ECI Proprietary
VIRTUAL CPE –
CHALLENGES AND
PATHS FORWARD
Hayim Porat
ECI CTO
ECI Telecom Proprietary and Confidential 2ECI Proprietary 2
NFV PROMISE
 NFV value already proven in
data centers
 Expected to speed past SDN
in terms of CSP network
deployment
 But lot’s remains to be done
NFV
From Gartner Hype Cycle for Communications
Service Provider Infrastructure, August 2015
SDN
Plateau in CSP networks reached in:
2-5 years 5-10 years
Today’s Discussion:
v-CPE use case
ECI Telecom Proprietary and Confidential 3ECI Proprietary 3
PHYSICAL CPE (P-CPE)
 Network functions for
interworking enterprise
LANs across the WAN
 Demarcation, routing, VPN,
NAT, WAN optimization,
security, etc.
 Implemented physically at
customer premises using
multiple dedicated
appliances
Service Provider or
Cloud NetworkP-CPE
4 4ECI Proprietary 4
VIRTUAL CPE (V-CPE) AT
CUSTOMER PREMISES
 Implements physical CPE
functions in software (VNFs) on
a standard commercial server
 Consolidates functionality
facilitating mgmt and upgrades
 Some functions need to
persist in legacy P-CPE
 Does not provide benefits of
cloud-based virtualization
P-CPE
V-CPE
Virtual network
functions (VNFs)
of physical CPE
Service Provider
or Cloud Network
5 5ECI Proprietary 5
CLOUD-BASED V-CPE
 VNFs implemented anywhere
between the customer premises
and remote data centers
 Provides cloud implementation
benefits:
 Elastic use of shared
resources
 Statistical multiplexing
 New services models
 Virtualization based on ETSI
NFV framework
P-CPE
V-CPEVirtual network
functions (VNFs)
of physical CPE
Service Provider
or Cloud Network
May be 100’s of km apart
ECI Telecom Proprietary and Confidential 6ECI Proprietary 6
ANTICIPATED
BENEFITS OF V-CPE
 Service providers – New
revenue streams
 Enterprises – Outsourcing
and simplification
 Other:
 Lower equipment costs
 Eliminate truck rolls
 Best of breed applications
 Customization
 Continuous updates
ECI Telecom Proprietary and Confidential 7ECI Proprietary 7
YET HEADWINDS
EXIST
 Virtualization issues
• Functional distribution
• Management complexity
 NFV issues
• Performance
• Energy
 Link issues
• Traffic Tromboning
• Security
• Latency
ECI Telecom Proprietary and Confidential 8ECI Proprietary 8
FUNCTIONAL DISTRIBUTION
NATURAL CUSTOMER PREMISES FUNCTIONS
 Termination point
 Enterprise network monitoring
 L2 forwarding
 Access link encryption
 Ethernet access
 Wireless LAN
 WAN load balancing
 WAN optimizationP-CPE
V-CPE
ECI Telecom Proprietary and Confidential 9ECI Proprietary 9
V-CPE
Service Provider
or Cloud Network
Routing and
multicast
Session
border control
NAT and/or
DHCP
IPsec Security
(firewalls, DPI,
DDOS, etc)
Configuration
management
Performance
monitoring and
logging
VoIP (PBX)
Value added
business services
Caching
FUNCTIONAL DISTRIBUTION
WAN LOCATABLE FUNCTIONS
ECI Telecom Proprietary and Confidential 10ECI Proprietary 10
MANY FUNCTIONAL DISTRIBUTION DECISIONS
Service Provider
or Cloud Network
P-CPE
V-CPE V-CPE
WAN Locatable Functions
 Routing and multicast
 Session border control
 NAT and/or DHCP
 L2 and L3 VPN
 IPsec
 Security (firewalls, DPI, DDOS, etc)
 Configuration management
 Performance monitoring and logging
 VoIP (PBX)
 Value added business services
 Caching
Natural Customer Premises Functions
 Termination point
 Enterprise network monitoring
 L2 forwarding
 Access link encryption
 Ethernet access
 Wireless LAN
 WAN load balancing
 WAN optimization
Virtual or physical?
