Network Architect/Engineer ‣ Did I mention you can rent me ? ‣ Blog - EtherealMind.com ‣ NetworkComputing.com (http://networkcomputing.com/blogs/author/Greg-Ferro) ‣ Slides: speakerdeck.com/etherealmind
SYSTEM ‣ every element is interconnected to another in the LAN or WAN or both ‣ Rebooting a device might/could take down the whole network ‣ If rebooting or reconfiguring a server could cause the entire DC to fail, what would your job look like ?
Network Servers, Storage, VMware Apps Impact Pyramid ‣ Which failure class causes the greatest impact ? ‣ A user ? ‣ One server ? ‣ A VMware cluster ? ‣ A storage array ? ‣ A Network ? ‣ A Data Centre
executives that network is bigger than VMware ....... ‣ “vCDNI means that you never have to talk to the network guy ever again” VMworld 2010 (faceless executive butthead) ‣ “Meanwhile, through all of the advances in server virtualization and cloud computing, networking has remained stuck in the past.” - Hatem Naguib, Vice President, Networking & Security - Mar 13, 2013 ‣ Servers connect to Clients ‣ Network is a platform. ‣ VMware is just one “network app”. ‣ take some time to look down the service chain instead of up your own arse
Virtual Routing in 2002/3 (MPLS) ‣ Virtual Network Appliances (firewalls, load balancers) in 2007/8 ‣ “Lets do it again” say bitter, cynical networking voices of experience ‣ Virtual Networking is OLD networking
Data Centre Network ‣ Sporadic Upgrades (usually in response to problems) Time Capital Expenditure Network Install Port Capacity Network Upgrade Server Upgrades Server Upgrades Server Upgrades CapEx Waste
Complex failure ‣ Why have only one pair of firewalls ‣ routing, cost, power users ‣ Only one or two critical services need HA ‣ HA systems are inherently risky & shared fate systems. ‣ Active/Standby firewall ‣ HA in vertical scale system = $$$$ $’s SVR WAN RTR Internet RTR FWL FWL SVR SVR SVR SVR SVR SVR Stateful HA Active/Standby WAN Internet LoadBal LoadBal Stateful HA
Self-configuring and adapting ‣ Central control neither desirable or relevant ie vCenter, SCVMM/SCOPs is risky system. ‣ Resilient & Distributed Systems like the Internet work well. ‣ Data Centres are NOT distributed systems
or 16 K TCAMs ‣ 16000 MAC = 16K VMs ‣ 50 VMs per server = 320 servers ‣ Other devices are rounding errors ‣ 4000 VLANs is not enough Scalability Problem
Creation and deletion ‣ IP Subnet Creation and Deletion ‣ Occur 24/7 without change control ‣ STP, IP Routing are slow & risky ‣ even at 250 ms timers with BFD
‣ Firewalls, routers, IDS, ‣ Instead of one big one, have many smaller ones per service ‣ configure HA on a service by service basis ‣ In a cloud, unused VMs don’t consume CPU/Memory and don’t need to be overspecified
or application in my data centre ‣ radical overhaul in security posture ‣ expect bifurcation from security (love/ hate) ‣ stop using hardware. ‣ Huge operational impact ‣ Massive security improvement
“Quilted Toilet Paper” ‣ Dumb networking must automate ‣ “don’t send a human to do a robot’s job” ‣ “dumb server-ing” must automate ‣ Data Centre networking now different from “other” networking ‣ Not true before
has 32 x 40GbE ports ‣ Each port can be 4 x 10GbE with QSFP breakout for 96 x 10GbE in single switch ‣ Blade server with 8 blades uses 2 x 10GbE to each switch ‣ 20 to 1 server compression ‣ 20 VMs x 8 Blades x 48 x (2x10GbE) ‣ = 7680 virtual servers
VM VM Core Core Core Core ToR ToR ToR ToR VXLAN, NVGRE, NVO3 or MPLSoGRE FWL RTR RTR Internal VTEP VTEP vSwitch Internet SW SW Direct Hosts Server Server Legacy Hosts "Not to Scale"
VM VM VM VM VM Core Core Core Core ToR ToR pNic pNic VM VM VM VM VM VM ToR ToR pNic pNic VM VM VM VM VM VM VXLAN, NVGRE, NVO3 or MPLSoGRE FWL RTR RTR Internal OVSDB VTEP VTEP vSwitch vSwitch vSwitch Network Controller OVSDB Internet SW SW Direct Hosts Server Server Legacy Hosts
Overlay must be integrated not abstracted ‣ Could be self serving and promote legacy hardware sales ‣ Could be a serous technical reason ‣ But I doubt it, Bandwidth Always Wins
VM Agent VM VM VM VM VM VM Agent VM VM VM pServer Router Firewall VMware Hyper-V/KVM Physical vCloud Director SCCM NETWORK CONTROLLER Controller Networking of Physical And Cloud •Controller handling physical •Cisco ACI
VM Agent VM VM VM VM VM VM Agent VM VM VM pServer Router Firewall VMware Hyper-V/KVM Physical vCloud Director SCCM NETWORK CONTROLLER Overlay Functional Integration Looks Like What ? Text •Controller handling logical ? •State in the underlay ? •Why would this integration add value ?
Edge Edge Edge Grow Over Time Core Core Dist'n Dist'n Dist'n Dist'n Access Access Access Access Access Access Access Access Server Server Server Server Server 10GbE Interfaces Bare Metal / vCenter / KVM / Other Hand Cranked Server Server Server Server Server Server Server •ECMP Network designs support software overlays just fine •And connect to the conventional network
Server Physical Server Physical Server Core Core Core Core ToR ToR ToR ToR Overlay LAN 2 pNic pNic pNic pNic pNic pNic Agent Agent Agent VM VM Ethernet Fabric - "Underlay Network"
Network Architect/Engineer ‣ Available for Hire ‣ Blog - EtherealMind.com ‣ NetworkComputing.com (http://networkcomputing.com/blogs/author/Greg-Ferro) ‣ Slides: speakerdeck.com/etherealmind