SlideShare ist ein Scribd-Unternehmen logo
1 von 57
NETWORKING FIELD DAY 13
November 17th, 2016
David Erickson, PhD
CEO & Co-Founder
AGENDA
+ An Introduction to Forward Networks
+ Platform Demo
+ Use Case: Outage Diagnosis & Resolution
+ Use Case: Network Auditing
+ Closed Session
Today’s Networks – Large, Complex, &
Heterogeneous
+ IPv4 routes
+ ACLs
+ MAC tables
+ Spanning tree
+ NAT
+ VLAN
+ Multicast
+ PBR
+ Cisco
+ Arista
+ HPE
+ Fortinet
+ Juniper
+ F5
+ Palo Alto
+ Checkpoint
Thousands of devices Millions of rules Dozens of vendors
Switches Routers
Load balancers Firewalls
Manual Operations Inadequate Tooling High Rate of Error
+ Device-by-device management
+ Limited end-to-end visibility
+ Hard to debug & test
+ Lack of innovation in tooling
+ Solutions are 20+years old
+ Ping, traceroute, SNMP, etc.
+ Networks rife with misconfiguration
+ 80% of outages caused by error1
+ 50% due to change config issues2
1&2
Network Operations – Manual & Error
Prone
Business Impacting Expensive to Repair Brand-Damaging
Networks Failures & Data Center
Outages
$
NETWORK ASSURANCE
Reducing the complexity of networks while eliminating the human
error, misconfiguration, and policy violations that lead to outages.
Unorganized real world
data
Own data model of real
world
Apps on top using data
model
Revolutionary algorithm
SEARCH VERIFY APIPREDICT
A NEW APPROACH TO NETWORK OPERATIONS
Unorganized real world
data
Own data model of real
world
Apps on top using data
model
Revolutionary algorithm
SEARCH VERIFY APIPREDICT
THE FORWARD
PLATFORM
A NEW APPROACH TO NETWORK OPERATIONS
SEARCH VERIFY PREDICT
THE FORWARD PLATFORM
CAPABILITIES OVERVIEW
What is my network’s
behavior?
Index your network and search
your devices and behavior on top
of an interactive topology
SEARCH
Is it doing what it should?
Validate network correctness and
audit your network for compliance
& security
VERIFY
Will this change work?
Simulate configuration changes to
ensure they are correct and secure
before rolling into production
PREDICT
THE FORWARD PLATFORM
CAPABILITIES OVERVIEW
Customer Network
Forward
Applications
PLATFORM ARCHITECTURE
PLATFORM DEMO
Brandon Heller, PhD
CTO & Co-Founder
- Interface Counters
- Flow Counters (NetFlow)
- Sampled Counters (sFlow)
- Probes (Ping, Traceroute)
+ Packet In -> Packet Out
(and all details)
(for any packet, seen or not)
Observed Traffic All Potential Traffic
What we don’t do What we do
USE CASE
Network Outage and Resolution
Behram Mistree, PhD
Product Engineer
NETWORK
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
NETWORK
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
ROBUST CONNECTIVITY BETWEEN CLIENT AND SERVER
WANTED
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
REQUIREMENTS
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
REQUIREMENTS
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
REQUIREMENTS
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
REQUIREMENTS
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
IS YOUR NETWORK
WORKING?
Traditional
Approach
FORWARD
VERIFY™
IS YOUR NETWORK
WORKING?
TRADITIONAL APPROACH
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
Traditional Approach
FORWARD VERIFY™
ping 18.10.11.2 show route show lacp interfaces
IS YOUR NETWORK
WORKING?
Traffic can flow Multiple paths Port channels
FORWARD VERIFY™
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
Traditional Approach
FORWARD VERIFY™
ping 18.10.11.2 show route show lacp interfaces
IS YOUR NETWORK
WORKING?
Traffic can flow Multiple paths Port channels
REQUIREMENTS
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
1. Traffic should flow from CLIENT to SERVER
2. Traffic should take multiple paths from CLIENT to SERVER
