With the recent cyber-security incidents, it is more important than ever to secure virtual applications! However, traditional advanced network security methods within an OpenStack cloud can introduce complexity, network latency, and general operational headaches. Network Service Chaining can be used to easily enable network functions, such as security. This workshop focuses on how to use the OpenStack Service Chaining functionality, available via the network-sfc Neutron plugin, to protect workloads on an OpenStack cloud.
In this workshop, attendees will be provided with an OpenStack cloud enabled with service chaining, several virtual security functions (WAF, IDS/IPS, Web Content Filters), and a virtualized web server to protect. Each will set up service chains and deploy virtual security functions to monitor and block malicious traffic destined for the virtual web server. This workshop is run completely on open source software.
Overall, attendees will learn an effective and efficient manner to protect virtualized workloads within an OpenStack cloud from ever present threats.
Attendees will learn how to use OpenStack Horizon and the OpenStack CLI to setup and deploy network service chains and virtual security functions. Attendees will also learn how to setup and configure open source security functions (WAF, IDS/IPS, Web Content Filtering) as virtual functions/machines.
Attendees will learn how to use the service chain functions within the Neutron command line interface. This includes setting up complex chains through the use of flow-classifiers, port pairs, and pair groups.
Attendees will learn how to utilize open source security functions to monitor and block malicious traffic through an OpenStack virtual network.