Automating Network Security Profiles. Vivek Kashyap Senior Technical Staff Member Linux Technology Center IBM
|
|
- Toby Day
- 7 years ago
- Views:
Transcription
1 Automating Network Security Profiles Vivek Kashyap Senior Technical Staff Member Linux Technology Center IBM
2 Cloud Interface Cloud Controller Image repository Domain 1 Control Domain N Control Host 1 Host 2 Host 3 Domain 1 Image Application Operating System Virtualization Image Application Operating System Image Application Operating System Virtual Server Virtual Server Virtual Server Compute Storage Memory Network Host 1 Host 2 Host 3 Domain n Multiple images deployed on physical nodes in the DataCenter/Cloud Network isolation a must for a viable multi-tenant solution Collaborative applications may be on same virtual network vivk@us.ibm.com Linux Collaboration Summit,
3 Network View Switch Virtual Switch Port Profile Server Virtual Switch Switch Switch Domain Edge Port Definition External External Network Network DataCenter consists of large number of physical and virtual switches Applications with different network profiles Host vswitch provides guest-guest switching, filtering, bandwidth control Error-prone managing large deployments Virtual switch is not integrated with network fabric management > inconsistencies and manual verification For load-balancing, resiliency the K guests are mobile Network policies must continue to be applied to the K guest workload > Manually ensure target are correctly configured to support network profiles > Physical port security/profiles need to be re-programmed with mobility vivk@us.ibm.com Linux Collaboration Summit, 2011
4 Linux Virtual Networking Linux/K * VEB VEB * F PCIe Adapter Enet Port PF VF * VF : VEB Enet Port VF PCIe IOV *Packet switching and filtering function * Adjacent Switch vivk@us.ibm.com Linux Collaboration Summit,
5 Automating Physical/Virtual Switching * F PCIe Adapter Enet Port Linux/K VEB * VEPA F PCIe Adapter Enet Port Adjacent Switch Port in Reflective Relay Mode Edge Virtual Bridging: IEEE 802.1Qbg Offload switching function to external bridge 's virtual interface directly tied to physical switch port policies Simplified VEPA (Virtual Ethernet Port Aggregator) bridging in hypervisor to send all packets to adjacent bridge. > Provides packet replication of inbound frames. Physical switch port put in 'reflective relay' mode > Sends packets back over same port Con: Introduces limited latency VEPA: Virtual Ethernet Port Aggregator VEB: Virtual Ethernet Bridge (or, Linux bridge) vivk@us.ibm.com Linux Collaboration Summit,
6 How Does it Work? The network profile Used by one or more s Unique id Stored in database Switch advertises 802.1Qbg support Linux/K host receives advertisement Configures switch port in VEPA (hairpin_mode) Offloads switching function Linux/K sends to switch unique id of network profile MAC/VLAN information Switch retrieves profile vswitch (a.k.a. VEB) Domain Edge Port Definition Switch VEPA Switch Port Profile Database External Network External Network Switch VEB Enforces bandwidth, Access controls vivk@us.ibm.com Linux Collaboration Summit,
7 Creating a K Guest System Admin Create new s network state (i.e. MAC Address, VLAN ID, VSI state*) Network Admin 3 System Manager Query available VSI types Obtain a VSI instance 2 Network (VSI Type) Manager Request creation of. Send VSI state*, MAC address, VLAN id. 4 Load VSI Type 6 Server Linux host Libvirt CIM Libvirt VSI Discovery and Configuration Protocol (VDP) associate LLDPAD EDP/VDP User Space Daemon Apps K with VEPA 5 On success from step 5, libvirt instantiates and starts the 7 8 Apps Switch (a.k.a. Bridge) begins communication, through K VEPA 0 Create set of VSI Types VSI Type Database L2 net(s) *VSI state consists of the following: VSI Manager ID, VSI Instance ID, VSI Type ID, VSI Type Version. vivk@us.ibm.com Linux Collaboration Summit,
8 Simple extension to libvirt The VSI state is specified using the following domain XML extension <interface type='direct'/> <source dev='device name' mode='vepa' /> <model type='virtio'/> <virtualport type='802.1qbg'> <parameters managerid='12' typeid='0x123456' typeidversion='1' instanceid='insert-uuid-here' /> </virtualport> </interface> Libvirt parses 'virtualport type' Sends netlink message with 'ASSOCIATE' request to LLDPAD LLDPAD sends ASSOCIATE VDP message Returns success or failure On success K guest is created vivk@us.ibm.com Linux Collaboration Summit,
