Cloud Training
Cloud Training
Cloud Training
com
➢ Data Center Engineering Lead and Data Center Manager (Thailand): Huawei Technology / 0.5 Years
Joined with Huawei Technologies (Thailand) that coverage 3 Data Center in Thailand. My critical mission are
maintaining 100% uptime for our cloud data center service that coverage and advise each DC provider to work with
zero risk and coordinated with related parties to make sure all work are no risk/impact to our service.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Contents: Section A
A.0 Introduction
A.1 Cloud Computing Concepts
A.2 Virtualization Basics
A.3 Cloud Computing Models
A.4 Fundamental Cloud Architecture
A.5 Components of Cloud Infrastructure
A.6 Cloud Performance Monitoring
A.7 Cloud Security
A.8 Cloud Standards
A.9 Solutions Use Cases
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Introduction to Cloud
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Vmware cloud
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
in 1999, Salesforce became the first company to offer applications over the
internet
On August 25, 2006, Amazon Web Services launched Elastic Compute Cloud (EC2)
2001 - 2022
Cloud Trends
Cloud Trends
Enterprise users need to work on migrating traditional Infrastructure to Cloud and create new business using
Cloud Native platform while maintaining the On-Premise systems.
Cloud Native
Cloud-enabled Infrastructure
Infrastructure
• Micro-service and
Traditional ICT • Some ICT systems run on API architecture
Infrastructure Private Cloud or Public
Cloud • DevOps-based
• Existing ICT runs on on- • Keeping core system runs IT management
premise physical on on-premise physical
servers servers • Remove cost of system
• Local operations IT • Optimizing cost & maintenance and
management for improvement of infrastructure
systems, hardware and operations efficiency for operations
data center hardware and data center
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Trends
Source: Gartner
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Trends
Attractive Growth Opportunities in AI Infrastructure and BIG DATA Market
23.1% 10.6%
AI market will grow Global BIG DATA will grow
from $14.6 billion to from $138.9 billion to
$50.6 billion by 2025 $229.4 billion by 2025
Source: marketsandmarkets.com
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Trends
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Users/PCs
Users/PCs
App App App App App App App App App App App App App App App App App App
User Profile User Profile User Profile User Profile User Profile User Profile
OS OS OS OS
(Windows/Linux) (Windows/Linux) (Windows/Linux) (Windows/Linux)
User User
User Profile User Profile
App App App App App App App App App Profile Profile
OS OS OS
User Profile User Profile User Profile (Windows) Linux Appliance
OS Hypervisor
(Windows/Linux) (ESXi, Hyper-V, OpenStack etc.)
Hypervisor
(ESXi, Hyper-V, OpenStack etc.)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
VM Servers
App App App App App App App
User User
User Profile User Profile
Profile Profile
VM OS VM OS VM OS
(Windows) Linux Appliance
Hypervisor
(ESXi, Hyper-V, OpenStack etc.)
Physical Server
NW Switch
Server Room
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
AWS
MS AZURE
Google Cloud
NTT
Alibaba
Huawei
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
NW Switch
VM Servers
Users/PCs
Data center, Network, Servers, Storage, Application Software etc.
As Resource Pools (except Security)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
5. Security: With Cloud Technology the real data cannot access directly
Virtualization Basics
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Virtualization
85%
20% 60%
5%
Firewall
Users/PCs
Characteristics of Cloud
1. On-Demand
Users can access computing services via the cloud when they need to without interaction from the service
provider. The computing services should be fully on-demand so that users have control and agility to meet
their evolving needs.
2. Network access
Cloud computing services are widely available via the network through users’ preferred (Private
Link/MPLS, Internet with Public IP, Site-to-Site VPN etc.)
3. Resource Pool
The most attractive elements of cloud computing is the pooling of resources to deliver computing services
at scale. Resources, such as storage, memory, processing, and network bandwidth, are pooled and
assigned to multiple consumers based on demand
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Characteristics of Cloud
4. Rapid elasticity
Successful resource allocation requires elasticity. Resources must be assigned accurately and quickly with
the ability to absorb significant increases and decreases in demand without service interruption or quality
degradation.
