The Case for Enterprise Ready Virtual Private Clouds



Similar documents
CloudNet: Enterprise. AT&T Labs Research, Joint work with: Timothy Wood, Jacobus van der Merwe, and Prashant Shenoy

The Case for Enterprise-Ready Virtual Private Clouds

Enterprise-Ready Virtual Cloud Pools: Vision, Opportunities and Challenges

Enterprise-Ready Virtual Cloud Pools: Vision, Opportunities, and Challenges

Virtual Private Networks. Juha Heinänen Song Networks

TODAY S enterprises run their server applications in data

CloudNet: Dynamic Pooling of Cloud Resources by Live WAN Migration of Virtual Machines

Disaster Recovery as a Cloud Service: Economic Benefits and Deployment Challenges

Lecture 02b Cloud Computing II

ICTTEN6172A Design and configure an IP- MPLS network with virtual private network tunnelling

VPLS lies at the heart of our Next Generation Network approach to creating converged, simplified WANs.

Network performance in virtual infrastructures

CLOUD NETWORKING THE NEXT CHAPTER FLORIN BALUS

How To Cloudburst

CloudNet: Dynamic Pooling of Cloud Resources by Live WAN Migration of Virtual Machines

Accelerate with Ampleflex Cloud! Highly adoptable and dependable platform for deploying services and applications into the Cloud.

Proactively Secure Your Cloud Computing Platform

Unleash the IaaS Cloud About VMware vcloud Director and more VMUG.BE June 1 st 2012

Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure

Layer-2 Design: Link Balancers Simplified

White Paper. Juniper Networks. Enabling Businesses to Deploy Virtualized Data Center Environments. Copyright 2013, Juniper Networks, Inc.

Security Challenges in Hybrid Cloud Infrastructures

How To Manage A Virtualization Server

Secure Cloud Computing with a Virtualized Network Infrastructure

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

JUNIPER. One network for all demands MICHAEL FRITZ CEE PARTNER MANAGER. 1 Copyright 2010 Juniper Networks, Inc.

Introduction to Network Virtualization in IaaS Cloud. Akane Matsuo, Midokura Japan K.K. LinuxCon Japan 2013 May 31 st, 2013

How To Deploy Sangoma Sbc Vm At Amazon Cloud Service (Awes) On A Vpc (Virtual Private Cloud) On An Ec2 Instance (Virtual Cloud)

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

SDN PARTNER INTEGRATION: SANDVINE

Application Description

CloudNet: A Platform for Optimized WAN Migration of Virtual Machines

Network Virtualization

SSVVP SIP School VVoIP Professional Certification

Demonstrating the high performance and feature richness of the compact MX Series

Securing Virtual Applications and Servers

Cisco Prime Network Services Controller. Sonali Kalje Sr. Product Manager Cloud and Virtualization, Cisco Systems

Software Defined Environments

Data Centers and Cloud Computing. Data Centers

Business Values of Network and Security Virtualization

VMware vcloud Networking and Security Overview

Cloud Computing and the Internet. Conferenza GARR 2010

NETWORKING FOR DATA CENTER CONVERGENCE, VIRTUALIZATION & CLOUD. Debbie Montano, Chief Architect dmontano@juniper.net

MPLS L2VPN (VLL) Technology White Paper

Edgewater Routers User Guide

Networking 4 Voice and Video over IP (VVoIP)

Going Hybrid. The first step to your! Enterprise Cloud journey! Eric Sansonny General Manager!

Leveraging SDN to Create Consumable, Programmable and

Network Virtualization Solutions

Elastic Management of Cluster based Services in the Cloud

VPN taxonomy. János Mohácsi NIIF/HUNGARNET tf-ngn meeting April 2005

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

NETE-4635 Computer Network Analysis and Design. Designing a Network Topology. NETE Computer Network Analysis and Design Slide 1

Networking with Windows Server vb. Day(s): 5. Version: Overview

Network Technologies for Next-generation Data Centers

Monetizing the Business Edge with Hosted Private Cloud Services

Cloud Atlas: A Software Defined Networking Abstraction for Cloud to WAN Virtual Networking

Network Virtualization Network Admission Control Deployment Guide

VMUG - vcloud Air Deep Dive VMware Inc. All rights reserved.

