SDN, OpenFlow and the ONF

Similar documents
COMPSCI 314: SDN: Software Defined Networking

Software Defined Networking

SDN Overview for UCAR IT meeting 19-March Presenter Steven Wallace Support by the GENI Program Office!

Ethernet-based Software Defined Network (SDN) Cloud Computing Research Center for Mobile Applications (CCMA), ITRI 雲 端 運 算 行 動 應 用 研 究 中 心

OpenFlow and Onix. OpenFlow: Enabling Innovation in Campus Networks. The Problem. We also want. How to run experiments in campus networks?

Junos OS Support for OpenFlow v1.0 Beta Draft

Software Defined Networking (SDN) OpenFlow and OpenStack. Vivek Dasgupta Principal Software Maintenance Engineer Red Hat

The State of OpenFlow: Advice for Those Considering SDN. Steve Wallace Executive Director, InCNTRE SDN Lab Indiana University

Network Virtualization Based on Flows

Securing Local Area Network with OpenFlow

SDN 交 換 機 核 心 技 術 - 流 量 分 類 以 及 應 用 辨 識 技 術. 黃 能 富 教 授 國 立 清 華 大 學 特 聘 教 授, 資 工 系 教 授 nfhuang@cs.nthu.edu.tw

Cloud Networking Disruption with Software Defined Network Virtualization. Ali Khayam

OpenFlow: History and Overview. Demo of routers

Software Defined Networking What is it, how does it work, and what is it good for?

Getting to know OpenFlow. Nick Rutherford Mariano Vallés

OpenFlow Overview. Daniel Turull

Multicasting on SDN. Prof. Sunyoung Han Konkuk University 23 July 2015

Software-Defined Networking for the Data Center. Dr. Peer Hasselmeyer NEC Laboratories Europe

Outline. Institute of Computer and Communication Network Engineering. Institute of Computer and Communication Network Engineering

SDN AND SECURITY: Why Take Over the Hosts When You Can Take Over the Network

LTE - Can SDN paradigm be applied?

Towards Software Defined Cellular Networks

Open Source Network: Software-Defined Networking (SDN) and OpenFlow


OpenFlow: Enabling Innovation in Campus Networks

Tutorial: OpenFlow in GENI

Software Defined Networking and OpenFlow: a Concise Review

Software Defined Networking

Software Defined Networking and the design of OpenFlow switches

Software Defined Networking A quantum leap for Devops?

OpenFlow and Software Defined Networking presented by Greg Ferro. OpenFlow Functions and Flow Tables

Software Defined Networking

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

SDN/OpenFlow. Dean Pemberton Andy Linton

Introduction to Software Defined Networking. Xenofontas Dimitropoulos 21/5/2015

OpenFlow: Concept and Practice. Dukhyun Chang

Does SDN accelerate network innovations? Example of Flexible Service Creation

OpenFlow - the key standard of Software-Defined Networks. Dmitry Orekhov, Epam Systems

Network Security through Software Defined Networking: a Survey

Network Virtualization and Software-defined Networking. Chris Wright and Thomas Graf Red Hat June 14, 2013

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

How To Make A Vpc More Secure With A Cloud Network Overlay (Network) On A Vlan) On An Openstack Vlan On A Server On A Network On A 2D (Vlan) (Vpn) On Your Vlan

OpenFlow. Ihsan Ayyub Qazi. Slides use info from Nick Mckeown

DEMYSTIFYING ROUTING SERVICES IN SOFTWAREDEFINED NETWORKING

Software Defined Networking

Conference. Smart Future Networks THE NEXT EVOLUTION OF THE INTERNET FROM INTERNET OF THINGS TO INTERNET OF EVERYTHING

Software Defined Networking What is it, how does it work, and what is it good for?

