SP Datacenter fabric technologies. Brian Kvisgaard System Engineer CCIE SP #41039

Size: px
Start display at page:

Download "SP Datacenter fabric technologies. Brian Kvisgaard System Engineer CCIE SP #41039"

Transcription

1 SP Datacenter fabric technologies Brian Kvisgaard System Engineer CCIE SP #41039

2 VMDC 2.1 DC Container Architecture Simplified architecture Services on the stick design modification (Core/Agg handoff) Core Cisco Nexus 7000 Enterprise centric services integration Enterprise multi-tenancy SLA with QoS and alignment with WAN/Campus QoS requirements Functional multicast integration with multi-tenancy Services Aggregation Cisco Nexus 7000 Nexus 1010 integration and Network analysis and monitoring (NAM) capability validation Access vpc Cisco Nexus 5000 Jumbo MTU support and jumbo frame validation Compute and Storage Components UCS Blade Server Compute Nexus 1010 VMware vcenter VMware vsphere 4x10GE 4x10G E 4x10G E 4x10G E Cisco UCS 6100 Fabric Interconnect UCS 5100 Blade Server NAS Storage vpc to N5K

3 Traditional Networking Management options: CLI Cut/Paste Limited automation Disparate management platforms Limitations: Box by box approach Lack of consistent configuration (no network wide policies) Leftover/unknown configuration Open any to any connectivity* Separate virtual and physical networks Separate L4-7 device management

4 ACI Networking APIC APIC APIC Management options: GUI (basic/advanced) CLI XML/JSON Scripting Open API Automation Benefits: Distributed, Centralised Management Full traffic visibility* Self documenting Integrated virtual and physical network Integrated L4-7 device management Policy defined network

5 New Concept: Endpoint Groups Endpoint Groups are quite simply groups of endpoints on the network. The endpoints are identified by their connectivity Domain (virtual/physical/outside) and their connectivity method e.g. Virtual machine portgroups (VLAN, VXLAN) Physical interfaces / VLANs External VLANs External subnets Devices within the same Endpoint group can communicate irrespective of their VLAN/VXLAN backing/id, provided that they have IP reachability. Communication between Endpoint groups is, by default, not permitted (similar to PVLAN).

6 Secure Networking with ACI End Point Groups APIC APIC APIC VRF: 01 (Anycast gateway) BD: storage Hardware Proxy: No ARP Flooding: Yes Unknown Unicast Flooding: Yes IP Routing: No BD: vmotion Hardware Proxy: No ARP Flooding: Yes Unknown Unicast Flooding: Yes IP Routing: No BD: Host-Mgmt Hardware Proxy: No ARP Flooding: Yes Unknown Unicast Flooding: Yes IP Routing: No Endpoints in EPG identified by Interface and VLAN ID vpc_to_ucs_a vlan-12 vpc_to_ucs_b vlan-12 vpc_to_ucs_a vlan-10 vpc_to_ucs_b vlan-10 vpc_to_ucs_a vlan-8 vpc_to_ucs_b vlan-8 ANP: ESXi-Hosts EPG: vmk-storage Security Zone EPG: vmotion Security Zone EPG: Host-Mgmt Security Zone Tenant: ESXi-Hosts Communication allowed within EPG Communication allowed within EPG Communication allowed within EPG

7 Hypervisor Integration APIC Network Admin APIC ACI Fabric Integrated gateway for VLAN, VxLAN, NVGRE networks from virtual to physical Normalization for NVGRE, VXLAN, VLAN VXLAN VLAN NVGRE VLAN VXLAN VLAN and VLAN networks ESX Hyper-V KVM Customer not restricted by a choice of hypervisor PHYSICAL SERVER Fabric is ready for multi-hypervisor Application Admin Hypervisor Management

8 New concept: Contracts (ACLs) Contracts are directional Access Lists between Provider and Consumer EPGs. They comprise of one or more Filters (ACEs) to identify traffic, e.g: Contract: Any-to-Any Filter: Any-Traffic Contract: Web Filter: 80, 443, 8000 Contract: DNS Filter: 53 ANP: My-Web-App Provider EPG: Web Filter: 80, 443 etc Contract: Clients-to-Web Any-to-Any Flags : IP Protocol Ports Stateful Etc. Filter: none Flags : Consumer External Subnet EPG: Clients L3out: Clients Apply in both directions (single contract which allows return traffic) Reverse filter ports (dynamically permits return flow based on src/dst ports)

9 Contracts are Required for Inter EPG Connectivity APIC APIC APIC VRF: 01 (Anycast gateway) BD: ESXi Hardware Proxy: Yes ARP Flooding: No Unknown Unicast Flooding: No IP Routing: /24 : /24 Primary Gateway: /24 Secondary Gateway: /24 vpc Node104_105/1/50 vlan-40 vpc_to_ucs_a vlan-30 vpc_to_ucs_b vlan-30 vpc_to_ucs_a vlan-8 vpc_to_ucs_b vlan-8 ANP: ESXi-Storage EPG: Shared-storage ANP: ESXi-Hosts EPG: vmk-storage EPG: Host-Mgmt Tenant: ESXi-Hosts Contract = Allow Communication No Contract = No Communication

10 Contracts Scope Contracts are scoped at: Global Tenant Context (aka Private Network, aka VRF) Web_to_App Application Profile App_to_DB ANP: 01 EPG: Web EPG: Web EPG: App EPG: App EPG: DB EPG: DB BD: 01 Hardware Proxy: Yes IP Routing: Yes ANP: 02 VRF: 01 Tenant: Web_Hosting

11 Application Centric Infrastructure DB DB Web Web App Web App Turnkey integrated solution with security, centralized management, compliance and scale Automated application centric-policy model with embedded security Broad and deep ecosystem Mass Market (commercial, enterprises, public sector)

12 Programmable Network across the Nexus portfolio Starting with programmability boost on N3K /N9K Programmable Open APIs 3 rd Party DevOps Automation Tools Custom Application Development Managing Switch with Linux Tools DC Repository 3 rd party/custom apps integration Nexus Open, Modular Operating System Toolset Integration in Open NX-OS Extensible Open NX-OS Leverage Linux Toolchain for Switch Management Enhancements to existing NX-API to support objectbased, model driven APIs (RESTful XML/JSON) Pre-developed RPMs from Cisco and Partners Leverage same software tools and expertise across different IT departments New SDK enables custom application development with option for securelxc containers CPU, memory, priority controls Leverage tcpdump, ifconfig ethtool, iproute, BASH shell commands for config and troubleshooting *Deliverables and Timelines for Nexus platforms varies*

