Foundation for High-Performance, Open and Flexible Software and Services in the Carrier Network. Sandeep Shah Director, Systems Architecture EZchip



Similar documents
Use Cases for the NPS the Revolutionary C-Programmable 7-Layer Network Processor. Sandeep Shah Director, Systems Architecture EZchip

Definition of a White Box. Benefits of White Boxes

Accelerating the Data Plane With the TILE-Mx Manycore Processor

Virtualization, SDN and NFV

Delivering Managed Services Using Next Generation Branch Architectures

Telecom - The technology behind

The Role of Virtual Routers In Carrier Networks

Bringing OpenFlow s Power to Real Networks

Using Network Virtualization to Scale Data Centers

NFV Acceleration with the EZchip NPS-400 Network Processor

How To Make A Vpc More Secure With A Cloud Network Overlay (Network) On A Vlan) On An Openstack Vlan On A Server On A Network On A 2D (Vlan) (Vpn) On Your Vlan

Optimizing Data Center Networks for Cloud Computing

Network Function Virtualization Using Data Plane Developer s Kit

The Road to SDN: Software-Based Networking and Security from Brocade

Using SDN-OpenFlow for High-level Services

SDN PARTNER INTEGRATION: SANDVINE

Accelerating Micro-segmentation

基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器

Programmable Networking with Open vswitch

EZchip Investor Presentation

Dynamic Service Chaining for NFV/SDN

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

L2-L7 BASED SERVICE REDIRECTION WITH SDN/OPENFLOW

BROCADE NETWORKING: EXPLORING SOFTWARE-DEFINED NETWORK. Gustavo Barros Systems Engineer Brocade Brasil

How To Orchestrate The Clouddusing Network With Andn

SDN and NFV in the WAN

Palo Alto Networks. Security Models in the Software Defined Data Center

BROADCOM SDN SOLUTIONS OF-DPA (OPENFLOW DATA PLANE ABSTRACTION) SOFTWARE

Evaluation and Characterization of NFV Infrastructure Solutions on HP Server Platforms

COMPUTING. Centellis Virtualization Platform An open hardware and software platform for implementing virtualized applications

OpenFlow: History and Overview. Demo of routers

SDN Testing & Validation ONF SDN Solutions Showcase Theme Demonstrations

Software Defined Network (SDN)

Different NFV/SDN Solutions for Telecoms and Enterprise Cloud

AppDirector Load balancing IBM Websphere and AppXcel

Data and Control Plane Interconnect solutions for SDN & NFV Networks Raghu Kondapalli August 2014

Leveraging SDN and NFV in the WAN

Challenges and Opportunities:

Intel Network Builders: Lanner and Intel Building the Best Network Security Platforms

Software-Defined Networking Architecture Framework for Multi-Tenant Enterprise Cloud Environments

IO Visor: Programmable and Flexible Data Plane for Datacenter s I/O

HAWAII TECH TALK SDN. Paul Deakin Field Systems Engineer

Network Technologies for Next-generation Data Centers

NFV Network and Compute Intensive H/W Acceleration (using SDN/PI forwarding)

Cloud Networking Disruption with Software Defined Network Virtualization. Ali Khayam

NFV: Addressing Global Challenges for Telecom Service Providers

Panel: Cloud/SDN/NFV 黃 仁 竑 教 授 國 立 中 正 大 學 資 工 系 2015/12/26

High-performance vswitch of the user, by the user, for the user

Blue Planet. Introduction. Blue Planet Components. Benefits

TIME TO RETHINK REAL-TIME BIG DATA ANALYTICS

Qualifying SDN/OpenFlow Enabled Networks

Software-Defined Network (SDN) & Network Function Virtualization (NFV) Po-Ching Lin Dept. CSIE, National Chung Cheng University

OpenStack Networking: Where to Next?

