Limitation of Riverbed s Quality of Service (QoS)



Similar documents
Identity-Based Traffic Logging and Reporting

Identity-Based Application and Network Profiling

JUNOScope IP Service Manager

IF-MAP FEDERATION WITH JUNIPER NETWORKS UNIFIED ACCESS CONTROL

WXOS 5.5 SSL Optimization Implementation Guide for Configuration and Basic Troubleshooting

Juniper Networks Solution Portfolio for Public Sector Network Security

Meeting PCI Data Security Standards with Juniper Networks Security Threat Response Manager (STRM)

Monitoring Network Traffic Using sflow Technology on EX Series Ethernet Switches

Using Multicast Call Admission Control for IPTV Bandwidth Management

MONITORING NETWORK TRAFFIC USING sflow TECHNOLOGY ON EX SERIES ETHERNET SWITCHES

VMWARE VIEW WITH JUNIPER NETWORKS SA SERIES SSL VPN APPLIANCES

MIGRATING IPS SECURITY POLICY TO JUNIPER NETWORKS SRX SERIES SERVICES GATEWAYS

PERFORMANCE VALIDATION OF JUNIPER NETWORKS SRX5800 SERVICES GATEWAY

Configuring and Implementing A10

CONFIGURATION OPTIONS FOR HARDWARE RULE SEARCH (RMS) AND SOFTWARE RULE SEARCH (SWRS)

Implementing Firewalls inside the Core Data Center Network

COORDINATED THREAT CONTROL

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

WAN OPTIMIZATION AND IPSEC FOR THE BRANCH OFFICE

Secure, Mobile Access to Corporate , Applications, and Intranet Resources

Web Filtering For Branch SRX Series and J Series

Juniper Networks Customer Service

Juniper Networks WX Series Large. Integration on Cisco

PRODUCT CATEGORY BROCHURE

Virtual Private LAN Service (VPLS)

Network and Security. Product Description. Product Overview. Architecture and Key Components DATASHEET

Demonstrating the high performance and feature richness of the compact MX Series

Voice Modules for the CTP Series

WEB FILTERING FOR BRANCH SRX SERIES AND J SERIES

Juniper Networks Education Services

Strategic Network Consulting

ENTERPRISE SOLUTION FOR DIGITAL AND ANALOG VOICE TRANSPORT ACROSS IP/MPLS

Solution Brief. Migrating to Next Generation WANs. Secure, Virtualized Solutions with IPSec and MPLS

PRODUCT CATEGORY BROCHURE

PRODUCT CATEGORY BROCHURE. Juniper Networks SA Series

Meeting PCI Data Security Standards with

SoLuTIoN guide. CLoud CoMPuTINg ANd ThE CLoud-rEAdy data CENTEr NETWork

Interoperability Test Results for Juniper Networks EX Series Ethernet Switches and NetApp Storage Systems

Juniper Networks Solution Portfolio for Public Sector Network Security

Deploying IP Telephony with EX-Series Switches

Implementation Consulting

SOLUTION BROCHURE. Lifecycle Wireless Infrastructure, Security and Services Management

Deploy secure, corporate access for mobile device users with the Junos Pulse Mobile Security Suite

TECHNICAL NOTE SETTING UP A STRM UPDATE SERVER. Configuring your Update Server

SECURE ACCESS TO THE VIRTUAL DATA CENTER

Setting up an icap Server for ISG- 1000/2000 AV Support

J-Flow on J Series Services Routers and Branch SRX Series Services Gateways

Security Solutions Portfolio

Juniper Networks Unified Access Control (UAC) and EX-Series Switches

After you have created your text file, see Adding a Log Source.

WX SERIES APPLICATION ACCELERATION PLATFORMS

Optimizing VoIP Applications with Juniper Networks EX3200 and EX4200 Line of Ethernet Switches

NETWORK AND SECURITY MANAGER APPLIANCES (NSMXPRESS AND NSM3000)

NETWORK AND SECURITY MANAGER

Solution Brief. Optimizing Data Replication: How Juniper Networks Accelerates Symantec Veritas Volume Replicator

Simplifying the Data Center Network to Reduce Complexity and Improve Performance

JUNIPER CARE PLUS ADVANCED SERVICES CREDITS

Best Practices for WAN Optimization

Juniper Networks Unified Access Control (UAC) and EX-Series Switches

Reasons Enterprises. Prefer Juniper Wireless

Juniper Networks WXC 250/500/590/1800/2600/3400 Application Acceleration Platforms

