Configuring network security
No matter whether a public cloud, a private cloud, or the edge, there are always two components to networking. One is the physical network, while the other is the software-defined network, an overlay network on top of the physical network. As we discussed previously, in the on-prem and the edge parts of hybrid cloud, the onus of responsibility for security is on the enterprise, while the public cloud provider guarantees a basic level of network security and provides networking services and capabilities to integrate security into the design. The following diagram shows the network boundaries that are typically implemented while creating the network architecture:
Figure 6.11 – Network boundaries
The preceding diagram illustrates two important considerations to bear in mind when designing networks. Both are paramount in a hybrid cloud architecture:
- Configuring network perimeter controls
- Configuring network segmentation...