68
0 Copyright 2016 FUJITSU Fujitsu Forum 2016 #FujitsuForum

Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Embed Size (px)

Citation preview

Page 1: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

0 Copyright 2016 FUJITSU

Fujitsu Forum 2016

#FujitsuForum

Page 2: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

1 Copyright 2016 FUJITSU

Reinventing IT & Enabling Hybrid Cloud withWindows Server 2016

Manfred Helber

Senior Consultant Microsoft Solutions

Page 3: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

2 Copyright 2016 FUJITSU

Windows Server The foundation of hybrid cloud

On-premises datacenter Microsoft Azure Stack

Page 4: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

3 Copyright 2016 FUJITSU

IT is being pulled in two directions

Support business agility and innovation

Provide secure, controlled IT resources

By 2017, 50% of total IT spending will be spent outside of the formal IT organization.

Page 5: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

4 Copyright 2016 FUJITSU

IT stress points

Security threats

Datacenterefficiency

Supporting innovation

Page 6: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

5 Copyright 2016 FUJITSU

Security is a top IT priority

Security threats

Datacenterefficiency

Supporting innovation

Page 7: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

6 Copyright 2016 FUJITSU

Increasing incidents

Multiple motivations

Bigger risk

Why security is a top IT priority

Page 8: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

7 Copyright 2016 FUJITSU

Source: McKinsey, Ponemon Institute, Verizon.

Cyber threats are a material r isk to your business

Impact of lost productivity and growth

Average cost of a data breach (15% YoY increase)

$3.0 Tr i l l ion $4 Mil l ion

Corporate liabilitycoverage.

$500 Mil l ion

“Cyber security is a CEO issue .”- M c K i n s e y

Page 9: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

8 Copyright 2016 FUJITSU

Security threats

Datacenterefficiency

Supporting innovation

Datacenter efficiency

Supporting innovation

Protect identity

Help secure virtual machines

Protect the OS on-premises or in the cloud

Better security starts at the OS

Page 10: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

9 Copyright 2016 FUJITSU

Challenges in protecting credentials

Ben Mary Jake AdminDomain admin

Typical administrator

Cap

ab

ility

Time

Social engineering leads to credential theft.

Most attacks seek out and leverage administrative credentials (Pass the Hash).

Administrative credentials often provide more privilege than necessary.

Page 11: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

10 Copyright 2016 FUJITSU

Typical administrator

Protect against compromised admin credentials

Ben Mary Jake AdminDomain admin

Just Enough and Just in Time administration

Cap

ab

ility

Time

Credential Guard Prevents Pass-the-Hash and Pass-the-Ticket attacks by protecting stored credentials through virtualization-based security.

Remote Credential Guard Works in conjunction with Credential Guard for RDP sessions to deliver Single Sign-On (SSO), eliminating the need to pass credentials to the RDP host.

Just Enough AdministrationLimits administrative privileges to the bare-minimum required set of actions (limited in space).

Just-in-Time AdministrationProvides privileged access through a workflow that is audited and limited in time.

Capability and time needed

Page 12: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

11 Copyright 2016 FUJITSU

Challenges in protecting the OS

New exploits can attack the OS boot-path all the way up through applications.

Known and unknown threats need to be blocked without impacting legitimate workloads.

Page 13: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

12 Copyright 2016 FUJITSU

Help protect the OS and its applicationsOn-premises or in any cloud

Device GuardEnsure that only permitted binaries can be executed from the moment the OS is booted.

Windows Defender Actively protects from known malware without impacting workloads.

Control Flow Guard Protects against unknown vulnerabilitiesby protecting against classes of memory corruption attacks.

Page 14: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

13 Copyright 2016 FUJITSU

Challenges protecting virtual machines

Virtual machines are easy to modify and copy.

Multiple fabric administrators typically have access.

Any compromised or malicious fabric administrators can access guest virtual machines.

Page 15: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

14 Copyright 2016 FUJITSU

Features to help protect virtual machines

Shielded Virtual Machines Use BitLocker to encrypt the disk and state of virtual machines protecting secrets from compromised admins and malware.

Host Guardian Service Attests to host health releasing the keys required to boot or migrate a Shielded VM only to healthy hosts.

Generation 2 VMsSupports virtualized equivalents of hardware security technologies (e.g., TPMs) enabling BitLocker encryption for Shielded Virtual Machines.

