SDN без OpenFlow
Подход Extreme Networks к программно-конфигурируемым сетям
Примеры работы приложений в рамках концепции SDN
Новый контроллер SDN Extreme OneController
Новые возможности использования приложений в сетях SDN
Максим Игуменов – системный инженер Extreme Networks, «Примеры работающих приложений в рамках концепции SDN»
1. Подробно об SDN: интеграция
с реальными приложениями
Extreme Networks / System Engineering
2. if this then that
Триггер Действие
Правило
Данные Данные
Зачем нам Software Defined Networking?
3. Если письмо приходит
с вложением PPT,
сохранить на Google
Drive
Если акции достигнут
определенной цены, послать
мне сообщение
Если я подъезжаю к дому,
открыть гараж, установить
температуру в доме на 20,
включить свет
Если я посылаю сообщение #SOS
позвонить на определенный
телефон
6. Экосистема партнеров Extreme Networks
IT Operations
&
Convergence
Data Center
Security
Management
& Analytics
Mobility
SDN base
Extreme
SDN
Ecosystem
Certified
Interoperable
Integrated
8. NextGen Firewall
Преимущества
• Динамическая привязка User ID
к IP и МАС адресам позволяет
определять пользователя на
всех этапах подключения и
передавать эту информацию в
Palo Alto
• Политики безопасности
применяются точечно, как
можно ближе к пользователю,
не затрагивая другие участки
сети
• Динамические политики и
полная информация в отчетах
9. Mobile Device Management
Преимущества
• Принудительная регистрация в
MDM, пользователь должен быть
зарегистрирован в MDM/NAC,
прежде чем получит доступ
• Обнаружение и изоляция
зараженных и опасных устройств,
запрет использования устройств с
jail-break
• Дополнительная информация для
NAC из MDM (IMSI, IMEI и др.)
• Возможность управления
неуправляемыми устройствами
10. Web-фильтрация
Преимущества
• Прозрачная аутентификация
• Динамическое присвоение групп iBoss
и политик, в зависимости от времени и
местоположения
• Информация о пользователях, типах
устройств, типах подключений в
реальном времени
• Подробные отчеты в OneView обо всех
активностях пользователей, их
устройствах, используемой
пропускной способности
11. Управление облачными сервисами
Control Center
(Объединенное управление и безопасность)
Я хочу создать новую
конфигурацию сети, с
настройками для vnetworks,
и vswitches в один клик!!
Создать конфигурацию и
синхронизировать с VMware
Создать vPorts,
названия сетей,
применить к
серверам.Старый способ – недели
Новый способ – минуты!
VM Management
(напр. Vmware)
13. Выборка и исследование любого потока
Использование OpenFlow и
OneController для отправки
первых N-пакетов любого
потока в Purview (или в любой
другой DPI)
Возможность наблюдать
любые потоки приложений в
любой OpenFlow сети
Результаты выводятся в
OneView
14. Traffic Engineering
Развитие реализованной интеграции с
Microsoft Lync (Skype for business)
Особенности
• Работает на любой инфраструктуре с
поддержкой OpenFlow
• Работает в беспроводных сетях
• Управление всем потоком, а не простое
вклчение ACL
• Динамическое изменение поведения
сети во время звонка
• Комбинация динамических ACL с
общими политиками
15. Управление облачным ЦОД
Особенности:
• Один и только один инструмент для
управления с доступом из единого окна
• Компонент OpenStack Orchestrator,
управляющий инфраструктурой
вычислений, хранения и сети ЦОД
• OpenStack передает все функции настройки
сети компоненту решения Extreme Networks
OneController.
