Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera rbarrera@grupo-dice.com. VERSION May, 2015



Similar documents
Simplify IT. With Cisco Application Centric Infrastructure. Barry Huang Nov 13, 2014

Unleash the power of Cisco ACI and F5 Synthesis for Accelerated Application deployments. Ravi Balakrishnan Senior Marketing Manager, Cisco Systems

Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure

Don't outsource IT! Bring your own Cloud with SDN

Enabling Application Aware Networks The Next Generation Data Centre with Citrix NetScaler & Cisco Nexus. Ralph W. Lorkins Lead Systems Engineer

HAWAII TECH TALK SDN. Paul Deakin Field Systems Engineer

Cisco Application Centric Infrastructure. Silvo Lipovšek Sistemski inženjer

Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre

SOFTWARE DEFINED NETWORKING

Virtualization, SDN and NFV

Building Scalable, Open, Programmable and Application Centric Data Center with Cisco ACI. 林 瑝 錦 / Jerry Lin Cisco Systems 2015 July

2013 ONS Tutorial 2: SDN Market Opportunities

Designing Virtual Network Security Architectures Dave Shackleford

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

Hybrid Cloud: Overview of Intercloud Fabric. Sutapa Bansal Sr. Product Manager Cloud and Virtualization Group

May 13-14, Copyright 2015 Open Networking User Group. All Rights Reserved Not For

Network Virtualization for the Enterprise Data Center. Guido Appenzeller Open Networking Summit October 2011

White Paper. SDN 101: An Introduction to Software Defined Networking. citrix.com

Using SouthBound APIs to build an SDN Solution. Dan Mihai Dumitriu Midokura Feb 5 th, 2014

Software defined networking. Your path to an agile hybrid cloud network

The Path to the Cloud

Cisco and Citrix Solution

SDN Applications in Today s Data Center

Cisco Prime Network Services Controller. Sonali Kalje Sr. Product Manager Cloud and Virtualization, Cisco Systems

Cisco Unified Network Services: Overcome Obstacles to Cloud-Ready Deployments

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

Datacenter Networking. Joy ABOIM Consulting System Engineer

SDN/Virtualization and Cloud Computing

Enterprise Data Center Networks

IT Infrastructure Services. White Paper. Utilizing Software Defined Network to Ensure Agility in IT Service Delivery

How To Build A Software Defined Data Center

Cisco and Red Hat: Application Centric Infrastructure Integration with OpenStack

Cisco Cloud Architecture for the Microsoft Cloud Platform

Software Defined Environments

White Paper. Juniper Networks. Enabling Businesses to Deploy Virtualized Data Center Environments. Copyright 2013, Juniper Networks, Inc.

Business Case for Open Data Center Architecture in Enterprise Private Cloud

Software Defined Network (SDN)

Thank you for joining us today! The presentation will begin shortly. Thank you for your patience.

What is SDN all about?

Application Centric Infrastructure

Software Defined Networks Virtualized networks & SDN

Cisco and Citrix: Building Application Centric, ADC-enabled Data Centers

Virtual Machine Manager Domains

Spotlight On Backbone Technologies

A Look at the New Converged Data Center

Strategic Direction of Networking IPv6, SDN and NFV Where Do You Start?

Cisco ACI and F5 LTM Integration for accelerated application deployments. Dennis de Leest Sr. Systems Engineer F5

Is Cisco Application Centric Infrastructure an SDN Technology?

DCB for Network Virtualization Overlays. Rakesh Sharma, IBM Austin IEEE 802 Plenary, Nov 2013, Dallas, TX

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Assessing the Business Value of SDN Datacenter Security Solutions

Federated Application Centric Infrastructure (ACI) Fabrics for Dual Data Center Deployments

Data Center Network Virtualisation Standards. Matthew Bocci, Director of Technology & Standards, IP Division IETF NVO3 Co-chair

Operationalizing the Network: SDN

Open Fabric SDN The Comprehensive SDN approach. Jake Howering, Director SDN Product Line Management Bithika Khargharia, PhD, Senior Engineer

How To Orchestrate The Clouddusing Network With Andn

An Application-Centric Infrastructure Will Enable Business Agility

Cisco and Citrix: Building Application Centric, ADC-enabled Data Centers

Securing the Virtualized Data Center With Next-Generation Firewalls

Leveraging SDN and NFV in the WAN

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates

Remote Voting Conference

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

How To Make A Vpc More Secure With A Cloud Network Overlay (Network) On A Vlan) On An Openstack Vlan On A Server On A Network On A 2D (Vlan) (Vpn) On Your Vlan

