Citrix NetScaler as part of a TMG replacement alex.dingemanse@citrix.com 06 – 3877 2139 TMG cannot be replaced by a single product • Cisco ᵒ ᵒ ᵒ ᵒ ᵒ Forward Proxy URL filtering IPS Malware scanning Firewall © 2015 Citrix • Citrix NetScaler ᵒ ᵒ ᵒ ᵒ ᵒ Reverse Proxy Loadbalancing SSL Offloading Web traffic compression Web traffic caching Mobile Workspace Infrastructure & Services Data Apps 1010SSL101SSL App Store Collaboration & Support Data Sync & Sharing Windows & Mobile Apps Collaboration Desktops Windows Desktops Personal © 2015 Citrix Networking & Cloud Infrastructure Work Anywhere Services Anywhere 1010SSL101SSL Create | Collaborate | Share © 2015 Citrix Build | Deliver | Scale Citrix NetScaler Overview Making Applications Run 5x Better • World-class load balancing • Health monitoring © 2015 Citrix • Caching • Compression • Optimization • TCP Connection Management • SSL processing • SSL VPN • Application firewall Web front-ends WEB and HDX Insight NetScaler Insight Center Application Database Citrix Products Oracle ? CloudBridge Connector Citrix Products NetScaler HA Pair Microsoft Products NetScaler Cluster Other Products External User Authentication Internal User Authentication + 2FA (SAML) (LDAP / RADIUS / SAML) © 2015 Citrix Microsoft Products Other Products NetScaler Traffic Domain Oracle MySQL MS SQL Product Lines: MPX & VPX & SDX MPX: Price-Performance VPX: Run Anywhere Hurksestraat 29-51, Eindhoven SDX: Multi-Service Multi-Tenant • Hardware • Virtual appliance • • Web app delivery • • High power SSL Runs on XenServer, Hyper-v and ESX Separate NetScaler Instances • • Powers the web Fast, inexpensive and flexible Direct and dedicated hardware access • Network Isolation • Up to 80 instances © 2015 Citrix • TriScale Scale up with Pay-As-You-Grow Scale in with ADC Consolidation © 2015 Citrix Scale out with TriScale Clustering PayGrow NetScaler Performance 120 Gbps 120 Gbps All platforms can be license upgraded across their supported ranges. MPX/SDX 22040 – 22120 50 Gbps MPX/SDX 11515-11542 25 Gbps 40 – 150Gbps 120k – 560k SSL TPS 80 instances 15 – 42Gbps 22.5k – 69.5k SSL TPS 20 Instances MPX/SDX 8005-8015 10 Gbps 5 – 15Gbps 6.5k – 11k SSL TPS 5 instances 5 Gbps VPX MPX 5550-5650 500Mbps – 5Gbps 10Mbps – 3Gbps 1 © 2015 Citrix 5 40 20 Maximum Tenants per Platform 80 NetScaler Offerings Packaged for broad adoption for all users Comprehensive L4-7 load balancing and optimizes expensive server and network resources to reduce cost © 2015 Citrix Web application delivery solution providing advanced traffic management and powerful application acceleration Web application delivery solution designed to deliver mission-critical applications with web application firewall security, fastest performance, and lowest cost Virtualization and Multi-Tenancy • NetScaler VPX is a fully featured NetScaler running on general purpose hypervisor environments • NetScaler SDX creates instances on a purpose build networking virtualization platform allowing for: ᵒ Independent, fully featured NetScalers ᵒ Dedicated or shared resources, allowing for network isolation ᵒ Independent versions, management, IP addresses, etc. • NetScaler supports Traffic Domains on top of VPX, MPX and SDX ᵒ Create segmentation within a single NetScaler, sharing the general platform, manageability and ᵒ Isolation of traffic, allows for overlapping IP address schemes ᵒ Limited feature support © 2015 Citrix Availability for NetScaler • HA Pair ᵒ Active Passive configuration, simple setup, guaranteed performance on node failure ᵒ HA pair on 1 site, or stretched over 2 sites (layer 2 required) • Clustering ᵒ Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active, Active (32 x) nodes in 1 cluster. ᵒ Cluster nodes must be on same site, selected features available ᵒ Scale Out model, add nodes for availability and performance! • Global Server Load Balancing ᵒ Active active. Supports stand alone sites or within DC ᵒ Prevents against logical device, link or datacentre failure © 2015 Citrix Web front-ends WEB and HDX Insight NetScaler Insight Center Application Database Citrix Products Oracle ? CloudBridge Connector Citrix Products NetScaler HA Pair Microsoft Products NetScaler Cluster Other Products External User Authentication Internal User Authentication + 2FA (SAML) (LDAP / RADIUS / SAML) © 2015 Citrix Microsoft Products Other Products NetScaler Traffic Domain Oracle MySQL MS SQL Call to action • Download TMG whitepaper ᵒ https://www.citrix.com/content/dam/citrix/en_us/documents/productssolutions/netscaler-a-comprehensive-replacement-for-microsoft-forefront-threatmanagement-gateway.pdf • Subscribe to the NetScaler newsletter ᵒ http://deliver.citrix.com/networking-newsletter.html • Join monthly online NetScaler Masterclass ᵒ http://www.citrix.com/events/netscaler-master-class.html • Read Citrix blogs ᵒ http://blogs.citrix.com/ © 2015 Citrix Questions © 2015 Citrix