NEW NETWORK DAY.
КЛЮЧЕВЫЕ ТЕНДЕНЦИИ ОТРАСЛИ
В ПОСЛЕДНЕЕ ВРЕМЯ.
Moscow, 1st April 2014
Uwe Richter, SE Director RESE
2 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
WHAT IS HOT IN 2014 ?
SDN M2M LTE Cloud
NFV
Whatsapp
3 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
Network Function Virtualization (NFV)
4 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
EVOLUTION OF VALUE ADDED SERVICES
IN OPERATOR NETWORKS
L3 Network Services
• Business Edge (L3VPN)
• Consumer Edge (Broadband)
• Mobile
Value Added Services
• Physical L4-L7 Services
• Security (Firewall, IDS, IPS, ...)
• Optimization (Caching, WAN Acc, ...)
• Other services (IMS, EPC, ...)
Virtualize Services
• Introduce NFV and SDN
• Reduce cost
• Increase agility
Contrail
Firefly
MX
SRX
MS-DPC
SCG
5 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
HOW THE OPERATORS SEE IT – EXTRACT FROM THE
PAPER - QUOTE:-
“Network Functions Virtualisation aims to address these problems by
leveraging standard IT virtualisation technology to consolidate many
network equipment types onto industry standard high volume servers,
switches and storage, which could be located in Datacentres, Network
Nodes and in the end user premises. We believe Network Functions
Virtualisation is applicable to any data plane packet processing and
control plane function in fixed and mobile network infrastructures.
We would like to emphasise that we see Network Functions
Virtualisation as highly complementary to Software Defined Networking
(SDN). These topics are mutually beneficial but are not dependent on
each other. Network Functions can be virtualised and deployed without
an SDN required and vice-versa.”
6 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
Service Chain
DPIDPI DPIDPIDPIDPIDPI
NFV + SDN
Juniper and Third Party Virtual Network Functions
NFV: virtualize network functions
Firewall IDPCache
Contrail Service Chaining
SDN: dynamically program network to create service chains
NATAnchor
Router
7 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
Juniper's NFV Implementation:
Contrail and VNFs
8 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL USE CASES
Public Cloud
Private Cloud Private Cloud
VPN VPN
WAN
Gateway
Access
Core
Cloud : Network Virtualization
• Private Clouds, Public Cloud, and Virtual Private Cloud
• Network Virtualization
• Tenant and Application Policies
• Network Function Virtualization and Service chaining
• Rich Analytics
Cloud : Interconnect
• Connect Private Cloud to Private Cloud (DCI)
• Connect Private Cloud to Public Cloud (bursting)
• Connect Campus to Private Cloud
Network Function Virtualization
• Virtualize Network Functions
• Service Chaining
• Attach Service Chain to Physical Network
• Application-Aware and Subscriber-Aware Steering
• Rich analytics
9 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL USE CASES
Access
Core
Network Function Virtualization
• Virtualize Network Functions
• Service Chaining
• Attach Service Chain to Physical Network
• Application-Aware and Subscriber-Aware Steering
• Rich analytics
Topic of today's presentation:
NFV Use Cases
Same technology as Cloud use cases
Tightly integrated with Cloud use cases
10 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL FUNCTION:
VIRTUAL NETWORKS
Virtual Networks
Provide isolation tenants, applications, or tiers within an application.
Physical location of virtual machine independent from logical location.
VM VM VM
Green
Virtual Network
VM VM VM
Red
Virtual Network
VM VM
Blue
Virtual Network
Bare
Metal
Server
11 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL FUNCTION:
VIRTUAL NETWORK POLICIES
Virtual Network Policies
At a high level of abstraction, applied at the boundaries of virtual networks.
VM VM VM
Green
Virtual Network
VM VM VM
Red
Virtual Network
Policy
only HTTP
NAT
12 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL FUNCTION:
SERVICE CHAINS FOR DATA CENTER TENANTS
Service Chaining
Policy based application of virtual and physical services with scale-out.
Firewall, Intrusion Prevention, Load balancer, Cache, WAN optimizer, proxy, ...
VM VM VM
Green
Virtual Network
VM VM VM
Red
Virtual Network
Virtual
Service
IDS
Virtual
Service
Cache
Physical
Service
Firewall
Policy
only HTTP
NAT + IDS + Cache + Firewall
13 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL FUNCTION:
SERVICE CHAINS FOR SERVICE PROVIDER NETWORKS
Access
Core
Business
Consumer
Broadband
Mobile
"Anchor" Service Chain
to Edge Router
Edge Router
14 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CUSTOMER-SPECIFIC NFVS AND SERVICE CHAINS
COMMON FOR BUSINESS EDGE
Access
MPLS Core
Business
MPLS L3VPN
Service
PE Router
Separate
Service Chain and VNFs
for each customer.
