If LAN is legacy, what is the UN-legacy...?
-
Today, even most companies that are still completely addicted to and committed to the LAN model, those that would never consider something different, rarely have anything on their LAN that ties them two it except for two things: Active Directory and old fashioned LAN file shares.
Both of these things are on the cusp of being legacy, in a way.
Microsoft has already moved AD features into Office 365 and Azure once you go to Windows 10. While you don't (yet) get the full power of traditional AD you get AD for super cheap while needing no infrastructure of your own without any of the old LAN limitations of AD. It's a huge win. AD is only going to keep going in this way. And the California model was to drop AD and tight desktop controls already. So as AD penetration begins to decline (not going away, just dropping from the 99% saturation point it was at) and as AD begins to leave the LAN fold, that is dramatically changing.
And LAN file sharing is getting demolished from two fronts. On one side products like Dropbox, ownCloud and OneDrive for Business are making users thing about storage differently and making IT step back and stop just "doing what we have always done." While on the other side ransomware is making traditional file sharing super risky. So the old method's inherent risks get exposed right as major alternative approaches arise. The LAN concept of storage is rarely needed any longer.
Add to this the idea that networks are more complicated, people need to work remotely from home, the car, a phone, a hotel, etc. and suddenly the LAN is really just "in the way" and no longer enabling good IT but rather blocking it.
-
None of this is to suggest that the physical LAN network of an office will go away or that we will not attempt to secure it (firewall, UTM, etc.) It is that we will stop thinking of it as a secure place to dump data willy nilly. And once we treat the LAN as a dangerous place like the Internet, suddenly we are not tied down to it any longer either.
-
@scottalanmiller said:
None of this is to suggest that the physical LAN network of an office will go away or that we will not attempt to secure it (firewall, UTM, etc.) It is that we will stop thinking of it as a secure place to dump data willy nilly. And once we treat the LAN as a dangerous place like the Internet, suddenly we are not tied down to it any longer either.
This was going to be my next question.
If I understand correctly, the firewall/UTM/"insert fav mode" concept still exists & is valid.
The old school "on prem" services (AD, File Shares, email) that were heavy on LAN kinda go away -
@FATeknollogee said:
If I understand correctly, the firewall/UTM/"insert fav mode" concept still exists & is valid.
The old school "on prem" services (AD, File Shares, email) that were heavy on LAN kinda go awayRight, that is what I expect. Having a firewall to provide "as much protection as possible" will be valid for a long time (although some weird people are even arguing that that is a waste, but I don't buy it) but having services that assume you are on a LAN will go away.
Email, AD, storage... we will continue to need those, but not in the old way. Right now we have to create this "special network" to deliver those services. SMB only works well over a low latency, high bandwidth connection. AD is complicated without local DNS controlling everything. Things like that. They are based on very limited assumptions that really curtail businesses.
-
And, of course, things like cloud platforms change this too. Once you remove the LAN, suddenly you can easily leverage not just a platform like AWS whenever needed, but you can do so in a very flexible way. We don't need a private cloud, we can use a cheaper and more powerful public one. We don't need to work with a single provider, we can use any one that is good for the needed workload.
Things get cheaper and more powerful.
And WAN purchasing changes. We don't need expensive VPN accelerators, managed VPN or MPLS. We just need fast WAN links, at lower cost. The WAN becomes far simpler, too.
-
And of course, just as the LAN never made sense for everyone, the LAN will likely always make sense for someone. But it is the assumption of a LAN, the foregone conclusion that the LAN is how businesses run and especially that it is how "enterprise" ones run, is already past its sell by date. Nothing wrong with LANs today, but they are not the cutting edge or something special. Companies that are skipping them are either forward thinking new entities or companies that had LANs that have worked hard to phase them out.
-
So there are two solutions for this that I know of Zero Tier and Pertino. What other options are there?
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
It seems like a lot more expensive.
Are there other options?
-
@Dashrender said:
So there are two solutions for this that I know of Zero Tier and Pertino. What other options are there?
The option is you do not need those either.
Those are simply alternate VPN methods letting you cling to your extended LAN functionality.
-
@Dashrender said:
So there are two solutions for this that I know of Zero Tier and Pertino. What other options are there?
Those are not solutions for what I am describing, those are just the most advanced uses of the legacy LAN concept. Those are all about remaining dedicated to the LAN even after your are physically in no way suitable for one. Great products, but designed solely around maintaining the LAN ideologically rather than replacing it.
-
@Dashrender said:
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
ZeroTier is truly free and can be done without Internet access, if you want.
-
@Dashrender said:
Are there other options?
The idea of the citadel (I call it this because the LAN was the castle) is that there is no "shared address range", or at least no dependency on it. Security is no handled by having a "safe zone" on which you put services, you assume all networks are suspect and secure data accordingly.
I think that there are two key elements to removing the LAN dependency and ideology:
- Secure everything as it everything was a suspect network.
- Publish everything so that there is not a "local" network addressing dependency for resolution.
-
I would love to read more about the idea of
but as the LAN becomes increasingly unnecessary I see "enterprise" very much not the term for this model. Enterprises are the ones best equipped to move to more modern structural models."
Any links to articles on the subject and concept
-
@scottalanmiller said:
@Dashrender said:
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
ZeroTier is truly free and can be done without Internet access, if you want.
But if you are doing that, why bother with ZT?
-
@Dashrender said:
@scottalanmiller said:
@Dashrender said:
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
ZeroTier is truly free and can be done without Internet access, if you want.
But if you are doing that, why bother with ZT?
If you are doing it for free? Just because you don't want to pay.
Without Internet? Because you want software defined networking. Same basic reasons for OpenDaylight.
-
@Dashrender said:
@scottalanmiller said:
@Dashrender said:
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
ZeroTier is truly free and can be done without Internet access, if you want.
But if you are doing that, why bother with ZT?
Encryption is the first thing that comes to mind.
-
@scottalanmiller said:
@Dashrender said:
@scottalanmiller said:
@Dashrender said:
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
ZeroTier is truly free and can be done without Internet access, if you want.
But if you are doing that, why bother with ZT?
If you are doing it for free? Just because you don't want to pay.
Without Internet? Because you want software defined networking. Same basic reasons for OpenDaylight.
OpenDaylight? (searching internet)
If your network isn't attached to the internet, then why would you need SDN? What do you gain? I definitely see why you use SDN for internet connected devices/services...
-
@JaredBusch said:
@Dashrender said:
@scottalanmiller said:
@Dashrender said:
What do you think about the fact that these SDNs aren't really free, yeah LANs aren't free you need a switch, but SDNs need a control node and switches and internet access.
ZeroTier is truly free and can be done without Internet access, if you want.
But if you are doing that, why bother with ZT?
Encryption is the first thing that comes to mind.
most systems already have their own encryption built in, so that shouldn't be a problem.
Windows can run completely encrypted on the LAN side if you want - enable certs/keys, etc...
-
@Dashrender said:
Windows can run completely encrypted on the LAN side if you want - enable certs/keys, etc...
Right... and you are just building a complicated, proprietary SDN
-
My biggest concerns about having things like AD on Azure would be that traffic (encrypted or not) being hit by a MITM type attack. It makes your information more vulnerable to that, than if you were, say... Running your business infrastructure on ZeroTier.
-
@dafyre said:
My biggest concerns about having things like AD on Azure would be that traffic (encrypted or not) being hit by a MITM type attack. It makes your information more vulnerable to that, than if you were, say... Running your business infrastructure on ZeroTier.
Tell me how ZT makes you immune to a MITM?