Data Center Network Evolution: Increase the Value of IT in Your Organization

Cisco and Canonical: Cisco Network Virtualization Solution for Ubuntu OpenStack

BROCADE NETWORKING: EXPLORING SOFTWARE-DEFINED NETWORK. Gustavo Barros Systems Engineer Brocade Brasil

The Mandate for a Highly Automated IT Function

SINGLE-TOUCH ORCHESTRATION FOR PROVISIONING, END-TO-END VISIBILITY AND MORE CONTROL IN THE DATA CENTER

Why Cisco for Cloud? IT Service Delivery, Orchestration and Automation

Software-Defined Networks Powered by VellOS

Introduction to Software Defined Networking

Shifting Roles for Security in the Virtualized Data Center: Who Owns What?

How To Switch A Layer 1 Matrix Switch On A Network On A Cloud (Network) On A Microsoft Network (Network On A Server) On An Openflow (Network-1) On The Network (Netscout) On Your Network (

A Presentation at DGI 2014 Government Cloud Computing and Data Center Conference & Expo, Washington, DC. September 18, 2014.

SDN and NFV in the WAN

Understanding Virtualization and Cloud in the Enterprise

Installation Guide Avi Networks Cloud Application Delivery Platform Integration with Cisco Application Policy Infrastructure

New Virtual Application Networks Innovations Advance Software-defined Network Leadership

Business Values of Network and Security Virtualization

SDN CONTROLLER. Emil Gągała. PLNOG, , Kraków

AVI NETWORKS CLOUD APPLICATION DELIVERY PLATFORM INTEGRATION WITH CISCO APPLICATION CENTRIC INFRASTRUCTURE

White Paper. SDN 102: Software Defined Networks and the Role of Application Delivery Network Services. citrix.com

VIRTUALIZING THE EDGE

How Open is Cisco s ACI?

SIMPLE NETWORKING QUESTIONS?

THE REVOLUTION TOWARDS SOFTWARE- DEFINED NETWORKING

Cisco Intercloud Fabric Security Features: Technical Overview

CON Software-Defined Networking in a Hybrid, Open Data Center

VMware NSX A Perspective for Service Providers part 2

Software Defined Networking - a new approach to network design and operation. Paul Horrocks Pre-Sales Strategist 8 th November 2012

Testing Challenges for Modern Networks Built Using SDN and OpenFlow

Transcription:

Simplify IT With Cisco Application Centric Infrastructure Roberto Barrera rbarrera@grupo-dice.com VERSION May, 2015

Content Understanding Software Definded Network (SDN) Why SDN? What is SDN and Its Benefits? Understanding OpenFlow What is OpenFlow SDN vs OpenFlow SDN Ecosystem SDN Vendors VERSION May, 2015

VERSION May, 2015 Why SDN?

Decoupling the system that makes decision about where traffic is sent (the control plane) from the underlying systems that forwards traffic to the selected destination (the data plane) What is SDN? Benefits Centralization of Control of the Network via eparation of Control Logic to Off Device Compute that enables automation and orchestration of network services via Open Programatting Interfaces. Efficiency: Optimaze existing application, services and Infrastructure. Scale: rapidly grow existing applications and services. Innovation: Create and deliver new types of applications and services and business models. VERSION May, 2015

What is OpenFlow OpenFlow is a standars based protocol allowing for a centralized control plane in a separate divice (the controller) Provides hardware abstraction Is managed by the Open Networking Foundation (ONF) Is asynchronous. VERSION May, 2015

SDN vs OpenFlow Application Layer Business Application API API API Control Layer Network Services Network Services Network Services Infraestructure Layer VERSION May, 2015

SDN vs OpenFlow SDN is not a Technology, it is a architecture There is nothing that can be implemented using SDN and not with traditional networks While SDN is a architecture, OpenFlow is a Protocol that enables deployment and implementation of it VERSION May, 2015

VERSION May, 2015 Some SDN Vendors

AGENDA Challenges and Opportunities Application Centric Infrastructure and Business Benefits What problem are we trying to solve and how do we solve it Open, Open and Open Summary and Q&A 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9

