+ All Categories
Home > Education > 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data...

6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data...

Date post: 21-Mar-2017
Category:
Upload: juergen-ambrosi
View: 21 times
Download: 3 times
Share this document with a friend
43
Introduction to NSX Carlo Cavallina Systems Engineer NSX Specialist 1
Transcript
Page 1: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Introduction to NSX

Carlo CavallinaSystems EngineerNSX Specialist

1

Page 2: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Agenda

1 Who am I?

2 The IT transformation and the SDDC approach

3 The Network Virtualization

4 Disaster Recovery – The new era

5 Microsegmentation

6 NSX – The use cases

Page 3: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Who am I?

Page 4: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Going beyond server virtualization

Page 5: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

IT’S TIME FOR A NEW IT APPROACH

SLOW TECHNOLOGYADOPTION RATES

HIGH USER EXPECTATIONS

SLOW REPONSES

PRIVACYISSUES

INTEGRATION PROBLEMS

SERVICE OUTAGES

SHORTAGE OF RIGHT SKILLS

DECLINING BUDGET

DIFFERENT APPLICATIONS AGING INFRASTRUCTURE

SECURITY

PROLIFERATIONOF DEVICES

FRAGMENTEDDATA CENTER

LIMITED RESOURCES

CLOUD SILOSSECURITY

PROLIFERATIONOF DEVICES

FRAGMENTEDDATA CENTER

CLOUD SILOS

Page 6: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

It’s Time to Virtualize the WHOLE Data Center

EFFICIENT SECURE

Optimized for rapid development and deliveryof all applications, for safe consumption on any device

The Software DefinedData Center

AGILE

Network Virtualization is Key

Page 7: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Data Center Virtualization Layer

Intelligence in SoftwareOperational Model of VM for Data CenterAutomated Configuration & Management

What is a Software Defined Data Center (SDDC)?

Intelligence in HardwareDedicated, Vendor Specific InfrastructureManual Configuration & Management

Software

Hardware Compute, Network and Storage CapacityPooled, Vendor Independent, Best Price/Performance InfrastructureSimplified Configuration & Management

Page 8: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Compute

Storage

Network

Enterprise Applications

Enterprise Data Center

SecurityLoad Balancing

RoutingService Chaining

Page 9: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Compute

Storage

Network

Custom Distributed Applications

(Security, Application Load Balancing, Routing, HA, etc.)

Google, Facebook, Amazon

Software AutomationAgility & Speed

Network Services Distributed out to Applications

Simplified

Increased Stability& Reliability

Lower Cost

Page 10: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Compute

Storage

Network

Custom Distributed Applications

(Security, Application Load Balancing, Routing, HA, etc.)

Google, Facebook, Amazon

Compute

Storage

Network

Enterprise Applications

Enterprise IT

Data CenterVirtualization Layer

Page 11: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Compute

Storage

Network

Custom Distributed Application Design

(Security, Application Load Balancing, Routing, HA, etc.)

Google, Facebook, Amazon

Compute

Storage

Network

Enterprise Applications

Enterprise IT

Data CenterVirtualization Layer

Page 12: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Compute

Storage

Network

Enterprise Applications

Enterprise IT

Data CenterVirtualization Layer

The operational model of a VM for the

entire data center

Programmatically CreateSnapshot

StoreMoveDelete

Restore

Page 13: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Sounds interesting, BUT… It sounds like a big change. I’m not even sure I understand what network virtualization is.

Page 14: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

BridgingTwo Worlds

Software DefinedData Center Approach

Traditional Approach

Page 15: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center
Page 16: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Which pill do you want?