5. Measured service
Cloud Computing resources used to monitor and the company uses it for recording. This resource
utilization is analyzed by supporting charge-per-use capabilities.
6. Easy Maintenance
The servers are easily maintained and the downtime is very low and even in some cases, there is no
downtime. Cloud Computing comes up with an update every time by gradually making it better.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Service Model
IaaS
PaaS
Platforms as a service remove the need for organizations to manage
the underlying infrastructure (usually hardware and operating
systems) and allow you to focus on the deployment and
management of your applications.
Serverless/Hostless
WebHosting Platform/
MangoDB as a Service Azure SQL cPanel/WordPress
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
SaaS
Software as a Service provides you with a completed product that is run and
managed by the service provider. In most cases, people referring to Software as
a Service are referring to end-user applications. With a SaaS offering you do not
have to think about how the service is maintained or how the underlying
infrastructure is managed;
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Deployment Model
Private Cloud
Dedicated HW for only Organization
VM Servers
Public Cloud
Virtualization Environment
Advantages of the public cloud model:
•Minimal Investment: Because it is a pay-per-use
Customer Customer Customer Customer service, there is no substantial upfront fee, making it
A B C XX excellent for enterprises that require immediate access
to resources.
•No setup cost: The entire infrastructure is fully
subsidized by the cloud service providers, thus there is
no need to set up any hardware.
•Infrastructure Management is not required: Using
the public cloud does not necessitate infrastructure
management.
•No maintenance: The maintenance work is done by
the service provider (Not users).
•Dynamic Scalability: To fulfill your company’s needs,
on-demand resources are accessible.
Physical Servers/Storage
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Hybrid Cloud
Multi Cloud
The back end is used by the service provider. It manages all the resources
that are required to provide cloud computing services. It includes a huge
amount of data storage, security mechanism, virtual machines, deploying
models, servers, traffic control mechanisms, etc
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Type 1: User Manage all Cloud resources, Create VM, Network and Security configurations
Example: Service provider model that provide IaaS to Customer, Customer’s IT Team will access to Cloud Portal
Hybrid Cloud
Remark: User has required Technical skill to manage Cloud Portal such as, Vmware vCenter, vCD, Azure Portal, ASW Portals
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
VMWare vCenter
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
ESXi
vCenter
Connect all ESXi to managed in single portal
as cluster(s)
Hypervisor
(ESXi, Hyper-V, OpenStack etc.)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Hybrid Cloud
(System Admins)
Remark: User has not required Cloud skill to manage Cloud Portal, Just access to OS
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
ERP Apps
Client / Users
(end users)
Applications DB
Hybrid Cloud
Cloud Management Portal
• Data center
• Servers / Storage
• Hypervisor
• Cloud Management Servers
• Network and Security Management
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Network
Security
Network Internet MPLS Firewall DDOS VPN Load
Security L2 / L3 IPS/IDS IPSEC/SSL Balance WAF Anti-virus
Cloud Foundation
Performance / Capacity / Configuration GW / FW / LB / VPN VM / File level / Item level SAS / NL-SAS
Service (SDDC)
vCloud Director + VMware vSphere + Virtual SAN
Multi-Tenancy / Operational / Catalog management / Virtualized compute / Storage Policy
Colo./
Datacenter DC DR
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Physical components
Virtualization | Hypervisor
Network Switches
Servers
Storage
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Traditional Storage
Virtual Storage
(e.g. Vmware vSAN)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Internet
MPLS
Firewall
VM on Cloud
CloudHealth by VMware
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Security
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud security
Cloud security is the whole bundle of technology, protocols, and best practices that
protect cloud computing environments, applications running in the cloud, and data
held in the cloud.
The full scope of cloud security (infra.) is designed to protect the following
• Physical networks — routers, electrical power, cabling, climate controls, etc.
• Data storage — hard drives, etc.
• Data servers — core network computing hardware and software
• Computer virtualization frameworks — virtual machine software, host machines, and guest machines
• Operating systems (OS) — software that houses
• Middleware — application programming interface (API) management,
• Runtime environments — execution and upkeep of a running program
• Data — all the information stored, modified, and accessed
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Internet
VPN
MPLS
VM on Cloud
Cloud Gateway
SSL VPN Accessible IPs
IPSec
SSL VPN
VM on Cloud
SSL VPN VM on Cloud
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Standards
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Standard
CSA STAR
Cloud Standard
ISO/IEC 22301
ISO/IEC 22301 is an international standard for security and resiliency. It
outlines frameworks for establishing business continuity management systems.