9 Migration Steps Source Server Apps 5 Move to VDP Pre-Associate state Switch (a.k.a. Bridge) Apps VEB or VEPA 8 Push Move After target up, De- Associate and terminate 4 System Admin migrate Manager VSI Type Database VSI Manager Pre-Associate to server s virtualization infrastructure Associate & Start-up 3 1 Retrieve VSI Information VDP Associate Target Server Apps Apps VEB or VEPA Switch (a.k.a. Bridge) is brought on-line after VDP completes VDP Pre-Associate with Resource Reservation L2 net(s) vivk@us.ibm.com Linux Collaboration Summit,
10 Automatic Host based Virtual Switching Host vswitch Linux bridge + ebtables/iptables + tc OpenVswitch (not in mainline) Administrative simplification: Associate filter rules to Virtual machines Rules enforced in the kernel when guest started Rules torn down when the guest is terminated Rules may be modified at runtime Rules may contain macros which get instantiated at runtime > IP Address, MAC address, more possible» DHCP Snooping/first packet to determine IP Address vivk@us.ibm.com Linux Collaboration Summit,
11 Example Filter <filter name='no-ip-spoofing' chain='ipv4'> <uuid>fce8ae33-e69e-83bf-262e-30786c1f8072</uuid> <rule action='drop' direction='out' priority='500'> <ip match='no' srcipaddr='$ip'/> </rule> </filter> This filter may now be referenced with any guest by adding to the 'interface' element in the guest domain: <interface type='bridge'> <mac address='52:54:00:56:44:32'/> <source bridge='br1'/> <ip address=$ip/> <target dev='vnet0'/> <model type='virtio'/> <filterref filter='no-ip-spoofing'/> </interface> Linux Collaboration Summit,
12 Status Linux onwards VEPA mode (for IEEE 802.1Qbg support) Bridging between virtual interfaces Vhost-net interface for Qemu GSO/GRO acceleration for macvtap Libvirt ( VEPA and VSI support > Netlink notifications for VDP protocol (to LLDPAD) Support for host based filter rules LLDPAD: Version lldpad (open-lldp.org) > EVB TLVs, ECP/VDP Libvirt-CIM: Support for specifying VEPA, VSI state Linux Collaboration Summit,
13 A peek into the Future: Network Profile Automation Linux/K: Manager Push & vport 2 Configuration to CIM provider (libvirt CIM) Host or direct libvirt interface Based on host capabilities and domain policy: Create ACL rules utilizing the linux virtualization library(libvirt) or Image library OVF Create/use existing VSI profile to impose on the guest Network extensions Include filters in the Virtual Machine meta data (e.g. in the OVF) Filters takes macros, that are instantiated at deployment (as shown with libvirt) Management tooling uses it to create libvirt rules or vis data profiles Edge Query available port profile types vswitch 1 Port Profile Database DB Client Interface DB-to-switch Interface Switch Edge Retrieve Port D Configuration 4 A 3 C vport Discovery IEEE Server 802.1Qbg Edgeprotocol support B L2 net(s) Port Profile DB Schema vivk@us.ibm.com Linux Collaboration Summit, 2011
14 Legal Statement This work represents the view of the author and does not necessarily represent the view of IBM. IBM is a registered trademark of International Business Machines Corporation in the United States and/or other countries. UNIX is a registered trademark of The Open Group in the United States and other countries. Linux is a registered trademark of Linus Torvalds in the United States, other countries, or both. Other company, product, and service names may be trademarks or service marks of others. vivk@us.ibm.com Linux Collaboration Summit,
15 Questions? Linux Collaboration Summit,
16 802.1Qbg Protocols External Virtual Bridging protocol (EVB) uses LLDP as transport Defines locus of to switching > Set VEPA or Bridge mode Channel Discovery and Configuration Protocol (CDCP) [Not Implemented] Virtualize the physical link to simultaneously support multiple VEPA/VEB components Edge Control Protocol (ECP) ECP provides a reliable, acknowledged protocol for VDP rather than using LLDP. Virtual Station Interface (VSI) Discovery Protoco(VDP) Associate and De-associate interface MAC/VLAN to port profile For specification go to: IEEE 802.1Qbg version 0 Specification vivk@us.ibm.com Linux Collaboration Summit,
17 Destroy Guest Server Linux host libvirt- CIM Libvirt LLDPAD EDP/VDP User Space Daemon Apps Apps 3 is destroyed 1 Virsh -c qemu:///system shutdown <kvm_guest> K with VEPA VSI Discovery and Configuration Protocol (VDP) deassociate 2 Switch (a.k.a. Bridge) L2 net(s) vivk@us.ibm.com Linux Collaboration Summit,
18 Linux K Components Management Entity Libvirt-CIM Provider Libvirt LLDPAD ECP/VDP User Space Daemon Apps K with VEPA/VEB Apps Enablement of 'macvtap' Linux virtualization library framework (libvirt) Configure interfaces in VEPA or VEB (Bridge)Mode Enforce ACLs on the VEB virtual port Support for creation, destroy and migration of K guests () Trigger of IEEE 802.1Qbg protocols with K guest life-cycle events VSI Profile Database Switch (a.k.a. Bridge) L2 net(s) VSI: Virtual station interface (a.k.a virtual interface or vnic) 802.1Qbg protocols implemented in LLDPAD daemon VDP : VSI Discovery Protocol *VSI state consists of the following: VSI Manager ID, VSI Instance ID, VSI Type ID, VSI Type Version. vivk@us.ibm.com Linux Collaboration Summit, ECP: Edge Control Protocol LLDP extensions for switch mode (Ethernet Virtual Bridging TLVs)