Page 17: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Network Virtualization is at the core of an SDDC approach

Network, storage, compute

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

HypervisorvSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

Hypervisor

Virtualization layer

Non-Disrupting Deployment

Page 18: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

HypervisorvSwitch

Hypervisor vSwitch

Hypervisor vSwitch

Hypervisor

vSwitch

Hypervisor

Network, storage, compute

Virtualization layer

“Network hypervisor”

Virtual Data Centers

Network Virtualization is at the core of an SDDC approach Non-Disrupting Deployment

Page 19: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

HypervisorvSwitch

Hypervisor vSwitch

Hypervisor vSwitch

Hypervisor

vSwitch

Hypervisor

The Power of Distributed Services

vSwitch

HypervisorvSwitch

Hypervisor vSwitch

Hypervisor vSwitch

Hypervisor

vSwitch

Hypervisor

vSwitch

Hypervisor

Switching

Routing

Firewalling/ACLs

Load Balancing

Network and security services now distributed in the hypervisor

Page 20: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

vSwitch

Hypervisor

Switching

Routing

Firewalling/ACLs

Load Balancing

vSwitch

HypervisorvSwitch

Hypervisor vSwitch

Hypervisor vSwitch

Hypervisor

High throughput rates

East-west firewalling

Native platform capability

The Power of Distributed Services

vSwitch

Hypervisor

Page 21: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Traditional Layer 3 Routing?

NSX vSwitchHypervisor

Physical NetworkHypervisor

VM

User Space

VMVM

User Space

NSX vSwitch

Page 22: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

A Virtual Network?

NSX vSwitchHypervisor

Physical Network

Virtual Network

Hypervisor

VM

User Space

VMVM

DistributedNetwork Services

User Space

NSX vSwitch

Page 23: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Virtual Network

A Virtual Network?

NSX vSwitchHypervisor

Hypervisor

VM

User Space

VMVM

Physical Network

DistributedNetwork Services

NSX vSwitch

Page 24: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Virtual Network

Non-Disruptive Deployment

NSX vSwitchHypervisor

NSX vSwitchHypervisor

VM

User Space

VMVM

Physical Network

VM

User Space

VMVM

DistributedNetwork Services

Page 25: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Virtual Network

Programmatically Provisioned

NSX vSwitchHypervisor

VM VMVM

Physical NetworkCloud Mgt Platform

NSX vSwitchHypervisor

VM

User Space

VMVM

Cluster Controller

DistributedNetwork Services

DistributedNetwork Services

Page 26: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Virtual Network

Network & Security Services Distributed to the Virtual Switch

Physical Host

NSX vSwitch

VM VMVM

NSX vSwitch

User Space

VMVM

Hypervisor

User Space

Hypervisor

Cluster Controller

Simplified IP Backplane No VLANs, No ACLs, No Firewall RulesPhysical Network

Cloud Mgt Platform

Physical Network becomes high-speed IP backplane

Page 27: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Virtual Network

Native Isolation

Physical Host

NSX vSwitch

VM VMVM

NSX vSwitch

VM

User Space

VMVM

Hypervisor

User Space

Hypervisor

192.168.2.10

192.168.2.10

192.168.2.11

192.168.2.11

Page 28: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

DR Today (simple view)

10.0.10/24 10.0.20/24

10.0.10.21 10.0.20.21 MajorRTOImpact

Change IP AddressReconfig Security4

Primary Site Recovery Site

Recoverthe VM

3

Replicate VM & Storage

2Physical Network Infrastructure Physical Network Infrastructure

SAN

1Snapshot VM

SAN

Step 1&2(e.g VMware SRM)

28

Page 29: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

DR with NSX Network Virtualization (simple view)

SAN SAN

10.0.30.21 10.0.30.21

Virtual Network10.0.30/24

80%RTONSX Controller NSX Controller

Snapshot Network & Security

2b

Primary Site Recovery Site

1Snapshot VM Network & Security

already exists

Recoverthe VM

3

Physical Network Infrastructure Physical Network Infrastructure2aReplicate

VM & Storage

10.0.10/24 10.0.20/24

Step 1&2(e.g VMware SRM)