13 Application Centric Infrastructure Programmable Network DB DB Web Web App Web App Turnkey integrated solution with security, centralized management, compliance and scale Automated application centric-policy model with embedded security Broad and deep ecosystem Modern NX-OS with enhanced NX-APIs Automation Ecosystem (Puppet, Chef, Ansible etc.) Common NX-API across N2K-N9K Mass Market (commercial, enterprises, public sector) Mega Scale Datacenters

14 VTE P IP Transport Network VTE P VXLAN VNI Local LAN Local LAN Segment Local LAN Local LAN Underlay Network: IP routing proven, stable, scalable ECMP utilize all available network paths Overlay Network: Standards-based overlay Layer-2 extensibility and mobility Expanded Layer-2 name space (16M) Scalable network domain Multi-Tenancy

15 Dst. MAC Addr. Src. MAC Addr. VLAN Type 0x8100 VLAN ID Tag Ether Type 0x0800 IP Header Misc Data Protocol 0x11 Header Checksum Outer Src. IP Outer Dst. IP UDP Src. Port UDP Dst Port UDP Length Checksu m 0x0000 VXLAN RRRR1RRR Reserved VNID Reserved Outer Mac Header Outer IP Header UDP Header VXLAN Header Original L2 Frame FCS FCS 10 or 14 Bytes 20 Bytes 8 Bytes 8 Bytes For next-hop transport in the underlay network Source and Destination addresses, allowing transport across the underlay IP network Allows for possible The well known VXLAN port Indicates a 16M segments VXLAN packet Hash of the internal L2/L3/L4 header of the original frame. Can be used as entropy for better ECMP/LACP load sharing

16 VXLAN terminates its tunnels on s (Virtual Tunnel End Point). Each has two interfaces, one is to provide bridging function for local hosts, the other has an IP identification in the core network for VXLAN encapsulation/decapsulation. Transport IP Network IP Interface IP Interface Local LAN Segment Local LAN Segment End System End System End System End System

17 No VXLAN control plane Data driven flood-&-learn Multicast transport for VXLAN BUM (Broadcast, Unknown Unicast and Multicast) traffic. End System End System -3 3 IP-3 End System A MAC-A IP-A -1 1 IP-1 Multicast Group IP Network -2 2 IP-2 End System B MAC-B IP-B

18 The Secret Sauce is the Control Plane, not the Encapsulation

19 MP-BGP with MPLS VPN Route Distribution Exchange of VPN Policies Among PE Routers Full mesh of BGP sessions among all PE routers BGP Route Reflector PE-CE Link BGP Route Reflector PE-CE Link Multi-Protocol BGP extensions (MP-iBGP) to carry VPN policies PE-CE routing options Static routes ebgp OSPF IS-IS CE CE Blue VPN Policy Red VPN Policy PE PE P P P P PE PE CE BlueVPN Policy` Red VPN Policy CE Label Switched Traffic

20 VPN Control Plane Processing VRF Parameters Make customer routes unique: Route Distinguisher (RD): 8-byte field, VRF parameters; unique value to make VPN IP routes unique VPNv4 address: RD + VPN IP prefix Selective distribute VPN routes: Route Target (RT): 8-byte field, VRF parameter, unique value to define the import/export rules for VPNv4 routes MP-iBGP: advertises VPNv4 prefixes + labels

21 Ethernet VPN Highlights Next generation solution for Ethernet multipoint connectivity services Leverage similarities with L3VPN Data-plane address learning from Access Control-plane address advertisement / learning over Core PEs run Multi-Protocol BGP to advertise & learn MAC addresses over Core Learning on PE Access Circuits via dataplane transparent learning VID 100 SMAC: M1 DMAC: F.F.F CE1 PE1 PE3 CE3 No pseudowire full-mesh required Unicast: use MP2P tunnels Multicast: use ingress replication over MP2P tunnels or use LSM MPLS Under standardization at IETF draft-ietfl2vpn-evpn PE2 BGP MAC adv. Route E-VPN NLRI MAC M1 via PE1 PE4

22 EVPN Ethernet VPN VXLAN Evolution Control- Plane EVPN MP-BGP draft-ietf-l2vpn-evpn Data- Plane Multi-Protocol Label Switching (MPLS) draft-ietf-l2vpn-evpn Provider Backbone Bridges (PBB) draft-ietf-l2vpn-pbb-evpn Network Virtualization Overlay (NVO) draft-sd-l2vpn-evpn-overlay EVPN over NVO Tunnels (VXLAN, NVGRE, MPLSoE) for Data Center Fabric encapsulations Provides Layer-2 and Layer-3 Overlays over simple IP Networks 22

23 DC Core 3-Tier Design Fabric Design DC Spine DC Aggregation DC Access DC Leaf Collapsed Core/Aggregation 2-Tier Design DC-1 DC Interconnect DC-2 DC Core/ Aggregation DC Access WAN

24 Flood-&-Learn EVPN Control Plane Overlay Services L2+L3 L2+L3 Underlay Network IP network with ECMP IP network with ECMP Encapsulation MAC in UDP MAC in UDP Peer Discovery Data-driven flood-&-learn MP-BGP Peer Authentication Not available MP-BGP Host Route Learning Local hosts: Data-driven flood-&-learn Remote hosts: Data-driven flood-&-learn Host Route Distribution No route distribution. MP-BGP Local Host: Data-driven Remote host: MP-BGP L2/L3 Unicast Forwarding Unicast encap Unicast encap BUM Traffic forwarding Multicast replication Unicast/Ingress replication Multicast replication Unicast/Ingress replication

25 MP-BGP for EVPN MP-BGP is the routing protocol for EVPN Multi-tenancy construct using VRF (Rout Distinguisher, Route Targets) New address-family l2vpn evpn for distributing EVPN routes EVPN routes = [MAC] + [IP] ibgp or ebgp support vrf context evpn-tenant-1 vni rd auto address-family ipv4 unicast route-target both auto route-target both auto evpn evpn vni l2 rd auto route-target import auto route-target export auto router bgp 100 router-id log-neighbor-changes address-family ipv4 unicast address-family l2vpn evpn neighbor remote-as 100 update-source loopback0 address-family ipv4 unicast address-family l2vpn evpn send-community extended vrf evpn-tenant-1 address-family ipv4 unicast advertise l2vpn evpn

