{"id":4480,"date":"2019-07-17T07:13:40","date_gmt":"2019-07-17T05:13:40","guid":{"rendered":"https:\/\/blog.wedos.cz\/?p=4480"},"modified":"2019-07-18T20:48:36","modified_gmt":"2019-07-18T18:48:36","slug":"blizka-budoucnost-aneb-co-nas-ted-ceka","status":"publish","type":"post","link":"https:\/\/blog.wedos.com\/cs\/blizka-budoucnost-aneb-co-nas-ted-ceka","title":{"rendered":"Bl\u00edzk\u00e1 budoucnost aneb co n\u00e1s te\u010f \u010dek\u00e1"},"content":{"rendered":"<p>Pravideln\u011b p\u00ed\u0161eme o p\u0159ipravovan\u00fdch slu\u017eb\u00e1ch jako je t\u0159eba <a href=\"https:\/\/blog.wedos.cz\/wms-webhosting-managed-server-predstaveni-konceptu-sluzby\" target=\"_blank\" rel=\"noopener\">WMS<\/a>, <a href=\"https:\/\/blog.wedos.cz\/wedos-cloud-skutecny-cloud\" target=\"_blank\" rel=\"noopener\">WEDOS Cloud<\/a> anebo <a href=\"https:\/\/blog.wedos.cz\/zvazujeme-b2b-vip-sluzby\" target=\"_blank\" rel=\"noopener\">B2B\/VIP<\/a>. Ty u\u017e jsou v\u0161ak v\u00edcem\u00e9n\u011b za dve\u0159mi. Konkr\u00e9tn\u011b u WMS se lad\u00ed posledn\u00ed detaily pro ve\u0159ejn\u00fd beta test a p\u0159edpokl\u00e1d\u00e1me, \u017ee slu\u017ebu spust\u00edme v srpnu. WEDOS Cloud se zasekl na p\u00e1r mali\u010dkostech, kter\u00e9 technici ji\u017e brzy vy\u0159e\u0161\u00ed a testujeme posledn\u00ed detaily.\u00a0 Nov\u00e1 B2B\/VIP u\u017e je v testovac\u00edm provozu.\u00a0 Co se t\u00fdk\u00e1 Datacentra WEDOS 2, tak tam u\u017e fini\u0161uj\u00ed pr\u00e1ce, aby mohl po pr\u00e1zdnin\u00e1ch za\u010d\u00edt testovac\u00ed provoz. Modernizace Datacenta WEDOS 1 m\u00e1 prvn\u00ed\u00a0 \u010d\u00e1st ze dvou ji\u017e \u00fasp\u011b\u0161n\u011b za sebou. Co bude ale d\u00e1l? \ud83d\ude09<\/p>\n<p><!--more--><\/p>\n<h3>Datacentrum WEDOS 3<\/h3>\n<p>Je velmi odv\u00e1\u017en\u00e9 ps\u00e1t o t\u0159et\u00edm datacentru, kdy\u017e v tom druh\u00e9m je\u0161t\u011b neza\u010dal ani testovac\u00ed provoz.\u00a0 Faktem ale je, \u017ee Datacentrum WEDOS 1 se postupn\u011b pln\u00ed a pokud bychom op\u011bt narazili na dal\u0161\u00ed super nab\u00eddku jakou byla koup\u011b 254 fyzick\u00fdch server\u016f ProLiant DL320e Gen8 v2 za zlomek ceny, tak by to mohl b\u00fdt probl\u00e9m, zvl\u00e1\u0161t\u011b kdy\u017e jsme si jist\u00ed, \u017ee bychom dok\u00e1zali za dobrou cenu prodat i 5x tolik. V\u017edy\u0165 <a href=\"https:\/\/www.wedos.cz\/dedikovane-servery\" target=\"_blank\" rel=\"noopener\">ProLiant DL320e Gen8 v2 je v nab\u00eddce<\/a> jen, kdy\u017e se n\u011bjak\u00fd zrovna uvoln\u00ed.<\/p>\n<p>Z\u00e1rove\u0148 se na n\u00e1s st\u00e1le obrac\u00edte, \u017ee chcete od n\u00e1s housing. Poskytovat v sou\u010dasn\u00e9m datacentru nic takov\u00e9ho v pl\u00e1nu nen\u00ed. V druh\u00e9m datacentru, kter\u00e9 dokon\u010dujeme, housing u\u017e v\u016fbec nep\u0159ipad\u00e1 v \u00favahu&#8230;, proto\u017ee tam je jen a pouze olejov\u00e9 chlazen\u00ed. A popravd\u011b, kdo z v\u00e1s m\u00e1 doma servery, kter\u00e9 lze chladit v oleji? \ud83d\ude42<\/p>\n<p><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/20170616_135529.