SlideShare une entreprise Scribd logo
1  sur  23
©2017 Zscaler, Inc. All rights reserved. | ZSCALER CONFIDENTIAL INFORMATION0
Pitfalls to Avoid When
Deploying Office 365
Dhawal Sharma – Director, Product Management
WEBCASTS
©2017 Zscaler, Inc. All rights reserved.1
To ask a question
• Type your questions into the chat box in the Webex
panel or email us at communications@zscaler.com
• We’ll try to get to all questions during the Q&A
session. If we do not get to your question, we’ll make
sure to follow up afterwards
• At the end of the webcast – please let us know how
we did!
©2017 Zscaler, Inc. All rights reserved.
Ask your question here…
©2017 Zscaler, Inc. All rights reserved. | ZSCALER CONFIDENTIAL INFORMATION2
Zscaler: The Market Leader in Cloud Security
Enterprise Customers
2,800 CUSTOMERS
Over 200 of the Fortune Global 2000
Global Partners
100
Data centers
35B
Daily requests
185
Countries served
Cloud Scale
The Pioneer in Cloud Security
Mature Global Cloud Operations
700+
Office 365 customers
2.8 PB
Office 365 traffic processed per
month and growing
131 TB
Office 365 traffic processed per
month for one customer
70% of Fortune 500 companies have purchased Office 365
Office 365 traffic growth and scalability
1.3 billion Office 365 requests daily
Elastic scale:
Mailbox migration
from a large customer
27 X Growth over 3 years!!
The Challenges of Deploying Office 365
A deployment survey of over 200 customers
had problems accessing
business-critical applications
including Office 365.
45%
69%Weekly issues
reported
Many continued to experience
bandwidth issues, impacting
business operations and
productivity
Many were plagued by
network latency issues on
a daily and weekly basis
30%Daily issues
reported
70%Weekly issues
reported
33%Daily issues
reported
Despite appliance upgrades After Deployment
Microsoft’s Guidance for Office 365 is Direct Internet
TechNet Blog: bit.ly/ZscalerO365
1. Local Network Egress as close to user as possible
2. Unhindered access to Microsoft
3. Local DNS resolution
4. Optimized connectivity to Microsoft’s global network
Legacy Hub and Spoke is the WRONG approach
• Cloud apps like Skype and Sharepoint are
designed for low latency direct access
• Hub and Spoke networks and VPN
requirements add unnecessary latency
• The user experience for Office 365 is
compromised
• MPLS backhauling adds extra cost to
deployment
DC Apps
HQ/IOT San FranciscoNew York
Paris London
Local Network Egress
Microsoft recommends against using a Hub and
Spoke network with Office 365
Hub and Spoke Network
Cloud apps need low latency connections
Outlook connections
per user
• Office 365 creates a excessive long-lived
connections that exhaust firewalls
Between 12-20 connections per user!
• Around 4,000 clients can be supported by a
single public IP safely
• Office 365 use will require more than Web
browsing (ports 80 / 443) – uses ephemeral
ports
THE IMPACT ON USER EXPERIENCE?
Local Network Egress
Legacy Hub and Spoke is the WRONG approach
Increased connect load on Firewalls and Proxies
Random hangs and connection issues
(Outlook in a disconnected state)
• Not recommended and requires
Microsoft review and approval
• Express route is very complex to configure
correctly.
• Must perform NGFW capacity assessment
– long lived, high throughput connection
• Office 365 traffic growth will outpace
gateway upgrades and budgets
“Microsoft has a review policy… ensure that all
parties are aware of the 2-6 months of planning,
extra complexity…”
ExpressRoute for Office not Recommended
Adds Complexity and extra planning
Local Network Egress
DC Apps
HQ/IOT San FranciscoNew York
Paris London
Hub and Spoke with ExpressRoute
Direct Internet connection with appliances
• Requires constant firewall updates – missing