Having business continuity management systems in place is vital in offering
highly available infrastructure to customers.
SOC 2
The System Organization Controls (SOC) 2 report is an independent third party audit
report on the control procedures within a data center. It analyzes and concludes on the
understanding of the control and risk assessment associated from an external point of
view.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Standard
ISO/IEC 20000-1
This document specifies requirements for an organization to
establish, implement, maintain and continually improve a service
management system (SMS)
The Information Technology Infrastructure Library (ITIL®) framework is the most widely
accepted framework for IT Service Management in the world . ITIL helps all
organizations, regardless of their industry or business sector, provide their IT services
using the most efficient and economical methods. The framework focuses on IT
Service Management best practices and efficient operations, and is used in
government, commercial, and non-profit organizations, alike.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cons
• Investment required
• Still must maintain HW MA for new
Servers
• Still require skill for Server, NW, Storage
plus Cloud Admin (Hypervisor)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Data Migration
Pros
• No require skill to manage Physical Things
Physical
Servers Cons
• Architect redesign required
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
DR on Cloud
DC DR onPublic Cloud
Backup data
Internet
Private Colocation
Cloud
On-premise
• BYOL
Cloud • VM level
Provider
NFS / FTP
• File level
• Backup disk space
Cloud Disk
Backup server
• NFS
• FTP
• Own Operations
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
SaaS on Cloud
IoT Hub
Hadoop
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Increasing security and A network that is unable to Deriving increased value from
compliance risks adequately support hybrid cloud data
The pace of change of public cloud Providing fast and secure network Business leadership demand instant
features, distributed working needs, and connectivity can make or break a cloud access to insights and analytics to
regulatory compliance requirements are migration project. make informed decisions
increasing complexity exponentially.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
A breadth of service Deep cloud expertise A platform approach to A more efficient total cost Agile contracting service
provider capabilities to throughout the different enable discovery, of IT operations and high- provider capabilities that
plan, design, migrate, stages of transformation. configuration, integration, performance environment. offers flexibility.
manage and optimize. and management of
services.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Run
Build
Operate
Design
Cloud Enablement Operation of
your IT landscape
Understand Identify Cloud Transformation
Plan, Cloud Architecture
Strategy. Current and Discovery, analysis and
target states. Business define High-level service
target and challenges. and solution design.
31% 43%
Average Infrastructure Fewer security
Cost savings incidents per year
62% 3X
IT staff More features
Productivity boots Delivered per year
Design – Assessment
Current IT views Discover & Organize data Strategies for each workload
• Refactor
Applications • Re-platform
Asset inventory System configurations
• Repurchase
Infrastructure
• Rehost
Performance info. SLA/OLA
• Relocate
Performance • Retain
• Retire
Architecture
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
Resource Sizing for P2V (Physical to Virtual)
vCPU = ?
vRAM = ?
vDISK = ?
HPE ProLiant DL360 Gen9 E5-2640v4 1P 16GB-R P440ar 8SFF 500W PS Base Server
1 * Intel® Xeon® E5-2640v4 (2.4GHz/10-core/25MB/90W)
16GB (1x16GB Registered DIMMs, 2400 MHz)
HPE Embedded 1Gb Ethernet 4-port 331i Adapter
HPE Flexible Smart Array P440ar/2GB (RAID 0,1,10, 5, 50, 6, 60)
HPE 500W Flex Slot Platinum Power Supply
iLO Management (standard), Intelligent Provisioning (standard)
Rack (1U), HP Easy Install Rails
4x HP 300GB 12G SAS 10K 2.5in SC ENT HDD (Configure RAID5)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
10 vCPUs
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
So now if you look at the utilization we get the Total Disk available on the server =
following specs 500 GB
Used in GB's = 235 GB
Remark #2
"Never Size on Average Utilization" - "Always Size on Peak Utilization“
or add buffer for peak utilization
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
So now if you look at the utilization we get the CPU = 480 MHz + 25% = 600 MHz
following specs
Memory = 656 MB + 25% = 820 MB
CPU = 600 MHz = 1 vCPU
CPU = 480 MHz Memory = 820 MB = 9 GB
Disk = 235 GB + 25% = 294 GB
Memory = 656 MB Disk = 294 GB
Disk = 235 GB (Actual Used)
There are 2 reasons why we added this 25%: or for play safe add 35%
i) The peak utilization data is a single peak point collected, however there could be multiple peak
points across business cycles which we needs to address, hence a buffer is always good.
