Beruflich Dokumente
Kultur Dokumente
1
PacketPushers.net
About Me
Host of Packet Pushers Podcast
Freelance Network Architect/Engineer
YOU CAN HIRE ME!
Blog - EtherealMind.com
NetworkComputing.com
(http://networkcomputing.com/blogs/author/Greg-Ferro)
gregferro.com - personal blog
2
Fundamental Changes
3
Post-Scarcity Markets
Genesis Custom Product Commodity
Infrastructure is Greg Ferro 2014
commoditised
Bandwidth is Prototype
Custom
Built
Short Run
Manufacture
Mass
Manufacture
cheap, plentiful,
Unique Components Repeatable Repeatable
available Complex Simplified Simpler Simple
Greg Ferro 2014
4
Post -Scarcity Impacts
5
Thoughts on New Networking
6
WAN Pain Points
COST
Service Provider Business
Highly profitable
Oversubscription is good profits
Service Guarantees are expensive to deliver and profitable to sell
Collapsing ecosystem (static revenue, competitive pressures, and
political change)
Technology doubles bandwidth every 2/3 yrs but costs dont
reduce
7
QoS as a BUG
QoS is a way of conserving bandwidth
Complex to design and deploy
Hardware dependent
Marking issues
Costly to Operate
monitoring, SLA, compliance,
what is important
8
WAN Tunnels with MPLS
MPLS is an Overlay Network
circuits are MPLS tunnels
Operating the overlay is expensive
Slow provisioning - MPLS is hard
Enterprise IT is generalist not specialist
MPLS works for carriers as specialist skill set
9
WAN Wants, Can and
Cants .
10
What You Want
Carrier independence
Technology independence
Full or Partial Mesh
Zero Risk Path Change
Dynamic
Temporal
Bandwidth
11
What You Can Have
Physical
Private WAN, Dark Fibre, IP Optical
DSL / Cable Broadband - low cost, fast, high con
LTE - fast deployment, high speed
Internet - buy enough capacity & quality is fine
Actually, you want all of these. From multiple providers
12
Bandwidth is Cheap
Waste It
Change It
If your WAN is
Source: Telegeography
Packet Inspection Only IP Headers and Domain Name Less Functional QoS
14
Building Network
Services
15
Services not Connectivity
16
Services not Connectivity
17
WAN as a Service
Service Features Service
18
Whats Wrong with
Routing ?
19
Forwarding Paths
Forwarding Paths independent of Physical
3
20
Best and Only Path
Why only ONE path ?
Unused Paths
Redundant & Unused Path
Router
24
What is Flow
Networking ?
25
Three Things
26
The Nature of Flow - 1
Session - Server to Client
Server Client
Server
Server Client
Server
Client
Server
29
Define Flow
MAC Source MAC IP Source Destination
Priority Ethertype IP Destination Protocol Source Port Counters Instructions
Address Destination Address Port
Ethernet
Flow Rule MAC IP Source TCP/ UDP/ TCP Source Destination
Frame 0001.00dc. IP Destination Counters Instructions
Priority Destination Address ICMP Port Port
Encapsulation
30
Flow Tables
Flow Table
Flow Record
Input Output
Flow Record
Client Server
applications dont see Client sends SYN Packet
SYN
Server ACKs to confirm inbound
interaction
33
Flow State Can Have An API
34
What Can Flows Be ?
Flow Types Technology
36
Flow Networking
Today SDN WAN / Tomorrow
37
Controller Networking
38
Flow Management
39
Controller Model
Cloud Orchestrator
SDN Controllers
40
Distributed Controller Models
SDN WAN Orchestrator
SDN Controller
API Network
Controller
APIs in Networking
42
Controller vs Self-Configuring
Todays networks are self configuring
Routing protocols configure devices
autonomously, uncontrolled way
Controller acts to focus configuration so that
entire network view can be taken
Controller does not prevent self-configuration ,
there are SDN types that use BGP or IS-IS
43
Controller / Flow Forwarding
Network Application Network Application
Network Controller
Greg Ferro 2014
Input Flow Record Output Input Flow Record Output Input Flow Record Output
Input Flow Record Output Input Flow Record Output Input Flow Record Output
SRC/DST IP, TCP Port, SRC/DST IP, TCP Port, SRC/DST IP, TCP Port,
Input VLAN or MPLS tag Output Input VLAN or MPLS tag Output Input VLAN or MPLS tag Output
45
Dierence
Naming Convention
Tunnels are statically configured encapsulation
IPSec, GRE, IPinIP, SSL VPN
Overlays are dynamically configured
encapsulation
VXLAN, NVGRE, IPSec, SSL VPN
46
Overlay and Path Independence
2
2 Router
Router
1 3
Router 2 Router
Router
Greg Ferro 2014
Encapsulated Path
47
Changing this is HARD
Router
Router Carrier
Router Carrier
Router
Router
Carrier Carrier
Greg Ferro 2014
48
Flow Routers at the Edge
Carrier Router
Router Carrier
Router
Carrier Carrier
Greg Ferro 2014
Encapsulated Path
