Académique Documents
Professionnel Documents
Culture Documents
EarlyEthernetCampusEvolution
Campus WAN
Core Layer
Layer3
Layer2
95%
5%
EthernetintheDataCenter
Data Center WAN
Core Layer
Aggregation Layer
< 25%
Thesamestructurednetworktopologies wereusedinthedatacenter,but
TrafficpatternismostlyEastWest (e.g.ApplicationtoDatabasetier). Largelayer2domainsneededfor clusteringandVirtualMachinemobility.
Layer2
Access Layer
Layer2
> 75%
SAN
TraditionalDataCenterNetworkIssues
Discrete& Decoupled
Discrete componentsandpieceparts Multiplemanagersand managementdomains BoxlevelpointServices Dynamicworkload managementcomplexity Multitenancycomplications SLAs&securityareerrorprone Toomanynetworktypes, withtoomanynodes&tiers Inefficient switching Expensive networkresources
Manual& Painful
Limited Scale
Clients are looking for smarter Data Center Infrastructure that solves these issues.
SmarterDataCenterInfrastructure
Expandable IntegratedSystem
Integrated
Simple,consolidatedmanagement SoftwareDrivenNetworkstack
WorkloadAwareNetworking
Automated Dynamicprovisioning
Wireonce fabric.Period.
Converged network
Optimized
Single,flatfabric Growasyouneedarchitecture
Optimized
TraditionalArcaneDCN MeshAhead
Optimized
StandardFabricTechnologyOptions
OpenFlow Controllers OpenFlowSwitches
OpenFlow Layer3
Largelayer2 Establishedtechnology Distributedcontrolplane Standardsbased Largescalability Distributedcontrolplane HAwithfastconvergence Largescalability Emergingtechnology HAwithfastconvergence (someproprietary) Smalllayer2without Singledisjointmultipath DOVEnetwork fabricmayneednewRFC Manydevicestomanage
2012 IBM Corporation
ECMP
TRILL
TRILL
Largelayer2 Distributedcontrolplane Largescalability HAwithfastconvergence Enablesnetwork functionsdeliveredas Services e.g.disjoint multipathing (morelater) Emergingtechnology Clientacceptancebarrier
Optimized
TRILLFabric
Migrationscalability
Keyfabricrequirements
Storage&clusterrequire fullpathredundancy and efficientmultipathing. Largelayer2forVMs.
VM
DualTRILLfabrics areemergingtoday.
Sharedmultipath Disjointmultipath
9
Optimized
OpenFlowBasedFabricOverview
EachswitchhasLayer2 forwardingturnedoff. Eachswitchconnectsto OpenFlow Controller (OFC). OFCdiscoversswitches andswitchadjacencies.
OpenFlow
Sharedmultipath Disjointmultipath
10
Manual& Painful
Virtualizationincreased networkmanagementcomplexity
Physical Network with vSwitches
App Server Database Server vSwitch Server vSwitch Server vSwitch Server
Before Virtualization
Web Server
Static workloads ran on bare-metal OS Each workload had network state associated with it. Physical network was static & simple (configured once)
11
Server virtualization = dynamic workloads VMs network state resides in vSwitch/DCN Physical network is dynamic and more complex (VMs come up dynamically & move)
http://dilbert.com/terms/
Automated
IBMVMready andDVS5000V
VMreadyPhase3 withDVS5000V VMMigration
VMreadyPhase2
ShippingsinceNov2008
VMMigration
vSwitch Server
vSwitch Server
vSwitch Server
5000V
Server
5000V
Server
5000V
Server
NMotion FollowsVM
NMotion PrecedesVM
Closedloopverification withvCenter
Automated
IBM BC-H IBM Rack Server
VM VM VM VM
DVS 5000v DVS 5000v DVS 5000v
VM
DVS 5000v
VM
DVS 5000v
between VMs in a single server (VEB) & VMs within a rack/chassis (VEPA)
NetworkVirtualizationTrends
VirtualMachinesper2SocketServer
(approximately10xevery10years)
2008
Infrastructure Groupware
2010
Database Web
2012
Email Application
2014
Terminal Server
2016
NumberofVMspersocketisrapidlygrowing(10xevery10years).
IncreasesamountofVMVMtrafficinEnterpriseDataCenters (e.g.coresidentWeb,Application&Database). VMgrowthincreasesnetworkcomplexityassociatedwithcreating/migrating: layer2(VLANs,ACLs)&layer3(e.g.Firewall,IPS)attributes.