26 C Install host info to RIB/FIB: H-MAC-1 MAC table H-IP-1 VRF IP host table Host IP VNI AC- H-IP-1 VNII BGP Update: H-MAC-1 H-IP-1-1 VNI Route Reflector 2 3 BGP Update: H-MAC-1 H-IP-1-1 VNI-1 BGP Update: H-MAC-1 H-IP-1-1 VNI Install host info to RIB/FIB: H-MAC-1 MAC table H-IP-1 VRF IP host table MAC Host IP VNI H-MAC-1 H-IP-1 VNII-1-1 MAC Host IP VNI H-MAC-1 H-IP-1 VNII-1-1 Local learning of host info: H-MAC-1 (MAC table) H-IP-1 (VRF IP host table ) 1-1 H-MAC-1 H-IP-1 VLAN-1 /VNI-1 BGP Update RD: Route distinguisher MAC address length: 6 bytes MAC address: Host MAC address IP address length: 32 or 128 IP address: Host IP address (IPv4 or IPv6) L2 VNI: VNI of the bridge domain to which the end host belongs L3 VNI: VNI associated with the tenant VRF routing instance

27 VXLAN BGP Control Plane EVPN Control Plane --- Host Movement NLRI: Host MAC1, IP1 NVE IP 1 VNI 5000 Next-Hop: -1 NLRI: Host MAC1, IP1 NVE IP 1 VNI 5000 Next-Hop: -3 Ext. Community: Encapsulation: VXLAN Cost/Sequence: 1 Ext. Community: Encapsulation: VXLAN Cost/Sequence: 0 Host 1 MAC1 IP 1 VNI MAC IP VNI Next-Hop Encap Seq MAC-1 IP VXLAN 0 MAC IP VNI Next-Hop Encap Seq MAC-1 IP VXLAN detects Host1 and advertise an EVPN route for Host1 with seq# 0 2. Host1 Moves behind detects Host1 and advertises an EVPN route for Host1 with seq # sees more recent route and withdraws its advertisement

28 SVI GW IP GW MAC Host 1 MAC1 IP 1 VLAN A VXLAN A Host 2 MAC2 IP 2 VLAN A VXLAN A Host 3 MAC3 IP 3 VLAN A VXLAN A Host 4 MAC4 IP 4 VLAN A VXLAN A

29 # VLAN to VNI mapping vlan 200 vn-segment 5200 # Anycast Gateway MAC, identically configured on all s fabric forwarding anycast-gateway-mac The same anycast gateway virtual IP address and MAC address need to be configured on all s in the VNI # Distributed IP Anycast Gateway (SVI) # Gateway IP address needs to be identically configured on all s interface vlan 200 no shutdown vrf member Tenant-A ip address /24 fabric forwarding mode anycast-gateway SVI GW IP GW MAC SVI GW IP GW MAC SVI GW IP GW MAC SVI GW IP GW MAC Host 1 MAC1 IP 1 VLAN A VXLAN A Host 2 MAC2 IP 2 VLAN A VXLAN A Host 3 MAC3 IP 3 VLAN A VXLAN A Host 4 MAC4 IP 4 VLAN A VXLAN A

30 ARP Suppression in MP-BGP EVPN ARP suppression reduces network flooding due to host learning IP Address MAC Address VLAN Physical Interface Index (ifindex) Flags IP-1 MAC-1 10 E1/1 Local IP-2 MAC-2 10 Null Remote IP-3 MAC-3 10 Null Remote -1 intercepts the ARP request and checks in its ARP suppression cache. It finds a match for IP-2 in its ARP suppression cache.* sends an ARP response back to Host-1 with MAC-2.* Host-1 learns the IP-2 and MAC-2 mapping. 3 4 Host 1 MAC1 IP 1 VLAN 10 VXLAN Host 1 MAC1 IP 2 VLAN 10 VXLAN 5000 Host-1 in VLAN 10 sends an ARP request for Host-2 s IP-2 address. * If -1 doesn t have a match for IP-2 in its ARP suppression cache table, it will flood the ARP request to all other s in this VNI 30

31 ARP Suppression in MP-BGP EVPN (Cont ed) ARP Suppression can be enabled on a per-vni basis under the interface nve1 configuration interface nve1 no shutdown source-interface loopback0 host-reachability protocol bgp member vni suppress-arp mcast-group member vni suppress-arp mcast-group member vni associate-vrf member vni associate-vrf n9396-vtep-1.sakommu-lab.com# sh ip arp suppression topo-info ARP L2RIB Topology information Topo-id ARP-suppression mode 100 L2 ARP Suppression 200 L2/L3 ARP Suppression 201 L2/L3 ARP Suppression

32 Head-end Replication Head-end Replication (aka. Ingress replication): Eliminate the need for underlay multicast to transport overlay BUM traffic Multicast-Free Spine Underlay 2-1 receives the overlay BUM traffic, encapsulates the packets into unicast VXLAN packets, sends one copy to each remote peer in the same VXLAN VNI Leaf 1 Host-1 sends BUM traffic into the VXLAN VNI 32

33 Different integrated Route/Bridge (IRB) Modes VXLAN Routing Overlay Networks do follow two slightly different integrated Route/Bridge (IRB) semantics Asymmetric Uses different path from Source to Destination and back Symmetric Uses same path from Source to Destination and back Cisco follows Symmetric IRB SVI A -1 Host 1 H-MAC-1 H-IP-1 VNI-A -2 Routing? IP Transport Network -3 SVI B -4 Host 2 H-MAC-2 H-IP-2 VNI-B

34 Asymmetric Routing and Bridging on the ingress Bridging on the egress Both source and destination VNIs need to reside on the ingress Ingress routes packets from source VNI to destination VNI. D- MAC in the inner header is the destination host MAC VNI A 1 VNI B S-IP: -1 D-IP: -4 VNI: VNI-B S-MAC: H-MAC-1 D-MAC: H-MAC-2 S-IP: H-IP-1 D-IP: H-IP-2 VNI A VNI B S-MAC: H-MAC-1 D-MAC: H-MAC-2 S-IP: H-IP-1 D-IP: H-IP-2 S-MAC: H-MAC-1 D-MAC: H-MAC-2 S-IP: H-IP-1 D-IP: H-IP-2-1 Host 1 H-MAC-1 H-IP-1 VNI-A Host 2 H-MAC-2 H-IP-2 VNI-B 2 Egress bridges packets in the destination VNI

35 VXLAN BGP Control Plane VNI Membership Asymmetric IRB Every needs to be in all VNIs Every needs to maintain MAC tables for all VNIs, including those they don t have local hosts for. SVI 100 SVI 200 SVI 100 SVI 200 SVI 100 SVI 200 SVI 100 SVI 200 Host 1 MAC1 IP 1 VLAN 100 VXLAN 5100 Host 2 MAC2 IP 2 VLAN 100 VXLAN 5100 Host 3 MAC3 IP 3 VLAN 200 VXLAN All s in a VNI can be the virtual IP gateway for the local hosts 2. Optimized south-north bound forwarding for routed traffic without hair-pinning