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"aligncenter size-large wp-image-5081 lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/20170616_135529-1024x576.jpg\" alt=\"\" width=\"525\" height=\"295\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/20170616_135529-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/20170616_135529-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/20170616_135529-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/20170616_135529.jpg 2048w\" data-sizes=\"(max-width: 525px) 100vw, 525px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 525px; --smush-placeholder-aspect-ratio: 525\/295;\" \/><\/a><\/p>\n<p>Na\u0161e prvn\u00ed datacentrum se krok za krokem pln\u00ed. Celkov\u011b se n\u00e1m tam vejde necel\u00fdch 70 rack\u016f, ale v re\u00e1lu po\u010d\u00edteme tak s 52. U\u017e nyn\u00ed je \u010d\u00e1st kapacit obsazen\u00e1 a nyn\u00ed jsme p\u0159e\u0161li na servery HPE Moonshot, kde je obrovsk\u00e1 hustota v\u00fdpo\u010detn\u00edho v\u00fdkonu.<\/p>\n<p>Te\u010f tam m\u00e1me v sou\u010dasn\u00e9m datacentru obsazen\u00fdch n\u011bkolik des\u00edtek rack\u016f a nov\u011b i 26 serverov\u00fdch sk\u0159\u00edn\u00ed HPE Moonshot, na kter\u00fdch jedou v\u0161echny na\u0161e nov\u00e9 slu\u017eby. Vzhledem k tomu, \u017ee do ka\u017ed\u00e9ho boxu HPE Moonshot, kter\u00fd je velk\u00fd 4 a 1\/3 U (tedy jak dva klasick\u00e9 servery) se vejde 45 samostatn\u00fdch fyzick\u00fdch server\u016f, tak je pom\u011brn\u011b n\u00e1ro\u010dn\u00e9 je uchladit, proto mohou b\u00fdt aktu\u00e1ln\u011b v samostatn\u00e9m racku maxim\u00e1ln\u011b 4. Pro jistotu. Ve\u0161lo by se jich tam v\u00edce, ale celkov\u011b by to byl velk\u00fd n\u00e1rok na chlazen\u00ed.\u00a0 Uvid\u00edme do budoucna.<\/p>\n<figure id=\"attachment_564\" aria-describedby=\"caption-attachment-564\" style=\"width: 525px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/01\/P_20171011_124304_vHDR_On.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"wp-image-564 size-large lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/01\/P_20171011_124304_vHDR_On-1024x576.jpg\" alt=\"\" width=\"525\" height=\"295\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/01\/P_20171011_124304_vHDR_On-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/01\/P_20171011_124304_vHDR_On-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/01\/P_20171011_124304_vHDR_On-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/01\/P_20171011_124304_vHDR_On.jpg 2048w\" data-sizes=\"(max-width: 525px) 100vw, 525px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 525px; --smush-placeholder-aspect-ratio: 525\/295;\" \/><\/a><figcaption id=\"caption-attachment-564\" class=\"wp-caption-text\">Kompletn\u011b osazen\u00fd HPE Moonshot v sob\u011b m\u00e1 45 server\u016f, 2x switch, 4x zdroj<\/figcaption><\/figure>\n<p>Na druhou stranu jeden HPE Moonshot vyd\u00e1 za v\u00edce n\u011b\u017e jeden a kus racku b\u011b\u017en\u00fdch server\u016f. To je d\u016fvod, pro\u010d jsme na n\u011b vsadili a pro\u010d stav\u00edme DC2 kompletn\u011b pro olejov\u00e9 chlazen\u00ed, kter\u00e9 je nesrovnateln\u011b