{"id":112852,"date":"2020-06-23T09:00:58","date_gmt":"2020-06-23T16:00:58","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=112852"},"modified":"2020-07-09T13:50:25","modified_gmt":"2020-07-09T20:50:25","slug":"network-multi-cloud-networking","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2020\/06\/network-multi-cloud-networking\/","title":{"rendered":"Multi-Cloud Networking Advances as Palo Alto Networks and Alkira Team Up"},"content":{"rendered":"<p><span style=\"font-weight: 400\">Palo Alto Networks is working with Alkira, a multi-cloud networking provider, to embed Palo Alto Networks VM-Series virtual firewalls into Alkira\u2019s networking-as-a-service platform. This integration is designed to help enterprises rapidly deploy and secure multi-cloud networks.<\/span><\/p>\n<p><span style=\"font-weight: 400\">We all recognize that cloud adoption continues to accelerate and shows no sign of slowing down. Enterprises are increasingly transitioning business-critical applications from on-premises data centers to a single or multiple public clouds and SaaS environments.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">This transition to support digital transformation presents significant challenges for traditional network and network security IT architectures, which have neither adapted to the needs of the cloud nor historically operated in synergy with the cloud. All the causes of these challenges are too long to list but include knowledge gaps, disparate cloud capabilities and limits, costly over-provisioning (i.e. overspend), fragmented security controls and operational invisibility, to name but a few. New thinking and approaches are needed to ensure cloud adoption delivers timely, comprehensive and cost-effective solutions to business stakeholders.<\/span><\/p>\n<p><span style=\"font-weight: 400\">\u00a0<\/span><span style=\"font-weight: 400\">Unshackling enterprise IT teams to deliver immediate business value through accelerated cloud adoption requires specific capabilities. In conversations with many enterprises, we consistently hear about the burning need for five cloud network infrastructure and network security services:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Global network connectivity to and across clouds.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Consistent and pervasive security model.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Operational visibility.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Simple provisioning.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Cloud-friendly consumption model.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">The collaboration of Palo Alto Networks and <a href=\"https:\/\/www.alkira.com\/\" rel=\"nofollow,noopener\" >Alkira<\/a> meets each of these enterprise-grade capabilities and more.<\/span><\/p>\n<p><span style=\"font-weight: 400\"> <div style=\"max-width:100%\" data-width=\"900\"><span class=\"ar-custom\" style=\"padding-bottom:55.67%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-112853 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/06\/Alkira-portal.png\" alt=\"This image shows how Alkira Cloud Exhange Point integrates with Palo Alto Networks VM-Series virtual firewalls for better multi-cloud networking. \" width=\"900\" height=\"501\" \/><\/span><\/div><\/span><\/p>\n<p><span style=\"font-weight: 400\">At the heart of this is an integration between Palo Alto Networks VM-Series virtual firewalls and the Alkira Cloud Services Exchange (Alkira CSX) unified multi-cloud network, which is delivered as a service. To meet cloud speed and agility, enterprises can now easily deploy a global multi-cloud network integrated with VM-Series virtual firewalls for end-to-end visibility and governance. The entire multi-cloud network is ready for use in minutes, thanks to an intuitive digital design canvas and one-click deployment.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Alkira CSX consists of a network of globally distributed Alkira Cloud Exchange Points (CXPs), which are virtual multi-cloud points of presence interconnected with high-bandwidth, low-latency cloud backbone. VM-Series virtual firewalls live and scale inside the Alkira CXPs<\/span><span style=\"font-weight: 400\"> \u2013 which, in turn, issue intent-based policies that allow enterprises to define traffic of interest for firewall inspection. To eliminate the need for configuring complicated routing domains or forcing network address translation (NAT), symmetric traffic steering simplifies proper stateful VM-Series operation in a single cloud location or across the entire cloud network.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">As application volumes change, Alkira CSX makes intelligent decisions to autoscale the VM-Series virtual firewalls to accommodate increasing or decreasing capacity demand in realtime. Autoscale avoids provisioning for peak capacity; at the same time, it allows dynamic high firewall scale when needed. Alkira CSX works jointly with Palo Alto Networks Panorama to make sure that autoscaling VM-Series virtual firewalls are configured with consistent security policies.