Software Defined Networking and Security
|
|
|
- Toby Carr
- 10 years ago
- Views:
Transcription
1 Software Defined Networking and Security Ivan Pepelnjak ipspace.net AG
2 Who is Ivan Pepelnjak Networking engineer since 1985 Technical director, later Chief Technology NIL Data Communications Consultant, blogger, book and webinar ipspace.net AG Teaching Scalable Web Application Design at University of Ljubljana Focus: Large-scale data centers and network virtualization Networking solutions for cloud computing Scalable application design Core IP routing/mpls, IPv6, VPN 2 More ipspace.net/about 2014 SDN and Security ipspace.net/webinars
3 High-Level Presentation Roadmap What is SDN? What is OpenFlow? Security aspects of controller-based networks Real-life controller-based security solutions 3 ipspace.net 2014 SDN and Security
4 Software Defined Networking 4 ipspace.net 2014 SDN and Security
5 What is SDN? SDN is the physical separation of the network control plane from the forwarding plane, and where a control plane controls several devices Open Networking Foundation Let s call whatever we can ship today SDN Vendor X SDN is the magic buzzword that will bring us VC funding Startup Y Is the ONF definition too restrictive? Shall we limit SDN to their understanding of it? 5 ipspace.net 2014 SDN and Security
6 Software-Defined? And What Were We Doing? Most networking devices have software Device behavior was always defined by its software Is it all hype or just marketing gone bad? Here be software Cisco AGS at Computer History Museum Source: Evilrouters.Net 6 ipspace.net 2014 SDN and Security
7 Motivations Behind SDN Movement Very large cloud providers (ONF founders): Give me cheap hardware, I will build my software (Google) Implement my own features or protocols (Yahoo) Whitebox hardware + open-source software (Facebook) Real-life requirements Faster software development Programmable network elements Faster provisioning Centralized intelligence, visibility and policies 1 The second set of requirements makes more sense for most customers 7 ipspace.net 2014 SDN and Security
8 Perl script Web UI Did We Have SDN in 1992? We stopped programming the networks when they became mission critical Lack of programming skills Lack of reliable automation tools and programmatic interfaces Lack of (semi)standardized configuration schema Lack of trust 5 Why have we stopped doing it? What went wrong? 8 ipspace.net 2014 SDN and Security
9 SDN Advantages / Perfect Use Cases Solving hard problems that require centralized view or synchronization Things we do well: Destination-only hop-by-hop L3 forwarding Things we don t do so well: Large-scale provisioning or orchestration Synchronized distributed policies (security, QoS...) Optimal traffic engineering (MPLS-TE) the knapsack problem Routing of elephant flows Things we don t do at all: QoS- or load-based forwarding adaptations L3/L4-based or source+destination-based forwarding (policy-based routing) Insertion of security features in the forwarding path Best approach: combine SDN with traditional mechanisms 9 ipspace.net 2014 SDN and Security
10 SDN Principles Revisited Centralized controllers Decisions made based on end-to-end visibility Automatic programming or configuration of network devices Usual objections How is this different from Single-Pane-of-Glass? What happens when network partitions? Why should it work this time? 10 ipspace.net 2014 SDN and Security
11 Can We Do SDN Today? NETCONF Router Management / Policy plane Configuration / CLI / GUI BGP Control plane OSPF Static routes PCEP Neighbor table Link state database IP routing table SNMP ForCES, BGP Flowspec, MPLS-TP Forwarding table Data plane Vendor APIs: Cisco, Juniper Scripting: Cisco, Juniper, Arista, Dell, F ipspace.net 2014 SDN and Security
12 What We Can and Cannot Do with Existing Protocols Easy to do Programmatic device configuration (management plane interactions) IP forwarding table modifications (BGP or Flowspec) Simple edge policy enforcement (per-user ACLs) Harder to do Topology discovery and extraction Non-standard forwarding models (example: source-based IP routing) Multi-vendor solutions (example: no standard YANG models, vendor-specific RADIUS attributes) End-to-end transactional consistency Impossible to do New control-plane protocols Modification of existing control-plane protocol behavior 12 ipspace.net 2014 SDN and Security
13 Emerging Protocols OF-Config, XMPP Router Management / Policy plane Configuration / CLI / GUI Control plane Static routes OSPF I2RS, OVSDB Neighbor table Link state database IP routing table OnePK OpenFlow Forwarding table Data plane 13 ipspace.net 2014 SDN and Security
14 OpenFlow and SDN Webinars on ipspace.net VMware NSX Architecture SDN Use Cases Overlay Virtual Networking ProgrammableFlow Deep Dive Cloud Computing Networking OpenFlow and SDN Coming in 2014 SDN, NFV and OpenFlow 101 Trainings Live sessions On-Site workshops Recordings and subscriptions SDN and NFV for Service Providers Other resources Consulting Books and case studies Inter-DC More information FCoE very limited use and requires no bridging 14 ipspace.net 2014 SDN and Security
15 OpenFlow ipspace.net 2014 SDN and Security
16 Management, Control and Data Planes Adjacent router Router Management / Policy plane Configuration / CLI / GUI Adjacent router Control Routing plane Control plane Static routes Control plane OSPF OSPF OSPF Neighbor table Link state database IP routing table Switching Forwarding table Data plane Data plane Data plane 16 ipspace.net 2014 SDN and Security
