Public Cloud Connection for R&E Network. Jin Tanaka APAN-JP/KDDI

Size: px
Start display at page:

Download "Public Cloud Connection for R&E Network. Jin Tanaka APAN-JP/KDDI"

Transcription

1 Public Cloud Connection for R&E Network Jin Tanaka APAN-JP/KDDI 45th APAN Meeting in Singapore 28th March 2018

2 Hyper Scale Public cloud and research & science data NASA EOSDIS(Earth Observing System Data and Information System are now running in AWS US Fermilab Use AWS to analyze data generated by CERN's LHC large research institute in Japan RIKEN in Japan provides genome data analysis environment to Japanese R&E institutes via Microsoft Azure World wide government and educational institutes use AWS

3 Public cloud services on Global s Internet2 NET+ GEANT Cloud Services SINET5 direct connect service AARNET CONNECT

4 NSF announced new collaboration with public clouds NSF Adds $30M to BIGDATA Program; AWS, Google, and Azure Participate The National Science Foundation (NSF) is providing nearly $30 million(3years) in new funding for research in data science and engineering through its Critical Techniques, Technologies and Methodologies for Advancing Foundations and Applications of Big Data Sciences and Engineering (BIGDATA) program. NSF's awards are paired with support from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure, which have each committed up to $3 million in cloud resources for relevant BIGDATA projects over a three-year period, beginning with this year s awards.

5 Cloud connection that the R&E network aims for Improve User Experience R&E network is a high performance, low latency than public internet Google cloud is also aiming for high performance networking It is important to have high-speed access to Public cloud in order to improve user experience Each peers with public cloud at local IX If IX is not nearby, consider connecting to nearby global open exchange point Where is the Network PoP and edge router of each major public cloud? We need to investigate the physical location of public cloud within the region Public Internet R&E Network

6 Cloud connection that can be realized in Asia try to connects with public cloud as much as possible in Asian main PoP Asia connect AWS Google GCP Microsoft Azure Asia connect Asia connect IP Peering Mapping the topology of major public cloud PoPs and APAN/Asia connect network connects to the nearest cloud PoP via IX and peer with them BGP based IP peering In particular, there are many clouds and commercial IXs, in Tokyo, Hong Kong, and Singapore are the best Commercial traffic not related cloud may flow, so NOC needs monitor traffic

7 Secure Privacy High Performance Reduce bandwidth cost How to connect to public cloud Connecting models of public clouds are almost same Classified into 3 connection methods: Public internet, VPN, and direct connect Some skills of network technology are required for the VPN and direct connect To reduce the burden on researchers and information, engineers should understand the cloud connection and learn its skill Network component and definition for each cloud services Configuration of IPsec VPN, Q-in-Q, BGP of each vendors INTERNET VPN DIRECT CONNECT Virtual machines can be set an Internet gateway to connect public Internet by user setting or by default. Mainly use for the providing a service with VMs in public subnet. Not suitable for sending important data from campus/ lab IPsec VPN tunnel connection between VPC and remote network AWS VPC - VPN Gateway Azure Virtual Network - VPN Gateway Google Cloud Virtual Network - VPN SD-WAN Options Can establish private/ dedicate connections to public clouds consistent performance AWS - Direct Connect Azure - Express Route Google - Cloud Interconnect

8 Secure Privacy High Performance Reduce bandwidth cost How to connect to public cloud Connecting models of public clouds are almost same Classified into 3 connection methods: Public internet, VPN, and direct connect Some skills of network technology are required for the VPN and direct connect To reduce the burden on researchers and information, engineers should understand the cloud connection and learn its skill Network component and definition for each cloud services Configuration of IPsec VPN, Q-in-Q, BGP of each vendors INTERNET VPN DIRECT CONNECT Virtual machines can be set an Internet gateway to connect public Internet by user setting or by default. Mainly use for the providing a service with VMs in public subnet. Not suitable for sending important data from campus/ lab IPsec VPN tunnel connection between VPC and remote network AWS VPC - VPN Gateway Azure Virtual Network - VPN Gateway Google Cloud Virtual Network - VPN SD-WAN Options Can establish private/ dedicate connections to public clouds consistent performance AWS - Direct Connect Azure - Express Route Google - Cloud Interconnect

9 VPN Connection IPsec via Internet Encrypted tunnel connections between your campus/lab and public cloud User prepare IPsec hardware router in your campus/lab as VPN end point Cisco, Juniper, Fortinet, Palo Alto, etc. Main parts to the configuration IPsec, IKE, Tunnel AES 128-bit/256-bit encryption, SHA-1/SHA-2 hashing Supports static routing and BGP(Option), and redundant gateway SD-WAN enables manage the public cloud WAN like a branch Centralized configuration and policy management across on premise and cloud end-points

10 AWS Direct connect Establishes a secure, dedicated connection to AWS Can reduce costs, increase bandwidth, and provide a more consistent network experience than Internet-based connections Single AWS direct connection allow us to build multi-region services Options to connect Physically direct connect at AWS Direct Connect location (1G, 10G only) Network service by AWS Direct Connect partner who is a member of the AWS Partner Network (APN) (10G, 1G, Sub-1G) Main parts to the configuration 802.1Q VLAN, BGP session and MD5 authentication, IPv4 and IPv6 BGP community to help control the scope(regional or global)and route preference