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">The combination of Palo Alto Networks and Alkira helps make macro-level security consistent. This helps organizations that leverage the concept of <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/02\/cloud-sdn-security\/\"><span style=\"font-weight: 400\">security zones<\/span><\/a><span style=\"font-weight: 400\">. For example, \u201cIntranet\u201d zone may be allowed to communicate with \u201cCloud\u201d zone, while \u201cDMZ\u201d zone may not be allowed to communicate with \u201cCloud\u201d zone. VM-Series virtual firewalls enforce advanced security policies to protect the allowed communications between zones with traffic content inspection, IPS, and malware analysis capabilities \u2013 and because Alkira CSX has full interoperability with VM-Series, enterprises can use Alkira CSX to maintain the same security architecture across their entire environment. This means IT security teams can design and enforce uniform zone-based security policies that stretches across on-prem, single cloud and multi-cloud environments to protect the following communication flows:\u00a0\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Between on-premises environments and a single or multi-cloud.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Between workloads in a single cloud or between workloads across multiple clouds.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Between on-premises environments and SaaS\/internet.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Between cloud or multi-cloud environments and SaaS\/internet.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Cloud-DMZ with controlled inbound access from the internet to on-premises, cloud or multi-cloud environments.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\"> <div style=\"max-width:100%\" data-width=\"900\"><span class=\"ar-custom\" style=\"padding-bottom:55.89%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-112866 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/06\/Alkira-cloud.png\" alt=\"This image shows how to achieve multi-cloud enterprise-grade security through Alkira Intent-Based Policy combined with Palo Alto Networks Firewall Security Policy. \" width=\"900\" height=\"503\" \/><\/span><\/div><\/span><\/p>\n<p><span style=\"font-weight: 400\">When deploying this joint solution, enterprises have the flexibility to choose between pay-as-you-go (PAYG) and bring-your-own-license (BYOL) licensing models or leverage both at the same time.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Alkira CSX takes care of the entire lifecycle of the VM-Series virtual firewall, including provisioning, management, and monitoring, which are available through the Alkira CSX Portal and programmatically through the exposed REST APIs.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Using VM-Series virtual firewalls with Alkira Cloud Services Exchange provides enterprises the following key benefits:<\/span><span style=\"font-weight: 400\">\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">High-speed, low-latency global network to and across clouds.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Uniform security policy across on-premises, cloud and multi-cloud environments.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Horizontal firewall autoscale based on real-time capacity demand.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Simple operations.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">One-click provisioning for network and firewall security capabilities.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Pay-as-you-go (PAYG) and bring-your-own-license (BYOL) pricing models.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">Learn more by downloading the <a href=\"https:\/\/www.paloaltonetworks.com\/resources\/techbriefs\/alkira\">Palo Alto Networks and Alkira Solution Brief<\/a>. And be sure to check out this webinar: <\/span><a href=\"https:\/\/www.alkira.com\/discover\/securitywebinar\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400\">Palo Alto Networks and Alkira: New Approaches to Multi-Cloud Networking &amp; Security<\/span><\/a><span style=\"font-weight: 400\">. <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Networks and Alkira work to embed VM-Series virtual firewalls into a networking-as-as-a-service platform for better multi-cloud networking.<\/p>\n","protected":false},"author":663,"featured_media":108494,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6768,6765],"tags":[5109,810,1860,309],"coauthors":[7128],"class_list":["post-112852","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-cloud","category-secure-the-enterprise","tag-multi-cloud","tag-network-security","tag-partner","tag-vm-series","net_sec_category-network-perimeter"],"jetpack_featured_media_url":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/03\/IMG_2009.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/112852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=112852"}],"version-history":[{"count":6,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/112852\/revisions"}],"predecessor-version":[{"id":113610,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/112852\/revisions\/113610"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/108494"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=112852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=112852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=112852"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=112852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}