Metaswitch.com OvertureNetworks.com Management & Orchestration of Metaswitch s Perimeta Virtual SBC Fortify your edge and protect your core with the Perimeta Session Border Controller: Virtual The 1st virtual SBC deployed in commercial networks Secure Architected and proven to be most secure Analytical - Provides unequal analytics, diagnostic and debugging capabilities Faced with the explosive growth of SIP endpoints and the corresponding escalation of SIP messages associated with applications such as presence and instant messaging, enterprises need to secure their networks against intruders and ensure that authorized endpoints are enabled to gain access from across the public Internet. To achieve this, they need to deploy SBCs at the edge of their IP networks. However, the small scale of enterprise SBCs makes them particularly vulnerable to denial of service attacks. A single virus-infected PC that has a softphone application installed and configured for access to an enterprise network could very quickly bring down the enterprise SBC. Perimeta vsbc from Metaswitch is a session border controller that can be deployed as a virtual function in a SP network or on a virtual CPE, and affords tremendous advantages over the previous generation of appliance-based, vertically integrated session border controllers. Using Overtures Ensemble Management and Orchestration platform to introduce a carriergrade vsbc in the form of Perimeta as an enterprise SBC, CSP s are able to address these concerns in an agile and scalable manner. Overture and Metaswitch: Partners for Managed vsbc Metaswitch have partnered with Overture to deliver a single solution that can realize a reduction in capital and operational costs. Through virtualization using more cost effective COTS based hardware, a simplified signaling can be introduced using Overture s Ensemble Service Orchestrator. For fixed-line, mobile or competitive carriers, the Perimeta product portfolio and Overture s Orchestration meets the requirements of next generation infrastructures, such as LTE and IMS, while delivering the performance required to support rich unified communications services that are innovative, sticky and can deliver on the promise of increasing revenue. In combining a Management and Orchestration (MANO) platform and the first and only carrierclass software based Virtual SBC, Overture and Metaswitch have delivered a joint solution that will ultimately simplify the delivery of SIP based services in a Virtualized Network.
2 Management & Orchestration of Metaswitch s Perimeta Virtual SBC Overture s Ensemble Open Service Architecture (OSA ) Overture s Ensemble Open Service Architecture (OSA ) is the industry s first open architecture to deliver carrier-class NFV MANO and automation at the metro service edge. Through the Ensemble Service Orchestrator (ESO) and Ensemble Network Controller (ENC), Overture enables Communication Service Providers (CSP s) to coordinate virtual resources and physical network elements to create, activate and assure services using one or more virtual network functions (VNF). With Ensemble OSA and NFV, service providers can add services like the Metaswitch Perimeta vsbc and additional virtual services (e.g. managed routers) on demand to create the required network environment for delivering tomorrows services in a fast and efficient way. This can all be done without changing the CPE or adding additional point-based physical appliances. Ensemble Service Orchestration (ESO) The ESO is an open, extensible carrier-class NFV service lifecycle management and orchestration system that coordinates virtual resources and physical network elements to create, activate and assure services using one or more virtual network functions. ESO uses the OpenStack cloud controller bundled with ESO to manage the virtual compute environment, including virtual machines, virtual switches and top-of-rack data center switches. For management of the physical wide area network traffic flows, ESO leverages Overture s Ensemble Network Controller, but it can also be integrated with other third-party network controllers.
3 Management & Orchestration of Metaswitch s Perimeta Virtual SBC THE OVERTURE METASWITCH ADVANTAGE The open, cloud-enabled and on-demand vsbc solution powered by Metaswitch and Overture reduces the need for multiple physical appliances, driving down the provider s overall costs allowing innovative service delivery and service support. ESO - Multi-Vendor NFV Lifecycle Management and Orchestration System Comprising three logical layers all interconnected via open (Restful) API s, Ensemble OSA is designed to easily integrate within the existing architecture and workflow of a CSP environment. The Orchestration and Control layer includes three components Ensemble Service Orchestrator (ESO), OpenStack Cloud Controller, Ensemble Service Intelligent and Ensemble Network Controller (ENC). ENC and ESO may be used together or independently based on the needs of the service provider. Frees up capital by minimizing expensive, proprietary hardware investments and on-going operational costs (management, space, power and cooling) Reduces the number of Truck-Rolls required for service rollouts and upgrades Open, flexible designs ensure the solution can integrate within any environment Turnkey solution to accelerate service delivery Deliver Advanced Functionality Ensemble Service Intelligence (ESI) and Ensemble Network Controller (ENC) The ESI and related applications are the NFV lifecycle management and analytics component to ESO providing NFV performance, fault management, lifecycle dash board, capacity, inventory and other functions. The ENC serves in a dual role as the WAN Infrastructure Manager (WIM) and/or the EMS/NMS for the Carrier Ethernet infrastructure and VNFs. In addition to virtual SBC, using the same NFV MANO system, Service Providers can also offer managed routing, stateful firewall, intrusion detection, IP-PBX, WAN optimisation and a wide variety of other virtualised services without compromising the reliability and carrier-class performance of the underlying hardware
4 Management & Orchestration of Metaswitch s Perimeta Virtual SBC Centralised or Distributed NFV Infrastructures ESO supports the placement of virtual network functions (VNFs) in centralized data centres as well as distributed placement across multiple data centres, points of presence or customer-located CPE platform. Support for any VNF To enable the broadest possible service definitions, ESO is capable of instantiating any arbitrary combination of VNFs from best-of-breed, third party software vendors such as Metaswitch. ESO can automatically optimize placement of these VNFs based on predefined policies or dynamic conditions such as network congestion or compute performance degradation or diagnostic requirements. WEBUI or open API s for intergration into higher order systems Service providers may initially deploy ESO using its built-in, web-based graphical user interface and standard workflow. They can then transition to a fully automated environment by integrating ESO interfaces into higher-level systems and customizing the VNF management workflow.
