Mobility and Virtualization in the Data Center with LISP and OTV

Size: px
Start display at page:

Download "Mobility and Virtualization in the Data Center with LISP and OTV"

Transcription

1

2 Mobility and Virtualization in the Data Center with LISP and OTV

3 Agenda Mobility and Virtualization in the Data Center Introduction to LISP LISP Data Center Use Cases LAN Extensions: OTV LISP + OTV Deployment Considerations Summary and Conclusion Slides Identified with the Book Icon Are Provided for Your Reference and Will Not Be Part of the Live Presentation 3

4 Distributed Data Centers Building the Data Center Cloud Distributed Data Center Goals Seamless workload mobility Distributed applications Pool and maximize global resources Business Continuity Interconnect Challenges Complex operations Transport dependence IP subnets and mobility Failure containment Geographically Disperse Data Centers 4

5 Connecting Virtualized Data Centers Multi-tenancy/segmentation: Segment-IDs in LISP, FabricPath and OTV OTV IP Mobility: LISP Network Services Elasticity: ACE, GSS, ASA, VSG OTV OTV L2 Domain Elasticity: Inter-DC: OTV/VPLS Intra-DC: vpc, FabricPath, FEX, VXLAN OTV OTV Storage Solutions & Partners: FCIP, Read/write Acceleration EMC, NetApp Location of compute resources is transparent to the user VM-awareness: Port Profiles 5

6 Agenda Mobility and Virtualization in the Data Center Introduction to LISP LISP Data Center Use Cases LAN Extensions: OTV LISP + OTV Deployment Considerations Summary and Conclusion 6

7 Location Identity Separation Protocol What do we mean by Location and Identity IP core Today s IP Behavior Loc/ID Overloaded Semantic When the Device Moves, It Gets a New IPv4 or IPv6 Address for Device IPv4 or IPv6 Its New Identity and Location Address Represents Identity and Location Device IPv4 or IPv6 Address Represents Identity Only. Its Location Is Here! IP core Only the Location Changes LISP Behavior Loc/ID Split When the Device Moves, Keeps Its IPv4 or IPv6 Address. It Has the Same Identity 7

8 A LISP Packet Walk How does LISP operate? 1 DNS Entry: D.abc.com A > > > > /24 LISP Site S ETR West-DC D 3 Mapping Entry ITR /24 EID-prefix: /24 Locator-set: Non-LISP site , priority: 1, weight: 50 (D1) Non-LISP site , priority: 1, weight: 50 (D2) IP Network /24 PITR EID-to-RLOC mapping This Policy Controlled by Destination Site East-DC

9 A LISP Packet Walk How about Non-LISP Sites? 1 DNS Entry: D.abc.com A Non-LISP Site S Non-LISP Site 3 Mapping Entry EID-Prefix: /24 Locator-Set: , priority: 1, weight: 50 (D1) , priority: 1, weight: 50 (D2) > ETR West-DC > D > > /24 IP Network /24 PITR East-DC EID-to-RLOC mapping

10 LISP Roles and Address Spaces What are the Different Components Involved? LISP Roles Tunnel Routers - xtrs Edge devices in charge of encap/decap Ingress/Egress Tunnel Routers (ITR/ETR) Proxy Tunnel Routers - PxTR Coexistence between LISP and non-lisp sites Ingress/Egress: PITR, PETR EID to RLOC Mapping DB Contains RLOC to EID mappings Distributed across multiple Map Servers (MS) MS may connect over an ALT network Non-LISP PxTR Address Spaces EID = End-point Identifier Host IP or prefix RLOC = Routing Locator IP address of routers in the backbone EID Space Prefix w.x.y.1 x.y.w.2 z.q.r.5 z.q.r.5 Next-hop e.f.g.h e.f.g.h e.f.g.h e.f.g.h ITR Mapping DB ETR EID a.a.a.0/24 b.b.b.0/24 c.c.c.0/24 d.d.0.0/16 RLOC w.x.y.1 x.y.w.2 z.q.r.5 z.q.r.5 EID a.a.a.0/24 b.b.b.0/24 c.c.c.0/24 d.d.0.0/16 RLOC Space EID Space EID ALT a.a.a.0/24 b.b.b.0/24 c.c.c.0/24 d.d.0.0/16 RLOC w.x.y.1 x.y.w.2 z.q.r.5 z.q.r.5 RLOC w.x.y.1 x.y.w.2 z.q.r.5 z.q.r.5 10

11 LISP Mapping Database The Basics Registration and Resolution LISP Site ITR Mapping Cache Entry (on ITR): /16-> ( , ) Map Server / Resolver: Map-Reply /16 -> ( , ) Database Mapping Entry (on ETR): /16 -> ( , ) ETR ETR ETR ETR Database Mapping Entry (on ETR): /16 -> ( , ) West-DC East-DC / /16 Y X Y Z

12 LISP Mapping Database Node Resiliency/Clustering Mapping Cache Entry (on ITR): /16-> ( , ) LISP Site ITR No Synchronization Protocol Between Map Servers; ETRs Must Register with All Map Servers Individually; ITRs anycast Map Requests Map-Reply /16 -> ( , ) Map Resolver: (Anycast) Map Server: Mapping DB Map Server: Node Cluster Database Mapping Entry (on ETR): /16 -> ( , ) ETR ETR ETR ETR Database Mapping Entry (on ETR): /16 -> ( , ) West-DC East-DC / /16 Y X Y Z

13 Basic LISP Configuration Servers ip lisp map-resolver ip lisp map-server lisp site west-dc authentication-key 0 s3cr3t eid-prefix /24 Border Routers Between Backbones ip lisp proxy-itr ip lisp ITR map-resolver Non-LISP Sites Branch Routers ip lisp itr-etr ip lisp ITR map-resolver DC Aggregation Routers ip lisp itr-etr ip lisp database-mapping / p1 w50 ip lisp database-mapping / p1 w50 ip lisp ETR map-server key s3cr3t ip lisp ETR map-server key s3cr3t Usually Devices Will Be Configured as ITRs and ETRs to Handle Traffic in Both Directions; We Illustrate Only One Direction for Simplicity LISP Site ITR ETR West-DC /24 RLOC IP Network EID PITR Mapping DB LISP Encap/Decap East-DC 13

14 Location ID/Separation Protocol(LISP) Next Generation Networking Architecture Single Network Architecture Delivers: VM Mobility (topology independent addressing) Security: VPNs/Multi-tenancy Route Scalability (on demand routing) IPv6 enablement, Routing Policy simplification Benefits Services integrated in a single architecture Services can be offered across organizational boundaries (multiple providers) Very large scale Open model to integrate with cloud orchestrators Use-Cases DCI route optimization/mobility Workload Portability to Cloud Secure Multi-tenancy across organizations Rapid IPv6 Deployment Route scaling Making the Network Cloud-Ready 14

15 LISP Use Cases Consolidated Architecture with Multiple Applications Efficient Multi-Homing IPv6 Transition Support LISP Site LISP Routers Internet IP Portability Ingress Traffic Engineering without BGP v6 Services LISP Router v6 IPv4 Internet v4 v6 v6-over-v4, v6-over-v6 v4-over-v6, v4-over-v4 LISP Router v6 IPv6 Internet Multi-Tenancy and VPNs LISP Site Host-Mobility LISP Site IP Network IP Network West-DC East-DC West-DC East-DC Reduced CapEx/OpEx Large scale Segmentation Cloud / Layer 3 VM moves Segmentation 15

16 Agenda Mobility and Virtualization in the Data Center Introduction to LISP LISP Data Center Use Cases Host-Mobility LAN Extensions: OTV LISP + OTV Deployment Considerations Summary and Conclusion 16

17 Moving vs. Distributing Workloads Why do we really need LAN Extensions? Moving Workloads Hypervisor Hypervisor Control Traffic (routable) IP Network Hypervisor Move workloads with IP mobility solutions: LISP Host Mobility IP preservation is the real requirement (LAN extensions not mandatory) Distribute workloads with LAN extensions Application High Availability with Distributed Clusters Distributed App (GeoCluster) OS OS OS Non-IP application traffic (heartbeats) LAN Extension (OTV) 17