Hyper-V

Virtual machine

Computer room

Building perimeter

Physical machine

Hyper-V

Shielded virtual machine

*

`

Page 16: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

15 Copyright 2016 FUJITSU

Shielded Virtual MachinesWorks with Host Guardian Service

Cloud/Datacenter

Hyper-V Host 1

Hypervisor

Guest VMGuest VM Guest VMHost OS

Hyper-V Host 2

Hypervisor

Guest VMGuest VMHost OS

Hyper-V Host 3

Hypervisor

Guest VMGuest VMHost OS

Key Protection

Host Guardian Service

Page 17: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

16 Copyright 2016 FUJITSU

Cloud/Datacenter

Hyper-V Host 1

Hypervisor

Guest VMGuest VM Guest VMHost OS

Hyper-V Host 2

Hypervisor

Guest VMGuest VMHost OS

Hyper-V Host 3

Hypervisor

Guest VMGuest VMHost OS

Key Protection

Host Guardian Service

healthy

Key release criteria TPM-mode)

1. Known physical machines

2. Trusted Hyper-V instance

3. CI-compliant configuration

Shielded Virtual MachinesWorks with Host Guardian Service

Page 18: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

17 Copyright 2016 FUJITSU

Security threats

Transforming the datacenter

Supporting innovation

Datacenterefficiency

Page 19: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

18 Copyright 2016 FUJITSU

Security threats

Datacenterefficiency

Datacenterefficiency

Software-define the datacenter

Supporting innovation

Enterprise-class Virtualization

Software-defined Storage

Software-defined Networking

Page 20: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

19 Copyright 2016 FUJITSU

MANAGEMENTCLOUDDATACENTER

Azure Inspired Compute

Page 21: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

20 Copyright 2016 FUJITSU

Software-defined

Compute

Mission-critical

Industry-leading scale

Linux first-class citizen

DATACENTER

Network

Infrastructure agility

Proven at cloud scale

VXLAN support

Storage

Cloud economics

3x performance at half the cost

Multi-vendor ecosystem

Page 22: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

21 Copyright 2016 FUJITSU

DATACENTER

RAM

per physical server

Page 23: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

22 Copyright 2016 FUJITSU

DATACENTER

Logical Processors

per physical server

Page 24: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

23 Copyright 2016 FUJITSU

DATACENTER

RAM

per VM

Page 25: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

24 Copyright 2016 FUJITSU

MANAGEMENTCLOUDDATACENTER

Virtual Processors

per VM

Page 26: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

25 Copyright 2016 FUJITSU

Software-defined

Compute

Mission-critical

Industry-leading scale

Linux first-class citizen

DATACENTER

Network

Infrastructure agility

Proven at cloud scale

VXLAN support

Storage

Cloud economics

3x performance at half the cost

Multi-vendor ecosystem

Page 27: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

26 Copyright 2016 FUJITSU

MANAGEMENTCLOUDDATACENTER

Azure Inspired SDN

Page 28: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

27 Copyright 2016 FUJITSU

DATACENTER

Azure Inspired

SDN

Azure Data Plane

Network Controller

Software Load Balancer

Distributed Firewall

VMs & Containers

RDMA Optimized

Micro-segmentation

Page 29: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

28 Copyright 2016 FUJITSU

Software-defined

Compute

Mission-critical

Industry-leading scale

Linux first-class citizen

DATACENTER

Network

Infrastructure agility

Proven at cloud scale

VXLAN support

Storage

Cloud economics

3x performance at half the cost

Multi-vendor ecosystem

Page 30: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

29 Copyright 2016 FUJITSU

DATACENTER

Azure Inspired SDS

Page 31: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

30 Copyright 2016 FUJITSU

MANAGEMENTCLOUDDATACENTER

Azure Inspired

SDS

Storage Spaces Direct

Storage Replica

NVMe

Storage QoS

Hyper-Converged Optimized

RDMA Optimized

Page 32: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

31 Copyright 2016 FUJITSU

Converged solutionOn-premises disaggregated solution

Scale components separately

in this model.

Simultaneous scaling is possible

when compute (Hyper-V) and storage

components (Storage Spaces Direct)

reside on the same cluster.