19 MACVTAP: VEPA interface Goal: Share a single Ethernet NIC between K guest interfaces with no bridging function except replication of incoming multicast/broadcast packets Implementation: Utilize existing 'macvlan' driver already supported in Linux Create a 'macvtap' device driver that plugs into a macvlan driver to interface to K guest > Macvtap driver implements tun/tap-like interface > Frames sent from guest put directly into queue of outbound interface > Frames received put in guests receive path vivk@us.ibm.com Linux Collaboration Summit,
20 Libvirt: VEPA interface Macvtap is tied specifically to an interface that provides uplink connectivity Define it in guest's domain xml as: <interface type='direct'/> <source dev='device name' mode='vepa' /> <model type='virtio'/> </interface> Additional modes defined: bridge and pepa Libvirt creates (and destroys) macvtap devices Passes macvtap file-descriptor to QEMU (similar to the case with tap interface) AF_NETLINK socket to create (and destroy) macvtap interface Linux Collaboration Summit,
Automating Virtual Machine Network Profiles
Automating Virtual Machine Network Profiles Vivek Kashyap kashyapv@us.ibm.com Gerhard Stenzel Gerhard.Stenzel@de.ibm.com Arnd Bergman arndb@de.ibm.com Stefan Berger stefanb@us.ibm.com Jens Osterkamp Jens.Osterkamp@de.ibm.com
More informationEthernet Virtual Bridging Automation Use Cases
Ethernet Virtual Bridging Automation Use Cases Renato Recio, Sivakumar Krishnasamy and Rakesh Sharma Abstract Managing the Ethernet switches is a complex task in today s Data Centers, as a lot of network
More informationVirtual networking technologies at the server-network edge
Virtual networking technologies at the server-network edge Technology brief Introduction... 2 Virtual Ethernet Bridges... 2 Software-based VEBs Virtual Switches... 2 Hardware VEBs SR-IOV enabled NICs...
More informationDCB for Network Virtualization Overlays. Rakesh Sharma, IBM Austin IEEE 802 Plenary, Nov 2013, Dallas, TX
DCB for Network Virtualization Overlays Rakesh Sharma, IBM Austin IEEE 802 Plenary, Nov 2013, Dallas, TX What is SDN? Stanford-Defined Networking Software-Defined Networking Sexy-Defined Networking Networking
More informationStandardizing Data Center Server- Network Edge Virtualization
Standardizing Data Center Server- Network Edge Virtualization October 2010 The following companies collaborated in the development of this white paper: Blade Network Technologies, Broadcom, Brocade, Citrix,
More informationHuawei Enterprise A Better Way VM Aware Solution for Data Center Networks
Huawei Enterprise A Better Way VM Aware Solution for Data Center Networks HUAWEI TECHNOLOGIES CO., LTD. Contents Server Virtualization Challenges in Data Center Networks Huawei VM Aware Solution Implementation
More informationVirtual Ethernet Bridging
Virtual Ethernet Bridging Mike Ko Renato Recio IBM IO Shared Through Virtualization Intermediary (e.g. Hypervisor) 2007 Standard High Volume Server PCI Device Sharing Example Operating Systems (a.k.a.
More informationControl Tower for Virtualized Data Center Network
Control Tower for Virtualized Data Center Network Contents 1 Virtual Machine Network Environment Analysis...3 2 "Control Tower" Must Have an Overall Picture of the Network...4 3 Virtual Machine Migration
More informationCloud Networks Uni Stuttgart
Cloud Networks Uni Stuttgart Gerhard Koch IBM Distinguished Engineer WW Engineering & Delivery Cloud SSA Network Inhibitors today to Cloud technologies Role of the Network in Cloud DC s Concrete Realization
More informationAutomated Migration of Port Profile for Multi-level Switches
Automated Migration of Profile for Multi-level Switches Yukihiro Nakagawa, Kazuki Hyoudou, Shinji Kobayashi, Osamu Shiraki, and Takeshi Shimizu Technologies Laboratory, IT Systems Laboratories Fujitsu
More informationVirtual Networking Management White Paper. Version 1.0.0 Status: DMTF Informational Publication Date: 2012-02-14 DSP2025
Version 1.0.0 Status: DMTF Informational Publication Date: 2012-02-14 Copyright Notice Copyright 2012 Distributed Management Task Force, Inc. (DMTF). All rights reserved. DMTF is a not-for-profit association
More informationDMTF Management Standards for Edge Virtual. Port Profiles. Hemal Shah, Associate Technical Director, Broadcom Corporation.