11 AWS Direct connect Establishes a secure, dedicated connection to AWS Can reduce costs, increase bandwidth, and provide a more consistent network experience than Internet-based connections Single AWS direct connection allow us to build multi-region services Options to connect Physically direct connect at AWS Direct Connect location (1G, 10G only) Network service by AWS Direct Connect partner who is a member of the AWS Partner Network (APN) (10G, 1G, Sub-1G) Main parts to the configuration 802.1Q VLAN, BGP session and MD5 authentication, AWS Direct IPv4 and connect IPv6 location related to BGP community to help control the scope(regional APAN or global)and route preference Global Switch, Singapore Equinix SG2, Singapore iadvantage Mega-i, Hong Kong KINX, Seoul, South Korea Equinix TY2, TY6 - TY8, Tokyo, Japan GPX, Mumbai, India Equinix SY1 - SY4, Sydney, Australia Global Switch, Sydney, Australia directconnect/details/

12 Google Cloud Interconnect Access to GCP over high speed and stable network Dedicated Interconnect This solution allows you to directly connect your on-premises network to GCP Requires you to have a connection in a Google supported colocation facility The minimum deployment per location is 10 Gbps. Main parts to the configuration EBGP-4 with multi-hop, 802.1Q VLAN, RFC 1918 address space Direct peering Connect your campus/lab directly to Google at any of 100+ locations in 33 countries is the simplest!! Carrier peering If you cannot satisfy Google s peering requirements, you can connect via a Carrier Peering partners

13 Google Cloud Interconnect Access to GCP over high speed and stable network Dedicated Interconnect This solution allows you to directly connect your on-premises network to GCP Requires you to have a connection in a Google supported colocation facility The minimum deployment per location is 10 Gbps. Main parts to the configuration EBGP-4 with multi-hop, 802.1Q VLAN, RFC 1918 address space Direct peering Connect your campus/lab directly to Google at any of 100+ locations in 33 countries is the simplest!! Carrier peering GCP interconnect colocation facility location related to APAN If you cannot satisfy Google s peering requirements, you can connect via a Carrier Peering partners Global Switch, Singapore Equinix SG2, Singapore iadvantage Mega-i, Hong Kong Equinix Hong Kong (HK2) Equinix TY2, Tokyo, Japan GPX, Mumbai, India Equinix SY3, Sydney, Australia NEXTDC S1, Sydney, Australia docs/concepts/colocation-facilities

14 Microsoft Azure Express route Provides private network access to 3 collections of Microsoft Azure resources More reliability, faster speeds, and lower latencies than Internet connections Express Route circuit consists of 2 redundant connections to Microsoft Edge Connectivity to Azure public, Azure private, and Microsoft (Office365,CRM) Global connectivity with ExpressRoute premium add-on Ports have an oversubscription ratio of 4:1 Options to connect CloudExchange Co-location, Point-to-point Ethernet Connection, IP-VPN connection Bandwidth 50M,100M,200M, 500M, 1G, 2G, 5G, 10G Main parts to the configuration 802.1ad(Q-inQ), BGP(community, Local preference, AS path prepend), etc.

15 Microsoft Azure Express route Provides private network access to 3 collections of Microsoft Azure resources More reliability, faster speeds, and lower latencies than Internet connections Express Route circuit consists of 2 redundant connections to Microsoft Edge Connectivity to Azure public, Azure private, and Microsoft (Office365,CRM) Global connectivity with ExpressRoute premium add-on Ports have an oversubscription ratio of 4:1 Options to connect CloudExchange Co-location, Point-to-point Ethernet Connection, IP-VPN connection Bandwidth 50M,100M,200M, 500M, 1G, 2G, Microsoft 5G, 10G Azure Express route location and NW provider related to APAN 802.1ad(Q-inQ), BGP(community, Local preference, AS path prepend), etc. NW: AARnet, SINET, GEANT, Intenet2 Main parts to the configuration Location : Singapore, Hong Kong Seoul, Mumbai, India, Tokyo Sydney, Australia expressroute/expressroute-locationsproviders#locations

16 VPN Model Connect to the nearest public cloud in Asian region with VPN Since there is not much difference from the current IP level connection, it is easiest to have secure connection to the cloud Asia connect don t need to set virtual circuits or additional routing protocol, simple Science flows will traverse the public Internet unless steps are taken to ingress and egress onto R&E networks instead of cloud provider transit networks Asia connect The public internet is highly fragmented and not engineered to support the large science data IP Peering

17 We NOCs are BGP Expert! We should provide high performance and high speed network

18 We NOCs are BGP Expert! We should provide high performance and high speed network Why don t we challenge to provide direct connect services!

19 Dedicated Direct connect Model Establish high capacity connection with Direct Connect or Direct Peer Connect directly to main public cloud PoP that will be near your country Asia connect connects to the public cloud by creating direct connection to supports the campus research institute Asia connect Designated Switch Dedicated VLAN It is possible to connect with the public cloud with high capacity and low latency, and support the large science data 's designated switches at direct connect location of cloud provides VLAN connectivity with neighboring router Tokyo, HongKong, Singapore

20 Open Exchange Point Model Open Exchange Point may be responsible for cloud exchange of R&E Network Open Exchange Point Backbone Asia connect Open Exchange Point OXP in Asian region should has a capability to support direct connect between the public cloud and s (by stand-alone or each-other) ensures connectivity for user institutions (as usual) connects to one or more OXPs Public cloud has connectivity through: Direct connections to Connections to one or more OXPs Networking should meet the agility of cloud service Deploy a dynamically controlled switch on demand and connect with the public cloud edge Provide flexible and scalable bandwidth between and cloud services for efficient use of network resources 10M 100M 200M 500M 1G 10G

