Building Scalable Multi-Tenant Cloud Networks with OpenFlow and OpenStack



Similar documents
Network Virtualization for the Enterprise Data Center. Guido Appenzeller Open Networking Summit October 2011

Virtualization, SDN and NFV

Data Center Network Virtualisation Standards. Matthew Bocci, Director of Technology & Standards, IP Division IETF NVO3 Co-chair

PLUMgrid Open Networking Suite Service Insertion Architecture

SOFTWARE DEFINED NETWORKING

Network Virtualization and Software-defined Networking. Chris Wright and Thomas Graf Red Hat June 14, 2013

SINGLE-TOUCH ORCHESTRATION FOR PROVISIONING, END-TO-END VISIBILITY AND MORE CONTROL IN THE DATA CENTER

JUNIPER. One network for all demands MICHAEL FRITZ CEE PARTNER MANAGER. 1 Copyright 2010 Juniper Networks, Inc.

Open Source Networking for Cloud Data Centers

Software Defined Network (SDN)

Data Center Infrastructure of the future. Alexei Agueev, Systems Engineer

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

Network Virtualization

Software Defined Networking - a new approach to network design and operation. Paul Horrocks Pre-Sales Strategist 8 th November 2012

Software-Defined Networks Powered by VellOS

HAWAII TECH TALK SDN. Paul Deakin Field Systems Engineer

2013 ONS Tutorial 2: SDN Market Opportunities

Data Center Virtualization and Cloud QA Expertise

Cisco Prime Network Services Controller. Sonali Kalje Sr. Product Manager Cloud and Virtualization, Cisco Systems

SDN v praxi overlay sítí pro OpenStack Daniel Prchal daniel.prchal@hpe.com

Outline. Why Neutron? What is Neutron? API Abstractions Plugin Architecture

SDN CONTROLLER. Emil Gągała. PLNOG, , Kraków

VIRTUALIZED SERVICES PLATFORM Software Defined Networking for enterprises and service providers

Enterprise Data Center Networks

Networking in the Era of Virtualization

Debunking the Myths: An Essential Guide to Software-Defined Networking April 17, 2013

CLOUD NETWORKING THE NEXT CHAPTER FLORIN BALUS

Simplify Your Data Center Network to Improve Performance and Decrease Costs

Scalable Approaches for Multitenant Cloud Data Centers

OpenFlow/SDN activities of NTT Communications

Testing Software Defined Network (SDN) For Data Center and Cloud VERYX TECHNOLOGIES

Software Defined Networks Virtualized networks & SDN

Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre

Extending Networking to Fit the Cloud

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器

Proactively Secure Your Cloud Computing Platform

How To Make A Vpc More Secure With A Cloud Network Overlay (Network) On A Vlan) On An Openstack Vlan On A Server On A Network On A 2D (Vlan) (Vpn) On Your Vlan

The promise of SDN. EU Future Internet Assembly March 18, Yanick Pouffary Chief Technologist HP Network Services

Building an Open, Adaptive & Responsive Data Center using OpenDaylight

White Paper. Juniper Networks. Enabling Businesses to Deploy Virtualized Data Center Environments. Copyright 2013, Juniper Networks, Inc.

Multitenancy Options in Brocade VCS Fabrics

What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates

How To Build A Software Defined Data Center

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Network Virtualization

Definition of a White Box. Benefits of White Boxes

The Value of Open vswitch, Fabric Connect and Fabric Attach in Enterprise Data Centers

Use Case Brief NETWORK SECURITY

SDN/Virtualization and Cloud Computing

Palo Alto Networks. Security Models in the Software Defined Data Center

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

Core and Pod Data Center Design

Analysis of Network Segmentation Techniques in Cloud Data Centers

EVOLVED DATA CENTER ARCHITECTURE

Using SouthBound APIs to build an SDN Solution. Dan Mihai Dumitriu Midokura Feb 5 th, 2014

The Path to the Cloud

Why Software Defined Networking (SDN)? Boyan Sotirov

Introduction to Network Virtualization in IaaS Cloud. Akane Matsuo, Midokura Japan K.K. LinuxCon Japan 2013 May 31 st, 2013

