SlideShare a Scribd company logo
1 of 18
Download to read offline
USER DEFINED NETWORK 
Jacek Wosz JNCIE #877
•Wykorzystanie SDN u operatora telekomunikacyjnego 
•Wymagania do świadczenia usług w chmurze z wykorzystaniem SDN 
•User DefinedNetwork jako kolejny krok? 
•User SelfCarePortal 
•Architektura blokowa 
•Co właściwie dzieje się w sieci 
Agenda
•Zwiększenie marżowości świadczonych usług 
•Możliwość świadczenia zaawansowanych serwisów dla klientów biznesowych (ManagedSecurity) 
•Możliwość oferowania coraz to nowych usług w bardzo krótkim czasie 
•Możliwość łatwej skalowalności usług 
•Wyróżnik względem konkurencji 
Współczesne potrzeby operatorów telekomunikacyjnych
SDNController 
Configuration 
Analytics 
Control 
Server(Compute) 
VM 
VM 
VM 
Server(Compute) 
VM 
VM 
VM 
IP fabric(underlay network) 
Juniper Qfabric/QFX/EX or 3rd party underlay switches 
Juniper MXor 3rd party gateway routers 
Tenant VMs(NVF ie. FireflyPerimeter) 
ContrailController 
REST 
XMPP 
Orchestrator 
XMPP 
BGP + Netconf 
Contrail vRouter(L2 & L3) on KVM, Xenand ESXi/HyperV 
2014 
CloudSystems Components
•Network Address Translation (Firefly) 
•StatefulFirewall (Firefly) 
•Unified Threat Management (Firefly) 
•Intrusion Detection / Prevention (Firefly) 
•vCPE(Firefly) 
•Caching (JunosContent Encore) 
•SSL VPN Gateway (vSA) 
•DDoS(JDDS) 
•Web Intrusion Deception (JunosWebAppSecure) 
NAT 
IntrusionDeception 
Caching 
DDoS 
vCPE 
SSLGW 
Video 
Conf. 
… 
DPI 
Analytics 
WAN Opt. 
CDN 
Virtual SBC 
Juniper Services 
3rdParty Services 
FWIDP 
•Anything !! 
User DefinedNetworks 
Centralized Cloud 
Data Centers 
GW Router 
MOBILE 
Physical Network 
BUSINESS 
CUSTOMER 
VMs / NFV 
VMs / NFV 
NFV 
NFV 
Edge Clouds 
MX 3D 
Portal
Scripts 
SyslogServer 
Web Portal 
REST/JSON API 
Block Architecture –creating a Service Instance 
OpenStackControler 
ContrailController 
JunosSpace/ Security Director 
CreatingService Instance
Scripts 
SyslogServer 
Web Portal 
REST/JSON API 
OpenStackControler 
ContrailController 
JunosSpace/ Security Director 
AddingFireflyto Space 
Bind predefinedpolicy 
(WF/Appsec/AV) 
Block Architecture-adding Firefly Perimeter to Security Director
Scripts 
SyslogServer 
Web Portal 
REST/JSON API 
OpenStackControler 
ContrailController 
JunosSpace/ Security Director 
Requestinfo to drawstatistics 
Block Architecture –LoggingSystem
GW Router 
MOBILE 
Physical Network 
BUSINESS 
VMs / NFV 
VMs / NFV 
NFV 
NFV 
Edge Clouds 
MX 3D 
eBGP 
Centralized Cloud 
Data Centers
Centralized Cloud 
Data Centers 
GW Router 
MOBILE 
Physical Network 
BUSINESS 
VMs / NFV 
VMs / NFV 
NFV 
NFV 
Edge Clouds 
MX 3D 
eBGP 
Reports
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
CONTRAIL ELEMENTS
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
BGP (XMPP) 
BGP
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
1.CREATE VN NET#1 , ROUTE TARGET ASN:10000 
VRF #1 RT ASN:10000 
2.CREATE VM#1 in NET#1 
3. VM #1 HOST ROUTE RT ASN:10000 
4. ADVERTISE VM#1 HOST ROUTE with RT ASN:10000, 
NH > COMPUTE NODE 
5. DYNAMIC GRE 
6. INSTALL VM#1 HOST ROUTE in VRF#1 
ROUTE ADVERTISE BETWEEN MPLS NETWORK AND CONTRAIL
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAIL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
1.CREATE vSRXSERVICE INSTANCE 
IFL #1 WAN NETWORK 
IFL #2 LAN NETWORK 
IFL #3 MGMT NETWORK 
VRF WAN RT ASN:66600666 
2. VM vSRXHOST ROUTE RT ASN:66600666 
3. ADVERTISE vSRXHOST ROUTES 
6. INSTALL vSRXHOST ROUTES in VRFs 
VRF CUSTOMER #1 RT ASN:10001 
VRF CARRIER MGMT RT ASN:950001 
2. VM vSRXHOST 
ROUTE RT ASN:10001 
2. VM vSRXHOST 
ROUTE RT ASN:950001 
CREATING vSRX SERVICE INSTANCE
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
VRF WAN RT ASN:66600666 
WAN. 0/0 -> WAN GW (CONTRAIL) 
VRF CUSTOMER #1 RT ASN:10001 
VRF CARRIER MGMT RT ASN:950001 
LAN BGP SESSION TERMINATED on MX 
CONNECTING vSRX SERVICE INSTANCE TO INFRASTRUCTURE 
MGMT 10.10.100/24 -> MGMT GW (CONTRAIL) 
ADVERTISE -> CUSTOMER ROUTE FROM VRF 
ADVERTISE -> 0/0 to MX VRF (BY CONTRAIL NOTvSRX)
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
VRF WAN RT ASN:66600666 
VRF CUSTOMER #1 RT ASN:10001 
VRF CARRIER MGMT RT ASN:950001 
PRECONFIGURING vSRXSERVICE INSTANCE TO NEW ROLE 
DISOVER NEW vSRX 
Security Director 
PRECONFIGURE PROFILE ROLE(NGFW/WEB-FILTERING ETC)
MX GATEWAY 
CONTRAIL vROUTER 
xe-2/0/0.96 
10.10.96.253 
CONTRAL/OPENSTACK 
CONTROLER 
CONTRAL/OPENSTACK 
COMPUTE NODE 
VRF WAN RT ASN:66600666 
VRF CARRIER MGMT RT ASN:950001 VRF CUSTOMER #1 RT ASN:10001 
FLOW FROM CUSTOMER IN VRF 
FIREWALL/APPLICATION VISIBILITY/WEB FILTERING/AV
Q & A