Juniper Networks High-Performance Networking for Branch Offices of Financial Services Institutions

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

Juniper Networks VPN Decision Guide

Configuring and Deploying the Dynamic VPN Feature Using SRX Series Services Gateways

TECHNICAL NOTE INSTALLING AND CONFIGURING ALE USING A CLI. Installing the Adaptive Log Exporter

Virtual Server in SP883

Product Description. Product Overview

Electronic Fulfillment of Feature, Capacity and Subscription License Activation Keys via the License Management System (LMS)

UNIFIED PERFORMANCE MANAGEMENT

NB6 Series Quality of Service (QoS) Setup (NB6Plus4, NB6Plus4W Rev1)

By default, STRM provides an untrusted SSL certificate. You can replace the untrusted SSL certificate with a self-signed or trusted certificate.

SECURING TODAY S MOBILE WORKFORCE

Migrating Log Manager to JSA

Application Note: Junos NAT Configuration Examples

Introduction to Carrier Ethernet VPNs: Understanding the Alternatives

Implementing Firewalls inside the Core Data Center Network

JUNIPER NETWORKS WIRELESS LAN SOLUTION

Security Solutions Portfolio

Web Security Firewall Setup. Administrator Guide

DEPLOYING IP TELEPHONY WITH EX SERIES ETHERNET SWITCHES

Network Configuration Example

WHITE PAPER. Copyright 2011, Juniper Networks, Inc. 1

Enabling Carrier-class Unified Communications with Juniper EX-series Ethernet Switches

THE IMPORTANT ROLE OF THE NETWORK IN A VIRTUALIZED WORLD

White Paper. Copyright 2012, Juniper Networks, Inc. 1

QoS (Quality of Service)

Service Description Overview

Optimization of Citrix ICA with Steelhead Appliances and RiOS 6.0 WHITE PAPER

Enabling Carrier-Class Unified Communications with Juniper Networks

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

Security That Ensures Tenants Do Not Pose a Risk to One Another In Terms of Data Loss, Misuse, or Privacy Violation

Features and Benefits

Network Configuration Example

EX SERIES ETHERNET SWITCHES: QOS-ENABLING THE ENTERPRISE

Chapter 3 Security and Firewall Protection

Lab Testing Summary Report

Mobile Workforce. Connect, Protect, and Manage Mobile Devices and Users with Junos Pulse and the Junos Pulse Mobile Security Suite.

Juniper Networks J-series Services Routers Quality of Service (QoS)

Configuration Guide. How to Configure SSL VPN Features in DSR Series. Overview

Transcription:

Application Note Limitation of Riverbed s Quality of Service (QoS) Riverbed s Quality of Service (QoS) configuration and limitations Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, California 94089 USA 408.745.2000 1.888 JUNIPER www.juniper.net Part Number: 350130-001 May 2008

Table of Contents Introduction... 3 Scope.... 3 Riverbed QoS Limitation........................................................... 3 Customer Example.... 3 Juniper WX Platform Configuration................................................... 3 Riverbed-Steelhead Configuration... 8 Summary..................................................................... 14 About Juniper Networks... 14 2 Copyright 2008, Juniper Networks, Inc.

Introduction The goal of this document is to explain the limitations of the Riverbed QoS and how only Juniper Networks WAN application acceleration platforms (WX application acceleration platforms) reply to end-customer quality of service (QoS) needs. Scope This AppNote is targeted for Juniper and partner SEs, especially in competitive deals against Riverbed. Riverbed QoS Limitation Riverbed implements QoS, as routers do. You define the local office WAN bandwidth and configure how much outgoing WAN guaranteed bandwidth you want for different applications. This design works well for routers, but is not suited for WAN optimization appliances. With such a technical approach, you can hardly provide per-remote office guaranteed bandwidth. Enterprises don t want to guarantee X percent of their headquarters outgoing bandwidth for critical applications. What enterprises need is X percent of their remote offices incoming bandwidth for critical applications. The following example will demonstrate the complexity of the Riverbed QoS implementation and how it applies to real customer needs. Customer Example This example is a classic enterprise QoS requirement. You have two centralized critical applications FTP servers and file servers (they could be Siebel, SAP, Oracle and so on) and you want to guarantee 25 percent of your remote locations bandwidth for ftp and 10 percent for CIFS: Headquarters link: 10,000 Kbps (10 Mbps) 15 Remote sites: 1500 Kbps Goal: Allocate to each remote site Juniper WX Platform Configuration -- -- 25 percent of remote office bandwidth for FTP traffic 10 percent of remote office bandwidth for CIFS traffic You can configure the QoS via the Setup Wizard or manually. The Setup Wizard does reply to a large number of requests. But this example requires a manual setup. Anyway, our manual setup is simple and easy. The configuration steps for this QoS requirement are as follows: 1. Set up the Outbound QoS Endpoints for the WX platform in the Headquarters. Select: QoS Templates. Copyright 2008, Juniper Networks, Inc. 3