ii) Its good to have some head room for situations where the memory utilization shoots up due to a
misbehaved service, process, application etc.
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Customer provided the quotation of Server that they use to buy as follows:
HPE ProLiant DL360 Gen9 E5-2640v4 1P 16GB-R P440ar 8SFF 500W PS Base Server
1 * Intel® Xeon® E5-2640v4 (2.4GHz/10-core/25MB/90W)
16GB (1x16GB Registered DIMMs, 2400 MHz)
HPE Embedded 1Gb Ethernet 4-port 331i Adapter
HPE Flexible Smart Array P440ar/2GB (RAID 0,1,10, 5, 50, 6, 60)
HPE 500W Flex Slot Platinum Power Supply
iLO Management (standard), Intelligent Provisioning (standard)
Rack (1U), HP Easy Install Rails
4x HP 300GB 12G SAS 10K 2.5in SC ENT HDD (Configure RAID5)
⚫ Peak Capacity
Existing Capacity
• CPU: 24 GHz * 87% = 20.9 GHZ
• CPU: 2.4 GHz x 10 = 24 GHz • RAM: 1.9 GB
• DISK: 290/900 GB
• RAM: 16 GB
• DISK: 300GB*4 (RAID 5) =
900 GB
⚫ Propose Cloud Spec
• vCPU: 21 vCPUs
• RAM: 2 GB
• DISK: 290 GB or More
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
Resource Sizing for V2V (Virtual to Virtual)
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
Specific System Conditions - Oracle
•DBSE2
• Server 2 Socket = 2 License Database
• DBEE
• Core x Socket x PCF = License Database
• 8 x 2 x 0.5 = 8 License Database
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Network
Design – Assessment
Specific System Conditions - SAP
Extend to 2030
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
SAP ECC 6.0
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
SAP S4
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
Specific System Conditions - SAP
SAP on Traditional
DB will EOS by ECC6.0 will EOS by
Traditional DB 2025 2030 2025
HANA HANA
MS SQL / Oracle
HW Appliance
HP, IBM, DELL etc.
Design – Assessment
Specific System Conditions - SAP
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Design – Assessment
Specific System Conditions - MS SQL
Licensing
E.g. License for 8 sockets or 24 cores
Design – Assessment
Software version compatibility
Build - Enablement
• Web Servers
• App Servers
• DB Servers
• Mail servers
• Etc.
Build
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Connectivity
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Internet access
S4-Prd
Cloud
Storage
SAP
Veeam
Internet Gateway
VBR
Content
Server PRD
Private Link
MPLS
S4-Prd Primary S4-Prd Secondary
Provider A
S4-Prd Active S4-Prd StandbyS4-Prd App1 S4-Prd App2
S4-Qas S4-Dev
MPLS
Provider B S4-Qas S4-Dev Solman
DMZ: Zone
S4-Prd
Cloud
Storage
SAP
Veeam
Internet Gateway
VBR
Content
Server PRD
MPLS
S4-Prd Primary S4-Prd Secondary
Provider A
S4-Prd Active S4-Prd StandbyS4-Prd App1 S4-Prd App2
S4-Qas S4-Dev
VPN Internet VPN
S4-Qas S4-Dev Solman
DMZ: Zone
Other Azure
Internet
Azure ExpressRoute Service
Users
AWS
Migrating
• Web Servers
• App Servers
• DB Servers
• Mail servers
• Etc.