18 LISP Host-Mobility Needs: Global IP-Mobility across subnets Optimized routing across extended subnet sites LISP Solution: Automated move detection on XTRs Dynamically update EID-to-RLOC mappings Traffic Redirection on ITRs or PITRs Benefits: Direct Path (no triangulation) Connections maintained across move No routing re-convergence No DNS updates required Transparent to the hosts Global Scalability (cloud bursting) IPv4/IPv6 Support LISP Site XTR LAN Extensions LISP-VM (XTR) West-DC RLOC Non-LISP Sites PXTR Mapping DB IP Network East-DC EID LISP Encap/Decap 18

19 Host-Mobility Scenarios Moves Without LAN Extension Moves With LAN Extension LISP Site XTR Non-LISP Site LISP Site XTR Mapping DB Internet or Shared WAN DR Location or Cloud Provider DC LAN Extension IP Network Mapping DB LISP-VM (XTR) LISP-VM (XTR) West-DC East-DC West-DC East-DC IP Mobility Across Subnets Disaster Recovery Cloud Bursting Routing for Extended Subnets Active-Active Data Centers Distributed Clusters Application Members in One Location Application Members Distributed (Broadcasts across sites) 19

20 LISP Host-Mobility Move Detection Monitor the source of Received Traffic The new xtr checks the source of received traffic Configured dynamic-eids define which prefixes may roam lisp dynamic-eid roamer database-mapping /24 <RLOC-C> p1 w50 database-mapping /24 <RLOC-D> p1 w50 map-server key abcd interface vlan 100 lisp mobility roamer Mapping DB LISP-VM (xtr) A B C D Received a Packet It s from a New Host It s in the Dynamic-EID Allowed Range It s a Move! Register the /32 with LISP West-DC East-DC / /16 Y X Y Z

21 LISP Host-Mobility Traffic Redirection Update Location Mappings for the Host System Wide When a host move is detected, updates are triggered: The host-to-location mapping in the Database is updated to reflect the new location The old ETR is notified of the move ITRs are notified to update their Map-caches Ingress routers (ITRs or PITRs) now send traffic to the new location Transparent to the underlying routing and to the host LISP Site xtr A B C D Mapping DB /16 RLOC A, B /32 RLOC C, D LISP-VM (xtr) West-DC East-DC / /16 Y X Y Z

22 Host Mobility without LAN extensions

23 LISP Host-Mobility First Hop Routing No LAN Extension SVI (Interface VLAN x) and HSRP configured as usual Consistent GWY-MAC configured across all dynamic subnets The lisp mobility <dyn-eid-map> command enables proxy-arp functionality on the SVI The LISP-VM router services first hop routing requests for both local and roaming subnets Hosts can move anywhere and always talk to a local gateway with the same MAC Totally transparent to the moving hosts interface vlan 100 interface Ethernet2/4 ip address /24 ip address /24 lisp mobility roamer lisp mobility ip roamer proxy-arp ip proxy-arp hsrp 101 hsrp 101 mac-address e1d.010c mac-address ip e1d.010c ip HSRP Active LISP-VM (xtr) A B C D West-DC East-DC / /24 HSRP ARP GWY-MAC interface vlan 200 interface vlan 100 ip address /24 ip address /24 lisp mobility roamer lisp mobility roamer ip proxy-arp ip proxy-arp hsrp 201 hsrp 201 mac-address e1d.010c mac-address e1d.010c ip ip HSRP ARP GWY-MAC HSRP Active 23

24 Host-Mobility and Multi-homing ETR Updates Across LISP Sites Null0 host routes indicate the host is away /16 RLOC A, B /32 RLOC C, D Map-Notify /32 <C,D> Mapping DB Map-Register /32 <C,D> Routing Table: /16 Local /32 Null0 10 Map-Notify /32 <C,D> Routing Table: / /16 Local / /32 Null0 1 East-DC West-DC Y A X B Routing Table: /16 Local /32 Local Y C 3 4 D Routing Table: /16 Local /32 Local Map-Notify /32 <C,D> 24

25 Refreshing the Map Caches Map ITR 1. ITRs and PITRs with cached mappings continue to send traffic to the old locators 1. The old xtr knows the host has moved (Null0 route) 2. Old xtr sends Solicit Map Request (SMR) messages to any encapsulators sending traffic to the moved host 3. The ITR then initiates a new map request process 4. An updated map-reply is issued from the new location 5. The ITR Map Cache is updated Traffic is now re-directed SMRs are an important integrity measure to avoid unsolicited map responses and spoofing /16 RLOC A,B LISP site ITR /32 RLOC C,D Mapping DB A B C D LISP-VM (xtr) West-DC East-DC / /16 X Y Y Z

26 LISP Mobility Across LISP Sites Communication to the Home Subnet Client-server communication established without the need to discover the workloads in the home subnet in West-DC /16 RLOC A, B Map ITR /16 RLOC A,B LISP site ITR Mapping DB Routing Table: /24 Local A B Routing Table: /24 Local /24 Null0 C D Routing Table: /24 Local /24 Null0 Installed by LISP to allow Proxy- ARP functions when moving x workloads here /24 West-DC X Y Routing Table: /24 Local /24 East-DC 26

27 On-subnet Server-Server Traffic On Subnet Traffic Across L3 Boundaries West-to-East X ARPs for Y, /32 Null0 entry for Y triggers proxy- ARP on West-DC xtrs to ensure traffic is steered there Note: entry for Y in X ARP cache is cleared by GARP message originated by West-DC XTRs Traffic to Y is LISP encapsulated East-to-West Y ARPs for X, /24 Null0 entry for the home subnet triggers proxy-arp on East DC xtrs to ensure traffic is steered there Note: assumption is that ARP cache on Y is refreshed after the move Traffic to X is LISP encapsulated B C C B A B C D A B C D LISP DC xtr LISP DC xtr West-DC West-DC /24 East-DC / /24 East-DC / Y Y X Y Z X Y Z

28 LISP Host-Mobility Configuration Without LAN Extensions ip lisp ITR-ETR ip lisp database-mapping /16 <RLOC-A> ip lisp database-mapping /16 <RLOC-B> ip lisp ITR-ETR ip lisp database-mapping /16 <RLOC-C> ip lisp database-mapping /16 <RLOC-D> lisp dynamic-eid roamer database-mapping /24 <RLOC-A> database-mapping /24 <RLOC-B> map-server key abcd map-server key abcd map-notify-group interface vlan 100 ip address /16 lisp mobility roamer (ip proxy-arp) hsrp 101 mac-address e1d.010c ip LISP-VM (xtr) A B C D lisp dynamic-eid roamer database-mapping /24 <RLOC-C> database-mapping /24 <RLOC-D> map-server key abcd map-server key abcd map-notify-group interface vlan 100 ip address /16 lisp mobility roamer (ip proxy-arp) hsrp 201 mac-address e1d.010c ip West-DC East-DC / /16 Mapping DB X Y Z 28

29 LISP Mobility Across LISP Sites MS/MR Deployment Recommended Option: co-locate MS/MR functionality on the DC xtr (one per DC site) MS/MR in West-DC LISP site /24 ip lisp map-resolver ip lisp map-server lisp site BRANCH_1 eid-prefix / /24 authentication-key abcd lisp site West-DC eid-prefix /16 accept-more-specifics authentication-key abcd lisp site East-DC eid-prefix /16 accept-more-specifics authentication-key abcd A B C D MS/MR in East-DC West-DC East-DC / /24 X Y Z 29

30 Agenda Mobility and Virtualization in the Data Center Introduction to LISP LISP Data Center Use Cases LAN Extensions: OTV LISP + OTV Deployment Considerations Summary and Conclusion 30

31 Moving vs. Distributing Workloads Why do we really need LAN Extensions? Moving Workloads Hypervisor Hypervisor Control Traffic (routable) IP Network Hypervisor Move workloads with IP mobility solutions: LISP Host Mobility IP preservation is the real requirement (LAN extensions not mandatory) Distribute workloads with LAN extensions Application High Availability with Distributed Clusters Distributed App (GeoCluster) OS OS OS Non-IP application traffic (heartbeats) LAN Extension (OTV) 31

