Rethinking Firewalls for the Cloud – Steve Mullaney, Aviatrix
Steve Mullaney, CEO of Aviatrix joins Mike Rothman to discuss the company’s new distributed cloud firewall offering. But that’s not all, they end up talking about how network security must change for the cloud, the role of the incumbent networking companies, and some old-school networking technologies (like 10BASE-T).
Transcript
This is Techstrong tv. Hi everybody. Mike Rothman here with another Techstrong TV interview.
Um, okay. Very pleased to be, uh, joined by Steve Elaney. He is c o e o.
Yes, c e o c E o. Demotion, You know, quite yet, the, there's the day's not over Steve, but, you know, we'll, we'll get there. Uh, of, uh, Aviatrix, Aviatrix, again, a a virtual network company.
I'm not gonna he'll he can introduce that. But what we're gonna talk about today is distributed firewall and really, you know, kind of integrating security into the network fabric as we continue to move towards this cloudy thing and, and, and programming and virtualizing, uh, not just our technology and our servers, but also our networks and a lot of the other constructs that we use to build up, uh, application environments. Uh, being able to really provide more programmatic control over the network becomes one of those critical things.
And, and Aviatrix has some very cool technology, uh, and it's making a very cool announcement today, actually, uh, that we'll get into. So, so Steve, welcome. How are you?
Thank you. I am doing very well, thank you. Good, good.
So why don't you tell us a little bit about one yourself. I mean, you've got a long history in, uh, in the networking space. We, we've known each other for, you know, decades in this.
We won't say how long Yeah, Exactly. But it tell us a little bit about Old decades. Exactly.
So, yeah, I'm a old time. I won't say old, but, uh, old time networking and network security person. So, um, starting my career, it's sy optics.
When, uh, before 10, BT was a standard. I was an engineer on ethernet actually before that, and coax cable, if you remember all those days. But, uh, been in a kind of networking and network security the entire 37 years I've been working.
Um, I, um, stayed at Synoptics Bay Networks for, for 10 years. Uh, then did a bunch of different startups. One of them called Palo Alto Networks, people may have heard of.
I was the VP of marketing that launched, uh, the category called Next Generation Firewall, which now should be called Last Generation Firewall. Lg fw. Cause We'll, we'll get there.
We'll get there, we'll Get there. Yeah. Um, was the, became the c e O of Naira around, um, uh, you know, software defined networking and so forth.
Um, we got bought by VMware. I stayed at VMware for a few years, created nsx, became a multi-billion dollar business there. I retired for five years, was never gonna work again.
Why did I come back? Because this thing called cloud four and a half years ago, every enterprise said, now we mean it. We're moving to the cloud and we mean it, it's going to become the center of gravity of our architecture, of our infrastructure.
And this is going to be the next 30 years. We've been talking about this forever, but now we mean it. And, um, I was on a bunch of boards, was never gonna work again, but saw this thing happen and said, my God, someone's gonna become the equivalent of what Cisco was and kind Palo Alto in the old world of on-prem, someone's gonna define networking and network security in the cloud and become the, the, the, the platform of choice for that.
And of course it's gonna be multi-cloud because cloud is defined by the business units, not by the infrastructure teams. And I looked around and I said, I don't know who it's gonna be, but I know who it's not gonna be. It's not gonna be Cisco, it's not gonna be Juniper, it's not gonna be Arista, it's not gonna be pant.
It's gonna be somebody new who's gonna come in and do it in a very cloud native way and just re-architect everything. And that's what I'm hearing. And that's part of what we're announcing today.
Good, good. So let's, you know, not cut to the chase, right? So there's a new announcement.
You guys are introducing a distributed cloud firewall technology. Yes. So why, why don't we kind of go through that a little bit and Yeah.
And and really start to compare and contrast to, Yeah. So to The ways folks are doing this. So if you think back to when I was at Palo Alto Networks and when we created the NextGen Firewall applications drive infrastructure.
We know that we don't do infrastructure just for infrastructure's sake. The applications change and the infrastructure has to react to that change. 15 years ago, the change was this thing called the internet.
And guess what? Firewalls used to just open and close ports and look at protocols and, you know, and they would just block access based on the application using that specific port. And everybody had to define port.