49
Forwarding in Overlay Networks
Network Application Network Application
Network Controller
Greg Ferro 2014
IP Routing
Input Flow Record Output Input FIB Output Input Flow Record Output
Input Flow Record Output Input FIB Output Input Flow Record Output
Input VLAN or MPLS tag Output Input FIB Output Input VLAN or MPLS tag Output
Flow Table with Tunnel/Encapsulation Action FIB Table Flow Table with Tunnel/Encapsulation Action
1 2 3 4 5
50
Overlay Networks
51
WAN Overlay Technologies
Encapsulation Protocols have different features
LISP - suited to self configuring/static networks
IPsec / DMVPN etc -
SSL VPN
Configuration management
Must manage crypto keys, session data, etc
End points, devices,
Viptela Case Study
SSL for control plane
IPsec for forwarding plane
52
Path Management / Quality
Two choices
flow quality by inspection
edge device analyses flow quality
in band detection
run a protocol in the path
eg. BiDirectional Forwarding Detection detect latency,
packet loss etc
53
The Impact of
Software Appliances
54
Bare x86 Performance
Source: Intel Xeon Processor E5-2600 v3 Product Family with the Intel
Communications Chipset 89xx Series for Telco and Cloud Service Providers DATS005
from Intel IDF2014
55
56
Source: Intel Xeon Processor E5-2600 v3 Product Family with the Intel Communications Chipset 89xx Series for Telco and Cloud Service Providers
DATS005 from Intel IDF2014
57
x86 Impact
Source: Intel Xeon Processor E5-2600 v3 Product Family with the Intel Communications Chipset 89xx Series for Telco and Cloud Service Providers
DATS005 from Intel IDF2014
58
Cloud Managed WANs
59
Branch Networking
Can we manage a branch network from a cloud
platform ?
Yes we can.
Netsocket, CloudGenix, Meraki
Also Aerohive, Aruba are compelling WiFI centric
options
60
Internet as WAN
66
What is NFV ?
NFV Platform
configurable to a fine
Router IPS/IDS
grained level WAN Accel Firewall Proxy
Network Forwarding
Customer Portal
67
Technical Highlights
NFV Platform
asset management
Managed Traffic Flow
out of band management
flexible service creation SDN Platform Cloud Orchestrator
etc etc
Customer Portal
68
Carrier NFV as Product
IPsec, SSLVPN are configured as end points not tunnels
x86 Server x86 Server x86 Server
Router Router
PoP
Cloud
SDN Platform
x86 Server x86 Server x86 Server Orchestrator
Router
WAN Accel IPS/IDS
Phone / Laptop Firewall Proxy
Mobile / Home
KVM Hypervisor
Physical Server
KVM Hypervisor
Physical Server
KVM Hypervisor
Physical Server
Customer
Portal
PoP
Data Centre
x86 Server x86 Server x86 Server
Router Router
WAN Accel IPS/IDS
Branch Firewall Proxy
KVM Hypervisor KVM Hypervisor KVM Hypervisor
Physical Server Physical Server Physical Server
Phone / Laptop
70
Business Value of NFV/Service Chain
72
Whats New
73
Flow Monitoring
NetFlow has proved that flow monitoring is what
we need
Devices that perform flow networking are
inherently well suited to monitoring
(not per bit or per packet)
Devices are producing statistics from the flow
database
74
Edge Devices
Processing Power in Hardware Device
Switches with Intel x86 Xeon CPU, 128 Gigabytes
memory
Switch Silicon - Broadcom T2, enterprise class
Operating System = Linux
Run Applications on Edge Device
Applications = Collectors, Rporters
75
Edge Devices - 2
Software Edge Devices
x86 Performance is already > 40 Gbps
VMs most likely
CPU / Memory is now cheap (post scarcity)
Intel DPDK demonstrated at 160 Gbps or 4 x 40GbE
interfaces with 100 byte packets Source: Intel IDF 2014
76
Examples
77
SDN WAN Vendors
78
Companies to Watch
Viptela Cisco
Talari Networks WAN Automation Engine
Vello Systems ACI
VeloCloud XNC/OpenDaylight
iWAN (Akamai)
Pertino
CloudGenie
Glue Networks
79
Wrap Up
80
Takeaways
Overlay Networking in the Enterprise WAN will
enable existing networks to move beyond
connectivity
Edge Routers will use flow networking to virtualise
the WAN
Controller/App technology can manage flows to
deliver services from connectivity
derived WAN offers new models of ownership
81
Takeaways
Network Edge start moving to commodity
appliances.
Some will use x86 servers and Ethernet interfaces
NFV and Software Appliances will dominate the
WAN product space
Technologies based on protocol interception and
analysis face an uncertain future
82
Please Rate Me
83
Question Time
Host of Packet Pushers Podcast
Freelance Network Architect/Engineer
Blog - EtherealMind.com
NetworkComputing.com
(http://networkcomputing.com/blogs/author/Greg-Ferro)
Slides: speakerdeck.com/etherealmind
84