• OneController использует приложение
Virtual Tenant Network (VTN) для управления
сетью в условиях облачного доступа
(множество изолированных пользователей),
которое также управляет «растягиванием»
сетей в условиях распределенных ЦОД
16. Компоненты управления для OpenDaylight
Улучшенный контроль
• Использует преимущества OneView для объединения
информации об устройствах, пользователях, сетях,
производительности и топологии
• Ускорение поиска и устранения неисправностей
• Снижение операционных затрат
• Повышение безопасности
Использование преимуществ NAC для дальнейшего
развития идеи использования Group-Based Policy
21. Расширения для Wi-Fi
Wireless
Редактор политик (Policy In)
WLAN
контроллер
ТД
ТД
ТД
Extr_MSG (Events)
Extr_MSG (Rule = Classifier, Action)
Extr_MSG (Endpoints, Groups)
Запрос
Политики
22. Преимущества Extreme SDN
• Производительность – оптимизация сети под
конкретные нужды приложений, высвобождение
пропускной способности, быстрое
развертывание сервисов
• Безопасность – защита на лету, в реальном
времени, с учетом полного контекста
пользователей, устройств, приложений и т.д.
• Единый инструмент управления – единое
окошко для любых действий
• Контроль и прозрачность сети – наличие
детальной и аккуратной информации обо всем,
что происходит, всегда
• Защита инвестиций – работа с любыми
вендорами
• Нам можно доверять – многолетняя история
развития SDN, четкий и понятный roadmap по
развитию функций SDN, ориентация на
открытые стандарты и технологии
Over the next couple slides we have some animated builds that help to ‘humanize’ what SDN means and what the market transition is all about.
We start on this slide by defining a simple concept: that of a design paradigm of “if this then that” – the notion that a more sophisticated, more dynamic model of behavior is what folks are starting to expect from technology.
In this model, real time triggers lead to dynamic actions and create a richer user experience that is more customized to the consumer than a static or rigid type model.
The purpose of this slide is to illustrate the IFTT trend and how it impacted something that we can all understand: cellular communications.
If you went back 10-15 years ago, cellular was about voice traffic. Going into the “smart phone” era, everyone thought of them as maybe also having messaging, e-mail and possibly web access.
The emergency of platforms, iOS and Android have created a new paradigm and lead to the enablement of new innovation and value created on top of the once exclusively ‘mobile voice’ experience.
Today, its expected that a dynamic set of services are available. These services interact at the phone level, but also in the cloud to create this richer experience that his highly tailored and much more personal.
So, what does this have to do with SDN?
And now consider how the “IFTTT” work might impact how network services are consumed in this new paradigm. Its highly dynamic and much more personal or tailed to the experience of a user, device or service than what we can achieve using traditional networking tools that really only apply to how packets flow between network devices.
Remember that the networking industry is at the same point in time as just before “smart phones” were deployed in the cellular industry. No one really knows what services and capabilities will be created on these new SDN platforms. We do know that SDN is a disruptive technology, a paradigm changer and will lead to unprecedented new innovation and value creation. This is what has got everyone so excited and scared at the same time.
At Extreme, we are playing the role of the market disrupter. We are engaged in becoming a change agent. We are building an SDN platform not unlike iOS or Android. This is a game changer for the networking industry.
SDN is not new. Its been around for some time now. In the early stages, most companies followed one of two architectural paradigms: Ether requiring a proprietary protocol and new boxes (green field) like OpenFlow or being build on vendor specific API’s like our “Extreme Policy” or “ACI”. Both of these models don’t provide what the market really wants.
At Extreme, we are pushing for a much more open and flexible model as shown on the right. In this model, we embrace greenfield, brownfield and multi-vendor networks not with any one API but a bunch of them. We are basing our architecture on OpenDaylight (ODL) which has this model that allows south bound, vendor specific API’s to be plugged into the bottom of the controller so that a collection of heterogeneous network devices suddenly look like a homogeneous network. That convergence happens in the middle of the controller.
On the north bound side of the controller, we have industry driven, multi-vendor supported API’s. This model, for the first time, will create a marketplace large enough (everyone’s switch having a common set of API’s) that we will be able to attract and create a sustainable application ecosystem. This will be a game changer and disruptive technology for the networking industry.