17 B B OpenFlow = Control / Data Plane Separation B Out-of-Band Control-Plane Network A B B Basic principles: Control / Management plane in a dedicated controller Networking devices perform forwarding and maintenance functions IP / SSL connectivity between controller and OpenFlow switch OpenFlow = Forwarding table (TCAM) download protocol B Prefix B B ipspace.net 2014 SDN and Security
18 Review: OpenFlow Protocol Details Message types: Configuration Feature requests Flow/Port/Table modifications install forwarding entries Statistics read per-forwarding-entry packet/byte counts Barriers (~ transactions) Packet In/Out control-plane protocols and packet punting 18 Hint: ipspace.net forwarding 2014 entry does SDN and not Security have to be a single session flow
19 LLDP Case Study: OpenFlow Topology Discovery A B1 Controller builds the network model as devices connect to it OpenFlow control packets used for interface Packet Out message used to send a packet through an interface Packet In message used by the switch when it receives unknown packet ipspace.net 2014 SDN and Security
20 OpenFlow Concepts Are not New (RFC 1925, sect 2.11) Do you still remember... Frame Relay and ATM networks SONET/SDH ForCES MPLS-TP The problems are always the same: Forwarding state abstraction / scalability Distributed network resilience with centralized control plane Fast feedback loops Fast convergence (FRR, PIC) Linecard protocols (BFD, LACP, LLDP...) 20 The important ipspace.net 2014 difference SDN this and Security time: customer pressure
21 OpenFlow Deployment Models Native OpenFlow Works well at the edge (single set of uplinks) Too many complications at the core (OOB management, fast failure detection...) OpenFlow with vendor-specific extensions Link bundling Load balancing Linecard functionality (LLDP, LACP, BFD...) QoS Ships in the night OpenFlow in parallel with traditional forwarding Some ports / VLANs dedicated to OpenFlow Fallback from OpenFlow to normal Solves OOB management and linecard functionality Integrated OpenFlow classifiers/actions become part of regular packet processing OpenFlow provides ephemeral state configuration 21 ipspace.net 2014 SDN and Security
22 Shipping OpenFlow Products Switches Commercial Arista 7500/7150 Brocade MLX/NetIron products Cisco Nexus 3000 Dell N3000/N400 Extreme BlackDiamond HP ProCurve IBM BNT G8264 Juniper MX & EX9200 (not GA) NEC ProgrammableFlow switches Smaller vendors (Mikrotik, ODMs) Switches Open Source Open vswitch (Xen, KVM) NetFPGA reference implementation OpenWRT Mininet (emulation) Controllers Commercial NEC ProgrammableFlow Controller VMware NSX Big Switch Networks Cisco extensible Network Controller HP VAN SDN Controller Controllers Open Source Open Daylight (Java) NOX (C++/Python) Beacon (Java) Floodlight (Java) Maestro (Java) RouteFlow (NOX, Quagga,...) NodeFlow (JavaScript) Trema (Ruby) 22 ipspace.net 2014 SDN and Security
23 OpenFlow and SDN Webinars on ipspace.net VMware NSX Architecture SDN Use Cases Overlay Virtual Networking ProgrammableFlow Deep Dive Cloud Computing Networking OpenFlow and SDN Coming in 2014 SDN, NFV and OpenFlow 101 Trainings Live sessions On-Site workshops Recordings and subscriptions SDN and NFV for Service Providers Other resources Consulting Books and case studies Inter-DC More information FCoE very limited use and requires no bridging 23 ipspace.net 2014 SDN and Security
24 SDN Security Challenges 24 ipspace.net 2014 SDN and Security
25 Threat Analysis Controller exploits Controller platform exploits A Switch-tocontroller communication Control-plane protocol fuzzing Switch overloads Control-plane DoS attacks ARP RQ B1 Control-plane attacks Denial-of-service attack (switch and controller) Fuzzing attacks 7 SDN controller is a very lucrative target 25 ipspace.net 2014 SDN and Security
26 Separate Data Plane Management network CP CP A OF OF OF B Well-known solutions Encrypted switch-to-controller communications Separate management- or control-plane network Forwarding and management contexts in the switches 26 ipspace.net 2014 SDN and Security
27 Proactive Flow Setups A B Reactive flow setups Punt unknown packets to the controller Compute forwarding paths on demand Install flow entries based on actual traffic Scalability concerns Flow granularity Packet punting rate Flow modification rate Proactive flow setups Discover network topology Discover endpoints Compute optimal forwarding topology Download flow entries No data plane controller involvement Exceptions: ARP and MAC learning 27 ipspace.net 2014 SDN and Security
28 Control-Plane Protection Shaping applied on ingress OFS OpenFlow control network A A X OF OF OF A X B OpenFlow switches send all unknown packets to controller Unicast flooding performed through controller control plane interference Control-plane protection needed in ingress OpenFlow switches 5 28 ipspace.net 2014 SDN and Security
29 Hardening an SDN Solution Common design guidelines Out-of-band Control Plane Minimize the control-plane involvement Use OpenFlow solutions with coarse-grained proactive forwarding model Prefer solutions with distributed intelligence Switch hardening Strict control/data plane separation Control-plane policing in OpenFlow networks Controller hardening Most controllers run on Linux you know what to do 29 ipspace.net 2014 SDN and Security
30 Use Case: Network Monitoring and Tapping 30 ipspace.net 2014 SDN and Security
31 Network Monitoring in Traditional Networks A B Netflow / Sflow SNMP counters MACP/IP/ARP tables Traffic statistics Too coarse (interface counters), detailed (Netflow / IPFIX) or sampled (Sflow) Limited visibility in multi-tenant environments Endpoint visibility Available on edge network devices Hard to summarize into a searchable format Forwarding information Information distributed across numerous devices (MAC tables, ARP tables, IP forwarding tables) Hard to reconstruct expected traffic path 31 ipspace.net 2014 SDN and Security
