Scalable Network Monitoring with SDN-Based Ethernet Fabrics



Similar documents
Scalable Network Monitoring with SDN-Based Ethernet Fabrics

Big Tap Monitoring Fabric Simpler, Scalable, Economical Release Version 4.1.1

Pervasive Security Enabled by Next Generation Monitoring Fabric

SDN Applications in Today s Data Center

Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre

Open SDN for Network Visibility

Big Tap Monitoring Fabric 4.5

基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器

SDN and Open Ethernet Switches Empower Modern Data Center Networks

Network Packet Monitoring Optimizations in Data Centre

Software Defined Networks Virtualized networks & SDN

Building an Open, Adaptive & Responsive Data Center using OpenDaylight

Software Defined Networks

SOFTWARE DEFINED NETWORKING

SDN PARTNER INTEGRATION: SANDVINE

SDN. What's Software Defined Networking? Angelo Capossele

Enabling Visibility for Wireshark across Physical, Virtual and SDN. Patrick Leong, CTO Gigamon

VSS - Game Changing Technology

Virtualization, SDN and NFV

Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera VERSION May, 2015

Qualifying SDN/OpenFlow Enabled Networks

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

Using SouthBound APIs to build an SDN Solution. Dan Mihai Dumitriu Midokura Feb 5 th, 2014

The promise of SDN. EU Future Internet Assembly March 18, Yanick Pouffary Chief Technologist HP Network Services

Network Virtualization for the Enterprise Data Center. Guido Appenzeller Open Networking Summit October 2011

Panel: Cloud/SDN/NFV 黃 仁 竑 教 授 國 立 中 正 大 學 資 工 系 2015/12/26

THE REVOLUTION TOWARDS SOFTWARE- DEFINED NETWORKING

How do software-defined networks enhance the value of converged infrastructures?

Testing Software Defined Network (SDN) For Data Center and Cloud VERYX TECHNOLOGIES

Global Headquarters: 5 Speen Street Framingham, MA USA P F

What is SDN all about?

SDN Software Defined Networks

The Business Case for Software-Defined Networking

Pluribus Netvisor Solution Brief

A Coordinated. Enterprise Networks Software Defined. and Application Fluent Programmable Networks

Cisco and Red Hat: Application Centric Infrastructure Integration with OpenStack

Whitepaper Unified Visibility Fabric A New Approach to Visibility

Core and Pod Data Center Design

Visibility in the Modern Data Center // Solution Overview

Network Services in the SDN Data Center

The Open Cloud Near-Term Infrastructure Trends in Cloud Computing

Blue Planet. Introduction. Blue Planet Components. Benefits

Outline. Why Neutron? What is Neutron? API Abstractions Plugin Architecture

F5 Application Delivery in a Virtual Network

Enhancing Cisco Networks with Gigamon // White Paper

Use Cases for the NPS the Revolutionary C-Programmable 7-Layer Network Processor. Sandeep Shah Director, Systems Architecture EZchip

Network Function Virtualization & Software Defined Networking

Software-Defined Networks Powered by VellOS

White Paper. SDN 101: An Introduction to Software Defined Networking. citrix.com

Definition of a White Box. Benefits of White Boxes

SDN/Virtualization and Cloud Computing

SDN software switch Lagopus and NFV enabled software node

Business Cases for Brocade Software-Defined Networking Use Cases

Delivering Managed Services Using Next Generation Branch Architectures

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

Affording the Upgrade to Higher Speed & Density

Open Fabric SDN The Comprehensive SDN approach. Jake Howering, Director SDN Product Line Management Bithika Khargharia, PhD, Senior Engineer

The Impact of PaaS on Business Transformation

2013 ONS Tutorial 2: SDN Market Opportunities

Strategic Direction of Networking IPv6, SDN and NFV Where Do You Start?

Fabrics that Fit Matching the Network to Today s Data Center Traffic Conditions

White Paper. Juniper Networks. Enabling Businesses to Deploy Virtualized Data Center Environments. Copyright 2013, Juniper Networks, Inc.

SDN Architecture and Service Trend

Getting started with O3 Project Achievement ~ Innovating Network Business through SDN WAN Technologies~

Software Defined Networking and Network Virtualization

Big Cloud Fabric 2.5

A Presentation at DGI 2014 Government Cloud Computing and Data Center Conference & Expo, Washington, DC. September 18, 2014.