an IP/URL update will cause connectivity issues
• Requires appliance capacity assessments to
handle high number of long-lived connections
• Sacrifices security in branches with only UTMs
or firewalls Ensure local DNS
• Impact of Office 365 still overwhelms
appliances, despite capacity upgrades
Appliance Sprawl
Unhindered Access
DC Apps
HQ/IOT San FranciscoNew York
Paris London
Complex, costly, and still under capacity
©2017 Zscaler, Inc. All rights reserved. | ZSCALER CONFIDENTIAL INFORMATION11
Direct Internet
For Office 365 and Open Internet
Zscaler for Office 365 and Direct Internet
HQMOBILE
BRANCHIOT
Data Loss Prevention
Cloud Apps (CASB)
File Type Controls
Data Protection
Cloud Firewall
URL Filtering
Bandwidth Control
DNS Filtering
Access Control
Adv. Protection
Cloud Sandbox
Anti-Virus
DNS Security
Threat Prevention
Zscaler for your Office 365 Traffic
SaaS Open
Internet
Fast, Secure access to the Office 365 and the Internet
Local Network Egress
Unhindered Access
• Direct Internet for a fast user
experience
• Best connection method per
Microsoft’s guidance
• Easily deployed – no hardware
needed
• One Click configuration
simplifies administration
A full security stack to secure your
Direct Internet connection
Zscaler for your Internet traffic
Minimize Office 365 latency with Local DNS
Zscaler Local DNS Architecture
San Jose User > San Jose DNS > San Jose O365
Shortest path, fewer hops = faster user experience
Latency: 12ms
Common Centralized DNS Architecture
San Jose user > LA > Denver > Austin > Atlanta O365
Lots of hops increases: slower user experience
Latency: 158ms (22ms+36ms+48ms+52ms)
Los Angeles
RTT=22 ms
Austin
RTT=48 ms
Atlanta
RTT=52 ms
Denver
RTT=36 ms
San Jose
RTT=12 ms
Local DNS
Centralized
DNS
O365
Connection
O365
Connection
Local DNS
Guarantee a fast, local connection regardless of location
Los Angeles Dallas
Denver
Toronto
New York
Washington DC
Atlanta
Miami
Paris
Sao Paulo
Johannesburg
London
Amsterdam
Oslo
Brussels Frankfurt
Gdansk
Stockholm
Moscow
Mumbai
Singapore
Sydney
Hong Kong
Tokyo
Madrid
TaipeiDubai
Riyadh
Cairo
Kuwait City
Kuala Lumpur
Cape Town
San Francisco Chicago
Lagos
Tel Aviv
Milan
Copenhagen
Melbourne
Zurich
Chennai
Tianjin
Manila
Doha
Abu Dhabi
Jeddah
Al Khobar
Warsaw
40B+
Requests / day
100M+
Threats blocked /
day
120K+
Unique security
updates / day
Zscaler peers with Office 365 in major DCs
100 DATA CENTERS – 5 CONTINENTS
Secure
On-going third
party testing
CertifiedReliable
Redundancy within and
failover across DCs
Transparent
Trust Portal for service
availability monitoring
O365 Peering Data Center
Seattle
Local DNS
Optimized Connectivity
Easily maintains updates without day to day
Office 365 administration
Traditional approach requires constant
firewall updates to maintain connectivity
HQ BRANCH
Local Network Egress
Unhindered Access
BRANCH
Zscaler One Click Configuration Optimized Connectivity
Simplify day to day Office 365 administration
Updates Office 365 connection details
multiple times a week
Automatically configures white list
Exempts Office 365 traffic from
authentication and SSL decryption
Fingerprints all Office 365 applications
No more keeping up with URL and IP changes
in the Office 365 applications.
.XML update list
One Click Configuration Easily define approved tenants
Optimized Zscaler TCP Scaling for faster file downloads
3MB file download from a SharePoint public site hosted at Iowa instance
Without Zscaler With Zscaler
Slower scaling,
does not scale beyond 3MB
Scaling starts after 50% of
transaction has completed
Starts at default
256 Byte value
Pre-negotiated
64KB connection
Scales faster, window scale > 4MB
Optimized Connectivity
Zscaler and Direct Internet for Best Office 365 Experience
Fully compliant with Microsoft’s recommendation
Local Network Egress Unhindered Access