SDN Software Defined Networks

How To Understand The Power Of A Network In A Microsoft Computer System (For A Micronetworking)

SDN and OpenFlow. Naresh Thukkani (ONF T&I Contributor) Technical Leader, Criterion Networks

Dell OpenFlow Deployment and User Guide Dell Software-Defined Networking (SDN)

OpenFlow Switch Specification

Programmable Networking with Open vswitch

NETWORK VIRTUALIZATION BASED ON SOFTWARE DEFINED NETWORK

NetFlow/IPFIX Various Thoughts

Underneath OpenStack Quantum: Software Defined Networking with Open vswitch

Spotlight On Backbone Technologies

基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器

Software Defined Networking

Security Challenges & Opportunities in Software Defined Networks (SDN)

IxNetwork OpenFlow Solution

SDN Applications in Today s Data Center

How To Understand The Power Of The Internet

BROADCOM SDN SOLUTIONS OF-DPA (OPENFLOW DATA PLANE ABSTRACTION) SOFTWARE

Multiple Service Load-Balancing with OpenFlow

How To Orchestrate The Clouddusing Network With Andn

Cloud Computing Security: What Changes with Software-Defined Networking?

OpenFlow Switch Specification

The Lagopus SDN Software Switch. 3.1 SDN and OpenFlow. 3. Cloud Computing Technology

OF 1.3 Testing and Challenges

Why Software Defined Networking (SDN)? Boyan Sotirov

Network layer: Overview. Network layer functions IP Routing and forwarding

OpenFlow Switch Specification Version ( Protocol version 0x04 )

BROCADE NETWORKING: EXPLORING SOFTWARE-DEFINED NETWORK. Gustavo Barros Systems Engineer Brocade Brasil

SSVVP SIP School VVoIP Professional Certification

TRILL for Data Center Networks

Internet Protocol: IP packet headers. vendredi 18 octobre 13

SDN software switch Lagopus and NFV enabled software node

Secure Networks for Process Control

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

Software Defined Networking (SDN) T Computer Networks II Hannu Flinck

VXLAN: Scaling Data Center Capacity. White Paper

OpenFlow/So+ware- defined Networks. Srini Seetharaman Clean Slate Lab Stanford University July 2010

ISTANBUL. 1.1 MPLS overview. Alcatel Certified Business Network Specialist Part 2

WHITE PAPER. SDN Controller Testing: Part 1

A Case for Overlays in DCN Virtualization Katherine Barabash, Rami Cohen, David Hadas, Vinit Jain, Renato Recio and Benny Rochwerger IBM

Ten Things to Look for in an SDN Controller

RESILIENT NETWORK DESIGN

INDIAN INSTITUTE OF TECHNOLOGY BOMBAY MATERIALS MANAGEMENT DIVISION : (+91 22) (DR)

Networking 4 Voice and Video over IP (VVoIP)

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

How To Connect To A Network On A Pc Or Mac (For Mac) On A Microsoft Mac 2.5 (For Ipo) On An Ipo 2.2 (For Pc) On Zephone (For Pnet) On

Software Defined Networking (SDN) - Open Flow

HP OpenFlow Protocol Overview

SDN Architecture and Service Trend

Introduction to OpenFlow:

Bringing OpenFlow s Power to Real Networks

Network Virtualization: Delivering on the Promises of SDN. Bruce Davie, Principal Engineer

Transcription:

SDN, OpenFlow and the ONF OpenFlow/Software-Defined Networking (SDN) OpenFlow/SDN is emerging as one of the most promising and disruptive networking technologies of recent years. It has the potential to enable network innovation and create choice, and thus help realize new capabilities and address persistent problems with networking. It also promises to give network operators more control of their infrastructure, allowing customization and optimization, therefore reducing overall capital and operational costs. Source: http://opennetsummit.org/why.html

OpenFlow Started 2008 at Standford Enabling innovation on campus Standard way to control flow-tables in commercial switches and routers Being deployed at Stanford Consider deploying it at your campus too OpenFlow (Or: Why can t I innovate in my wiring closet? ) The Stanford Clean Slate Program http://cleanslate.stanford.edu

ONF and Community grows fast!

What is the Difference? Separation of control- and data plane!

How to configure your network? Static Ask you Network Admin Automatic Write some scripts Automatic via Netconf, SNMP Protocols Dynamic via Network Protocols Dynamic via RADIUS, DIAMETER Protocols Whats next?