21 OXP should be direct connect provider of public clouds What s issues? Technical Point Definition of provisioning flow when OXP set VLANs API inter-working for matching the VLAN-IDs on OXP and user-ids on public cloud services Direct connection is best but commercial commercial cloud exchange solves the difficulty of technology Commercial cloud exchange uses SDN technology for agility, R&E GXP must also implement similar technology Partner ship How we APAN make collaboration model between public cloud providers Collaboration between public cloud at the global level is required Implementation In case of direct connection public cloud and elaborate testing will be necessary First of all, we will start trial in GXP Japan planned in Tokyo User Interface SDN App SDN Interface OXP Switch API API DB SDN capability for cloud change service at OXP Distribute Open Exchange Point in Tokyo(Planning)

22 References AWS Microsoft Azure Google Cloud Platform NSF

CONNECTING TO AWS AND MICROSOFT AZURE

CONNECTING TO AWS AND MICROSOFT AZURE CONNECTING TO AWS AND MICROSOFT AZURE Warrick Mitchell warrick.mitchell@aarnet.edu.au Amazon Web Services (AWS) Microsoft Azure Google Compute Questions? AARNet Pty Ltd 2 AMAZON WEB SERVICES CONNECTIVITY

More information

MCR Google Cloud Partner Interconnect

MCR Google Cloud Partner Interconnect MCR Google Cloud Partner Interconnect 1 MCR Google Cloud Partner Interconnect MCR Connections to Google Cloud Platform using GCI Partner Google s private interconnection service is called Google Cloud

More information

How to Configure BGP over IKEv2 IPsec Site-to- Site VPN to an Google Cloud VPN Gateway

How to Configure BGP over IKEv2 IPsec Site-to- Site VPN to an Google Cloud VPN Gateway How to Configure BGP over IKEv2 IPsec Site-to- Site VPN to an Google Cloud VPN Gateway To connect to the Google Cloud VPN gateway, create an IPsec IKEv2 site-to-site VPN tunnel on your F-Series Firewall

More information

Multicloud Networking: An Overview. Shannon McFarland CCIE #5245 Distinguished

Multicloud Networking: An Overview. Shannon McFarland CCIE #5245 Distinguished Multicloud Networking: An Overview Shannon McFarland CCIE #5245 Distinguished Engineer @eyepv6 Agenda Hybrid Cloud Networking vs Multicloud Networking - A Level Set Extending on-premises private cloud

More information

RACKCONNECT GLOBAL PRODUCT DEEP DIVE:

RACKCONNECT GLOBAL PRODUCT DEEP DIVE: PRODUCT DEEP DIVE: RACK GLOBAL Connect to Rackspace and other off-premises data centers, including Microsoft Azure and Amazon Web Services, for the ultimate in multi-cloud cloud flexibility. TABLE OF CONTENTS

More information

CLOUD GATEWAY TECHNICAL GUIDE

CLOUD GATEWAY TECHNICAL GUIDE CLOUD GATEWAY TECHNICAL GUIDE TABLE OF CONTENTS INTRODUCTION...4 1 Why Cloud Gateway?...4 2 Why us?...4 3 Telstra Cloud Gateway overview...4 4 Network connectivity and bandwidth tiers...6 5 Cloud service

More information

New International Connectivities of SINET5

New International Connectivities of SINET5 Mar 28 th, 2018 at APAN45 New International Connectivities of SINET5 SINET 100G Global Ring Motonori Nakamura National Institute of Informatics (NII), Japan Academic Infrastructure operated by NII Our

More information

Update on Hong Kong Open exchange (HKOX) APAN Mar 2018

Update on Hong Kong Open exchange (HKOX) APAN Mar 2018 Update on Hong Kong Open exchange (HKOX) APAN 45 28 Mar 2018 HKOX Background HKOX is set up and managed by Joint Universities Computer Centre (JUCC) JUCC is a consortium of computing and IT services centres

More information

Cradlepoint to Palo Alto VPN Example. Summary. Standard IPSec VPN Topology. Global Leader in 4G LTE Network Solutions

Cradlepoint to Palo Alto VPN Example. Summary. Standard IPSec VPN Topology. Global Leader in 4G LTE Network Solutions Cradlepoint to Palo Alto VPN Example Summary This configuration covers an IPSec VPN tunnel setup between a Cradlepoint Series 3 router and a Palo Alto firewall. IPSec is customizable on both the Cradlepoint

More information

Top 30 AWS VPC Interview Questions and Answers Pdf

Top 30 AWS VPC Interview Questions and Answers Pdf Top 30 AWS VPC Interview Questions and Answers Pdf Top 30 AWS VPC Interview Questions and Answers Pdf AWS Certified Solutions Architect Begins the 30 Top Funding IT Certifications. Surely, AWS Architect

More information

Network. Arcstar Universal One

Network. Arcstar Universal One Network Universal One ARCSTAR UNIVERSAL ONE Universal One Enterprise Network NTT Communications' Universal One is a highly reliable, premium-quality network service, delivered and operated in more than

More information

Cisco CSR1000V Overview. Cisco CSR 1000V Use Cases in Amazon AWS

Cisco CSR1000V Overview. Cisco CSR 1000V Use Cases in Amazon AWS Cisco CSR1000V Overview The Cisco Cloud Services Router 1000V (CSR 1000V) sets the standard for enterprise network services and security in the Amazon Web Services (AWS) cloud. The Cisco CSR 1000V is based

More information

NTT Com Press Conference March 1, 2016 #enterprisecloud

NTT Com Press Conference March 1, 2016 #enterprisecloud NTT Com Press Conference March 1, 2016 #enterprisecloud 1 Significant Enhancement of Enterprise Cloud - Realizing Digital Transformation - NTT Communications March 1, 2016 2 NTT Communications Initiatives