Customer 1
Customer 2
Customer 3
15 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
MULTI-TENANT NFVS AND SERVICE CHAINS
COMMON FOR CONSUMER / SOHO EDGE (WIRELINE AND MOBILE)
Access
MPLS Core
Subscriber-aware
Application-aware
Policy-driven
Steering
Scale-out multi-tenant
Service Chains and NFVs
"Gold" Service
"Silver" Service
16 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
DYNAMIC STEERING
PCRF
Contrail
Controller
SCG
Policies
Thousands per second
Data Packets
Millions per second
Service Chains
New: once per month
Scale-out: once per day
17 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL SERVICE CHAIN IMPLEMENTATION
WITHIN THE CLOUD
VM
G1
VM
G2
VM
G3
Green
Virtual Network
VM
R1
VM
R2
VM
R3
Red
Virtual Network
Contrail
Controller
VM
G
VM
R
XMPP
CloudStack
OpenStack
18 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL SERVICE CHAIN IMPLEMENTATION
FOR THE BUSINESS EDGE
Contrail
Controller
OpenStack
CloudStack
BGP + Netconf
XMPP
19 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
CONTRAIL SERVICE CHAIN IMPLEMENTATION
IN THE GI-LAN WITH SERVICE STEERING
GGSN / PGW
SCG / TDF
PCRF
Contrail
Controller
OpenStack
CloudStack
Subscriber Awareness
Layer 3-7 Classification
Steering Capabilities
20 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
SERVICE CHAIN SCALE-OUT
Note: for simplicity, this example shows each service-instance on a separate compute node. In reality a single compute node can host multiple service instances.
Service Chain "Width"
Service Chain "Length"
For scale-out
Width varies per step
Can be changed using API
Dynamic in future
For functionality
Can be changed using API
Currently only transparent
services support length > 1
21 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
SCALE-OUT AND LOAD BALANCING
load balancing in
Physical Router
load balancing as
Virtual Service
load balancing in
vRouter
Mechanisms
ECMP
Flow Tables
Consistent Hashing
Challenges
Scale and performance
Stickiness
Symmetry
22 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
JUNIPER VIRTUAL SERVICE ENABLERS
CURRENT AND PLANNED
Firefly Perimeter
Firefly Host
DDoS Secure
WebApp Secure
Pulse Secure Access
Pulse AUC Secure
Secure Analytics
Content Encore
Policy Control
Subscriber Aware
Web Aware
VM Firewall and Connectivity
Kernel Firewall and Visibility
Distribution Denial of Service Prevention
Web Application Security
SSL VPN
Unified Access Control
System Event and Log Correlation
Content Caching
Application-Aware Service Steering (on SDG with DPI)
Subscriber-Aware Service Steering (on SDG with PCRF / RADIUS)
HTTP Header Enrichment and Redirection (on service cards)
SERVICES FROM OTHER VENDORS (PARTNER OR NOT) ARE ALSO SUPPORTED
23 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
Orchestration and Analytics
24 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
GOAL: CUSTOMER SELF-SERVICE PORTAL
WITH FULLY AUTOMATED BACK-END
25 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
REST APIS
FOR AUTOMATING THE BACK-END WORK-FLOW
Configuration
Nodes
Analytics
Nodes
REST APIs
Contrail Controller
Service Data Model
High Level of Abstraction
Generates
Contrail GUI Orchestrators
26 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
WHAT PART OF THE PROBLEM DOES CONTRAIL SOLVE?
GGSN / PGW
SDG / TDF
PCRF
Contrail
Controller
OpenStack
CloudStack
Manage
Service Chains
Manage
Virtual Machines
REST APIs
REST APIs
27 Copyright © 2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014
THE ROLE OF END-TO-END ORCHESTRATION
Cloud
Management
System
OpenStack
CloudStack
Server
Management
System
Puppet
Chef
VNF Element
Management
System
Space
Security Director
Data Center
SDN Controller
Contrail
Network
Management
System
Space
Network Director
WAN
Controller
NorthStar
WANDL
End-to-End Orchestration
Service
Deployment
Workflow
Self-Service Portal BSS OSS
Access Edge Service Center / Data Center Core
APIs
Ключевые тенденции отрасли в последнее время

Ключевые тенденции отрасли в последнее время

  • 1.
