7 FALLACIES OF NETWORK FUNCTION VIRTUALIZATION Steven Wright, MBA PhD JD Chair, ETSI NFV ISG ETSI 2015. All rights reserved
The Seven Fallacies* Recast to NFV The network is reliable. Latency is zero. Bandwidth is infinite. The network is secure. Topology doesn't change. -> VNF Designs assume the NFVI is NOT reliable -> Predictable Performance Matters -> Bandwidth Bottlenecks Occur -> Security by Design is Needed -> Change is Continuous There is one administrator. -> Independent Administrations Exist Transport cost is zero. -> Cost is Complicated The network is homogeneous. -> NFVI Heterogeneity is normal * With apologies to L. Peter Deutsch for the meme the 7 fallacies of distributed computing ETSI 2015. All rights reserved
VNF Designs Assume the NFVI is NOT reliable REL002: Scalable Architectures for Reliability Management Goal Develop an Informative Technical Report that: Examines Cloud/Data Center Techniques for Reliability Management for delivery of High Availability Develops Scalable Methods for Managing Network Reliability in NFV Environment Scope: Describe various types of conditions where Scalable Methods apply: Resource failures Bursty Traffic Conditions Describe scale-out techniques for instantiating new VNFs for such conditions Provide corroborating lab results
Predictable Performance Matters Acceleration & NFV Reference Points NFV Management and Orchestration OSS/BSS Os-Ma NFV Orchestrator Or-Vnfm NFVI EVE001 Hypervisor virtio EM 1 VNF 1 Computing Computing EM 2 EM 3 VNF 2 Vn-Nf IFA002 Storage isation Layer Vl-Ha Acceleration Resources Storage VNF 3 Network IFA003 resources Network Ve-Vnfm Nf-Vi IFA004 VNF Manager(s) Vi-Vnfm ised Infrastructure Manager(s) Service, VNF and Infrastructure Description IFA005 Or-Vi IFA006 IFA011 Deployment flavors, VDUs accelerationcapabilities SWA VNFC-VNFC KPI (EVE006: DMTF? QUEST?) Execution reference points Other reference points Main NFV reference points IFA001: overview IFA003: vswitch benchmarking / requirements ETSI 2015. All rights reserved REL: accelerator state migration SEC: EPD plugins, isolation acceleration TST: involvement
Bandwidth Bottlenecks Occur Figure 29 GS NFV INF 001 ETSI 2015. All rights reserved
Security by Design is Needed Problems identified in the NFV Security Problem Statement Topology Validation and Enforcement Availability of Management Support Infrastructure Secured Boot Secure Crash Performance Isolation User/Tenant Authentication, Authorization, and Accounting Authenticated Time Service Private Keys within Cloned Images Back-doors via ized Test and Monitoring Functions Multi-Administrator Isolation Security monitoring across multiple administrative domains (i.e., lawful interception) http://www.etsi.org/deliver/etsi_gs/nfv-sec/001_099/001/01.01.01_60/gs_nfv-sec001v010101p.pdf
Change is Continuous high-level objectives of NFV are: Rapid service innovation through software-based deployment and operationalization of network functions and end-toend services... GS NFV 001 Services can be rapidly scaled up/down as required. Operator NFV Whitepaper #1 capabilities needed for the continuous delivery of service in conformance with the service specification Operator NFV Whitepaper #2 Technology-driven innovation, where rapid development, continuous integration, deployment, and experimentation, meet business and service operations agility and enable the migration to next generation operations. GS NFV MANO 001 ETSI All rights reserved
Independent Administrations Exist Figure 4 / GS NFV 001 Use Cases ETSI All rights reserved
Cost is Complicated Lots of TCO Tradeoffs: Capex / Opex/ Time to Market Compute/Storage/network Direct / Indirect costs, etc Existing Network Function ized Network Functions Custom SW Obtain Custom SW #1 Obtain Custom SW #2 Obtain Install Install Install Custom HW Obtain COTS HW Obtain Install Install ETSI All rights reserved Figure 19 GS NFV INF 001
NFVI Heterogenity is normal EVE003: NFVI Node Architecture Report OSS/BSS Os-Ma NFV Management and Orchestration NFV Orchestrator Or-Vnfm Scope: Guidelines for NFVI node ARC: HW resources compute, storage, & network, to construct & support the functions of an NFVI node NFVI EM 1 VNF 1 Computing Computing EM 2 EM 3 VNF 2 Vn-Nf Storage isation Layer Vl-Ha Storage VNF 3 Network resources Network Ve-Vnfm Nf-Vi VNF Manager(s) Vi-Vnfm ised Infrastructure Manager(s) Service, VNF and Infrastructure Description Or-Vi General Principles & Key Criteria: Racks, Processors, Power, Interconnections, Cooling, Platform Management Open Compute Project Illustration EVE003 Scope
The NFV Transformation: Multiple Use Cases on Common infrastructure ETSI 2015. All rights reserved Figure 1 GS NFV INF 001