32 Network Monitoring in Controller-Based Networks A B Controller is the authoritative source of information on Network configuration Network topology Forwarding paths Endpoints (IP prefixes or IP/MAC addresses) 32 ipspace.net 2014 SDN and Security
33 Network Monitoring in OpenFlow-Based Networks A B OpenFlow statistics Byte- and packet counters associated with every OpenFlow entry Controller can read flow statistics (similar to SNMP interface counters) Flow counters reported to OpenFlow controller every time a switch removes a flow due to idle timeout Traffic statistics in OpenFlow controller Controller can collect traffic statistics at any granularity configured with flow entries downloaded to the switches Constraint: switch hardware or software limits 33 ipspace.net 2014 SDN and Security
34 OpenFlow/SDN in Tap Aggregation Network A B Span port Hardware tap Solution Overview Replace dedicated tap aggregation equipment with standard OpenFlow-capable switches Program filtering and forwarding rules with OpenFlow OpenFlow Controller Benefits of OpenFlow Based on commodity switches Filter early in the forwarding path use capturing devices more efficiently N-tuple filtering Flow-based metering Simple tap- and filter changes 34 ipspace.net 2014 SDN and Security
35 Traffic Tapping with OpenFlow Switches A B Span port Hardware tap Use OpenFlow flows to mirror traffic to SPAN ports Higher traffic redirection granularity lower number of SPAN ports required Any OpenFlow controller capable of inserting individual flows could be used 35 ipspace.net 2014 SDN and Security
36 Use Case: Scale-Out Network Services 36 ipspace.net 2014 SDN and Security
37 Scale-Out Stateful Services Don t Scale Well Stateful services are hard to scale out: Forward and reverse traffic flows might not match Traffic distribution might change with introduction or removal of devices Switches might dynamically rehash ECMP entries Stateful devices have to exchange state and/or user traffic Result: scale-out performance is not linear 37 ipspace.net 2014 SDN and Security
38 Simplistic OpenFlow-Based Stateful Services Punt new flows to OpenFlow controller Install per-session entries throughout the network Scalability challenges Number of flows in hardware switches Control channel bandwidth Flow modification (installation/removal) rate orders of magnitude too low for GE/10GE environment with reasonable traffic mix 38 ipspace.net 2014 SDN and Security
39 OpenFlow-Assisted Scale-Out Services OpenFlow switches use coarse-grained flows (based on source/destination IP address ranges) Load balancing appliances perform fine-grained load balancing Load balancing controller modifies OpenFlow flows (and traffic distribution) based on node availability and traffic load 39 ipspace.net 2014 SDN and Security
40 Use Case: Scale-Out IDS and IPS 40 ipspace.net 2014 SDN and Security
41 Scale Out IDS with OpenFlow Controller Internet Data Center OpenFlow used to distribute the load to multiple IDS appliances Coarse-grained flows deployed on the OpenFlow switch Flow granularity adjusted in real time to respond to changes in traffic Each appliance receives all traffic from a set of endpoints (complete session and endpoint behavior visibility) 41 ipspace.net 2014 SDN and Security
42 Scale Out IPS with OpenFlow Flows Internet Data Center DoS detection system reports offending X-tuples Source IP addresses Targeted servers Applications (port numbers) OpenFlow controller installs drop flows Module for Bro IDS already available 42 ipspace.net 2014 SDN and Security
43 Use Case: Service Insertion 43 ipspace.net 2014 SDN and Security
44 Service Insertion 101 Service insertion principles Dynamically insert network services in the forwarding path Based on endpoints (users), applications, or both Data center use cases Firewalls, load balancers, IPS/IDS appliances Enterprise and service provider use cases Traffic filters (firewalls or packet filters) Captive portals WAN acceleration and caching 44 ipspace.net 2014 SDN and Security
45 Layer-2 Service Insertion A B IP-A MAC-A IP-S MAC-S MAC-A IP-A MAC-S IP-S IP-A MAC-A IP-S MAC-S MAC-A IP-A MAC-S IP-S IP-B MAC-B IP-S MAC-S MAC-B IP-B MAC-S IP-S IP-B MAC-B IP-S MAC-S MAC-B IP-B MAC-S IP-S S Layer-2 frames redirected to a transparent (bump-in-wire) appliance Based on MAC (potentially IP) headers Typical implementation VLAN chaining Hard to implement for individual endpoints Impossible to implement for individual applications Fantastic potential for forwarding loops ipspace.net 2014 SDN and Security
46 Layer-3 Service Insertion A IP-A MAC-A IP-S MAC-G MAC-A IP-A MAC-G IP-S IP-A MAC-G IP-S MAC-S MAC-G IP-A MAC-S IP-S B IP-B MAC-B IP-S MAC-F MAC-B IP-B MAC-G IP-S MAC-F MAC-F IP-B MAC-G IP-S MAC-S MAC-F IP-B MAC-S IP-S S Layer-3 frames redirected to a transparent or inter-subnet appliance Based on IP headers Might require MAC header rewrite Typical implementation Policy-based routing (PBR) MAC rewrite is automatic Hard to implement for appliances not close to the forwarding path ipspace.net 2014 SDN and Security
47 Service Insertion in OpenFlow-Based Fabrics A S B Simplistic approach Install redirection flow entries wherever needed Change flow redirection entries on every topology change Scalable approach Create new forwarding paths between edge switches and appliances Map traffic to forwarding paths in ingress switches 47 ipspace.net 2014 SDN and Security
48 ProgrammableFlow Service Insertion Example A B Create a flow list to match the traffic Apply a flow filter to a VTN interface Flow filter can include redirect action Redirect action could perform MAC rewrite Use CLI, GUI or API to perform these operations flow-list WebTraffic { sequence-number 10 { l4-destination-port 80 } } vtn VTN1 { vbridge VBR1 { interface VIF_VEX1 { flow-filter in { sequence-number 10 { } } } } S match flow-list WebTraffic action redirect redirect-destination... } sequence-number 20 { action pass } 48 ipspace.net 2014 SDN and Security