29

Virtual Network10.0.30/24

Page 30: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Virtual Network

Support for Physical Workloads and VLANs

VLANPhysical or Virtual

Workloads

Physical Host

NSX vSwitch

VM VMVM

NSX vSwitch

VM

User Space

VMVM

Hypervisor

User Space

Hypervisor

Physical Workload

x86 Gateway

Cluster Controller

Page 31: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

VLANPhysical or Virtual

Workloads

Virtual Network

Support for Physical Workloads and VLANs

Physical Host

NSX vSwitch

VM VMVM

NSX vSwitch

VM

User Space

VMVM

Hypervisor

User Space

Hypervisor

Top-of-Rack Switches(OVS/DB – VTEP)

Cluster Controller

Physical Workload

Page 32: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Non-Disruptive Deployment

Page 33: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

The Power of Distributed Network & Security Services & Policies

Page 34: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Why traditional approaches are operationally infeasible…

34

Internet

Hypervisor

Physical Host

VM VM

vSwitchHypervisor

Physical Host

vSwitch

VM VM

Perimeter Firewalls

• Create firewall rules before provisioning• Update Firewall rules when move or change• Delete firewall rules when app decommissioned• Problem increases with more East-West traffic

Page 35: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

How an SDDC approach makes micro-segmentation feasible

35

Internet

Hypervisor

Physical Host

VM VMVM

vSwitchHypervisor

Physical Host

vSwitch

VM VMVM

Security Policy

Perimeter Firewalls

VM

CloudManagement

Platform

Page 36: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

There is a BIG difference…

Host

VM VMVM

Hypervisor

Host

VM VMVM

Hypervisor

Host

VM VMVM

Hypervisor

Host

VM VMVM

Hypervisor

Hypervisor

Host

VM VMVM

• Traditional Rule Mgt & Operations

• Chokepoint Enforcement• Virtual Firewalls (~1Gbps)

Virtual Firewalls

Physical Firewalls• Traditional Rule Mgt &

Operations• Chokepoint Enforcement• Physical Firewalls (~100 Gbps)

Distributed Firewalling• Automated Policy Mgt & Operations• Distributed Enforcement• vSphere Kernel-based Performance• Distributed Scale-out Capacity (20

Gbps/host)

Page 37: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Align type of controls to what you are protecting

Isolation Explicit Allow Comm. Secure Communications

VM VM VM

VM VM VM

VM VM VM

VM VM VM

VM VM VM

VM VM VM

NGFW

IPS

IPS

NGFW

Ser

vice

Inse

rtion

Application A

Application B

App Tier

DB Tier

(e.g

TC

P,14

33)

No Communication Path

Page 38: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

NSX Controller

Advanced Services Insertion – Example: Palo Alto Networks NGFW

Internet

Hypervisor

Physical Host

VMVM

vSwitchHypervisor

Physical Host

vSwitch

VMVM

Security Policy

Security Admin

TrafficSteering

Page 39: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Intelligent groupingGroups defined by customized criteria

Operating System Machine Name

Application Tier

Services

Security PostureRegulatory Requirements

Page 40: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

DDD

Automated Security in a Software-Defined Data CenterData Center Micro-Segmentation

CONFIDENTIAL 40

A AA

W W W

Page 41: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Automated Security in a Software-Defined Data CenterData Center Micro-Segmentation

CONFIDENTIAL 41

A

WD

AD

A

W

D

W

W

Page 42: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

42

Benefits of Taking a Software Defined Data Center Approach

Multi-tenant Infrastructure

IT Automating IT

Developer CloudDMZ Anywhere

Micro-segmentation

Secure End User

Metro Pooling

Hybrid Cloud Networking

Reduce infrastructure provisioning time from weeks to minutes

Secure infrastructure at 1/3 the cost

Reduce RTO by 80%

Disaster Recovery

Security Speed & Agility Application Continuity

Value

Page 43: 6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il Software-Defined Data Center

Thank you


Recommended