32 LAN Extensions Evolution From Circuits to Packets Circuits + Data Plane Flooding Packet Switching + Control Protocol DC-1 DC-2 DC-1 DC-2 L3 L2 L3 L2 B B A C D A C D Full mesh of circuits (pseudo-wires) MAC learning based on flooding Failure propagation Limited information Operationally Challenging Loop prevention and multi-homing must be provided separately Traditional L2 VPNs B B A C D A C D Packet switched connectivity MAC learning by control protocol Failure containment Rich information Operational simplification Automatic loop prevention & multi-homing MAC Routing 32

33 Overlay Transport Virtualization (OTV) Simplifying LAN Extensions Ethernet LAN Extension over any Network Works over dark fiber, MPLS, or IP Multi-data center scalability Simplified Configuration & Operation Seamless overlay - No network re-design Single touch site configuration High Resiliency Failure domain isolation Seamless Multi-homing Maximizes available bandwidth Automated multi-pathing Optimal multicast replication Many Physical Sites One Logical Data Center Any Workload, Anytime, Anywhere Unleashing the Full Potential of Compute Virtualization 33

34 Ingress Routing Challenge in DCI Extending Subnets Creates a Routing Challenge A subnet usually implies location Yet we use LAN extensions to stretch subnets across locations LISP site XTR Location semantics of subnets are lost Traditional routing relies on the location semantics of the subnet IP Network Can t tell if a server is at the East or West location of the subnet LAN Extension More granular (host level) information is required West-DC East-DC LISP provides host level location semantics 34

35 Host Mobility in Extended Subnets

36 LISP Host-Mobility First Hop Routing With Extended Subnets Consistent GWY-IP and GWY-MAC configured across all sites Consistent HSRP group number across sites consistent GWY-MAC Servers can move anywhere and always talk to a local gateway with the same IP/MAC interface vlan 100 interface vlan 200 interface vlan 100 ip address /24 ip address /24 interface Ethernet2/4 ip address /24 lisp mobility roamer lisp mobility roamer ip address /24 lisp mobility roamer lisp extended-subnet-mode lisp extended-subnet-mode lisp mobility lisp roamer extended-subnet-mode hsrp 101 LAN Ext. hsrp 101 lisp extended-subnet-mode hsrp 101 ip ip hsrp 101 ip A B C D ip HSRP Active LISP-VM (xtr) West-DC East-DC / /24 HSRP ARP GWY-MAC HSRP ARP GWY-MAC HSRP Active 36

37 Host-Mobility and Multi-homing ETR updates Extended Subnets Null0 host routes indicate the host is away /16 RLOC A, B /32 RLOC C, D /24 is the dyn-eid 4 Routing Table: /16 Local /24 Null /32 Null / /16 1 OTV East-DC West-DC A B 2 Y X Map-Notify /32 <C,D> Mapping DB Routing Table: /16 Local /24 Null /32 Local Routing Table: /16 Local /24 Null /32 Null Map-Register /32 <C,D> Y C 3 4 D Routing Table: /16 Local /24 Null /32 Local Map-Notify /32 <C,D> 37

38 Refreshing the Map Caches Map ITR 1. ITRs and PITRs with cached mappings continue to send traffic to the old locators 1. The old xtr knows the host has moved (Null0 route) 2. Old xtr sends Solicit Map Request (SMR) messages to any encapsulators sending traffic to the moved host 3. The ITR then initiates a new map request process 4. An updated map-reply is issued from the new location 5. The ITR Map Cache is updated Traffic is now re-directed SMRs are an important integrity measure to avoid unsolicited map responses and spoofing LISP-VM (xtr) West-DC OTV East-DC / /16 X LISP site Y ITR A B C D /32 RLOC A,B /32 RLOC A,B /32 RLOC C,D Y Z Mapping DB 38

39 LISP VM-Mobility Configuration With Extended Subnets extended-subnet-mode ip lisp ITR-ETR ip lisp database-mapping /16 <RLOC-A> ip lisp database-mapping /16 <RLOC-B> lisp dynamic-eid roamer database-mapping /24 <RLOC-A> database-mapping /24 <RLOC-B> map-server key abcd map-server key abcd map-notify-group interface vlan 100 ip address /16 lisp mobility roamer lisp extended-subnet-mode hsrp 101 ip ip lisp ITR-ETR ip lisp database-mapping /16 <RLOC-C> ip lisp database-mapping /16 <RLOC-D> lisp dynamic-eid roamer database-mapping /24 <RLOC-C> database-mapping /24 <RLOC-D> map-server key abcd map-server key abcd map-notify-group interface vlan 100 ip address /16 lisp mobility roamer lisp extended-subnet-mode hsrp 101 ip LISP-VM (xtr) LAN Ext A B C D Mapping DB West-DC /16 East-DC X Y Z 40

40 Off-subnet Client-Server Traffic All Off-Subnet/Off-Site Traffic Is LISP Encapsulated Clients ( & communicate with Server Client-server traffic is LISP encapsulated at the ITRs or PITRs Client-to-server: to ETRs C or D Server-to-client: to ETR (F) for LISP sites to PETR (G) for non-lisp sites Server-Server off-subnet traffic across sites is also LISP encapsulated CLIENT LISP Site F West-DC xtr CLIENT A B C D X Y F C Non-LISP Sites Y PxTR G D Mapping DB LISP-VM (xtr) East-DC / / G 41

41 On-subnet Server-Server Traffic On Subnet Traffic Across L3 Boundaries With LAN Extension Live moves and cluster member dispersion Traffic between X & Y uses the LAN Extension Link-local-multicast handled by the LAN Extension Without LAN Extensions Cold moves, no application dispersion X- Y traffic is sent to the LISP-VM router & LISP encapsulated Need LAN extensions for link-local multicast traffic B C Mapping DB LAN Ext A B C D A B C D LISP-VM (xtr) LISP-VM (xtr) West-DC /16 East-DC West-DC /16 East-DC / Y Y X Y Z X Y Z

42 Agenda Mobility and Virtualization in the Data Center LAN Extensions: OTV Introduction to LISP LISP Data Center Use Cases Multi-Tenancy LISP + OTV Deployment Considerations Summary and Conclusion 43

43 LISP Multi-Tenancy High Level View Needs: Integrated Segmentation Ease of operations Global Scale and interoperability LISP Solution: Traffic (control & data) is colored (tagged) with an instance-id Mappings are also colored in DB and caches On xtrs use VRFs as map cache contexts LISP Site xtr Non-LISP Sites IP Network PxTR Instance IP Location Red A East Blue A West Yellow C (Move) East West Mapping DB Benefits: xtr Very high scale tenant segmentation Distributed/on-demand/no-adjacencies Global mobility + high scale segmentation integrated in a single IP solution IP based solution, transport independent No Inter-AS complexity Overlay solution is transparent to the core West-DC RLOC EID LISP Encap/Decap East-DC 44

44 Network Virtualization in LISP LISP Multi-tenancy Virtualized Mapping Service: Instance EID IP Location Green A East Blue A West EID entries with instance-id semantics To MPLS VPNs, VRF-lite or separate networks Colored Map Requests/Replies Yellow C East West To LISP Control packets also contain instanceid semantics G D Instance G E Instance G F Instance Virtualized Map Cache (xtrs): Mappings cached in different VRFs per instance-id Interoperable with other VRF features/solutions Single RLOC space shared by multiple instances Colored Traffic: Instance-ID tag in LISP data header Instance-ID encoded in LISP control packets Coloring is transparent to the core 45

45 Segmentation End-to-end LISP-VRF Integration servers Enterprise Core A Enterprise WAN B Global Corp-A User MS/MR xtr11 xtr203 Doctor Corp-A101 User Enterprise Remote Site Finance Corp-A102 User Global VRF- Corp-A101 VRF-Corp-A102 VRF-Lite / EVN (or MPLS VPN) LISP Multi-Tenancy Instances 0,101,102 A B Instance 0 S D in Global A B Instance 101 S D in Corp-A101 A B Instance 102 S D in Corp-A102 VRF-Lite / EVN (or MPLS VPN) Global VRF- Corp-A101 VRF-Corp-A102 Single RLOC space shared by multiple instances Legend: EIDs -> Green Locators -> Red LISP encap/decap 47