49 OpenFlow and SDN Webinars on ipspace.net VMware NSX Architecture SDN Use Cases Overlay Virtual Networking ProgrammableFlow Deep Dive Cloud Computing Networking OpenFlow and SDN Coming in 2014 SDN, NFV and OpenFlow 101 Trainings Live sessions On-Site workshops Recordings and subscriptions SDN and NFV for Service Providers Other resources Consulting Books and case studies Inter-DC More information FCoE very limited use and requires no bridging 49 ipspace.net 2014 SDN and Security
50 Should I Care? 50 ipspace.net 2014 SDN and Security
51 Conclusions SDN and OpenFlow are interesting concepts They will significantly impact the way we do networking Centralized computation and management plane makes more sense than centralized control plane OpenFlow is just a low-level tool Initial SDN use cases: large data portals or cloud providers (cost cutting or virtualized networking) Still a very immature technology, standards are rapidly changing Northbound controller API is missing (but badly needed) Creating controller vendor lock-in Already crossed the academic commercial gap 51 If you ipspace.net want 2014 to get involved, SDN and NOW Security is a good time
52 OpenFlow and SDN Webinars on ipspace.net VMware NSX Architecture SDN Use Cases Overlay Virtual Networking ProgrammableFlow Deep Dive Cloud Computing Networking OpenFlow and SDN Coming in 2014 SDN, NFV and OpenFlow 101 Trainings Live sessions On-Site workshops Recordings and subscriptions SDN and NFV for Service Providers Other resources Consulting Books and case studies Inter-DC More information FCoE very limited use and requires no bridging 52 ipspace.net 2014 SDN and Security
53 Questions? Send them to 53 ipspace.net 2014 SDN and Security
OpenFlow and SDN: hype, useful tools or panacea? Ivan Pepelnjak ([email protected]) Chief Technology Advisor NIL Data Communications
OpenFlow and SDN: hype, useful tools or panacea? Ivan Pepelnjak ([email protected]) Chief Technology Advisor NIL Data Communications Who is Ivan Pepelnjak (@ioshints) Networking engineer since 1985 Technical
OpenFlow and SDN: Hype, Useful Tools or Panacea? Ivan Pepelnjak ([email protected]) Chief Technology Advisor NIL Data Communications
OpenFlow and SDN: Hype, Useful Tools or Panacea? Ivan Pepelnjak ([email protected]) Chief Technology dvisor NIL Data Communications Who is Ivan Pepelnjak (@ioshints) Networking engineer since 1985 Technical
Software Defined Networks Four Years Later. Quo Vadis, SDN? Ivan Pepelnjak ([email protected]) Network Architect. ipspace.net AG
Software Defined Networks Four Years Later Quo Vadis, SDN? Ivan Pepelnjak ([email protected]) Network Architect ipspace.net AG Who is Ivan Pepelnjak (@ioshints) Past Kernel programmer, network OS and web
Automating Network Security
Automating Network Security Ivan Pepelnjak ([email protected]) Network Architect ipspace.net AG Who is Ivan Pepelnjak (@ioshints) Past Kernel programmer, network OS and web developer Sysadmin, database admin,
Open Source Network: Software-Defined Networking (SDN) and OpenFlow
Open Source Network: Software-Defined Networking (SDN) and OpenFlow Insop Song, Ericsson LinuxCon North America, Aug. 2012, San Diego CA Objectives Overview of OpenFlow Overview of Software Defined Networking
Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre
Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre Wilfried van Haeren CTO Edgeworx Solutions Inc. www.edgeworx.solutions Topics Intro Edgeworx Past-Present-Future
Designing Virtual Network Security Architectures Dave Shackleford
SESSION ID: CSV R03 Designing Virtual Network Security Architectures Dave Shackleford Sr. Faculty and Analyst SANS @daveshackleford Introduction Much has been said about virtual networking and softwaredefined
Testing Software Defined Network (SDN) For Data Center and Cloud VERYX TECHNOLOGIES
Testing Software Defined Network (SDN) For Data Center and Cloud VERYX TECHNOLOGIES Table of Contents Introduction... 1 SDN - An Overview... 2 SDN: Solution Layers and its Key Requirements to be validated...
OpenFlow and Software Defined Networking presented by Greg Ferro. Software Defined Networking (SDN)
OpenFlow and Software Defined Networking presented by Greg Ferro Software Defined Networking (SDN) would like to thank Greg Ferro and Ivan Pepelnjak for giving us the opportunity to sponsor to this educational
Network Virtualization and Software-defined Networking. Chris Wright and Thomas Graf Red Hat June 14, 2013
Network Virtualization and Software-defined Networking Chris Wright and Thomas Graf Red Hat June 14, 2013 Agenda Problem Statement Definitions Solutions She can't take much more of this, captain! Challenges
How To Write A Network Plan In Openflow V1.3.3 (For A Test)
OpenFlowand IPv6 Two great tastes that taste great together! Scott Hogg, CTO GTRI Chair Emeritus RMv6TF Infoblox IPv6 COE Today s Outline Software-Defined Networking Background Introduction to OpenFlow
Ten Things to Look for in an SDN Controller
Ten Things to Look for in an SDN Controller Executive Summary Over the last six months there has been significant growth in the interest that IT organizations have shown in Software-Defined Networking
基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器
基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器 楊 竹 星 教 授 國 立 成 功 大 學 電 機 工 程 學 系 Outline Introduction OpenFlow NetFPGA OpenFlow Switch on NetFPGA Development Cases Conclusion 2 Introduction With the proposal
Software Defined Networking What is it, how does it work, and what is it good for?