#1 Ask your Network Admin

#1 Ask your Network Admin

#1 CLI Automation Expect is quickly becoming a part of every UNIX user's toolbox. It allows you to automate Telnet, FTP, passwd, rlogin, and hundreds of other applications that normally require human interaction. Using Expect to automate these applications will allow you to speed up tasks and, in many cases, solve new problems that you never would have even considered before.

#3 Netconf / SNMP Formal protocols to configure and monitor network devices. Often read only! Back to CLI for configuration!

#3 Dynamic Configuration Complex Standards and Protocols to adapt Network Behavior for requested Services. Carrier Centric approach Based on AAA Protocols (RADIUS, DIAMETER=)

Conclusion! You always Configure existing Functionality! There is no common API to Program the network functionality!

Program your Network! With SDN/OpenFLow you get an API to program the network behavior with your language of choice! Rule Action Stats Packet + byte counters 1. Forward packet to port(s) 2. Encapsulate and forward to controller 3. Drop packet 4. Send to normal processing pipeline Switch Port MAC src MAC dst Eth type VLAN ID IP Src IP Dst IP Prot TCP sport TCP dport

#1 Cellubi m2m Network Production Network for m2m Communication Overlay Network over four 3G provider across the globe Fine granular policy control and 1:1 NAT funtionality

#2 Distributed BRAS Proof of Concept implementation Distributed PPPoE Termination close to the Edge of a Carrier FTTH Network Eliminates huge, central, costly BRAS installations Multicast Replication point is pushed to the edge for IPTV optimisation

FlowER Openflow Controller in Erlang

Classic Switch vs. Software Defined Networking (SDN)

Classic Network Switch Static control path (static configuration) VLANs, AAA, Filter, L3 Forwarding specified in configuration Limited matching in forwarding decision, mostly only things like MAC, VLAN and/or QoS tags Once a forwarding decision has been made, it can t be revised until it expires

Packet in Port Y: SRC MAC: 00:11:11:11:11:11 DST MAC: 00:55:55:55:55:55 DST MAC on Port X? Learn SRC MAC on Port Y Flood on all Ports Forward on Port X? Interessting Questions: How can a MAC be moved to different port (e.g a VM migrating to a new host) Can a switched be sliced into different network partitions? E.g. Spanning Tree with multiple VLANs How can ports isolated from each other while still forming a single L2 domain? e.g. Ethernet-to-the-Home and Fibre-to-the-Home (FTTH) deployments

Software Defined Network (SDN) Control Plane decoupled from Forwarding Plane Network Control Plane accessible through API One Control instance can control multiple forwarding instances Can match on everything in the packet and in any combination (e.g. MAC+VLAN+IP+Port) Can alter packet during forwarding

Controller Controller can talk to multiple control plane instances Flexible matching MAC/Port learning over multiple instance Proactive moving MACs of to different ports Once forwarding decision has been made, forwarding occurs in dedicate hardware at line speed Control Path API Data Path (specialized hardware)

What is OpenFlow (OF)? Protocol specification and reference implementation of Software Defined Network (SDN) OF Datapath imlementation for Linux Kernel (replaces bridging) and FPGA board Used as basis in several commercial openflow enabled switches

OF enabled datapath element Typical OF message flow packet_in <Port, Payload> flow_add <Match, Action> flow_mod <Match, Action> OF controller flow_removed <Match, Statistics>

OpenVSwitch Linux Kernel Datapath, Controller and Configuration Database Can control OF enable hardware switch Used as software switch in Xen Supports for many standard management interfaces and protocols (e.g. NetFlow, sflow, SPAN, RSPAN, CLI, LACP, 802.1ag) Extensions over OpenFlow 1.0 Protocol

FlowER Modular platform for build OpenFlow switches in Erlang Concentrate on the Switch and Flow logic, Flower does the rest. Provides: OpenFlow protocol, connection and data abstraction Tools and algorithms typicaly needed for a controller implementation

Why Erlang? You probably already know?!? Flexible binary matching Fault isolation Concurrency.