ACI Addresses Business Objectives Best Customer Service Product and Service Innovation IT as a Competitive Advantage Increased Business Insight Accelerated Application Delivery Flexible Infrastructure Greater Visibility and Analytics Simplified Processes Compliance and Governance Auditing and Forensics Integration Security Intelligence Alignment with Business Objectives CEO CIO CISO ACI Benefits Competitive Advantage 2014 Cisco and/or its affiliates. All rights reserved. Business Agility Lower TCO Reduced Risk Cisco Confidential 10

IT Challenges and Opportunities Better alignment of IT with rapidly changing business needs requires dynamic and automated policy-based control of DC and Cloud infrastructure. Technology Transitions CIOs need a model that balances agility & risk. Public Cloud Offerings Brings new and different security and operational challenges/opportunities. IT Processes Policy semantics impede alignment of IT with business. 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11

Introducing: Application Centric Infrastructure Apps + Infrastructure Open + Secure Physical + Virtual On-Premises + Cloud Application Oriented Policy = Operational Simplicity 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12

Application Centric Infrastructure Customer Business Benefits Deploy applications faster Workload mobility Higher application availability Compliant and secure CapEx reduction Single open API for entire system Network Service Appliances H Y P E R V I S O R X86 Multi-Hypervisor H Y P E R V I S O R H Y P E R V I S O R Customer Operational Benefits Application Centric Infrastructure East-West optimized for all workloads Risk mitigation Better utilization of resources Operational efficient / zero touch deployment and de-commissioning Self documenting network Simplified day-2 troubleshooting OpEx reduction X86-Virtual Machines & Virtual Appliances X86 Servers Unix Systems P and Z systems IP Storage 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13

ACI: Business Outcome and Benefits for Cisco IT Cisco ACI is an open, future-proofed data center architecture that can continue to grow as we enhance client services. Chuck Crane Network and Security Architect, Axciom (Transitioning from AWS to Private Cloud) Cisco s open standards approach makes ACI even stronger. We conducted testing on ACI it fully delivered everything we expected, and proved to be quite stable and mature. Nik Weidenbacher Principal Engineer, SunGard This will enable Telstra to deliver service agility, security and performance that our customers expect from an enterprise grade cloud. Erez Yarkoni Executive Director, Telstra Greater Business Agility Lower Capital Expenses Reduced Costs/ Complexity Lower Operating Cost Resource Optimization 58 % Reduce Network Provisioning 25 % CAPEX Reduction 21 % Reduce Management Costs 45 % Reduce Power and Cooling Costs 10-20 % Compute and Storage Optimization 2013-2014 Cisco and/or its affiliates. All rights reserved. Source: Cisco IT Cisco Confidential 14

ACI Addresses the Security Challenge in the DC Security Expressed in Application Language Simplified Policybased Segmentation Network Services Automation, Open Eco- System Visibility, Analytics, Forensics Automate Compliance, Centralized Audit Centralized Security Across Physical and Virtual 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15

Investment Protection Extending ACI into the existing infrastructure Extend ACI Model on existing IP networks, L4-7 Services, Hypervisors Existing Nexus networks PROFILE ACI Fabric AVS Extended ACI POLICY Bare Metal AVS Hypervisors VM s Bare Metal Hypervisor VMs 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16

ACI is evolving the network infrastructure to be an enabler for faster application deployment. 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17

Two Types of Languages Infrastructure Language App Language VLAN IP Address Subnets Firewalls Quality of Service Load Balancer Access Lists Human Translator Application Tier Policy and Dependencies Security Requirements Service Level Agreement Application Performance Compliance Geo Dependencies 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18

Data Center Automation Manual versus Policy Driven Architect it Design it Procure it Install it Configure it Secure it QA it Is it ready? Architect it Design it ACI Policy Driven Is procured Is installed Is configured Is secured Is QA d It is ready Service Request ARCHITECT DESIGN COMPUTE 2014 Cisco and/or its affiliates. All rights reserved. Application SERVICES SECURITY NETWORK Available Application Available Cisco Confidential 19

Data Center Automation and IT Collaboration Today: Serialized Configuration and Management MANUAL PROCESS LEADS TO INCREASED DEPLOYMENT TIMES Application Requirements COMPUTE SERVICES NETWORK SECURITY Successful Deployment Deployment Trigger Configuration Mismatch Policy Violation Service Request ARCHITECT DESIGN COMPUTE 2014 Cisco and/or its affiliates. All rights reserved. SERVICES SECURITY NETWORK Application Available Cisco Confidential 20