efektivn\u011bj\u0161\u00ed a nen\u00ed probl\u00e9m tak doslova zv\u00fd\u0161it hustotu v\u00fdpo\u010detn\u00edho v\u00fdkonu \ud83d\ude42<\/p>\n<p>V druh\u00e9m datacentru bude prostor na cca 240 box\u016f HPE Moonshot, co\u017e je 10.800 fyzick\u00fdch server\u016f. Jedn\u00e1 se o mimo\u0159\u00e1dn\u011b v\u00fdkonn\u00e9 servery. Re\u00e1ln\u011b to je kapacita, kter\u00e1 ut\u00e1hne cel\u00fd \u010desk\u00fd internet a je\u0161t\u011b zbyde. Tak to mus\u00edme zaplnit.<\/p>\n<p>Prost\u011b nechceme nech\u00e1vat nic n\u00e1hod\u011b a DC3 (Datacentrum 3) jsme museli p\u0159esunout ze st\u0159edn\u011bdob\u00e9ho pl\u00e1nu do situace &#8222;pot\u0159ebujeme te\u010f&#8220; \ud83d\ude42<\/p>\n<p>V sou\u010dasn\u00e9 dob\u011b u\u017e <strong>m\u00e1me pozemek<\/strong>, p\u0159ipravuje se<strong> projektov\u00e1 dokumentace<\/strong> a do konce pr\u00e1zdnin se rozhodneme na 100%, zda budeme stavbu realizovat hned nyn\u00ed nebo ne a a\u017e n\u011bkdy v budoucnu. Pokud nyn\u00ed, tak bychom na podzim r\u00e1di za\u017e\u00e1dali o stavebn\u00ed povolen\u00ed. Mezit\u00edm si nech\u00e1me ud\u011blat \u017eelezobetonov\u00e9 &#8222;sou\u010d\u00e1stky&#8220; na m\u00edru a jakmile dostaneme stavebn\u00ed povolen\u00ed, tak si DC3 WEDOS do p\u00e1r t\u00fddn\u016f prost\u011b slo\u017e\u00edme.<\/p>\n<p>Pokud v\u0161e p\u016fjde podle pl\u00e1n\u016f, tak v druh\u00e9 polovin\u011b 2020 u\u017e bychom r\u00e1di d\u011blali na technologick\u00e9 infrastruktu\u0159e DC3 a od po\u010d\u00e1tku roku 2021 rozjeli pln\u00fd provoz.<\/p>\n<p>P\u0159edpokl\u00e1d\u00e1me, \u017ee v\u0161e p\u016fjde rychle, proto\u017ee nebudeme \u0159e\u0161it p\u0159\u00edpravu na certifikaci TIER IV,\u00a0 jako tomu bylo u DC2. Nebude to ani tak jedine\u010dn\u00fd projekt kv\u016fli olejov\u00e9mu chlazen\u00ed. Ud\u011bl\u00e1me si hezk\u00e9 nov\u00e9 modern\u00ed datacentrum, pro b\u011b\u017en\u00fd provoz. \u017d\u00e1dn\u00e9 zbyte\u010dn\u00e9 vymo\u017eenosti. Jen v\u0161e nadstandardn\u011b z\u00e1lohovan\u00e9, X kr\u00e1t 100 Gbps trasy a zva\u017eujeme i takov\u00fd speci\u00e1ln\u00ed serverhousing nejen pro jiho\u010desk\u00e9 IT firmy.\u00a0 Ale nep\u0159edb\u00edhejme. Uvid\u00edme, jak fin\u00e1ln\u011b dopadne projektov\u00e1 dokumentace \ud83d\ude09<\/p>\n<p>Ve v\u00fdsledku po\u010d\u00edt\u00e1me s t\u00edm, \u017ee mezit\u00edm spust\u00edme druh\u00e9 datacentrum, dokon\u010d\u00edme upgrade prvn\u00edho (v\u0161e naprosto du\u00e1ln\u011b rozd\u011blujeme na maxim\u00e1ln\u00ed spolehlivost &#8211; inspirovali jsme se n\u00e1pady z TIER IV).\u00a0 T\u00edm se n\u00e1m uvoln\u00ed ruce a n\u011bkolik na\u0161ich lid\u00ed, kte\u0159\u00ed se pod\u00edlej\u00ed na v\u00fdstavb\u011b druh\u00e9ho a na upgradu prvn\u00edho datacentra, se za\u010dne nudit \ud83d\ude42 To samoz\u0159ejm\u011b p\u0159eh\u00e1n\u00edme.