More information

AWS Networking & Hybrid Cloud Connectivity

AWS Networking & Hybrid Cloud Connectivity AWS Networking & Hybrid Cloud Connectivity Gold Coast AWS User Group Nov 2015 Kent Plummer - VPN Solutions Managed Private IP Networks for Business vpnsolutions.com.au AWS Networking & Hybrid Cloud Connectivity

More information

Technologies for the coming GXP in Japan

Technologies for the coming GXP in Japan Technologies for the coming GXP in Japan Takatoshi Ikeda APAN-JP NOC/JGN NOC/TEIN-JP NOC/KDDI 1 2 Background Requirements Design and Technologies Distributed GXP in Asia Roadmap Agenda 3 Background 4 Why

More information

Extending Enterprise Security to Multicloud and Public Cloud

Extending Enterprise Security to Multicloud and Public Cloud Extending Enterprise Security to Multicloud and Public Cloud Paul Kofoid Sr. Consulting Engineer: Security & Cloud This statement of direction sets forth Juniper Networks current intention and is subject

More information

AXON. AWS Direct Connect CUSTOMER GUIDE. Technical Brief. Direct Connect. AXON ethernet

AXON. AWS Direct Connect CUSTOMER GUIDE. Technical Brief. Direct Connect. AXON ethernet AXON Technical Brief AWS Direct Connect CUSTOMER GUIDE Direct Connect where the cloud lives 13 NEXT sales@nextdc.com www.nextdc.com Contents AWS Direct Connect 4 AWS Direct Connect Local POP 5 AWS Direct

More information

AWS Direct Connect Deep Dive

AWS Direct Connect Deep Dive AWS Direct Connect Deep Dive Steve Seymour Principal Specialist Solutions Architect, AWS @sseymour What is AWS Direct Connect? AWS Direct Connect Dedicated, private connection into AWS Create private (VPC)

More information

Agenda. This Session: Azure Networking Basics, On-prem connectivity options DEMO Create VNET/Gateway Cost-estimation for VNET/Gateways

Agenda. This Session: Azure Networking Basics, On-prem connectivity options DEMO Create VNET/Gateway Cost-estimation for VNET/Gateways Onur Dogruoz Agenda Previous Sessions: Introduction to Azure Infrastructure as a Service (IaaS), Azure portal, role-based access control (RBAC), calculator overview VM Types, Azure Hybrid Use Benefits(AHUB),

More information

Best Practices for Extending the WAN into AWS (IaaS) with SD-WAN

Best Practices for Extending the WAN into AWS (IaaS) with SD-WAN Best Practices for Extending the WAN into AWS (IaaS) with SD-WAN Ariful Huq Product Management @arifulhuq & Rob McBride Marketing @digitalmcb Industry trends impacting networking Cloud Mobile Social 2

More information

Connectivity FastConnect Level 200. Jamal Arif November 2018

Connectivity FastConnect Level 200. Jamal Arif November 2018 Connectivity FastConnect Level 200 Jamal Arif November 2018 Copyright Copyright 2018, Oracle 2018, and/or Oracle its and/or affiliates. its affiliates. All rights reserved. All rights reserved. 1 Safe

More information

AWS Pilot Report M. O Connor, Y. Hines July 2016 Version 1.3

AWS Pilot Report M. O Connor, Y. Hines July 2016 Version 1.3 AWS Pilot Report M. O Connor, Y. Hines July 2016 Version 1.3 Ernest Orlando Lawrence Berkeley National Laboratory 1 Cyclotron Road, Berkeley, CA 94720 8148 This work was supported by the Director, Office

More information

Case 1: VPN direction from Vigor2130 to Vigor2820

Case 1: VPN direction from Vigor2130 to Vigor2820 LAN to LAN IPSec VPN between Vigor2130 and Vigor2820 using Aggressive mode In this document we will introduce how to create a LAN to LAN IPSec VPN between Vigor2130 and a Vigor2820 using Aggressive mode.

More information

How to Configure a Site-To-Site IPsec VPN to the Amazon AWS VPN Gateway

How to Configure a Site-To-Site IPsec VPN to the Amazon AWS VPN Gateway How to Configure a Site-To-Site IPsec VPN to the Amazon AWS VPN Gateway If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both

More information

Architecture Overview

Architecture Overview Architecture Overview For organizations that need high quality video conferencing and want to avoid burdening their IT staff and resources, VidyoCloud is a hosted video collaboration solution that provides

More information

Oracle Cloud. Using Oracle Network Cloud Service - FastConnect Standard Edition E

Oracle Cloud. Using Oracle Network Cloud Service - FastConnect Standard Edition E Oracle Cloud Using Oracle Network Cloud Service - FastConnect Standard Edition E74464-05 April 2017 Oracle Cloud Using Oracle Network Cloud Service - FastConnect Standard Edition, E74464-05 Copyright 2016,

More information

HKIX Development and HKIX-R&E Updates at APAN 46

HKIX Development and HKIX-R&E Updates at APAN 46 HKIX Development and HKIX-R&E Updates at APAN 46 Kenneth CHAN Team Lead, HKIX www.hkix.net 5-9 Aug 2018, Auckland What is HKIX? Established in Apr 1995, Hong Kong Internet exchange (HKIX) is the main layer-2

More information

3/10/2011. Copyright Link Technologies, Inc.