Technical Note: You don t manually define the 15 locations (endpoints). They are automatically listed once the WX platform is registered to the registration server. What you define is simply: The local max WAN link (Outbound Speed) The max WAN link to remote locations with no WX platform (Other traffic Circuit Speed) Each remote max WAN link (remote endpoint Circuit Speed) 2. Define the ftp class for the application FTP and CIFS. Select: QoS Traffic Classes Edit Classes. 4 Copyright 2008, Juniper Networks, Inc.

3. Associate the application FTP to the class ftp and CIFS to the class CIFS. Select: QoS Traffic Classes. Technical Note: The WX platform proposes 53 predefined applications (such as FTP and CIFS). There is obviously the ability to create your own applications if they are not prelisted. The applications can be defined with Layer 3 information (IP addresses) and/or Layer 4 information (TCP/UDP ports) and even Layer 7 information (HTTP URL or Citrix application name). 4. Define the Class Template CompanyX-QoS with 25 percent guaranteed for the class ftp and 10 percent for the class CIFS. Select: QoS Templates New template. Technical Note: Priority definition is optional. The excess bandwidth not guaranteed (in that case bandwidth above 35 percent) will be used in high-priority for ftp Traffic Class, then CIFS and at last for the default traffic class. 5. Select the Class Template to the different endpoints. Select: QoS Overview. Copyright 2008, Juniper Networks, Inc. 5

Via the Edit button, select the template CompanyX-QoS for each remote location. In this example, the Other traffic (traffic with destination where there is no WX platform) remains without template, as we don t want to guarantee bandwidth for it. Technical Note: You can t allocate in guaranteed bandwidth more than 80 percent of the WAN bandwidth. In that example the WAN bandwidth is 10 Mbps => 8 Mbps as the max for the total guaranteed bandwidth. You can see via the WX WebUI how much you have already allocated by selecting the Show bandwidth as: Kbps. 6 Copyright 2008, Juniper Networks, Inc.

Technical Note: And in case you try to overallocate, a warning message will prevent the configuration change. Copyright 2008, Juniper Networks, Inc. 7

Riverbed-Steelhead Configuration Riverbed has no concept of remote locations. So you can t allocate a guaranteed bandwidth for a remote location. Riverbed proposes a real complex workaround with limited scalability. You have to create one QoS class with WAN guaranteed bandwidth per remote location/per application. And you have to apply the correct QoS class to each destination subnet. This means with Riverbed, you have to manually do the following: Calculate how much local WAN bandwidth percentage is each remote location s guaranteed bandwidth. Note: The Juniper WX platform detects each remote location WAN bandwidth. So you simply specify the percentage of remote location WAN bandwidth you want to guarantee. Gather each remote location s subnets. Note: Each Juniper WX platform automatically detects other Juniper WX platforms local subnets. So there is no need to manually define the remote locations subnets Create one QoS class per remote location and per application. Note: You simply create a single QoS template with the Juniper WX platform, whatever the number of remote locations and applications. Create a specific QoS rule per remote subnet and per application for each remote location. Note: You simply associate the QoS template to each remote location with the Juniper WX platform. And in that specific basic example you have to create manually: 30 QoS classes!!! There are 15 remote locations and 2 applications (ftp and CIFS): 15 x 2 = 30 QoS classes Note: The Riverbed high-end platforms support only up to 200 QoS classes. So Riverbed can t support more than 200 sites with 1 single application classified or 50 sites with 4 applications classified. For information, that was one single QoS template created on the Juniper WX platform. 90 QoS rules!!! There are 15 remote locations, 3 local subnets per location and 2 applications (FTP and CIFS): 15 x 3 x 2 = 90 QoS classes Note: The Riverbed high-end platforms support only up to 600 QoS rules. So Riverbed can t support more than 200 sites with 3 subnets and 1 single application classified or 50 sites with 3 subnets and 4 applications classified. For information, the 15 remote locations were simply associated with the QoS template on the Juniper WX platform. 8 Copyright 2008, Juniper Networks, Inc.