Delivers fast Direct-to-
Internet for Office 365
traffic
Delivers best User
Experience
Peering in most major
exchanges with 1-2 ms
round trip time
Always a local user
connection
One-Click configuration
simplifies and optimizes
connectivity updates
Window scaling for
faster file downloads
Cloud platform easily
accommodates long-
lived connections
Easily scales as Office
365 user demands grow
Local DNS
Optimized
Connectivity
Fully Embrace Direct Internet with Zscaler Cloud Firewall
Office 365
Port: 443
Protocol: HTTPS
User: Jen
APP: Outlook Online
Location: All
APP: Outlook Online
Port: 3478, 3479, 3480, 3481
Protocol: UDP
User: Chris
APP: Skype for Business Online
Location: All
APP: Skype for Business Online
Port: Any
Protocol: UDP
User: Steve
Location: All
APP: BitTorrent
Internet
Branch User
Checking Email
HQ User
Sharing Desktop
Mobile User
Downloading Movies
APP: BitTorrent
Easily scale NGFW visibility and control across all
locations without the appliance cost and complexity
Application visibility and control
• Adv. DPI engine - stateful packet inspection
• ID Apps regardless of port, protocol, or evasion
• Intrusion Prevention w/ protocol anomaly and
signature-based detection.
User identity awareness
ID Users & Groups regardless of IP address
Unified Policy and Visibility
Single console for policy management
and real-time log visibility
Zscaler
Cloud
Firewall
Direct Internet Traffic
Unlimited SSL inspection capacity
• Inspect ALL your Internet traffic
• One-Click config excludes O365 traffic
Zscaler Bandwidth Control
Prioritize Office 365 traffic as Business Critical
Always guarantee
Office 365
40% of bandwidth
Cap YouTube
traffic at 20%
• Policies are defined in a single console
and immediately enforced globally
• Policies are enforced in the cloud,
before the last mile bottleneck
• Window shaping and bandwidth
throttling deliver a smooth user
experience
How Zscaler Bandwidth Control Works
Low Office 365
traffic in NY
despite one of the
largest offices
– user issues?
Easily identify
the top
Office 365 users
OneDrive
traffic is low –
is Box still
being used?
Real-time
traffic volume
trending
Get Unprecedented Office 365 Visibility with Zscaler
How well is Office 365 being adopted by your users?
• Causing WAN congestion
• Sessions were overwhelming firewalls
• Deploying UTMs or NGFWs was prohibitively
expensive and complex (650 locations)
CHALLENGES
• Local Internet breakouts for a fast connection
• Cloud Firewall – elastic scale to handle the
increase number of connections
• Bandwidth Control for Office 365 prioritization
SOLUTION
17B monthly
transactions
700+ successful customer
deployments and growing
1.2PB of traffic processed
monthly (Oct. 2016)
Office 365 is finally the highest use – not YouTube
40% of bandwidth
reserved for O365
during periods of
contention
YouTube
capped at 20%
WAN transformation: Fast Office 365 experience
Global workforce staffing company case study
Enable Office 365 ✔
1. Microsoft recommended deployment model (700+ customers)
2. Best possible user experience (fast response times)
3. Rapid deployment (no upgrades, configuration changes)
4. Investment protection and cost avoidance (no hardware or backhaul)
5. Visibility into all Internet traffic within seconds (single console)
Zscaler for Office 365: Five Reasons Why
Zscaler for Office 365
Solution Brief
zscaler.com/O365
The 4 Pitfalls of
Deploying Office 365
zscaler.com/pitfalls
Learn more about Office 365
Secure remote access without
the pitfalls of VPN's
Cloud-Delivered SD-
WAN and Security
Thank You!
Questions and Next Steps
Dhawal Sharma
Director, Product Management
dhawal@zscaler.com
Other Webcasts
zscaler.com > resources > webcasts and live demos
Thursday, November 16th, 2017
Americas - 08:30 am PST

