SlideShare a Scribd company logo
1 of 18
Download to read offline
USER DEFINED NETWORK 
Jacek Wosz JNCIE #877
•Wykorzystanie SDN u operatora telekomunikacyjnego 
•Wymagania do świadczenia usług w chmurze z wykorzystaniem SDN 
•User DefinedNetwork jako kolejny krok? 
•User SelfCarePortal 
•Architektura blokowa 
•Co właściwie dzieje się w sieci 
Agenda
•Zwiększenie marżowości świadczonych usług 
•Możliwość świadczenia zaawansowanych serwisów dla klientów biznesowych (ManagedSecurity) 
•Możliwość oferowania coraz to nowych usług w bardzo krótkim czasie 
•Możliwość łatwej skalowalności usług 
•Wyróżnik względem konkurencji 
Współczesne potrzeby operatorów telekomunikacyjnych
SDNController 
Configuration 
Analytics 
Control 
Server(Compute) 
VM 
VM 
VM 
Server(Compute) 
VM 
VM 
VM 
IP fabric(underlay network) 
Juniper Qfabric/QFX/EX or 3rd party underlay switches 
Juniper MXor 3rd party gateway routers 
Tenant VMs(NVF ie. FireflyPerimeter) 
ContrailController 
REST 
XMPP 
Orchestrator 
XMPP 
BGP + Netconf 
Contrail vRouter(L2 & L3) on KVM, Xenand ESXi/HyperV 
2014 
CloudSystems Components
•Network Address Translation (Firefly) 
•StatefulFirewall (Firefly) 
•Unified Threat Management (Firefly) 
•Intrusion Detection / Prevention (Firefly) 
•vCPE(Firefly) 
•Caching (JunosContent Encore) 
•SSL VPN Gateway (vSA) 
•DDoS(JDDS) 
•Web Intrusion Deception (JunosWebAppSecure) 
NAT 
IntrusionDeception 
Caching 
DDoS 
vCPE 
SSLGW 
Video 
Conf. 
… 
DPI 
Analytics 
WAN Opt. 
CDN 
Virtual SBC 
Juniper Services 
3rdParty Services 
FWIDP 
•Anything !! 
User DefinedNetworks 
Centralized Cloud 
Data Centers 
GW Router 
MOBILE 
Physical Network 
BUSINESS 
CUSTOMER 
VMs / NFV 
VMs / NFV 
NFV 
NFV 
Edge Clouds 
MX 3D 
Portal
Scripts 
SyslogServer 
Web Portal 
REST/JSON API 
Block Architecture –creating a Service Instance 
OpenStackControler 
ContrailController 
JunosSpace/ Security Director 
CreatingService Instance
Scripts 
SyslogServer 
Web Portal 
REST/JSON API 
OpenStackControler 
ContrailController 
JunosSpace/ Security Director 
AddingFireflyto Space 
Bind predefinedpolicy 
(WF/Appsec/AV) 
Block Architecture-adding Firefly Perimeter to Security Director
Scripts 
SyslogServer 
Web Portal 
REST/JSON API 
OpenStackControler 
ContrailController 
JunosSpace/ Security Director 
Requestinfo to drawstatistics 
Block Architecture –LoggingSystem
GW Router 
MOBILE 
Physical Network 
BUSINESS 
VMs / NFV 
VMs / NFV 
NFV 
NFV 
Edge Clouds 
MX 3D 
eBGP 
Centralized Cloud 
Data Centers
Centralized Cloud 
Data Centers 
GW Router 
MOBILE 
Physical Network 
BUSINESS 
VMs / NFV 
VMs / NFV 
NFV 
NFV 
Edge Clouds 
MX 3D 
eBGP 
Reports
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
CONTRAIL ELEMENTS
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
BGP (XMPP) 
BGP
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
1.CREATE VN NET#1 , ROUTE TARGET ASN:10000 
VRF #1 RT ASN:10000 
2.CREATE VM#1 in NET#1 
3. VM #1 HOST ROUTE RT ASN:10000 
4. ADVERTISE VM#1 HOST ROUTE with RT ASN:10000, 
NH > COMPUTE NODE 
5. DYNAMIC GRE 
6. INSTALL VM#1 HOST ROUTE in VRF#1 
ROUTE ADVERTISE BETWEEN MPLS NETWORK AND CONTRAIL
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAIL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
1.CREATE vSRXSERVICE INSTANCE 
IFL #1 WAN NETWORK 
IFL #2 LAN NETWORK 
IFL #3 MGMT NETWORK 
VRF WAN RT ASN:66600666 
2. VM vSRXHOST ROUTE RT ASN:66600666 
3. ADVERTISE vSRXHOST ROUTES 
6. INSTALL vSRXHOST ROUTES in VRFs 
VRF CUSTOMER #1 RT ASN:10001 
VRF CARRIER MGMT RT ASN:950001 
2. VM vSRXHOST 
ROUTE RT ASN:10001 
2. VM vSRXHOST 
ROUTE RT ASN:950001 
CREATING vSRX SERVICE INSTANCE
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
VRF WAN RT ASN:66600666 
WAN. 0/0 -> WAN GW (CONTRAIL) 
VRF CUSTOMER #1 RT ASN:10001 
VRF CARRIER MGMT RT ASN:950001 
LAN BGP SESSION TERMINATED on MX 
CONNECTING vSRX SERVICE INSTANCE TO INFRASTRUCTURE 
MGMT 10.10.100/24 -> MGMT GW (CONTRAIL) 
ADVERTISE -> CUSTOMER ROUTE FROM VRF 
ADVERTISE -> 0/0 to MX VRF (BY CONTRAIL NOTvSRX)
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
VRF WAN RT ASN:66600666 
VRF CUSTOMER #1 RT ASN:10001 
VRF CARRIER MGMT RT ASN:950001 
PRECONFIGURING vSRXSERVICE INSTANCE TO NEW ROLE 
DISOVER NEW vSRX 
Security Director 
PRECONFIGURE PROFILE ROLE(NGFW/WEB-FILTERING ETC)
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
VRF WAN RT ASN:66600666 
VRF CARRIER MGMT RT ASN:950001 VRF CUSTOMER #1 RT ASN:10001 
FLOW FROM CUSTOMER IN VRF 
FIREWALL/APPLICATION VISIBILITY/WEB FILTERING/AV
Q & A