3/10/2011. Copyright Link Technologies, Inc. Mikrotik Certified Trainer / Engineer MikroTik Certified Dude Consultant Consulting Since 1997 Enterprise Class Networks WAN Connectivity Certifications Cisco, Microsoft, MikroTik BGP/OSPF Experience Deployed

More information

Microsoft Azure Configuration. Azure Setup for VNS3

Microsoft Azure Configuration. Azure Setup for VNS3 Microsoft Azure Configuration Azure Setup for VNS3 2016 Table of Contents Requirements 3 Create Azure Private VLAN 10 Launch VNS3 Image from Azure Marketplace 15 Deliver and launch VNS3 from Azure 22 VNS3

More information

GÉANT IP Service Description. High Performance IP Services to Support Advanced Research

GÉANT IP Service Description. High Performance IP Services to Support Advanced Research GÉANT IP Service Description High Performance IP Services to Support Advanced Research Issue Date: 1 November 2017 GÉANT IP Overview The GÉANT IP service provides high-bandwidth, international Internet

More information

How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT

How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT Table of Contents TABLE OF CONTENTS 1 INTRODUCTION 2 AWS Configuration: 2 Forcepoint Configuration 3 APPENDIX 7 Troubleshooting

More information

Cisco Multicloud Portfolio: Cloud Connect

Cisco Multicloud Portfolio: Cloud Connect Design and Deployment Guide Cisco Multicloud Portfolio: Cloud Connect Design and Deployment Guide for Private Data Center to AWS VPC October 2018 2018 Cisco and/or its affiliates. All rights reserved.

More information

Course Outline. Module 1: Microsoft Azure for AWS Experts Course Overview

Course Outline. Module 1: Microsoft Azure for AWS Experts Course Overview Course Outline Module 1: Microsoft Azure for AWS Experts Course Overview In this module, you will get an overview of Azure services and features including deployment models, subscriptions, account types

More information

The Possible Hong Kong Open Exchange Point. Che-Hoo CHENG 04 Aug 2016

The Possible Hong Kong Open Exchange Point. Che-Hoo CHENG 04 Aug 2016 The Possible Hong Kong Open Exchange Point Che-Hoo CHENG 04 Aug 2016 Developing a Blueprint for Global R&E Network Architecture http://gna-re.net The Global Network Architecture program (GNA) is an international

More information

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

VMware Cloud on AWS Networking and Security. 5 September 2018 VMware Cloud on AWS

VMware Cloud on AWS Networking and Security. 5 September 2018 VMware Cloud on AWS VMware Cloud on AWS Networking and Security 5 September 2018 VMware Cloud on AWS You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have

More information

HKIX Updates at APAN 44

HKIX Updates at APAN 44 HKIX Updates at APAN 44 Kenneth CHAN Team Lead, HKIX www.hkix.net 31 Aug 2017 What is HKIX? Established in Apr 1995, Hong Kong Internet exchange (HKIX) is the main layer-2 Internet exchange Point (IXP)

More information

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

Transit Network VPC. AWS Reference Deployment Guide. Last updated: May 10, Aviatrix Systems, Inc. 411 High Street Palo Alto, CA USA

Transit Network VPC. AWS Reference Deployment Guide. Last updated: May 10, Aviatrix Systems, Inc. 411 High Street Palo Alto, CA USA Transit Network VPC AWS Reference Deployment Guide Last updated: May 10, 2017 Aviatrix Systems, Inc. 411 High Street Palo Alto, CA 94301 USA http://www.aviatrix.com Tel: +1 844.262.3100 TABLE OF CONTENTS

More information

VNS3 Configuration. Quick Launch for first time VNS3 users in Azure

VNS3 Configuration. Quick Launch for first time VNS3 users in Azure VNS3 Configuration Quick Launch for first time VNS3 users in Azure Table of Contents Setup 3 Notes 9 Create a Static IP 12 Create a Network Security Group 14 Launch VNS3 from Marketplace 19 VNS3 Unencrypted

More information

OpenKilda. Stream Processing Meets OpenFlow. Jeff Young Product Architecture, Global Platforms

OpenKilda. Stream Processing Meets OpenFlow. Jeff Young Product Architecture, Global Platforms OpenKilda Stream Processing Meets OpenFlow Jeff Young Product Architecture, Global Platforms Agenda What is the Telstra Programmable Network? Why Build on Openflow? Why Create (yet another) Openflow Controller?

More information

AUTOMATE THE DEPLOYMENT OF SECURE DEVELOPER VPCs

AUTOMATE THE DEPLOYMENT OF SECURE DEVELOPER VPCs AUTOMATE THE DEPLOYMENT OF SECURE DEVELOPER VPCs WITH PALO ALTO NETWORKS AND REAN CLOUD 1 INTRODUCTION EXECUTIVE SUMMARY Organizations looking to provide developers with a free-range development environment

More information

Dimension Data IaaS Services. Gary Ramsay

Dimension Data IaaS Services. Gary Ramsay Dimension Data IaaS Services Gary Ramsay 29.08.2017 In a world first, Dimension Data provided real-time data analytics on each of the 198 riders in this year s Tour de France. accelerate your ambition

More information

ENTERPRISE INTERNET SOLUTIONS AWS IS CLOUDCONNECT SOLUTION OVERVIEW

ENTERPRISE INTERNET SOLUTIONS AWS IS CLOUDCONNECT SOLUTION OVERVIEW ENTERPRISE INTERNET SOLUTIONS AWS IS CLOUDCONNECT SOLUTION OVERVIEW INTERNET SOLUTIONS PARTNERSHIP WITH AMAZON WEB SERVICES (AWS) DIRECT CONNECT Our partnership with AWS enables us to offer our enterprise

More information

JGN2plus. Presenter: Munhwan Choi

JGN2plus. Presenter: Munhwan Choi JGN2plus Presenter: Munhwan Choi JGN2plus Type of Services Network Structure R&D with SPARC Status of Utilization Overview JGN2plus JGN2plus looks for the visions of the future ICT society through activities

More information

Transform your network and your customer experience. Introducing SD-WAN Concierge