DMTF Management Standards for Edge Virtual Bridging (EVB) and Network Port Profiles Hemal Shah, Associate Technical Director, Broadcom Corporation DMTF Platform Management Sub-Committee Chair March, 2011
More informationVirtualized Access Layer. Petr Grygárek
Virtualized Access Layer Petr Grygárek Goals Integrate physical network with virtualized access layer switches Hypervisor vswitch Handle logical network connection of multiple (migrating) OS images hosted
More informationExpert Reference Series of White Papers. VMware vsphere Distributed Switches
Expert Reference Series of White Papers VMware vsphere Distributed Switches info@globalknowledge.net www.globalknowledge.net VMware vsphere Distributed Switches Rebecca Fitzhugh, VCAP-DCA, VCAP-DCD, VCAP-CIA,
More informationLinux KVM Virtual Traffic Monitoring
Linux KVM Virtual Traffic Monitoring East-West traffic visibility Scott Harvey Director of Engineering October 7th, 2015 apcon.com Speaker Bio Scott Harvey Director of Engineering at APCON Responsible
More informationA Case for Overlays in DCN Virtualization Katherine Barabash, Rami Cohen, David Hadas, Vinit Jain, Renato Recio and Benny Rochwerger IBM
Presenter: Vinit Jain, STSM, System Networking Development, IBM System & Technology Group A Case for Overlays in DCN Virtualization Katherine Barabash, Rami Cohen, David Hadas, Vinit Jain, Renato Recio
More informationHow To Manage A Virtualization Server
Brain of the Virtualized Data Center Contents 1 Challenges of Server Virtualization... 3 1.1 The virtual network breaks traditional network boundaries... 3 1.2 The live migration function of VMs requires
More informationHow Linux kernel enables MidoNet s overlay networks for virtualized environments. LinuxTag Berlin, May 2014
How Linux kernel enables MidoNet s overlay networks for virtualized environments. LinuxTag Berlin, May 2014 About Me: Pino de Candia At Midokura since late 2010: Joined as a Software Engineer Managed the
More informationAvaya Virtualization Provisioning Service
Avaya Virtualization Provisioning Service Delivering visibility, validation, automation and reporting across applications, servers and network devices for the next-generation Virtualized Data Center The
More informationProgrammable Networking with Open vswitch
Programmable Networking with Open vswitch Jesse Gross LinuxCon September, 2013 2009 VMware Inc. All rights reserved Background: The Evolution of Data Centers Virtualization has created data center workloads
More informationNetwork Virtualization Technologies and their Effect on Performance
Network Virtualization Technologies and their Effect on Performance Dror Goldenberg VP Software Architecture TCE NFV Winter School 2015 Cloud Computing and NFV Cloud - scalable computing resources (CPU,
More informationOptimize Server Virtualization with QLogic s 10GbE Secure SR-IOV
Technology Brief Optimize Server ization with QLogic s 10GbE Secure SR-IOV Flexible, Secure, and High-erformance Network ization with QLogic 10GbE SR-IOV Solutions Technology Summary Consolidation driven
More informationSimplify IT. With Cisco Application Centric Infrastructure. Barry Huang bhuang@cisco.com. Nov 13, 2014
Simplify IT With Cisco Application Centric Infrastructure Barry Huang bhuang@cisco.com Nov 13, 2014 There are two approaches to Control Systems IMPERATIVE CONTROL DECLARATIVE CONTROL Baggage handlers follow
More informationFCoCEE* Enterprise Data Center Use Cases
ocee* Enterprise Data Center Use Cases Dan Eisenhauer, IBM over CEE Development Renato Recio, DE, IBM Data Center Networking CTO *Fibre Channel over Convergence Enhanced The Data Center is Undergoing Transition
More informationVirtual Networking Features of the VMware vnetwork Distributed Switch and Cisco Nexus 1000V Series Switches
Virtual Networking Features of the vnetwork Distributed Switch and Cisco Nexus 1000V Series Switches What You Will Learn With the introduction of ESX, many virtualization administrators are managing virtual
More informationIBM Tivoli Composite Application Manager for Microsoft Applications: Microsoft Hyper-V Server Agent Version 6.3.1 Fix Pack 2.
IBM Tivoli Composite Application Manager for Microsoft Applications: Microsoft Hyper-V Server Agent Version 6.3.1 Fix Pack 2 Reference IBM Tivoli Composite Application Manager for Microsoft Applications:
More informationCON8474 - Software-Defined Networking in a Hybrid, Open Data Center
CON8474 - Software-Defined Networking in a Hybrid, Open Data Center Krishna Srinivasan Director, Product Management Oracle Virtual Networking Ronen Kofman Director of Product Development Oracle OpenStack
More informationExploration of Large Scale Virtual Networks. Open Network Summit 2016
Exploration of Large Scale Virtual Networks Open Network Summit 2016 David Wilder wilder@us.ibm.com A Network of Containers Docker containers Virtual network More containers.. 1 5001 2 4 OpenVswitch or
More informationOVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS
OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS Matt Eclavea (meclavea@brocade.com) Senior Solutions Architect, Brocade Communications Inc. Jim Allen (jallen@llnw.com) Senior Architect, Limelight
More informationFeature Comparison. Windows Server 2008 R2 Hyper-V and Windows Server 2012 Hyper-V
Comparison and Contents Introduction... 4 More Secure Multitenancy... 5 Flexible Infrastructure... 9 Scale, Performance, and Density... 13 High Availability... 18 Processor and Memory Support... 24 Network...
