The Fat Pipe - All Packet Pushers Pods

The Fat Pipe - All Packet Pushers Pods

By Packet PushersTechnology
Download on the App Store

The Fat Pipe - All Packet Pushers Pods episodes

  • BiB 064: Is Riverbed’s SD-WAN Product Too Late To Matter?
    The following is a transcript of the audio you can listen to in the player above.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary.
    I’m Ethan Banks, it’s December 1, 2018, and here’s what’s on my mind.
    I’ve had a few briefings with Riverbed in the last month or two. You can watch some of those on YouTube by searching for Riverbed SD-WAN and Tech Field Day. You probably know Riverbed as that WAN optimization company that bought CACE Technologies a few years back bringing WireShark under Riverbed’s care.
    SD-WAN Is Crucial To Riverbed
    The most critical thing happening at Riverbed these days is SD-WAN. Here’s why. The SD-WAN market is exploding with products. Consolidation is beginning to happen as major players Cisco and VMware have made SD-WAN acquisitions and begun preaching about the glory of SD-WAN to their customers…and that’s a lot of customers.
    Many of those WAN customers might well be Riverbed customers, too–Riverbed’s install base of WAN optimization appliances is huge. But the need for WAN optimization, by itself, isn’t a strong enough play anymore. People might or might not need WAN op, but as applications increasingly transition to encrypted HTTP, WAN op isn’t providing the gain it once did. That’s not to say it doesn’t matter, but organizations have to evaluate WAN optimization’s usefulness to them based on their individual application mix.
    So when Cisco comes knocking on my door telling me I can install IOSXE-SDWAN on my ISR routers and get the Viptela product, that’s pretty interesting. Sure, there’s no WAN optimization there, but maybe I make the switch and have one less supplier to deal with. Why keep Riverbed around?
    Then again, maybe I don’t make the switch. Riverbed has been a little slow with their SD-WAN strategy, but it’s far from too late. SD-WAN adoption in the enterprises where Riverbed has been making their money for so many years has been slow, too. And I think that’s going to work out well for Riverbed. Because now, I think their SD-WAN story has shaped up reasonably. This could keep Riverbed customers in the fold.
    Two New Riverbed SD-WAN Products
    If I’m interested in SD-WAN and I am running Riverbed SteelHeads, I now have an in-place upgrade option, plus some lower cost device options for sites where maybe I hadn’t deployed SteelHeads before. There are 2 appliances Riverbed has announced, adding to the SteelConnect products they launched a couple of years ago.
    SteelHead SD
    The first new appliance is the SteelHead SD. Riverbed bills SteelHead SD as a full-featured SD-WAN product, with VPN, cloud connectivity, OSPF and BGP routing, active/active high availability pairs managed as a single unit, path steering, and a business intent driven policy engine, as well as retaining the WAN optimization capabilities that Riverbed customers are likely familiar with.
    Again, just because WAN optimization isn’t as important as it once was doesn’t mean it’s no longer important at all. For example, Silver Peak claims that a pretty large percentage of their SD-WAN customers will license Boost, their WAN optimization module, for some or all of their SD-WAN fabrics. I’m sure that will be true with Riverbed SD-WAN customers as well.
    SteelHead SD is available as a software upgrade for many existing Riverbed appliances, so a lot of folks can get these features with a minimum of operational disturbance. And in fact, Riverbed has that exact scenario in mind with SteelHead SD. They are aiming this product at brownfield deployments where the routing requirements might be complex and the WAN circuits might be a hybrid of private MPLS and public Internet. Riverbed knows from their work with customers that bolting SD-WAN on…
    7 min
  • BiB 063: Can An SD-WAN Device Replace A WAN Router?
    The following is a transcript of the audio you can hear in the player above.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary. (And today we’re going to do a lot of commentary.)
    I’m Ethan Banks, it’s November 30, 2018 and here’s what’s going on. I had a briefing with Silver Peak earlier this month. Silver Peak is a software defined WAN company. They make devices and controllers that allow you to manage your wide area network fabric centrally, leveraging a mix of different circuit types, as they take care of security and traffic optimization for you.
    In this briefing, Silver Peak offered a current status of their company and a series of deeply technical demos which you can find on YouTube by searching for Silver Peak and Tech Field Day. All of this was in the context of using Silver Peak devices as WAN router replacements. Silver Peak is invested in a marketing campaign to displace Cisco WAN routers. Yep, they called Cisco out specifically.
    The campaign is a series of tongue-in-cheek videos built around the character Wayne McFarkus. Wayne is a mullet-wearing 80’s stereotype bearing the not-so-subtle message that routers are old and outdated. Modern networks wouldn’t use something so antiquated as a router. Instead, they’d use a modern solution from, oh I don’t know, Silver Peak.
    Replace A WAN Router With An SD-WAN Device?
    Let’s examine this assertion from Silver Peak. Is an SD-WAN device able to be a drop-in replacement for a WAN router from Cisco or whomever?
    First, we have to back away from the FUD claiming that routers are ancient technology that should be banished along with parachute pants and the mullet. WAN routers are, of course, an integral part of most networks of any size. They tend to have complex configurations for several reasons.