Software Defined Networking What is it, how does it work, and what is it good for? slides stolen from Jennifer Rexford, Nick McKeown, Michael Schapira, Scott Shenker, Teemu Koponen, Yotam Harchol and David
2013 ONS Tutorial 2: SDN Market Opportunities
2013 ONS Tutorial 2: SDN Market Opportunities SDN Vendor Landscape and User Readiness Jim Metzler, Ashton, Metzler & Associates [email protected] April 15, 2013 1 1 Goals & Non-Goals Goals: Describe
Software-Defined Networking for the Data Center. Dr. Peer Hasselmeyer NEC Laboratories Europe
Software-Defined Networking for the Data Center Dr. Peer Hasselmeyer NEC Laboratories Europe NW Technology Can t Cope with Current Needs We still use old technology... but we just pimp it To make it suitable
What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates
What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates 1 Goals of the Presentation 1. Define/describe SDN 2. Identify the drivers and inhibitors of SDN 3. Identify what
SDN. What's Software Defined Networking? Angelo Capossele
SDN What's Software Defined Networking? Angelo Capossele Outline Introduction to SDN OpenFlow Network Functions Virtualization Some examples Opportunities Research problems Security Case study: LTE (Mini)Tutorial
Virtual Firewalls. Ivan Pepelnjak ([email protected]) NIL Data Communications
Virtual Firewalls Ivan Pepelnjak ([email protected]) NIL Data Communications Who is Ivan Pepelnjak (@ioshints) Networking engineer since 1985 Focus: real-life deployment of advanced technologies Chief Technology
Software Defined Networks Virtualized networks & SDN
Software Defined Networks Virtualized networks & SDN Tony Smith Solution Architect HPN 2 What is Software Defined Networking Switch/Router MANAGEMENTPLANE Responsible for managing the device (CLI) CONTROLPLANE
Software Defined Networking & Openflow
Software Defined Networking & Openflow Autonomic Computer Systems, HS 2015 Christopher Scherb, 01.10.2015 Overview What is Software Defined Networks? Brief summary on routing and forwarding Introduction
Cloud Networking From Theory to Practice" Ivan Pepelnjak ([email protected]) NIL Data Communications"
Cloud Networking From Theory to Practice Ivan Pepelnjak ([email protected]) NIL Data Communications Who is Ivan Pepelnjak (@ioshints) Networking engineer since 1985 Consultant, blogger (blog.ioshints.info),
OpenFlow and Software Defined Networking presented by Greg Ferro. OpenFlow Functions and Flow Tables
OpenFlow and Software Defined Networking presented by Greg Ferro OpenFlow Functions and Flow Tables would like to thank Greg Ferro and Ivan Pepelnjak for giving us the opportunity to sponsor to this educational
SDN Applications in Today s Data Center
SDN Applications in Today s Data Center Harry Petty Director Data Center & Cloud Networking Cisco Systems, Inc. Santa Clara, CA USA October 2013 1 Customer Insights: Research/ Academia OpenFlow/SDN components
Wedge Networks: Transparent Service Insertion in SDNs Using OpenFlow
Wedge Networks: EXECUTIVE SUMMARY In this paper, we will describe a novel way to insert Wedge Network s multiple content security services (such as Anti-Virus, Anti-Spam, Web Filtering, Data Loss Prevention,
Software Defined Networking (SDN) OpenFlow and OpenStack. Vivek Dasgupta Principal Software Maintenance Engineer Red Hat
Software Defined Networking (SDN) OpenFlow and OpenStack Vivek Dasgupta Principal Software Maintenance Engineer Red Hat CONTENTS Introduction SDN and components SDN Architecture, Components SDN Controller
From Active & Programmable Networks to.. OpenFlow & Software Defined Networks. Prof. C. Tschudin, M. Sifalakis, T. Meyer, M. Monti, S.
From Active & Programmable Networks to.. OpenFlow & Software Defined Networks Prof. C. Tschudin, M. Sifalakis, T. Meyer, M. Monti, S. Braun University of Basel Cs321 - HS 2012 (Slides material from www.bigswitch.com)
SDN Software Defined Networks
There is nothing more important than our customers SDN Software Defined Networks A deployable approach for the Enterprise 2012 Enterasys Networks, Inc. All rights reserved SDN Overview What is SDN? Loosely
Palo Alto Networks. Security Models in the Software Defined Data Center
Palo Alto Networks Security Models in the Software Defined Data Center Christer Swartz Palo Alto Networks CCIE #2894 Network Overlay Boundaries & Security Traditionally, all Network Overlay or Tunneling
Data Center Fabrics What Really Matters. Ivan Pepelnjak ([email protected]) NIL Data Communications
Data Center Fabrics What Really Matters Ivan Pepelnjak ([email protected]) NIL Data Communications Who is Ivan Pepelnjak (@ioshints) Networking engineer since 1985 Technical director, later Chief Technology
Skip the Transitions, Jump Straight into IPv6
Skip the Transitions, Jump Straight into IPv6 Ivan Pepelnjak (@ioshints, [email protected]) NIL Data Communications Presentation @ 7. Slovenian IPv6 Summit organized by go6.si Who is Ivan Pepelnjak (@ioshints)
How To Understand The Power Of The Internet
DATA COMMUNICATOIN NETWORKING Instructor: Ouldooz Baghban Karimi Course Book: Computer Networking, A Top-Down Approach, Kurose, Ross Slides: - Course book Slides - Slides from Princeton University COS461
An Overview of OpenFlow
An Overview of OpenFlow By Jim Metzler, Ashton Metzler & Associates Distinguished Research Fellow and Co-Founder, Webtorials Editorial/Analyst Division The OpenFlow Protocol Figure 1 depicts the Open Networking
Ethernet-based Software Defined Network (SDN) Cloud Computing Research Center for Mobile Applications (CCMA), ITRI 雲 端 運 算 行 動 應 用 研 究 中 心
Ethernet-based Software Defined Network (SDN) Cloud Computing Research Center for Mobile Applications (CCMA), ITRI 雲 端 運 算 行 動 應 用 研 究 中 心 1 SDN Introduction Decoupling of control plane from data plane
Defining SDN. Overview of SDN Terminology & Concepts. Presented by: Shangxin Du, Cisco TAC Panelist: Pix Xu Jan 2014
Defining SDN Overview of SDN Terminology & Concepts Presented by: Shangxin Du, Cisco TAC Panelist: Pix Xu Jan 2014 2013 Cisco and/or its affiliates. All rights reserved. 2 2013 Cisco and/or its affiliates.