3. Traffic should flow on all interfaces in a port channel
REPLACE INTERFACE ON
LAX
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
REPLACE INTERFACE ON
LAX
CLIENT SJCCE
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
SEA
1. Set ISIS overload bit
REPLACE INTERFACE ON
LAX
1. Set ISIS overload bit
2. Replace line card
CLIENT SJCCE
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
SEA
REPLACE INTERFACE ON
LAX
1. Set ISIS overload bit
2. Replace line card
3. Verify
CLIENT SJCCE
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
SEA
VERIFICATION COMPARISION
Traditional
Approach
FORWARD
VERIFY™
1. Check port channel
up
1. Single button press
2. Ping LAX to SERVER 3. Ping LAX to CLIENT
TRANSIT TRAFFIC
DISALLOWED
TRANSIT TRAFFIC
DISALLOWED
✔ Fixed
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
Latent
misconfiguration
Traditional Approach
FORWARD VERIFY™
VERIFICATION COMPARISION
Traditional Approach
FORWARD VERIFY™
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
VERIFICATION COMPARISION
Latent
misconfiguration
Traditional Approach
FORWARD VERIFY™
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
CLIENT SJCCE
SEA
LAX MIA
LGA
IAD SERVER
(18.10.11.2)
VERIFICATION COMPARISION
Latent
misconfiguration
FORWARD VERIFY™
PREVENTS OUTAGES
Instantly see failing checks during service window
Fix network issues as soon as they appear
SIMPLIFIES DIAGNOSIS
Using historical snapshots, we could reconstruct
where traffic was going, what had changed, and why
USE CASE
Network Audit
Behram Mistree, PhD
Product Engineer
FORWARD’S MISSION
We want to help you build networks that work and
that you can trust because you’ve verified them
FORWARD VERIFY™
PREDEFINE
D
CHECKS
AUDITING WITH PREDEFINED CHECKS LEADS TO SAFER
NETWORKS
AUDITING WITH PREDEFINED CHECKS LEADS TO SAFER
NETWORKS
CLASSIC DC SPINE LEAF
CLASSIC DC
“UPTIME BANK” SERVERS
Peer
Core
Aggregation
Access
CVE-2016-7810XXX
CVE-ID CVE-2016-7810XXX
DATE 20161117
REFERENCES http://example.com
DESCRIPTION
CVE-2016-7810XXX
CVE-ID CVE-2016-7810XXX
DATE 20161117
REFERENCES http://example.com
DESCRIPTION Your switch has a massive security vulnerability
CLASSIC DC
“UPTIME BANK” SERVERS
Peer
Core
Aggregation
Access
Both need upgrade
CLASSIC DC
“UPTIME BANK” SERVERS
Peer
Core
Aggregation
Access
AGG-1-
0
AGG-1-1
ACC-1-
1
VRR
P
LIVE DEMO
WHAT’S HAPPENING
“UPTIME BANK” SERVERS
Server Down?
Interfaces Down?
Spanning Tree?
Guesswork starts
AGG-1-
0
AGG-1-1
ACC-1-
1
IGP Issues?
Peering Issue?
Application Down?
“I don’t know!”
VRR
P
AUDITING WITH PREDEFINED CHECKS LEADS TO SAFER
NETWORKS
CLASSIC DC SPINE LEAF
Peer
Border
Spine
Leaf
SPINE LEAF
SPINE-1
LEAF-
1
SPINE-0
SPINE LEAF
Peer
Border
Spine
Leaf
“UPTIME BANK” SERVERS
SPINE-1
LEAF-
1
SPINE-0
SPINE LEAF
Peer
Border
Spine
Leaf
“UPTIME BANK” SERVERS
Needs reboot to
install firmware
AUDITING WITH PREDEFINED CHECKS LEADS TO SAFER
NETWORKS
TODAY FORWARD VERIFY™
VLAN Consistency ✘outage ✔ prevents outage
MTU Consistency ✘outage ✔ prevents outage
AUDITING WITH PREDEFINED CHECKS LEADS TO SAFER
NETWORKS
TODAY FORWARD VERIFY™
VLAN Consistency ✘outage ✔ prevents outage
MTU Consistency ✘outage ✔ prevents outage
Duplex Consistency ✘outage ✔ prevents outage
Link Speed Consistency ✘outage ✔ prevents outage
No Forwarding Loop ✘outage ✔ prevents outage
Port Channel Consistency ✘outage ✔ prevents outage
Shortest Path ✘outage ✔ prevents outage
Trunk Whitelist ✘outage ✔ prevents outage
IP Address Uniqueness ✘outage ✔ prevents outage
VLAN Existence ✘outage ✔ prevents outage
I WILL NEVER TRUST A NETWORK …
There is no such thing as a network that
works, just a network that hasn’t broken yet
www.forwardnetworks.com @fwdnetworks