More Related Content

What's hot

[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With ContrailOpenStack Korea Community
 
Using OpenContrail with Kubernetes
Using OpenContrail with KubernetesUsing OpenContrail with Kubernetes
Using OpenContrail with KubernetesMatt Baldwin
 
Site-to-Site IPSEC VPN Between Cisco ASA and Pfsense
Site-to-Site IPSEC VPN Between Cisco ASA and PfsenseSite-to-Site IPSEC VPN Between Cisco ASA and Pfsense
Site-to-Site IPSEC VPN Between Cisco ASA and PfsenseHarris Andrea
 
[OpenStack 하반기 스터디] HA using DVR
[OpenStack 하반기 스터디] HA using DVR[OpenStack 하반기 스터디] HA using DVR
[OpenStack 하반기 스터디] HA using DVROpenStack Korea Community
 
Using vSAN technology for hosted private cloud storage
Using vSAN technology for hosted private cloud storageUsing vSAN technology for hosted private cloud storage
Using vSAN technology for hosted private cloud storageOVHcloud
 
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...Vietnam Open Infrastructure User Group
 
NAT with ASA & ASA Security Context
NAT with ASA & ASA Security ContextNAT with ASA & ASA Security Context
NAT with ASA & ASA Security ContextNetProtocol Xpert
 
Accelerating SDN Applications with Open Source Network Overlays
Accelerating SDN Applications with Open Source Network OverlaysAccelerating SDN Applications with Open Source Network Overlays
Accelerating SDN Applications with Open Source Network OverlaysCumulus Networks
 
Отказоустойчивость с использованием Cisco ASA Clustering
Отказоустойчивость с использованием Cisco ASA ClusteringОтказоустойчивость с использованием Cisco ASA Clustering
Отказоустойчивость с использованием Cisco ASA ClusteringCisco Russia
 
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit ModeSetting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit ModeDhruv Sharma
 
Open contrail slides for BANV meetup
Open contrail slides for BANV meetupOpen contrail slides for BANV meetup
Open contrail slides for BANV meetupScott Edwards
 
