UCL Data Centres
Infrastructure Design
James Clements
Emma Cardinal-Richards
Areas Covered
• Background
• Design Process
• Routing and Site Connectivity
• Application Delivery Controllers
• Switching
• Storage
• Security
Background
• Extensive dark fibre network
• One logical data centre
• Simplicity for applications
• Stretched failure
Design Process
• Requirements Gathering
• Current State
• Vision
• Plan
• Design Validation
• Business Validation
The White Paper: Key elements
• Active-Active
• Disaster Recovery
• No Cross DC Dependency
• Symmetric architecture where possible
• Auto-failover where possible
• Converged Networking where available
Campus
Network
Routing
(Logical)
Routing
(Physical)
SLB Current State
• Cisco Application Control Engine Service Modules
Application Delivery Controllers
• Essential for multi-site data centres
• PoC market leaders
• F5 solution selected
Future State - GSLB
• DNS-Based multi-site
load balancing
• Active/Active
• Client location
• Load distribution
• Site failover
Future State - SLB
• No need to use the
ADC to route
• Service
optimisations
• Delegated
administration
Switching
Current State
Switching –
Production Design
• Leaf Spine Architecture
• Nexus 5K
• Fabricpath
• VPC+
• Dynamic FCoE
• New (but familiar) VM hosting platform
• New (but familiar) storage platform
• Decoupling the DCs
• Partially new software stack
Torrington Place 1 Wolfson House SloughTorrington Place #
Infrastructure Platform Vision
Storage Area Networking (SAN)
• Converged Networking (FCoE)
• Collaborative working
• Keeping existing storage design concepts
• Dynamic FCoE over FabricPath
• SANs existing within 1 Data Centre
• Cisco Data Centre Network Manager
Security from a ISG view
Security –
Network Style
Security Zones
Simplified!
FIREWALL
INTERNET
DATACENTRE
CAMPUS
RESEARCH
FIREWALL
INTERNET
DATACENTRE
CAMPUS
RESEARCH
SLOUGH
TORRINGTON
PLACE
Standardised Service Design
• Separate IP space per datacentre for both IPv4 and
IPv6
• Symmetrical networks
• Standardisation
• Layered application design
• Security
Service Layers
Presentation Layer
Application Layer
Additional Service Layer
Data Layer
Clients/ExternalAccess
Blockedbyfirewallbydefault
ManagementLayer
VPN
ApplicationDeliveryController
Client Traffic Service Traffic (direct or load balanced) Management TrafficKey
Current Layer New
Applications
Ad-hoc ACLs Network Security Firewall, ACLs, Zoned, Secured
Application specific, secured by
application, complex
Networking Layout Standard, Secure by Design, IPv6 Ready,
Consistent
Not Required Global Server Load Balancing (GSLB) F5 BigIP GTM
Cisco ACE Server Load Balancing (SLB) F5 BigIP LTM
Split HA/BH Stacks, Non-representative
Development
Hardware Stacks Single Converged Stack, Representative
Development
VMware vSphere ESXi Virtualisation VMware vSphere ESXi
VMware vSphere ESXi Virtual Mobility SRM or Zerto or Veeam
Not Used Virtualisation Insights VMware Operations Manager
IBM HS22/23 Blades in BladeCentre-H Virtualisation Hardware Lenovo x240 Blades in Flex Chassis
Separate Ethernet/Storage Network Interconnect Converged Network Adaptors
IBM DS5100/v7000 G1/SVC Storage IBM v7000 G2/SVC
Synchronous Everywhere Storage Replication Asynchronous
IBM/Brocade Fibre Channel SAN Storage Networking Cisco Nexus Converged
Cisco Catalyst Ethernet Networking Cisco Nexus Converged Network
One Logical Site across Two Physical Physical Location Two Distinct Physical Sites
Physical Data Centres
</presentation>
• Thanks to all the (uncredited!) people from whom we
have ‘borrowed’ drawings, photos etc.
• Even more thanks to all at JISC/Janet and Infinity who
have been very understanding and accommodating of
our shifting requirements and sometimes unusual
requests.