Contenu connexe

Plus de Zscaler

Schneider electric powers security transformation with one simple app copy
Schneider electric powers security transformation with one simple app   copySchneider electric powers security transformation with one simple app   copy
Schneider electric powers security transformation with one simple app copyZscaler
 
Top 5 mistakes deploying o365
Top 5 mistakes deploying o365Top 5 mistakes deploying o365
Top 5 mistakes deploying o365Zscaler
 
Three Key Steps for Moving Your Branches to the Cloud
Three Key Steps for Moving Your Branches to the CloudThree Key Steps for Moving Your Branches to the Cloud
Three Key Steps for Moving Your Branches to the CloudZscaler
 
How sdp delivers_zero_trust
How sdp delivers_zero_trustHow sdp delivers_zero_trust
How sdp delivers_zero_trustZscaler
 
Zenith Live - Security Lab - Phantom
Zenith Live - Security Lab - PhantomZenith Live - Security Lab - Phantom
Zenith Live - Security Lab - PhantomZscaler
 
Moving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospitalMoving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospitalZscaler
 
O365 quick with fast user experience
O365 quick with fast user experienceO365 quick with fast user experience
O365 quick with fast user experienceZscaler
 
Faster, simpler, more secure remote access to apps in aws
Faster, simpler, more secure remote access to apps in awsFaster, simpler, more secure remote access to apps in aws
Faster, simpler, more secure remote access to apps in awsZscaler
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerZscaler
 
Office 365 deployment
Office 365 deploymentOffice 365 deployment
Office 365 deploymentZscaler
 
Dissecting ssl threats
Dissecting ssl threatsDissecting ssl threats
Dissecting ssl threatsZscaler
 
SD-WAN plus cloud security
SD-WAN plus cloud securitySD-WAN plus cloud security
SD-WAN plus cloud securityZscaler
 
The secure, direct to-internet branch
The secure, direct to-internet branchThe secure, direct to-internet branch
The secure, direct to-internet branchZscaler
 
The evolution of IT in a cloud world
The evolution of IT in a cloud worldThe evolution of IT in a cloud world
The evolution of IT in a cloud worldZscaler
 
Rethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation EraRethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation EraZscaler
 
Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?Zscaler
 
Top reasons o365 deployments fail
Top reasons o365 deployments failTop reasons o365 deployments fail
Top reasons o365 deployments failZscaler
 
GDPR - are you ready?
GDPR - are you ready?GDPR - are you ready?
GDPR - are you ready?Zscaler
 
Rethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation EraRethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation EraZscaler
 
Secure remote access to AWS your users will love
Secure remote access to AWS your users will loveSecure remote access to AWS your users will love
Secure remote access to AWS your users will loveZscaler
 

Plus de Zscaler (20)

Schneider electric powers security transformation with one simple app copy
Schneider electric powers security transformation with one simple app   copySchneider electric powers security transformation with one simple app   copy
Schneider electric powers security transformation with one simple app copy
 
Top 5 mistakes deploying o365
Top 5 mistakes deploying o365Top 5 mistakes deploying o365
Top 5 mistakes deploying o365
 
Three Key Steps for Moving Your Branches to the Cloud
Three Key Steps for Moving Your Branches to the CloudThree Key Steps for Moving Your Branches to the Cloud
Three Key Steps for Moving Your Branches to the Cloud
 
How sdp delivers_zero_trust
How sdp delivers_zero_trustHow sdp delivers_zero_trust
How sdp delivers_zero_trust
 
Zenith Live - Security Lab - Phantom
Zenith Live - Security Lab - PhantomZenith Live - Security Lab - Phantom
Zenith Live - Security Lab - Phantom
 
Moving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospitalMoving from appliances to cloud security with phoenix children's hospital
Moving from appliances to cloud security with phoenix children's hospital
 
O365 quick with fast user experience
O365 quick with fast user experienceO365 quick with fast user experience
O365 quick with fast user experience
 
Faster, simpler, more secure remote access to apps in aws
Faster, simpler, more secure remote access to apps in awsFaster, simpler, more secure remote access to apps in aws
Faster, simpler, more secure remote access to apps in aws
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscaler
 
Office 365 deployment
Office 365 deploymentOffice 365 deployment
Office 365 deployment
 
Dissecting ssl threats
Dissecting ssl threatsDissecting ssl threats
Dissecting ssl threats
 
SD-WAN plus cloud security
SD-WAN plus cloud securitySD-WAN plus cloud security
SD-WAN plus cloud security
 
The secure, direct to-internet branch
The secure, direct to-internet branchThe secure, direct to-internet branch
The secure, direct to-internet branch
 
The evolution of IT in a cloud world
The evolution of IT in a cloud worldThe evolution of IT in a cloud world
The evolution of IT in a cloud world
 
Rethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation EraRethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation Era
 
Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?Adopting A Zero-Trust Model. Google Did It, Can You?
Adopting A Zero-Trust Model. Google Did It, Can You?
 