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngipsCisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngipsIT Tech
 
Contrail integrated with Kubernetes and Openstack
Contrail integrated with Kubernetes and OpenstackContrail integrated with Kubernetes and Openstack
Contrail integrated with Kubernetes and OpenstackDaisuke Nakajima
 
Using Agilio SmartNICs for OpenStack Networking Acceleration
Using Agilio SmartNICs for OpenStack Networking AccelerationUsing Agilio SmartNICs for OpenStack Networking Acceleration
Using Agilio SmartNICs for OpenStack Networking AccelerationNetronome
 
Service Chaining - Cloud Network Services at Scale
Service Chaining - Cloud Network Services at ScaleService Chaining - Cloud Network Services at Scale
Service Chaining - Cloud Network Services at ScaleMarketingArrowECS_CZ
 
Contrail Deep-dive - Cloud Network Services at Scale
Contrail Deep-dive - Cloud Network Services at ScaleContrail Deep-dive - Cloud Network Services at Scale
Contrail Deep-dive - Cloud Network Services at ScaleMarketingArrowECS_CZ
 
Fortinet Ansible Solution Part 2
Fortinet Ansible Solution Part 2Fortinet Ansible Solution Part 2
Fortinet Ansible Solution Part 2Salim Haniff
 
It's all about Security! Let’s get you started with Azure Bastion
It's all about Security! Let’s get you started with Azure BastionIt's all about Security! Let’s get you started with Azure Bastion
It's all about Security! Let’s get you started with Azure BastionWim Matthyssen
 

What's hot (19)

[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail[OpenStack 스터디] OpenStack With Contrail
[OpenStack 스터디] OpenStack With Contrail
 
SSL Web VPN
SSL Web VPNSSL Web VPN
SSL Web VPN
 
Using OpenContrail with Kubernetes
Using OpenContrail with KubernetesUsing OpenContrail with Kubernetes
Using OpenContrail with Kubernetes
 
Site-to-Site IPSEC VPN Between Cisco ASA and Pfsense
Site-to-Site IPSEC VPN Between Cisco ASA and PfsenseSite-to-Site IPSEC VPN Between Cisco ASA and Pfsense
Site-to-Site IPSEC VPN Between Cisco ASA and Pfsense
 
[OpenStack 하반기 스터디] HA using DVR
[OpenStack 하반기 스터디] HA using DVR[OpenStack 하반기 스터디] HA using DVR
[OpenStack 하반기 스터디] HA using DVR
 
Using vSAN technology for hosted private cloud storage
Using vSAN technology for hosted private cloud storageUsing vSAN technology for hosted private cloud storage
Using vSAN technology for hosted private cloud storage
 
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
Packaging Strategy for Community Openstack and Implementation Reference | Hoj...
 
NAT with ASA & ASA Security Context
NAT with ASA & ASA Security ContextNAT with ASA & ASA Security Context
NAT with ASA & ASA Security Context
 
Accelerating SDN Applications with Open Source Network Overlays
Accelerating SDN Applications with Open Source Network OverlaysAccelerating SDN Applications with Open Source Network Overlays
Accelerating SDN Applications with Open Source Network Overlays
 
Отказоустойчивость с использованием Cisco ASA Clustering
Отказоустойчивость с использованием Cisco ASA ClusteringОтказоустойчивость с использованием Cisco ASA Clustering
Отказоустойчивость с использованием Cisco ASA Clustering
 
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit ModeSetting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
 
Open contrail slides for BANV meetup
Open contrail slides for BANV meetupOpen contrail slides for BANV meetup
Open contrail slides for BANV meetup
 
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngipsCisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngips
 
Contrail integrated with Kubernetes and Openstack
Contrail integrated with Kubernetes and OpenstackContrail integrated with Kubernetes and Openstack
Contrail integrated with Kubernetes and Openstack
 
Using Agilio SmartNICs for OpenStack Networking Acceleration
Using Agilio SmartNICs for OpenStack Networking AccelerationUsing Agilio SmartNICs for OpenStack Networking Acceleration
Using Agilio SmartNICs for OpenStack Networking Acceleration
 
Service Chaining - Cloud Network Services at Scale
Service Chaining - Cloud Network Services at ScaleService Chaining - Cloud Network Services at Scale
Service Chaining - Cloud Network Services at Scale
 