More Related Content

What's hot

What's hot (19)

[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail
 
SSL Web VPN
SSL Web VPNSSL Web VPN
SSL Web VPN
 
Using OpenContrail with Kubernetes
Using OpenContrail with KubernetesUsing OpenContrail with Kubernetes
Using OpenContrail with Kubernetes
 
Site-to-Site IPSEC VPN Between Cisco ASA and Pfsense
Site-to-Site IPSEC VPN Between Cisco ASA and PfsenseSite-to-Site IPSEC VPN Between Cisco ASA and Pfsense
Site-to-Site IPSEC VPN Between Cisco ASA and Pfsense
 
[OpenStack 하반기 스터디] HA using DVR
[OpenStack 하반기 스터디] HA using DVR[OpenStack 하반기 스터디] HA using DVR
[OpenStack 하반기 스터디] HA using DVR
 
Using vSAN technology for hosted private cloud storage
Using vSAN technology for hosted private cloud storageUsing vSAN technology for hosted private cloud storage
Using vSAN technology for hosted private cloud storage
 
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
 
NAT with ASA & ASA Security Context
NAT with ASA & ASA Security ContextNAT with ASA & ASA Security Context
NAT with ASA & ASA Security Context
 
Accelerating SDN Applications with Open Source Network Overlays
Accelerating SDN Applications with Open Source Network OverlaysAccelerating SDN Applications with Open Source Network Overlays
Accelerating SDN Applications with Open Source Network Overlays
 
Отказоустойчивость с использованием Cisco ASA Clustering
Отказоустойчивость с использованием Cisco ASA ClusteringОтказоустойчивость с использованием Cisco ASA Clustering
Отказоустойчивость с использованием Cisco ASA Clustering
 
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit ModeSetting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
 
Open contrail slides for BANV meetup
Open contrail slides for BANV meetupOpen contrail slides for BANV meetup
Open contrail slides for BANV meetup
 
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngipsCisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngips
 
Contrail integrated with Kubernetes and Openstack
Contrail integrated with Kubernetes and OpenstackContrail integrated with Kubernetes and Openstack
Contrail integrated with Kubernetes and Openstack
 
Using Agilio SmartNICs for OpenStack Networking Acceleration
Using Agilio SmartNICs for OpenStack Networking AccelerationUsing Agilio SmartNICs for OpenStack Networking Acceleration
Using Agilio SmartNICs for OpenStack Networking Acceleration
 
Service Chaining - Cloud Network Services at Scale
Service Chaining - Cloud Network Services at ScaleService Chaining - Cloud Network Services at Scale
Service Chaining - Cloud Network Services at Scale
 