Weitere ähnliche Inhalte

Was ist angesagt?

Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
ozkan01
 

Was ist angesagt? (20)

Securing the LAN Best practices to secure the wired access network
Securing the LAN Best practices to secure the wired access networkSecuring the LAN Best practices to secure the wired access network
Securing the LAN Best practices to secure the wired access network
 
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
 
Aruba mobility access switch useful commands v2
Aruba mobility access switch useful commands v2Aruba mobility access switch useful commands v2
Aruba mobility access switch useful commands v2
 
APIC-EM API Deep Dive
APIC-EM API Deep DiveAPIC-EM API Deep Dive
APIC-EM API Deep Dive
 
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Evolve IT: Why Performance Matters When Building Your New SD-WAN, Not all SD-...
Evolve IT: Why Performance Matters When Building Your New SD-WAN, Not all SD-...Evolve IT: Why Performance Matters When Building Your New SD-WAN, Not all SD-...
Evolve IT: Why Performance Matters When Building Your New SD-WAN, Not all SD-...
 
Software Defined WAN – SD-WAN
Software Defined WAN – SD-WANSoftware Defined WAN – SD-WAN
Software Defined WAN – SD-WAN
 
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice ConfigurationEMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
 
SD-WAN for Service Providers - VeloCloud
SD-WAN for Service Providers - VeloCloudSD-WAN for Service Providers - VeloCloud
SD-WAN for Service Providers - VeloCloud
 
Take a Walk on the Wired Side
Take a Walk on the Wired SideTake a Walk on the Wired Side
Take a Walk on the Wired Side
 
Benefits of disaggregation and open source networking in data centers
Benefits of disaggregation and open source networking in data centersBenefits of disaggregation and open source networking in data centers
Benefits of disaggregation and open source networking in data centers
 
A consolidated virtualization approach to deploying distributed cloud networks
A consolidated virtualization approach to deploying distributed cloud networksA consolidated virtualization approach to deploying distributed cloud networks
A consolidated virtualization approach to deploying distributed cloud networks
 
Verizon Managed SD-WAN with Cisco IWAN
Verizon Managed SD-WAN with Cisco IWAN Verizon Managed SD-WAN with Cisco IWAN
Verizon Managed SD-WAN with Cisco IWAN
 
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Configuring different APIs  in Aruba 8.x EMEA Airheads - Configuring different APIs  in Aruba 8.x
EMEA Airheads - Configuring different APIs in Aruba 8.x
 
Extending mobility to remote networks with aruba instant, remote APs, and clo...
Extending mobility to remote networks with aruba instant, remote APs, and clo...Extending mobility to remote networks with aruba instant, remote APs, and clo...
Extending mobility to remote networks with aruba instant, remote APs, and clo...
 
ClearPass 6.3.6 Release Notes
ClearPass 6.3.6 Release NotesClearPass 6.3.6 Release Notes
ClearPass 6.3.6 Release Notes
 
Getting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement FirewallGetting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement Firewall
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
 
EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments
EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deploymentsEMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments
EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments
 
Aruba Campus Wireless Networks
Aruba Campus Wireless NetworksAruba Campus Wireless Networks
Aruba Campus Wireless Networks
 

Ähnlich wie Forward Networks - Networking Field Day 13 presentation

Integrate steelhead into iwan
Integrate steelhead into iwanIntegrate steelhead into iwan
Integrate steelhead into iwan
luis2203
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
nvirters
 

Ähnlich wie Forward Networks - Networking Field Day 13 presentation (20)

Smart networking with service meshes
Smart networking with service meshes  Smart networking with service meshes
Smart networking with service meshes
 
Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...
 