36 Routing on both ingress and egress s Layer-3 VNI Tenant VPN indicator One per tenant VRF Router MAC Ingress routes packets onto the Layer-3 VNI Egress routes packets to the destination Layer-2 VNI

37 Ingress routes packets from source VNI to L3 VNI. D-MAC in the inner header is the egress router MAC VNI A 1 L3 VNI S-IP: -1 D-IP: -4 VNI: L3 VNI S-MAC: Router-MAC-1 D-MAC: Router-MAC-4 S-IP: H-IP-1 D-IP: H-IP-2 L3 VNI 2 VNI B Egress routes packets from L3 VNI to the destination VNI/VLAN S-MAC: H-MAC-1 D-MAC: H-MAC-2 S-IP: H-IP-1 D-IP: H-IP-2-1 Router MAC Router MAC-4 S-MAC: H-MAC-1 D-MAC: H-MAC-2 S-IP: H-IP-1 D-IP: H-IP-2 Host 1 H-MAC-1 H-IP-1 VNI-A Host 2 H-MAC-2 H-IP-2 VNI-B

38 VXLAN BGP Control Plane VNI Membership Symmetric IRB Every only needs to be in VNIs that it has local hosts for. s don t need to maintain MAC tables for VNIs that they don t have local hosts for. SVI 100 SVI 100 SVI 200 Host 1 MAC1 IP 1 VLAN 100 VXLAN 5100 Host 2 MAC2 IP 2 VLAN 100 VXLAN 5100 Host 3 MAC3 IP 3 VLAN 200 VXLAN Optimal utilization of ARP and MAC tables 2. A only needs to be in the VNIs which it has local hosts for.

39 -1 IP Transport Network S-MAC: Router-MAC-1 D-MAC: Router-MAC-2 S-IP: H-IP-1 D-IP: H-IP-2 S-IP: -1 D-IP: -2 VNI: L3-VNI-A -2 Use addresses in the outer header to route encapsulated packets to the egress S-IP: -1 D-IP: -2 VNI: L3 VNI-A S-MAC: Router-MAC-1 D-MAC: Router-MAC-4 S-IP: H-IP-1 D-IP: H-IP-2 Use L3-VNI to identify the tenant VRF S-MAC: H- MAC-1 D-MAC: H- MAC-2 S-IP: H-IP-1 D-IP: H-IP-2 Host 1 H-MAC-1 H-IP-1 VNI-A L3-VNI-A VRF-A S-MAC: H- MAC-1 D-MAC: H- MAC-2 S-IP: H-IP-1 D-IP: H-IP-2 Host 2 H-MAC-2 H-IP-2 VNI-B L3-VNI-A VRF-A Tenant A VRF-A L3-VNI-A H-IP-2 Tenant B VRF-B L3-VNI-B Tenant C VRF-C L3-VNI-C

40 Symmetric IRB has optimal utilization of ARP and MAC tables on a Symmetric IRB scales better for end hosts Symmetric IRB scales better in terms of the total number of VNIs a VXLAN overlay network can support Multi-vendor interoperability: Some vendors implemented Asymmetric IRB It s been agreed upon among multiple vendors that Symmetric IRB is the ultimate solution Cisco implemented Symmetric IRB Cisco will introduce backward compatability with asymmetric IRB by adding the support for it.

41 Local Scoping of VLANs ToR Local 16 million possible VNIs global scope VNI 5000 maps to VLAN 10 VLANS are Locally Scoped at Top of Rack/ Gateway Possible VLAN IDs 1-4K VNI 5000 maps to VLAN 60 VLANS are Locally Scoped at Top of Rack/ Gateway Possible VLAN IDs 1-4K 41

42 Local Scoping of VLANs Port Local* * Available in Q2CY million possible VNIs global scope (Eth1/1, Vlan10) => VNI (Eth1/2, Vlan10) => VNI (Eth1/2, Vlan11) => VNI VNI 5000 maps to (E1/1, VLAN 10) VNI 5000 maps to (E1/2, VLAN 60 VLANS are Locally Scoped VLAN to VNI mapping is per-port significant Possible VLAN IDs 1-4K VLANS are Locally Scoped VLAN to VNI mapping is per-port significant Possible VLAN IDs 1-4K 42

43 Underlay IP Network BGP Router ID 1 BGP Router ID 2 vpc with Anycast Address vpc -1 Virtual PortChannel vpc -2 interface loopback0 ip address /32 ip address /32 secondary Layer 2 Link Layer 3 Link

44 EVPN Control Plane Advantages A multi-tenant fabric solution with host-based forwarding Industry standard protocol for multi-vendor interoperability Build-in multi-tenancy support Leverage MP-BGP to deliver VXLAN with L3VPN characteristics Truly scalable with protocol-driven learning Host MAC/IP address advertisement through EVPN MP-BGP Fast convergence upon host movements or network failures MP-BGP protocol driven re-learning and convergence Upon host movement, the new will send out a BGP update to advertise the new location of the host

45 EVPN Control Plane Advantages (Cont ed) A multi-tenant fabric solution with host-based forwarding Optimal traffic forwarding supporting host mobility Anycast IP gateway for optimal forwarding for host generated traffic No need for hair-pinning to to reach the IP gateway ARP suppression Minimize ARP flooding in overlay Head-end Replication with dynamically learned remote- list Head-end replication enables multicast-free underlay network Dynamically learned remote- list minimizes the operational overhead of head-end replication peer authentication via MP-BGP authentication Added security to prevent rogue s or spoofing

46 Application Centric Infrastructure Programmable Fabric Programmable Network DB DB Web Web App Web App Turnkey integrated solution with security, centralized management, compliance and scale Automated application centric-policy model with embedded security Broad and deep ecosystem VxLAN-BGP EVPN standard-based 3 rd party controller support Modern NX-OS with enhanced NX-APIs Automation Ecosystem (Puppet, Chef, Ansible etc.) Common NX-API across N2K-N9K Mass Market (commercial, enterprises, public sector) Service Providers Mega Scale Datacenters

47 Application Centric Infrastructure Programmable Fabric Programmable Network VTS DB DB Web Web App Web App Turnkey integrated solution with security, centralized management, compliance and scale VxLAN-BGP EVPN standard-based Modern OS with enhanced APIs Integrated Overlay and Underlay optimizations Overlay optimizations Mass Market (commercial, enterprises, public sector) Service Providers Mega Scale Datacenters