Top reasons o365 deployments fail
Top reasons o365 deployments failTop reasons o365 deployments fail
Top reasons o365 deployments fail
 
GDPR - are you ready?
GDPR - are you ready?GDPR - are you ready?
GDPR - are you ready?
 
Rethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation EraRethinking Cybersecurity for the Digital Transformation Era
Rethinking Cybersecurity for the Digital Transformation Era
 
Secure remote access to AWS your users will love
Secure remote access to AWS your users will loveSecure remote access to AWS your users will love
Secure remote access to AWS your users will love
 

Dernier

LEVEL 5 - SESSION 1 2023 (1).pptx - PDF 123456
LEVEL 5   - SESSION 1 2023 (1).pptx - PDF 123456LEVEL 5   - SESSION 1 2023 (1).pptx - PDF 123456
LEVEL 5 - SESSION 1 2023 (1).pptx - PDF 123456KiaraTiradoMicha
 
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Steffen Staab
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfkalichargn70th171
 
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdfPayment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdfkalichargn70th171
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️Delhi Call girls
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxComplianceQuest1
 
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfintroduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfVishalKumarJha10
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providermohitmore19
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comFatema Valibhai
 
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdfAzure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdfryanfarris8
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesVictorSzoltysek
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...Health
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfkalichargn70th171
 
The Top App Development Trends Shaping the Industry in 2024-25 .pdf
The Top App Development Trends Shaping the Industry in 2024-25 .pdfThe Top App Development Trends Shaping the Industry in 2024-25 .pdf
The Top App Development Trends Shaping the Industry in 2024-25 .pdfayushiqss
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park masabamasaba
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerThousandEyes
 
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrainmasabamasaba
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfonteinmasabamasaba
 
ManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide DeckManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide DeckManageIQ
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park masabamasaba
 

Dernier (20)

LEVEL 5 - SESSION 1 2023 (1).pptx - PDF 123456
LEVEL 5   - SESSION 1 2023 (1).pptx - PDF 123456LEVEL 5   - SESSION 1 2023 (1).pptx - PDF 123456
LEVEL 5 - SESSION 1 2023 (1).pptx - PDF 123456
 
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdfPayment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfintroduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.com
 
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdfAzure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
The Top App Development Trends Shaping the Industry in 2024-25 .pdf
The Top App Development Trends Shaping the Industry in 2024-25 .pdfThe Top App Development Trends Shaping the Industry in 2024-25 .pdf
The Top App Development Trends Shaping the Industry in 2024-25 .pdf
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
 
ManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide DeckManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide Deck
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
 