Virtual at CP or
within WAN?
Customer
Portal
NFV MANO
EMS
NMS
OSS
Local
Mgmt
ECI Telecom Proprietary and Confidential 11ECI Proprietary 11
ADD MANAGEMENT COMPLEXITY
Service Provider
or Cloud NetworkP-CPE
V-CPE
V-CPE
WAN Locatable
Functions
Natural Customer
Premises Functions
NFVi
Manager
VNF
Manager
Orches-
trator
ECI Proprietary 12
NFV ISSUES
PLATFORM VERSUS APPLIANCE
General purpose vs.
dedicated appliances
Input/output
processing
Power
consumption
 FW throughput
about 10 Gbps
 600W
 FW throughput
60 Gbps
 250W
SW licensing
costs
ECI Telecom Proprietary and Confidential 13ECI Proprietary 13
CHEAPER YES? BUT HOW MANY
X =?
ECI Telecom Proprietary and Confidential 14ECI Proprietary 14
BUSINESS CASE CONSIDERATION
COST OF ENERGY
Annual Energy cost (assume 1000 servers)
= 1000 x 0.5kW x $0.1/kWh x 24 x 365
= $0.5M/year
Significant costs moving from
businesses to the carrier
X
=
?
ECI Proprietary 15
P-CPE
1. Cleartext
2. Service provider
IPSec Tunnel
4. User’s
encrypted traffic
Service
Provider or
Cloud Network
3. IPsec decryption,
vCPE processing,
User encryption
 vCPE needs cleartext to
process data
 However the medium
between the CP and
cloud is unprotected
 Hence both user
encryption and tunnel
encryption is required
 Doubles processing and
energy costs
LINK ISSUES
V-CPE
V-CPE
ECI Proprietary 16
P-CPE
V-CPE
Service Provider
or Cloud Network
V-CPE
 Can occur frequently
• DHCP
• DNS
• AAA
 Creates link congestion
 Can add many 10s of
ms to transactions
LINK ISSUES
TROMBONING AND
LATENCY
ECI Proprietary 17
SO HOW DO WE
BEST LAUNCH
THE GOOD SHIP
V-CPE?
ECI Telecom Proprietary and Confidential 18ECI Proprietary 18
SOME STEPS TO
CONSIDER
 NFV acceleration
 NFV at the network edge
 Hyper-converged cloud
ECI Telecom Proprietary and Confidential 19ECI Proprietary 19
NFV ACCELERATION
 Supplement NFV for intensive
input/output or other processing
tasks not best suited to general
purpose computing
 Create a hybrid device with best
of both worlds
 Optimize for first cost and
energy costs
 Optional add-on only when
needed
ECI Telecom Proprietary and Confidential 20ECI Proprietary 20
NFV TO THE NETWORK
EDGE
 Reduces latency
 Limits tromboning to the last
mile
 Also a platform for edge
computing services (e.g.
MEC, IoT, M2M, AR)
Service Provider
or Cloud Network
P-CPE
V-CPE
Move NFV from anywhere in the
network or cloud, to as close as
possible to the network edge
V-CPE
V-CPE
ECI Telecom Proprietary and ConfidentialECI Proprietary 21
HYPER CONVERGED
CLOUD
 Strong fit with distributed
network edge computing
 Eases complexity through
local plus hierarchical
management
Servers Storage Network Management Security Facilities Services
Converged Infrastructure
Compute
Storage
Networking
Intelligence
Virtual Machine
ECI Proprietary 22
 Multiple platforms for best
application fit
 Neptune packet transport
system integrated blade
 Stand-alone module
 I/O acceleration
 Library of best of breed VNFs
 Fully hyper converged cloud
platform based on
OpenStack
ECI ELASTIC
VIRTUALIZATION
Mercury NFV platforms
ECI Telecom Proprietary and Confidential 23ECI Proprietary 23
“Simplicity is a great virtue but it requires hard work
to achieve it and education to appreciate it. And to
make matters worse: complexity sells better.”