Hyper-convergedScale compute, storage simultaneously

Storage Software

SMB3

Virtual machines on Hyper-V host

Scale-out file server

Storage Software

Virtual Machines

Scale-out file server

Storage Software

Page 33: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Industry-standard servers with internal drives

Page 34: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

No shared storage, no fancy cables – just Ethernet

Page 35: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 36: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Let’s cluster them

Page 37: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 38: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Software-defined “pool” of storage

Page 39: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 40: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

We’re ready to create volumes!

Page 41: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 42: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Hyper-Converged

Page 43: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

42 Copyright 2016 FUJITSU

Demo:Software-defined storage

Page 44: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

© Fujitsu 2016

Storage Spaces Direct (S2D)

Scale-Out

Page 45: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 46: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Add new node to cluster

Page 47: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 48: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 49: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

© Fujitsu 2016

Storage Spaces Direct (S2D)

Fault Tolerance

Page 50: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Server Fault ToleranceUp to 2 simultaneous failures

Copies always land in different servers

Accommodates servicing and maintenance

Data resyncs automatically

Page 51: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Server Fault ToleranceUp to 2 simultaneous failures

Copies always land in different servers

Accommodates servicing and maintenance

Data resyncs automatically

Page 52: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Server Fault ToleranceUp to 2 simultaneous failures

Copies always land in different servers

Accommodates servicing and maintenance

Data resyncs automatically

Page 53: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Server Fault ToleranceUp to 2 simultaneous failures

Copies always land in different servers

Accommodates servicing and maintenance

Data resyncs automatically

Page 54: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Server Fault ToleranceUp to 2 simultaneous failures

Copies always land in different servers

Accommodates servicing and maintenance

Data resyncs automatically

Page 55: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Server Fault ToleranceUp to 2 simultaneous failures

Copies always land in different servers

Accommodates servicing and maintenance

Data resyncs automatically

Page 56: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

Chassis & Rack Fault Tolerance

Page 57: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 58: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 59: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 60: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016
Page 61: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

© Fujitsu 2016

Fault Domain Awareness

Flexible Scenarios

Set up with PowerShell or XML policy

Create flexible, nested topologies

Fault Domains

Clustering now understands

Node, Chassis, Rack, and Site

Failure policies and Spaces Direct data

placement

Page 62: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

© Fujitsu 2016

Hyper-converged Storage Spaces Direct

Page 63: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

62 Copyright 2016 FUJITSU

Nano Server installation option - just enough OS

Nano ServerJust enough OS

Page 64: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

63 Copyright 2016 FUJITSU

Increase reliability with cluster enhancements

Cluster OS Rolling Upgrade Upgrade your fabric to Windows Server 2016, without

downtime to workloads running on Hyper-V virtual

machines.

Mixed OS Mode clusterProvides ability for Windows Server 2012 R2 cluster

nodes to operate with Windows Server 2016 nodes.

VM resiliencyDesigned for cloud-scale environments, this helps

preserve VM session state in the event of transient

storage or network disruptions.

Fault domain-aware clusters Enhances key operations during cluster lifecycle such

as failover behavior, placement policies, heartbeating

between nodes, and quorum behavior.

Page 65: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

64 Copyright 2016 FUJITSU

Complete software-defined storage solution

Storage ReplicaCreate affordable business

continuity and disaster recovery

among datacenters.

Storage Quality of ServicePrevent noisy neighbors from

impacting high priority workloads

with a Storage QoS policy.

Storage Spaces DirectUse standard servers with local

storage to build highly available and

scalable software-defined storage.

Site 1 Site 2

Page 66: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

65 Copyright 2016 FUJITSU

Azure-inspired, software-defined networking

Move faster with Network Controller

VXLAN-based virtual networking

Hybrid SDN gateways for cross-cloud deployment

External and internal software load balancing

Reduce costs

Ability to converge RDMA and Ethernet traffic on the same teamed NICs

QoS for predictable performance

Monitoring and automation to reduce OpEx

Enhance network security

Distributed firewall

Network Security Groups for microsegmentation

Routing and mirroring to specialized virtual appliances

Page 67: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

66 Copyright 2016 FUJITSU

Demo:Nano Server

Page 68: Reinventing IT & Enabling Hybrid Cloud with Windows Server 2016

67 Copyright 2016 FUJITSU