Thursday, 8 October 2020

Tanmay Kshirsagar (D18IT136) & Dhruvkumar Dholakiya (D18IT137)

Moving towards advance security in networking via SD - WAN

Why SD-WAN?


According to researcher International Data Corporation (IDC), the SD-WAN market will continue growing at a more than 30% rate over the next few years. Many organizations are embracing SD-WAN solutions for a number of key benefits, including the following Companies for examples Cisco, Fortinet, Juniper, JIO etc.

Introduction

Software-defined wide-area network (SD-WAN) solutions transform an organization’s capabilities by leveraging the corporate wide-area network (WAN) as well as multi-cloud connectivity to deliver high-speed application performance at the WAN edge of branch sites. One of the chief benefits of SD-WAN is that it provides a dynamic path selection among connectivity options 4G/5G, or broadband ensuring organizations can quickly and easily access business-critical cloud applications. SD-WAN solutions have become increasingly popular as organizations request fast, scalable, and flexible connectivity among different network environments, and seek to lower overall total cost of ownership (TCO) while preserving user experience. But the wrong SD-WAN solution can significantly inhibit an organization’s ability to quickly adapt to changing business demands, not least because it creates new security headaches.

Figure 1: SD-WAN

As you can see by using SD-WAN the traffic passing through the public internet so security like web-filtering, anti-malware, is much important for network.Improve user experience and simplify operations at the WAN Edge with an integrated NGFW and SD-WAN in single offering.

Problem Description

Currently, Traditional network support basic capabilities however WAN are connected through MPLS which are very expensive. To overcome this problem the concept of SD- WAN were take placed and now most of the organizations are plan to move on to this technology, but SD-WAN Transmit the traffic through insecure channel so the security is the main concern for SD-WAN.

Motivation

SD-WAN is the emerging technology which reduces the overall WAN costs by Multiprotocol Label Switching (MPLS) substitution with internet. The traffic passes from the public internet (3G/4G) and insecure channel. Security is the biggest concern in SD-WAN. So to solve such problem we need some advanced security features like web-filtering, anti- malware, intrusion prevention (IPS) and many more features.

Scope

Traditional Hybrid network has many issues to distribute the critical traffic and other traffic in different interface. By using SD-WAN we can easily control and distribute the traffic as per their priorities.

Objective:

The objective of this research study to provide security for SD-WAN because SD-WAN will transfer some traffic via public internet. SD-WAN uses Public internet for passing the traffic therefore security is main concern for protecting the corporate data.The underlying technology in SD-WAN allows remote sites to connect more easily to networks, with lower latency, better performance, and more reliable connectivity. In the era when users demand a lot more of their applications and infrastructure at unprecedented speed and scale, an appealing user experience can be a make-or-break.

SD-WAN needs security like:

·         Anti-Malware

·         URL filtering

·         Intrusion prevention

·         SSL inspection

·         Sandboxing 

SD-WAN does not support layer 4 to layer 7 security which is most required.

Advantages


Lower TCO: Multiprotocol Label Switching (MPLS) and other connectivity technologies aren’t just outdated, they’re also more expensive when the Total cost of ownership (TCO) is considered. SD-WAN significantly reduces bandwidth costs, and when it can offer benefits such as zero-touch provisioning, better automates certain processes and cuts down on the amont of hardware and manual management required for success.

Simplicity: As network infrastructures have evolved, the sprawl of point products used for networking and security can make things pretty complicated. SD-WAN uses automation and other benefits to make connectivity a simpler process across mixed environments, including on-premises, hybrid, and cloud.

Multi-cloud Readiness: With more than 90% of enterprises today investing in a multi-cloud strategy, the right SD-WAN solution makes that environment easier to manage. Multi-cloud is not the same as hybrid cloud, in which public and private clouds are integrated to optimize performance, security and flexibility. 

Better Security Overall: An SD-WAN solution needs to have integrated security; otherwise, it’s just another connectivity option that unfortunately becomes an attack vector. When properly implemented, secure SD-WAN improves the security of the business overall.

Description of Architecture

SD-WAN with Embedded Firewall

·         This firewall is same as a state full firewall which you can see at branch offices.

·         It will use for smaller branch office which has noncritical activities.

·         As we see it was used by smaller branches the relative cost is less than other system.