Pitfalls to avoid when deploying Office 365

  • 1. ©2017 Zscaler, Inc. All rights reserved. | ZSCALER CONFIDENTIAL INFORMATION0 Pitfalls to Avoid When Deploying Office 365 Dhawal Sharma – Director, Product Management WEBCASTS
  • 2. ©2017 Zscaler, Inc. All rights reserved.1 To ask a question • Type your questions into the chat box in the Webex panel or email us at communications@zscaler.com • We’ll try to get to all questions during the Q&A session. If we do not get to your question, we’ll make sure to follow up afterwards • At the end of the webcast – please let us know how we did! ©2017 Zscaler, Inc. All rights reserved. Ask your question here…
  • 3. ©2017 Zscaler, Inc. All rights reserved. | ZSCALER CONFIDENTIAL INFORMATION2 Zscaler: The Market Leader in Cloud Security Enterprise Customers 2,800 CUSTOMERS Over 200 of the Fortune Global 2000 Global Partners 100 Data centers 35B Daily requests 185 Countries served Cloud Scale The Pioneer in Cloud Security Mature Global Cloud Operations
  • 4. 700+ Office 365 customers 2.8 PB Office 365 traffic processed per month and growing 131 TB Office 365 traffic processed per month for one customer 70% of Fortune 500 companies have purchased Office 365
  • 5. Office 365 traffic growth and scalability 1.3 billion Office 365 requests daily Elastic scale: Mailbox migration from a large customer 27 X Growth over 3 years!!
  • 6. The Challenges of Deploying Office 365 A deployment survey of over 200 customers had problems accessing business-critical applications including Office 365. 45% 69%Weekly issues reported Many continued to experience bandwidth issues, impacting business operations and productivity Many were plagued by network latency issues on a daily and weekly basis 30%Daily issues reported 70%Weekly issues reported 33%Daily issues reported Despite appliance upgrades After Deployment
  • 7. Microsoft’s Guidance for Office 365 is Direct Internet TechNet Blog: bit.ly/ZscalerO365 1. Local Network Egress as close to user as possible 2. Unhindered access to Microsoft 3. Local DNS resolution 4. Optimized connectivity to Microsoft’s global network
  • 8. Legacy Hub and Spoke is the WRONG approach • Cloud apps like Skype and Sharepoint are designed for low latency direct access • Hub and Spoke networks and VPN requirements add unnecessary latency • The user experience for Office 365 is compromised • MPLS backhauling adds extra cost to deployment DC Apps HQ/IOT San FranciscoNew York Paris London Local Network Egress Microsoft recommends against using a Hub and Spoke network with Office 365 Hub and Spoke Network Cloud apps need low latency connections
  • 9. Outlook connections per user • Office 365 creates a excessive long-lived connections that exhaust firewalls Between 12-20 connections per user! • Around 4,000 clients can be supported by a single public IP safely • Office 365 use will require more than Web browsing (ports 80 / 443) – uses ephemeral ports THE IMPACT ON USER EXPERIENCE? Local Network Egress Legacy Hub and Spoke is the WRONG approach Increased connect load on Firewalls and Proxies Random hangs and connection issues (Outlook in a disconnected state)
  • 10. • Not recommended and requires Microsoft review and approval • Express route is very complex to configure correctly. • Must perform NGFW capacity assessment – long lived, high throughput connection • Office 365 traffic growth will outpace gateway upgrades and budgets “Microsoft has a review policy… ensure that all parties are aware of the 2-6 months of planning, extra complexity…” ExpressRoute for Office not Recommended Adds Complexity and extra planning Local Network Egress DC Apps HQ/IOT San FranciscoNew York Paris London Hub and Spoke with ExpressRoute
  • 11. Direct Internet connection with appliances • Requires constant firewall updates – missing an IP/URL update will cause connectivity issues • Requires appliance capacity assessments to handle high number of long-lived connections • Sacrifices security in branches with only UTMs or firewalls Ensure local DNS • Impact of Office 365 still overwhelms appliances, despite capacity upgrades Appliance Sprawl Unhindered Access DC Apps HQ/IOT San FranciscoNew York Paris London Complex, costly, and still under capacity
  • 12. ©2017 Zscaler, Inc. All rights reserved. | ZSCALER CONFIDENTIAL INFORMATION11 Direct Internet For Office 365 and Open Internet Zscaler for Office 365 and Direct Internet HQMOBILE BRANCHIOT Data Loss Prevention Cloud Apps (CASB) File Type Controls Data Protection Cloud Firewall URL Filtering Bandwidth Control DNS Filtering Access Control Adv. Protection Cloud Sandbox Anti-Virus DNS Security Threat Prevention Zscaler for your Office 365 Traffic SaaS Open Internet Fast, Secure access to the Office 365 and the Internet Local Network Egress Unhindered Access • Direct Internet for a fast user experience • Best connection method per Microsoft’s guidance • Easily deployed – no hardware needed • One Click configuration simplifies administration A full security stack to secure your Direct Internet connection Zscaler for your Internet traffic
  • 13. Minimize Office 365 latency with Local DNS Zscaler Local DNS Architecture San Jose User > San Jose DNS > San Jose O365 Shortest path, fewer hops = faster user experience Latency: 12ms Common Centralized DNS Architecture San Jose user > LA > Denver > Austin > Atlanta O365 Lots of hops increases: slower user experience Latency: 158ms (22ms+36ms+48ms+52ms) Los Angeles RTT=22 ms Austin RTT=48 ms Atlanta RTT=52 ms Denver RTT=36 ms San Jose RTT=12 ms Local DNS Centralized DNS O365 Connection O365 Connection Local DNS Guarantee a fast, local connection regardless of location