Ensuring end-user quality in NFV-based infrastructures

Securing the Intelligent Network

Assessing the Performance of Virtualization Technologies for NFV: a Preliminary Benchmarking

Testing Software Defined Network (SDN) For Data Center and Cloud VERYX TECHNOLOGIES

Data Center Network Virtualisation Standards. Matthew Bocci, Director of Technology & Standards, IP Division IETF NVO3 Co-chair

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

White Paper. SDN 101: An Introduction to Software Defined Networking. citrix.com

Linux KVM Virtual Traffic Monitoring

Certes Networks Layer 4 Encryption. Network Services Impact Test Results

Scalable Network Monitoring with SDN-Based Ethernet Fabrics

Virtual CDNs: Maximizing Performance While Minimizing Cost

Enhancing Hypervisor and Cloud Solutions Using Embedded Linux Iisko Lappalainen MontaVista

Pluribus Netvisor Solution Brief

Radware s Attack Mitigation Solution On-line Business Protection

SOFTWARE DEFINED NETWORKING

Intel Network Builders Solution Brief. Intel and ASTRI* Help Mobile Network Operators Support Small Cell Networks

WHITE PAPER. Network Virtualization: A Data Plane Perspective

Beyond the Data Center: How Network-Function Virtualization Enables New Customer-Premise Services

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Towards Software Defined Cellular Networks

Network Virtualization and Software-defined Networking. Chris Wright and Thomas Graf Red Hat June 14, 2013

Network Virtualization for Large-Scale Data Centers

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

Network Virtualization Technologies and their Effect on Performance

Intel Ethernet Switch Load Balancing System Design Using Advanced Features in Intel Ethernet Switch Family

White Paper. Innovate Telecom Services with NFV and SDN

Intel DPDK Boosts Server Appliance Performance White Paper

Deliver the Next Generation Intelligent Datacenter Fabric with the Cisco Nexus 1000V, Citrix NetScaler Application Delivery Controller and Cisco vpath

Jun (Jim) Xu Principal Engineer, Futurewei Technologies, Inc.

CloudLink - The On-Ramp to the Cloud Security, Management and Performance Optimization for Multi-Tenant Private and Public Clouds

Carrier/WAN SDN. SDN Optimized MPLS Demo

Corporate Network Services of Tomorrow Business-Aware VPNs

Networking Goes Open-Source. Michael Zimmerman VP Marketing, Tilera

Building an Open, Adaptive & Responsive Data Center using OpenDaylight

Cisco Wireless Security Gateway R2

Radware s AppDirector and AppXcel An Application Delivery solution for applications developed over BEA s Weblogic

Network Functions Virtualization Using Intel Ethernet Multi-host Controller FM10000 Family

Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre

What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates

Software Defined Networking (SDN) - Open Flow

Developing High-Performance, Flexible SDN & NFV Solutions with Intel Open Network Platform Server Reference Architecture

Scaling the S in SDN at Azure. Albert Greenberg Distinguished Engineer & Director of Engineering Microsoft Azure Networking

Transcription:

Foundation for High-Performance, Open and Flexible Software and Services in the Carrier Network Sandeep Shah Director, Systems Architecture EZchip Linley Carrier Conference June 10, 2015 1

EZchip Overview Fabless semiconductor company, NASDAQ listed (EZCH) Leading provider of high-performance data-path processing solutions for carrier, cloud and data center networks NPUs (Network Processors) Multi-core CPUs Intelligent adapters and appliances EZchip is a strategic supplier of NPUs to the top routing vendors and the highest placed and fastest growing NPU vendor Developing the NPS, the most powerful NPU for carrier edge routers, datacenter appliances and white-box solutions Following the Tilera acquisition, developing the TILE-Mx, the highest core count many-core CPU with EZchip's networking accelerators Founded in 1999; >280 employees, over 200 in R&D Global offices in Israel (HQ); San Jose, CA; Boston, MA; and China Strong financial model; $184M in cash, no debt 2

Agenda Challenges facing the carrier today EZchip NPS: Addressing the challenges with fully S/W programmable NPU NPS software stack NPS based solutions Carrier Edge Switch Router L4-7 load balancing L4-7 network visibility and control NFV acceleration Stateful security interception SDN smart switch 3

Carriers: The Challenge Carriers are pressured more than ever before With Flat revenues Declining income from traditional services Growing competition from OTT players Continued growth of overall traffic volumes There are two ways that carriers can improve their position: Lower OPEX through better operational efficiency Increase revenues by introducing new services 4

Carriers: Software as a Solution!? An increased emphasis on software promises to address the challenges discussed, offering: Improved operational flexibility Faster way to introduce new services Lowering proprietary HW lock down Current NFV and SDN offering has shown that, as promised, all can be done in software but the scalability and cost remain a challenge 5