Transform your network and your customer experience. Introducing SD-WAN Concierge Transform your network and your customer experience Introducing SD-WAN Concierge Optimize your application performance, lower your total cost of ownership and simplify your network management. 2X Bandwith

More information

Cisco Cloud Services Router 1000V and Amazon Web Services CASE STUDY

Cisco Cloud Services Router 1000V and Amazon Web Services CASE STUDY Cisco Cloud Services Router 1000V and Amazon Web Services CASE STUDY CASE STUDY ADOBE 2 About Adobe Adobe Systems provides digital media and marketing solutions to customers around the world including

More information

How to Configure an IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

Reaping the Full Benefits of a Hybrid Network

Reaping the Full Benefits of a Hybrid Network Singtel Business Product Factsheet Managed Hybrid Network Reaping the Full Benefits of a Hybrid Network Singtel Managed Hybrid Network is an innovative offering that extends the enterprise s network coverage

More information

Voice of the Customer First American Title SD-WAN Transformation

Voice of the Customer First American Title SD-WAN Transformation Voice of the Customer First American Title SD-WAN Transformation CJ Metz First American - Senior IT Manager, Network Eng Archish Dalal Viptela Senior Systems Engineer #FutureWAN First American Financial

More information

Global Deployment of SD-WAN. Mike Howell October 2017

Global Deployment of SD-WAN. Mike Howell October 2017 Global Deployment of SD-WAN Mike Howell October 2017 Rentokil Initial Rentokil Initial is a member of the FTSE100 and is an international pest control and hygiene services company. 35,000+ employees 1800

More information

Configuring Aviatrix Encryption

Configuring Aviatrix Encryption Configuring Aviatrix Encryption For AWS Direct Connect Azure Express Route Google Cloud Interconnect Last updated: October 9, 2016 Aviatrix Systems, Inc. 4555 Great America Pkwy Santa Clara CA 95054 USA

More information

New Asian IP Backbone Architecture

New Asian IP Backbone Architecture New Asian IP Backbone Architecture Hideo Ishii Vice President, Product Strategy & Management, IP & Cloud Services Pacnet MyNOG 16th January 2012 Who is Pacnet? 2 International Connectivity in Asia Countries

More information

AWS Networking Fundamentals

AWS Networking Fundamentals AWS Networking Fundamentals Tom Adamski Specialist Solutions Architect, AWS Traditional Network WAN VPN VPN Fiber Applications Applications AWS Network VPN WAN (AWS Direct Connect) VPN Fiber Applications

More information

Transform your network and your customer experience. Introducing SD-WAN Concierge

Transform your network and your customer experience. Introducing SD-WAN Concierge Transform your network and your customer experience Introducing SD-WAN Concierge Optimize your application performance, lower your total cost of ownership and simplify your network management. 2X Bandwith

More information

Measurement and Monitoring. Yasuichi Kitmaura Takatoshi Ikeda

Measurement and Monitoring. Yasuichi Kitmaura Takatoshi Ikeda Measurement and Monitoring Yasuichi Kitmaura (kita@jp.apan.net) Takatoshi Ikeda (ikeda@kddnet.ad.jp) Who are we? Yasuichi Kitamura researcher of National Institute of Information and Communications Technology

More information

Introducing AWS Transit Gateway

Introducing AWS Transit Gateway Introducing AWS Transit Gateway Nick Matthews Principal Solutions Architect AWS @nickpowpow Mohamed Hassan Senior Product Manager EC2 Networking, AWS @mohnader What is Transit Gateway? Introducing AWS

More information

Microsoft Azure for AWS Experts

Microsoft Azure for AWS Experts Microsoft Azure for AWS Experts OD40390B; On-Demand, Video-based Course Description This course provides an in-depth discussion and practical hands-on training of Microsoft Azure Infrastructure Services

More information

Network Service Description

Network Service Description Network Service Description Applies to: Office 365 Dedicated Topic Last Modified: 2015-09-03 Contents... 1 Network Architecture... 2 Customer Connectivity to Services... 5 Customer-Owned Private Network

More information

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme LHC2384BU VMware Cloud on AWS A Technical Deep Dive Ray Budavari @rbudavari Frank Denneman - @frankdenneman #VMworld #LHC2384BU Disclaimer This presentation may contain product features that are currently

More information

CLOUD GATEWAY TECHNICAL GUIDE INTERNATIONAL

CLOUD GATEWAY TECHNICAL GUIDE INTERNATIONAL CLOUD GATEWAY TECHNICAL GUIDE DRAFT [SECURITY CLASSIFICATION] CLOUD GATEWAY TECHNICAL GUIDE INTERNATIONAL WELCOME TO CLOUD GATEWAY For sales, account set-up enquiries and technical support, contact your

More information

Securizarea Calculatoarelor și a Rețelelor 32. Tehnologia MPLS VPN

Securizarea Calculatoarelor și a Rețelelor 32. Tehnologia MPLS VPN Platformă de e-learning și curriculă e-content pentru învățământul superior tehnic Securizarea Calculatoarelor și a Rețelelor 32. Tehnologia MPLS VPN MPLS VPN 5-ian-2010 What this lecture is about: IP

More information

Cloud Transformation and Significance of Security

Cloud Transformation and Significance of Security Cloud Transformation and Significance of Security Mohit Sharma, Chief Architect & Cloud Evangelist @onlinesince2009 www.cloudsec.com Datacenter Management Change Management Policy Physical Network Management

More information

Nuts & Bolts of Networking in Azure. Pracheta Budhwar Technology Evangelist, Microsoft

Nuts & Bolts of Networking in Azure. Pracheta Budhwar Technology Evangelist, Microsoft Learn. Connect. Explore. Nuts & Bolts of Networking in Azure Pracheta Budhwar Technology Evangelist, Microsoft India @prachetab Agenda Must know concepts of networking on Azure Scenarios - Most commonly

More information

Virtual Private Cloud. User Guide. Issue 03 Date

Virtual Private Cloud. User Guide. Issue 03 Date Issue 03 Date 2016-10-19 Change History Change History Release Date What's New 2016-10-19 This issue is the third official release. Modified the following content: Help Center URL 2016-07-15 This issue

More information

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco PSOACI-4592 Why ACI: An overview and a customer (BBVA) perspective TJ Bijlsma César Martinez Joaquin Crespo Technology Officer DC EMEAR Cisco Lead Architect BBVA Lead Architect BBVA Cisco Spark How Questions?