Mock RFI for Enterprise SDN Solutions
Mock RFI for Enterprise SDN Solutions Written By Sponsored By Table of Contents Background and Intended Use... 3 Introduction... 3 Definitions and Terminology... 7 The Solution Architecture... 10 The SDN
BROADCOM SDN SOLUTIONS OF-DPA (OPENFLOW DATA PLANE ABSTRACTION) SOFTWARE
BROADCOM SDN SOLUTIONS OF-DPA (OPENFLOW DATA PLANE ABSTRACTION) SOFTWARE Network Switch Business Unit Infrastructure and Networking Group 1 TOPICS SDN Principles Open Switch Options Introducing OF-DPA
Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure
White Paper Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure What You Will Learn The new Cisco Application Centric Infrastructure
Open Fabric SDN The Comprehensive SDN approach. Jake Howering, Director SDN Product Line Management Bithika Khargharia, PhD, Senior Engineer
Open Fabric SDN The Comprehensive SDN approach Jake Howering, Director SDN Product Line Management Bithika Khargharia, PhD, Senior Engineer Agenda SDN Market and Industry Extreme Networks Open Fabric SDN
SOFTWARE DEFINED NETWORKS REALITY CHECK. DENOG5, Darmstadt, 14/11/2013 Carsten Michel
SOFTWARE DEFINED NETWORKS REALITY CHECK DENOG5, Darmstadt, 14/11/2013 Carsten Michel Software Defined Networks (SDN)! Why Software Defined Networking? There s a hype in the industry!! Dispelling some myths
Cisco Nexus 1000V Switch for Microsoft Hyper-V
Data Sheet Cisco Nexus 1000V Switch for Microsoft Hyper-V Product Overview Cisco Nexus 1000V Switches provide a comprehensive and extensible architectural platform for virtual machine and cloud networking.
SDN and NFV Open Source Initiatives. Systematic SDN and NFV Workshop Challenges, Opportunities and Potential Impact
SDN and NFV Open Source Initiatives Systematic SDN and NFV Workshop Challenges, Opportunities and Potential Impact May 19, 2014 Eric CARMES 6WIND Founder and CEO SPEED MATTERS V1.0. All rights reserved.
NEC contribution to OpenDaylight: Virtual Tenant Network (VTN)
NEC contribution to OpenDaylight: Virtual Tenant Network (VTN) June. 2013 NEC Page 1 Agenda OpenDaylight Virtual Tenant Network - VTN Model Live Demo VTN Implementation Page 2 OpenDaylight Virtual Tenant
OpenFlow Technology Investigation Vendors Review on OpenFlow implementation
OpenFlow Technology Investigation Vendors Review on OpenFlow implementation Ioan Turus, NORDUnet GN3 JRA1 T1&2, Copenhagen, 21.11.2012 Outline! Software Defined Networks (SDN)! Introduction to OpenFlow!
Outline. Institute of Computer and Communication Network Engineering. Institute of Computer and Communication Network Engineering
Institute of Computer and Communication Network Engineering Institute of Computer and Communication Network Engineering Communication Networks Software Defined Networking (SDN) Prof. Dr. Admela Jukan Dr.
Why Software Defined Networking (SDN)? Boyan Sotirov
Why Software Defined Networking (SDN)? Boyan Sotirov Agenda Current State of Networking Why What How When 2 Conventional Networking Many complex functions embedded into the infrastructure OSPF, BGP, Multicast,
SOFTWARE DEFINED NETWORKING
SOFTWARE DEFINED NETWORKING Bringing Networks to the Cloud Brendan Hayes DIRECTOR, SDN MARKETING AGENDA Market trends and Juniper s SDN strategy Network virtualization evolution Juniper s SDN technology
Software Defined Networking What is it, how does it work, and what is it good for?
Software Defined Networking What is it, how does it work, and what is it good for? Many slides stolen from Jennifer Rexford, Nick McKeown, Scott Shenker, Teemu Koponen, Yotam Harchol and David Hay Agenda
Using SDN-OpenFlow for High-level Services
Using SDN-OpenFlow for High-level Services Nabil Damouny Sr. Director, Strategic Marketing Netronome Vice Chair, Marketing Education, ONF [email protected] Open Server Summit, Networking Applications
How To Orchestrate The Clouddusing Network With Andn
ORCHESTRATING THE CLOUD USING SDN Joerg Ammon Systems Engineer Service Provider 2013-09-10 2013 Brocade Communications Systems, Inc. Company Proprietary Information 1 SDN Update -
What is SDN all about?
What is SDN all about? Emil Gągała Juniper Networks Piotr Jabłoński Cisco Systems In the beginning there was a chaos CLOUD BUILDING BLOCKS CAN I VIRTUALIZE MY Compute Network? Storage Where is my money?
Software Defined Networking A quantum leap for Devops?
Software Defined Networking A quantum leap for Devops? TNG Technology Consulting GmbH, http://www.tngtech.com/ Networking is bottleneck in today s devops Agile software development and devops is increasing
The State of OpenFlow: Advice for Those Considering SDN. Steve Wallace Executive Director, InCNTRE SDN Lab Indiana University ssw@iu.