The Benefits of SD-WAN with Integrated Branch Security

Ensuring end-user quality in NFV-based infrastructures

Software Defined Networking and Network Virtualization

Datacenter Networking. Joy ABOIM Consulting System Engineer

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Building Scalable Multi-Tenant Cloud Networks with OpenFlow and OpenStack

HOW SDN AND (NFV) WILL RADICALLY CHANGE DATA CENTRE ARCHITECTURES AND ENABLE NEXT GENERATION CLOUD SERVICES

APPLICATION DELIVERY IN OPENSTACK WITH AVI NETWORKS

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Use Case Brief NETWORK SECURITY

THE VIRTUAL PROBE: ASSURANCE & MONITORING IN THE NFV/SDN ERA

Deliver the Next Generation Intelligent Datacenter Fabric with the Cisco Nexus 1000V, Citrix NetScaler Application Delivery Controller and Cisco vpath

Extreme Networks Software Defined Networking (SDN) Platform: Open, Standards-based and Comprehensive

MaxDeploy Ready. Hyper- Converged Virtualization Solution. With SanDisk Fusion iomemory products

Network Virtualization

BROADCOM SDN SOLUTIONS OF-DPA (OPENFLOW DATA PLANE ABSTRACTION) SOFTWARE

Optimally Manage the Data Center Using Systems Management Tools from Cisco and Microsoft

OF 1.3 Testing and Challenges

U s i n g S D N - and NFV-based Servi c e s to M a x i m iz e C SP Reve n u e s a n d I n c r e ase

The Impact of Virtualization on Cloud Networking Arista Networks Whitepaper

Mit Soft- & Hardware zum Erfolg. Giuseppe Paletta

Het is een kleine stap naar een hybrid cloud

BRINGING NETWORKS TO THE CLOUD ERA

Optimizing Data Center Networks for Cloud Computing

Product Brochure. Hedvig Distributed Storage Platform Modern Storage for Modern Business. Elastic. Accelerate data to value. Simple.

Why Cisco for Cloud? IT Service Delivery, Orchestration and Automation

Virtualization: The entire suite of communication services can be deployed in a virtualized environment 2.

Transcription:

Scalable Network Monitoring with SDN-Based Ethernet Fabrics Prashant Gandhi VP, Product Management & Strategy Big Switch Networks 1

Agenda Trends in Network Monitoring SDN s Role in Network Monitoring Monitoring Fabric based on SDN & Bare-metal switching Customer Use Cases 2

Why Network Monitoring? Physical Workloads Virtual Workloads Monitoring Tools Production Network Net Mon SLA Mon Sec Mon App Mon Data Recorder VOIP Mon Every organization needs to Monitor Enterprises, Service Providers, Public Sector, Cloud 3

Customer Requirements Physical Workloads Virtual Workloads Monitoring Tools Net Mon App Mon Production Network Sec Mon VOIP Mon SLA Mon Data Recorde r Bandwidth: 10G, 40G Scale: 100s of Ports Flexibility: Any Tool to Any Tap Multi-tenancy: Multiple IT Teams Cost Optimized: Lower CapEx and OpEx 4

Gen-1: Tap & Tool Silo Tools 1/10GE Network Probe / Recorder 1/10GE Performance Monitoring Appliance Security Appliance Physical & Virtual Workloads Manual Connections Complex Silo operation May 2014 Big Switch Networks (www.bigswitch.com) 5

Gen-2: Limited Tap Aggregation Tools Physical & Virtual Workloads Complex Limited-scope Operation Higher cost 6

Gen-3: SDN-based Monitoring Fabrics SDN Controller 1G/10G/40G SDN-based Ethernet Monitoring Fabric based on Bare-metal Switches 1G/ 10G/ 40G Physical & Virtual Workloads Monitoring Fabric s as Service Nodes Tool Farm 7

SDN s Role in Network Monitoring 8

Learnings from HyperScale DCs Bare Metal - HW / SW disaggregation - No vendor lock-in - Much lower CapEx SDN - No complex protocols on HW - Massive simplification w/ SDN Controller - Fast speed of change - Much lower OpEx Modern Network Architecture - Agility - Choice - Lower TCO 9