48 Cisco Virtual Topology System (VTS) Overlay Provisioning & Management System Cisco Network Services Orchestrator VMware vcenter GUI Flexible Overlays Physical and Virtual Overlays Bare-metal and Virtualized Workloads Service Chaining REST API Automated Seamless Integration with Orchestrators Automated Overlay Provisioning Automated DCI/WAN Integration Open and Programmable REST-Based Northbound APIs Multi-protocol Support Multi-hypervisor Support Cisco Virtual Topology System YANG CLI NX-API BGP-EVPN Scalable VXLAN Mgmt. MP-BGP EVPN Control Plane Virtual Tenant Networks High Performance Virtual Forwarding Nexus Portfolio Nexus 2k 9k

49 VTS Architecture Cisco Network Services Orchestrator (Tail-f) VMware vcenter GUI Unified Information Model (REST API) Virtual Topology System Service and Infrastructure Policy Resource Management Device Management Inventory Database IOS XRv Policy Plane Control Plane Control Plane Federation MP-BGP YANG CLI NX-API BGP-EVPN Virtual Compute Environment Cisco Nexus 2000, 3000, 5000, and 7000 Series Cisco Nexus 9000 Series Cisco ASR 9000 Series OVS VTF DVS

50 EVPN Control Plane S1 MAC, IP Address 1 S2 MAC, IP Address 2 S3 MAC, IP Address 3 S4 MAC, IP Address 4 Industry standard protocol for multi-vendor support IP Transport Network MP-BGP EVPN RR Built in multi-tenancy support VXLAN VNI Restconf/YANG Scalable, protocol driven control plane architecture Fast convergence upon network failures and host movements VTF 4 Local LAN Local LAN LAN Segment Local LAN Local LAN Minimize flooding through ARP suppression S1 S2 S3 S4 Overlay Forwarding Table Security through peer-authentication S1 MAC, IP Address P1/2 S2 MAC, IP Address 2 S3 MAC, IP Address 3 S4 MAC, IP Address 4

51 VTS Architecture Hardware Switches Spine Spine REST API Cisco VTS NX-API, CLI, YANG ToR ToR ToR VMware vcenter Hypervisor Hypervisor Hypervisor VM VM VM VM x86 Server x86 Server x86 Server 51

52 VTS Architecture Integrated DCI Simpler Configuration Single MP-BGP session for all tenants DCI REST API Cisco VTS NX-API, CLI, YANG Spine Spine L3 VNIs (Route) VRF Route-Leaking L3PVN Stitching ToR ToR ToR VMware vcenter Hypervisor Hypervisor Hypervisor VM VM VM VM x86 Server x86 Server x86 Server 52

53 VTS Architecture - VTF User space packet forwarder, Multi tennant DCI Uses Cisco Vector Packet Processing technology Border Leaf Integrated with Intel DPDK Supports VXLAN, extend to e.g SR, MPLS, MPLSoGRE, L2TPv3.. VTF (VM) Programmed by VTS using Restconf/YANG Tenant VM Tenant VM Spine VTF (VM) Spine Tenant VM Tenant VM REST API Cisco VTS NX-API, CLI, YANG vswitch vswitch vswitch ESXi ToR ToR ToR KVM NIC NIC VMware vcenter Hypervisor Hypervisor Hypervisor VM VM VM VM x86 Server x86 Server x86 Server 53

54 VTS Hardware and Software overlay management and provisioning NX-OS mode based VXLAN fabric with MP-BGP EVPN & ToR-based anycast gateway BGP-EVPN VXLAN Overlay Hardware Underlay (standards-based) Hardware-based Overlay (standards-based) VTS ESX Bare Metal ESX Bare Metal ESX Software-based Overlay (standards-based)

55 VTS OpenStack Workflow VTS provisions, VLAN for each and EVPN on ToR/VTF 7 1 Create Tenant Networks 2 Tenent and Tenant Networks Created NX-API, CLI, YANG Spine Spine REST API Cisco VTS OpenStack Tenant View 3 VNID assigned for each network ToR VXLAN ToR VXLAN ToR 4 Attach VM to Network 5 VM Host info captured by VTS and mapped to the right ToR & ToR port using topology database 6 Neutron agent modified to request VLAN information from VTS before programming vswitch Hypervisor 55 VLAN VM x86 Server VLAN Hypervisor VM VM x86 Server VLAN Hypervisor VM x86 Server VLAN

56 VTS OpenStack Workflow 9 VTS provisions L3 VXLAN (distributed L2/L3), Anycast gateway with EVPN Spine Spine NX-API, CLI, YANG REST API Cisco VTS VXLAN VXLAN OpenStack Tenant View ToR ToR ToR VLAN VLAN VLAN Hypervisor Hypervisor Hypervisor VLAN 8 Create router and attach interfaces to tenant networks VM x86 Server VM x86 Server VM VM x86 Server 56

57 Admin Domain d1

58 Administration BGP Route Reflector The Administrator can choose to install BGP RR configuration on 1. Virtualized XR 2. Inline RR on Nexus9k Spine

59 View Virtual Forwarding Group compute2 compute1 BOTH XRv and VTFs register w/ VTS automatically Control Plane is xrv02 running IOS-XR

60 What does VTS provide Infrastructure Providers Tenant selfprovisioning Neutron Abstracted view of a network-wide topology Automate VM discovery in topology and provision virtual network attachment. Make it simple for the end-user SW Forwarder Seamless P2V HW Forwarder SW forwarder for brownfield deployment HW forwarder for performance Virtual Appliance inter-working w/ Physical appliance WA N Connect Tenant networks to Provider Networks Stitch Provider L3VPN to Tenant DC virtual network(s) Tenants attach to External networks via Provider Network VTE P VTE P VTE P VTE P VTE P VTE P

61 Application Centric Infrastructure Programmable Fabric Programmable Network DB DB Web Web App Web App Turnkey integrated solution with security, centralized management, compliance and scale Automated application centric-policy model with embedded security Broad and deep ecosystem VxLAN-BGP EVPN standard-based 3 rd party controller support VTS for software overlay provisioning and management across N2K-N9K Modern NX-OS with enhanced NX-APIs Automation Ecosystem (Puppet, Chef, Ansible etc.) Common NX-API across N2K-N9K Mass Market (commercial, enterprises, public sector) Service Providers Mega Scale Datacenters

62

MP-BGP VxLAN, ACI & Demo. Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017

MP-BGP VxLAN, ACI & Demo. Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017 MP-BGP VxLAN, ACI & Demo Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017 Datacenter solutions Programmable Fabric Classic Ethernet VxLAN-BGP EVPN standard-based Cisco DCNM Automation Modern

More information

Cisco VTS. Enabling the Software Defined Data Center. Jim Triestman CSE Datacenter USSP Cisco Virtual Topology System

Cisco VTS. Enabling the Software Defined Data Center. Jim Triestman CSE Datacenter USSP Cisco Virtual Topology System Cisco Virtual Topology System Cisco VTS Enabling the Software Defined Data Center Jim Triestman CSE Datacenter USSP jtriestm@cisco.com VXLAN Fabric: Choice of Automation and Programmability Application