    * They connect TDM circuits, such as T1s or T3s. These circuit types are still present in many markets particularly in the US, and it takes special cards to support them.
    * They often sit at the edge of a routing domain, so they might have complicated routing policies.
    * They tend to represent a chokepoint between high-bandwidth LANs and low-bandwidth WANs, so there’s usually a QoS policy for traffic prioritization and congestion management.
    * If they are sitting at the Internet edge they might be handling public Internet routing tables and/or announcing routes themselves via BGP.
    * They are often candidates to be endpoints for tunnels like GRE or IPSEC.
    * They are frequently used as stateful firewalls, or at least for traffic filtering with access-lists, as they might be governing traffic flows between two or more different organizations.
    * For organizations requiring multicast, the WAN router needs to be a proper multicast router to avoid dropped traffic or traffic being flooded across WAN links where bandwidth is precious.
    * For those companies that are rolling out IPv6, the WAN router needs to support data-plane and ideally control-plane v6 functionality. V6 is 20 years old, so you wouldn’t think this is an issue. It’s a huge issue, especially as more organizations are getting serious about bringing the v6 running around their network already under control.
    * And finally, WAN routers are often asked to participate in network segmentation, using schemes such as VRFs, or in larger organizations, L3VPN over MPLS.

    I say all that to raise the point that routers are, for the most part, anything but mullet-wearing 80’s throwbacks. Assuming the appropriate network operating system and licensing, plenty of modern WAN routers can do all of these things. Often,
    8 min
  • BiB 063: Can An SD-WAN Device Replace A WAN Router?
    The following is a transcript of the audio you can hear in the player above.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary. (And today we’re going to do a lot of commentary.)
    I’m Ethan Banks, it’s November 30, 2018 and here’s what’s going on. I had a briefing with Silver Peak earlier this month. Silver Peak is a software defined WAN company. They make devices and controllers that allow you to manage your wide area network fabric centrally, leveraging a mix of different circuit types, as they take care of security and traffic optimization for you.
    In this briefing, Silver Peak offered a current status of their company and a series of deeply technical demos which you can find on YouTube by searching for Silver Peak and Tech Field Day. All of this was in the context of using Silver Peak devices as WAN router replacements. Silver Peak is invested in a marketing campaign to displace Cisco WAN routers. Yep, they called Cisco out specifically.
    The campaign is a series of tongue-in-cheek videos built around the character Wayne McFarkus. Wayne is a mullet-wearing 80’s stereotype bearing the not-so-subtle message that routers are old and outdated. Modern networks wouldn’t use something so antiquated as a router. Instead, they’d use a modern solution from, oh I don’t know, Silver Peak.
    Replace A WAN Router With An SD-WAN Device?
    Let’s examine this assertion from Silver Peak. Is an SD-WAN device able to be a drop-in replacement for a WAN router from Cisco or whomever?
    First, we have to back away from the FUD claiming that routers are ancient technology that should be banished along with parachute pants and the mullet. WAN routers are, of course, an integral part of most networks of any size. They tend to have complex configurations for several reasons.