SOLUTIONS FOR DEPLOYING SERVER VIRTUALIZATION IN DATA CENTER NETWORKS

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

Enabling Solutions in Cloud Infrastructure and for Network Functions Virtualization

White Paper. Complementing or Migrating MPLS Networks

ENSEMBLE OSA Bringing the Benefits of the Cloud to the Metro Edge

Software Defined Network (SDN)

Malaysia State Government Data Center Construction

Edgewater Routers User Guide

IT & COMMUNICATION MANAGED SERVICES CATALOGUE

What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates

SSVP SIP School VoIP Professional Certification

Introduction to MPLS-based VPNs

Cloud Networking an Enterprise View

Cloud Computing Trends

The Platform as a Service Model for Networking

A Comparison of Clouds: Amazon Web Services, Windows Azure, Google Cloud Platform, VMWare and Others (Fall 2012)

Migrating to the Cloud. Developing the right Cloud strategy and minimising migration risk with Logicalis Cloud Services

Connecting to the Cloud with F5 BIG-IP Solutions and VMware VMotion

IPOP-TinCan: User-defined IP-over-P2P Virtual Private Networks

SINGLE-TOUCH ORCHESTRATION FOR PROVISIONING, END-TO-END VISIBILITY AND MORE CONTROL IN THE DATA CENTER

Expert Reference Series of White Papers. vcloud Director 5.1 Networking Concepts

Customer Training Catalog Training Programs IDC

SOFTWARE DEFINED NETWORKING

Installing Intercloud Fabric Firewall

VMware NSX Network Virtualization Design Guide. Deploying VMware NSX with Cisco UCS and Nexus 7000

MikroTik RouterOS Introduction to MPLS. Prague MUM Czech Republic 2009

Service Orchestration: The Key to the Evolution of the Virtual Data Center

Control Tower for Virtualized Data Center Network

Campus LAN at NKN Member Institutions

Virtualization, SDN and NFV

OpenFlow/SDN for IaaS Providers

Cloud Security Best Practices

HBC How to build your cloud - Steps to Extend your Datacenter

Disaster Recovery as a Cloud Service: Economic Benefits & Deployment Challenges

Pluralsight Training Pre-Approved for CompTIA CEUs

Aerohive Networks Inc. Free Bonjour Gateway FAQ

VXLAN: Scaling Data Center Capacity. White Paper

Shifting Roles for Security in the Virtualized Data Center: Who Owns What?

CloudLink - The On-Ramp to the Cloud Security, Management and Performance Optimization for Multi-Tenant Private and Public Clouds

Software Defined Network Application in Hospital

Transcription:

The Case for Enterprise Ready Virtual Private Clouds Timothy Wood, Alexandre Gerber *, K.K. Ramakrishnan *, Jacobus van der Merwe *, and Prashant Shenoy University of Massachusetts Amherst *AT&T Research

Cloud Computing Rent computation and storage resources on demand Accessed by multiple enterprise sites Cloud Platform Cloud Platform types: Software as a Service Hotmail, Google Docs Platform as a Service Google App Engine, Microsoft Azure Infrastructure as a Service Amazon EC2, VMware vcloud Enterprise Sites

Enterprise Cloud Challenges Existing platforms do not meet the needs of enterprise customers Insufficient security controls Need isolation at server and network level Deployment is difficult Cloud resources are completely separate from local ones Can t make VMs look like part of existing LAN Limited control over network resources Cannot specify network topology or IP addresses Cannot reserve bandwidth or request QoS guarantees for network links

Moving to the Cloud Acme wants to move part of its payroll app into the cloud Should be easy, right? Acme LAN Front End Reports Processing Tier Data Store Processing Tier Cloud Platform