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

Cloud Networking Disruption with Software Defined Network Virtualization. Ali Khayam

May 13-14, Copyright 2015 Open Networking User Group. All Rights Reserved Not For

Windows Server 2012 Hyper-V Virtual Switch Extension Software UNIVERGE PF1000 Overview. IT Network Global Solutions Division UNIVERGE Support Center

How Network Virtualization can improve your Data Center Security

Designing Virtual Network Security Architectures Dave Shackleford

SDN PARTNER INTEGRATION: SANDVINE

Network Virtualization Solutions

The Next Frontier for SDN: SDN Transport

White Paper. SDN 101: An Introduction to Software Defined Networking. citrix.com

Brocade VCS Fabrics: The Foundation for Software-Defined Networks

Datacenter Networking. Joy ABOIM Consulting System Engineer

Network Virtualization: Delivering on the Promises of SDN. Bruce Davie, Principal Engineer

Scalable Network Monitoring with SDN-Based Ethernet Fabrics

VMware

Simplifying Virtual Infrastructures: Ethernet Fabrics & IP Storage

Network Virtualization for Large-Scale Data Centers

Pluribus Netvisor Solution Brief

CON Software-Defined Networking in a Hybrid, Open Data Center

Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera VERSION May, 2015

Simplify the Data Center with Junos Fusion

A Case for Overlays in DCN Virtualization Katherine Barabash, Rami Cohen, David Hadas, Vinit Jain, Renato Recio and Benny Rochwerger IBM

Installing Intercloud Fabric Firewall

DCB for Network Virtualization Overlays. Rakesh Sharma, IBM Austin IEEE 802 Plenary, Nov 2013, Dallas, TX

VMware NSX A Perspective for Service Providers part 2

Fabrics that Fit Matching the Network to Today s Data Center Traffic Conditions

SDN and Data Center Networks

CONNECTING PHYSICAL AND VIRTUAL WORLDS WITH VMWARE NSX AND JUNIPER PLATFORMS

Brocade Data Center Fabric Architectures

Adopting Software-Defined Networking in the Enterprise

Securing the Virtualized Data Center With Next-Generation Firewalls

NETWORK AUTOMATION AND ORCHESTRATION

BROCADE NETWORKING: EXPLORING SOFTWARE-DEFINED NETWORK. Gustavo Barros Systems Engineer Brocade Brasil

THE REVOLUTION TOWARDS SOFTWARE- DEFINED NETWORKING

Brocade Data Center Fabric Architectures

Use Case Brief BUILDING A PRIVATE CLOUD PROVIDING PUBLIC CLOUD FUNCTIONALITY WITHIN THE SAFETY OF YOUR ORGANIZATION

How To Orchestrate The Clouddusing Network With Andn

Transcription:

Building Scalable Multi-Tenant Cloud Networks with OpenFlow and OpenStack Dave Tucker Hewlett-Packard April 2013 1

About Me Dave Tucker WW Technical Marketing HP Networking dave.j.tucker@hp.com Twitter: @dave_tucker April 2013 2

What we will cover Cloud Network Requirements Cloud Network Design Creating a Network Abstraction with OF Automating the cloud with OpenStack Q&A

Which cloud are we talking about? Enterprise Private Cloud Public Cloud Telecom Cloud Integration with legacy estates Support for legacy application & behaviors L2 adjacency mechanism to enable P2V migration Live workload mobility Accessed over Internet Massive scale 10s of thousands of projects 100s of thousands of VMs Flexibility unconstrained by HW innovation cycle Extreme cost sensitivity Pay-as-you-go use model Integration of multitenancy into telecom core Distributed datacenters Requirements trickle down

Critical cloud requirements Enable Competitive Cost Structure The network should not constrain scale Consistent Performance @ Scale Avoid Brown-Outs & Luck of the Draw Performance isolation High performance multi-path fabric Secure Multi-Tenancy @ Scale System segregation Enforcement of tenant policies Reliable Automation @ Scale Sustain high rate of churn High Availability Tolerate & isolate failures (server, AZ, region) Flexibility Avoid vendor lock-in Avoid lock-in to specific HW function Develop and deploy new services independent of HW development cycles Hypervisor Agnostic Network Model Consistent security & functional models across multiple hypervisors Fabric Independent L2 Functional Model Maintain Standard Network Behaviors