FlowEr NIB Library MAC Learning DB Flow Decoder Packet De/Encoder Controller Dispatcher Connection Abstraction (Datapath Objects) Control Path OpenFlow API Data Path (specialized hardware)

Flower Process Achitecture controller A controller B controller C flower_dispatcher flower_datapath flower_connection flower_datapath flower_connection

Theory of Operation flower_datapath module reads events from network element flower_dispatcher forwards events to interested parties (controller) controllers are chainable through events controllers implement full switch or parts of it, generates new event processed by other controllers or sends answer to datapath

flower_datapath flower_datapath Abstracts the real OF enabled network element Manages connection setup and keep-alive Controllers register for events from datapath elements such as join, leave, packet-in Controllers messages to datapath elements such as packet-out or flow-mod

OpenFlow Packet Decoder {[#ovs_msg{version = 1,type = features_reply,xid = 3, msg = #ofp_switch_features{datapath_id = 150876804345, n_buffers = 256,n_tables = 2, capabilities = [arp_match_ip,port_stats,table_stats, flow_stats], actions = [enqueue,set_tp_dst,set_tp_src,set_nw_tos, set_nw_dst,set_nw_src,set_dl_dst,set_dl_src,strip_vlan, set_vlan_pcp,set_vlan_vid,output], ports = [#ofp_phy_port{port_no = 2, hw_addr = <<0,80,86,174,0,20>>, <<>>} name = <<"eth2">>,config = [], state = [link_down], curr = [autoneg,copper], advertised = [autoneg,copper,'1gb_fd','100mb_fd','100mb_hd', '10mb_fd','10mb_hd'], supported = [autoneg,copper,'1gb_fd','100mb_fd','100mb_hd', '10mb_fd','10mb_hd'], peer = []},... ]}}],

Network Information Base (NIB) NIB Library Library for implementing: Network and network range based lookups Routing Tables Nib = flower_nib4:new(), Nib1 = flower_nib4:add({<<10,0,0,0>>, 8}, priv1, Nib), {value, priv1} = flower_nib4:lookup(<<10,10,10,10>>, Nib).

MAC Learning DB MAC Learning DB MAC address learning and lookup table Addres expiry Filter for special MAC addresses MAC to string formater

Flow Decoder Flow Decoder Raw packet decoded into all matchable fields: Src and Dst MAC Address VLAN Id L2 Protocol Type: IP, IPv6, ARP, LACP,... IP Protocol Type: UDP, TCP,... Src and Dst IP Address Src and Dst Port...

De/encoder for network protocols Packet De/Encoder Decodes and build packet fragments for: IP, TCP and UDP header ICMP ARP more to come... make_icmp({dest_unreach, pkt_filtered}, VLAN, DstMAC, SrcMAC, IPSrc, IPDst, Payload).

OpenFlow Matches OpenFlow matches specified as Erlang Term #ofp_match{wildcards = 4178159, in_port = none, dl_src = <<0,0,0,0,0,0>>, dl_dst = <<0,0,0,0,0,0>>, dl_vlan = 0,dl_vlan_pcp = 0, dl_type = ip,nw_tos = 0, nw_proto = 0, nw_src = <<127,0,0,1>>, nw_dst = <<0,0,0,0>>, tp_src = 0,tp_dst = 0}

Given a decoded flow construct a match on IP Protocol and Src IP: IP = <<127,0,0,1>>, Flow = #flow{dl_type = ip, nw_src = IP, nw_dst = IP}, encode_ofp_matchflow([{nw_src_mask,32}, dl_type], Flow).

Controller Implementations flower_simple_switch: Sample learning Layer 2 switch Implements MAC learning only Less than 50 LOC! flsc (not included): production ready Layer 3 switch and router in about 1100 LOC

Further Work IPv6 support Replace the MAC learning database with something much faster Improve and extend NIB Library Add load distribution in dispatcher Extend Documentation ;-)

Available on Github Repo: https://github.com/travelping/flower