Move
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
• Live Migration
Hybrid Cloud
VPN
Private Cloud
/ On-Prem Public Cloud
ERP Server
Mail Server
Web Server
Extender
Appliance
Extender
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
https://www.expedient.com/knowledgebase/tools-and-calculators/file-transfer-time-calculator/ https://www.omnicalculator.com/other/data-transfer
Fallback plan
Work Plan for change Cloud IP
Target Actual
No Activities Responsible Name Date Status Note
Time (Hrs) Start Finish Time (Hrs) Start Finish
Preparation Steps Porar to change DNS forward on Thu 19 Jan 2012 5:30pm
Coordinate
Preparation Steps
1 Amnat 19-Jan-22 0:15 9:00 9:15 0:15 9:00 9:15 Done
- webmail.siphhospital.com
2 Coordinate NOC to change DNS reverse on Thu 19 Jan 2012 5:30pm
Amnat 19-Jan-22 0:15 9:15 9:30 0:15 9:15 9:30 Done
- webmail.siphhospital.com
3 Backup ASA firewall configuration Sasi 19-Jan-22 0:30 17:00 17:30 0:05 17:00 17:05 Done
Deployment Step
1 Anouncement all users for network down by ? Wanpen2 19-Jan-22 0:05 8:00 8:05 0:05 8:00 8:05 Done
Change ip WAN interface on both ASA
2 Sasi2 19-Jan-22 0:10 17:30 17:40 0:05 17:05 17:10 Done
- Change 118.174.142.218 ==>1.179.129.12
3 Test WAN connection - ping & trace route with result
Sasi2 19-Jan-22 0:10 17:40 17:50 0:03 17:10 17:13 Done
(Check Point 1)
4
5
6
Change
-Change
firewall
Test firewall
DNS bymail
rulerule and NAT (refer NAT, Firewall rule)
Metha (SiPH),configuration
outgoing
backup by Supachai
on both(IT1)
Ironport (send mail directly, not
Sasi2
Metha2, Amnat2
Amnat2
19-Jan-22
19-Jan-22
19-Jan-22
0:30
1:00
0:15
17:50
18:20
19:20
18:20
19:20
19:35
0:02
0:35
0:10
17:13
17:15
17:50
17:15
17:50
18:00
Done
Done
Done
Deployment Steps
forward to TOT) mail
Test send/receive
7 Amnat2 19-Jan-22 1:00 19:35 20:35 0:30 18:00 18:30 Done (With issue) Can not send mail from siphhospital.net to siphhospital.com: Asked Porar to fix this issue
- Hot mail
Backout plan
(Check
ChangePoint 1) interface on both ASA
ip WAN
1 - Change 1.179.129.12 ==>118.174.142.218 19-Jan-22 0:10 17:50 18:00 0:10 17:13 17:23
2 Test WAN connection - ping & trace route with result 19-Jan-22 0:10 18:00 18:10 0:10 17:23 17:33
3 Coordinate Porar to change DNS forward Amnat 19-Jan-22 0:10 18:10 18:20 0:10 17:33 17:43
4 Coordinate NOC to change DNS reverse Amnat 19-Jan-22 0:10 18:20 18:30 0:10 17:43 17:53
(Check
ChangePoint 2) interface on both ASA
ip WAN 19-Jan-22
1 - Change 1.179.129.12 ==>118.174.142.218 19-Jan-22 0:10 19:20 19:30 0:10 17:50 18:00
2 Test WAN connection - ping & trace route with result 19-Jan-22 0:10 19:30 19:40 0:10 18:00 18:10
3 Restore firewall
Test firewall rulerule and NAT from backup 19-Jan-22 0:10 19:40 19:50 0:10 18:10 18:20
4 Metha, Amnat 1:00 19:50 20:50 1:00 18:20 19:20
Backout plan
- DNS by Metha (SiPH), backup by Supachai (IT1) 19-Jan-22
5 Coordinate Porar to change DNS forward Amnat 19-Jan-22 0:10 20:50 21:00 0:10 19:20 19:30
6 Coordinate NOC to change DNS reverse Amnat 19-Jan-22 0:10 21:00 21:10 0:10 19:30 19:40
(Check
ChangePoint 3) interface on both ASA
ip WAN 19-Jan-22
1 - Change 1.179.129.12 ==>118.174.142.218 19-Jan-22 0:10 20:35 20:45 0:10 18:30 18:40
2 Test WAN connection - ping & trace route with result 19-Jan-22 0:10 20:45 20:55 0:10 18:40 18:50
3 Restore firewall
Test firewall rulerule and NAT from backup 19-Jan-22 0:10 20:55 21:05 0:10 18:50 19:00
4 - DNS by Metha (SiPH), backup by Supachai (IT1) Metha, Amnat 19-Jan-22 1:00 21:05 22:05 1:00 19:00 20:00