More information

Implementing VXLAN in DataCenter

Implementing VXLAN in DataCenter Implementing VXLAN in DataCenter LTRDCT-1223 Lilian Quan Technical Marketing Engineering, INSBU Erum Frahim Technical Leader, ecats John Weston Technical Leader, ecats Why Overlays? Robust Underlay/Fabric

More information

Cisco Virtual Topology System (VTS)

Cisco Virtual Topology System (VTS) Cisco Virtual Topology System (VTS) Cisco Knowledge Network Presentation Vijay Arumugam and Palak Desai Product Management, Cloud and Virtualization Feb 3, 2016 Agenda Trends and Challenges in SP market

More information

Introduction to External Connectivity

Introduction to External Connectivity Before you begin Ensure you know about Programmable Fabric. Conceptual information is covered in the Introduction to Cisco Programmable Fabric and Introducing Cisco Programmable Fabric (VXLAN/EVPN) chapters.

More information

Introduction to Cisco Virtual Topology System DP Ayyadevara, Product Manager, Cloud Virtualization Cisco PSOSDN-1050

Introduction to Cisco Virtual Topology System DP Ayyadevara, Product Manager, Cloud Virtualization Cisco PSOSDN-1050 Introduction to Cisco Virtual Topology System DP Ayyadevara, Product Manager, Cloud Virtualization Group @ Cisco PSOSDN-1050 Agenda Cisco Data Center SDN Strategy Programmable Fabric with VTS VTS Architecture

More information

IP Fabric Reference Architecture

IP Fabric Reference Architecture IP Fabric Reference Architecture Technical Deep Dive jammon@brocade.com Feng Shui of Data Center Design 1. Follow KISS Principle Keep It Simple 2. Minimal features 3. Minimal configuration 4. Configuration

More information

Provisioning Overlay Networks

Provisioning Overlay Networks This chapter has the following sections: Using Cisco Virtual Topology System, page 1 Creating Overlays, page 2 Creating Network using VMware, page 4 Creating Subnetwork using VMware, page 4 Creating Routers

More information

Cisco Virtual Topology System Release Service Provider Data Center Cisco Knowledge Network. Phil Lowden (plowden) October 9, 2018

Cisco Virtual Topology System Release Service Provider Data Center Cisco Knowledge Network. Phil Lowden (plowden) October 9, 2018 Cisco Virtual Topology System Release 2.6.2 Service Provider Data Center Cisco Knowledge Network Phil Lowden (plowden) October 9, 2018 Cisco VTS is a standards-based, open software-overlay management and

More information

Introduction to Cisco Virtual Topology System (VTS) Vijay Arumugam Kannan - Product Manager, VTS

Introduction to Cisco Virtual Topology System (VTS) Vijay Arumugam Kannan - Product Manager, VTS Introduction to Cisco Virtual Topology System (VTS) Vijay Arumugam Kannan - Product Manager, VTS Agenda Cisco Data Center SDN Strategy Cisco Virtual Topology System (VTS) VTS Use Cases Cisco Virtual Topology

More information

VXLAN Deployment Use Cases and Best Practices

VXLAN Deployment Use Cases and Best Practices VXLAN Deployment Use Cases and Best Practices Azeem Suleman Solutions Architect Cisco Advanced Services Contributions Thanks to the team: Abhishek Saxena Mehak Mahajan Lilian Quan Bradley Wong Mike Herbert

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, page 1 Guidelines and Limitations for VXLAN EVPN Multi-Site, page 2 Enabling VXLAN EVPN Multi-Site, page 2 Configuring VNI Dual

More information

Hierarchical Fabric Designs The Journey to Multisite. Lukas Krattiger Principal Engineer September 2017

Hierarchical Fabric Designs The Journey to Multisite. Lukas Krattiger Principal Engineer September 2017 Hierarchical Fabric Designs The Journey to Multisite Lukas Krattiger Principal Engineer September 2017 A Single Fabric, a Single Data Center External Layer-3 Network Pod 1 Leaf/ Topologies (aka Folded

More information

Contents. EVPN overview 1

Contents. EVPN overview 1 Contents EVPN overview 1 EVPN network model 1 MP-BGP extension for EVPN 2 Configuration automation 3 Assignment of traffic to VXLANs 3 Traffic from the local site to a remote site 3 Traffic from a remote

More information

Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003

Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003 Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003 Agenda ACI Introduction and Multi-Fabric Use Cases ACI Multi-Fabric Design Options ACI Stretched Fabric Overview

More information

Data Center Configuration. 1. Configuring VXLAN

Data Center Configuration. 1. Configuring VXLAN Data Center Configuration 1. 1 1.1 Overview Virtual Extensible Local Area Network (VXLAN) is a virtual Ethernet based on the physical IP (overlay) network. It is a technology that encapsulates layer 2

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, page 1 Licensing Requirements for VXLAN EVPN Multi-Site, page 2 Guidelines and Limitations for VXLAN EVPN Multi-Site, page 2 Enabling

More information

HPE FlexFabric 5940 Switch Series

HPE FlexFabric 5940 Switch Series HPE FlexFabric 5940 Switch Series EVPN Configuration Guide Part number: 5200-2002b Software version: Release 25xx Document version: 6W102-20170830 Copyright 2017 Hewlett Packard Enterprise Development

More information

Huawei CloudEngine Series. VXLAN Technology White Paper. Issue 06 Date HUAWEI TECHNOLOGIES CO., LTD.

Huawei CloudEngine Series. VXLAN Technology White Paper. Issue 06 Date HUAWEI TECHNOLOGIES CO., LTD. Issue 06 Date 2016-07-28 HUAWEI TECHNOLOGIES CO., LTD. 2016. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any means without prior written consent of

More information

Ethernet VPN (EVPN) in Data Center

Ethernet VPN (EVPN) in Data Center Ethernet VPN (EVPN) in Data Center Description and Design considerations Vasilis Stavropoulos Sparkle GR EVPN in Data Center The necessity for EVPN (what it is, which problems it solves) EVPN with MPLS

More information

Provisioning Overlay Networks

Provisioning Overlay Networks This chapter has the following sections: Using Cisco Virtual Topology System, page 1 Creating Overlays, page 2 Creating Network using VMware, page 3 Creating Subnetwork using VMware, page 4 Creating Routers

More information

VXLAN Design with Cisco Nexus 9300 Platform Switches

VXLAN Design with Cisco Nexus 9300 Platform Switches Guide VXLAN Design with Cisco Nexus 9300 Platform Switches Guide October 2014 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 39 Contents What