Problem #1: Transparency Application may have been written for LAN environment Might utilize broadcast or LAN service discovery Must add Internet gateways for apps previously only on LAN Now must communicate via public IPs or configure DNS Acme LAN Front End front.acme.com Data Store data.acme.com GW GW Lack of transparency causes application modifications and infrastructure reconfigurations Cloud Platform Processing proc.cloud.com

Problem #2: Security Acme s servers are now accessible from the public internet! Servers formerly on secure LAN now exposed to malicious users Must configure firewall rules to limit access Fine grain rules are difficult to manage in dynamic environments Acme LAN Front End front.acme.com Data Store data.acme.com Lack of secure cloud connections exposes enterprise to threats from both in and out of the cloud Cloud Platform Processing proc.cloud.com Hacker123 hax.cloud.com

Problem #3: Flexible Resource Mgmt Benefit of cloud computing: ability to easily adjust resource capacities and add new VMs After a change must deal with transparency and security issues all over again! Current platforms do not support network resource reservation (Bandwidth/QoS guarantees) Acme LAN Front End front.acme.com Data Store data.acme.com +1 +1 Enterprises want control over network resources. Cloud must support dynamic changes +1 Cloud Platform Processing proc.cloud.com Processing #2 proc2.cloud.com

Key Observation Existing cloud platforms only cover storage and computation Cloud Platform Disk VM + + Enterprise Sites Enterprise Clouds need control over the network as well

Virtual Private Clouds A Virtual Private Cloud is A secure collection of server, storage, and network resources spanning one or more cloud data centers That is seamlessly connected to one or more enterprise sites VM VM Enterprise Sites VM VM Cloud Sites Virtual Private Networks (VPNs) Layer 2 and 3 MPLS based VPNs Created by network provider with no end host configuration Already used by many businesses!

For the customer: VPC Benefits Isolates network & compute resources Cloud resources are only accessible through VPN Simplifies deployment since cloud looks same as local resources For the service provider: Provides mechanism for control over resource reservation within provider network Simplifies management of multiple data centers by combining them into large resource pools

VPC Challenges & Solutions Existing cloud platforms do not integrate with network service providers Must coordinate with ISP to create VPN endpoints VPN endpoints must be linked to VLANs within the cloud data center VPN endpoints are traditionally static Utilize virtual routers with programmable interfaces to rapidly create and reconfigure routers Use BGP signaling to dynamically adjust VPN topology

CloudNet Cloud Manager Allocates computation and storage resources Manages VLAN assignment within cloud network Network Manager Creates and configure VPN endpoints Reserves network resources Network Manager Routers Customer Edge Cloud Manager Provider Edge VPN VPN VLAN VLAN VM VM VM VM

WAN Migration Layer 2 VPNs make WAN act like a LAN Can use existing LAN migration techniques to move across WAN

WAN Migration Layer 2 VPNs make WAN act like a LAN Customer Site CE Cloud Site 1 PE PE VLAN A B ARP! Layer 2 VPN (VPLS) Router Switch VPN endpoint PE CE VLAN ARP! B Cloud Site 2 Can use existing LAN migration techniques to move across WAN

Summary Cloud Computing for enterprises requires: Security Transparency Flexibility CloudNet can help provide these features Defines interface between cloud platform and network provider Uses VPNs for secure, seamless connections Employs virtualization at server, router, and network levels to improve agility and efficiency Future Work Network optimizations to reduce latency of WAN migration Utilize VPLS to simplify deployment of high availability services across WAN

Questions? twood@cs.umass.edu

Extra slides

WAN Migration LAN migration already supported by Xen, VMware, etc Transparently move a VM between two hosts Useful for load balancing, maintenance, etc Only works on LAN because of need for network reconfiguration Layer 2 VPNs make WAN act like a LAN Lets VPN endpoints across WAN act as a single LAN segment Allows for WAN migration without modifying VM platform! Storage migration still must be handled by other means