Virtualized Security – The end of Big Irons

Virtualized, scalable and carrier grade performance/functionalities, a true game changer for CSP's.

How to maintain security while adopting SDN/NFV.

Most of the telecom industry agrees: SDN/NFV is the answer to optimized network efficiency, agility and to new revenue opportunities. The discussions now are not if but rather when and how SDN/NFV can replace the legacy systems.

As an example of the benefits gained by adopting SDN/NFV, Gartner highlights that some CSPs anticipates Opex reduction of 60% and Capex reduction of 40%*, providing virtualized network solutions. In addition to attractive cost reductions, CSPs can also capitalize on the new technologies by introducing new services such as Software-Defined WAN (SD-WAN) and virtual CPEs (vCPEs).

One of the key concerns and success criteria of any SDN/NFV initiative is to find technologies and products that delivers on its promise.

As SDN/NFV is relatively new technology, there is a clear gap between what is needed and what's available on the market. This is a situation that is especially true when it comes to security products. The reason for this gap boils down to that traditional firewall appliances often utilize proprietary hardware components (such as ASICs and FPGAs) to achieve the necessary performance. SDN/NFV, on the other hand, is designed to utilize Common Off The Shelf (COTS) Intel x86 platforms. Migrating an ASIC/FPGA based security product to function in an SDN/NFV environment can be challenging – if even possible at all – and often leads to sub-optimal solutions that lacks both performance and the robust APIs to enable in-depth SDN/NFV integration.

Starting out in the other end, with a security solution that is originally designed for virtual domains, they often lack the specific carrier grade functionality that is required, in combination with limited scalability to manage the ever-increasing throughput capacity.

This raises several important design aspects that have to be taken into account in the planning process. Among them, three fundamental areas CSP's has to verify when they apply security VNF's are:

  • Can carrier grade-quality, -performance and -feature set be guaranteed in a security VNF?
  • Is there a strong eco-system and open API's in place to ensure seamless integration to underlying SDN platforms and orchestration tools?
  • Is there a business model applied that provides flexible roll out and monitoring of numerous VNF's as one holistic function?

That said, with good security products that meets these needs, and a pragmatic staged approach, CSP's are able to make the transition, from traditional legacy equipment, to SDN/NFV also for their security infrastructure. Given that security infrastructure is a significant and important part of the ip-based telecom networks this means huge possibilities for cost-optimization and operational efficiency.

Read More

* Source: Gartner, Market Insight: Key Strategic Implications for CSPs' CTO, CIO and CMO to Consider When Planning SDN and NFV, Martina Kurth, 17th of May 2016

Source: Clavister