Contrail Deep-dive - Cloud Network Services at Scale
Contrail Deep-dive - Cloud Network Services at ScaleContrail Deep-dive - Cloud Network Services at Scale
Contrail Deep-dive - Cloud Network Services at Scale
 
Fortinet Ansible Solution Part 2
Fortinet Ansible Solution Part 2Fortinet Ansible Solution Part 2
Fortinet Ansible Solution Part 2
 
It's all about Security! Let’s get you started with Azure Bastion
It's all about Security! Let’s get you started with Azure BastionIt's all about Security! Let’s get you started with Azure Bastion
It's all about Security! Let’s get you started with Azure Bastion
 

Similar to PLNOG 13: Jacek Wosz: User Defined Network

ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000VASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS SK
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
nvirters
 

Similar to PLNOG 13: Jacek Wosz: User Defined Network (20)

Contrail Enabler for agile cloud services
Contrail Enabler for agile cloud servicesContrail Enabler for agile cloud services
Contrail Enabler for agile cloud services
 
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
 
Cisco Virtualized Network Services
Cisco Virtualized Network ServicesCisco Virtualized Network Services
Cisco Virtualized Network Services
 
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSXOVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
 
Anuta Networks at Networking Field Day 14
Anuta  Networks at Networking Field Day 14Anuta  Networks at Networking Field Day 14
Anuta Networks at Networking Field Day 14
 
Telco Cloud 02 - Introduction to nfv
Telco Cloud 02 - Introduction to nfvTelco Cloud 02 - Introduction to nfv
Telco Cloud 02 - Introduction to nfv
 
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000VASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
 
Demystifying OpenStack for NFV
Demystifying OpenStack for NFVDemystifying OpenStack for NFV
Demystifying OpenStack for NFV
 
vSRX
vSRXvSRX
vSRX
 
EYWA Presentation v0.1.27
EYWA Presentation v0.1.27EYWA Presentation v0.1.27
EYWA Presentation v0.1.27
 
OpenStack MeetUp - OpenContrail Presentation
OpenStack MeetUp - OpenContrail PresentationOpenStack MeetUp - OpenContrail Presentation
OpenStack MeetUp - OpenContrail Presentation
 
Iben from Spirent talks at the SDN World Congress about the importance of and...
Iben from Spirent talks at the SDN World Congress about the importance of and...Iben from Spirent talks at the SDN World Congress about the importance of and...
Iben from Spirent talks at the SDN World Congress about the importance of and...
 
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryOpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service Delivery
 
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryOpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service Delivery
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
 
Introduction to SDN and NFV
Introduction to SDN and NFVIntroduction to SDN and NFV
Introduction to SDN and NFV
 
Presentation cisco nexus 1010 overview and deployment
Presentation   cisco nexus 1010 overview and deploymentPresentation   cisco nexus 1010 overview and deployment
Presentation cisco nexus 1010 overview and deployment
 
Citrix Day 2014: NetScaler Cisco ACE
Citrix Day 2014: NetScaler Cisco ACECitrix Day 2014: NetScaler Cisco ACE
Citrix Day 2014: NetScaler Cisco ACE
 
Nfd18 anuta-networks
Nfd18 anuta-networksNfd18 anuta-networks
Nfd18 anuta-networks
 

Recently uploaded

Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Sheetaleventcompany
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
imonikaupta
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
sexy call girls service in goa
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
ellan12
 

Recently uploaded (20)

Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 

PLNOG 13: Jacek Wosz: User Defined Network

  • 1. USER DEFINED NETWORK Jacek Wosz JNCIE #877
  • 2. •Wykorzystanie SDN u operatora telekomunikacyjnego •Wymagania do świadczenia usług w chmurze z wykorzystaniem SDN •User DefinedNetwork jako kolejny krok? •User SelfCarePortal •Architektura blokowa •Co właściwie dzieje się w sieci Agenda
  • 3. •Zwiększenie marżowości świadczonych usług •Możliwość świadczenia zaawansowanych serwisów dla klientów biznesowych (ManagedSecurity) •Możliwość oferowania coraz to nowych usług w bardzo krótkim czasie •Możliwość łatwej skalowalności usług •Wyróżnik względem konkurencji Współczesne potrzeby operatorów telekomunikacyjnych
  • 4. SDNController Configuration Analytics Control Server(Compute) VM VM VM Server(Compute) VM VM VM IP fabric(underlay network) Juniper Qfabric/QFX/EX or 3rd party underlay switches Juniper MXor 3rd party gateway routers Tenant VMs(NVF ie. FireflyPerimeter) ContrailController REST XMPP Orchestrator XMPP BGP + Netconf Contrail vRouter(L2 & L3) on KVM, Xenand ESXi/HyperV 2014 CloudSystems Components
  • 5. •Network Address Translation (Firefly) •StatefulFirewall (Firefly) •Unified Threat Management (Firefly) •Intrusion Detection / Prevention (Firefly) •vCPE(Firefly) •Caching (JunosContent Encore) •SSL VPN Gateway (vSA) •DDoS(JDDS) •Web Intrusion Deception (JunosWebAppSecure) NAT IntrusionDeception Caching DDoS vCPE SSLGW Video Conf. … DPI Analytics WAN Opt. CDN Virtual SBC Juniper Services 3rdParty Services FWIDP •Anything !! User DefinedNetworks Centralized Cloud Data Centers GW Router MOBILE Physical Network BUSINESS CUSTOMER VMs / NFV VMs / NFV NFV NFV Edge Clouds MX 3D Portal
  • 6. Scripts SyslogServer Web Portal REST/JSON API Block Architecture –creating a Service Instance OpenStackControler ContrailController JunosSpace/ Security Director CreatingService Instance
  • 7. Scripts SyslogServer Web Portal REST/JSON API OpenStackControler ContrailController JunosSpace/ Security Director AddingFireflyto Space Bind predefinedpolicy (WF/Appsec/AV) Block Architecture-adding Firefly Perimeter to Security Director
  • 8. Scripts SyslogServer Web Portal REST/JSON API OpenStackControler ContrailController JunosSpace/ Security Director Requestinfo to drawstatistics Block Architecture –LoggingSystem
  • 9. GW Router MOBILE Physical Network BUSINESS VMs / NFV VMs / NFV NFV NFV Edge Clouds MX 3D eBGP Centralized Cloud Data Centers
  • 10. Centralized Cloud Data Centers GW Router MOBILE Physical Network BUSINESS VMs / NFV VMs / NFV NFV NFV Edge Clouds MX 3D eBGP Reports
  • 11. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE CONTRAIL ELEMENTS
  • 12. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE BGP (XMPP) BGP
  • 13. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE 1.CREATE VN NET#1 , ROUTE TARGET ASN:10000 VRF #1 RT ASN:10000 2.CREATE VM#1 in NET#1 3. VM #1 HOST ROUTE RT ASN:10000 4. ADVERTISE VM#1 HOST ROUTE with RT ASN:10000, NH > COMPUTE NODE 5. DYNAMIC GRE 6. INSTALL VM#1 HOST ROUTE in VRF#1 ROUTE ADVERTISE BETWEEN MPLS NETWORK AND CONTRAIL
  • 14. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAIL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE 1.CREATE vSRXSERVICE INSTANCE IFL #1 WAN NETWORK IFL #2 LAN NETWORK IFL #3 MGMT NETWORK VRF WAN RT ASN:66600666 2. VM vSRXHOST ROUTE RT ASN:66600666 3. ADVERTISE vSRXHOST ROUTES 6. INSTALL vSRXHOST ROUTES in VRFs VRF CUSTOMER #1 RT ASN:10001 VRF CARRIER MGMT RT ASN:950001 2. VM vSRXHOST ROUTE RT ASN:10001 2. VM vSRXHOST ROUTE RT ASN:950001 CREATING vSRX SERVICE INSTANCE
  • 15. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE VRF WAN RT ASN:66600666 WAN. 0/0 -> WAN GW (CONTRAIL) VRF CUSTOMER #1 RT ASN:10001 VRF CARRIER MGMT RT ASN:950001 LAN BGP SESSION TERMINATED on MX CONNECTING vSRX SERVICE INSTANCE TO INFRASTRUCTURE MGMT 10.10.100/24 -> MGMT GW (CONTRAIL) ADVERTISE -> CUSTOMER ROUTE FROM VRF ADVERTISE -> 0/0 to MX VRF (BY CONTRAIL NOTvSRX)
  • 16. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE VRF WAN RT ASN:66600666 VRF CUSTOMER #1 RT ASN:10001 VRF CARRIER MGMT RT ASN:950001 PRECONFIGURING vSRXSERVICE INSTANCE TO NEW ROLE DISOVER NEW vSRX Security Director PRECONFIGURE PROFILE ROLE(NGFW/WEB-FILTERING ETC)
  • 17. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE VRF WAN RT ASN:66600666 VRF CARRIER MGMT RT ASN:950001 VRF CUSTOMER #1 RT ASN:10001 FLOW FROM CUSTOMER IN VRF FIREWALL/APPLICATION VISIBILITY/WEB FILTERING/AV
  • 18. Q & A