\u00a0<\/p>\n<p>Do v\u00fdstavby druh\u00e9ho datacentra jsme nainvestovali ji\u017e p\u0159es 50 milion\u016f korun. V t\u00e9to \u010d\u00e1stce po\u010d\u00edt\u00e1me jen stavebn\u00ed pr\u00e1ce a investice do vybaven\u00ed. Nejsou v tom zahrnut\u00e9 n\u011bjak\u00e9 r\u016fzn\u00e9 n\u00e1klady s t\u00edm souvisej\u00edc\u00ed (nap\u0159\u00edklad 3 nov\u00e9 optick\u00e9 trasy nebo trasa chlazen\u00ed)&#8230; To jsou dal\u0161\u00ed miliony. Nejsou tam zahrnut\u00e9 ani n\u00e1klady na mzdy n\u011bkolika lid\u00ed, kte\u0159\u00ed se stavb\u011b v\u011bnuj\u00ed prakticky na pln\u00fd \u00favazek ji\u017e n\u011bkolik let. V\u0161e si \u0159e\u0161\u00edme vlastn\u00edmi silami, stavbu si \u0159\u00edd\u00edme vlastn\u00edmi lidmi a velkou \u010d\u00e1st realizace d\u011bl\u00e1me tak\u00e9 ve vlastn\u00ed re\u017eii.\u00a0 Tohle jsou dal\u0161\u00ed a dal\u0161\u00ed miliony korun (respektive \u010d\u00e1stka bl\u00ed\u017e\u00edc\u00ed pomalu k 20 milion\u016fm korun). Celkov\u011b to tedy nen\u00ed \u017e\u00e1dn\u00e1 drobn\u00e1 investice, ale z\u00e1le\u017eitost, kdy n\u00e1s to bude st\u00e1t re\u00e1ln\u011b kolem 100 milion\u016f korun. A to v tom nen\u00ed jeden jedin\u00fd server&#8230; To v\u00edte, ale v\u0161e je n\u011bkolikan\u00e1sobn\u011b ji\u0161t\u011bn\u00e9. V druh\u00e9m datacentru najdete nap\u0159\u00edklad 5 motorgener\u00e1tor\u016f, 4 druhy chlazen\u00ed, r\u016fzn\u00e9 nez\u00e1visl\u00e9 nap\u00e1jen\u00ed bez soub\u011bhu (jedno pod stropem a druh\u00e9 pod podlahou a ka\u017ed\u00e9 z jin\u00e9 strany budovy), v\u0161e neho\u0159lav\u00e9 nebo s funk\u010dn\u00ed odolnost\u00ed proti po\u017e\u00e1ru na 90 minut&#8230;<\/p>\n<p>U t\u0159et\u00edho datacentra naopak po\u010d\u00edt\u00e1me s v\u00fdrazn\u011b men\u0161\u00edmi n\u00e1klady.\u00a0<\/p>\n<h3>World Wide WEDOS aneb celosv\u011btov\u00e1 WEDOS CDN<\/h3>\n<p>V roce 2014 jsme se stali c\u00edlem rozs\u00e1hl\u00fdch a dlouhotrvaj\u00edc\u00edch DDoS \u00fatok\u016f. Tehdy jsme pochopili, \u017ee pokud chceme p\u0159e\u017e\u00edt a r\u016fst, tak mus\u00ed b\u00fdt kybernetick\u00e1 bezpe\u010dnost na\u0161\u00ed prioritou. Ro\u010dn\u011b tak investujeme v\u00edce jak 10 % v\u0161ech n\u00e1klad\u016f do v\u00fdvoje a rozvoje na\u0161ich bezpe\u010dnostn\u00edch technologi\u00ed.<\/p>\n<p>K dne\u0161n\u00edmu dni jsme odfiltrovali 670.851 DDoS \u00fatok\u016f!!!<\/p>\n<figure id=\"attachment_104\" aria-describedby=\"caption-attachment-104\" style=\"width: 525px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/20160824_075325.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"size-large wp-image-104 lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/20160824_075325-1024x576.jpg\" alt=\"\" width=\"525\" height=\"295\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325.jpg 2048w\" data-sizes=\"(max-width: 525px) 100vw, 525px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 525px; --smush-placeholder-aspect-ratio: 525\/295;\" \/><\/a><figcaption id=\"caption-attachment-104\" class=\"wp-caption-text\">Sondy &#8211; servery pro detekci z\u00e1vadn\u00fdch paket\u016f m\u00e1me v r\u016fzn\u00fdch pra\u017esk\u00fdch datacentrech. V roce 2016 prob\u011bhl jejich rozs\u00e1hl\u00fd upgrade.