More informationEVOLVING ENTERPRISE NETWORKS WITH SPB-M APPLICATION NOTE
EVOLVING ENTERPRISE NETWORKS WITH SPB-M APPLICATION NOTE EXECUTIVE SUMMARY Enterprise network managers are being forced to do more with less. Their networks are growing in size and complexity. They need
More informationBroadcom Ethernet Network Controller Enhanced Virtualization Functionality
White Paper Broadcom Ethernet Network Controller Enhanced Virtualization Functionality Advancements in VMware virtualization technology coupled with the increasing processing capability of hardware platforms
More informationSoftware Defined Networking using VXLAN
Thomas Richter IBM Research and Development, Linux Technology Center LinuxCon Edinburgh 21-Oct-2013 Software Defined Networking using VXLAN Thomas Richter 2009 IBM Corporation Agenda Vxlan IETF Draft VXLAN
More informationEnterasys Data Center Fabric
TECHNOLOGY STRATEGY BRIEF Enterasys Data Center Fabric There is nothing more important than our customers. Enterasys Data Center Fabric Executive Summary Demand for application availability has changed
More informationExtreme Networks: Building Cloud-Scale Networks Using Open Fabric Architectures A SOLUTION WHITE PAPER
Extreme Networks: Building Cloud-Scale Networks Using Open Fabric Architectures A SOLUTION WHITE PAPER WHITE PAPER Building Cloud- Scale Networks Abstract TABLE OF CONTENTS Introduction 2 Open Fabric-Based
More informationVMware ESX Server 3 802.1Q VLAN Solutions W H I T E P A P E R
VMware ESX Server 3 802.1Q VLAN Solutions W H I T E P A P E R Executive Summary The virtual switches in ESX Server 3 support VLAN (IEEE 802.1Q) trunking. Using VLANs, you can enhance security and leverage
More informationSOLUTIONS FOR DEPLOYING SERVER VIRTUALIZATION IN DATA CENTER NETWORKS
WHITE PAPER SOLUTIONS FOR DEPLOYING SERVER VIRTUALIZATION IN DATA CENTER NETWORKS Copyright 2010, Juniper Networks, Inc. 1 Table of Contents Executive Summary........................................................................................................
More informationVMware vsphere-6.0 Administration Training
VMware vsphere-6.0 Administration Training Course Course Duration : 20 Days Class Duration : 3 hours per day (Including LAB Practical) Classroom Fee = 20,000 INR Online / Fast-Track Fee = 25,000 INR Fast
More informationHigh Performance OpenStack Cloud. Eli Karpilovski Cloud Advisory Council Chairman
High Performance OpenStack Cloud Eli Karpilovski Cloud Advisory Council Chairman Cloud Advisory Council Our Mission Development of next generation cloud architecture Providing open specification for cloud
More informationPart 1 - What s New in Hyper-V 2012 R2. Clive.Watson@Microsoft.com Datacenter Specialist
Part 1 - What s New in Hyper-V 2012 R2 Clive.Watson@Microsoft.com Datacenter Specialist Microsoft Cloud OS Vision Public Cloud Azure Virtual Machines Windows Azure Pack 1 Consistent Platform Windows Azure
More informationAnalysis of Network Segmentation Techniques in Cloud Data Centers
64 Int'l Conf. Grid & Cloud Computing and Applications GCA'15 Analysis of Network Segmentation Techniques in Cloud Data Centers Ramaswamy Chandramouli Computer Security Division, Information Technology
More informationPrivate cloud computing advances
Building robust private cloud services infrastructures By Brian Gautreau and Gong Wang Private clouds optimize utilization and management of IT resources to heighten availability. Microsoft Private Cloud
More informationHyper-V Networking. Aidan Finn
Hyper-V Networking Aidan Finn About Aidan Finn Technical Sales Lead at MicroWarehouse (Dublin) Working in IT since 1996 MVP (Virtual Machine) Experienced with Windows Server/Desktop, System Center, virtualisation,
More informationOpen vswitch and the Intelligent Edge
Open vswitch and the Intelligent Edge Justin Pettit OpenStack 2014 Atlanta 2014 VMware Inc. All rights reserved. Hypervisor as Edge VM1 VM2 VM3 Open vswitch Hypervisor 2 An Intelligent Edge We view the
More informationSecurity Overview of the Integrity Virtual Machines Architecture
Security Overview of the Integrity Virtual Machines Architecture Introduction... 2 Integrity Virtual Machines Architecture... 2 Virtual Machine Host System... 2 Virtual Machine Control... 2 Scheduling
More informationImpact of Virtualization on Cloud Networking Arista Networks Whitepaper
Overview: Virtualization takes IT by storm The adoption of virtualization in datacenters creates the need for a new class of networks designed to support elasticity of resource allocation, increasingly
More informationIntel Ethernet and Configuring Single Root I/O Virtualization (SR-IOV) on Microsoft* Windows* Server 2012 Hyper-V. Technical Brief v1.