    * They connect TDM circuits, such as T1s or T3s. These circuit types are still present in many markets particularly in the US, and it takes special cards to support them.
    * They often sit at the edge of a routing domain, so they might have complicated routing policies.
    * They tend to represent a chokepoint between high-bandwidth LANs and low-bandwidth WANs, so there’s usually a QoS policy for traffic prioritization and congestion management.
    * If they are sitting at the Internet edge they might be handling public Internet routing tables and/or announcing routes themselves via BGP.
    * They are often candidates to be endpoints for tunnels like GRE or IPSEC.
    * They are frequently used as stateful firewalls, or at least for traffic filtering with access-lists, as they might be governing traffic flows between two or more different organizations.
    * For organizations requiring multicast, the WAN router needs to be a proper multicast router to avoid dropped traffic or traffic being flooded across WAN links where bandwidth is precious.
    * For those companies that are rolling out IPv6, the WAN router needs to support data-plane and ideally control-plane v6 functionality. V6 is 20 years old, so you wouldn’t think this is an issue. It’s a huge issue, especially as more organizations are getting serious about bringing the v6 running around their network already under control.
    * And finally, WAN routers are often asked to participate in network segmentation, using schemes such as VRFs, or in larger organizations, L3VPN over MPLS.

    I say all that to raise the point that routers are, for the most part, anything but mullet-wearing 80’s throwbacks. Assuming the appropriate network operating system and licensing, plenty of modern WAN routers can do all of these things. Often,
    8 min
  • Weekly Show 418: A Real-World Network Design Session
    Network design is a popular listener topic. On today’s Weekly Show, we have two guests from the University of Idaho to talk about their current network design, new ideas and initiatives they’re considering, and a conversation/consultation on how to address their challenges.
    The University of Idaho has 12,000 students and 3,000 residents across one main campus and 18 small campuses. As many as 30,000 hosts attach to the network.
    We dive into current network design issues, including around firewalling and microsegmentation, identity management in the wireless network, and a home-grown network management system.
    Our guests are Brian Jemes, Network Manager; and Mike Rusca, Network Engineer, both at the University of Idaho.
    Sponsor: ThousandEyes
    ThousandEyes gives you performance visibility from every user to every app over any network, both internal and external, so you can migrate to the cloud, troubleshoot faster and deliver exceptional user experiences. Sign up for a free account at thousandeyes.com/packetpushers and choose a free ThousandEyes t-shirt.
    Sponsor: ITProTV
    Whether you’re just starting out or you’re a seasoned IT professional, ITProTV is the only source you’ll need to learn the skills to pass the most in-demand IT certs — from entry level to advanced — with engaging hosts and a talk-show style format. Visit itpro.tv/packetpushers and use code PACKETPUSHERS to try it FREE for 7 days, and receive 30% off your monthly membership for the lifetime of your active subscription.
    1 hr 3 min
  • BiB 062: Globally Scalable Microsegmentation With Illumio
    The following is a transcript of the audio you can listen to in the player above.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary. I’m Ethan Banks, it’s November 29, 2018, and here’s what’s happening. I had a briefing with Illumio earlier this month.
    Who Is Illumio?
    Illumio is a security company focused on preventing breaches from spreading through an organization using microsegmentation. The system works with a combination of agents and a central controller they call the Policy Compute Engine. The PCE determines, based on policy, what each endpoint in the network should be allowed to communicate with and tells the installed agents. Each agent programs the local operating system firewall service such as iptables or Windows Firewall.
    And in that way, you’ve got a centrally managed security policy with granular controls you can keep up with. The Policy Compute Engine is doing the heavy lifting of figuring out exactly what rules are needed in each endpoint’s firewall. There’s more to the Illumio story, but that sets the background for the announcement I’m bringing to your attention today.
    Illumio’s PCE Supercluster & Use Cases
    In this briefing, Illumio discussed their Policy Compute Engine Supercluster. The PCE Supercluster is, as the name implies, a cluster of Policy Compute Engines that spans regions or even the globe. Illumio cited several scenarios driving this available architecture of their central controller.
    Massive scale was one of those, and Illumio didn’t just throw a number up on the wall and expect people to believe it. In a live demo with a total of around 225K actual workloads spun up in three AWS regions around the world, they showed the Supercluster in action.
    The point? Supercluster distributed controller architecture works when a single, centralized controller is likely to hit scaling limits. You can grow your microsegmentation domain as big as it needs to with this product.
    A second scenario Illumio matched up with the PCE Supercluster architecture was that of large, globally distributed organizations. Why does this scenario matter to Illumio? Global companies like this often have complex applications that are communicating across the globe. For instance, a workload in one region might need to hit an authentication server in another, or perform a replication task. You get the idea.
    To manage these communications well, you need a way to coordinate policy for flow between regions, and the Supercluster offers this. The alternative is manual firewall coordination at region edges, and that’s not terribly practical in an automated world. Controller federation really matters in some organizations.
    Federation has a parallel benefit of offering consistent policy everywhere that an app is deployed, for example in multiple regions. Why reinvent the policy for each region? Create the policy once, then leverage that same policy in any region the PCE Supercluster lives and the app has been deployed.
    For More Information
    Illumio went into a lot more detail with some of the best live demos I’ve ever seen covering how the Policy Compute Engine Supercluster functions, recovers from failure scenarios, and so on.
    If you’re one of those companies with tens or even hundreds of thousands of workloads distributed globally either on-premises, in the public cloud, or both, Illumio is bringing you maximally scalable microsegmentation.