Contrail Deep-dive - Cloud Network Services at Scale
Contrail Deep-dive - Cloud Network Services at ScaleContrail Deep-dive - Cloud Network Services at Scale
Contrail Deep-dive - Cloud Network Services at Scale
 
Fortinet Ansible Solution Part 2
Fortinet Ansible Solution Part 2Fortinet Ansible Solution Part 2
Fortinet Ansible Solution Part 2
 
It's all about Security! Let’s get you started with Azure Bastion
It's all about Security! Let’s get you started with Azure BastionIt's all about Security! Let’s get you started with Azure Bastion
It's all about Security! Let’s get you started with Azure Bastion
 

Similar to PLNOG 13: Jacek Wosz: User Defined Network

VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...VMworld
 
Cisco Virtualized Network Services
Cisco Virtualized Network ServicesCisco Virtualized Network Services
Cisco Virtualized Network ServicesSoumen Chatterjee
 
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSXOVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSXOVHcloud
 
Anuta Networks at Networking Field Day 14
Anuta  Networks at Networking Field Day 14Anuta  Networks at Networking Field Day 14
Anuta Networks at Networking Field Day 14Kiran Sirupa
 
Telco Cloud 02 - Introduction to nfv
Telco Cloud 02 - Introduction to nfvTelco Cloud 02 - Introduction to nfv
Telco Cloud 02 - Introduction to nfvVikas Shokeen
 
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000VASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000VASBIS SK
 
Demystifying OpenStack for NFV
Demystifying OpenStack for NFVDemystifying OpenStack for NFV
Demystifying OpenStack for NFVTrinath Somanchi
 
EYWA Presentation v0.1.27
EYWA Presentation v0.1.27EYWA Presentation v0.1.27
EYWA Presentation v0.1.27JungIn Jung
 
OpenStack MeetUp - OpenContrail Presentation
OpenStack MeetUp - OpenContrail PresentationOpenStack MeetUp - OpenContrail Presentation
OpenStack MeetUp - OpenContrail PresentationStacy Véronneau
 
Iben from Spirent talks at the SDN World Congress about the importance of and...
Iben from Spirent talks at the SDN World Congress about the importance of and...Iben from Spirent talks at the SDN World Congress about the importance of and...
Iben from Spirent talks at the SDN World Congress about the importance of and...Iben Rodriguez
 
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryOpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryLew Tucker
 
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryOpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryMirantis
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrailnvirters
 
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...VMworld
 
Presentation cisco nexus 1010 overview and deployment
Presentation   cisco nexus 1010 overview and deploymentPresentation   cisco nexus 1010 overview and deployment
Presentation cisco nexus 1010 overview and deploymentxKinAnx
 
Citrix Day 2014: NetScaler Cisco ACE
Citrix Day 2014: NetScaler Cisco ACECitrix Day 2014: NetScaler Cisco ACE
Citrix Day 2014: NetScaler Cisco ACEDigicomp Academy AG
 
Nfd18 anuta-networks
Nfd18 anuta-networksNfd18 anuta-networks
Nfd18 anuta-networksKiran Sirupa
 

Similar to PLNOG 13: Jacek Wosz: User Defined Network (20)

Contrail Enabler for agile cloud services
Contrail Enabler for agile cloud servicesContrail Enabler for agile cloud services
Contrail Enabler for agile cloud services
 
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
VMworld 2013: Troubleshooting VXLAN and Network Services in a Virtualized Env...
 
Cisco Virtualized Network Services
Cisco Virtualized Network ServicesCisco Virtualized Network Services
Cisco Virtualized Network Services
 
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSXOVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
 
Anuta Networks at Networking Field Day 14
Anuta  Networks at Networking Field Day 14Anuta  Networks at Networking Field Day 14
Anuta Networks at Networking Field Day 14
 
Telco Cloud 02 - Introduction to nfv
Telco Cloud 02 - Introduction to nfvTelco Cloud 02 - Introduction to nfv
Telco Cloud 02 - Introduction to nfv
 
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000VASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
ASBIS: Virtualization Aware Networking - Cisco Nexus 1000V
 
Demystifying OpenStack for NFV
Demystifying OpenStack for NFVDemystifying OpenStack for NFV
Demystifying OpenStack for NFV
 
vSRX
vSRXvSRX
vSRX
 
EYWA Presentation v0.1.27
EYWA Presentation v0.1.27EYWA Presentation v0.1.27
EYWA Presentation v0.1.27
 
