Sydney
November 6-8, 2017

Event Details

Please note: All times listed below are in Central Time Zone


Service Chaining Virtual Security Functions

With the recent cyber-security incidents, it is more important than ever to secure virtual applications! However, traditional advanced network security methods within an OpenStack cloud can introduce complexity, network latency, and general operational headaches. Network Service Chaining can be used to easily enable network functions, such as security. This workshop focuses on how to use the OpenStack Service Chaining functionality, available via the network-sfc Neutron plugin, to protect workloads on an OpenStack cloud.

In this workshop, attendees will be provided with an OpenStack cloud enabled with service chaining, several virtual security functions (WAF, IDS/IPS, Web Content Filters), and a virtualized web server to protect. Each will set up service chains and deploy virtual security functions to monitor and block malicious traffic destined for the virtual web server. This workshop is run completely on open source software.


What can I expect to learn?

Overall, attendees will learn an effective and efficient manner to protect virtualized workloads within an OpenStack cloud from ever present threats.

Attendees will learn how to use OpenStack Horizon and the OpenStack CLI to setup and deploy network service chains and virtual security functions. Attendees will also learn how to setup and configure open source security functions (WAF, IDS/IPS, Web Content Filtering) as virtual functions/machines.

Attendees will learn how to use the service chain functions within the Neutron command line interface. This includes setting up complex chains through the use of flow-classifiers, port pairs, and pair groups.

Attendees will learn how to utilize open source security functions to monitor and block malicious traffic through an OpenStack virtual network.

Monday, November 6, 1:30pm-3:00pm (2:30am - 4:00am UTC)
Difficulty Level: Intermediate
Cyber Security Consultant
John is the author of several OpenInfra and CNCF proof of concepts including OpenStack on ARM, OpenStack on Equinix Metal, Rook with Ceph on Equinix Metal, and the Packet Zuul Node Pool driver. By day, he is a network security consultant for manufacturing, telco, and SaaS providers.  FULL PROFILE
Senior Staff Engineer, Huawei
Louis is currently a senior staff engineer working on network virtualization, cloud services, and SDN technologies at Huawei Technology USA. Louis is an active contributor to serverless cloud computing and service function chaining at several organizations including OpenStack, ONF, ETSI NFV, IETF, OPNFV and CNCF. FULL PROFILE