    For more information, see the recordings of the live demos I mentioned earlier by searching YouTube for Tech Field Day and Supercluster, visit illumio.com, or stay tuned into the Packet Pushers, as we’re going to publish an episode with Illumio in the coming weeks.
    4 min
  • BiB 062: Globally Scalable Microsegmentation With Illumio
    The following is a transcript of the audio you can listen to in the player above.
    Welcome to Briefings In Brief, an audio digest of IT news and information from the Packet Pushers, including vendor briefings, industry research, and commentary. I’m Ethan Banks, it’s November 29, 2018, and here’s what’s happening. I had a briefing with Illumio earlier this month.
    Who Is Illumio?
    Illumio is a security company focused on preventing breaches from spreading through an organization using microsegmentation. The system works with a combination of agents and a central controller they call the Policy Compute Engine. The PCE determines, based on policy, what each endpoint in the network should be allowed to communicate with and tells the installed agents. Each agent programs the local operating system firewall service such as iptables or Windows Firewall.
    And in that way, you’ve got a centrally managed security policy with granular controls you can keep up with. The Policy Compute Engine is doing the heavy lifting of figuring out exactly what rules are needed in each endpoint’s firewall. There’s more to the Illumio story, but that sets the background for the announcement I’m bringing to your attention today.
    Illumio’s PCE Supercluster & Use Cases
    In this briefing, Illumio discussed their Policy Compute Engine Supercluster. The PCE Supercluster is, as the name implies, a cluster of Policy Compute Engines that spans regions or even the globe. Illumio cited several scenarios driving this available architecture of their central controller.
    Massive scale was one of those, and Illumio didn’t just throw a number up on the wall and expect people to believe it. In a live demo with a total of around 225K actual workloads spun up in three AWS regions around the world, they showed the Supercluster in action.
    The point? Supercluster distributed controller architecture works when a single, centralized controller is likely to hit scaling limits. You can grow your microsegmentation domain as big as it needs to with this product.
    A second scenario Illumio matched up with the PCE Supercluster architecture was that of large, globally distributed organizations. Why does this scenario matter to Illumio? Global companies like this often have complex applications that are communicating across the globe. For instance, a workload in one region might need to hit an authentication server in another, or perform a replication task. You get the idea.
    To manage these communications well, you need a way to coordinate policy for flow between regions, and the Supercluster offers this. The alternative is manual firewall coordination at region edges, and that’s not terribly practical in an automated world. Controller federation really matters in some organizations.
    Federation has a parallel benefit of offering consistent policy everywhere that an app is deployed, for example in multiple regions. Why reinvent the policy for each region? Create the policy once, then leverage that same policy in any region the PCE Supercluster lives and the app has been deployed.
    For More Information
    Illumio went into a lot more detail with some of the best live demos I’ve ever seen covering how the Policy Compute Engine Supercluster functions, recovers from failure scenarios, and so on.
    If you’re one of those companies with tens or even hundreds of thousands of workloads distributed globally either on-premises, in the public cloud, or both, Illumio is bringing you maximally scalable microsegmentation.
    For more information, see the recordings of the live demos I mentioned earlier by searching YouTube for Tech Field Day and Supercluster, visit illumio.com, or stay tuned into the Packet Pushers, as we’re going to publish an episode with Illumio in the coming weeks.
    4 min
  • IPv6 Buzz 014: We Answer Listener Questions
    Today's IPv6 Buzz podcast episode answers listener questions including where and how you can get a block of v6 addresses for testing and learning, when to use DHCPv6 vs. SLAAC, and more. Send us more questions at @IPv6Buzz on Twitter.
    33 min
  • Datanauts 152: No More Stretched Clusters!
    At first glance, stretching a single cluster between two physical locations kinda makes sense. You get business continuity, redundancy, and you don’t have to do any weird engineering.
    But is stretching a cluster really that simple? We argue there’s a lot more to think about on today’s episode of Datanauts.
    Our guest is Erik Ableson, owner of the consultancy Infrageeks. We discuss why people stretch clusters, the problems this can cause, and alternative design strategies.
    Sponsor: Packet Pushers Virtual Design Clinic 3
    Register now for the Packet Pushers’ Virtual Design Clinic on December 19th. This live, online event includes deep-dive technical presentations for network engineers, Ask Me Anything sessions with expert panelists, and a sponsored presentation from Apcela. It’s free to sign up. Register here.
    Show Links:
    Erik Abelson on Twitter
    Infrageeks Blog
    VMware vSphere Metro Storage Cluster Recommended Practices – VMware (PDF)
    Introduction To Stretched Clusters – VMware
    No-Click Data Center Site Failovers Powered by Metro Availability Witness – Nutanix
    46 min
  • Datanauts 152: No More Stretched Clusters!
    At first glance, stretching a single cluster between two physical locations kinda makes sense. You get business continuity, redundancy, and you don’t have to do any weird engineering.
    But is stretching a cluster really that simple? We argue there’s a lot more to think about on today’s episode of Datanauts.
    Our guest is Erik Ableson, owner of the consultancy Infrageeks. We discuss why people stretch clusters, the problems this can cause, and alternative design strategies.
    Sponsor: Packet Pushers Virtual Design Clinic 3
    Register now for the Packet Pushers’ Virtual Design Clinic on December 19th. This live, online event includes deep-dive technical presentations for network engineers, Ask Me Anything sessions with expert panelists, and a sponsored presentation from Apcela. It’s free to sign up. Register here.
    Show Links:
    Erik Abelson on Twitter
    Infrageeks Blog
    VMware vSphere Metro Storage Cluster Recommended Practices – VMware (PDF)
    Introduction To Stretched Clusters – VMware
    No-Click Data Center Site Failovers Powered by Metro Availability Witness – Nutanix
    46 min