46 Agenda Mobility and Virtualization in the Data Center LAN Extensions: OTV Introduction to LISP LISP Data Center Use Cases LISP + OTV Deployment Considerations Summary and Conclusion 49

47 LISP Host-Mobility Router Main Data Disaster Recover facilities Ideally: First hop routers for the subnets in which the mobile hosts reside: Detect host moves Provide a consistent first hop presence Could also be the second hop Usually the Aggregation Switches in the Data Center Customer Managed LISP Site XTR LISP-VM (XTR) West-DC RLOC Internet / WAN Backbone Data Center IP Backbone EID LISP-VM (XTR) DC-Aggregation DC-Access East-DC LISP Encap/Decap DR Location or Cloud Provider DC 50

48 OTV Router Main Data Centers only Typically not Disaster Recover facilities First hop routers for the subnets in which the mobile hosts reside: Connect to the VLANs to be extended Connect to the IP core Usually the Aggregation Switches in the Data Center Customer Managed LISP Site XTR OTV West-DC RLOC LAN Extension to DR or Cloud Facilities Is Usually Not Required Internet / WAN Backbone EID Data Center IP Backbone DC-Aggregation DC-Access East-DC LISP Encap/Decap DR Location or Cloud Provider DC OTV 51

49 PxTR Placement Advertise DC Routes to Non-LISP Sites PXTR Ideally placed on path between non-lisp and LISP sites Aggregation points are optimal: Border routers between DC core and WAN Internet Routers Customer Routers at Co-location Provider routers (PXTR service) PITRs must be configured to inject routes into the non-lisp network Attract traffic from Non-LISP sites Encap and send to the Data Center West-DC RLOC Provider PXTR Internet / WAN Backbone Data Center IP Backbone EID DC-Aggregation DC-Access Non-LISP Sites Private PXTR East-DC LISP Encap/Decap 52

50 Map Server Placement A Daemon on a Router The Map Server functionality can be enabled on any router BGP route-reflectors are a good analogy Off path is good, but not mandatory Distribute Map Servers across different locations Private Data Centers (Self managed) SP Data Centers/Cloud (SP Service) Map Server resiliency options: Clustered and distributed Distributed Database (DDT) West-DC LISP Site SP Mapping Service Private Map Server RLOC XTR Internet / WAN Backbone Data Center IP Backbone EID DC-Aggregation Non-LISP Sites DC-Access Private Map Server East-DC LISP Encap/Decap 53

51 Map Server Placement Private DC deployment Options Option 1: co-locate MS/MR functionality on the DC xtr (same as for LISP Across Subnet Mode) Option 2: push the MS/MR functionality on the OTV VDC (one per DC site) MS/MR in West DC MS/MR in West DC MS/MR in West DC MS/MR in West DC 54

52 Agenda Mobility and Virtualization in the Data Center LAN Extensions: OTV Introduction to LISP LISP Data Center Use Cases LISP + OTV Deployment Considerations Stateful Services Considerations Summary and Conclusion 59

53 Live Moves or Cold Moves Live (hot) Moves preserve existing connections and state e.g. vmotion, Cluster failover Requires synchronous storage and network policy replication Distance limitations Cold Moves bring machines down and back up elsewhere e.g. Site Recovery Manager No state preservation: less constrained by distances or services capabilities Moving Workloads Hypervisor Hypervisor Control Traffic (routable) IP Network Hypervisor Mobility across PODs within a site or across different locations 60

54 Services - Live Moves Services Cold Moves LISP LISP LISP LISP LAN Extension LAN Extension LAN Extension LAN Extension Redirection of established flows: - Extended Clusters - Cluster or LISP based re-direction DC1 DC2 DC1 IP preservation Uniform Policies DC2 Established before the move Established after the move 61

55 Cold Moves / Disaster Recovery Localized FW & SLB Clusters Independent FW & SLB cluster in each location LAN extensions not required New state created after moves No state synchronization LISP steers traffic to different locations Disaster recovery Cold workload relocation LISP FW cluster SLB cluster LISP FW cluster SLB cluster DC1 DC2 62

56 Live Moves Extended Firewall Clusters All Active FW cluster extended across locations LAN extensions for heartbeats, state sync and redirection within the cluster LISP LISP FW state is synchronized across all cluster members All members active LAN Extension LAN Extension Extended cluster LAN Extension LAN Extension LISP steers traffic to different locations Flows existing prior to the move will be redirected within the FW cluster (over the LAN extension) New flows will be instantiated on the FWs at the new site DC1 DC2 64

57 SLB Virtual-IP (VIP) Failover VIP is active at one location at a time VIP location is advertised in LISP LISP LISP VIP may failover on failure or change active device on machine moves VIP becomes active at a new site VIP VIP VIP activity is detected by the VMmobility logic LAN Extension LAN Extension VIP location is updated in LISP on failover DC1 DC2 66

58 Dynamic routes Inserting Firewalls in routed mode Traffic is Decapsulated Before Being Handed off to the FWs XTR is not the first hop router LISP host-mobility functionality is split to two places: XTR LISP registration/encap/decap 1 st Hop router Move detection, host route injection, proxy default GWY LISP encap/decap LISP signaling L3 Core R3: 3 rd Hop Router (XTR) R2: 2 nd Hop Router (FW) Local host routes fix up routing to the moving device The XTR LISP registers host routes in the dynamic-eid range Move Detection Host route injection Default GWY proxy roamer (lands in a foreign network) R1: 1 st Hop Router 67

59 Agenda Mobility and Virtualization in the Data Center LAN Extensions: OTV Introduction to LISP LISP Data Center Use Cases LISP + OTV Deployment Considerations Interaction with VXLAN Summary and Conclusion 70

60 L2 Host Overlays and Virtualization - VXLAN IP1 VXLAN elastic creation of virtual Segments web app GWY VM VM web vxlan 1 vxlan 2 IP1 GWY VM VSG vxlan 21 vxlan 22 Small Segments Usually don t stretch outside of a POD Mobile: Can be instantiated anywhere Move along with VMs as necessary Very large number of segments db VM app vxlan 3 db VM VM VSG vxlan 23 Do not consume resources in the network core Host overlays are initiated at the hypervisor virtual switch Virtual hosts only GWY to connect to the non-virtualized world Multi-tier Virtual App = VMs + Segments + GWY Application: Cloud Services VXLAN shipping since 2011 on Cisco Nexus 1000v, other variants: NVGRE, STT 71

61 IP1 VXLAN + LISP for vapp mobility GWY vxlan 1 web VM Move virtual Applications (vapps) to private cloud PODs Move VMs and virtual Segments (VXLANs) app VM vxlan 2 VSG LISP host mobility allows the vapp GWY to roam db VM vxlan 3 Maintain GWY IP address, segmentation and optimal reachability LISP IP mobility IP Network DC-west DC-east POD POD POD POD GWY web web web app app app db db db VM VM VM VM VM VM GWY VM VM vxlan 1 GWY vxlan 1 vxlan 1 vxlan 2 vxlan 2 vxlan 2 vxlan 3 VM vxlan 3 vxlan 3 web app db GWY VM VM VM vxlan 1 vxlan 2 vxlan 3 web app GWY VM VM vxlan 1 vxlan 2 vxlan 3 VM db 72

62 Service State Mobility vpath and the Virtual Services Gateway (VSG) VSG uses the vpath model FW policies are maintained centrally FW state/enforcement is distributed to the hypervisor switch FW state moves granularly with each VM LISP LISP DC1 DC2 73

63 Summary and Conclusions

64 Summary and Conclusions LISP provides an effective solution for host mobility Some applications may require LAN extensions in combination with host mobility LISP consolidates many network services in one architecture: Mobility, network segmentation, traffic engineering Enhanced scalability Location Identity Separation opens many opportunities in the Data Center space 76