Data Center Automation and IT Collaboration ACI: Common Policy Framework and Operational Model POLICY-BASED AUTOMATION Deployment Trigger STORAGE SECURITY Application Requirements COMPUTE Application Policy NETWORK Defined set of application requirements APPLICATION CLOUD Team builds application policy and template Operations team deploys with minimal risk and maximum speed Service Request ARCHITECT 2014 Cisco and/or its affiliates. All rights reserved. DESIGN Application Available Cisco Confidential 21

A new common language to describe desired state is needed. 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22

An Innovative Approach to Policy Provided Contract Provided Contract Provided Contract OUTSIDE F/W ADC WEB ADC APP DB What is an application policy? 1. 2. 3. Group: A set of virtual or physical workloads with the same policy Contracts: A set of rules governing communication between groups Service Chains: A set of network services between groups 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23

Policy is Business Relevant Application Centric Infrastructure (ACI) allows the entire infrastructure to take commands in a business-relevant language. ACI Policy Aligned with Applications Traditional Policy Aligned with.? Let my app servers talk to my web servers. 1. Figure out where app lives in physical net 2. Trunk VLAN 112 to switch 22. 3. Add route. 4. Plumb ports 7-12 5. Configure ACL 6. Apply QoS 2013-2014 Cisco and/or its affiliates. All rights reserved. 7. Repeat every time app moves or needs more capacity Cisco Confidential 24

The Benefits of an Application Centric Policy Application Workload Mobility Health Score TENANT APPLICATION Health Score Systems Telemetry 0 Packets dropped 25 Packets dropped Systems Telemetry Latency 0 0 0 7 0 0 0 6 Latency Isolation Isolation CONSISTENT VISIBILITY ACROSS CLOUD AND DC 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25

Simplify IT Combining Public and Private Cloud Enterprise Cloud APIC Provider Cloud F/W WE AP ADC L/B WEB ADC L/B APP DB B P InterCloud Secure Connection WE F/W ADC L/B WEB ADC L/B F/W B WE ADC L/B WEB ADC L/B F/W B WE ADC L/B WEB ADC L/B B AP APP P AP APP P AP APP P Consistent ACI Policy Across Public and Private Clouds 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26

Open Open Source, Open Standards, Open Interfaces 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27

Opening the ACI Policy with OpFlex OPFLEX PROTOCOL + ECOSYSTEM APIC OPEN SOURCE Open source implementation available to anyone OPFLEX STANDARD Upcoming OpFlex standard through IETF L4-7 DEVICE HYPERVISOR SWITCH ECOSYSTEM Broad, growing vendor support including hypervisor, network, and L4-7 2013-2014 Cisco and/or its affiliates. All rights reserved. DELIVERING INVESTMENT PROTECTION BY ALLOWING ANY DEVICE TO INTEGRATE WITH CISCO ACI Cisco Confidential 28

Open: APIC Programming Interfaces Automation Hypervisor Management OVM Enterprise Monitoring Systems Manageme nt Orchestration Frameworks Open REST APIs Support Integration With Any Software Applications NORTHBOUND PROGRAMMABILITY LAYER APIC OpFlex: Open Fabric Attached Device API Supports Integration with Any Network Device SOUTHBOUND PROGRAMMABILITY LAYER 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29

The ACI Fabric HYPERVISOR HYPERVISOR HYPERVISOR 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30

Open and Secure from the Ground Up OPEN SOURCE WITH ADVANCED SECURITY Policy OPEN STANDARDS NSH VXLAN OpFlex + RBAC Encryption Auditing Tenant Isolation OPEN INTERFACES JSON XML REST OpFlex 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31

Summary: Our Direction Data centers and cloud network infrastructures, both physical and virtual, will no longer be configured, will not be software defined (or programmed), but instead will be Policy Driven and Application Centric. 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32

Thank you.

Open and Secure from the Ground Up OPEN SOURCE WITH ADVANCED SECURITY Policy OPEN STANDARDS NSH VXLAN OpFlex + RBAC Encryption Auditing Tenant Isolation OPEN INTERFACES JSON XML REST OpFlex 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34