SDN in the Public Cloud: Windows Azure. Albert Greenberg Partner Development Manager Windows Azure Networking albert@microsoft.com



Similar documents
SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Ethernet-based Software Defined Network (SDN) Cloud Computing Research Center for Mobile Applications (CCMA), ITRI 雲 端 運 算 行 動 應 用 研 究 中 心

Microsoft SharePoint Architectural Models

How To Make A Vpc More Secure With A Cloud Network Overlay (Network) On A Vlan) On An Openstack Vlan On A Server On A Network On A 2D (Vlan) (Vpn) On Your Vlan


Microsoft System Center

Testing Software Defined Network (SDN) For Data Center and Cloud VERYX TECHNOLOGIES

VMware vcloud Air. Enterprise IT Hybrid Data Center TECHNICAL MARKETING DOCUMENTATION

Software Defined Network (SDN)

Virtualization, SDN and NFV

SDN CONTROLLER. Emil Gągała. PLNOG, , Kraków

Cloud Networking Disruption with Software Defined Network Virtualization. Ali Khayam

VMware vcloud Air Networking Guide

SOFTWARE-DEFINED NETWORKING AND OPENFLOW

Data Center Network Virtualisation Standards. Matthew Bocci, Director of Technology & Standards, IP Division IETF NVO3 Co-chair

Cisco Prime Network Services Controller. Sonali Kalje Sr. Product Manager Cloud and Virtualization, Cisco Systems

WINDOWS AZURE NETWORKING

NVGRE Overlay Networks: Enabling Network Scalability for a Cloud Infrastructure

BRINGING NETWORKS TO THE CLOUD ERA

Introduction to Network Virtualization in IaaS Cloud. Akane Matsuo, Midokura Japan K.K. LinuxCon Japan 2013 May 31 st, 2013

Definition of a White Box. Benefits of White Boxes

CLOUD NETWORKING THE NEXT CHAPTER FLORIN BALUS

SDN PARTNER INTEGRATION: SANDVINE

SDN AND SECURITY: Why Take Over the Hosts When You Can Take Over the Network

Pluribus Netvisor Solution Brief

Chapter 11 Cloud Application Development

How To Orchestrate The Clouddusing Network With Andn

Microsoft Azure for IT Professionals 55065A; 3 days

CoIP (Cloud over IP): The Future of Hybrid Networking

Cisco Intercloud Fabric for Business

Ethernet-based Software Defined Network (SDN)

Hyper-V Network Virtualization Gateways - Fundamental Building Blocks of the Private Cloud

Deploying Microsoft Dynamics CRM in Microsoft Azure Virtual Machines. October 2015

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

State of the Art Cloud Infrastructure

Outline. Why Neutron? What is Neutron? API Abstractions Plugin Architecture

Technical white paper. Realizing the power of SDN with HP Virtual Application Networks

HAWAII TECH TALK SDN. Paul Deakin Field Systems Engineer

OpenFlow/SDN for IaaS Providers

SharePoint 2013 on Windows Azure Infrastructure David Aiken & Dan Wesley Version 1.0

The Road to SDN: Software-Based Networking and Security from Brocade

Introduction to Software Defined Networking (SDN) and how it will change the inside of your DataCentre

SDN/Virtualization and Cloud Computing

Implementing Microsoft Azure Infrastructure Solutions

Software-Defined Networks Powered by VellOS

CERN Cloud Infrastructure. Cloud Networking

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

SOFTWARE DEFINED NETWORKING

Qualifying SDN/OpenFlow Enabled Networks

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

SDN v praxi overlay sítí pro OpenStack Daniel Prchal daniel.prchal@hpe.com

Building Scalable Multi-Tenant Cloud Networks with OpenFlow and OpenStack

IPOP-TinCan: User-defined IP-over-P2P Virtual Private Networks

Software Defined Networking (SDN) OpenFlow and OpenStack. Vivek Dasgupta Principal Software Maintenance Engineer Red Hat

Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera VERSION May, 2015

Delivering Managed Services Using Next Generation Branch Architectures

The Last Piece of the Puzzle From Legacy to SDN and NFV. Benjamin Then

Hybrid Cloud with NVGRE (Cloud OS)

Extending your datacenter to the cloud

VMUG - vcloud Air Deep Dive VMware Inc. All rights reserved.

vcloud Air - Virtual Private Cloud OnDemand Networking Guide

Cloud Fabric. Huawei Cloud Fabric-Cloud Connect Data Center Solution HUAWEI TECHNOLOGIES CO.,LTD.

Microsoft Implementing Microsoft Azure Infrastructure Solutions

Remote Voting Conference

Palo Alto Networks. Security Models in the Software Defined Data Center

What is SDN? And Why Should I Care? Jim Metzler Vice President Ashton Metzler & Associates

SDN and Data Center Networks

Defining SDN. Overview of SDN Terminology & Concepts. Presented by: Shangxin Du, Cisco TAC Panelist: Pix Xu Jan 2014

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

Using LISP for Secure Hybrid Cloud Extension

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

OpenStack Networking: Where to Next?

Testing Network Virtualization For Data Center and Cloud VERYX TECHNOLOGIES

Network Virtualization for Large-Scale Data Centers

Building a BI Solution in the Cloud

SDN for the Cloud. Albert Greenberg Distinguished Engineer Director of Microsoft Azure albert@microsoft.com

Securing the Virtualized Data Center With Next-Generation Firewalls

Availability Digest. Redundant Load Balancing for High Availability July 2013

2013 ONS Tutorial 2: SDN Market Opportunities

Clodoaldo Barrera Chief Technical Strategist IBM System Storage. Making a successful transition to Software Defined Storage

A Coordinated. Enterprise Networks Software Defined. and Application Fluent Programmable Networks

SDN Architecture and Service Trend

Part 1 - What s New in Hyper-V 2012 R2. Clive.Watson@Microsoft.com Datacenter Specialist

SDN Software Defined Networks

Cloud OS. Philip Meyer Partner Technology Specialist - Hosting

SDN Applications for IXPs and Service Providers. Jason Kleeh Senior Product Manager January, 2013

PLUMgrid Open Networking Suite Service Insertion Architecture

HOW SDN AND (NFV) WILL RADICALLY CHANGE DATA CENTRE ARCHITECTURES AND ENABLE NEXT GENERATION CLOUD SERVICES

SQL Server Hybrid Features. Luis Vargas, Senior Program Manager Lead Xin Jin, Program Microsoft

RemoteApp Publishing on AWS

Bring your virtualized networking stack to the next level

Microsoft System Center

Accelerating Network Virtualization Overlays with QLogic Intelligent Ethernet Adapters

基 於 SDN 與 可 程 式 化 硬 體 架 構 之 雲 端 網 路 系 統 交 換 器

SOFTWARE DEFINED NETWORKING: A PATH TO PROGRAMMABLE NETWORKS. Jason Kleeh September 27, 2012

Bringing the Public Cloud to Your Data Center

Network Virtualization Based on Flows

Transcription:

SDN in the Public Cloud: Windows Azure Albert Greenberg Partner Development Manager Windows Azure Networking albert@microsoft.com

Microsoft s big bet on public cloud service Lets companies move their IT infrastructure to the cloud Provides platform services to build SaaS applications, infrastructure services for IT, scalable cloud storage, and more Elastic scaling and much lower COGS than on-prem data centers Also runs major Microsoft cloud properties. All are moving to Windows Azure

Windows Azure - Some Stats More than 50% of Fortune 500 companies using Azure Nearly 1000 customers signing up every day Hundreds of thousands of servers We are doubling compute and storage capacity every 6-9 months Azure Storage is Massive over 4 trillion objects stored Windows Azure Directory has processed 200 billion authentications

