DNS, DHCP & IP Address Management appliances
For Microsoft DNS & DHCP servers
For open source DNS & DHCP servers
Cloud-based visualization of analytics across DDI architecture
Manage multi-vendor cloud DNS servers centrally
RIR Declaration Management and Automation
Automated network device configuration and management
Centralized visibility over all your clouds
A single source of truth for your network automation
Why DDI is an Obvious Starting Point
DNS Threat Intelligence for proactive defense
Intelligence Insights for Threat Detection and Investigation
Adaptive DNS security for service continuity and data protection
Improve Application Access Control to prevent spread of attacks
Protect users and block DNS-based malware activity
Carrier-grade DNS DDoS attack protection
Optimize application delivery performance from the edge
for Proactive Network Security
Visibility, analytics and micro segmentation for effective Zero Trust strategy
Enable work from anywhere by controlling access, security and data privacy
Simplify management and control costs across AWS, Azure and GCP environments
Risk-free migration to reduce DDI complexity and cost
Move risk-free to improve performance, security and costs
Automate management, unify control and strengthen security of connected devices
Protect your network against all DNS attacks, data exfiltration and ransomware
Enable zero touch operations for network management and security
Improve resiliency, deployment velocity and user experience for SD-WAN projects
Integrated DNS, DHCP, IPAM services to simplify, automate and secure your network.
Simplify design, deployment and management of critical DDI services for telcos
Optimize administration and security of critical DDI services for healthcare
Simplify and automate management of critical DDI services for finance
Simplify and automate management of critical DDI services for higher education
Simplify and automate management of critical DDI services for retail
Simplify Management and Automation for Network Operations Teams
Elevate SecOps Efficiency by Simplifying Threat Response
Open architecture for DDI integration
Technology partnerships for network security & management ecosystems
Extend security perimeters and strengthen network defenses
Submit requests for temporary licenses
Submit access requests for EfficientIP knowledge platforms
Submit membership requests for EfficientIP Community
Strengthen Your Network Protection with Smart DNS Security
Customer-centric DDI project delivery and training
Acquire the skills needed to manage EfficientIP SOLIDserver™
Identify vulnerabilities with an assessment of your DNS traffic
Test your protection against data breaches via DNS
Dedicated representation for your organization inside EfficientIP
Explore content which helps manage and automate your network and cloud operations
Read content which strengthens protection of your network, apps, users and data
Learn how to enhance your app delivery performance to improve resilience and UX
Why Using DNS Allow Lists is a No-Brainer
This enterprise-grade cloud platform allows you to improve visibility, enhance operational efficiency, and optimize network performance effortlessly.
Who we are and what we do
Meet the team of leaders guiding our global growth
Technology partnerships for network security and management ecosystems
Discover the benefits of the SmartPartner global channel program
Become a part of the innovation
The latest updates, release information, and global events
February 14, 2019 | Written by: Efficient IP | DDI, DNS, DNS Security, Virtualization & Cloud
Data exfiltrationData PrivacyData protectionDDIDDI ManagementDDI ServicesDDI SolutionsDevOpsDigital TransformationDNSDNS FilteringDNS ManagementDNS SolutionEnterprise Network SecurityMalwarePrivate DNS
Many organizations are starting their journey to the cloud by moving some workloads to public providers. Most of the time, the first ones are development and test environments as they are generally considered less critical. Moving to production is performed after this initiation on non-critical front applications, sometimes including storage as files and databases. Then come bigger deployments.
Common strategy starts with “lift & shift” of existing eligible applications to public cloud compute services, aka IaaS (Infrastructure as a Service), like AWS EC2, Google Compute Engine or Microsoft Azure. At the same time, enterprises start refactoring and building new applications for optimal use of elastic cloud serverless resources and containers for microservices. Since refactoring takes time and may have low business value, most workloads will remain in the IaaS for a long period of time.