The configuration steps for Steelhead are as follows: Technical Note: The screenshots are based on the Riverbed RiOS 4.1. 1. Enable QoS and specify WAN bandwidth. Select: Setup Advanced Networking - QoS Classification 2. Create manually the 30 QoS classes: One for each remote location/application Manually repeat this 15 times for each 15 remote locations. Select: Setup Advanced Networking - QoS Classification Technical Note: Riverbed cannot determine the remote location bandwidth. So you have to manually calculate how much local bandwidth is 25 percent of the remote location bandwidth. In that case, 25 percent of 1.5 Mbps is 375 Kbps. And 375 Kbps is 3.75 percent of 10 Mbps. Copyright 2008, Juniper Networks, Inc. 9

Technical Note: Riverbed cannot determine the remote location bandwidth. So you have to manually calculate how much local bandwidth is 10 percent of the remote location bandwidth. In that case, 10 percent of 1.5 Mbps is 150 Kbps. And 150 Kbps is 1.5 percent of 10 Mbps. So at the end of the 30 QoS classes that were manually configured, you have the following: 10 Copyright 2008, Juniper Networks, Inc.

3. Create the port label for CIFS (TCP 139 + 445). Riverbed doesn t have predefined applications. QoS rules (see next point) are based on source and destination IP and ports. In the case of CIFS application, two TCP ports are used: 139 and 445. To avoid the creation of two QoS rules for each CIFS rule, you can create a port label for CIFS. Select: Setup Port Labels 4. Create manually the 90 QoS rules: One for each remote subnet/application Manually repeat this 15 times for all 15 remote locations. Select: Setup Advanced Networking - QoS Classification Copyright 2008, Juniper Networks, Inc. 11

Those three QoS rules are for the application FTP. Note: The three subnets in the branch office 1 are 1.1.1.0/24, 1.1.2.0/24, and 1.1.3.0/24. 12 Copyright 2008, Juniper Networks, Inc.

Those three QoS rules are for the application CIFS. Note: The three subnets in the branch office 1 are 1.1.1.0/24, 1.1.2.0/24, and 1.1.3.0/24. Copyright 2008, Juniper Networks, Inc. 13

Summary Even if both Juniper and Riverbed support QoS, this document explained how only Juniper can reply to QoS enterprise needs. For more information about the Riverbed solution and the Juniper advantages, you can look at the latest Riverbed competitive information available on the partner site: https://www.juniper.net/ partners/partner_center/content/reseller/products/wan_kit.jsp#comp. About Juniper Networks Juniper Networks, Inc. is the leader in high-performance networking. Juniper offers a high-performance network infrastructure that creates a responsive and trusted environment for accelerating the deployment of services and applications over a single network. This fuels high-performance businesses. Additional information can be found at www.juniper.net. CORPORATE HEADQUARTERS AND SALES HEADQUARTERS FOR NORTH AND SOUTH AMERICA Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA Phone: 888.JUNIPER (888.586.4737) or 408.745.2000 Fax: 408.745.2100 www.juniper.net EUROPE, MIDDLE EAST, AFRICA REGIONAL SALES HEADQUARTERS Juniper Networks (UK) Limited Building 1 Aviator Park Station Road Addlestone Surrey, KT15 2PG, U.K. Phone: 44.(0).1372.385500 Fax: 44.(0).1372.385501 EAST COAST OFFICE Juniper Networks, Inc. 10 Technology Park Drive Westford, MA 01886-3146 USA Phone: 978.589.5800 Fax: 978.589.0800 ASIA PACIFIC REGIONAL SALES HEADQUARTERS Juniper Networks (Hong Kong) Ltd. 26/F, Cityplaza One 1111 King s Road Taikoo Shing, Hong Kong Phone: 852.2332.3636 Fax: 852.2574.7803 Copyright 2008 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. JUNOS and JUNOSe are trademarks of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. To purchase Juniper Networks solutions, please contact your Juniper Networks sales representative at 1-866-298-6428 or authorized reseller. 14