    NEW NETWORK DAY. КЛЮЧЕВЫЕТЕНДЕНЦИИ ОТРАСЛИ В ПОСЛЕДНЕЕ ВРЕМЯ. Moscow, 1st April 2014 Uwe Richter, SE Director RESE
  • 2.
    2 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 WHAT IS HOT IN 2014 ? SDN M2M LTE Cloud NFV Whatsapp
  • 3.
    3 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 Network Function Virtualization (NFV)
  • 4.
    4 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 EVOLUTION OF VALUE ADDED SERVICES IN OPERATOR NETWORKS L3 Network Services • Business Edge (L3VPN) • Consumer Edge (Broadband) • Mobile Value Added Services • Physical L4-L7 Services • Security (Firewall, IDS, IPS, ...) • Optimization (Caching, WAN Acc, ...) • Other services (IMS, EPC, ...) Virtualize Services • Introduce NFV and SDN • Reduce cost • Increase agility Contrail Firefly MX SRX MS-DPC SCG
  • 5.
    5 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 HOW THE OPERATORS SEE IT – EXTRACT FROM THE PAPER - QUOTE:- “Network Functions Virtualisation aims to address these problems by leveraging standard IT virtualisation technology to consolidate many network equipment types onto industry standard high volume servers, switches and storage, which could be located in Datacentres, Network Nodes and in the end user premises. We believe Network Functions Virtualisation is applicable to any data plane packet processing and control plane function in fixed and mobile network infrastructures. We would like to emphasise that we see Network Functions Virtualisation as highly complementary to Software Defined Networking (SDN). These topics are mutually beneficial but are not dependent on each other. Network Functions can be virtualised and deployed without an SDN required and vice-versa.”
  • 6.
    6 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 Service Chain DPIDPI DPIDPIDPIDPIDPI NFV + SDN Juniper and Third Party Virtual Network Functions NFV: virtualize network functions Firewall IDPCache Contrail Service Chaining SDN: dynamically program network to create service chains NATAnchor Router
  • 7.
    7 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 Juniper's NFV Implementation: Contrail and VNFs
  • 8.
    8 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL USE CASES Public Cloud Private Cloud Private Cloud VPN VPN WAN Gateway Access Core Cloud : Network Virtualization • Private Clouds, Public Cloud, and Virtual Private Cloud • Network Virtualization • Tenant and Application Policies • Network Function Virtualization and Service chaining • Rich Analytics Cloud : Interconnect • Connect Private Cloud to Private Cloud (DCI) • Connect Private Cloud to Public Cloud (bursting) • Connect Campus to Private Cloud Network Function Virtualization • Virtualize Network Functions • Service Chaining • Attach Service Chain to Physical Network • Application-Aware and Subscriber-Aware Steering • Rich analytics
  • 9.
    9 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL USE CASES Access Core Network Function Virtualization • Virtualize Network Functions • Service Chaining • Attach Service Chain to Physical Network • Application-Aware and Subscriber-Aware Steering • Rich analytics Topic of today's presentation: NFV Use Cases Same technology as Cloud use cases Tightly integrated with Cloud use cases
  • 10.
    10 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL FUNCTION: VIRTUAL NETWORKS Virtual Networks Provide isolation tenants, applications, or tiers within an application. Physical location of virtual machine independent from logical location. VM VM VM Green Virtual Network VM VM VM Red Virtual Network VM VM Blue Virtual Network Bare Metal Server
  • 11.
    11 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL FUNCTION: VIRTUAL NETWORK POLICIES Virtual Network Policies At a high level of abstraction, applied at the boundaries of virtual networks. VM VM VM Green Virtual Network VM VM VM Red Virtual Network Policy only HTTP NAT
  • 12.
    12 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL FUNCTION: SERVICE CHAINS FOR DATA CENTER TENANTS Service Chaining Policy based application of virtual and physical services with scale-out. Firewall, Intrusion Prevention, Load balancer, Cache, WAN optimizer, proxy, ... VM VM VM Green Virtual Network VM VM VM Red Virtual Network Virtual Service IDS Virtual Service Cache Physical Service Firewall Policy only HTTP NAT + IDS + Cache + Firewall
  • 13.