Big Bet on Enterprise: Infrastructure as a Service (IaaS) Bring your own persistent VMs to the Cloud Anything that runs on Hyper-V runs on Azure Manage your infrastructure and policy as if it was your own What does IaaS require of networking? Domain join your VMs to your domain controller Connect cloud DNS to on-premise DNS Set up a Sharepoint farm in the cloud and serve it back to your corporate intranet 7x 6x 5x 4x 3x 2x 1x 0x Active IaaS VMs running on Azure September 2012 April 2013 1.5 Million IaaS VMs created since IaaS preview (June 12)

Onboarding Enterprises to the Cloud: Windows Azure Virtual Networks Goal: Windows Azure is just another branch office of your enterprise, via VPN 10/8 Requirements BYO Customer Address (CA) Space + Policy to the cloud Communication between tenants of your Azure deployment is efficient and scalable Enabled via overlay networking (NVGRE) 10/8

Challenge of Building VNet: Agility at Scale Goals Agility: On demand provisioning of customer networks and policies Every time a customer creates a VM or tenant, network resources must be provisioned Scale: Millions of VMs, 100 s of thousands of nodes with high density (10GbE) How to solve this: division of labor Software focuses on translation of demands to policy and implementation Hardware focuses on capacity, reliability and perf 10G Servers

Solution: Software Defined Networking Key architecture: policy is abstracted, with sharp division of labor between management, control and data planes Management Plane (Northbound API) Azure Frontend Management plane Control plane Data plane Example: Access Control Lists (ACLs) Create a tenant Plumb these tenant ACLs to these switches Apply these ACLs to these flows Control Plane (Southbound API) Controller VMSwitch

SDN Approach to Building VNet Customer Config A VNet is essentially a set of mappings from a customer defined address space (CAs) to provider addresses (PAs) of hosts where VMs are located Separate the interface to specify a VNet from the interface to plumb mappings to VMSwitches via a Network Controller Northbound API Southbound API Azure Frontend VMSwitch Controller VNet Description (CAs) L3 Forwarding Policy (CAs <-> PAs) VMSwitch Green VMs CA Space Blue VMs CA Space

Vnet Controller Model Customer Config Azure Frontend Secondary Controllers Consensus Protocol Controller VNet Description Green Enterprise Network 10.2/16 VPN GW L3 Forwarding Policy Node1: 10.1.1.5 Node2: 10.1.1.6 Node3: 10.1.1.7 Green VM1 Blue VM1 Red VM1 Green VM2 10.1.1.3 Green S2S GW 10.1.2.1

Forwarding Policy: Intra-VNet Secure, intra-tenant networks on shared infrastructure Controller L3 Forwarding Policy Policy lookup: VM 10.1.1.3 is on host with PA 10.1.1.6 Src: Dst:10.1.1.3 Src:10.1.1.5 Dst:10.1.1.6 GRE:Green Src: Dst:10.1.1.3 Node1: 10.1.1.5 Node2: 10.1.1.6 Packet is on Green Vnet: Decap Src: Dst:10.1.1.3 Green VM1 Blue VM1 Red VM1 Green VM2 10.1.1.3

Forwarding Policy: Traffic to On-premise Green Enterprise Network 10.2/16 VPN GW BYO Routing Policy Controller to the Cloud L3 Forwarding Policy L3VPN PPP Src: Dst:10.2.0.9 Policy lookup: 10.2/16 routes to GW on host with PA 10.1.1.7 Src: Dst:10.2.0.9 Src:10.1.1.5 Dst:10.1.1.7 GRE:Green Src: Dst:10.2.0.9 Node1: 10.1.1.5 Src: Dst:10.2.0.9 Node3: 10.1.1.7 Green VM1 Blue VM1 Green S2S GW 10.1.2.1