SDN 2.0 Architectural Evolution Accelerate Production-grade SDN and Bare-metal deployments SDN 1.0: Fragmented SW stack Automation Tool SDN Controller OpenFlow APIs SDN App North-bound APIs SDN 2.0: Converged SW Stack Automation Tool North-bound APIs SDN App SDN Controller OpenFlow & Extensions (Thick) NetOS OF Traditional Switch HW Too many moving parts for SW (many SW vendors) OF agent from HW vendor varied implementations Limited access to switch ASIC access & Switch HW (Thin) Switch Light OS Bare Metal Switch HW SW solution from single vendor (exactly like the hypervisor/server model) Full access to switch ASIC and Switch HW Logically Centralized / Hierarchically implemented Control-Plane 10

Gen-3: SDN-based Monitoring Fabrics SDN Controller 1G/10G/40G Network Monitoring Fabric based on SDN and Bare-metal Switches 1G/ 10G/ 40G Physical & Virtual Workloads Monitoring Fabric s as Service Nodes Tool Farm 11

Monitoring Fabric based on SDN and Bare-metal Switches 12

Gen-3: Monitoring Fabrics Controller 1G/10G/40G 1G/ 10G/ 40G Physical & Virtual Workloads Monitoring Fabric s as Service Nodes Tool Farm 13

Monitoring Fabric: Components Filter Ports (Tap and facing ports) Controller Monitoring Fabric Delivery Ports (Tool facing ports) Controller (SW) Single pane of glass VM or appliance Built-in GUI, CLI, REST Policy management Fabric (forwarding) management Switch control & management Role-based Access Control Trouble-shooting, fault detection Clustering for High Availability Switches Hardware: Bare-metal switch OS: Switch Light No complex protocols Auto installation via ONIE Ports Filter, Service, Delivery 14

Policy Example 1 Controller Tool Farm F1 D1 Policy P1: Filter Port: F1 Delivery port: D1 Match packets with source ip=10.1.1.x/24 All Packets that do NOT match the rule are DROPPED (filtering operation) Production Network Monitoring Fabric s as Service Nodes 15

Policy Example 2 Controller Tool Farm D1 D2 Policy P2: Filter Port: F2 Delivery port: D1, D2, D3 Match packets with source ip=10.1.1.x/24 F2 D3 All packets matching the rule are replicated and sent to the designated tools (as per policy) Production Network Monitoring Fabric s as Service Nodes 16

Service Chaining of s Controller Tool Farm s as Service Nodes for adv. packet processing: Time-stamping De-duplication packet slicing Service Chaining: Multiple s can be logically chained on a per-policy basis for sophisticated flow processing Production Network Monitoring Fabric s as Service Nodes 17

Tool Scaling Controller Tool Farm Tool Load-balancing: Scale tool bandwidth Production Network Monitoring Fabric s as Service Nodes 18

Monitoring VM-to-VM Traffic vswitch Enable R vswitch Enable R Physical Network Same Monitoring Fabric is leveraged for monitoring VM-to-VM traffic R-Span Traffic Monitoring Fabric Prod Traffic Tools 19

Multi-tenant Operation Monitoring as a Service Self-service monitoring for each group Role-based authorization and privileges Local and/or remote authentication Tenant-Aware GUI, CLI and REST API TACACS+ 20

Event-Triggered Monitoring Programmatic creation of policies based on an event using REST APIs Normal packet Packet of Interest Controller Invoke REST API of the Monitoring Fabric Wireshark (Capture) Dynamically provision / activate / update the policy Traffic of interest is now replicated to the capture tool too. Monitoring Fabric Snort (IDS) 21

Filter Ports (Tap and facing ports) Monitoring Fabric: Functionality Controller Monitoring Fabric Delivery Ports (Tool facing ports) Rich Feature Set 7-tuple policies (L2 L4) IPv6 support Fine-grain Role-Based Access Control Intelligent Policy Resolution VM-to-VM monitoring Programmatic control Service chaining of s Operational Simplicity Auto-Installation Fabric Management & Programmability Enhanced GUI Workflows Scalable Architecture Tool scaling (via load balancing) Fabric scaling (scale-out) Policy scaling (via optimization) 22

Customer Use Cases 23

Customer Use Cases Large Web 2.0 Datacenter: Network ops, security and compliance teams all share the same taps LTE Operator: 4G LTE network monitoring for trouble-shooting and compliance Large Hi-Tech Company: Self-service production tapping for software developers Santa Clara, CA USA April-May 2014 24

Customer Testimonial FYI, we just had a the other day. We had a customer facing issue that s been going on for a month. We thought it was an issue with the ISP. Being able to take a capture off the Core device, we were able to prove it was an issue in our own infra. to identify once we had access to the data. - Network Administrator in a Fortune 50 Company 25

Thank You! 26