NPS: Addressing the Challenge With its best of breed HW accelerators and massively parallel architecture NPS directly addresses the carriers needs SW services may be: Integrated into the router and switch or Deployed on servers with key data path computations being offloaded to NPS increasing the VM density lowering the overall solution s power & management costs maintaining the flexibility and openness of SW Providing quick development and deployment of powerful software services at scales, throughput rates and economies suitable for carrier networks 6

NPS: A Game Changer NPU 400 Gbps NPU C Programmable Security & DPI Hardware Accelerators NPS NPU Performance CPU Programmability Linux OS Traffic Management Layer2- Layer7 Processing 7

NPS Value Proposition Wire speed L2 & L3 switching and routing SDN, Openflow, MPLS, IPV4, IPV6, VXLAN, NVGRE, GENEVE and any packet format and tunneling scheme Scalable to support millions of subscribers & flows Completely flexible flow classification, stateful tracking, ACLs and policy enforcement Guaranteed SLAs Highly granular traffic scheduling, priority enforcement and bandwidth allocation Statistics collection for millions of programmable flows & events Netflow interface to any data collection and analysis tools L4 L7 services on top of L2 & L3 Load balancing, IPsec, access control, network monitoring, application recognition, DPI Best power & space efficiency Single 1U NPS-based system is equivalent to a rack full of servers Fully S/W programmable for adding new features & services on the fly 8

NPS Software NPS includes a large set of C libraries These are designed to make full use of the state of the art HW acceleration offered by the NPU Reference applications are provided to shorten development time and highlight the architecture s capabilities 9

NPS Middleware: SFT Stateful Flow Table (SFT) Providing HW accelerated, stateful, bi-directional flow awareness and user mapping Client agnostic supporting 50 million concurrent flows at rates of 400Gbps Stateful services developed using the SFT Seamlessly scales across the NPS s 4096 Linux machines SFT deals with packet ordering and tunnel stripping ahead of its clients SFT efficiently manages the flow state for itself and its clients through hardware acceleration Fast path APIs to apply policy to all the packets within a flow All of the above functionality and scalability is provided without any need for flow based locking 10

NPS Middleware: DPI DPI based Application Recognition Developed on top of the SFT Provides application recognition at rates up to 400Gbps Supports 1000+ standard signatures Includes HTTP and SIP parsers DPI signature compiler provided in support of 3rd party signatures Develops as if there is a single stream (i.e. flow) and seamlessly scales to 4096 threads. => Functionality Robustness Feature Velocity Scale 11

NPS provided Reference Applications L7 visibility through dedicated NetFlow reporting L2-3 Carrier Edge Switch & Router Reference application provided 6Wind Gate optimized solution available on x86 HTTP L4-7 Load Balancing Using the SFT and DPI libraries to provide content based LB IPsec NPS includes hardware crypto engines IPsec reference application provides decryption/encryption of IPsec traffic at rates of 200Gbps Lawful Interception Demonstrates the use of the NPS pattern matching acceleration OpenFlow Reference application provided NoviFlow NoviWare solution coming soon Accelerated implementation enables customers to update to the latest version via software download without requiring a hardware re-spin DPDK based application acceleration DPDK Poll-Mode Driver controlling an NPS device through PCIe bus Allows x86 application to use the NPS HW accelerations 12

NPS markets and applications Network Monitoring Switching & Routing SDN / NFV Lawful Interception NPS Targets Carrier and Data Center Networks Network Virtualization Network Appliances Load Balancers DPI Security 13

Solution: L7 Visibility and Control NPS provides L7 application visibility and control at unprecedented rates up to 400Gb on the router/switch: Carrier can identify how the network is used.. And through that: Identify and drive new services Provide much more intelligent policies and SLAs Optimize the network use to improve OPEX All without adding new appliances to network class-map match-all p2p-app match protocol attribute p2p-technology p2p-tech-yes policy-map control-policy class p2p-app police 8000 conform-action transmit exceed-action drop 14