OpenStack MeetUp - OpenContrail Presentation
OpenStack MeetUp - OpenContrail PresentationOpenStack MeetUp - OpenContrail Presentation
OpenStack MeetUp - OpenContrail Presentation
 
Iben from Spirent talks at the SDN World Congress about the importance of and...
Iben from Spirent talks at the SDN World Congress about the importance of and...Iben from Spirent talks at the SDN World Congress about the importance of and...
Iben from Spirent talks at the SDN World Congress about the importance of and...
 
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryOpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service Delivery
 
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service DeliveryOpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service Delivery
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
vVMworld 2013: Deploying, Troubleshooting, and Monitoring VMware NSX Distribu...
 
Introduction to SDN and NFV
Introduction to SDN and NFVIntroduction to SDN and NFV
Introduction to SDN and NFV
 
Presentation cisco nexus 1010 overview and deployment
Presentation   cisco nexus 1010 overview and deploymentPresentation   cisco nexus 1010 overview and deployment
Presentation cisco nexus 1010 overview and deployment
 
Citrix Day 2014: NetScaler Cisco ACE
Citrix Day 2014: NetScaler Cisco ACECitrix Day 2014: NetScaler Cisco ACE
Citrix Day 2014: NetScaler Cisco ACE
 
Nfd18 anuta-networks
Nfd18 anuta-networksNfd18 anuta-networks
Nfd18 anuta-networks
 

Recently uploaded

FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607dollysharma2066
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girlsstephieert
 
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With RoomVIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Roomishabajaj13
 
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Lucknow
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Dana Luther
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一Fs
 
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on DeliveryCall Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Deliverybabeytanya
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Roomdivyansh0kumar0
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一Fs
 
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girladitipandeya
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsThierry TROUIN ☁
 
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)Christopher H Felton
 

Recently uploaded (20)

FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girls
 
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With RoomVIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
 
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
 
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on DeliveryCall Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
 
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call GirlVIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
VIP 7001035870 Find & Meet Hyderabad Call Girls LB Nagar high-profile Call Girl
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with Flows
 
Call Girls Service Dwarka @9999965857 Delhi 🫦 No Advance VVIP 🍎 SERVICE
Call Girls Service Dwarka @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SERVICECall Girls Service Dwarka @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SERVICE
Call Girls Service Dwarka @9999965857 Delhi 🫦 No Advance VVIP 🍎 SERVICE
 
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Uttam Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
 
sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-
sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-
sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-
 

