Confidential Built-in network drivers Driver Model Bridge Host-only bridge NAT to expose services Host Host network namespaces All containers use same interfaces Overlay VXLAN encapsulation Docker control plane MACVLAN IP per container No NAT, No encapsulation
PROFILE Contract Contract Contract OUTSIDE DB APP WEB ADC F/W ADC What is a group policy? An API to capture user intent Group: A set of VMs / servers with the same policy 1. Contracts: A set of rules governing communication between groups 2. Service Chains: A set of network services between groups 3.
Confidential Contiv Network Integration Choices Cloud L2+ L3 Native L3 EVPN Overlays Cisco ACI Every Container needs external access No Additional IPs As many IPs As many IPs As many IPs As many IPs Scale (#Containers) Very High High Very High High Very High Multi-Destination Traffic No Yes No No Yes Performance (throughput/latency) Not Good Very Good Good Not Good (Host VTEP) Leaf VTEP is good Very good Automated Multi-tenancy Yes No No Yes Yes Ease of External Access Not Good Good Good Good Good Greenfield Deployment Not Good OK Good Good Good Scale (#Nodes) OK Not Good Very Good Will need BGP RR Very Good Favorable Physical Topology All Look Same Access/Agg regation L3 CLOS L3 Underlay + VXLAN overlay ACI 26 TECDCT-2020
Confidential • Use the network model that suits the infrastructure • Contiv provides flexibility on the network side with consistency on the application side • References: • https://github.com/contiv/netplugin • https://github.com/contiv/install Summary