<\/figcaption><\/figure>\n<p>Dostali jsme se tak do stavu, kdy m\u00e1me a um\u00edme poskytnout jedno z nejbezpe\u010dn\u011bj\u0161\u00edch \u0159e\u0161en\u00ed na ochranu p\u0159ed kybernetick\u00fdmi \u00fatoky v \u010cR. Pravideln\u011b k n\u00e1m chod\u00ed n\u00e1v\u0161t\u011bvy z velk\u00fdch IT spole\u010dnost\u00ed a kdy\u017e vid\u00ed, jakou masivn\u00ed bezpe\u010dnostn\u00ed infrastrukturu se n\u00e1m poda\u0159ilo za ty roky vybudovat, tak n\u00e1m \u0159\u00edkaj\u00ed, \u017ee by se jim taky l\u00edbila a hned by j\u00ed vym\u011bnili za to, co pou\u017e\u00edvaj\u00ed.<\/p>\n<p>Um\u00edme filtrovat \u00fatoky o s\u00edle des\u00edtek Gbps, tedy \u010distit provoz. Aktu\u00e1ln\u011b m\u00e1me na Hlubokou konektivitu\u00a0 3x 100Gbps (fyzicky 3 r\u016fzn\u00e9 trasy od 2 r\u016fzn\u00fdch poskytovatel\u016f do 2 r\u016fzn\u00fdch lokalit), co\u017e z n\u00e1s d\u011bl\u00e1 prakticky nejl\u00e9pe p\u0159ipojen\u00e9 datacentrum v regionu. Do internetu m\u00e1me konektivitu od n\u011bkolika poskytovatel\u016f a v sou\u010dtu je\u0161t\u011b vy\u0161\u0161\u00ed.<\/p>\n<figure id=\"attachment_5294\" aria-describedby=\"caption-attachment-5294\" style=\"width: 548px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/ddod-37gbps.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"size-full wp-image-5294 lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/ddod-37gbps.png\" alt=\"\" width=\"548\" height=\"259\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/ddod-37gbps.png 548w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/ddod-37gbps-300x142.png 300w\" data-sizes=\"(max-width: 548px) 100vw, 548px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 548px; --smush-placeholder-aspect-ratio: 548\/259;\" \/><\/a><figcaption id=\"caption-attachment-5294\" class=\"wp-caption-text\">37 Gbps DDoS \u00fatok. D\u00edky 100 Gbps lince v re\u00e1ln\u00e9m \u010dase detekov\u00e1n, zanalyzov\u00e1n a nasazena filtrace. C\u00edl to ani nezjistil. Tak vypad\u00e1 automatizace po 6 letech v\u00fdvoje, kter\u00e1 um\u00ed zajistit klid va\u0161emu webu v \u0159\u00e1dech vte\u0159in.<\/figcaption><\/figure>\n<figure id=\"attachment_5296\" aria-describedby=\"caption-attachment-5296\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/248-Gbps-utok.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"size-full wp-image-5296 lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/248-Gbps-utok.png\" alt=\"\" width=\"500\" height=\"135\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/248-Gbps-utok.png 500w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/248-Gbps-utok-300x81.png 300w\" data-sizes=\"(max-width: 500px) 100vw, 500px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 500px; --smush-placeholder-aspect-ratio: 500\/135;\" \/><\/a><figcaption id=\"caption-attachment-5296\" class=\"wp-caption-text\">DDoS \u00fatok 24,8 Gbps na na\u0161em ve\u0159ejn\u00e9m grafu p\u0159enos\u016f. Jak vid\u00edte na modr\u00e9 \u010d\u00e1\u0159e (p\u0159enosy ven), tak slu\u017eeb na\u0161ich z\u00e1kazn\u00edk\u016f se to nijak nedotklo.