·         It vendors for this types are Citrix, Cloud Genix, Silver Peak, VeloCloud.

·         It was use for larger branch and which has more critical activities.

·         The cost is probably high.

·         The vendor which provides these types of security is barracuda network, Cisco Meraki,  Fortinet.

·         The security in this architecture is very high.



Figure 2: Firewall with Embedded SD-WAN

SD-WAN with Third-party Firewall

·         It was also use for larger branches and critical activities.

·         The relative cost is high.

·         Security perspective it will give more security then all others.

·         The vendors like check point, Cisco, Fortinet, Juniper Networks, Palo Alto Networks.


                                                 Figure 3: SD-WAN with 3rd Party firewall

Create SD-WAN Interface

 

Figure 4: SD-WAN Interface



Figure 5: SD-WAN Usage (Volume)



Figure 6: SD-WAN Usage (Sessions)


 

Figure 7: SD-WAN Usage (Bandwidth)

·   Here you can create or add the SD-WAN interface. We need minimum two interfaces to create SD-WAN. Add the interface with their dedicated gateway address.

·  Here we can manage the SD-WAN by the usage of Bandwidth, Volume or Sessions. We get the graphical representation of SD-WAN usage.

·      We can also enable or disable the interface as per our need and requirement.

Cisco Security Services Exchange

·    Firepower events that are promoted to incidents are displayed on the Incidents page in Cisco SecureX threat response.

·     If an IP address that you are investigating in Cisco SecureX threat response was observed in a Firepower event, that event appears in the investigation dataset, even if the event was not promoted to incident.

·    For information on effectively using Cisco SecureX threat response to find, investigate, and take action on threats, see the online help in Cisco SecureX threat response.

                               Figure 8: Cisco Security Services Exchange using for SD-WAN


Conclusion

Traditional Networks will use the MPLS technology for connecting their branches to each other which are too costly. This technology was replaced by the emerging SDN technology merging with WAN. By using SD-WAN we can transfer our traffic through the public internet 4G/LTE, so all the traffic is passing via insecure channel. SD-WAN will reduce the cost. By using this we can monitor and control the traffic from one placed and also provide the feature like we can send our high bandwidth usage application to high bandwidth with low latency and expensive line and low bandwidth application from low bandwidth with High latency and less-expensive line. 

By using SD-WAN we can reduce the cost and increase the network operations but security is the main concern. We have include the advanced security features like Intrusion prevention, ssl-inspection, anti-malware and much more. 

At last we can conclude that SD-WAN will provide by many vendors but it need some advanced security features for better network performance and provide the Secure SD- WAN to the organization.
  

Future Extensions


SD-WAN are the emerging technology so it will be highlighted for some years in research areas. We can enhanced the security for SD-WAN and also make the SD-WAN automated for selecting the High-Bandwidth line by itself for VoIP traffic and business critical applications. We can also work on High availability for SD-WAN. SD-WAN are worked at direct internet so Attacks and Threats must be neglected from the network.

Bibliography


1. Shin, M. K., Nam, K. H., & Kim, H. J. (2012, October). Software-defined networking (SDN): A reference architecture and open APIs. In 2012 International Conference on ICT Convergence (ICTC) (pp. 360-361). IEEE. 

2. Christensson, P. (2006). WAN Definition. Retrieved 2019, Nov 21, from https://techterms.com

3. Michel, O., & Keller, E. (2017, May). SDN in wide-area networks: A survey. In 2017 Fourth International Conference on Software Defined Systems (SDS) (pp. 37-42). IEEE.

4. Glenda, M. (2017). Secure SD-WAN: Integrated NGFW Security with WAN Transformation. Gartner. 

5. Singh, Naresh. “Fortinet Secure SD-WAN: Best-of-Breed NGFW and SD-WAN in a Single Offering.” Gartner, November 12, 2018.

My Achievement 

Certification

Badges

Department of Information Technology
Smt. Kundanben Dinsha Patel Department of Information Technology
Charotar University of Science and Technology,
CHARUSAT Campus, Changa
Taluka: Petlad, Dist: Anand
Gujarat (India) 388 421

Certification

  Network Security Expert 1 Certification Number : F2kwBxHLWg Network Security Expert 2 Certification Number : SpwZ6ca0KO Certified Network ...