  • 14. Los Angeles Dallas Denver Toronto New York Washington DC Atlanta Miami Paris Sao Paulo Johannesburg London Amsterdam Oslo Brussels Frankfurt Gdansk Stockholm Moscow Mumbai Singapore Sydney Hong Kong Tokyo Madrid TaipeiDubai Riyadh Cairo Kuwait City Kuala Lumpur Cape Town San Francisco Chicago Lagos Tel Aviv Milan Copenhagen Melbourne Zurich Chennai Tianjin Manila Doha Abu Dhabi Jeddah Al Khobar Warsaw 40B+ Requests / day 100M+ Threats blocked / day 120K+ Unique security updates / day Zscaler peers with Office 365 in major DCs 100 DATA CENTERS – 5 CONTINENTS Secure On-going third party testing CertifiedReliable Redundancy within and failover across DCs Transparent Trust Portal for service availability monitoring O365 Peering Data Center Seattle Local DNS Optimized Connectivity
  • 15. Easily maintains updates without day to day Office 365 administration Traditional approach requires constant firewall updates to maintain connectivity HQ BRANCH Local Network Egress Unhindered Access BRANCH Zscaler One Click Configuration Optimized Connectivity Simplify day to day Office 365 administration Updates Office 365 connection details multiple times a week Automatically configures white list Exempts Office 365 traffic from authentication and SSL decryption Fingerprints all Office 365 applications No more keeping up with URL and IP changes in the Office 365 applications. .XML update list One Click Configuration Easily define approved tenants
  • 16. Optimized Zscaler TCP Scaling for faster file downloads 3MB file download from a SharePoint public site hosted at Iowa instance Without Zscaler With Zscaler Slower scaling, does not scale beyond 3MB Scaling starts after 50% of transaction has completed Starts at default 256 Byte value Pre-negotiated 64KB connection Scales faster, window scale > 4MB Optimized Connectivity
  • 17. Zscaler and Direct Internet for Best Office 365 Experience Fully compliant with Microsoft’s recommendation Local Network Egress Unhindered Access Delivers fast Direct-to- Internet for Office 365 traffic Delivers best User Experience Peering in most major exchanges with 1-2 ms round trip time Always a local user connection One-Click configuration simplifies and optimizes connectivity updates Window scaling for faster file downloads Cloud platform easily accommodates long- lived connections Easily scales as Office 365 user demands grow Local DNS Optimized Connectivity
  • 18. Fully Embrace Direct Internet with Zscaler Cloud Firewall Office 365 Port: 443 Protocol: HTTPS User: Jen APP: Outlook Online Location: All APP: Outlook Online Port: 3478, 3479, 3480, 3481 Protocol: UDP User: Chris APP: Skype for Business Online Location: All APP: Skype for Business Online Port: Any Protocol: UDP User: Steve Location: All APP: BitTorrent Internet Branch User Checking Email HQ User Sharing Desktop Mobile User Downloading Movies APP: BitTorrent Easily scale NGFW visibility and control across all locations without the appliance cost and complexity Application visibility and control • Adv. DPI engine - stateful packet inspection • ID Apps regardless of port, protocol, or evasion • Intrusion Prevention w/ protocol anomaly and signature-based detection. User identity awareness ID Users & Groups regardless of IP address Unified Policy and Visibility Single console for policy management and real-time log visibility Zscaler Cloud Firewall Direct Internet Traffic Unlimited SSL inspection capacity • Inspect ALL your Internet traffic • One-Click config excludes O365 traffic
  • 19. Zscaler Bandwidth Control Prioritize Office 365 traffic as Business Critical Always guarantee Office 365 40% of bandwidth Cap YouTube traffic at 20% • Policies are defined in a single console and immediately enforced globally • Policies are enforced in the cloud, before the last mile bottleneck • Window shaping and bandwidth throttling deliver a smooth user experience How Zscaler Bandwidth Control Works
  • 20. Low Office 365 traffic in NY despite one of the largest offices – user issues? Easily identify the top Office 365 users OneDrive traffic is low – is Box still being used? Real-time traffic volume trending Get Unprecedented Office 365 Visibility with Zscaler How well is Office 365 being adopted by your users?
  • 21. • Causing WAN congestion • Sessions were overwhelming firewalls • Deploying UTMs or NGFWs was prohibitively expensive and complex (650 locations) CHALLENGES • Local Internet breakouts for a fast connection • Cloud Firewall – elastic scale to handle the increase number of connections • Bandwidth Control for Office 365 prioritization SOLUTION 17B monthly transactions 700+ successful customer deployments and growing 1.2PB of traffic processed monthly (Oct. 2016) Office 365 is finally the highest use – not YouTube 40% of bandwidth reserved for O365 during periods of contention YouTube capped at 20% WAN transformation: Fast Office 365 experience Global workforce staffing company case study
  • 22. Enable Office 365 ✔ 1. Microsoft recommended deployment model (700+ customers) 2. Best possible user experience (fast response times) 3. Rapid deployment (no upgrades, configuration changes) 4. Investment protection and cost avoidance (no hardware or backhaul) 5. Visibility into all Internet traffic within seconds (single console) Zscaler for Office 365: Five Reasons Why
  • 23. Zscaler for Office 365 Solution Brief zscaler.com/O365 The 4 Pitfalls of Deploying Office 365 zscaler.com/pitfalls Learn more about Office 365 Secure remote access without the pitfalls of VPN's Cloud-Delivered SD- WAN and Security Thank You! Questions and Next Steps Dhawal Sharma Director, Product Management dhawal@zscaler.com Other Webcasts zscaler.com > resources > webcasts and live demos Thursday, November 16th, 2017 Americas - 08:30 am PST

