The networking declaration of independence How overlay networking gives you control of your networks Chris Swan, CTO @cpswan the original cloud networking company copyright 2014 1
Agenda What is NFV? Declaration of Independence NFV Capabilities Preview: Waves of Adoption copyright 2014 2
What is Network Function Virtualization? copyright 2014 3
Positioning - NFV and SDN copyright 2014 4
NFV can be a networking Swiss Army knife Application SDN (Software Defined Network) Appliances Allow control, mobility & agility by separating network location and network identity Control over end to end encryption, IP addressing and network topology NFV Hybrid Router Switch Firewall virtual device able to extend to IPsec/SSL VPN concentrator Protocol Redistributor Dynamic & Scriptable SDN multiple sites copyright 2014 5
Networking Declaration of Independence copyright 2014 6
Nicira s declaration of independence from metal, freed NFV from OpenFlow + http://nicira.com/sites/default/files/docs/nicira%20- %20The%20Seven%20Properties%20of%20Virtualization.pdf copyright 2014 7
These same properties free NFV from the constraints of OpenFlow (technology, timing and target) Nicira defined the 7 Properties of network virtualization as: 1. Independence from network hardware 2. Faithful reproduction of the physical network service model 3. Follow operational model of compute virtualization 4. Compatible with any hypervisor platform 5. Secure isolation between virtual networks, the physical network, and the control plane 6. Cloud performance and scale 7. Programmatic networking provisioning and control copyright 2014 8
Independence from network hardware Public Cloud Region 1 Overlay Network Cloud Server Overlay IP: 172.31.11.xx Standard IPsec Tunnel Cloud Server NFV Firewall / IPsec Device IP: 192.168.1.xx LAN Data Center Servers Customer Data Center With VM-based network devices you can use the cloud network as bulk transport and are indifferent to all else. copyright 2014 9
Reproduction of physical network model Public Cloud Region 1 Overlay Network Cloud Server Cloud Server NFV Standard IPsec Tunnel Virtual Network Data Center Servers Data Center Servers Customer Data Center NFV devices look and feel like the same networking devices customers have used for ever, without boundaries copyright 2014 10
Follow operational model of compute virtualization NFV NFV NFV NFV NFV functions can be dynamically brought on-line, up to the elastic limits of the total infrastructure available (!!) copyright 2014 11
Compatible with any hypervisor platform Public Clouds Private Clouds Virtual Infrastructure NFV does more than follow the model of compute virtualization, it exists via compute virtualization. copyright 2014 12
Secure isolation US East 1 EMEA APAC Overlay Network Subnet: 172.31.0.0/22 Cloud Server A Cloud Server B Cloud Server C Cloud Server D Cloud Server E Cloud Server F Overlay IP: 172.31.1.1 Overlay IP: 172.31.1.5 Overlay IP: 172.31.1.9 Overlay IP: 172.31.1.13 Overlay IP: 172.31.1.17 Overlay IP: 172.31.1.21 NFV Public IP: 184.73.174.250 Overlay IP: 172.31.1.250 Active IPsec 192.168.3.0/24 Tunnel - 172.31.1.0/24 Firewall / IPsec Cisco 5505 Peered NFV Public IP: 54.246.224.156 Overlay IP: 172.31.1.246 Failover IPsec Tunnel Peered Public IP: 192.158.29.143 Overlay IP: 172.31.1.242 Active IPsec Tunnel 192.168.4.0/24-172.31.1.0/24 Firewall / IPsec Cisco 5585 User Workstation User Workstation Data Center Server Data Center Server LAN IP: 192.168.4.50 LAN IP: 192.168.4.100 LAN IP: 192.168.3.50 LAN IP: 192.168.3.100 Customer Remote Office Chicago, IL USA Remote Subnet: 192.168.3.0/24 Customer Data Center London, UK Remote Subnet: 192.168.4.0/24 Isolation takes many forms: from underlying infra, allow my protocols, keep my chattiness in, keep others out, etc.. copyright 2014 13
Cloud performance and scale NFV Data Center Server User Workstation User Workstation Where NFV really shines today: create a WAN in minutes, use cloud as points of presence for your business copyright 2014 14
Programmatic networking provisioning & control Public Clouds Private Clouds + http://maxoffsky.com/code-blog/building-restful-api-in-laravel-start-here/ Virtual Infrastructure Cloud Compute and Network APIs + NFV Device APIs allow previously unimaginable flexibility and power copyright 2014 15
Preview: Waves of Adoption copyright 2014 16
Waves of NFV Adoption Tomorrow 11:25-11:50 in DCIM / Software Defined Datacentres and Networks Stream Public Cloud Region 1 Overlay Network Public Cloud Region 1 Overlay Network Encrypted Overlay network in VPC Cloud Server Overlay IP: 172.31.11.xx Cloud Server Cloud Server Cloud Server Web App 1 Web App 2 Web App 3 Standard IPsec Tunnel NFV NFV Encrypted Connections Standard IPsec Tunnel Multiple IPsec Devices Firewall / IPsec Device IP: 192.168.1.xx LAN Data Center Servers Customer Data Center Customer Site 1 Customer Site 2 Customer Site N Bursting and Containment Hubs and Spokes Winning back control copyright 2014 17
Questions? Paddington, London, UK ContactMe@cohesiveft.com +44 20 8144 0156 copyright 2014 18