65 LISP Host Mobility Support Part of the LISP Solution Space IPv6 Network xtr IPv6 Core 1. Multihoming 2. IPv6 Transition 3. Virtualization/VPN 4. Mobility IPv4 Network xtr IPv4 Core v6 v4 LISP is an Architecture 77

66 LISP References

67 LISP References LISP Sessions at Cisco Live London 2013 TRY LISP YOURSELF! LISP Walk-In Self-Paced (WISP) Labs Mon 09:30-18:30 Tues 11:15-12:45 Mon 09:30-18:30 Fri 11:30-13:00 Mon 09:30-18:30 You Are Here Wed 14:00-15:30 Thurs 15:00-18:30 79

68 LISP References LISP Information and Mailing Lists LISP Information Cisco LISP Site. (IPv4 and IPv6) Cisco LISP Marketing Site... LISP Beta Network Site or LISP DDT Root... IETF LISP Working Group... LISP Mailing Lists Cisco LISP Questions IETF LISP Working Group LISP Interest (public). LISPmob Questions... 80

69 Call to Action Visit the Cisco Campus at the World of Solutions to experience Cisco innovations in action Get hands-on experience attending one of the Walk-in Labs Schedule face to face meeting with one of Cisco s engineers at the Meet the Engineer center Discuss your project s challenges at the Technical Solutions Clinics 81

70 82

71

Mobility and Virtualization in the Data Center with LISP and OTV

Mobility and Virtualization in the Data Center with LISP and OTV Mobility and Virtualization in the Data Center with LISP and OTV Victor Moreno, Distinguished Engineer Agenda Mobility and Virtualization in the Data Center Introduction to LISP LISP Data Center Use Cases

More information

Mobility and Virtualization in the Data Center with LISP and OTV

Mobility and Virtualization in the Data Center with LISP and OTV Cisco Expo 2012 Mobility and Virtualization in the Data Center with LISP and OTV Tech DC2 Martin Diviš Cisco, CSE, mdivis@cisco.com Cisco Expo 2012 Cisco and/or its affiliates. All rights reserved. 1 Twitter

More information

Location ID Separation Protocol. Gregory Johnson -

Location ID Separation Protocol. Gregory Johnson - Location ID Separation Protocol Gregory Johnson - grjohnso@cisco.com LISP - Agenda LISP Overview LISP Operations LISP Use Cases LISP Status (Standards and in the Community) Summary 2 LISP Overview 2010

More information

INTRODUCTION 2 DOCUMENT USE PREREQUISITES 2

INTRODUCTION 2 DOCUMENT USE PREREQUISITES 2 Table of Contents INTRODUCTION 2 DOCUMENT USE PREREQUISITES 2 LISP MOBILITY MODES OF OPERATION/CONSUMPTION SCENARIOS 3 LISP SINGLE HOP SCENARIO 3 LISP MULTI- HOP SCENARIO 3 LISP IGP ASSIT MODE 4 LISP INTEGRATION

More information

Deploying LISP Host Mobility with an Extended Subnet

Deploying LISP Host Mobility with an Extended Subnet CHAPTER 4 Deploying LISP Host Mobility with an Extended Subnet Figure 4-1 shows the Enterprise datacenter deployment topology where the 10.17.1.0/24 subnet in VLAN 1301 is extended between the West and

More information

Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN

Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN Ron Fuller CCIE #5851 (R&S/Storage) Technical Marketing Engineer, Nexus 7000 rfuller@cisco.com Agenda The Evolving Data Centre Fabric

More information

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV.

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV. 2 CHAPTER Cisco's Disaster Recovery as a Service (DRaaS) architecture supports virtual data centers that consist of a collection of geographically-dispersed data center locations. Since data centers are

More information

IP Mobility Design Considerations

IP Mobility Design Considerations CHAPTER 4 The Cisco Locator/ID Separation Protocol Technology in extended subnet mode with OTV L2 extension on the Cloud Services Router (CSR1000V) will be utilized in this DRaaS 2.0 System. This provides

More information

DNA SA Border Node Support

DNA SA Border Node Support Digital Network Architecture (DNA) Security Access (SA) is an Enterprise architecture that brings together multiple building blocks needed for a programmable, secure, and highly automated fabric. Secure

More information

LISP. - innovative mobility w/ Cisco Architectures. Gerd Pflueger Consulting Systems Engineer Central Europe Version 0.

LISP. - innovative mobility w/ Cisco Architectures. Gerd Pflueger Consulting Systems Engineer Central Europe Version 0. Version 0.2 22 March 2012 LISP - innovative mobility w/ Cisco Architectures Gerd Pflueger Consulting Systems Engineer Central Europe gerd@cisco.com 2012 Cisco and/or its affiliates. All rights reserved.

More information

LISP Locator/ID Separation Protocol

LISP Locator/ID Separation Protocol LISP Locator/ID Separation Protocol Hernán Contreras G. Consulting Systems Engineer hcontrer@cisco.com LISP Next Gen Routing Architecture Locator-ID Separation Protocol (LISP) Elevator Pitch LISP is a

More information

Hierarchical Fabric Designs The Journey to Multisite. Lukas Krattiger Principal Engineer September 2017

Hierarchical Fabric Designs The Journey to Multisite. Lukas Krattiger Principal Engineer September 2017 Hierarchical Fabric Designs The Journey to Multisite Lukas Krattiger Principal Engineer September 2017 A Single Fabric, a Single Data Center External Layer-3 Network Pod 1 Leaf/ Topologies (aka Folded

More information

Multi-site Datacenter Network Infrastructures

Multi-site Datacenter Network Infrastructures Multi-site Datacenter Network Infrastructures Petr Grygárek rek 2009 Petr Grygarek, Advanced Computer Networks Technologies 1 Why Multisite Datacenters? Resiliency against large-scale site failures (geodiversity)

More information

Locator ID Separation Protocol (LISP) Overview

Locator ID Separation Protocol (LISP) Overview Locator ID Separation Protocol (LISP) is a network architecture and protocol that implements the use of two namespaces instead of a single IP address: Endpoint identifiers (EIDs) assigned to end hosts.

More information

Evolution of Network Overlays in Data Center Clouds

Evolution of Network Overlays in Data Center Clouds Evolution of Network Overlays in Data Center Clouds Victor Moreno, Distinguished Engineer Agenda In the beginning - Overlay Foundational Principles Square pegs and round holes Evolution to meet networking

More information

Evolving your Campus Network with. Campus Fabric. Shawn Wargo. Technical Marketing Engineer BRKCRS-3800

Evolving your Campus Network with. Campus Fabric. Shawn Wargo. Technical Marketing Engineer BRKCRS-3800 Evolving your Campus Network with Campus Fabric Shawn Wargo Technical Marketing Engineer BRKCRS-3800 Campus Fabric Abstract Is your Campus network facing some, or all, of these challenges? Host Mobility

More information

Implementing VXLAN in DataCenter

Implementing VXLAN in DataCenter Implementing VXLAN in DataCenter LTRDCT-1223 Lilian Quan Technical Marketing Engineering, INSBU Erum Frahim Technical Leader, ecats John Weston Technical Leader, ecats Why Overlays? Robust Underlay/Fabric

More information

IP Routing: LISP Configuration Guide, Cisco IOS Release 15M&T

IP Routing: LISP Configuration Guide, Cisco IOS Release 15M&T First Published: 2012-07-27 Last Modified: 2013-03-29 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Cisco Nexus 7000 Series NX-OS LISP Configuration Guide

Cisco Nexus 7000 Series NX-OS LISP Configuration Guide First Published: 2011-10-25 Last Modified: 2014-04-25 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Locator/ID Separation Protocol (LISP) Virtual Machine Mobility Solution

Locator/ID Separation Protocol (LISP) Virtual Machine Mobility Solution White Paper Locator/ID Separation Protocol (LISP) Virtual Machine Mobility Solution White Paper 2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1

More information

Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003

Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003 Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003 Agenda ACI Introduction and Multi-Fabric Use Cases ACI Multi-Fabric Design Options ACI Stretched Fabric Overview

More information

LISP. Migration zu IPv6 mit LISP. Gerd Pflueger Version Feb. 2013

LISP. Migration zu IPv6 mit LISP. Gerd Pflueger Version Feb. 2013 Version 0.7 24 Feb. 2013 LISP Migration zu IP mit LISP Gerd Pflueger gerd@cisco.com 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 2011 Cisco and/or its affiliates. All rights reserved.