More information

Hybrid Cloud and Connecting to MS Azure

Hybrid Cloud and Connecting to MS Azure Hybrid Cloud and Connecting to MS Azure Michael Schofield, Sr. Global Solutions Architect November, 2016 2016 Equinix Inc. #EQIXAD16 Agenda Who is Equinix Cloud Technology Overview Hybrid Cloud Connecting

More information

Cross-Site Virtual Network Provisioning in Cloud and Fog Computing

Cross-Site Virtual Network Provisioning in Cloud and Fog Computing This paper was accepted for publication in the IEEE Cloud Computing. The copyright was transferred to IEEE. The final version of the paper will be made available on IEEE Xplore via http://dx.doi.org/10.1109/mcc.2017.28

More information

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. 1 Agenda 1. Overview and company presentation 2. Solution presentation 3. Main benefits to show to customers 4. Deployment models 2 VeloCloud Company

More information

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002 Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002 Agenda Joint Cisco and Microsoft Integration Efforts Introduction to CCA-MCP What is a Pattern?

More information

FortiGate. on OCB FE Configuration Guide. 6 th December 2018 Version 1.0

FortiGate. on OCB FE Configuration Guide. 6 th December 2018 Version 1.0 on OCB FE 6 th December 2018 Version 1.0 document control date version no. author change/addition 6 th December 2018 1.00 Ahmad Samak Creation Internal Use Only 2 of 24 table of contents 1 References...

More information

CCNA ROUTING & SWITCHING

CCNA ROUTING & SWITCHING CCNA ROUTING & SWITCHING Curriculum Overview The CCNA Routing and Switching curriculum consists of four courses that make up the recommended learning path. Students will be prepared to take the Cisco CCENT

More information

BGP Case Studies. ISP Workshops

BGP Case Studies. ISP Workshops BGP Case Studies ISP Workshops These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/) Last updated

More information

Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites

Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites The recommended knowledge and skills that a learner must have before attending this course are as follows: Knowledge

More information

GÉANT L3VPN Service Description. Multi-point, VPN services for NRENs

GÉANT L3VPN Service Description. Multi-point, VPN services for NRENs GÉANT L3VPN Service Description Multi-point, VPN services for NRENs Issue Date: 1 November 2017 GÉANT L3VPN Overview The GÉANT L3VPN service offers the National Research and Education Networks (NRENs)

More information

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV.

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV. 2 CHAPTER Cisco's Disaster Recovery as a Service (DRaaS) architecture supports virtual data centers that consist of a collection of geographically-dispersed data center locations. Since data centers are

More information

EXPRESSROUTE STRATEGY & CONNECTIVITY WORKSHOP

EXPRESSROUTE STRATEGY & CONNECTIVITY WORKSHOP EXPRESSROUTE STRATEGY & CONNECTIVITY WORKSHOP FOR THE ENTERPRISE Equinix.com/eps We needed help confirming our network could support O365 peering via ExpressRoute, as well as peering options, provisioning

More information

Overview. AWS networking services including: VPC Extend your network into a virtual private cloud. EIP Elastic IP

Overview. AWS networking services including: VPC Extend your network into a virtual private cloud. EIP Elastic IP Networking in AWS 2017 Amazon Web Services, Inc. and its affiliates. All rights served. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon Web Services,

More information

Singapore Advanced Research and Education Network. ipv6.singaren.net.sg

Singapore Advanced Research and Education Network.   ipv6.singaren.net.sg Singapore Advanced Research and Education Network www.singaren.net.sg ipv6.singaren.net.sg Background Singapore Advanced Research and Education Network (SingAREN) facilitates the cost-competitive adoption

More information

Peering as a Cloud enabler for Enterprises

Peering as a Cloud enabler for Enterprises Peering as a Cloud enabler for Enterprises Lionel MARIE Network architect Schneider Electric Advisor Self employed Former Board Member France-IX (2013-2015) Schneider Electric at a Glance We are the global

More information

Quick Introduction of HKIX. Che-Hoo Cheng Development Director APNIC

Quick Introduction of HKIX. Che-Hoo Cheng Development Director APNIC Quick Introduction of HKIX Che-Hoo Cheng Development Director APNIC What is HKIX? Established in Apr 1995, Hong Kong Internet exchange (HKIX) is the main layer-2 Internet exchange Point (IXP) in Hong Kong

More information

Deploying Cisco SD-WAN on AWS

Deploying Cisco SD-WAN on AWS How to Guide Deploying Cisco SD-WAN on AWS Introduction: Why use an SD-WAN solution for the cloud? Organizations leveraging branch office locations, IoT devices, and distributed network devices face a

More information

Cato Cloud. Software-defined and cloud-based secure enterprise network. Solution Brief

Cato Cloud. Software-defined and cloud-based secure enterprise network. Solution Brief Cato Cloud Software-defined and cloud-based secure enterprise network Solution Brief Legacy WAN and Security Appliances are Incompatible with the Modern Enterprise Cato Networks: Software-defined and Cloud-based