14
Automated
HypervisorNetworkVirtualization TechnologyTrend
DOVE
Server Server Service VM1 Server
DC 1
DC 2
Layer2vSwitch features,plus: 1. Layer3DistributedOverlay VirtualEthernet(DOVE) 2. Simpleconfigureoncenetwork (physicalnetworkdoesnthaveto beconfiguredperVM). 3. Decouplesvirtualfromphysical 4. Multitenantaware 5. Enablescrosssubnet virtualapplianceservices (e.g.Firewall,IPS)
15
Automated
DOVETechnology VXLANbasedEncapsulationExample
Original Packet
Inner MAC Inner IP Payload
Encapsulation
Outer MAC Outer IP UDP EP Header Inner MAC Inner IP Payload
Version
I R R R Domain ID
Reserved Reserved
Encapsulation Protocol (EP) Header (e.g. VXLAN based) (VXLAN extension in Yellow necessary IETF version field)
16
Automated
OverviewofDOVETechnologyElements
DOVES
DOVES
Physical network
DOVE Controller
Overlay Network
DOVEController
Performsmanagement&aportionofcontrolplanefunctions acrossDOVESwitches
DOVESwitches(DOVES)
Provideslayer2overUDPoverlay(e.g.basedonOTV/VXLAN) Performsdataandsomecontrolplanefunctions RunsinHypervisorvSwitch orgateways ProvidesinterfacesforVirtualAppliancestopluginto (Analogoustoappliancelinecardsonamodularswitch)
17
Integrated
DOVETechnology+Multipathing
DOVE Gateways Software Defined Networking Stack
(more next)
..
DOVE controls overlay network forwarding
..
DOVEnetworksimplifiesvirtualmachinenetwork
EnablesmultitenancyallthewaytotheVM EnablessingleMACAddressperphysicalserver(2forHA) SignificantlyreducessizeofphysicalnetworkTCAM&ACLtables Increaseslayer2scalewithinDataCenterandacrossDataCenters, bydecouplingVMslayer2fromphysicalnetwork Qbg automateslayer2provisioning,DOVEautomateslayer37provisioning
Standardsbasedmultipathed physicalnetwork
18
Integrated
SystemNetworkingElementManager
Perform Efficient Firmware or Configuration Updates to Multiple Switches
Engineer
Operate
Automate VM network resident port profiles and converged fabric Quality of Service
Plan
19
Integrated
SoftwareDefinedNetworking Technologies
NetworkController
Multi-tenant Services SAN Services
Networkfunctions deliveredasservices
NetworkAPIs NetworkOperatingSystem
NativeSwitch (L2/3)Driver DOVE Driver OpenFlow Driver
MultitenantVMsecurity Virtualizedloadbalancing
Software HW&embeddedSW
ControlPlane
NetworkOperatingSystem drivessetofdevices
5KV 5KV 5KV 5KV
Physicaldevices(e.g.TOR) Virtualdevices(e.g.DVS5000v)
20
SummaryofTechnologyTrends
CAPEX OPEX ExpandableIntegratedSystem Technologies SDNStack (OpenFlow,DOVE,Services) IntegratedManagement
Integrated SystemNetworkElement
Manager SoftwareDefinedNetwork VirtualMachinenetwork stateautomation Multitenantaware NetworkHypervisor
Automated
Singlemanagedstackedswitch
21
Thank You !
22
Backups
Automatingcoordinationoflayer2state IBMDVS5000voverview Examplesofsomeofthevalues associatedwithDOVETechnology
Multitenancy Efficiency
SummaryofTechnologyTrends
23
Automated Virtualization
vSwitch 4
VSI Discovery and Configuration Protocol (VDP)
Network Admin
0
VSI Manager
Database
1 Create set of
Virtual Port Profiles
L2 net(s)
24
Automated Virtualization
IBMDVS5000VCapabilities
IBM DVS 5000v Internal External
IBM
VM-VM Virtual Switching Mode Virtual Switch Provider IBM Flexibility to use a mix of internal Yes and external switching modes Eliminates the need to manage the o No virtual switch
Yes
Standard based IEEE 802.1 de-facto IEEE 802.1 de-facto version 0 VEPA & VDP network virtualization coordination version 0 VEPA & VDP Requires new hardware No Sophisticated switch attributes Yes (e.g. ACLs, QoS) A. Internal Yes Automated Switch migration of port B. External profiles Yes Switches Cross Data Center VM migration
No Yes (External switchs)
N/A
Yes - With external switch that supports Qbg
25
Automated Virtualization
ImprovingNetworkingEfficiencyfor ConsolidatedServers
Layer-3 Layer-2 Distributed vSwitch
APP APP HTTP A Virtual Machine
Site
vAppliance 10.0.5.7 10.0.5.4 00:23:45:67:00:04 APP 00:23:45:67:00:14 10.0.5.1 10.0.5.5 00:23:45:67:00:01 APP 00:23:45:67:00:15 10.0.0.42 10.0.3.6 00:23:45:67:00:25 Database 00:23:45:67:00:16 Server
Layer-3
HTTP HTTP
Appliance (e.g.IPS)
vAppliance
TosolvethisissuerequirescrosssubnetcommunicationsinHypervisorsvSwitch.
26
Automated Virtualization
MultiTenantwith OverlappingAddressSpaces
vAppliance
A Virtual Machine
Site
HOST
10.0.3.1 00:23:45:67:00:01
Database
Site
10.0.5.7 00:23:45:67:00:04 APP 10.0.3.1 00:23:45:67:00:01 HTTP 10.0.0.4 00:23:45:67:00:25 Database HTTP Server 10.0.3.42 00:23:45:67:00:01
vAppliance
Multitenant,CloudenvironmentsrequiremultipleIPaddressspaces withinthesameserver,withinaDataCenterandacrossDataCenters(seeabove).
Layer3DistributedOverlayVirtualEthernet(DOVE)switchesenable multitenancyallthewayintotheServer/Hypervisor, withoverlappingIPAddressspacesfortheVirtualMachines.
27