Выявление и локализация проблем в сети с помощью инструментов Riverbed
Выявление и локализация проблем в сети с помощью инструментов RiverbedВыявление и локализация проблем в сети с помощью инструментов Riverbed
Выявление и локализация проблем в сети с помощью инструментов Riverbed
 
ENSURING FAST AND SECURE GAMING APPLICATION DOWNLOADS GLOBALLY
ENSURING FAST AND SECURE GAMING APPLICATION DOWNLOADS GLOBALLYENSURING FAST AND SECURE GAMING APPLICATION DOWNLOADS GLOBALLY
ENSURING FAST AND SECURE GAMING APPLICATION DOWNLOADS GLOBALLY
 
Dynamic Service Chaining
Dynamic Service Chaining Dynamic Service Chaining
Dynamic Service Chaining
 
21st Docker Switzerland Meetup - ISTIO
21st Docker Switzerland Meetup - ISTIO21st Docker Switzerland Meetup - ISTIO
21st Docker Switzerland Meetup - ISTIO
 
Mini-Track: Lessons from Public Cloud
Mini-Track: Lessons from Public CloudMini-Track: Lessons from Public Cloud
Mini-Track: Lessons from Public Cloud
 
Integrate steelhead into iwan
Integrate steelhead into iwanIntegrate steelhead into iwan
Integrate steelhead into iwan
 
Explore Advanced CA Release Automation Configuration Topics
Explore Advanced CA Release Automation Configuration TopicsExplore Advanced CA Release Automation Configuration Topics
Explore Advanced CA Release Automation Configuration Topics
 
Active network
Active networkActive network
Active network
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
Cisco connect winnipeg 2018 a look at network assurance in dna center
Cisco connect winnipeg 2018   a look at network assurance in dna centerCisco connect winnipeg 2018   a look at network assurance in dna center
Cisco connect winnipeg 2018 a look at network assurance in dna center
 
RGNet Ver.1.0.pptx
RGNet Ver.1.0.pptxRGNet Ver.1.0.pptx
RGNet Ver.1.0.pptx
 
Using Istio to Secure & Monitor Your Services
Using Istio to Secure & Monitor Your ServicesUsing Istio to Secure & Monitor Your Services
Using Istio to Secure & Monitor Your Services
 
Technology Primer: Software-Defined Networking and Its Impact on Infrastructu...
Technology Primer: Software-Defined Networking and Its Impact on Infrastructu...Technology Primer: Software-Defined Networking and Its Impact on Infrastructu...
Technology Primer: Software-Defined Networking and Its Impact on Infrastructu...
 
OVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
OVNC 2015-Enabling Software-Defined Transformation of Service Provider NetworksOVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
OVNC 2015-Enabling Software-Defined Transformation of Service Provider Networks
 
Rudder 3.0 and beyond
Rudder 3.0 and beyondRudder 3.0 and beyond
Rudder 3.0 and beyond
 
OpenFlow: What is it Good For?
OpenFlow: What is it Good For? OpenFlow: What is it Good For?
OpenFlow: What is it Good For?
 
Innovation in SDN Tools and Platforms
Innovation in SDN Tools and PlatformsInnovation in SDN Tools and Platforms
Innovation in SDN Tools and Platforms
 
Top Performance Problems in Distributed Architectures
Top Performance Problems in Distributed ArchitecturesTop Performance Problems in Distributed Architectures
Top Performance Problems in Distributed Architectures
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Kürzlich hochgeladen (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