<\/figcaption><\/figure>\n<p>Za\u010dali jsme se tak\u00e9 v\u011bnovat IPS\/IDS ochran\u00e1m, postaven\u00fdm na technologii deep packet inspection a strojov\u00e9m u\u010den\u00ed. V b\u011b\u017en\u00e9m provozu maj\u00ed na\u0161e IPS\/IDS ochrany p\u0159es dvacet tis\u00edc aktivn\u00edch filtr\u016f, jejich\u017e po\u010det se neust\u00e1le m\u011bn\u00ed podle aktu\u00e1ln\u00edch hrozeb.<\/p>\n<p>Dok\u00e1\u017eeme tak br\u00e1nit nap\u0159\u00edklad weby p\u0159ed r\u016fzn\u00fdmi chybami v redak\u010dn\u00edch syst\u00e9mech. Aktu\u00e1ln\u011b jen na HTTP, ale ji\u017e brzo na HTTPS.\u00a0<\/p>\n<figure id=\"attachment_5298\" aria-describedby=\"caption-attachment-5298\" style=\"width: 525px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/IDS-IPS.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"size-large wp-image-5298 lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/07\/IDS-IPS-1024x249.png\" alt=\"\" width=\"525\" height=\"128\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/IDS-IPS-1024x249.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/IDS-IPS-300x73.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/IDS-IPS-768x187.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/07\/IDS-IPS.png 1066w\" data-sizes=\"(max-width: 525px) 100vw, 525px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 525px; --smush-placeholder-aspect-ratio: 525\/128;\" \/><\/a><figcaption id=\"caption-attachment-5298\" class=\"wp-caption-text\">Nasazen\u00ed IPS\/IDS ochrany na testovac\u00edm vzorku v roce 2016. B\u011bhem 15 minut prov\u011b\u0159eno t\u00e9m\u011b\u0159 6 milion\u016f paket\u016f.<\/figcaption><\/figure>\n<p>Tento rok jsme \u00fasp\u011b\u0161n\u011b nasadili <a href=\"https:\/\/blog.wedos.cz\/lepsi-a-prisnejsi-filtrace-utoku-a-zbytecnych-robotu-u-webhostingu\" target=\"_blank\" rel=\"noopener\">nov\u00fd druh velmi rychl\u00e9 ochrany webov\u00fdch aplikac\u00ed<\/a> na z\u00e1klad\u011b na\u0161eho &#8222;priv\u00e1tn\u00edho honeypotu&#8220;, kter\u00fd v podstat\u011b tvo\u0159\u00ed data z v\u00edce jak sto t\u0159iceti tis\u00edc dom\u00e9n. Tato data zpracov\u00e1v\u00e1me a vyhodnocujeme v re\u00e1ln\u00e9m \u010dase. Nav\u00edc filtry funguj\u00ed i p\u0159i extr\u00e9mn\u011b siln\u00e9m \u00fatoku, kter\u00fd by b\u011b\u017enou IPS\/IDS ochranu dok\u00e1zal odstavit.<\/p>\n<p>Jen pro p\u0159edstavu &#8211; p\u0159es 43% paket\u016f\u00a0 v\u016fbec do na\u0161\u00ed s\u00edt\u011b nepust\u00edme a rovnou filtrujeme na vstupu. O tohle jsou na\u0161e servery &#8222;ochuzeny&#8220;.\u00a0<\/p>\n<figure id=\"attachment_1670\" aria-describedby=\"caption-attachment-1670\" style=\"width: 525px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/04\/nasazeni-automaticke-ochrany.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"wp-image-1670 size-large lazyload\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2019\/04\/nasazeni-automaticke-ochrany-1024x355.png\" alt=\"\" width=\"525\" height=\"182\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/04\/nasazeni-automaticke-ochrany-1024x355.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/04\/nasazeni-automaticke-ochrany-300x104.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/04\/nasazeni-automaticke-ochrany-768x266.