― Edsger W. Dijkstra
ECI Proprietary
THANK YOU!
24

vCPE Challenges and Ways Forward

  • 1.
    ECI Proprietary VIRTUAL CPE– CHALLENGES AND PATHS FORWARD Hayim Porat ECI CTO
  • 2.
    ECI Telecom Proprietaryand Confidential 2ECI Proprietary 2 NFV PROMISE  NFV value already proven in data centers  Expected to speed past SDN in terms of CSP network deployment  But lot’s remains to be done NFV From Gartner Hype Cycle for Communications Service Provider Infrastructure, August 2015 SDN Plateau in CSP networks reached in: 2-5 years 5-10 years Today’s Discussion: v-CPE use case
  • 3.
    ECI Telecom Proprietaryand Confidential 3ECI Proprietary 3 PHYSICAL CPE (P-CPE)  Network functions for interworking enterprise LANs across the WAN  Demarcation, routing, VPN, NAT, WAN optimization, security, etc.  Implemented physically at customer premises using multiple dedicated appliances Service Provider or Cloud NetworkP-CPE
  • 4.
    4 4ECI Proprietary4 VIRTUAL CPE (V-CPE) AT CUSTOMER PREMISES  Implements physical CPE functions in software (VNFs) on a standard commercial server  Consolidates functionality facilitating mgmt and upgrades  Some functions need to persist in legacy P-CPE  Does not provide benefits of cloud-based virtualization P-CPE V-CPE Virtual network functions (VNFs) of physical CPE Service Provider or Cloud Network
  • 5.
    5 5ECI Proprietary5 CLOUD-BASED V-CPE  VNFs implemented anywhere between the customer premises and remote data centers  Provides cloud implementation benefits:  Elastic use of shared resources  Statistical multiplexing  New services models  Virtualization based on ETSI NFV framework P-CPE V-CPEVirtual network functions (VNFs) of physical CPE Service Provider or Cloud Network May be 100’s of km apart
  • 6.
    ECI Telecom Proprietaryand Confidential 6ECI Proprietary 6 ANTICIPATED BENEFITS OF V-CPE  Service providers – New revenue streams  Enterprises – Outsourcing and simplification  Other:  Lower equipment costs  Eliminate truck rolls  Best of breed applications  Customization  Continuous updates
  • 7.
    ECI Telecom Proprietaryand Confidential 7ECI Proprietary 7 YET HEADWINDS EXIST  Virtualization issues • Functional distribution • Management complexity  NFV issues • Performance • Energy  Link issues • Traffic Tromboning • Security • Latency
  • 8.
    ECI Telecom Proprietaryand Confidential 8ECI Proprietary 8 FUNCTIONAL DISTRIBUTION NATURAL CUSTOMER PREMISES FUNCTIONS  Termination point  Enterprise network monitoring  L2 forwarding  Access link encryption  Ethernet access  Wireless LAN  WAN load balancing  WAN optimizationP-CPE V-CPE
  • 9.
    ECI Telecom Proprietaryand Confidential 9ECI Proprietary 9 V-CPE Service Provider or Cloud Network Routing and multicast Session border control NAT and/or DHCP IPsec Security (firewalls, DPI, DDOS, etc) Configuration management Performance monitoring and logging VoIP (PBX) Value added business services Caching FUNCTIONAL DISTRIBUTION WAN LOCATABLE FUNCTIONS
  • 10.
    ECI Telecom Proprietaryand Confidential 10ECI Proprietary 10 MANY FUNCTIONAL DISTRIBUTION DECISIONS Service Provider or Cloud Network P-CPE V-CPE V-CPE WAN Locatable Functions  Routing and multicast  Session border control  NAT and/or DHCP  L2 and L3 VPN  IPsec  Security (firewalls, DPI, DDOS, etc)  Configuration management  Performance monitoring and logging  VoIP (PBX)  Value added business services  Caching Natural Customer Premises Functions  Termination point  Enterprise network monitoring  L2 forwarding  Access link encryption  Ethernet access  Wireless LAN  WAN load balancing  WAN optimization Virtual or physical? Virtual at CP or within WAN?