So if you wanted to block instant messaging aol, you blocked port 51 90 and then you blocked it. The problem is, when we went to the internet, guess what everything did Mike. It all went on Port 80 hdtp.
So you had a firewall that only mechanism for blocking was which port and which protocol. So Port 80 protocol http, what's the rule? Allow, Right?
So guess what? Your firewall became a piece of wire so near, and the team at Palo Alto said, this is ridiculous. We have to create a new version of a firewall that goes deeper, looks at the user, looks at the content, looks at the threat, and all these devices around the firewall just went away and everybody, and then the next gen firewall took over.
And Palo Alto is now a 50 billion market cap company. Oof. Right?
Well, you now fast forward another 15 years and you look and you go, the next model of computing is what cloud, guess what? Applications and the infrastructure fundamentally has changed. And it, the needs are require, it requires a fundamental reinvention of network security, of which the spawar of that is the firewall.
And the reason we've had to change is in on-prem, it was a very boundary oriented environment where you g you, you passed all traffic through this choke point called the firewall. And that's where I applied all my security. Great.
You go to the cloud, it's, it's perimeter less. Where's the perimeter? It's everywhere.
Right? By definition, the cloud, because it's designed around agility and, and being able to do things quick access to the internet is by default. So there's no boundary.
So what we've done as an industry, Mike, is because we didn't have any choice, and I'm talking about customers, I took this 15 year old concept that is a choke point that passes traffic through it. And I jammed it into my beautiful cloud, which is perimeter less. And I tried to create a perimeter.
So you're going, you're creating an unnatural act in the cloud. Remove all agility, create horrible, complex operational model. The scale is horrible because how big of a firewall do I now need to put there if all of my entire traffic is going through this choke point?
Yep. Um, what happens to the traffic that isn't steered through the choke point, Mike? We don't get to inspect it.
Nothing. How much of that traffic is not inspected? Hopefully not a lot.
Right? Guess what? It's a lot.
Why? Because the natural traffic pattern of the cloud is not to be That's right. Steered through this choke point.
So bad security, horrible scalability, performance, choke point, uh, operationally very complex, lack of agility, which is the whole reason we're going to cloud. And then on top of that, yep. I've heard the word gouging by customers, right?
This is wildly expensive and the best tool that every enterprise has right now is a yellow highlighter. They're looking at cost. And so they look at all this, but why?
But so why didn't anybody do anything else? Well, because that's all we had. So customers, comfort, Comfort in inertia, right?
Comfort in inertia. I mean that Folks are comfortable with, we need to something like reinvent, just like I did 15 years ago, right? Create a new category we have to reinvent.
And if you have a new piece of paper, clean slate, would you steer traffic to something? No. You would embed that inspection and intelligence into the network, not as an agent, right?
No one likes agents. I don't wanna steer traffic and I don't want agent. What if I could embed all that intelligence, firewalling intelligence, and I'm talking L four through seven, scanning, anomaly detection, I D S I P S, decryption everything in a distributed manner and do a little bit of that everywhere.
That's how you get to zero trust. That's how the cloud model goes. So now I infinitely scale operationally.
It's all part of the C I C D pipeline. Uh, the, the, so the operationally it's simpler. Um, no performance bottlenecks cuz I just do all this stuff.
Yeah. Um, the cost is just now just additive on top of o of the thing. Um, and um, you know, you just look at that and you go, and so it's gonna, and and it's gonna save tremendous amount of money.
And, and so for us that's, I've talked to now probably about a hundred of our big enterprise customers. I've not found one who says this is not the right way to go. And the reason this is, no one else has done this.
It's incredibly hard, Mike. Sorry. That's fine.
I've been here for four years. We've been working on this for four years. Why?
Because the operational model that the mental model is, it looks like one big giant firewall Yeah. With one policy engine that's based on tags and, and, and, uh, smart groups we call it that follow the things around and one enforcement enforcement point that happens to be physically distributed as a distributed system. So it's thousands of points that look like, Steve, Let's frame it a little bit differently, right?
Because I mean, I know that, you know, kind of the news is about the distributed firewall and you know, it's kind of everywhere. But I, I wanna kind of frame it as the concept of, you know, a network that's secure as opposed to mm-hmm. Secure networking or cloud networking or anything like that.
That's what we've always wanted, right? That's what we've always been trying to do for the 30 years I've been doing this as well. Right.