Intel Ethernet and Configuring Single Root I/O Virtualization (SR-IOV) on Microsoft* Windows* Server 2012 Hyper-V Technical Brief v1.0 September 2012 2 Intel Ethernet and Configuring SR-IOV on Windows*
More informationGaining Control of Virtualized Server Environments
Gaining Control of Virtualized Server Environments By Jim Metzler, Ashton Metzler & Associates Distinguished Research Fellow and Co-Founder, Webtorials Editorial/Analyst Division Introduction The traditional
More informationWindows Server 2008 R2 Hyper-V Server and Windows Server 8 Beta Hyper-V
Features Comparison: Hyper-V Server and Hyper-V February 2012 The information contained in this document relates to a pre-release product which may be substantially modified before it is commercially released.
More informationNext Generation Data Center Networking.
Next Generation Data Center Networking. Intelligent Information Network. עמי בן-עמרם, יועץ להנדסת מערכות amib@cisco.comcom Cisco Israel. 1 Transparency in the Eye of the Beholder With virtualization, s
More informationSimplifying Big Data Deployments in Cloud Environments with Mellanox Interconnects and QualiSystems Orchestration Solutions
Simplifying Big Data Deployments in Cloud Environments with Mellanox Interconnects and QualiSystems Orchestration Solutions 64% of organizations were investing or planning to invest on Big Data technology
More informationHow To Make A Virtual Machine Aware Of A Network On A Physical Server
VMready Virtual Machine-Aware Networking White Paper Table of Contents Executive Summary... 2 Current Server Virtualization Environments... 3 Hypervisors... 3 Virtual Switches... 3 Leading Server Virtualization
More informationNutanix Tech Note. VMware vsphere Networking on Nutanix
Nutanix Tech Note VMware vsphere Networking on Nutanix Nutanix Virtual Computing Platform is engineered from the ground up for virtualization and cloud environments. This Tech Note describes vsphere networking
More informationVirtual Networking with z/vm Guest LANs and the z/vm Virtual Switch
Virtual Networking with z/vm Guest LANs and the z/vm Virtual Switch Alan Altmark, IBM z/vm Development, Endicott, NY Note References to IBM products, programs, or services do not imply that IBM intends
More informationCloud Optimize Your IT
Cloud Optimize Your IT Windows Server 2012 The information contained in this presentation relates to a pre-release product which may be substantially modified before it is commercially released. This pre-release
More informationVirtual Machine Manager Domains
This chapter contains the following sections: Cisco ACI VM Networking Supports Multiple Vendors' Virtual Machine Managers, page 1 VMM Domain Policy Model, page 2 Virtual Machine Manager Domain Main Components,
More informationNetwork Virtualization
Network Virtualization What is Network Virtualization? Abstraction of the physical network Support for multiple logical networks running on a common shared physical substrate A container of network services
More informationWindows Server 2012 R2 Hyper-V: Designing for the Real World
Windows Server 2012 R2 Hyper-V: Designing for the Real World Steve Evans @scevans www.loudsteve.com Nick Hawkins @nhawkins www.nickahawkins.com Is Hyper-V for real? Microsoft Fan Boys Reality VMware Hyper-V
More informationThe Value of Open vswitch, Fabric Connect and Fabric Attach in Enterprise Data Centers
The Value of Open vswitch, Fabric Connect and Fabric Attach in Enterprise Data Centers Table of Contents Enter Avaya Fabric Connect. 2 A typical data center architecture with Avaya SDN Fx... 3 A new way:
More informationThe Impact of Virtualization on Cloud Networking Arista Networks Whitepaper
Virtualization takes IT by storm The Impact of Virtualization on Cloud Networking The adoption of virtualization in data centers creates the need for a new class of networking designed to support elastic
More informationNetwork Virtualization and Data Center Networks 263-3825-00 Data Center Virtualization - Basics. Qin Yin Fall Semester 2013
Network Virtualization and Data Center Networks 263-3825-00 Data Center Virtualization - Basics Qin Yin Fall Semester 2013 1 Walmart s Data Center 2 Amadeus Data Center 3 Google s Data Center 4 Data Center
More informationESX Server 3 Configuration Guide Update 2 and later for ESX Server 3.5 and VirtualCenter 2.5
ESX Server 3 Configuration Guide Update 2 and later for ESX Server 3.5 and VirtualCenter 2.5 This document supports the version of each product listed and supports all subsequent versions until the document
More informationCLOUD NETWORKING FOR ENTERPRISE CAMPUS APPLICATION NOTE
CLOUD NETWORKING FOR ENTERPRISE CAMPUS APPLICATION NOTE EXECUTIVE SUMMARY This application note proposes Virtual Extensible LAN (VXLAN) as a solution technology to deliver departmental segmentation, business
More informationInstallation Guide Avi Networks Cloud Application Delivery Platform Integration with Cisco Application Policy Infrastructure
Installation Guide Avi Networks Cloud Application Delivery Platform Integration with Cisco Application Policy Infrastructure August 2015 Table of Contents 1 Introduction... 3 Purpose... 3 Products... 3
More informationnswitching: Virtual Machine Aware Relay Hardware Switching to improve intra-nic Virtual Machine Traffic
nswitching: Virtual Machine Aware Relay Hardware Switching to improve intra-nic Virtual Machine Traffic Jim Bardgett Harris Corporation 1025 W. NASA Blvd. Melbourne, FL 32919 Cliff Zou University of Central
More informationWhat s New in VMware vsphere 5.5 Networking
VMware vsphere 5.5 TECHNICAL MARKETING DOCUMENTATION Table of Contents Introduction.................................................................. 3 VMware vsphere Distributed Switch Enhancements..............................