Not all apps are created equal Application Requirements Does the app depend on infrastructure for availability? Does the app implement multi-tenancy & is it trustworthy? What level of infrastructure affinity does the app have? What is the app doing to data in flight? Ultimately, you ll likely have to support all of these! Architectural flexibility to support racks of various network blocking ratios Multi-tenancy solution which comprehends both virtual and bare metal Support for multiple HW builds

Accomplishing tenant segregation HW-Centric? SW-Centric? Encapsulate in ToR switch Switch to Destination VM Switch to Gateway Encapsulate in vswitch Tunnel to Destination VM Tunnel to vgw - Higher acquisiton cost - Multi-Tier automation - HW Innovation pace + Edge-only automation + SW Innovation Pace - N/S traffic become E/W A SW-centric approach to multi-tenancy within the cloud is not ideal but it s the right answer today. And it s moving in the right direction for tomorrow. April 2013 7

Performance @ Scale Deterministic Performance Avoid Excessive Oversubscription Allow internal environments to scale without incurring cost of scaling expensive core components Controlled oversubscription between fabrics to enable high performance comms & maintain cost controls Low to No oversubscription within the L2 Fabric where most east-west comms occur Traffic Policing Prohibit individual guests from impacting their neighbors through overconsumption of network resources Subsume Segregation & Policy Enforcement Into the Hypervisor Use existing integrated firewall capability to build a massively scalable distributed firewall Avoid highly expensive firewall appliances Avoid network choke points associated with network services appliances Implement virtual network layer to enforce tenant segregation Avoid dependence on infrastructure elements for segregation April 2013 8

Reliable Automation @ Scale OpenFlow provides a means for a Network controller to influence the data plane SDN Controller provides a broader Network Abstraction via its Northbound API This abstraction is the perfect interface to Cloud Orchestration tooling April 2013 9

Automating with OpenStack OpenStack provides a common provisioning platform for the cloud Quantum provides networking functions. Intelligence is implemented in plugins Simple shim plugin is all that is required to convert Quantum API to Controller API April 2013 10

Cloud Network Building Blocks Client Access Network MPLS WWW Tenant Connectivity DC Core Carrier Integration & Peering Intra-DC Compute Zone Integration DC resiliency DC Fabric Compute Node Connectivity Deterministic Performance Compute Resiliency Compute Networking vswitch vswitch Tenant Security Data Center Interconnect Synchronization DWDM VPLS Inter-Tool communication Out-of-band access April 2013 11

Multi-Tenancy: HP Virtual Cloud Networks Cloud Network Orchestration Network Controller Network Router Traditional Switch Fabric Private Encapsulated vnet Private Encapsulated vnet Private Encapsulated vnet Public VLAN Open vswitch (Encap & PEP) Open vswitch (Encap & PEP) Open vswitch (Encap & PEP) Guest Guest Guest Guest Guest Guest Guest Guest Guest Guest Guest Guest Compute Node Compute Node Network Node

The End-game is Multi-Layer SDN HW-Centric SW-Centric Encap in ToR Switch Switch to Destination VM Switch to vgw Encap in vswitch i.e. VLAN, PBB Tunnel to Destination VM Tunnel to vgw Software-Defined Cloud Networks Multi-Layer SDN Traffic Policy Enforced in Fabric Cost Effective Topology Flexibility Simplified Fabric Automation HW Support of Generic UDP Tunneling Efficient Broadcast & Multicast Support i.e. HP VCN, VMWare NVP

What does this enable? Multi-Layer SDN? Avoid tromboning through GW VMs or appliances Traffic Policy Enforced in Fabric? Simple & efficient implementation of inline security & load balancing services Cost Effective Topology Flexibility More capable fabrics without excessive cost Simplified Fabric Automation Abstraction of control plan reduces complexity and risk of multi-tier automation HW Support of Generic UDP Tunneling Enable integration of SW-centric multi-tenancy models with HW-centric solutions

Thank You! April 2013 15

Q&A April 2013 16