You know, we've had to bastardize the environment by bolting on a whole bunch of different things, grooming traffic in a way that is unnatural from that perspective, we really wanted this to be part of the fabric since we've started these things. It just wasn't practical until we were able to get to a generational upgrade of the infrastructure. And that's Because we had, we also had a natural boundary that we could, we could pass things through in the da in the on-prem data center, there's a natural boundary and so that's fine.
And so the problem you go in the cloud is exactly what you said. Now all of a sudden there's no boundary. You're now forced to do it in the network.
And the problem is you have to be a networking player in order to do it in the network. And Palo Alto Networks is not a networking company. Yeah.
They're a firewall. So, So let's talk a little bit about, you know, kind of how you work with all the different cloud providers, right? Because, and I, I've spent a whole mess of time.
Mostly you guys spent a lot of Azure, a little bit of, of some other cloud platforms too. And, and man, the constructs are just totally different in terms of how you do networking between different, you know, cloud platforms. So, so how do you guys kind of arbitrate all that, that Azure does things in a totally different way than aws, than gcp, than Oracle, than, you know, kinda Alibaba and all these other, you know, kind.
That's, that's what you do in computer science, right? You abstract, you create simplicity as opposed to managing the complexity. That's what we do.
So our intelligent, you know, software defined infrastructure with a controller and enforcement points, the controllers smart enough that we talk a d s, we know the a w s constructs, we talk Azure, we talk Google, we talk Alibaba, we talk gcp. And then what we do in each one of those is slightly different. And then what we expose to the customer, meaning our enterprise is a common set of advanced services.
How we handle that in each of them, it's almost like a high level software compiler that depending on what is the, the hardware, it'll have different low level hardware instructions. We have different hardware instructions based on what cloud, but we abstract that away from our user such that we can create a one infrastructure, one architecture, which is very simple for them across any of the public cloud. Yeah.
So, so customers don't have to worry about the constructs of security groups and AWS or VMAs. We handle all that and we will leverage anything we can. So whatever they have natively, we will leverage and then we will augment what they don't have.
So what we augment in a w this is very different than what we augment in g CCP or Azure. Great. So it feels like a brain transplant on the network.
So how do you kind of get there without having to, you know, is there an incremental phasin Absolutely. Type of approach to, to, So the first thing we're going at, so first of all, it's shocking how little security people have in the cloud that by the way, that's a big Not shocking. I, I do this for Steve.
I know. And, and the reason is it's very complex, very expensive. And, and they don't know how to do it.
So they go, well, let's just not tell anyone and we'll get there. So for us it's, it's easy because most of the times we come in when competing against nothing, right? So we can go in, aw, Ws NAC Gateway as an example, is has no security, no visibility.
It allows you to connect your VPCs to the internet, but no security. We are saving people millions of dollars a year in their net gateway chargers. It's a, it's horribly expensive.
No security, no visibility. Great way for us to insert. Then because of the recession, people are also looking at that firewall line and saying, okay, how about what if you can insert there as well.
But there's areas I would say net gateway and then areas where people have no EastWest firewalling in the cloud at all are great places for us. Insert, prove ourselves, get the trust model going where they say, okay, Aviatrix, I trust you. And then over time we get more and more, we did this at Apollo in the beginning of the days.
We did not replace checkpoint firewalls day one. Took us five years, Mike, because we couldn't walk in and say, hi, I'm near Zuck from Palo Alto Networks said, I'm here to replace your checkpoint firewall. They would've laughed at us.
We said, well we are gonna replace it. It's just after you've earned trust, we've earned that trust. We're gonna do the same thing.
We're gonna slowly burn, boil the frog and add more value to eventually people look and they say, why do I have you and them? We're gonna go, I don't know, you could have got rid of them two years ago. Okay, I'm now gonna go with you.
We'll do the same thing and earn that trust from people. Yep, Yep, yep, yep. But Architecturally this is the way to do it.
So I know we're gonna win because architecture matters. It always does. When I first started working, You, you, you know, from the past, you, you had some words, I wrote it down in a notebook 15 years ago when we launched Palo Alto, you had comments for me and I wrote 'em down.
You know, not to say that again cuz I got my notebook. No. Yeah, you, so I remember that discussion too, Steve, and, and and I, my my issue is you going after checkpoint at, at first with the, with the new category.