More informationExtreme Networks: Public, Hybrid and Private Virtualized Multi-Tenant Cloud Data Center A SOLUTION WHITE PAPER
Extreme Networks: Public, Hybrid and Private Virtualized Multi-Tenant Cloud Data Center A SOLUTION WHITE PAPER WHITE PAPER Public, Hybrid and Private Virtualized Multi-Tenant Cloud Data Center Abstract
More informationHigh-performance vnic framework for hypervisor-based NFV with userspace vswitch Yoshihiro Nakajima, Hitoshi Masutani, Hirokazu Takahashi NTT Labs.
High-performance vnic framework for hypervisor-based NFV with userspace vswitch Yoshihiro Nakajima, Hitoshi Masutani, Hirokazu Takahashi NTT Labs. 0 Outline Motivation and background Issues on current
More informationIntroduction to SFC91xx ASIC Family
White Paper Introduction to SFC91xx ASIC Family Steve Pope, PhD, Chief Technical Officer, Solarflare Communications David Riddoch, PhD, Chief Software Architect, Solarflare Communications The 91xx family
More informationPublic, Hybrid and Private Virtualized Multi-Tenant Cloud Data Center Architecture Overview
Extreme Networks White Paper Public, Hybrid and Private Virtualized Multi-Tenant Cloud Data Center Architecture Overview Abstract The Extreme Networks Virtualized Multi-Tenant and Cloud Data Center Architecture
More informationSet Up a VM-Series Firewall on an ESXi Server
Set Up a VM-Series Firewall on an ESXi Server Palo Alto Networks VM-Series Deployment Guide PAN-OS 6.0 Contact Information Corporate Headquarters: Palo Alto Networks 4401 Great America Parkway Santa Clara,
More informationHow to Manage Data Center Networks - A Tutorial
Implementation and Evaluation of Management System to Reduce Management Cost Caused by Server ization Masahiro Yoshizawa, Toshiaki Tarui and Hideki Okita Abstract The cost of managing data center networks
More informationSDN CENTRALIZED NETWORK COMMAND AND CONTROL
SDN CENTRALIZED NETWORK COMMAND AND CONTROL Software Defined Networking (SDN) is a hot topic in the data center and cloud community. The geniuses over at IDC predict a $2 billion market by 2016
More informationCERN Cloud Infrastructure. Cloud Networking
CERN Cloud Infrastructure Cloud Networking Contents Physical datacenter topology Cloud Networking - Use cases - Current implementation (Nova network) - Migration to Neutron 7/16/2015 2 Physical network
More information基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器
基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器 楊 竹 星 教 授 國 立 成 功 大 學 電 機 工 程 學 系 Outline Introduction OpenFlow NetFPGA OpenFlow Switch on NetFPGA Development Cases Conclusion 2 Introduction With the proposal
More informationFiber Channel Over Ethernet (FCoE)
Fiber Channel Over Ethernet (FCoE) Using Intel Ethernet Switch Family White Paper November, 2008 Legal INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECTION WITH INTEL PRODUCTS. NO LICENSE, EXPRESS OR
More informationVirtual Networking with z/vm 5.1.0 Guest LAN and Virtual Switch
Virtual Networking with z/vm 5.1.0 Guest LAN and Virtual Switch HILLGANG March 2005 Dennis Musselwhite, IBM z/vm Development, Endicott, NY Note References to IBM products, programs, or services do not
More informationIntel Ethernet Switch Load Balancing System Design Using Advanced Features in Intel Ethernet Switch Family
Intel Ethernet Switch Load Balancing System Design Using Advanced Features in Intel Ethernet Switch Family White Paper June, 2008 Legal INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECTION WITH INTEL
More informationCMB 207 1I Citrix XenApp and XenDesktop Fast Track
CMB 207 1I Citrix XenApp and XenDesktop Fast Track This fast paced course provides the foundation necessary for students to effectively centralize and manage desktops and applications in the datacenter
More informationCloud Computing and the Internet. Conferenza GARR 2010
Cloud Computing and the Internet Conferenza GARR 2010 Cloud Computing The current buzzword ;-) Your computing is in the cloud! Provide computing as a utility Similar to Electricity, Water, Phone service,
More informationAn Oracle Technical White Paper November 2011. Oracle Solaris 11 Network Virtualization and Network Resource Management
An Oracle Technical White Paper November 2011 Oracle Solaris 11 Network Virtualization and Network Resource Management Executive Overview... 2 Introduction... 2 Network Virtualization... 2 Network Resource
More informationQuick Start for Network Agent. 5-Step Quick Start. What is Network Agent?
