You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: "A deployable architecture that is based on the IBM Cloud for Financial Services reference and that provides virtual servers in a secure VPC for your workloads."
# Cloud foundation for VPC - Standard (Financial Services edition) variation
47
47
{: #vpc-ra}
48
48
{: toc-content-type="reference-architecture"}
49
49
{: toc-industry="Banking,FinancialSector"}
50
50
{: toc-use-case="Cybersecurity"}
51
51
{: toc-compliance="FedRAMP"}
52
52
{: toc-version="8.5.0"}
53
53
54
-
The Standard variation of the VPC landing zone deployable architecture uses two Virtual Private Clouds (VPC), a Management VPC, and a Workload VPC to manage the environment and the deployed workload. Each VPC is a multi-zoned, multi-subnet implementation that keeps your workloads secure. A transit gateway connects the VPCs to each other and Virtual Private Endpoints are used connect to IBM Cloud services.
54
+
The Standard (Financial Services edition) variation of the Cloud foundation for VPC deployable architecture uses two Virtual Private Clouds (VPC), a Management VPC, and a Workload VPC to manage the environment and the deployed workload. Each VPC is a multi-zoned, multi-subnet implementation that keeps your workloads secure. A transit gateway connects the VPCs to each other and Virtual Private Endpoints are used connect to IBM Cloud services.
55
55
56
56
IBM Cloud Flow Logs for VPC enables the collection and storage of information about the internet protocol (IP) traffic that is going to and from network interfaces within your VPC. In addition, Activity Tracker logs events from enabled services. IBM Cloud Flow Logs for VPC and Activity Tracker are included in this deployable architecture. You can add more security services, such as Hyper Protect Crypto Services.
57
57
58
58
## Architecture diagram
59
59
{: #ra-vpc-architecture-diagram}
60
60
61
-
{: caption="Figure 1. Standard variation of VPC landing zone" caption-side="bottom"}{: external download="vpc.drawio.svg"}
61
+
{: caption="Standard (Financial Services edition) variation of Cloud foundation for VPC" caption-side="bottom"}{: external download="vpc.drawio.svg"}
62
62
63
63
## Design requirements
64
64
{: #ra-vpc-qs-design-requirements}
65
65
66
-
{: caption="Figure 2. Scope of the design requirements" caption-side="bottom"}
66
+
{: caption="Scope of the design requirements" caption-side="bottom"}
67
67
68
68
<!--
69
69
TODO: Add the typical use case for the architecture.
@@ -81,7 +81,7 @@ business challenge, or target cloud environments.
81
81
| * Provide infrastructure/application administration access to monitor, operate, and maintain the environment. \n * Limit the number of infrastructure/application administration entry points to ensure security audit. | Management VPC service |||
82
82
| * Provide infrastructure for service management components like backup, monitoring, IT service management, shared storage \n * Ensure you can reach all IBM Cloud and on-premises services | Workload VPC service |||
83
83
| * Set up network for all created services \n * Isolate network for all created services \n * Ensure all created services are interconnected | Secure landing zone components | Create a minimum set of required components for a secure landing zone | Create a modified set of required components for a secure landing zone in preset |
@@ -91,7 +91,7 @@ business challenge, or target cloud environments.
91
91
| * Isolate management VPC and allow only a limited number of network connections \n * All other connections from or to management VPC are forbidden | ACL and security group rules in management VPC|| More ports might be opened in preset or added manually after deployment |
92
92
| * Isolate workload VPC and allow only a limited number of network connections \n * All other connections from or to workload VPC are forbidden | ACL and security group rules in workload VPC || More ports might be opened in preset or added manually after deployment |
93
93
| Load VPN configuration to simplify VPN setup | VPNs | VPN configuration is the responsibility of the customer ||
0 commit comments