More information

Introduction to External Connectivity

Introduction to External Connectivity Before you begin Ensure you know about Programmable Fabric. Conceptual information is covered in the Introduction to Cisco Programmable Fabric and Introducing Cisco Programmable Fabric (VXLAN/EVPN) chapters.

More information

Data Center Interconnect Solution Overview

Data Center Interconnect Solution Overview CHAPTER 2 The term DCI (Data Center Interconnect) is relevant in all scenarios where different levels of connectivity are required between two or more data center locations in order to provide flexibility

More information

TTL Propagate Disable and Site-ID Qualification

TTL Propagate Disable and Site-ID Qualification The TTL Propagate Disable feature supports disabling of the TTL (Time-To-Live) propagation for implementing the traceroute tool in a LISP network when RLOC and EID belong to different address-family. The

More information

Data Center Interconnection

Data Center Interconnection Dubrovnik, Croatia, South East Europe 20-22 May, 2013 Data Center Interconnection Network Service placements Yves Louis TSA Data Center 2011 2012 Cisco and/or its affiliates. All rights reserved. Cisco

More information

Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric)

Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric) White Paper Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric) What You Will Learn This document describes how to achieve a VXLAN EVPN multifabric design by integrating Virtual

More information

Cisco Nexus 7000 Series NX-OS LISP Command Reference

Cisco Nexus 7000 Series NX-OS LISP Command Reference First Published: 2016-11-24 Last Modified: -- Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax:

More information

Lecture 7 Advanced Networking Virtual LAN. Antonio Cianfrani DIET Department Networking Group netlab.uniroma1.it

Lecture 7 Advanced Networking Virtual LAN. Antonio Cianfrani DIET Department Networking Group netlab.uniroma1.it Lecture 7 Advanced Networking Virtual LAN Antonio Cianfrani DIET Department Networking Group netlab.uniroma1.it Advanced Networking Scenario: Data Center Network Single Multiple, interconnected via Internet

More information

Locator/ID Separation Protocol (LISP)

Locator/ID Separation Protocol (LISP) Locator/ID Separation Protocol (LISP) Damien Saucez* INRIA Sophia Antipolis FRNOG 18, December 2 th, 2011 * special thanks to Olivier Bonaventure, Luigi Iannone and Dino Farinacci Disclaimer Not a vendor

More information

MP-BGP VxLAN, ACI & Demo. Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017

MP-BGP VxLAN, ACI & Demo. Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017 MP-BGP VxLAN, ACI & Demo Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017 Datacenter solutions Programmable Fabric Classic Ethernet VxLAN-BGP EVPN standard-based Cisco DCNM Automation Modern

More information

LISP: What and Why. RIPE Berlin May, Vince Fuller (for Dino, Dave, Darrel, et al)

LISP: What and Why. RIPE Berlin May, Vince Fuller (for Dino, Dave, Darrel, et al) LISP: What and Why RIPE Berlin May, 2008 Vince Fuller (for Dino, Dave, Darrel, et al) http://www.vaf.net/prezos/lisp-ripe-long.pdf Agenda What is the problem? What is LISP? Why Locator/ID Separation? Data

More information

Cisco Nexus 7000 Series NX-OS LISP Configuration Guide

Cisco Nexus 7000 Series NX-OS LISP Configuration Guide First Published: 2016-12-23 Last Modified: 2018-07-05 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Cisco IOS LISP Application Note Series: Lab Testing Guide

Cisco IOS LISP Application Note Series: Lab Testing Guide Cisco IOS LISP Application Note Series: Lab Testing Guide Version 3.0 (28 April 2011) Background The LISP Application Note Series provides targeted information that focuses on the integration configuration

More information

VXLAN Overview: Cisco Nexus 9000 Series Switches

VXLAN Overview: Cisco Nexus 9000 Series Switches White Paper VXLAN Overview: Cisco Nexus 9000 Series Switches What You Will Learn Traditional network segmentation has been provided by VLANs that are standardized under the IEEE 802.1Q group. VLANs provide

More information

APT: A Practical Transit-Mapping Service Overview and Comparisons

APT: A Practical Transit-Mapping Service Overview and Comparisons APT: A Practical Transit-Mapping Service Overview and Comparisons draft-jen-apt Dan Jen, Michael Meisel, Dan Massey, Lan Wang, Beichuan Zhang, and Lixia Zhang The Big Picture APT is similar to LISP at

More information

Cisco Campus Fabric Introduction. Vedran Hafner Systems engineer Cisco

Cisco Campus Fabric Introduction. Vedran Hafner Systems engineer Cisco Cisco Campus Fabric Introduction Vedran Hafner Systems engineer Cisco Campus Fabric Abstract Is your Campus network facing some, or all, of these challenges? Host Mobility (w/o stretching VLANs) Network

More information

LISP Parallel Model Virtualization

LISP Parallel Model Virtualization Finding Feature Information, page 1 Information About, page 1 How to Configure, page 6 Configuration Examples for, page 24 Additional References, page 25 Feature Information for, page 26 Finding Feature

More information

Cisco ACI Multi-Pod and Service Node Integration

Cisco ACI Multi-Pod and Service Node Integration White Paper Cisco ACI Multi-Pod and Service Node Integration 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 68 Contents Introduction... 3 Prerequisites...

More information

Cisco Dynamic Fabric Automation Architecture. Miroslav Brzek, Systems Engineer

Cisco Dynamic Fabric Automation Architecture. Miroslav Brzek, Systems Engineer Cisco Dynamic Fabric Automation Architecture Miroslav Brzek, Systems Engineer mibrzek@cisco.com Agenda DFA Overview Optimized Networking Fabric Properties Control Plane Forwarding Plane Virtual Fabrics

More information

Segmentation. Threat Defense. Visibility

Segmentation. Threat Defense. Visibility Segmentation Threat Defense Visibility Establish boundaries: network, compute, virtual Enforce policy by functions, devices, organizations, compliance Control and prevent unauthorized access to networks,

More information

LISP: Intro and Update

LISP: Intro and Update LISP: Intro and Update RIPE Berlin May, 2008 Vince Fuller (for Dino, Dave, Darrel, et al) http://www.vaf.net/prezos/lisp-ripe-short.pdf Agenda What is LISP? What problem is LISP solving? www.vaf.net/prezos/rrg-prague.pdf

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, on page 1 Licensing Requirements for VXLAN EVPN Multi-Site, on page 2 Guidelines and Limitations for VXLAN EVPN Multi-Site, on

More information

LISP Generalized SMR

LISP Generalized SMR The feature enables LISP xtr (ITR and ETR) to update map cache when there is a change in database mapping. Note There is no configuration commands for this feature. This feature is turned on automatically.

More information

Overview. Overview. OTV Fundamentals. OTV Terms. This chapter provides an overview for Overlay Transport Virtualization (OTV) on Cisco NX-OS devices.