Solution: Carrier Edge Switch Router NPS combines best-in-class HW accelerators with modern architecture offering scale and flexibility 400Gbps Linux based providing C programmability at all layers On-chip Traffic Manager 1M queues, 5-level Hierarchical-QoS Carrier-grade, field-proven, enabling traffic engineering and SLAs Enables subscriber isolation, bandwidth allocation and fully programmable policies IPsec through hardware acceleration Unique performance point enabling 100G IPsec tunnels for secure data center interconnect Support for very high scale of ACLs using on-chip TCAM with algorithmic extension to external DRAM Up to 96GB of DRAM for tables, stats, counters at wire-speed performance 15

Solution: NPS based Load Balancing Hardware accelerated mapping of traffic based on ACLs, Flows, L7 applications and service chains Dynamic load balancing among: Distributed VMs VNFs Blades Reference application uses on board HTTP parser to control traffic steering NFV Enabled Edge Router Smart NFV TOR Forwarding based on applicative flows Distributes traffic among cards based on L2-4 NPS enables smart equipment with load balancing NFV Accelerated White Box/Appliances/Blades Forwarding based on policy & content 16

Solution: NFV Acceleration NFV enabler Carriers require VNFs but are faced with scale issues VNFs are available but the number of servers/vms and related cost (e.g. equipment, power, management) limits actual large scale deployments The NPS distributed DP architecture directly addresses the scale issue by offloading the computation heavy parts of the VNFs High level architecture VNFs deployed in servers NPS serves as the fast path for policy and actions (e.g. QOS, encryption/decryption, drop, etc.) NPS decrypts and maps packets to flows, L7 application ID and users ahead of the service Packets received by the VNFs are already classified Host-based Fast Path Library and APIs allow services to enjoy the NPS acceleration without developing code on it 17

Solution: NFV Acceleration (cont.) NPS offloads: Crypto, DPI, classification, statistics and QOS, packet handling VNF focuses on business logic all the rest happens on the NPS Less computation per VM Larger VM density Lower power management Much better OPEX Achieving Scale while maintaining the openness and flexibility of SW solutions!!! of fast thepath fastlibrary. path library Developed Developed onon toptop of the Does Does not NPUNPU expertise notrequire require expertise Abstracts thethe NPSNPS acceleration Abstracts acceleration Deals with service chaining Constructs packet metadata Forwards packets 18

Solution: Stateful Security Inspection Offload Pattern matching offload for stateful security features such as IPS and Lawful Interception 200Gbps of HW accelerated Bloom filter based pattern matching Regex signatures are compiled out of box The loaded compiled signatures are matched using the accelerated Bloom filters DPI processes results in SW Suspected packets are forwarded for extra Regex matching Solution scales above 200Gbps through stateful bypass of un-interesting traffic small percentage of the traffic Loads compiled Regex signatures majority of the traffic Forwards suspected traffic for further processing 19

Solution: SDN Smart Switch Traditional SDN switch NPS based Smart TOR switch Always behind the latest OVS specs. Typical ASIC based SDN TOR switches have limited scalability OpenFlow connections to each Open vswitch in each server Non scalable scheme (10K-100K OpenFlow connections) Latest OVS support through SW update Managed Open vswitch integrated into TOR Server offload with switching and application services Tunneling to servers via VEB/VEPA Scalable Reduces system complexity 20

The Smart NPS White Box Switch - L2 /L3 forwarding - Data center bridging - Fixed encapsulation protocols - Limited scale Offloading VNF reduces the cost of NFV deployment - L2 /L3 forwarding & routing - Data center bridging - Multiple encapsulation protocols - VxLAN, NVGRE, STT - OVS offload & OpenFlow 1.3 ++ - Stateful flow table scaling to millions of flows - Classification & access control (ACL) - Load balancing - Firewall, security (IPsec, SSL) - DPI / application awareness - Traffic management - SLA enforcement - Network monitoring - TCP acceleration / termination - Service chaining 21

Summary Carriers are looking at software to provide improved OPEX and create new revenue streams. NPS provides a rich set of software libraries and infrastructure built on dedicated state of the art hardware accelerators. The scale and flexibility of NPS based services this allows are without precedent. NPS programmable packet processing enables the deployment of services at new rates and locations Opening new revenue opportunities Allowing improved manageability lowering OPEX Increasing the scale of NFV solutions All without the need to deploy extra appliances 22