The State of OpenFlow: Advice for Those Considering SDN Steve Wallace Executive Director, InCNTRE SDN Lab Indiana University [email protected] 2 3 4 SDN is an architecture Separation of Control and Data Planes
RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL
RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL Pascal Geenens CONSULTING ENGINEER, JUNIPER NETWORKS [email protected] BUSINESS AGILITY Need to create and deliver new revenue opportunities faster Services
Software Defined Network (SDN)
Georg Ochs, Smart Cloud Orchestrator ([email protected]) Software Defined Network (SDN) University of Stuttgart Cloud Course Fall 2013 Agenda Introduction SDN Components Openstack and SDN Example Scenario
SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT
BROCADE SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT Rajesh Dhople Brocade Communications Systems, Inc. [email protected] 2012 Brocade Communications Systems, Inc. 1 Why can t you do these things
SOFTWARE-DEFINED NETWORKING AND OPENFLOW
SOFTWARE-DEFINED NETWORKING AND OPENFLOW Freddie Örnebjär TREX Workshop 2012 2012 Brocade Communications Systems, Inc. 2012/09/14 Software-Defined Networking (SDN): Fundamental Control
The Internet: A Remarkable Story. Inside the Net: A Different Story. Networks are Hard to Manage. Software Defined Networking Concepts
The Internet: A Remarkable Story Software Defined Networking Concepts Based on the materials from Jennifer Rexford (Princeton) and Nick McKeown(Stanford) Tremendous success From research experiment to
ViSION Status Update. Dan Savu Stefan Stancu. D. Savu - CERN openlab
ViSION Status Update Dan Savu Stefan Stancu D. Savu - CERN openlab 1 Overview Introduction Update on Software Defined Networking ViSION Software Stack HP SDN Controller ViSION Core Framework Load Balancer
VXLAN: Scaling Data Center Capacity. White Paper
VXLAN: Scaling Data Center Capacity White Paper Virtual Extensible LAN (VXLAN) Overview This document provides an overview of how VXLAN works. It also provides criteria to help determine when and where
How OpenFlow-based SDN can increase network security
How OpenFlow-based SDN can increase network security Charles Ferland, IBM System Networking Representing the ONF [email protected] +49 151 1265 0830 Important elements The objective is to build SDN networks
Using SouthBound APIs to build an SDN Solution. Dan Mihai Dumitriu Midokura Feb 5 th, 2014
Using SouthBound APIs to build an SDN Solution Dan Mihai Dumitriu Midokura Feb 5 th, 2014 Agenda About Midokura Drivers of SDN & Network Virtualization Adoption SDN Architectures Why OpenDaylight? Use
SDN Overview for UCAR IT meeting 19-March-2014. Presenter Steven Wallace ([email protected]) Support by the GENI Program Office!
SDN Overview for UCAR IT meeting 19-March-2014 Presenter Steven Wallace ([email protected]) Support by the GENI Program Office! Patterns (here, there, everywhere) Patterns (here, there, everywhere) Today s Internet
BRINGING NETWORKS TO THE CLOUD ERA
BRINGING NETWORKS TO THE CLOUD ERA SDN enables new business models Aruna Ravichandran VICE PRESIDENT, MARKETING AND STRATEGY [email protected] SOFTWARE DEFINED NETWORKING (SDN), JUNIPER NETWORKS
Software Defined Networks
Software Defined Networks Damiano Carra Università degli Studi di Verona Dipartimento di Informatica Acknowledgements! Credits Part of the course material is based on slides provided by the following authors
Software Defined Network (SDN) for Service Providers
Software Defined Network (SDN) for Service Providers Santanu Dasgupta Sr. Consulting Engineer Global Service Provider HQ SANOG 21 January 28th, 2013 2011 2010 Cisco and/or its affiliates. All rights Cisco
SDN Getting Started Guide
SDN Getting Started Guide Early Access February 2015 Release 9034842 Published April 2015 Copyright 2015 All rights reserved. Legal Notice Extreme Networks, Inc., on behalf of or through its wholly-owned
Network Virtualization Solutions
Network Virtualization Solutions An Analysis of Solutions, Use Cases and Vendor and Product Profiles October 2013 The Independent Community and #1 Resource for SDN and NFV Tables of Contents Introduction
Multiple Service Load-Balancing with OpenFlow
2012 IEEE 13th International Conference on High Performance Switching and Routing Multiple Service Load-Balancing with OpenFlow Marc Koerner Technische Universitaet Berlin Department of Telecommunication
Panel: Cloud/SDN/NFV 黃 仁 竑 教 授 國 立 中 正 大 學 資 工 系 2015/12/26
Panel: Cloud/SDN/NFV 黃 仁 竑 教 授 國 立 中 正 大 學 資 工 系 2015/12/26 1 Outline Cloud data center (CDC) Software Defined Network (SDN) Network Function Virtualization (NFV) Conclusion 2 Cloud Computing Cloud computing
SDN FOR IP/OPTICAL TRANSPORT NETWORKS
SDN FOR IP/OPTICAL TRANSPORT NETWORKS Tony Kourlas IP Routing and Transport Group, Alcatel-Lucent April 2014 THE EVOLUTION OF IP & OPTICAL NETWORKS Cloud-optimized IP routing & transport IP routing networks
Applications of Software-Defined Networking (SDN) in Power System Communication Infrastructure: Benefits and Challenges
Applications of Software-Defined Networking (SDN) in Power System Communication Infrastructure: Benefits and Challenges Jasson Casey and Alex Sprintson Texas A&M University ([email protected] and [email protected]
THE REVOLUTION TOWARDS SOFTWARE- DEFINED NETWORKING
THE REVOLUTION TOWARDS SOFTWARE- DEFINED NETWORKING Transforming Networking with Open SDN Guido Appenzeller April, 2013 JOIN THE REVOLUTION TOWARDS OPEN NETWORKING Independence from closed, proprietary
Network Security Demonstration - Snort based IDS Integration -