More information

Extreme Networks How to Build Scalable and Resilient Fabric Networks

Extreme Networks How to Build Scalable and Resilient Fabric Networks Extreme Networks How to Build Scalable and Resilient Fabric Networks Mikael Holmberg Distinguished Systems Engineer Fabrics MLAG IETF TRILL Cisco FabricPath Extreme (Brocade) VCS Juniper QFabric IEEE Fabric

More information

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN This module provides conceptual information for VXLAN in general and configuration information for layer 2 VXLAN on Cisco ASR 9000 Series Router. For configuration information of layer 3 VXLAN, see Implementing

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, on page 1 Licensing Requirements for VXLAN EVPN Multi-Site, on page 2 Guidelines and Limitations for VXLAN EVPN Multi-Site, on

More information

Building Data Center Networks with VXLAN EVPN Overlays Part I

Building Data Center Networks with VXLAN EVPN Overlays Part I BRKDCT-2949 Building Data Center Networks with VXLAN EVPN Overlays Part I Lukas Krattiger, Principal Engineer Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session

More information

Solution Guide. Infrastructure as a Service: EVPN and VXLAN. Modified: Copyright 2016, Juniper Networks, Inc.

Solution Guide. Infrastructure as a Service: EVPN and VXLAN. Modified: Copyright 2016, Juniper Networks, Inc. Solution Guide Infrastructure as a Service: EVPN and VXLAN Modified: 2016-10-16 Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net All rights reserved.

More information

Network Virtualization in IP Fabric with BGP EVPN

Network Virtualization in IP Fabric with BGP EVPN EXTREME VALIDATED DESIGN Network Virtualization in IP Fabric with BGP EVPN Network Virtualization in IP Fabric with BGP EVPN Version 2.0 9035383 February 2018 2018, Extreme Networks, Inc. All Rights Reserved.

More information

EXTREME VALIDATED DESIGN. Network Virtualization in IP Fabric with BGP EVPN

EXTREME VALIDATED DESIGN. Network Virtualization in IP Fabric with BGP EVPN EXTREME VALIDATED DESIGN Network Virtualization in IP Fabric with BGP EVPN 53-1004308-07 April 2018 2018, Extreme Networks, Inc. All Rights Reserved. Extreme Networks and the Extreme Networks logo are

More information

Virtual Extensible LAN and Ethernet Virtual Private Network

Virtual Extensible LAN and Ethernet Virtual Private Network Virtual Extensible LAN and Ethernet Virtual Private Network Contents Introduction Prerequisites Requirements Components Used Background Information Why you need a new extension for VLAN? Why do you chose

More information

Ethernet VPN (EVPN) and Provider Backbone Bridging-EVPN: Next Generation Solutions for MPLS-based Ethernet Services. Introduction and Application Note

Ethernet VPN (EVPN) and Provider Backbone Bridging-EVPN: Next Generation Solutions for MPLS-based Ethernet Services. Introduction and Application Note White Paper Ethernet VPN (EVPN) and Provider Backbone Bridging-EVPN: Next Generation Solutions for MPLS-based Ethernet Services Introduction and Application Note Last Updated: 5/2014 Ethernet VPN (EVPN)

More information

VXLAN Cisco and/or its affiliates. All rights reserved. Cisco Public

VXLAN Cisco and/or its affiliates. All rights reserved. Cisco Public VXLAN Presentation ID 1 Virtual Overlay Encapsulations and Forwarding Ethernet Frames are encapsulated into an IP frame format New control logic for learning and mapping VM identity (MAC address) to Host

More information

BESS work on control planes for DC overlay networks A short overview

BESS work on control planes for DC overlay networks A short overview BESS work on control planes for DC overlay networks A short overview Jorge Rabadan IETF99, July 2017 Prague 1 Agenda EVPN in a nutshell BESS work on EVPN for NVO3 networks EVPN in the industry today Future

More information

ACI Multi-Site Architecture and Deployment. Max Ardica Principal Engineer - INSBU

ACI Multi-Site Architecture and Deployment. Max Ardica Principal Engineer - INSBU ACI Multi-Site Architecture and Deployment Max Ardica Principal Engineer - INSBU Agenda ACI Network and Policy Domain Evolution ACI Multi-Site Deep Dive Overview and Use Cases Introducing ACI Multi-Site

More information

VXLAN Overview: Cisco Nexus 9000 Series Switches

VXLAN Overview: Cisco Nexus 9000 Series Switches White Paper VXLAN Overview: Cisco Nexus 9000 Series Switches What You Will Learn Traditional network segmentation has been provided by VLANs that are standardized under the IEEE 802.1Q group. VLANs provide

More information

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme NET1350BUR Deploying NSX on a Cisco Infrastructure Jacob Rapp jrapp@vmware.com Paul A. Mancuso pmancuso@vmware.com #VMworld #NET1350BUR Disclaimer This presentation may contain product features that are

More information

Unicast Forwarding. Unicast. Unicast Forwarding Flows Overview. Intra Subnet Forwarding (Bridging) Unicast, on page 1

Unicast Forwarding. Unicast. Unicast Forwarding Flows Overview. Intra Subnet Forwarding (Bridging) Unicast, on page 1 Unicast, on page 1 Unicast Flows Overview Intra and inter subnet forwarding are the possible unicast forwarding flows in the VXLAN BGP EVPN fabric, between leaf/tor switch VTEPs. They are explained in

More information

Multi-site Datacenter Network Infrastructures

Multi-site Datacenter Network Infrastructures Multi-site Datacenter Network Infrastructures Petr Grygárek rek 2009 Petr Grygarek, Advanced Computer Networks Technologies 1 Why Multisite Datacenters? Resiliency against large-scale site failures (geodiversity)

More information

H3C S6520XE-HI Switch Series

H3C S6520XE-HI Switch Series H3C S6520XE-HI Switch Series EVPN Configuration Guide New H3C Technologies Co., Ltd. http://www.h3c.com.hk Software version: Release 1108 Document version: 6W100-20171228 Copyright 2017, New H3C Technologies

More information

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV.