5 Management & Orchestration of Metaswitch s Perimeta Virtual SBC USE CASE: Perimeta vsbc from Metaswitch Perimeta vsbc from Metaswitch Perimeta is the only session border controller architected as a pure software solution, and first in the market to be deployed by Tier1 carriers as a VNF. It is a critical component in the march towards network functions virtualization (NFV) and in helping to transition operators into being true software Telco s. Liberated from old hardware-based deployment models, carriers can realize savings in Capex and Opex while benefiting from a more flexible network on which they can launch innovative new applications and services more quickly. To this end, the communications industry is transitioning from being defined by specialized hardware to focusing on open and programmable virtual appliances running in private or public cloud computing environments. When combined with Overture s Management and Orchestration platform, network operators and enterprise users are able to secure the perimeter of their communications architecture with the first and only carrier-class software vsbc. Perimeta is deigned to face the new challenges brought by cloud environments: security and analytics. Perimeta has proven to support massive volumetric attacks, as well as application specific ones. It can also provide much needed data to improve the operator experience, and provide the ability to diagnose and debug any calls traversing the network, without affecting its performance. The Role of Session Control Session border controllers reside either at the interconnect point between two network providers or at the access boundary between a managed carrier infrastructure and residential or enterprise customers. With critical but diverse functions that now need to be virtualized, and include security and network visibility at session level, SBCs must perform their tasks without affecting network performance or resiliency. Virtual Perimeta is not dependent on any proprietary equipment, such as network processors. Instead, Perimeta can run on standard server hardware, providing cutting-edge performance and platform flexibility, while allowing for reuse of existing hardware and for great cost savings. This combined approach adds speed and agility to delivering new services while removing the cost and complexity of juggling multiple scarce resources using the principles of NFV and orchestration in an SDN enabled network environment. Perimeta is the first SBC de be deployed in an NFV architecture, and continues to prove that being designed from its inception to be a software function, is essential for the cloud and NFV environments. Not only that it provides a faster time to market, but it also lives up the promises of NFV: lower capex, lower opex, and no end of life. (Use Case - continues on page 6)
6 Management & Orchestration of Metaswitch s Perimeta Virtual SBC (Use Case - continued from page 5) Secure The Perimeta product portfolio has been designed for performance. By working closely with Intel, Perimeta provides the strength to resist DoS attacks by discarding packets at line rate. Perimeta s intelligent blacklisting and rate-limiting functions protect vulnerable devices from distributed denial of service (DDoS) or flooding attacks. Perimeta s overload prevention and adaptive traffic management protect your network from continuously extreme or bursty signaling and media loads. Intelligent traffic management guarantees that signaling and media packets are processed and queued optimally. Packets are marked with standardized differentiated services code points (DSCP) for proper handling by intermediate network switches and routers. SIP is used in many varieties and interpretations in multi-vendor networks, which is one of the reasons for being a much more vulnerable protocol. Perimeta s SIP Message Manipulation Framework is used to prevent any SIP attacks, and also making sure that appropriate traffic is inter-worked properly by modifying SIP headers and message bodies that proxies cannot, to ensure that session control functions operate in every circumstance. Analytics Perimeta provides a level of insight into the network that is unmatched in the industry. Perimeta provides the operator with the ability to store every signaling and control packet through the network, view all network activity, and provide activity and alarms in a format that provides immediate context for the operator. The operator can easily diagnose any issue, and because the data is always available on a per call basis, there is no need to replicate the issue. Furthermore, it provides data at protocol and call flow level, therefore the issues can be easily debugged and fixed, cutting significant operational costs.
7 Management & Orchestration of Metaswitch s Perimeta Virtual SBC Overture and Metaswitch: Perimeta Virtual SBC Solution The perimeter of a communications network is only as strong as its weakest link. Beyond the boundary of the managed infrastructure lie many threats to the continuity of service offerings and to the integrity of your network. Overtures Management and Orchestration (MANO) platform when combined with the first and only carrier-class virtual SBC from Metaswitch, enables CSP s and enterprises alike to fortify the edge and protect the core in the most scalable, agile and cost effective way possible. Overture and Metaswitch have delivered a joint solution that will ultimately simplify the delivery of SIP based services in a Virtualised Network. Metaswitch is powering the transition of communication networks into a cloud-based, software-centric future. The company develops openly programmable solutions that run on standard hardware or in virtualized environments and act as the key control points in elastic voice, video and data networks. In its 30-year history, Metaswitch has helped hundreds of service providers worldwide advance their infrastructures, retain their customers, extend their brands and reduce their costs through every major network transformation. Overture is the preferred provider of Carrier Ethernet solutions for the metro service edge. By leveraging Overture s Carrier Ethernet expertise and its new Ensemble Open Service Architecture for software-defined services, network operators and service providers worldwide are maximizing operational efficiencies and introducing new revenue-generating services on a scale never before possible. Learn more at www.overturenetworks.com 2015 Overture All Rights Reserved. HAR-METASWITCH-021615 Notice: This document is for informational purposes only and does not set forth any warranty, expressed or implied, concerning any equipment, equipment feature, or service offered or to be offered by Overture. Overture reserves the right to make changes to this document at any time, without notice, and assumes no responsibility for its use. This informational document describes features that may not be currently available. Contact a Overture sales office for information on feature and product availability. Export of technical data contained in this document may require an export license from the United States government. overturenetworks.com/harmony