maqsood siddiqui · virtual machine virtual machine virtual machine network application application...

37
© 2014 VMware Inc. All rights reserved. Maqsood Siddiqui 10 th June 2014

Upload: others

Post on 10-Jul-2020

11 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

© 2014 VMware Inc. All rights reserved.

Maqsood Siddiqui 10th June 2014

Page 2: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

© 2014 VMware Inc. All rights reserved.

Bringing Network Virtualisation to VMware Environments With NSX VMware vForums 2014

Maqsood Siddiqui

10th June 2014

Page 3: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Agenda

• The Software-Defined Data Center and the Network

• How Does It Work

• Better Security

• Better Operational Visibility

• Use Cases

• Eco System

Page 4: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

The Software-Defined Data Center and the Network

Page 5: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Intelligence in Software Operational Model of VM for Data Center Automated Configuration & Management

What is a Software-Defined Data Center (SDDC)?

Intelligence in ASICs Dedicated, Vendor Specific Hardware Manual Configuration & Management

Software

Hardware Compute, Network and Storage Capacity Vendor Independent, Best Price/Performance Hardware Simplified Configuration & Management

Page 6: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Infrastructure

Servers Clouds

Be more responsive to business, change economics of IT

• Fast Workload Provisioning – weeks to minutes

• Unlimited Workload Placement & Mobility

• Any Hardware or Topology

• Improved cloud security

The Transformation of Infrastructure

Page 7: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Compute Virtualization

The Network is a Barrier to Software Defined Data Center

Any Physical Infrastructure

• Provisioning is slow

• Placement & Mobility is limited

• Operational visibility is limited

• Hardware dependent

• Operationally intensive

Network

Server

Storage

Page 8: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

The Solution – Transform the Network with Virtualization

Compute Virtualization

• Programmatic provisioning

• Any workload anywhere

• End-to-end operational visibility

• Decoupled from hardware

• Operationally efficient

Network Virtualization

Hardware Independent

Network

Server

Storage

Any Physical Infrastructure

Software Defined Virtual Network

Page 9: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

What is a Network Hypervisor?

General Purpose Server Hardware (Dell, HP, IBM, Quanta,…)

Server Hypervisor

Requirement: x86

Virtual

Machine

Virtual

Machine

Virtual

Machine

Application Application Application

x86 Environment

Decoupled

Hardware

Software

General Purpose IP Hardware (Arista, Cisco, HP, Juniper, Cumulus,…)

Network Hypervisor

Requirement: IP Transport

Virtual

Network

Virtual

Network Virtual

Network

Workload Workload Workload

L2, L3, L4-7 Network Services

Page 10: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Virtualize the Network

Decouple

Any

Hardware

Platform

Network Virtualisation Layer

Page 11: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Network Virtualization Decouples and reproduces the network model

Network Hypervisor Decoupled

Physical Network

(Arista, Cisco, HP, Juniper, Cumulus,…)

Workload Workload Workload

L2

L2

L3

Virtual Network

Workload Workload Workload

Virtual Network

L2

WAN

Subnet A Subnet B Subnet C

Page 12: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

How Does It Work?

Page 13: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

A Data Centre Network…

Internet

Page 14: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Compute Infrastructure….

Internet

Page 15: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Hypervisors and vSwitches…

Internet

Page 16: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

NSX | The “Network Hypervisor”

Internet

Page 17: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Virtual Networks – Like Virtual Machines for the Network

Internet

Page 18: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Programmatic Provisioning

Page 19: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Services Distributed to the Virtual Switch

Page 20: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Physical Workloads and Legacy VLANs

Page 21: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

The Power of Distribution

Page 22: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Better Security

22

Page 23: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Security – Complete Isolation

Virtual Networks are isolated from each other (Overlapping IP Addresses)

Virtual Networks are isolated from underlying physical network (IPv6 over IPv4)

Page 24: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Central Policies, Distributed Enforcement, Move with VMs

Internet

Security Policy Security Policy

- Reduce Choke Point Security

- Centrally Define Policies, Distribute Rule Enforcement for Segmentation

- Security Policies Move with VMs

- Changes to central policies automatically

distributed to affected VMs

Page 25: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

The Power of Distribution

Page 26: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Service Insertion – Example: Palo Alto Networks Next Generation Firewall

Internet

Security Policy

Security Admin

Traffic Steering

Page 27: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Better Operational Visibility

27

Page 28: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Visibility & Troubleshooting

Page 29: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Visibility & Troubleshooting

Use the network troubleshooting tools you use today,

but with better information

Page 30: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Visibility & Troubleshooting

Use the network troubleshooting tools you use today,

but with better information

IPFIX Log

syslog Netflow Log

Page 31: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Use Cases

31

Page 32: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

VMware NSX Use Case Examples

• Self Service R&D Clouds & Data Center Automation

– Speed & Agility

– Automated Provisioning

• Data Center Refresh

– Flexibility and choice for physical infrastructure

– Hardware independence

• Data Center Migration and Disaster Recovery

– No Re-IPing application workloads

• Scale-out DMZ

• Micro-segmentation

– Leverages inherent isolation and distributed firewalling

32

Page 33: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Ecosystem

33

Page 34: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

VMware NSX Ecosystem – Technology Partners

Page 35: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

More Information

CONFIDENTIAL 35

Hands on Labs (HOL): http://labs.hol.vmware.com/ NSX Design Guide: http://www.vmware.com/products/nsx/resources NSX Public Landing Page: http://www.vmware.com/products/nsx

Page 36: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware

Thank You Questions?

CONFIDENTIAL 36

Page 37: Maqsood Siddiqui · Virtual Machine Virtual Machine Virtual Machine Network Application Application Application x86 Environment Software Decoupled Hardware General Purpose IP Hardware