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2019\/04\/nasazeni-automaticke-ochrany.png 1123w\" data-sizes=\"(max-width: 525px) 100vw, 525px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 525px; --smush-placeholder-aspect-ratio: 525\/182;\" \/><\/a><figcaption id=\"caption-attachment-1670\" class=\"wp-caption-text\">Prvn\u00ed nasazen\u00ed nov\u00e9ho druhu ochrany a jej\u00ed vliv na 10 nejvyt\u00ed\u017een\u011bj\u0161\u00edch webhosting\u016f. Na grafu je vid\u011bt, jak ochrana postupn\u011b sb\u00edr\u00e1 data a vyhodnocuje \u00fatoky. Ty postupn\u011b filtruje, a\u017e z\u016fstane jen \u010dist\u00fd provoz.<\/figcaption><\/figure>\n<p>Tak\u017ee m\u00e1me v podstat\u011b 3 odli\u0161n\u00e9 technologie zji\u0161\u0165ov\u00e1n\u00ed \u00fatok\u016f a ka\u017ed\u00e1 filtruje jin\u00fdm zp\u016fsobem. V p\u0159\u00edpad\u011b nouze dok\u00e1\u017ee jedna ochr\u00e1nit weby, kdy\u017e ta druh\u00e1 by m\u011bla v\u00fdpadek. Ale hlavn\u00ed je to, \u017ee se mezi sebou vz\u00e1jemn\u011b dopl\u0148uj\u00ed.\u00a0<\/p>\n<p>\u0158ekli jsme si, \u017ee kdy\u017e tohle v\u0161echno m\u00e1me, tak pro\u010d nenab\u00eddnout bezpe\u010dn\u00fd WEDOS prostor i pro ostatn\u00ed. Na\u0161i z\u00e1kazn\u00edci s WEDOS NoLimit jsou u\u017e chr\u00e1n\u011bni kompletn\u011b (DDoS i IPS\/IDS). Slu\u017eby VPS SSD, VPS ON a dedikovan\u00e9 servery chr\u00e1n\u00ed DDoS ochrana \u010d\u00e1ste\u010dn\u011b (do 1 Gbps, p\u0159i nov\u00fdch \u00fatoc\u00edch experiment\u00e1ln\u011b i daleko v\u00edce &#8211; sb\u00edr\u00e1me data a zku\u0161enosti).<\/p>\n<p>Letos jsme cht\u011bli spustit celosv\u011btovou anycast DNS slu\u017ebu a tohle je v podstat\u011b dal\u0161\u00ed krok.<\/p>\n<p>P\u0159i volb\u011b vhodn\u00e9ho \u0159e\u0161en\u00ed jsme zjistili, \u017ee by nebyl probl\u00e9m propojit tyto na\u0161e anti DDoS a IDS\/IPS technologie s na\u0161\u00ed WEDOS proxy a ji\u017e zam\u00fd\u0161lenou Anycast DNS. V podstat\u011b tak m\u016f\u017eeme provozovat skute\u010dnou CDN s ochranou. Respektive sp\u00ed\u0161e to bude ochrana s dopl\u0148kovou slu\u017ebou CDN po cel\u00e9m sv\u011bt\u011b.<\/p>\n<p>Podle n\u00e1vrh\u016f n\u00e1m bude sta\u010dit v prvn\u00ed f\u00e1zi vybrat 5 v\u00fdznamn\u00fdch sv\u011btov\u00fdch lokalit a do ka\u017ed\u00e9 um\u00edstit celkem 45 fyzick\u00fdch server\u016f na 2x 100 Gbps linku. Do budoucna po\u010d\u00edt\u00e1me s t\u00edm, \u017ee t\u011bch lokalit m\u016f\u017ee b\u00fdt n\u011bkolik des\u00edtek nebo stovek po cel\u00e9m sv\u011bt\u011b.<\/p>\n<p>V t\u00e9to v\u011bci u\u017e jsme provedli prvn\u00ed kroky a kontaktovali potenci\u00e1ln\u00ed partnery, kte\u0159\u00ed maj\u00ed pot\u0159ebn\u00e9 z\u00e1zem\u00ed v zahrani\u010d\u00ed. Domlouv\u00e1me detaily. Letos bychom cht\u011bli slu\u017ebu nab\u00eddnout v\u0161em klient\u016fm.<\/p>\n<p>Po\u017e\u00e1dali jsme RIPE o p\u0159id\u011blen\u00ed nov\u00e9ho autonomn\u00edho syst\u00e9mu, nov\u00e9ho rozsahu IP adres, kter\u00e9 budeme pou\u017e\u00edvat pro novou anycast slu\u017ebu.\u00a0 Chceme to m\u00edt zcela odd\u011blen\u00e9 od st\u00e1vaj\u00edc\u00edch slu\u017eeb i z tohoto pohledu.