Why? The Cloud Goes (Went) Enterprise! On-the-go Home or Hotel Regional Office Regional Gateway Sales from the road on iPAD Office from everywhere Marketing user groups Training videos from iPhone Corporate storage Cloud Services Business Critical HQ APT/0Day DLP Users Applications Personal or business Use
— Impact — 3 Trends Transforming Network & Security Users work from home or on-the-go Users who BYOD Cloud-based applications used by an enterprise employees use Facebook at work
1 GB Traditional MPLS Networking – Hub & Spoke NEW YORK HQ: SAN JOSE SEATTLEATLANTA DATACENTER INTERNET For Internet Access also provision a 1 Gbps Dedicated Internet Line at the “hub” datacenter 4 Provision a T3 (45 Mbps) per site to provide connectivity to the MPLS network 2 T3 Provision a 1 Gbps Ethernet circuit to provide the “hub” datacenter connectivity to the MPLS network 3 1 GB MPLS PROVIDER Contact a MPLS Service Provider & Architect 1
Is This The Best Way to Provide Internet Access? NEW YORK HQ: SAN JOSE SEATTLE ATLANTA DATACENTER INTERNET 1 GB MPLS PROVIDER T3 1 GB By volume often 70%+ of MPLS backhauled traffic is Internet bound or Web Traffic port 80 & 443 MPLS Bandwidth is more expensive than commodity Direct Internet Access $$$$$$$
1 GB “Direct 2 Net” Split Tunnel Path to Insecurity? NEW YORK HQ: SAN JOSE SEATTLE ATLANTA DATACENTER INTERNET T3 1 GB MPLS PROVIDER Layers of appliances (FW, IPS, AV, DLP, NGFW, BA) are deployed at the “hub” datacenter to secure Internet access! Branch router security (UTM) is one approach to secure local Internet access… … but keeping policy consistent and providing per user policy and reporting/visibility is a nightmare Easy way out is to still backhaul… So is MPLS Dead?
The Web Traffic Offload Approach with Zscaler NEW YORK HQ: SAN JOSE SEATTLE ATLANTA DATACENTER INTERNET Reduce the size of the MPLS links to a T1 (1.5Mbps) instead of a T3 Link (45 Mbps) and save $$ 2 T1 Reduce the size of the Internet access at the datacenter. Simplify Network & Security and save $$ MB MPLS PROVIDER Purchase inexpensive local Internet access at the branches (often faster/lower latency!) and save $$ 1 INTERNET ISP 100 MB Offload your Web traffic to the Zscaler Cloud for security processing! 4
What Does Typical Security Look Like Today? Regional Office Home or Hotspot HQ On-the-go Social Media Cloud Apps Mobile Apps Botnet Exploits Proxy Server APT/Bot Gateway Application Awaerness URL Web-Filter Antivirus-Filter WAN/SSL Accleration Load Balancer DLP SSL/IPSec VPN
What Does Zscaler Do? Block the bad, protect the good NO HARDWARE | NO SOFTWARE Regional Office Home or Hotspot HQ On-the-go Social Media Cloud Apps Mobile Apps Botnet Exploits