About The Fat Pipe - All Packet Pushers Pods

From the publisher's feed

Everything we offer in one high bandwidth output queue. New content every weekday. High priority, low latency, jitter free. Too much technology would never be enough.

More shows like The Fat Pipe - All Packet Pushers Pods

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,498 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,087 Listeners

The Everything Feed - All Packet Pushers Pods by Packet Pushers

The Everything Feed - All Packet Pushers Pods

194 Listeners

Heavy Networking by Packet Pushers

Heavy Networking

327 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

The Daily by The New York Times

The Daily

111,766 Listeners

Tech Field Day Podcast by Tech Field Day

Tech Field Day Podcast

16 Listeners

Tech Bytes by Packet Pushers

Tech Bytes

5 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,535 Listeners

IPv6 Buzz by Packet Pushers

IPv6 Buzz

33 Listeners

Advent of Computing by Sean Haas

Advent of Computing

83 Listeners

Day Two DevOps by Packet Pushers

Day Two DevOps

15 Listeners

The Art of Network Engineering by Andy and Friends

The Art of Network Engineering

84 Listeners

Heavy Strategy by Packet Pushers

Heavy Strategy

27 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners

Heavy Wireless by Packet Pushers

Heavy Wireless

11 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners

Packet Protector by Packet Pushers

Packet Protector

7 Listeners

Network Automation Nerds by Packet Pushers

Network Automation Nerds

5 Listeners

Total Network Operations by Packet Pushers

Total Network Operations

4 Listeners

Technically Leadership by Packet Pushers

Technically Leadership

0 Listeners

N Is For Networking by Packet Pushers

N Is For Networking

29 Listeners

Network Automagic by Steinn Örvar

Network Automagic

0 Listeners

The Cloud Gambit by Packet Pushers

The Cloud Gambit

0 Listeners

Life In Uptime by Packet Pushers

Life In Uptime

14 Listeners