PLNOG 13: Jacek Wosz: User Defined Network

  • 1. USER DEFINED NETWORK Jacek Wosz JNCIE #877
  • 2. •Wykorzystanie SDN u operatora telekomunikacyjnego •Wymagania do świadczenia usług w chmurze z wykorzystaniem SDN •User DefinedNetwork jako kolejny krok? •User SelfCarePortal •Architektura blokowa •Co właściwie dzieje się w sieci Agenda
  • 3. •Zwiększenie marżowości świadczonych usług •Możliwość świadczenia zaawansowanych serwisów dla klientów biznesowych (ManagedSecurity) •Możliwość oferowania coraz to nowych usług w bardzo krótkim czasie •Możliwość łatwej skalowalności usług •Wyróżnik względem konkurencji Współczesne potrzeby operatorów telekomunikacyjnych
  • 4. SDNController Configuration Analytics Control Server(Compute) VM VM VM Server(Compute) VM VM VM IP fabric(underlay network) Juniper Qfabric/QFX/EX or 3rd party underlay switches Juniper MXor 3rd party gateway routers Tenant VMs(NVF ie. FireflyPerimeter) ContrailController REST XMPP Orchestrator XMPP BGP + Netconf Contrail vRouter(L2 & L3) on KVM, Xenand ESXi/HyperV 2014 CloudSystems Components
  • 5. •Network Address Translation (Firefly) •StatefulFirewall (Firefly) •Unified Threat Management (Firefly) •Intrusion Detection / Prevention (Firefly) •vCPE(Firefly) •Caching (JunosContent Encore) •SSL VPN Gateway (vSA) •DDoS(JDDS) •Web Intrusion Deception (JunosWebAppSecure) NAT IntrusionDeception Caching DDoS vCPE SSLGW Video Conf. … DPI Analytics WAN Opt. CDN Virtual SBC Juniper Services 3rdParty Services FWIDP •Anything !! User DefinedNetworks Centralized Cloud Data Centers GW Router MOBILE Physical Network BUSINESS CUSTOMER VMs / NFV VMs / NFV NFV NFV Edge Clouds MX 3D Portal
  • 6. Scripts SyslogServer Web Portal REST/JSON API Block Architecture –creating a Service Instance OpenStackControler ContrailController JunosSpace/ Security Director CreatingService Instance
  • 7. Scripts SyslogServer Web Portal REST/JSON API OpenStackControler ContrailController JunosSpace/ Security Director AddingFireflyto Space Bind predefinedpolicy (WF/Appsec/AV) Block Architecture-adding Firefly Perimeter to Security Director
  • 8. Scripts SyslogServer Web Portal REST/JSON API OpenStackControler ContrailController JunosSpace/ Security Director Requestinfo to drawstatistics Block Architecture –LoggingSystem
  • 9. GW Router MOBILE Physical Network BUSINESS VMs / NFV VMs / NFV NFV NFV Edge Clouds MX 3D eBGP Centralized Cloud Data Centers
  • 10. Centralized Cloud Data Centers GW Router MOBILE Physical Network BUSINESS VMs / NFV VMs / NFV NFV NFV Edge Clouds MX 3D eBGP Reports
  • 11. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE CONTRAIL ELEMENTS
  • 12. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE BGP (XMPP) BGP
  • 13. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE 1.CREATE VN NET#1 , ROUTE TARGET ASN:10000 VRF #1 RT ASN:10000 2.CREATE VM#1 in NET#1 3. VM #1 HOST ROUTE RT ASN:10000 4. ADVERTISE VM#1 HOST ROUTE with RT ASN:10000, NH > COMPUTE NODE 5. DYNAMIC GRE 6. INSTALL VM#1 HOST ROUTE in VRF#1 ROUTE ADVERTISE BETWEEN MPLS NETWORK AND CONTRAIL
  • 14. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAIL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE 1.CREATE vSRXSERVICE INSTANCE IFL #1 WAN NETWORK IFL #2 LAN NETWORK IFL #3 MGMT NETWORK VRF WAN RT ASN:66600666 2. VM vSRXHOST ROUTE RT ASN:66600666 3. ADVERTISE vSRXHOST ROUTES 6. INSTALL vSRXHOST ROUTES in VRFs VRF CUSTOMER #1 RT ASN:10001 VRF CARRIER MGMT RT ASN:950001 2. VM vSRXHOST ROUTE RT ASN:10001 2. VM vSRXHOST ROUTE RT ASN:950001 CREATING vSRX SERVICE INSTANCE
  • 15. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE VRF WAN RT ASN:66600666 WAN. 0/0 -> WAN GW (CONTRAIL) VRF CUSTOMER #1 RT ASN:10001 VRF CARRIER MGMT RT ASN:950001 LAN BGP SESSION TERMINATED on MX CONNECTING vSRX SERVICE INSTANCE TO INFRASTRUCTURE MGMT 10.10.100/24 -> MGMT GW (CONTRAIL) ADVERTISE -> CUSTOMER ROUTE FROM VRF ADVERTISE -> 0/0 to MX VRF (BY CONTRAIL NOTvSRX)
  • 16. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE VRF WAN RT ASN:66600666 VRF CUSTOMER #1 RT ASN:10001 VRF CARRIER MGMT RT ASN:950001 PRECONFIGURING vSRXSERVICE INSTANCE TO NEW ROLE DISOVER NEW vSRX Security Director PRECONFIGURE PROFILE ROLE(NGFW/WEB-FILTERING ETC)
  • 17. MX GATEWAY CONTRAIL vROUTER xe-2/0/0.96 10.10.96.253 CONTRAL/OPENSTACK CONTROLER CONTRAL/OPENSTACK COMPUTE NODE VRF WAN RT ASN:66600666 VRF CARRIER MGMT RT ASN:950001 VRF CUSTOMER #1 RT ASN:10001 FLOW FROM CUSTOMER IN VRF FIREWALL/APPLICATION VISIBILITY/WEB FILTERING/AV
  • 18. Q & A