Contact
James Clements
Network Core Services Manager
james.clements@ucl.ac.uk
Emma Cardinal-Richards
Senior Network Architect
e.cardinal-richards@ucl.ac.uk

Data networking at UCL - Networkshop44

  • 1.
    UCL Data Centres InfrastructureDesign James Clements Emma Cardinal-Richards
  • 2.
    Areas Covered • Background •Design Process • Routing and Site Connectivity • Application Delivery Controllers • Switching • Storage • Security
  • 3.
    Background • Extensive darkfibre network • One logical data centre • Simplicity for applications • Stretched failure
  • 4.
    Design Process • RequirementsGathering • Current State • Vision • Plan • Design Validation • Business Validation
  • 5.
    The White Paper:Key elements • Active-Active • Disaster Recovery • No Cross DC Dependency • Symmetric architecture where possible • Auto-failover where possible • Converged Networking where available
  • 6.
  • 7.
  • 8.
  • 9.
    SLB Current State •Cisco Application Control Engine Service Modules Application Delivery Controllers • Essential for multi-site data centres • PoC market leaders • F5 solution selected
  • 10.
    Future State -GSLB • DNS-Based multi-site load balancing • Active/Active • Client location • Load distribution • Site failover
  • 11.
    Future State -SLB • No need to use the ADC to route • Service optimisations • Delegated administration
  • 12.
  • 13.
    Switching – Production Design •Leaf Spine Architecture • Nexus 5K • Fabricpath • VPC+ • Dynamic FCoE
  • 14.
    • New (butfamiliar) VM hosting platform • New (but familiar) storage platform • Decoupling the DCs • Partially new software stack Torrington Place 1 Wolfson House SloughTorrington Place # Infrastructure Platform Vision
  • 15.
    Storage Area Networking(SAN) • Converged Networking (FCoE) • Collaborative working • Keeping existing storage design concepts • Dynamic FCoE over FabricPath • SANs existing within 1 Data Centre • Cisco Data Centre Network Manager
  • 16.
  • 17.
  • 18.
  • 19.
    Standardised Service Design •Separate IP space per datacentre for both IPv4 and IPv6 • Symmetrical networks • Standardisation • Layered application design • Security
  • 20.
    Service Layers Presentation Layer ApplicationLayer Additional Service Layer Data Layer Clients/ExternalAccess Blockedbyfirewallbydefault ManagementLayer VPN ApplicationDeliveryController Client Traffic Service Traffic (direct or load balanced) Management TrafficKey
  • 21.
    Current Layer New Applications Ad-hocACLs Network Security Firewall, ACLs, Zoned, Secured Application specific, secured by application, complex Networking Layout Standard, Secure by Design, IPv6 Ready, Consistent Not Required Global Server Load Balancing (GSLB) F5 BigIP GTM Cisco ACE Server Load Balancing (SLB) F5 BigIP LTM Split HA/BH Stacks, Non-representative Development Hardware Stacks Single Converged Stack, Representative Development VMware vSphere ESXi Virtualisation VMware vSphere ESXi VMware vSphere ESXi Virtual Mobility SRM or Zerto or Veeam Not Used Virtualisation Insights VMware Operations Manager IBM HS22/23 Blades in BladeCentre-H Virtualisation Hardware Lenovo x240 Blades in Flex Chassis Separate Ethernet/Storage Network Interconnect Converged Network Adaptors IBM DS5100/v7000 G1/SVC Storage IBM v7000 G2/SVC Synchronous Everywhere Storage Replication Asynchronous IBM/Brocade Fibre Channel SAN Storage Networking Cisco Nexus Converged Cisco Catalyst Ethernet Networking Cisco Nexus Converged Network One Logical Site across Two Physical Physical Location Two Distinct Physical Sites Physical Data Centres
  • 22.
    </presentation> • Thanks toall the (uncredited!) people from whom we have ‘borrowed’ drawings, photos etc. • Even more thanks to all at JISC/Janet and Infinity who have been very understanding and accommodating of our shifting requirements and sometimes unusual requests.
  • 23.
    Contact James Clements Network CoreServices Manager james.clements@ucl.ac.uk Emma Cardinal-Richards Senior Network Architect e.cardinal-richards@ucl.ac.uk