Beruflich Dokumente
Kultur Dokumente
#NET5270
Agenda
Introduction
NSX Edge Gateway
Routing & Firewalling
LB
VPN
Introduction
VMware vCAC
NSX API
L3 Gateway
L2 Gateway
VM
VM
ADC/LB
VM
VM
VM
Endpoint
Security
VM
VMware vSphere
NSX
Edge
Firewall
GatewayVPN
Use Cases
External
Networks
L2 VPN
BGP
L2 Bridge
Perimeter NSX Edge
(HA, FW, NAT, VPN, LB Services)
Bridged
VLAN
VM
OSPF
Bridged Logical
Switch
Management
VLAN
Transit
Logical Switch
VM
Logical Distributed Router
LB
Web
App
DB
Web
6
App
DB
Mainstream2
Early
Majority1
Early
Adopters
2011
Innovators
Enhanced FW
Basic LB
Basic VPN
Basic NAT
2010
Baseline
FW/Router
Science
Fiction
7
1
2
2013
2012
Enterprise Grade
Firewall
L7 LB
SSL VPN
Advanced NAT
Static Routing
Compliance
Certifications
IPSec VPN H/W
Accel
LB Scale,
Performance, SSL,
L7++
10G Firewall
L2VPN
Dynamic Routing
OSPF, BGP, IS-IS
IPv6
Multi-tenant/multi-context
Optimal placement
Run-time re-balancing
Perpetual redundancy
Advanced resource isolation
Scalable MGMT 2500 multi-tenant instances
Overview
Load Balancer
VPN
Routing
L2/L3
Gateway
L2/L3 Gateway
VM
VM
VM
VM
VM
10
Logical Firewall/Routing
Features
Tenant A
OSPF/eBGP/iBGP/IS-IS
Tenant B
L2
L2
L2
Tenant C
L2
L2
L2
L2
L2
11
Logical Firewall
VApp
Deny
Allow
WebServer
VApp Network
12
AppServer
DbServer
Logical Firewall
VApp
Deny
Allow
WebServer
VApp Network
13
AppServer
DbServer
14
Web 1
Web 2
Web 3
15
vApp
Load Balancer
WebServer-1
WebServer-2
Request
16
vApp
WebServer-1
WebServer-2
Load Balancer on
regular Edge
VDC Network
17
Request
18
Internet/
WAN
Internet/
WAN
19
Logical L2 VPN
Features
VM
VM
SSL-based
Web-proxy Support
L2 Bridge to Cloud
Broadcast support
VM
Public
Cloud
Use Cases
Cloud On-boarding
Cloud Bursting
20
21
So What?
External
Networks
L2 VPN
BGP
Management
VLAN
VM
22
So What?
External
Networks
VMware vCAC
NSX API
NSX Controller & NSX Manager
Partner Extensions
Security Services
L2 Gateway
24
ADC/LB
Firewall
IDS/IPS
AV/FIM
Vulnerability
Management
25
26
Operations
Load Balancer
Firewall
Analytics using
VCOPs
Syslog
28
vCHS
29
Virtual Workspace
Private
Clouds
Public
Clouds
Hybrid Cloud
Compute
Network and
Security
Objectives
vCHS Edge
Why Edge?
Evaluated leading Hardware and Software vendors to build the service
Edge was the only multiservice device that can be rapidly deployed, meet
scalability needs and integrate with vCD and vSphere
31
Load
Balancing
Web
Server LB
Dynamic
Per Tenant
VPN
IPSEC
Tunnel
SSL VPN
DCE L2
VPN
L3 Gateway
Static
Routes
Default
Gateway
32
Questions?
To get complete understanding of NSX Optimized for
vSphere checkout
Network Virtualization
NET5266 - Network Virtualization for vSphere environments with VMware NSX
33
THANK YOU
NET5270
Virtualized Network Services Model
with VMware NSX
Arun Goel, VMware
Serge Maskalik, VMware
#NET5270