<\/p>\n<p><strong>P\u0159em\u00fd\u0161l\u00edme nad fin\u00e1ln\u00edm n\u00e1zvem&#8230; N\u011bjak\u00e9 n\u00e1pady m\u00e1me. Pokud n\u00e1m porad\u00edte, tak V\u00e1m\u00a0 nab\u00eddneme antiDDOoS do\u017eivotn\u011b zdarma \ud83d\ude42 <a href=\"https:\/\/client.wedos.com\/contact\/cform.html?nologin=1\" target=\"_blank\" rel=\"noopener\">Napi\u0161te n\u00e1m.<\/a><\/strong><\/p>\n<p>Moment\u00e1ln\u011b tak\u00e9 p\u0159em\u00fd\u0161l\u00edme nad vhodn\u00fdm obchodn\u00edm modelem. Chceme ur\u010dit\u011b ud\u011blat z\u00e1kladn\u00ed verzi ve velmi levn\u00e9m proveden\u00ed nebo zdarma, pak jeden levn\u011bj\u0161\u00ed tarif pro b\u011b\u017en\u00e9 sd\u00edlen\u00e9 webhostingy a hodn\u011b vymazlenou variantu pro hodn\u011b nav\u0161t\u011bvovan\u00e9 komer\u010dn\u00ed projekty.<\/p>\n<p>O t\u00e9to nov\u00e9 slu\u017eb\u011b nap\u00ed\u0161eme v\u00edce detail\u016f v nejbli\u017e\u0161\u00edch dnech.<\/p>\n<h3>Z\u00e1v\u011br<\/h3>\n<p>A to nen\u00ed zdaleka v\u0161e. M\u00e1me rozjet\u00e9 dal\u0161\u00ed projekty, kter\u00e9 postupn\u011b odhal\u00edme. N\u011bkter\u00e9 zde na blogu jin\u00e9 snad u\u017e na konferenc\u00edch v na\u0161em druh\u00e9m datacentru \ud83d\ude42<\/p>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pravideln\u011b p\u00ed\u0161eme o p\u0159ipravovan\u00fdch slu\u017eb\u00e1ch jako je t\u0159eba WMS, WEDOS Cloud anebo B2B\/VIP. Ty u\u017e jsou v\u0161ak v\u00edcem\u00e9n\u011b za dve\u0159mi. Konkr\u00e9tn\u011b u WMS se lad\u00ed posledn\u00ed detaily pro ve\u0159ejn\u00fd beta test a p\u0159edpokl\u00e1d\u00e1me, \u017ee slu\u017ebu spust\u00edme v srpnu. WEDOS Cloud se zasekl na p\u00e1r mali\u010dkostech, kter\u00e9 technici ji\u017e brzy vy\u0159e\u0161\u00ed a testujeme posledn\u00ed detaily.\u00a0 Nov\u00e1 &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.wedos.com\/cs\/blizka-budoucnost-aneb-co-nas-ted-ceka\" class=\"more-link\">Pokra\u010dovat ve \u010dten\u00ed<span class=\"screen-reader-text\"> &#8222;Bl\u00edzk\u00e1 budoucnost aneb co n\u00e1s te\u010f \u010dek\u00e1&#8220;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":5284,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[82,43,84,83],"class_list":["post-4480","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-spolecnost","tag-dc3","tag-ddos-ochrana","tag-ips-ids-ochrana","tag-ochrana"],"_links":{"self":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/4480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/comments?post=4480"}],"version-history":[{"count":26,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/4480\/revisions"}],"predecessor-version":[{"id":6022,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/4480\/revisions\/6022"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media\/5284"}],"wp:attachment":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media?parent=4480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/categories?post=4480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/tags?post=4480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}