Network Security Demonstration - Snort based IDS Integration - Hyuk Lim ([email protected]) with TJ Ha, CW Jeong, J Narantuya, JW Kim Wireless Communications and Networking Lab School of Information and
Spotlight On Backbone Technologies
Spotlight On Backbone Technologies Shawn Stevens Technical Lead, Data Center Technologies CCIE #4618 [email protected] CDW.com/network 800.800.4239 Agenda Overview of Software-Defined Networking (SDN)
Software-Defined Networking Architecture Framework for Multi-Tenant Enterprise Cloud Environments
Software-Defined Networking Architecture Framework for Multi-Tenant Enterprise Cloud Environments Aryan TaheriMonfared Department of Electrical Engineering and Computer Science University of Stavanger
Qualifying SDN/OpenFlow Enabled Networks
Qualifying SDN/OpenFlow Enabled Networks Dean Lee Senior Director, Product Management Ixia Santa Clara, CA USA April-May 2014 1 Agenda SDN/NFV a new paradigm shift and challenges Benchmarking SDN enabled
Leveraging SDN and NFV in the WAN
Leveraging SDN and NFV in the WAN Introduction Software Defined Networking (SDN) and Network Functions Virtualization (NFV) are two of the key components of the overall movement towards software defined
SDN, OpenFlow and the ONF
SDN, OpenFlow and the ONF OpenFlow/Software-Defined Networking (SDN) OpenFlow/SDN is emerging as one of the most promising and disruptive networking technologies of recent years. It has the potential to
Carrier/WAN SDN Brocade Flow Optimizer Making SDN Consumable
Brocade Flow Optimizer Making SDN Consumable Business And IT Are Changing Like Never Before Changes in Application Type, Delivery and Consumption Public/Hybrid Cloud SaaS/PaaS Storage Users/ Machines Device
SDN PARTNER INTEGRATION: SANDVINE
SDN PARTNER INTEGRATION: SANDVINE SDN PARTNERSHIPS SSD STRATEGY & MARKETING SERVICE PROVIDER CHALLENGES TIME TO SERVICE PRODUCT EVOLUTION OVER THE TOP THREAT NETWORK TO CLOUD B/OSS AGILITY Lengthy service
Group-Based Policy for OpenStack
Group-Based Policy for OpenStack Introduction Over the past four years, OpenStack has grown from a simple open source project to a major community-based initiative including thousands of contributors in
SDN CONTROLLER. Emil Gągała. PLNOG, 30.09.2013, Kraków
SDN CONTROLLER IN VIRTUAL DATA CENTER Emil Gągała PLNOG, 30.09.2013, Kraków INSTEAD OF AGENDA 2 Copyright 2013 Juniper Networks, Inc. www.juniper.net ACKLOWLEDGEMENTS Many thanks to Bruno Rijsman for his
Outline. Why Neutron? What is Neutron? API Abstractions Plugin Architecture
OpenStack Neutron Outline Why Neutron? What is Neutron? API Abstractions Plugin Architecture Why Neutron? Networks for Enterprise Applications are Complex. Image from windowssecurity.com Why Neutron? Reason
Cisco and Canonical: Cisco Network Virtualization Solution for Ubuntu OpenStack
Solution Overview Cisco and Canonical: Cisco Network Virtualization Solution for Ubuntu OpenStack What You Will Learn Cisco and Canonical extend the network virtualization offered by the Cisco Nexus 1000V
Software Defined Networks (SDN)
Software Defined Networks (SDN) Nick McKeown Stanford University With: Martín Casado, Teemu Koponen, Scott Shenker and many others With thanks to: NSF, GPO, Stanford Clean Slate Program, Cisco, DoCoMo,
Software-Defined Networking. Starla Wachsmann. University Of North Texas
Running head: Software-Defined Networking (SDN) Software-Defined Networking Starla Wachsmann University Of North Texas What is Software-Defined Networking? Software-Defined Networking has one consistent
Virtualization, SDN and NFV
Virtualization, SDN and NFV HOW DO THEY FIT TOGETHER? Traditional networks lack the flexibility to keep pace with dynamic computing and storage needs of today s data centers. In order to implement changes,
Virtualized Network Services SDN solution for enterprises
Virtualized Network Services SDN solution for enterprises Nuage Networks Virtualized Network Services (VNS) is a fresh approach to business networking that seamlessly links your enterprise s locations
OpenFlow: Concept and Practice. Dukhyun Chang ([email protected])
OpenFlow: Concept and Practice Dukhyun Chang ([email protected]) 1 Contents Software-Defined Networking (SDN) Overview of OpenFlow Experiment with OpenFlow 2/24 Software Defined Networking.. decoupling
How OpenFlow -Based SDN Transforms Private Cloud. ONF Solution Brief November 27, 2012
How OpenFlow -Based SDN Transforms Private Cloud ONF Solution Brief November 27, 2012 Table of Contents 2 Executive Summary 2 Trends in the Private Cloud 3 Network Limitations and Requirements 4 OpenFlow-Based
SDN and NFV in the WAN
WHITE PAPER Hybrid Networking SDN and NFV in the WAN HOW THESE POWERFUL TECHNOLOGIES ARE DRIVING ENTERPRISE INNOVATION rev. 110615 Table of Contents Introduction 3 Software Defined Networking 3 Network
Introduction to Software Defined Networking
Introduction to Software Defined Networking Introduction to SDN Ahmed Maged MENOG 15 Dubai April 2015 @amaged [email protected] Agenda What is SDN and What it is not SDN Trends Getting Ready for SDN 2
A Coordinated. Enterprise Networks Software Defined. and Application Fluent Programmable Networks
A Coordinated Virtual Infrastructure for SDN in Enterprise Networks Software Defined Networking (SDN), OpenFlow and Application Fluent Programmable Networks Strategic White Paper Increasing agility and
Evolution of Software Defined Networking within Cisco s VMDC
Evolution of Software Defined Networking within Cisco s VMDC Software-Defined Networking (SDN) has the capability to revolutionize the current data center architecture and its associated networking model.