User logs into the network over wired or wireless
NetSight/ NAC applies config and vlan to user
NetSight/ NAC informs FW of connected user so FW can apply policy
FW monitors external user activity
FW notifies NetSight/ NAC of suspicious User activity and blocks external access
NetSight/ NAC blocks internal user traffic
Requirements
Software - Extreme
Extreme Networks NetSight 6.1 or above with Advanced License
Extreme Networks NAC 6.1 or above
Extreme Networks OneFabric Connect Software
Hardware
Any RFC3580 switch that can support at least MAC authentication (requires Kerberos or Web Registration via NAC), Kerberos Snooping or better 802.1x authentication
Services
PS-OFCONNECTREMOTE Remote installation of the OneFabric Connect
PS-OF-Connect-ESU On-Site installation of the Enterasys OneFabric Connect
We have integrations with MDM solutions today. In a BYOD world, coordinating on-boarding of users with an MDM solutions simplifies the provisioning process. In this integration, we translate the MDM authority to join a network into specific policy for the BYOD device within the enterprise network.
In addition to MDM and firewall integrations, we have integrations with identity management systems such as iBoss that allow identity to be coordinated between the systems. MDM is concerned with device authentication, firewalls deal with addresses and applications and this solution deals with user identity.
This experimental capability enables a network administrator to take an application flow for ‘inspection’ via NetSight. After doing so, OneController is directed to lay down OpenFlow rules on the switches associated with the flow and direct packets to the manager so that the administration can have visibility into what’s going on in that session, in real time. Flow probing is completely dynamic and will work with most OpenFlow capable switches. We’ve validated the functionality for EXOS and with OpenVSwitch (OVS.)
The following chart illustrates how the flow programming works. Think of this as a dynamic virtual tap onto a live flow in progress.
In this experimental capability we extend our MicroSoft Lync integration to include OpenFlow capable switches that we can program via the OneController.
Today we have commercial data center orchestration integrations for MicroSoft, Citrix and vmWare. Through OneController we add experimental support for OpenStack integration utilizing the VTN (Virtual Tennant Network) API set. VTN programs VLANs to achieve tenant isolation within a data center.
Solution Benefits
Provide orchestration of compute, storage and network
Faster deployment of new services and applications
Multi tenant cloud style data center design
CAPEX and OPEX savings through convergence
Automate service provisioning and VM mobility
On top of a Layer 3 infrastructure
Scalable network infrastructure
Intelligent Data Center Interconnect
Enable DR and active/active DC designs
Pooling of Compute and Storage resources across the entire IT infrastructure
Optimized CAPEX
Higher application availability
The OpenDaylight community does not support or provide for a network management platform. With this release of the platform we have added a number of management features to NetSight for the platform. One of those addresses a shortcoming of the ODL platform, that is visibility into more than just port/mac address for a host on the network.
Here, we’ve added experimental visibility into the host tracker information provided by the OneController platform.
Use Case
Provide a application (L7) detection and application based policy enforcement solution
True application control, quality of service and potential traffic management
Can be leveraged to insert other services like DPI, IDS etc in a similar fashion
Supports any OpenFlow capable network element
Purview Application Detection “everywhere” possible
Physical and virtual (OVS) network elements supported
Benefit
Deploy Purview in 3rd party and virtual environments to provide application visibility and control
for incursion strategy and investment protection
Protoype and limited scale provides upsell opportunities to Purview with CoreFlow2
Virtualized services like DPI, IDS etc are more cost effective and can be easily inserted with the same basic solution
Cost savings and reduced deployment complexity
Establish our credibility
Extreme is a pioneer in Software Defined Networking architectures with patents dating back to the 1990s (US patents 5790546 & 5485455 ) for flow-based architectures that have been performing SDN-like functions for years.
This investment in flow technology has resulted in a deep understanding of the architectures and development requirements represented by SDN.
In June of 2012 we embraced OpenFlow by announcing that we will support OpenFlow throughout our portfolio of XOS switches. We also announced plug-in for the OpenStack and fostered SDN development community In Feb of 2013 we delivred on that promise with XOS 15.3 which included support for OpenFlow and also an OpenStack plugin providing a rich API for EXOS
Then in May of 2013, we officially launched OF Connect SDN which provided Northbound API and several precanned applications for Data Center and Wireless Campus. This product has been widely deployed by several customers around the globe.
Evolve your organization: establish cross functional team(s) for SDN – network, applications, systems, security – to drive and articulate requirements, use cases
Get more software, interface and development expertise
Validate your partner and vendor relationships as it relates to SDN strategy and knowledge
Establish a SDN test kitchen, lab to validate assumptions and use cases