10. 基础架构可靠性:网络和UCS
Nexus 7000 and Nexus 5000
Aggregation Layer Loopless Topology with vPC
Port-Channel
RPVST+
vPC
Access Layer
Unified Computing System
Fabric Availability
Control Plane Availability
Forwarding Path Availability
Blade Server Path Availability
vPC vPC vPC vPC
Nexus 1000V
A UCS 1 B A UCS 2 B Nexus 1000V
x4 x4 x4 x4 Supervisor Availability
VSM Active
(VSM)
x4 x4 x4 x4
VEM Forwarding Path
VSM Standby Availability (VEM)
x4 x4 x4 x4
x4 x4 x4 x4
11. 基础架构可靠性:VMware HA和vCenter心跳
• VMware HA
– Protection against server failure
• Configurable VM restart priority
– Protection against VM guest OS failure
• Configurable VM heartbeat monitor sensitivity
– Primary vs. Secondary Nodes
• vCenter Heartbeat
– Primary and Secondary vCenter server in
replication and synchronization
– Protection against hardware and application
failure
12. 基础架构可靠性:vMotion和Storage vMotion
• vMotion
– Continuously availability to
tenants during planned server
outages
• Zero downtime migration of
VM between servers
• Storage vMotion
– Continuously availability to
tenants during migration to
different tiers of storage
• Supports all three protocols:
NFS, iSCSI, FCP
15. 数据安全隔离
服务器 网络 存储
UCS & vSphere RBAC Access Control List vFiler units
VM Security with VLAN Segmentation IP Spaces
vShield and Nexus 1000V QoS - Classification VLAN Segmentation
UCS Resource Pool
Separation
16. 访问控制
Cloud Administrator 定义角色
云架构管理员
租赁单元管理员
NetApp MultiStore
租赁单元用户
vFiler vFiler vFiler vFiler 基于角色的访问控制
Tenant A Tenant B Tenant C Tenant D UCS Manager
Tenant B Server Admin
Network Admin
Storage Admin
Customized Admin
vCenter
Privilege Assignment
User Group Association
Permission Assignment
访问控制列表
Nexus 1000V, 5000, 7000
17. VLAN整合
VLAN Types Function Routable
Control Plane VLAN To Mange control Plane No
Management VLAN To Mange Management Yes
Engineering VLAN
Marketing VLAN To service Marketing team.
复杂
To separate for Engineering. No
Depends
HR VLAN To to service HR group. No
Data Center VLAN To separate Data Center from other places. Depends
Storage VLAN VLAN only for SAN No
Perspective VLAN组 功能 Routable
Cloud Admin Management Manage UCS, N1KV, Yes
Storage, Network Devices
Network Management & OOB
Control Connectivity across compute, network, and No
storage entities
Tenant(租赁单元) Application Admin VM and application administration Yes
Data Service the customer application. Depends
18. VM安全和vShield和Nexus 1000V
与N1KV完全集成
•Virtual Service Domain (VSD) feature
Tenant A Tenant B Tenant C leveraged by vShield to intercept VM-
destined flows
安全隔离
•Simple container-based rule creation
leveraging vCenter inventory objects
•Point of enforcement close to VM
•Policy based separation between
tenants
•Policy based separation for multi-tier
application
Protected Members of VSD
(VSD Inside)
Nexus 1000V
vMotion awareness
• vShield session state tables follow the
Unprotected VM
(VSD Outside) •Cisco VN-Link maintains VM protection
policy consistency during vMotion
Physical Adapters
19
19. 计算资源的隔离
vSphere Resource Pool Design Best Practice
Dedicated resource pools for infrastructure and tenants
Separate sub-resource pool for individual tenants
Combined with RBAC to securely isolate access between tenants
Tenant B Resource Pool
Storage Pool Interconnect Pool
Tenant A Tenant B Tenant B Resource Pool
Resource Pool Resource Pool
Tenant Resource Pool Infrastructure Resource Pool
20. NetApp Secure Multi-Tenancy
用户/应用/符合的分区隔离
Challenges
Resource utilization
MultiStore® Secure separation
Resource hogs
Customer A Customer B Customer C
Data Data Data
Secure multi-tenancy MultiStore
Secure partition of storage and
Data Data Data
networking
Data Data Data
Proven technology: 16,000 licenses
Virtual Storage Virtual Storage Virtual Storage Third-party valid security testing
Partition Partition Partition
22. 服务保证 – 交付服务级别协议(SLA)
计算
Expandable Reservation
Dynamic Resource Scheduler
UCS QoS System Classes for
Resource Reservation and Limit
网络
QoS - Classification
QoS - Queuing
2 GE
Gold
4 GE
Platinum
QoS - Bandwidth control
CoS
CoS QoS - Rate Limiting
存储
FlexShare
Storage Reservations
Med Priority High Priority
Thin Provisioning
23. 网络服务保证
Traffic Types Service-Class CoS & UCS Class • QoS – Classification
NFS Data Store/N1KV
Control &