Forward Networks - Networking Field Day 13 presentation

Hinweis der Redaktion

  1. OPTION 1
  2. The main reason nobody has gone down this path is because it’s incredibly difficult. The first problem is building models, and this is an enormous grind, because there’s an enormous legacy tail of devices and versions. Then, you have to support all the new versions that come out, quickly. We’ve addressed this by investing heavily in automating our testing pipeline and growing the team by outsourcing. The second problem is figuring out how to scale network analysis so that it’s fast for any kind of network, on modest hardware. This is yet another grind, and we have about 12 person-years of PhD-level work put into this. And once you grind through both of those problems, you’ve still got to figure out an interface that makes complex data understandable. You can only solve this by iterating with the users, and we’re on our fourth iteration .
  3. The main reason nobody has gone down this path is because it’s incredibly difficult. The first problem is building models, and this is an enormous grind, because there’s an enormous legacy tail of devices and versions. Then, you have to support all the new versions that come out, quickly. We’ve addressed this by investing heavily in automating our testing pipeline and growing the team by outsourcing. The second problem is figuring out how to scale network analysis so that it’s fast for any kind of network, on modest hardware. This is yet another grind, and we have about 12 person-years of PhD-level work put into this. And once you grind through both of those problems, you’ve still got to figure out an interface that makes complex data understandable. You can only solve this by iterating with the users, and we’re on our fourth iteration .
  4. The main reason nobody has gone down this path is because it’s incredibly difficult. The first problem is building models, and this is an enormous grind, because there’s an enormous legacy tail of devices and versions. Then, you have to support all the new versions that come out, quickly. We’ve addressed this by investing heavily in automating our testing pipeline and growing the team by outsourcing. The second problem is figuring out how to scale network analysis so that it’s fast for any kind of network, on modest hardware. This is yet another grind, and we have about 12 person-years of PhD-level work put into this. And once you grind through both of those problems, you’ve still got to figure out an interface that makes complex data understandable. You can only solve this by iterating with the users, and we’re on our fourth iteration .
  5. So how is Forward Networks addressing these challenges. To begin with, we learned from the leader in a different space, that also had similar challenges, Google. So what did they do. -First they built a crawler to go and collect all the web data that they possibly could -Second they parsed all of this data and created their own internal copy of the web -Third they applied their revolutionary algorithm named Page Rank that amazing user experiences with a variety of applications on top such as -Search, Maps, Contacts, etc, etc, etc Summary: Google revoultionized the user experience of search by gathering *all* the data, applying smart algorithms to it, then putting a slick UI in front. We have taken a similar path to revolutionize network operations. -First we collect both configuration, and dynamic runtime state from all devices in the network (switches, routers, load balancers, firewalls, etc) -We bring that data centrally, and for every device we use our revolutionary algorithms (originally called Header Space Analysis) to precisely model how it will behave for any packet it receives, given the current configuration and state. So effectively we have an entire copy of your network, in software. -On top of that copy of your network we use our algorithms to trace through that copy of your network where every possible packet could go, then we put that in a database, and it is the core of our data. This is unique to Forward Networks, nobody else has this level of data about the network. -Collectively we call this the Forward Platform. -On top we we add applications that utilize this data to present experiences that solve the problems mentioned earlier.
  6. OPTION 1
  7. It’s all potential traffic.  We’ve traced through every possible path that traffic could take.  So for any packet of your choice, you can see what will happen to it.  You can see if it’ll get dropped, or if it passes through, and how it’s changed.  You can see everything relevant to the story of any potential packet.  What makes this model powerful is that we can reason about packets the network has not even seen. Note what is not covered in the model. We don’t look at interface counters. We don’t look at flow counters.   We don’t look at sampled counters. We don’t look at probes.
  8. Hi, I’m Behram Mistree. And I’m going to be doing a couple of live demos of Forward Verify, and hopefully showing you that it’s going to make your lives easier and solve a bunch of your problems. So, before all of you got here, we talked to customers We talked to network engineers We did a lot of reading We did a lot of testing And what we were looking for were good examples of outages. We wanted those outages to be: * Nasty * Potentially catastrophic * Real
  9. And that’s what this is. A network and a set of steps that caused an outage in the network. Now let’s not focus on the details of the outage here in the bottom left corner. We’ll get into that in a bit. Let’s just take a look at the network itself.
  10. To answer this fundamentally important question: Is my network working? I had a network engineer * Log into a bunch of boxes * Run a bunch of commands * Parse their output and * Get back to me Now, let’s look at another way.
  11. Before I had to log into all these boxes, execute a bunch of commands. Now, I just press a single button, and get the answer whenever I want. Now let’s bubble up a minute about what that means for a second.
  12. Every day, you’re betting your business on this. You’re betting your business on having skilled network engineers that know: * What it means for your network to be working * That know how to log into these boxes, run their commands, and verify that they’re working * And that those engineers have the time and capacity to do that frequently enough that you’re going to catch important issues early and before they cascade. And for the rest of this talk. I’m going to show you how that bet can go wrong, and what happens when it does.
  13. In the previous demo, we saw how Forward Verify could have prevented an outage. We’re going to continue on with that them in this demo by focusing on one component of the entire Forward Verify experience, called Predefined Checks.