VNet is a Hit! >25% of all IaaS deployments create VNets Tens of thousands of VNets created since preview last summer, running gateways back to on-prem We have single VNets running thousands of VMs VNet is the central piece of our Hybrid Cloud strategy we let enterprises migrate to the cloud at their own pace, in a familiar environment Corpnet

More Cloud Networking Challenges

Cloud Services Run Behind Load Balancers All infrastructure runs behind a load balancer (LB) to enable high availability and application scale How do we make application load balancing scale to the cloud? Challenges: How do you load balance the load balancers? Hardware LBs are complex, and cannot support the rapid creation/deletion of LB endpoints required in the cloud Support 100s of Gbps per data center Need a simple provisioning model Web Server VM SQL Service IaaS VM LB Web Server VM SQL Service IaaS VM

SDN Approach: All-Software Load Balancer Client VIP VIP Edge Routers Goal of an LB: Map a Virtual IP (VIP) to a set of Dedicated IP addresses (DIPs) of a cloud service Two steps: Load balance (select a DIP) and NAT (translate VIP DIP and ports) Pushing the NAT to the VMSwitch removes state from LB and enables direct return Single SDN controller abstracts out LB/VMSwitch interactions Tenant Definition: VIPs, # DIPs Controller VM DIP 10.1.1.5 LB VM NAT Mappings VM DIP 10.1.1.4 Direct Return: VIP VIP VM DIP 10.1.1.3 LB VM DIP NAT NAT Stateless Tunnel DIP VM DIP

SDN abstracts all net policies Simple policy management Azure Frontend Customer Config 5-tuple ACLs Infrastructure Protection User-defined Protection Billing Metering traffic to internet Rate limiting Security Guards Spoof, ARP, DHCP, and other attacks Per-tenant DNS VLANs Physical switches More in development VM1 Controller Tenant Description ACL: VM2 can talk to other green VMs ACL: VM2 can talk to VM3 but not VM4 Meter all traffic from VM2 outside of 10/8 Rate limit VM2 to 800mbps Node2: 10.2.1.6 VM4 10.1.1.5 Billing VM3 10.1.1.4 VM2 10.1.1.3 VM2 sent 23MB of public internet traffic

VMSwitch: The intersection of all policy VMSwitch exposes a typed matchaction-table API to controllers One table per policy type Similar to OpenFlow 1.x, but with stronger typing (to gain performance at 10GbE) VNet Routing Policy Controller NAT Endpoints VNet Description Tenant Description ACLs Node: 10.4.1.5 NIC Flow Action Flow Action Flow Action TO: 10.2/16 Encap to GW TO: 79.3.1.2 DNAT to TO: 10.1.1/24 Allow TO: 10.1.1.5 Encap to 10.5.1.7 TO:!10/8 SNAT to 79.3.1.2 10.4/16 Block TO:!10/8 NAT out of VNET TO:!10/8 Allow VNET LB NAT ACLS Blue VM1

End Result: Agility and Scale Windows Azure supports virtual networks, rich load balancing, tenant ACLs, and more for hundreds of thousands of servers, via software No Hardware per tenant ACLs No Hardware NAT No Hardware VPN / overlay No Vendor-specific control, management or data plane Load Balancer (VM) All policy is in software and everything s a VM! Network services deployed like all other services Red VM Azure Frontend (VM) Controller (VM) VMSwitch Northbound API Southbound API Gateway VM We bet our infrastructure on SDN, and it paid off

Final thoughts: Challenges Overcome It s not scalable to synchronously push the entire network state to every VMSwitch We have to enable eventual consistency on the network with event-driven control plane updates A wire protocol back to the controller doesn t scale we need smart agents The VMSwitch is policy rich, but needs to support 10GbE/40GbE Extensive flow hashing is required, as well as strict table typing Managing latency and latency jitter is getting increasingly difficult SDN scales better, but it still has finite scale; need to federate controllers It s a challenge to federate the controller sets and still achieve consistent policy Have to federate the Northbound API