Overview. Overview. OTV Fundamentals. OTV Terms. This chapter provides an overview for Overlay Transport Virtualization (OTV) on Cisco NX-OS devices. This chapter provides an overview for Overlay Transport Virtualization (OTV) on Cisco NX-OS devices., page 1 Sample Topologies, page 6 OTV is a MAC-in-IP method that extends Layer 2 connectivity across

More information

Virtual Security Gateway Overview

Virtual Security Gateway Overview This chapter contains the following sections: Information About the Cisco Virtual Security Gateway, page 1 Cisco Virtual Security Gateway Configuration for the Network, page 10 Feature History for Overview,

More information

Cisco IOS LISP Application Note Series: Access Control Lists

Cisco IOS LISP Application Note Series: Access Control Lists Cisco IOS LISP Application Note Series: Access Control Lists Version 1.1 (28 April 2011) Background The LISP Application Note Series provides targeted information that focuses on the integration and configuration

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, page 1 Guidelines and Limitations for VXLAN EVPN Multi-Site, page 2 Enabling VXLAN EVPN Multi-Site, page 2 Configuring VNI Dual

More information

Ethernet VPN (EVPN) and Provider Backbone Bridging-EVPN: Next Generation Solutions for MPLS-based Ethernet Services. Introduction and Application Note

Ethernet VPN (EVPN) and Provider Backbone Bridging-EVPN: Next Generation Solutions for MPLS-based Ethernet Services. Introduction and Application Note White Paper Ethernet VPN (EVPN) and Provider Backbone Bridging-EVPN: Next Generation Solutions for MPLS-based Ethernet Services Introduction and Application Note Last Updated: 5/2014 Ethernet VPN (EVPN)

More information

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN This module provides conceptual information for VXLAN in general and configuration information for layer 2 VXLAN on Cisco ASR 9000 Series Router. For configuration information of layer 3 VXLAN, see Implementing

More information

GETVPN+LISP Lab Guide

GETVPN+LISP Lab Guide GETVPN+LISP Lab Guide Developers and Lab Proctors This lab was created by: Gregg Schudel, TME LISP Development Team Version 1.0: Created by Gregg Schudel Lab proctor: Gregg Schudel (gschudel@cisco.com)

More information

Virtuální firewall v ukázkách a příkladech

Virtuální firewall v ukázkách a příkladech Praha, hotel Clarion 10. 11. dubna 2013 Virtuální firewall v ukázkách a příkladech T-SEC3 / L2 Tomáš Michaeli Cisco 2013 2011 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Agenda VXLAN

More information

Software-Defined Access Wireless

Software-Defined Access Wireless Introduction to, page 1 Configuring SD-Access Wireless (CLI), page 7 Enabling SD-Access Wireless (GUI), page 8 Configuring SD-Access Wireless VNID (GUI), page 9 Configuring SD-Access Wireless WLAN (GUI),

More information

ACI Multi-Site Architecture and Deployment. Max Ardica Principal Engineer - INSBU

ACI Multi-Site Architecture and Deployment. Max Ardica Principal Engineer - INSBU ACI Multi-Site Architecture and Deployment Max Ardica Principal Engineer - INSBU Agenda ACI Network and Policy Domain Evolution ACI Multi-Site Deep Dive Overview and Use Cases Introducing ACI Multi-Site

More information

Software-Defined Access Wireless

Software-Defined Access Wireless Introduction to, page 1 Configuring SD-Access Wireless (CLI), page 7 Introduction to The Enterprise Fabric provides end-to-end enterprise-wide segmentation, flexible subnet addressing, and controller-based

More information

Frequently Asked Questions for HP EVI and MDC

Frequently Asked Questions for HP EVI and MDC Frequently Asked Questions for HP EVI and MDC Q. What are we announcing at VMworld? A. HP will be expanding Virtual Application Networks with new FlexFabric innovations that simplify the interconnection

More information

VXLAN Deployment Use Cases and Best Practices

VXLAN Deployment Use Cases and Best Practices VXLAN Deployment Use Cases and Best Practices Azeem Suleman Solutions Architect Cisco Advanced Services Contributions Thanks to the team: Abhishek Saxena Mehak Mahajan Lilian Quan Bradley Wong Mike Herbert

More information

Multi-Site Use Cases. Cisco ACI Multi-Site Service Integration. Supported Use Cases. East-West Intra-VRF/Non-Shared Service

Multi-Site Use Cases. Cisco ACI Multi-Site Service Integration. Supported Use Cases. East-West Intra-VRF/Non-Shared Service Cisco ACI Multi-Site Service Integration, on page 1 Cisco ACI Multi-Site Back-to-Back Spine Connectivity Across Sites Without IPN, on page 8 Bridge Domain with Layer 2 Broadcast Extension, on page 9 Bridge

More information

Contents. EVPN overview 1

Contents. EVPN overview 1 Contents EVPN overview 1 EVPN network model 1 MP-BGP extension for EVPN 2 Configuration automation 3 Assignment of traffic to VXLANs 3 Traffic from the local site to a remote site 3 Traffic from a remote

More information

#nwsau17. Future campus design. James Horne. Enterprise Services Technical Consultant Networking, AARNet

#nwsau17. Future campus design. James Horne. Enterprise Services Technical Consultant Networking, AARNet #nwsau17 Future campus design James Horne Enterprise Services Technical Consultant Networking, AARNet JAMES HORNE Technical Consultant Networks AARNet Enterprise Services Currently working on major projects

More information

Campus Fabric Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 9300 Switches)

Campus Fabric Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 9300 Switches) Campus Fabric Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 9300 Switches) First Published: 2017-07-31 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706

More information

LISP Router IPv6 Configuration Commands

LISP Router IPv6 Configuration Commands ipv6 alt-vrf, page 2 ipv6 etr, page 4 ipv6 etr accept-map-request-mapping, page 6 ipv6 etr map-cache-ttl, page 8 ipv6 etr map-server, page 10 ipv6 itr, page 13 ipv6 itr map-resolver, page 15 ipv6 map-cache-limit,

More information

VXLAN Multipod Design for Intra-Data Center and Geographically Dispersed Data Center Sites

VXLAN Multipod Design for Intra-Data Center and Geographically Dispersed Data Center Sites White Paper VXLAN Multipod Design for Intra-Data Center and Geographically Dispersed Data Center Sites May 17, 2016 Authors Max Ardica, Principal Engineer INSBU Patrice Bellagamba, Distinguish System Engineer

More information

Service Graph Design with Cisco Application Centric Infrastructure

Service Graph Design with Cisco Application Centric Infrastructure White Paper Service Graph Design with Cisco Application Centric Infrastructure 2017 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 101 Contents Introduction...

More information

BESS work on control planes for DC overlay networks A short overview

BESS work on control planes for DC overlay networks A short overview BESS work on control planes for DC overlay networks A short overview Jorge Rabadan IETF99, July 2017 Prague 1 Agenda EVPN in a nutshell BESS work on EVPN for NVO3 networks EVPN in the industry today Future

More information

Campus Fabric Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 3650 Switches)

Campus Fabric Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 3650 Switches) Campus Fabric Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 3650 Switches) First Published: 2017-07-31 Last Modified: 2017-11-03 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive

More information

Cisco Virtualized Workload Mobility Introduction

Cisco Virtualized Workload Mobility Introduction CHAPTER 1 The ability to move workloads between physical locations within the virtualized Data Center (one or more physical Data Centers used to share IT assets and resources) has been a goal of progressive

More information

Demand-Based Control Planes for Switching Fabrics

Demand-Based Control Planes for Switching Fabrics Demand-Based Control Planes for Switching Fabrics Modern switching fabrics use virtual network overlays to support mobility, segmentation, and programmability at very large scale. Overlays are a key enabler

More information

Software-Defined Access Wireless

Software-Defined Access Wireless Introduction to, page 1 Configuring SD-Access Wireless (CLI), page 7 Enabling SD-Access Wireless (GUI), page 8 Configuring SD-Access Wireless VNID (GUI), page 9 Configuring SD-Access Wireless WLAN (GUI),

More information

Evolution with End-to-End Data Center Virtualization

Evolution with End-to-End Data Center Virtualization Evolution with End-to-End Data Center Virtualization Yves Louis DC Virtualisation Technical Solution Architect Agenda Data Center Virtualization Overview Front-End Data Center Virtualization Core Layer

More information

Provisioning Overlay Networks

Provisioning Overlay Networks This chapter has the following sections: Using Cisco Virtual Topology System, page 1 Creating Overlays, page 2 Creating Network using VMware, page 4 Creating Subnetwork using VMware, page 4 Creating Routers

More information

Campus Fabric. How To Integrate With Your Existing Networks. Kedar Karmarkar - Technical Leader BRKCRS-2801

Campus Fabric. How To Integrate With Your Existing Networks. Kedar Karmarkar - Technical Leader BRKCRS-2801 Campus Fabric How To Integrate With Your Existing Networks Kedar Karmarkar - Technical Leader Campus Fabric Abstract Is your Campus network facing some, or all, of these challenges? Host Mobility (w/o