    13 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL FUNCTION: SERVICE CHAINS FOR SERVICE PROVIDER NETWORKS Access Core Business Consumer Broadband Mobile "Anchor" Service Chain to Edge Router Edge Router
  • 14.
    14 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CUSTOMER-SPECIFIC NFVS AND SERVICE CHAINS COMMON FOR BUSINESS EDGE Access MPLS Core Business MPLS L3VPN Service PE Router Separate Service Chain and VNFs for each customer. Customer 1 Customer 2 Customer 3
  • 15.
    15 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 MULTI-TENANT NFVS AND SERVICE CHAINS COMMON FOR CONSUMER / SOHO EDGE (WIRELINE AND MOBILE) Access MPLS Core Subscriber-aware Application-aware Policy-driven Steering Scale-out multi-tenant Service Chains and NFVs "Gold" Service "Silver" Service
  • 16.
    16 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 DYNAMIC STEERING PCRF Contrail Controller SCG Policies Thousands per second Data Packets Millions per second Service Chains New: once per month Scale-out: once per day
  • 17.
    17 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL SERVICE CHAIN IMPLEMENTATION WITHIN THE CLOUD VM G1 VM G2 VM G3 Green Virtual Network VM R1 VM R2 VM R3 Red Virtual Network Contrail Controller VM G VM R XMPP CloudStack OpenStack
  • 18.
    18 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL SERVICE CHAIN IMPLEMENTATION FOR THE BUSINESS EDGE Contrail Controller OpenStack CloudStack BGP + Netconf XMPP
  • 19.
    19 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 CONTRAIL SERVICE CHAIN IMPLEMENTATION IN THE GI-LAN WITH SERVICE STEERING GGSN / PGW SCG / TDF PCRF Contrail Controller OpenStack CloudStack Subscriber Awareness Layer 3-7 Classification Steering Capabilities
  • 20.
    20 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 SERVICE CHAIN SCALE-OUT Note: for simplicity, this example shows each service-instance on a separate compute node. In reality a single compute node can host multiple service instances. Service Chain "Width" Service Chain "Length" For scale-out Width varies per step Can be changed using API Dynamic in future For functionality Can be changed using API Currently only transparent services support length > 1
  • 21.
    21 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 SCALE-OUT AND LOAD BALANCING load balancing in Physical Router load balancing as Virtual Service load balancing in vRouter Mechanisms ECMP Flow Tables Consistent Hashing Challenges Scale and performance Stickiness Symmetry
  • 22.
    22 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 JUNIPER VIRTUAL SERVICE ENABLERS CURRENT AND PLANNED Firefly Perimeter Firefly Host DDoS Secure WebApp Secure Pulse Secure Access Pulse AUC Secure Secure Analytics Content Encore Policy Control Subscriber Aware Web Aware VM Firewall and Connectivity Kernel Firewall and Visibility Distribution Denial of Service Prevention Web Application Security SSL VPN Unified Access Control System Event and Log Correlation Content Caching Application-Aware Service Steering (on SDG with DPI) Subscriber-Aware Service Steering (on SDG with PCRF / RADIUS) HTTP Header Enrichment and Redirection (on service cards) SERVICES FROM OTHER VENDORS (PARTNER OR NOT) ARE ALSO SUPPORTED
  • 23.
    23 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 Orchestration and Analytics
  • 24.
    24 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 GOAL: CUSTOMER SELF-SERVICE PORTAL WITH FULLY AUTOMATED BACK-END
  • 25.
    25 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 REST APIS FOR AUTOMATING THE BACK-END WORK-FLOW Configuration Nodes Analytics Nodes REST APIs Contrail Controller Service Data Model High Level of Abstraction Generates Contrail GUI Orchestrators
  • 26.
    26 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 WHAT PART OF THE PROBLEM DOES CONTRAIL SOLVE? GGSN / PGW SDG / TDF PCRF Contrail Controller OpenStack CloudStack Manage Service Chains Manage Virtual Machines REST APIs REST APIs
  • 27.
    27 Copyright ©2014 Juniper Networks, Inc. Presented at Juniper New Network Day in Moscow , 1st April 2014 THE ROLE OF END-TO-END ORCHESTRATION Cloud Management System OpenStack CloudStack Server Management System Puppet Chef VNF Element Management System Space Security Director Data Center SDN Controller Contrail Network Management System Space Network Director WAN Controller NorthStar WANDL End-to-End Orchestration Service Deployment Workflow Self-Service Portal BSS OSS Access Edge Service Center / Data Center Core APIs