End-to-end network security service for workloads across different network environments
Implementations include providing security services to workloads deployed across various types of network environments, such as public networks, private networks, hybrid networks, customer premise network environments, and the like, by redirecting traffic intended for the service device through a security environment of the first network. After application of the security features to the incoming traffic, the “clean” traffic may be transmitted to the service device instantiated on the separate network via a tunnel. Redirection of incoming traffic to the security-providing first network may include correlating a network address of the service device to a reserved network address of a block of reserved addresses and updating a Domain Name Server (DNS) or other address resolving system with the reserved address. The return transmission tunnel may be established between the security environment and the network address of the service device.
1 . A system for operating a network, the system comprising:
a processing device; and
a non-transitory computer-readable medium encoded with instructions, which when executed by the processing device, cause the processing device to:
generate, based on a service parameter, a performance threshold value for providing a security service for network traffic corresponding to a destination workload;
simulate, on a model of a network configuration, providing the security services for the network traffic;
select, based on a comparison of an output of the simulation to a performance threshold value, a network environment from a plurality of available network environments; and
instantiating, in the selected network environment, the destination workload.
2 . The system of claim 1 wherein the instructions further cause the processing device to:
monitor a network performance value for providing the security services to the network traffic over a period of time; and
modify the model of the network configuration based on the monitored network performance value.
3 . The system of claim 1 wherein the instructions further cause the processing device to:
migrate, based on the selection of the network environment, a secure communication tunnel to connect to the destination workload.
4 . The system of claim 1 wherein the network environment comprises at least one of a public cloud environment, a private cloud environment, or a compute environment of the network.
5 . The system of claim 4 wherein the network performance values comprise one of a maximum transmission speed, an expected packet loss, or an available bandwidth.
6 . The system of claim 5 wherein the performance threshold is based on a service level agreement.