More information

/ Lot 1 Standard Service Offer Data Access Services Service Offer RM1045-L1-SSO Pinacl

/ Lot 1 Standard Service Offer Data Access Services Service Offer RM1045-L1-SSO Pinacl / Lot 1 Standard Service Offer Data Access Services Service Offer RM1045-L1-SSO-00002-Pinacl Standard Service Offer - Connectivity MPLS with Cloud Service Provider Connectivity MPLS (Multiprotocol Label

More information

1. Click on "IaaS" to advance to the Windows Azure Scenario. 2. Click to configure the "CloudNet" Virtual Network

1. Click on IaaS to advance to the Windows Azure Scenario. 2. Click to configure the CloudNet Virtual Network Introduction to the Virtual Network Lab Scenario Steps Description 1. Click on "IaaS" to advance to the Windows Azure Scenario Windows Azure Infrastructure Services ( IaaS ) provides us with the capability

More information

ASX NET. In Detail: Connectivity Guide

ASX NET. In Detail: Connectivity Guide ASX NET In Detail: Connectivity Guide CONTENTS INTRODUCTION 2 ASX NET SITE REQUIREMENTS 3 ASX NET SERVICES OVERVIEW 4 ASX NET SERVICES IN DETAIL 5 ASX NET NETWORK SERVICES 6 ASX NET GLOBAL OVERVIEW 11

More information

MPLS VPN--Inter-AS Option AB

MPLS VPN--Inter-AS Option AB The feature combines the best functionality of an Inter-AS Option (10) A and Inter-AS Option (10) B network to allow a Multiprotocol Label Switching (MPLS) Virtual Private Network (VPN) service provider

More information

Introduction to Segment Routing

Introduction to Segment Routing Segment Routing (SR) is a flexible, scalable way of doing source routing. Overview of Segment Routing, page 1 How Segment Routing Works, page 2 Examples for Segment Routing, page 3 Benefits of Segment

More information

Configuring High Availability

Configuring High Availability This section contains the following topics: Information about High Availability, on page 1 Error Messages for Amazon Web Services High Availability, on page 3 How to Configure High Availability, on page

More information

Cloud Security Best Practices

Cloud Security Best Practices Cloud Security Best Practices Cohesive Networks - your applications secured Our family of security and connectivity solutions, VNS3, protects cloud-based applications from exploitation by hackers, criminal

More information

AT&T NetBond for SoftLayer

AT&T NetBond for SoftLayer NetBond for Service Activation Overview 2016 Intellectual Property. All rights reserved., Globe logo and other marks are trademarks and service marks of Intellectual Property and/or affiliated companies.

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

How to configure IPSec VPN between a CradlePoint router and a Fortinet router

How to configure IPSec VPN between a CradlePoint router and a Fortinet router How to configure IPSec VPN between a CradlePoint router and a Fortinet router Summary This article presents an example configuration of a Policy-Based site-to-site IPSec VPN tunnel between a Series 3 CradlePoint

More information

Impact of IPv6 On By Default in ISP

Impact of IPv6 On By Default in ISP Impact of IPv6 On By Default in ISP VIETNAM IPV6 DAY 2014 NTT Communications Corporation Network Services Yasuhiro Shirasaki 2014-05-06 Agenda 1. Background 2. How we turned On IPv6 3. The impact of IPv6

More information

Advanced CSR Lab with High Availability and Transit VPC

Advanced CSR Lab with High Availability and Transit VPC Advanced CSR Lab with High Availability and Transit VPC Fan Yang, Cisco, Engineer, Technical Marketing Nikolai Pitaev, Cisco, Engineer, Technical Marketing LTRVIR-3004 Agenda Slides (30 Min.): CSR 1000V

More information

Google Cloud VPN Interop Guide

Google Cloud VPN Interop Guide Google Cloud VPN Interop Guide Using Cloud VPN With Fortinet FortiGate 300C Fortinet, FortiGate, and other Fortinet marks are trademarks of Fortinet, Inc., its subsidiaries and affiliates. Contents Introduction

More information

HKIX Updates & Bilateral Peering over HKIX

HKIX Updates & Bilateral Peering over HKIX HKIX Updates & Bilateral Peering over HKIX Che-Hoo CHENG 鄭志豪 The Chinese University of Hong Kong / Hong Kong Internet Exchange 29 JAN 2010 Introduction of HKIX (1/2) HKIX is a Settlement-Free Layer-2 2

More information

Connectivity Services, Autobahn and New Services

Connectivity Services, Autobahn and New Services Connectivity Services, Autobahn and New Services Domenico Vicinanza, DANTE EGEE 09, Barcelona, 21 st -25 th September 2009 Agenda Background GÉANT Connectivity services: GÉANT IP GÉANT Plus GÉANT Lambda

More information

1. Introduction. 2. Purpose of this paper and audience. Best Practices 1 for Cloud Provider Connectivity for R&E Users

1. Introduction. 2. Purpose of this paper and audience. Best Practices 1 for Cloud Provider Connectivity for R&E Users Best Practices 1 for Cloud Provider Connectivity for R&E Users Authors (in alphabetical order): Erik-Jan Bos 2, Lars Fischer 2, David Foster 3 & Josva Kleist 2 Date: 31 August 2016 Version: 2.0 1. Introduction

More information

QTS IS ABOUT CONNECTING YOU

QTS IS ABOUT CONNECTING YOU QTS IS ABOUT CONNECTING YOU Where you need it, When you need it, How you need it. MORE THAN DATA SOLUTIONS. DATA SOLVED. QTS recognizes that robust,you need it, carrier-neutral connectivity is a key component

More information