So what do you think now? You know, so, so, and, and so one of these things where I got lucky, I've been doing cloud for, you know, know 12, 13 years at this point. So you, you know, before a lot of these even VPC constructs, uh, were there, uh, it's difficult.
And, and the problem is, and and I kind of used that term inertia very intentionally before. Yeah. Because what you see with a lot of enterprise is they kind of end up with a network that kind of looks like they're on-prem network.
Cuz they don't know any different, right? They still have their spreadsheets. If IP addresses this, it's like, guys, you don't have to do any of that stuff in the cloud, right?
You, you can, you can really think about things in a much more, you know, kind of virtual and constructive way. Uh, and they just can't. Right?
So they just can't. Yeah. So, so there's a mental jump that has to happen for folks to really understand what virtualizing, you know, and, and cloudifying a lot of their infrastructure is, is gonna look like.
But, but once they make that jump, then they start to think about, well how do I do this stuff? And, and again, I do a lot of, you know, Azure need of west type work and they're so fundamentally different. Yeah.
I think it's becoming a problem. Cause that Is true what's Right because People is, they've been doing that model the, the Bolton. Exactly.
Like let me lift and shift my security model for on-prem cause I've got no other way to do it. They've now had a few years experience with that. The lack of agility, the expensiveness, all things I talked about, they're now going and realizing, yeah, this is a problem and it's really expensive.
So, and it's really, trust me, there's a lot of interest. The words game-changing are used with most customers. I think You be, and, and just think about two very, you know, tactical things and you mentioned one of them, right?
I'll throw transit gateway in there too. And that's the way folks get from their cloud back into their on-prem networks. I mean, these things are just tremendously expensive.
They don't scale past, you know, a couple of dozen different connections and, and it's very problematic. So being able to replace these components on a use case by use case basis and then backing into, you know, oh by the way, we can pretty much do all of this network across your entire multi-cloud. Yes, I agree that ultimately this is the way things have to do, but I'm, I'm also understanding and considerate of the fact that it's scary for a lot of these folks to, you know, kind of turn their back on the things that they've been doing for People.
And I, and I think you said a very important thing, which is I want networks that are secure, right? And so what I'm seeing with people is, and this is exactly what we do, so we call it what we do, secure cloud networking. But if you really think about it, I don't view network security and networking as different.
I view them as one thing. The customers are actually organizing that way. Now, Mike, they're combining networking and network security and a lot of time underneath the cso, right?
Because they're not two things anymore. It's one thing. Yeah.
Well, it, it, it, you know, you've got a kind of an infrastructure path and, and you know, kind of then you have folks that are doing platform engineering to build out the templates and able to enable customers to, to do that. Then you've got kind of DevOps and application teams on top of that to, you know, kind of build the, the value ultimately to the business. All these things are so intertwined and, you know, folks think about cloud and they really should in terms of isolation, right?
I wanna isolate where I can, but you know, again, having a, a common foundation that they can plug into that provides the ingress, right? That, that, you know, provides protection on egress. If I have to, you know, have that, that gives me the ability to, you know, take connections from not just customers but employees that gives me the ability to find resources on-prem and data on-prem as I need to, to integrate with past services Inc.
Like Databricks or, uh, a Snowflake or any of these kind of things get tremendously complicated given what we're trying to do in the number of places we're trying to do it at the velocity that's, that it's expected to happen. So, uh, again, I do think programmability is incredibly important. I do think that, you know, kind of having a multi-cloud fabric is going to, uh, re really, you know, be something that, that folks have to consider moving forward.
And ultimately you have to have security baked into that because you can't separate out the two, right? Connectivity without protection in this kind of environment is a killer. Got it.
It will kill you And you have to be the network in order to be able to do that. And that's what you guys are trying to do. Yeah.
Steve Elaney, thank you. Always great to catch up again. You know, when you, there's just so many people that you know that for many years and just to see, you know, kind of the, the different paths that we've all taken.
It's always very interesting. But yeah, great team. I, I do value the time and, and thanks for being here on text, on TV and, um, how, how do folks find you guys.
So just wanna know more. com. So with that, we will send it back to the studio for the next interview.
Again, Steve Elaney, C e o of Aviatrix. Thanks a bunch, man. Thank you.