5 Change mail outgoing
Test send/receive mailconfiguration on both Ironport (send mail by forward to TOT) Amnat 19-Jan-22 0:15 22:05 22:20 0:15 20:00 20:15
6 - Hot mail Amnat 19-Jan-22 1:00 22:20 23:20 1:00 20:15 21:15
7 Coordinate Porar to change DNS forward Amnat 19-Jan-22 0:10 23:20 23:30 0:10 21:15 21:25
8 Coordinate NOC to change DNS reverse Amnat 19-Jan-22 0:10 23:30 23:40 0:10 21:25 21:35
19-Jan-22
Fallback plan
(Check
ChangePoint
ip WAN1) interface on both ASA
1 - Change 1.179.129.12 ==>118.174.142.218 NA NA NA NA NA NA NA
2 Test WAN connection - ping & trace route with result NA NA NA NA NA NA NA
(Check
ChangePoint
ip WAN2) interface on both ASA
1 - Change 1.179.129.12 ==>118.174.142.218 NA NA NA NA NA NA NA
2 Test WAN connection - ping & trace route with result NA NA NA NA NA NA NA
3 Restore firewall
Test firewall rulerule and NAT from backup NA NA NA NA NA NA NA
4 - DNS by Metha (SiPH), backup by Supachai (IT1) NA NA NA NA NA NA NA
5 Coordinate Porar to change DNS forward NA NA NA NA NA NA NA
1
6 Coordinate NOC to change DNS reverse
(Check
ChangePoint 3) interface on both ASA
ip WAN
- Change 1.179.129.12 ==>118.174.142.218
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
Fallback plan
2 Test WAN connection - ping & trace route with result NA NA NA NA NA NA NA
3 Restore firewall
Test firewall rulerule and NAT from backup NA NA NA NA NA NA NA
4 - DNS by Metha (SiPH), backup by Supachai (IT1) NA NA NA NA NA NA NA
5 NA NA NA NA NA NA NA
Change mail outgoing
Test send/receive mailconfiguration on both Ironport (send mail by forward to TOT)
6 - Hot mail NA NA NA NA NA NA NA
7 Coordinate Porar to change DNS forward NA NA NA NA NA NA NA
8 Coordinate NOC to change DNS reverse NA NA NA NA NA NA NA
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Run - Operations
Performance Monitoring and alert
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
4TB
3.8TB 1TB
0.8TB 0.2TB
0.8TB
3TB 3TB 3TB
Snapshot VS Backup
Day 1 Day 2
Snapshort Snapshort
Recovering
Day 1 Day 2
Backup Backup
Recovering
Backup
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Run - Optimization
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
CAPEX
OPEX
• High investment with facility, hardware • Reduce upfront investment • Easy adoption of new technologies
and software • Ready to use • Flexible and scalable support for business
• Takes months or years for growth
implementation
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Facility Management
Network Management
Application Vendor
SLA?
internet
internet
internet
internet
Operation cost
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Facility Management
Network Management
System Management
Application Vendor
Cloud Connect
Simple
internet SLA
Security
Cloud Provider
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Cloud Governance
a set of rules and policies adopted by companies that run services in the cloud. The
goal of cloud governance is to enhance data security, manage risk, and enable the
smooth operation of cloud systems.
Monitoring
Cost Optimization
Security & Compliance
Governance
Recommendations/
Auditing
Improvement
Operations review
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Risk Management
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]
Backup SLA
Test restore on Full backup on Sunday, and it took 5 hr.
Then committed user for RPO 24hr and RTO hr.
On-Prem
Norman Abungan / Engineer / ZTE Philippines Inc / (+63) 9454877114 / [email protected]