Video details

LinkedIn's Distributed Firewall

DevOps
10.29.2017 at LISA
English

San Francisco

Mike Svoboda (LinkedIn)

Distributed Firewall (DFW) has fundamentally altered LinkedIn's System, Network, and Security Operations. This technology has enabled LinkedIn to expand with unbound horizontal scalability by leveraging Software Defined Networking. Combining system automation with host based firewalls, DFW has not only allowed LinkedIn to alter the physical network design, but it has also increased the security protections that we can now provide in Production environments.
In this presentation, we will share how LinkedIn was able to remove physical and logical network firewall bottlenecks. By shifting network security enforcement down to the per-host level, DFW enables LinkedIn to fully utilize datacenter power, cooling, and space facilities by intermixing heterogeneous environments within the same physical rack and network footprint. Integrating DFW with LinkedIn's code deployment system, the firewall has become aware of the specific application requirements on each node, and can build a unique security profile to secure the hosted services.
We will demonstrate DFW in action, point to the open source code, and will share lessons learned from our Production implementation so other organizations could leverage this technology.