What is Network Agent? Websense Network Agent software monitors all internet traffic on the machines that you assign to it. Network Agent filters HTTP traffic and more than 70 other popular internet protocols,
More informationCloud Infrastructure Management - IBM VMControl
Cloud Infrastructure Management - IBM VMControl IBM Systems Director 6.3 VMControl 2.4 Thierry Huche IBM France - Montpellier thierry.huche@fr.ibm.com 2010 IBM Corporation Topics IBM Systems Director /
More informationApplication Note Gigabit Ethernet Port Modes
Application Note Gigabit Ethernet Port Modes Application Note Gigabit Ethernet Port Modes Table of Contents Description... 3 Benefits... 4 Theory of Operation... 4 Interaction with Other Features... 7
More informationNetwork Virtualization Solutions - A Practical Solution
SOLUTION GUIDE Deploying Advanced Firewalls in Dynamic Virtual Networks Enterprise-Ready Security for Network Virtualization 1 This solution guide describes how to simplify deploying virtualization security
More informationVeeam 74-409 Study Webinar Server Virtualization with Windows Server Hyper-V and System Center. Orin Thomas @orinthomas
Veeam 74-409 Study Webinar Server Virtualization with Windows Server Hyper-V and System Center Orin Thomas @orinthomas http://hyperv.veeam.com/ study-guide-microsoft-certification-exam-74-409-server-virtualization-windows-server-hyper-v-system-center-4202/
More informationNetwork configuration for the IBM PureFlex System
Network configuration for the IBM PureFlex System Note: The initial configuration of your IBM PureFlex System will be performed by IBM services that are included with your purchase. To ensure their success,
More informationQuickStart Guide vcenter Server Heartbeat 5.5 Update 2
vcenter Server Heartbeat 5.5 Update 2 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent
More informationModule I-7410 Advanced Linux FS-11 Part1: Virtualization with KVM
Bern University of Applied Sciences Engineering and Information Technology Module I-7410 Advanced Linux FS-11 Part1: Virtualization with KVM By Franz Meyer Version 1.0 February 2011 Virtualization Architecture
More informationvsphere Networking ESXi 5.0 vcenter Server 5.0 EN-000599-01
ESXi 5.0 vcenter Server 5.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions
More informationAssessing the Performance of Virtualization Technologies for NFV: a Preliminary Benchmarking
Assessing the Performance of Virtualization Technologies for NFV: a Preliminary Benchmarking Roberto Bonafiglia, Ivano Cerrato, Francesco Ciaccia, Mario Nemirovsky, Fulvio Risso Politecnico di Torino,
More informationTelecom - The technology behind
SPEED MATTERS v9.3. All rights reserved. All brand names, trademarks and copyright information cited in this presentation shall remain the property of its registered owners. Telecom - The technology behind
More informationMicrosoft SQL Server 2012 on Cisco UCS with iscsi-based Storage Access in VMware ESX Virtualization Environment: Performance Study
White Paper Microsoft SQL Server 2012 on Cisco UCS with iscsi-based Storage Access in VMware ESX Virtualization Environment: Performance Study 2012 Cisco and/or its affiliates. All rights reserved. This
More informationSDN software switch Lagopus and NFV enabled software node
SDN software switch Lagopus and NFV enabled software node Kazuaki OBANA NTT Network Innovation Laboratories SDN software switch Lagopus 1 Motivation Agile and flexible networking Full automation in provisioning,
More informationHow To Configure Voice Vlan On An Ip Phone
1 VLAN (Virtual Local Area Network) is used to logically divide a physical network into several broadcast domains. VLAN membership can be configured through software instead of physically relocating devices
More informationNetwork Technologies for Next-generation Data Centers
Network Technologies for Next-generation Data Centers SDN-VE: Software Defined Networking for Virtual Environment Rami Cohen, IBM Haifa Research Lab September 2013 Data Center Network Defining and deploying
More informationEthernet Fabric Requirements for FCoE in the Data Center
Ethernet Fabric Requirements for FCoE in the Data Center Gary Lee Director of Product Marketing glee@fulcrummicro.com February 2010 1 FCoE Market Overview FC networks are relatively high cost solutions
More informationExpert Reference Series of White Papers. vterminology: A Guide to Key Virtualization Terminology
Expert Reference Series of White Papers vterminology: A Guide to Key Virtualization Terminology 1-800-COURSES www.globalknowledge.com vterminology: A Guide to Key Virtualization Terminology John A. Davis,
More informationPanel : Future Data Center Networks
Vijoy Pandey, Ph.D. CTO, Network IBM Distinguished Engineer vijoy.pandey@us.ibm.com Panel : Future Data Center Networks 2012 IBM Corporation Networking folks were poor Custom silicon or poor functionality
More informationNetwork Discovery Protocol LLDP and LLDP- MED
Network LLDP and LLDP- MED Prof. Vahida Z. Attar College of Engineering, Pune Wellesely Road, Shivajinagar, Pune-411 005. Maharashtra, INDIA Piyush chandwadkar College of Engineering, Pune Wellesely Road,
More information