{"id":12133,"date":"2016-02-10T14:00:04","date_gmt":"2016-02-10T22:00:04","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=12133"},"modified":"2016-02-10T09:45:11","modified_gmt":"2016-02-10T17:45:11","slug":"the-best-of-both-worlds-building-a-secure-hybrid-data-center-with-aws","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2016\/02\/the-best-of-both-worlds-building-a-secure-hybrid-data-center-with-aws\/","title":{"rendered":"The Best of Both Worlds: Building a Secure Hybrid Data Center with AWS"},"content":{"rendered":"<p>If you\u2019re looking for a new car, you may be considering a hybrid \u2013 one that combines electric power for efficiency and mileage with traditional internal combustion to recharge the engine and extend the travel range. For many buyers, it is the best of both worlds, providing greater flexibility to extend your trip as needed. The same concept applies to a hybrid data center \u2013 one that combines your own, dedicated on-premises resources with the scalability and agility of on-demand compute, networking and storage resources such as those from Amazon Web Services (AWS).<\/p>\n<p>As the insatiable appetite for compute and storage resources to support the business continues unabated, customers are using the public cloud as a way to augment their data centers more quickly and more efficiently than in the past. Initially, a hybrid approach was viewed as a step toward migrating all applications and data to the public cloud. In reality, many customers are settling on a hybrid approach as their new data center architecture.<!--more--><\/p>\n<p>In a recent conversation I had with a customer, two new physical data centers had just come online, and they were already over-subscribed. They were looking to AWS as a way to extend the life of their data center using a hybrid approach. When you think about it, a hybrid approach makes the most sense. First off, it allows you to start small and establish some guidelines around which applications and data should reside in the cloud. There will be legacy applications that cannot or should not be migrated. There will be data that, after careful internal analysis, does not belong in the public cloud. For new applications, you might look at adopting a simple cloud-first mentality that says: for new applications, look to the cloud as the deployment location. A more advanced cloud-first approach entails changing your application development methodology to one that is componentized, makes heavy use of APIs, can be updated rapidly, and can be deployed globally \u2013 in the cloud first.<\/p>\n<p>From a security architecture perspective, a hybrid data center is an extension of your data center and therefore should be treated no differently than your physical data. This means that you should:<\/p>\n<ul>\n<li>Know exactly which applications are running in the cloud and whitelist them to ensure they are the only ones allowed in the cloud<\/li>\n<li>Segment the applications to control which can talk to which and limit lateral movement<\/li>\n<li>Enable applications based on the user credentials and the business need<\/li>\n<li>Apply threat prevention to block threats from accessing your cloud applications and data while also blocking them from moving laterally<\/li>\n<\/ul>\n<p>When deployed in AWS, the <a href=\"https:\/\/www.paloaltonetworks.com\/documentation\/61\/virtualization\/virtualization\/about-the-vm-series-firewall.html\" target=\"_blank\">Palo Alto Networks VM-Series<\/a> can securely enable your hybrid data center, acting as an IPSec VPN termination point and as a virtualized next-generation firewall, protecting your AWS deployment with application control and advanced threat prevention. More advanced use cases include segmentation for added security and compliance purposes through VPC to VPC and subnet to subnet policies. In effect, you can mimic your physical data center security in AWS.<\/p>\n<p>To learn more about how a hybrid data center with AWS might benefit your organization, check out these resources:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.sans.org\/webcasts\/go-key-aws-security-considerations-101452\" rel=\"nofollow,noopener\"  target=\"_blank\">SANS Webinar with Dave Shackleford: Know Before You Go: Key AWS Security Considerations<\/a><\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/whitepapers\/aws-hybrid-design-guidelines.html\" target=\"_blank\">VM-Series with AWS Hybrid Data Center Deployment Guidelines (includes sample deployment script)<\/a><\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/whitepapers\/security-considerations-for-private-vs-public-clouds.html\" target=\"_blank\">CSA White Paper: Public vs. Private Cloud Security Considerations<\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/go.paloaltonetworks.com\/ignite2016\"><div style=\"max-width:100%\" data-width=\"500\"><span class=\"ar-custom\" style=\"padding-bottom:33.4%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-12021 size-large lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-500x167.png\" alt=\"Ignite 2016 register now\" width=\"500\" height=\"167\" srcset=\"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-500x167.png 500w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-230x77.png 230w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-510x170.png 510w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-120x40.png 120w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now.png 900w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/span><\/div><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you\u2019re looking for a new car, you may be considering a hybrid \u2013 one that combines electric power for efficiency and mileage with traditional internal combustion to recharge the engine and &hellip;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[113,75],"tags":[814,1760,1759,309,101],"coauthors":[800],"class_list":["post-12133","post","type-post","status-publish","format-standard","hentry","category-cloud-computing-2","category-data-center-2","tag-amazon-web-services","tag-hybrid-data-center","tag-ipsec","tag-vm-series","tag-vpn"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/12133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=12133"}],"version-history":[{"count":1,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/12133\/revisions"}],"predecessor-version":[{"id":12134,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/12133\/revisions\/12134"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=12133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=12133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=12133"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=12133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}