More information

IP Fabric Reference Architecture

IP Fabric Reference Architecture IP Fabric Reference Architecture Technical Deep Dive jammon@brocade.com Feng Shui of Data Center Design 1. Follow KISS Principle Keep It Simple 2. Minimal features 3. Minimal configuration 4. Configuration

More information

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC)

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC) Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC) Dedi Shindler - Sr. Manager Product Management Cloud System Management Technology Group Cisco Agenda Trends Influencing

More information

Data Center Configuration. 1. Configuring VXLAN

Data Center Configuration. 1. Configuring VXLAN Data Center Configuration 1. 1 1.1 Overview Virtual Extensible Local Area Network (VXLAN) is a virtual Ethernet based on the physical IP (overlay) network. It is a technology that encapsulates layer 2

More information

HPE FlexFabric 5940 Switch Series

HPE FlexFabric 5940 Switch Series HPE FlexFabric 5940 Switch Series EVPN Configuration Guide Part number: 5200-2002b Software version: Release 25xx Document version: 6W102-20170830 Copyright 2017 Hewlett Packard Enterprise Development

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

VXLAN Design with Cisco Nexus 9300 Platform Switches

VXLAN Design with Cisco Nexus 9300 Platform Switches Guide VXLAN Design with Cisco Nexus 9300 Platform Switches Guide October 2014 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 39 Contents What

More information

Data Center InterConnect (DCI) Technologies. Session ID 20PT

Data Center InterConnect (DCI) Technologies. Session ID 20PT Data Center InterConnect (DCI) Technologies Session ID 20PT Session Objectives The main goals of this session are: Highlighting the main business requirements driving Data Center Interconnect (DCI) deployments

More information

Ethernet VPN (EVPN) in Data Center

Ethernet VPN (EVPN) in Data Center Ethernet VPN (EVPN) in Data Center Description and Design considerations Vasilis Stavropoulos Sparkle GR EVPN in Data Center The necessity for EVPN (what it is, which problems it solves) EVPN with MPLS

More information

PrepAwayExam. High-efficient Exam Materials are the best high pass-rate Exam Dumps

PrepAwayExam.   High-efficient Exam Materials are the best high pass-rate Exam Dumps PrepAwayExam http://www.prepawayexam.com/ High-efficient Exam Materials are the best high pass-rate Exam Dumps Exam : 642-997 Title : Implementing Cisco Data Center Unified Fabric (DCUFI) Vendor : Cisco

More information

Provisioning Overlay Networks

Provisioning Overlay Networks This chapter has the following sections: Using Cisco Virtual Topology System, page 1 Creating Overlays, page 2 Creating Network using VMware, page 3 Creating Subnetwork using VMware, page 4 Creating Routers

More information

LISP A Next Generation Networking Architecture

LISP A Next Generation Networking Architecture LISP A Next Generation Networking Architecture Victor Moreno Distinguished Engineer #clmel Agenda LISP Overview LISP Operations How setup LISP LISP Deployment Examples LISP Status LISP Summary 3 LISP Overview

More information

Page 2

Page 2 Page 2 Mgmt-B, vmotion-a vmotion-b VMM-Pool-B_ Connection-B -Set-A Uplink-Set-A Uplink-Set-B ACI-DC Standard Aggregation L3 Switch Configuration for existing Layer 2 : Nexus 6K-01 switch is

More information

Cisco Dynamic Fabric Automation Architecture

Cisco Dynamic Fabric Automation Architecture Cisco Dynamic Fabric Automation Architecture Lukas Krattiger Technical Marketing Engineer Agenda DFA Requirements and Functions Fabric Management Workload Automation Optimised Network Fabric Properties

More information

Virtual Subnet (VS): A Scalable Data Center Interconnection Solution

Virtual Subnet (VS): A Scalable Data Center Interconnection Solution Virtual Subnet (VS): A Scalable Data Center Interconnection Solution draft-xu-virtual-subnet-05 Xiaohu Xu (xuxh@huawei.com) NANOG52, Denver Requirements for Data Center Interconnection To interconnect

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, page 1 Licensing Requirements for VXLAN EVPN Multi-Site, page 2 Guidelines and Limitations for VXLAN EVPN Multi-Site, page 2 Enabling

More information

21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal. By Adeyemi Ademola E. Cloud Engineer

21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal. By Adeyemi Ademola E. Cloud Engineer 21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal By Adeyemi Ademola E. Cloud Engineer 1 Contents Introduction... 5 1.2 Document Purpose and Scope...5 Service Definition...

More information

LISP A Next-Generation Networking Architecture

LISP A Next-Generation Networking Architecture LISP A Next-Generation Networking Architecture LISP Disjointed RLOC Space Technical Details Version 0.8 30 October 2013 LISP Disjointed RLOC Space Details Agenda LISP Disjointed RLOC Space Technical Details

More information

Higher scalability to address more Layer 2 segments: up to 16 million VXLAN segments.

Higher scalability to address more Layer 2 segments: up to 16 million VXLAN segments. This chapter tells how to configure Virtual extensible LAN (VXLAN) interfaces. VXLANs act as Layer 2 virtual networks over Layer 3 physical networks to stretch Layer 2 networks. About VXLAN Encapsulation

More information

VXLAN EVPN Multi-Site Design and Deployment

VXLAN EVPN Multi-Site Design and Deployment White Paper VXLAN EVPN Multi-Site Design and Deployment 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 55 Contents What you will learn... 4

More information

LISP Multicast. Finding Feature Information. Prerequisites for LISP Multicast

LISP Multicast. Finding Feature Information. Prerequisites for LISP Multicast The feature introduces support for carrying multicast traffic over a Locator ID Separation Protocol (LISP) overlay. This support currently allows for unicast transport of multicast traffic with head-end

More information

Exam Questions

Exam Questions Exam Questions 642-997 DCUFI Implementing Cisco Data Center Unified Fabric (DCUFI) v5.0 https://www.2passeasy.com/dumps/642-997/ 1.Which SCSI terminology is used to describe source and destination nodes?

More information

Cisco Virtual Security Gateway (VSG) Mohammad Salaheldin

Cisco Virtual Security Gateway (VSG) Mohammad Salaheldin Cisco Virtual Security Gateway (VSG) Mohammad Salaheldin Virtual Security Gateway (VSG) Overview VSG Packet Flow VSG Policy Model Use Case Example ASA on 1000V Summary 2011 Cisco and/or its affiliates.

More information

Actual4Test. Actual4test - actual test exam dumps-pass for IT exams

Actual4Test.   Actual4test - actual test exam dumps-pass for IT exams Actual4Test http://www.actual4test.com Actual4test - actual test exam dumps-pass for IT exams Exam : 300-165 Title : Implementing Cisco Data Center Infrastructure Vendor : Cisco Version : DEMO Get Latest

More information

Architecting Scalable Clouds using VXLAN and Nexus 1000V

Architecting Scalable Clouds using VXLAN and Nexus 1000V Architecting Scalable Clouds using VXLAN and Nexus 1000V Lawrence Kreeger Principal Engineer Agenda Session Is Broken Into 3 Main Parts Part 1: VXLAN Overview What is a VXLAN? Why VXLANs? What is VMware

More information

Pluribus Adaptive Cloud Fabric

Pluribus Adaptive Cloud Fabric Product Overview Adaptive Cloud Fabric Powering the Software-Defined Enterprise Highlights Completely software enabled and built on open networking platforms Powered by the Netvisor ONE network Operating

More information

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. 1 Agenda 1. Overview and company presentation 2. Solution presentation 3. Main benefits to show to customers 4. Deployment models 2 VeloCloud Company

More information

LISP in Campus Networks

LISP in Campus Networks LISP in Campus Networks Divya Rao CCIE # 25083 Technical Marketing Engineer Enterprise Networking Group Abstract Session ID Title LISP in Campus Networks Abstract This session introduces LISP (Locator/ID

More information

How to Achieve True Active Active Data Centre Infrastructures

How to Achieve True Active Active Data Centre Infrastructures How to Achieve True Active Active Data Centre Infrastructures John Schaper Technical Solutions Architect BRKDCT-2615 # 5354 Agenda Introduction Mapping Applications to Business Criticality Levels Active

More information