ned’s brain about infrastructure as code and his hands-on experience with HashiCorp’s Terraform.
    Find Out More About Terraform

    Datanauts Episode 71 with Mitchell Hashimoto
    https://packetpushers.net/podcast/podcasts/datanauts-071-everything-code-hashicorp/
    Datanauts Episode 92 with Brett Johnson
    https://packetpushers.net/podcast/podcasts/datanauts-092-microsoft-mcsa-lab-creation-chef/
    Hashicorp Training
    https://www.hashicorp.com/training

    Follow Ned Bellavance

    Ned’s Courses On PluralSight
    https://www.pluralsight.com/authors/edward-bellavance
    Ned’s Blog
    https://nedinthecloud.com/
    The Buffer Overflow Podcast
    https://www.anexinet.com/resources/podcasts/buffer-overflow/
    The Anexipod Podcast
    https://www.anexinet.com/resources/podcasts/anexipod/

    0 min
  • BiB 043: DriveScale’s Software Composable Infrastructure For Flash
    A transcript of the audio that you can play above follows.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary. I’m Ethan Banks, it’s June 5th, 2018, and here’s what’s happening.
    I had a briefing with DriveScale on May 31st. Who’s DriveScale? DriveScale is a storage company, whose main product is software to centrally manage and share disk for clustered applications and big data environments. File under buzzword “software composable infrastructure.”
    A central DriveScale chassis filled with disk is attached to the network in the same rack as the compute that needs it. DriveScale software makes sure that all compute nodes in the rack have as much storage as they need, but does away with the waste that direct attached storage sometimes experiences in this environments.
    In this briefing, DriveScale announced Software Composable Infrastructure for Flash, which they claim is a market first. Flash storage is all about high bandwidth and low latency, and the latest NVMe flash drives have ferocious network-filling capability. If you think serving storage over Ethernet is a performance compromise, think again.
    Quoting the official DriveScale press release,
    “DriveScale’s SCI for Flash is available as software, capable of being deployed on a variety of hardware systems. These include DriveScale’s own Composable Flash System and Western Digital’s Ultrastar Serv24-HA. The system combines the speed of up to 24 dual-ported NVMe™ drives, four 100 Gbit Ethernet ports and a dual-server architecture to deliver IT operations high performance and high availability flash storage in a composable system.”
    These systems are sometimes known as EBOFs, or Ethernet-attached Bunch of Flash. DriveScale described their EBOF to me as containing 2 controllers each with 2x100G Ethernet ports. That’s a 400G of pipe from the ToR switch to the EBOF. The controllers handle converting Ethernet to NVMe. DriveScale sells the empty chassis, allowing their channel partners to populate the chassis with NVMe drives of their choice. Again, remember that DriveScale is primarily a software company.
    In case your mind snapped at the thought of a bunch of disks being able to fill 100Gbps Ethernet channels, have a listen to the Datanauts podcast episode 111, where we talk with storage expert J Metz about NVMe and its network impact.
    To connect to the EBOFs, there are two communications protocols supported. Most environments are going to use iSCSI. But RDMA over Converged Ethernet (RoCE) is also supported, but obviously you need an RDMA fabric for this, something Mellanox might have sold you. RoCE is the “ultimate performance” solution. Looking down the road, NVMe-over-TCP is probably the final answer according to DriveScale, but NVMe-over-TCP is not standardized yet.
    One of the drivers for this solution is cost optimization. Flash is expensive, still as much as 10x over spinning rust. DriveScale SCI allows for flash to be sliced, so that, in effect, partial drives can be presented to compute nodes, rather than having to use up an entire drive as happens when the drives are directly attached.
    Other nifty capabilities include on-the-fly recomposability, keeping in step with the ephemeral container world. Public key authentication is centrally managed, and used to encrypt drives and connect drives to compute nodes. The central PKI management means that your encrypted drive data can move around as demanded by applications and still be decrypted.
    Predictive analytics are also part of the solution, helping you to determine what data should go where to optimize storage system performance.
    DriveScale was also just awarded the Cool Vendor designation in the cloud infrastructure area.…
    0 min

About The Everything Feed - All Packet Pushers Pods

From the publisher's feed

Everything we offer in one high bandwidth output queue. New content every weekday. High priority, low latency, jitter free. Too much technology would never be enough.

More shows like The Everything Feed - All Packet Pushers Pods

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

374 Listeners

Heavy Networking by Packet Pushers

Heavy Networking

327 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

The Fat Pipe - All Packet Pushers Pods by Packet Pushers

The Fat Pipe - All Packet Pushers Pods

70 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

652 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Tech Bytes by Packet Pushers

Tech Bytes

5 Listeners

IPv6 Buzz by Packet Pushers

IPv6 Buzz

33 Listeners

Day Two DevOps by Packet Pushers

Day Two DevOps

15 Listeners

The Hedge by Russ White

The Hedge

18 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

Heavy Strategy by Packet Pushers

Heavy Strategy

27 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners

Heavy Wireless by Packet Pushers

Heavy Wireless

11 Listeners

Packet Protector by Packet Pushers

Packet Protector

7 Listeners

Network Automation Nerds by Packet Pushers

Network Automation Nerds

5 Listeners

Total Network Operations by Packet Pushers

Total Network Operations

4 Listeners

Technically Leadership by Packet Pushers

Technically Leadership

0 Listeners

N Is For Networking by Packet Pushers

N Is For Networking

29 Listeners

The Cloud Gambit by Packet Pushers

The Cloud Gambit

0 Listeners

Life In Uptime by Packet Pushers

Life In Uptime

14 Listeners