CoS 5 Platinum
– Classification Capability
Network Management CoS 6 Gold
Management
vMotion
– Identify Traffic Types
CoS 4, Silver
Transactional CoS 5, Platinum – Classify at Source of
Front End Traffic CoS 6, Gold Origin
Bulk Data CoS 4, Silver
Application CoS 2, Bronze • QoS – Queuing
Storage IO
Back End Traffic
CoS 5, Platinum – Packet Delivery Schedule
App to App CoS 6, Gold
(multi-tier)
CoS 4, Silver • QoS - Bandwidth Control
Best Effort
Best Effort • QoS – Rate Limiting
Scavenger CoS 0 & 1, Best Effort
24. 计算资源服务保证
• 内嵌vCenter Resource Pool设置提供:
– resource guarantee for infrastructure and tenant services
• Resource pool设置基于用户所需的SLA要求:
Resource Pool Platinum Tenant Gold Silver Tenant
Settings Tenant
Reservation Reserved Reserved No reservation
Limits Unlimited Limited Limited
Shares High Medium Low
Expandable Enabled Disabled Disabled
Reservation
• VMware DRS 提供了一个ESX集群内的完全自动的跨UCS刀片的负载分配
– 在VM/vApp运行状态下
– 在稳定或不稳定的状况下
25. 存储系统服务级别协议(SLA)保证
• 可对优先应用或用户提供
Clients 高优先级访问保证
Database Server
• Five levels of prioritization
Switch
available
Platinum SLA • 隔离租赁单元性能问题,
Gold SLA 保证其它租赁单元的SLA
不受其影响
High Medium
Priority Priority
运行Flexshare软件的FAS存储系统
27. 端到端的管理
Server Layer
Unified Computing System
vCenter Server (UCS) Manager
vShield Manager
SANscreen
Network Layer
Data Center Network Manager
Flexible NetFlow SANscreen
Fabric Manager
Storage Layer
Operations Manager
Provisioning and Protection Manager
SANscreen
Service Insight
Service Assurance
Application Insight
Capacity Manager
VM Insight
28. Cisco UCS Manager
• Single point of management for UCS
GUI Custom Portal or Tools system of components
– Adapters, blades, chassis, fabric extenders,
fabric interconnects
CLI Systems Management
Software
• Embedded device manager
–Discovery, Inventory, Configuration,
Monitoring, Diagnostics, Statistics Collection
UCS Manager –Coordinated deployment to managed
endpoints
• APIs for integration with new and
existing data center infrastructure
–SMASH-CLP, IPMI, SNMP
–XML-based SDK for commercial & custom
implementations
29. Cisco Data Center Network Manager
Centralized management throughout the data
center network
Ethernet, IP routing and Network Security domain
awareness
Enables error-free provisioning
Configuration validation via syntax and semantics
checks
Health monitoring
Real-time alarms and key traffic performance
indicators
Facilitates the insertion of innovative network
features
Network virtualization transparently supported
Powerful industry-standard SOAP/XML API
Stateful network information enabling network-aware
3rd party applications
30. vCenter基础架构管理
Centralized Control and Resource Allocation Overview
Visibility Performance Charts Overview
Datastore Utilization Overview
Proactive Management Default Alarms to monitor infrastructure health,
resource and space utilization
Extensibility vShield Manager
NetApp Virtual Storage Console (VSC)
31. vShield Manager
和vCenter
server集成
Policy Overview
Traffic flow
Historical
flowchart
Real Time
flowchart
32
32. NetApp存储系统管理
SANscreen allows providers
and tenants visibility into full
storage path
Provisioning Manager eases
providers deployment
Protection manager makes
backups and recovery a snap.
Operations Manager offers
chargeback reporting and
monitoring
35. 弹性的存储架构:统一的存储架构设计
SAN NAS
Enterprise Departmental Enterprise Departmental
iSCSI
Fibre Dedicated Corporate
Channel Ethernet LAN
FCoE
SAN NAS
(Block) LUN LUN File File
(File)
FAS Series
36
36. 弹性的存储架构:持续在线的数据流动性
解决无法为下列操作安排停机
时间的问题
– 存储扩容
– 计划内维护宕机时间
– 技术更新
– 软件升级
Storage Pool 提高服务级别的灵活度
Storage Pool
– 动态的负载均衡
– 可调整的存储设备级别
应用透明化集成
Data
Data
– 保持优异性能
Data
– 保持交易一致性
37
NetApp Confidential - Internal Use Only 37
40. 存储有效性:多种空间有效性存储技术
Save Deduplication Save
up to over SnapshotTM Copies
95% 重复数据删除 80% 快照备份
Saves up to 95% for full backups;
25% to 55% for most data sets.
Up to Save
46% RAID 6 (RAID-DPTM) over Writable Snapshot
Saves up to 46% versus mirrored 80% (FlexClone®) Copies
data or RAID 10.
虚拟克隆技术
33% Thin Provisioning
(FlexVol®) PAM /PAMII
自动精简部署技术 性能加速模块
20% to 33% typical savings.
Savings compound when using
41 multiple features!
41. 虚拟化环境集成:SMVI虚拟化套件
主站点 容灾站点
APP APP APP
Virtual
Server OS OS OS
Admin
API
VM VM VM
VMDK Storage Pool VMDK VMDK Storage Pool VM1
VMDK
42
42