Notes de l'éditeur

  1. https://msdn.microsoft.com/en-us/library/mt450488.aspx Although ExpressRoute is being used by Microsoft IT, ExpressRoute is not required or recommended for Office 365 customers except in a small number of situations. These situations include a) regulatory requirements that would mandate a direct network connection or b) following a required customer network assessment for Skype for Business voice and video when network deficiencies are discovered that ExpressRoute can address.  In the situations where ExpressRoute for Office 365 is implemented, Microsoft should be directly involved to ensure a successful implementation.
  2. TCP Window scaling allows large files to be downloaded faster and efficiently Large TCP Window size per connection to O365 with flexible receive buffer for faster downloads
  3. TCP OPTIMIZATIONS Large TCP Window size per connection to O365 with flexible receive buffer for faster downloads Disabled Nagle algorithm for higher performance of long lived Office 365 connections Flexible TCP Idle Time out starting at 120 sec Nagle's algorithm works by combining a number of small outgoing messages, and sending them all at once. Specifically, as long as there is a sent packet for which the sender has received no acknowledgment, the sender should keep buffering its output until it has a full packet's worth of output, so that output can be sent all at once.
  4. App identification with DPI & Heuristics
  5. Kelly services, a long time customer of Zscaler, was looking to deploy Office 365. As they went into pilot mode, their users were complaining and realized that Office 365 creates a high number of long-lived connections that increases network utilization and can overwhelm firewalls. And traffic and congestion was increasing on the MPLS network — which was driving MPLS costs higher. They evaluated deploying NGFWs at all the branches to route traffic locally, but it was too expensive. They decided to leverage the Zscaler Cloud Firewall and bandwidth control to route traffic locally and ensure Office 365 traffic was prioritized over YouTube during periods of congestion. To date, we’ve helped over 700 customers successfully deploy Office 365, and we’re processing 17B requests monthly and about 1.2PB of traffic.