  • 11.
    Customer Portal NFV MANO EMS NMS OSS Local Mgmt ECI TelecomProprietary and Confidential 11ECI Proprietary 11 ADD MANAGEMENT COMPLEXITY Service Provider or Cloud NetworkP-CPE V-CPE V-CPE WAN Locatable Functions Natural Customer Premises Functions NFVi Manager VNF Manager Orches- trator
  • 12.
    ECI Proprietary 12 NFVISSUES PLATFORM VERSUS APPLIANCE General purpose vs. dedicated appliances Input/output processing Power consumption  FW throughput about 10 Gbps  600W  FW throughput 60 Gbps  250W SW licensing costs
  • 13.
    ECI Telecom Proprietaryand Confidential 13ECI Proprietary 13 CHEAPER YES? BUT HOW MANY X =?
  • 14.
    ECI Telecom Proprietaryand Confidential 14ECI Proprietary 14 BUSINESS CASE CONSIDERATION COST OF ENERGY Annual Energy cost (assume 1000 servers) = 1000 x 0.5kW x $0.1/kWh x 24 x 365 = $0.5M/year Significant costs moving from businesses to the carrier X = ?
  • 15.
    ECI Proprietary 15 P-CPE 1.Cleartext 2. Service provider IPSec Tunnel 4. User’s encrypted traffic Service Provider or Cloud Network 3. IPsec decryption, vCPE processing, User encryption  vCPE needs cleartext to process data  However the medium between the CP and cloud is unprotected  Hence both user encryption and tunnel encryption is required  Doubles processing and energy costs LINK ISSUES V-CPE V-CPE
  • 16.
    ECI Proprietary 16 P-CPE V-CPE ServiceProvider or Cloud Network V-CPE  Can occur frequently • DHCP • DNS • AAA  Creates link congestion  Can add many 10s of ms to transactions LINK ISSUES TROMBONING AND LATENCY
  • 17.
    ECI Proprietary 17 SOHOW DO WE BEST LAUNCH THE GOOD SHIP V-CPE?
  • 18.
    ECI Telecom Proprietaryand Confidential 18ECI Proprietary 18 SOME STEPS TO CONSIDER  NFV acceleration  NFV at the network edge  Hyper-converged cloud
  • 19.
    ECI Telecom Proprietaryand Confidential 19ECI Proprietary 19 NFV ACCELERATION  Supplement NFV for intensive input/output or other processing tasks not best suited to general purpose computing  Create a hybrid device with best of both worlds  Optimize for first cost and energy costs  Optional add-on only when needed
  • 20.
    ECI Telecom Proprietaryand Confidential 20ECI Proprietary 20 NFV TO THE NETWORK EDGE  Reduces latency  Limits tromboning to the last mile  Also a platform for edge computing services (e.g. MEC, IoT, M2M, AR) Service Provider or Cloud Network P-CPE V-CPE Move NFV from anywhere in the network or cloud, to as close as possible to the network edge V-CPE V-CPE
  • 21.
    ECI Telecom Proprietaryand ConfidentialECI Proprietary 21 HYPER CONVERGED CLOUD  Strong fit with distributed network edge computing  Eases complexity through local plus hierarchical management Servers Storage Network Management Security Facilities Services Converged Infrastructure Compute Storage Networking Intelligence Virtual Machine
  • 22.
    ECI Proprietary 22 Multiple platforms for best application fit  Neptune packet transport system integrated blade  Stand-alone module  I/O acceleration  Library of best of breed VNFs  Fully hyper converged cloud platform based on OpenStack ECI ELASTIC VIRTUALIZATION Mercury NFV platforms
  • 23.
    ECI Telecom Proprietaryand Confidential 23ECI Proprietary 23 “Simplicity is a great virtue but it requires hard work to achieve it and education to appreciate it. And to make matters worse: complexity sells better.” ― Edsger W. Dijkstra
  • 24.