What is really attractive in public cloud offering is that all of the underlying parts of the infrastructure and orchestration procedures hosting the application components are fully managed and mostly hidden. Here we are talking about network, internet access and security, storage, servers, and computing virtualization. Everything is easily configurable through a simple user interface or API, and we now see a lot of orchestration and configuration tools available to build full application stacks, ready to host the software developed in-house.
DNS is a central part of this infrastructure, fully managed by the cloud provider and allowing access to any cloud services and internet resources. Most of the time, no specific configuration is required to get full DNS access from the workloads pushed on public cloud infrastructures.
Deploying multi-tier applications on cloud services still require some basic security and isolation concepts. In order to answer enterprise security concerns, cloud providers are proposing private networking solutions to deploy internal resources and back-end services (e.g. databases, file storage, specific computation, back office management). This allows them to embrace security and regulatory concerns like data protection (e.g. GDPR or US CLOUD Act), data ciphering, or simply not exposing part of the applications directly to the Internet, which is good practice.
However, we would advise deploying computational back-end resources on subnets or networks not connected to Internet, and only reachable by known sources. Filtering rules can be enforced on managed network components in order to restrict access and comply to security policies. Most of the time, the filtering is performed at a higher level on cloud infrastructures than on internal ones, thanks to “infrastructure as code” patterns and automatic deployment strategies.
Are you aware that private networks, without access to the Internet, are still able to communicate with it through DNS?
DNS tunneling, DNS file systems and data exfiltration are possible on most public cloud providers by default. This is not a security flaw, but more due to “standard-built” DNS implementation, mainly to help the workloads accessing cloud serverless services, thus easing digital transformation.
This opens a wide range of possible data leaks. We’ll focus on four that present different impacts and likelihoods:
If you manipulate or store business information on private networks hosted in public cloud, even temporarily, you have to deploy a private DNS service that will allow you to filter what should be accessible and what should not.
This requires specific cloud patterns that are new to most system and network architects. Rare are workloads requiring full access to the Internet, the standard architecture patterns impose these to be fully autonomous, as data access and security are far more simple to track that way. But sometimes, DevOps people prefer to have direct access to the Internet in order to update the infrastructure, install packages or dependencies- it simplifies the deployment phase and concurs to “time to market” regular deliveries.
One good approach is “immutable infrastructure” with prebuilt images, private networks and controlled communication inbound and outbound. In addition, regular testing phases should be performed as options of cloud providers may change without being integrated into standard change management of enterprises. Remember, ITIL flowcharts are still used for at least the legacy IT systems.
Multi-cloud approaches are more complex to handle since each cloud provider is implementing the features with different flavors. DNS could be disabled, or not, per subnet, per virtual private cloud network, or per host. Some are proposing advanced DNS service to host private zones, others allow contact to enterprise internal DNS. What is questionable is that DNS could be applied to all the underlying services considered as system, network or security and handled directly by the service provider. Don’t underestimate the focus required for securing the workload you push to the public cloud and generally to IaaS and PaaS providers.
To be efficient, private networks in the cloud should be deployed without DNS access (at least the recursive part if possible at cloud provider level). A private DNS solution is required and will reinforce any resolution performed by all the workloads in IaaS and cloud services (e.g. VMs, function as a service, big data computation cluster, containers orchestrators, or batch systems). In addition, it could also include security features based on traffic behavior.
Configuring such on-demand built DNS service in public cloud is made easier with a flexible DDI solution integrated to the cloud orchestrator. DDI will automatically push the appropriate records in the configuration once the service is enabled, bringing time savings and enforcing policies to help secure public cloud deployments.
Une version en français tiré de cet article est disponible sur le site des Echos Opinions : Les plateformes de cloud public ne sont pas étanches !
When our goal is to help companies face the challenges of modern infrastructures and digital transformation, actions speak louder than words.
Explore content highlighting the value EfficientIP solutions bring to your network
We use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site.