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV. 2 CHAPTER Cisco's Disaster Recovery as a Service (DRaaS) architecture supports virtual data centers that consist of a collection of geographically-dispersed data center locations. Since data centers are

More information

Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric)

Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric) White Paper Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric) What You Will Learn This document describes how to achieve a VXLAN EVPN multifabric design by integrating Virtual

More information

Page 2

Page 2 Page 2 Mgmt-B, vmotion-a vmotion-b VMM-Pool-B_ Connection-B -Set-A Uplink-Set-A Uplink-Set-B ACI-DC Standard Aggregation L3 Switch Configuration for existing Layer 2 : Nexus 6K-01 switch is

More information

Cisco Virtual Networking Solution for OpenStack

Cisco Virtual Networking Solution for OpenStack Data Sheet Cisco Virtual Networking Solution for OpenStack Product Overview Extend enterprise-class networking features to OpenStack cloud environments. A reliable virtual network infrastructure that provides

More information

Creating and Managing Admin Domains

Creating and Managing Admin Domains This chapter has the following sections: Admin Domain Overview, page 1 Viewing Admin Domain, page 2 Creating an Admin Domain, page 2 Creating DCI Interconnect Profiles, page 6 Admin Domain Overview The

More information

Design Guide: Deploying NSX for vsphere with Cisco ACI as Underlay

Design Guide: Deploying NSX for vsphere with Cisco ACI as Underlay Design Guide: Deploying NSX for vsphere with Cisco ACI as Underlay Table of Contents Executive Summary... 2 Benefits of NSX Architecture... 4 2.1 NSX Primary Use Cases... 4 2.2 Logical Layer Connectivity...

More information

Internet Engineering Task Force (IETF) Request for Comments: N. Bitar Nokia R. Shekhar. Juniper. J. Uttaro AT&T W. Henderickx Nokia March 2018

Internet Engineering Task Force (IETF) Request for Comments: N. Bitar Nokia R. Shekhar. Juniper. J. Uttaro AT&T W. Henderickx Nokia March 2018 Internet Engineering Task Force (IETF) Request for Comments: 8365 Category: Standards Track ISSN: 2070-1721 A. Sajassi, Ed. Cisco J. Drake, Ed. Juniper N. Bitar Nokia R. Shekhar Juniper J. Uttaro AT&T

More information

Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack

Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack White Paper Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack Introduction Cisco Application Centric Infrastructure (ACI) is a next-generation data center fabric infrastructure

More information

Building NFV Solutions with OpenStack and Cisco ACI

Building NFV Solutions with OpenStack and Cisco ACI Building NFV Solutions with OpenStack and Cisco ACI Domenico Dastoli @domdastoli INSBU Technical Marketing Engineer Iftikhar Rathore - INSBU Technical Marketing Engineer Agenda Brief Introduction to Cisco

More information

Feature Information for BGP Control Plane, page 1 BGP Control Plane Setup, page 1. Feature Information for BGP Control Plane

Feature Information for BGP Control Plane, page 1 BGP Control Plane Setup, page 1. Feature Information for BGP Control Plane Feature Information for, page 1 Setup, page 1 Feature Information for Table 1: Feature Information for Feature Releases Feature Information PoAP diagnostics 7.2(0)N1(1) Included a new section on POAP Diagnostics.

More information

Designing Mul+- Tenant Data Centers using EVPN- IRB. Neeraj Malhotra, Principal Engineer, Cisco Ahmed Abeer, Technical Marke<ng Engineer, Cisco

Designing Mul+- Tenant Data Centers using EVPN- IRB. Neeraj Malhotra, Principal Engineer, Cisco Ahmed Abeer, Technical Marke<ng Engineer, Cisco Designing Mul+- Tenant Data Centers using EVPN- IRB Neeraj Malhotra, Principal Engineer, Cisco Ahmed Abeer, Technical Marke

More information

Traffic Load Balancing in EVPN/VXLAN Networks. Tech Note

Traffic Load Balancing in EVPN/VXLAN Networks. Tech Note Traffic Load Balancing in EVPN/VXLAN Networks Tech Note December 2017 Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net Juniper Networks assumes no

More information

Routing Design. Transit Routing. About Transit Routing

Routing Design. Transit Routing. About Transit Routing Transit Routing, page 1 L3Out Ingress Policy Enforcement, page 16 L3Out MTU Considerations, page 20 Shared L3Outs, page 22 L3Out Router IDs, page 27 Multiple External Connectivity, page 30 Transit Routing

More information

Contents. Introduction. Prerequisites. Requirements. Components Used

Contents. Introduction. Prerequisites. Requirements. Components Used Contents Introduction Prerequisites Requirements Components Used Background Information Terminology What is VXLAN? Why VXLAN? Configure Network Diagram Configurations 3172-A 9396-A 9396-B Verify Example

More information

VXLAN EVPN Fabric and automation using Ansible

VXLAN EVPN Fabric and automation using Ansible VXLAN EVPN Fabric and automation using Ansible Faisal Chaudhry, Principal Architect Umair Arshad, Sr Network Consulting Engineer Lei Tian, Solution Architecture Cisco Spark How Questions? Use Cisco Spark

More information

Pluribus Data Center Interconnect Validated

Pluribus Data Center Interconnect Validated Design Guide Pluribus Data Center Interconnect Validated Design Guide www.pluribusnetworks.com Terminology Reference This is a glossary of acronyms and terms used throughout this document. AS BFD BGP L2VPN

More information

VXLAN EVPN Multihoming with Cisco Nexus 9000 Series Switches

VXLAN EVPN Multihoming with Cisco Nexus 9000 Series Switches White Paper VXLAN EVPN Multihoming with Cisco Nexus 9000 Series Switches 2017 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 27 Contents Introduction...

More information

LTRDCT-2781 Building and operating VXLAN BGP EVPN Fabrics with Data Center Network Manager

LTRDCT-2781 Building and operating VXLAN BGP EVPN Fabrics with Data Center Network Manager LTRDCT-2781 Building and operating VXLAN BGP EVPN Fabrics with Data Center Network Manager Henrique Molina, Technical Marketing Engineer Matthias Wessendorf, Technical Marketing Engineer Cisco Spark How

More information

Service Graph Design with Cisco Application Centric Infrastructure

Service Graph Design with Cisco Application Centric Infrastructure White Paper Service Graph Design with Cisco Application Centric Infrastructure 2017 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 101 Contents Introduction...

More information

Cisco CCIE Data Center Written Exam v2.0. Version Demo

Cisco CCIE Data Center Written Exam v2.0. Version Demo Cisco 400-151 CCIE Data Center Written Exam v2.0 Version Demo QUESTION 1 Which IETF standard is the most efficient messaging protocol used in an lot network? A. SNMP B. HTTP C. CoAP D. MQTI Correct Answer:

More information

Cisco Nexus 7000 Series NX-OS VXLAN Configuration Guide

Cisco Nexus 7000 Series NX-OS VXLAN Configuration Guide First Published: 2015-05-07 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 2016

More information

ACI Fabric Endpoint Learning

ACI Fabric Endpoint Learning White Paper ACI Fabric Endpoint Learning 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 45 Contents Introduction... 3 Goals of this document...

More information

Border Provisioning Use Case in VXLAN BGP EVPN Fabrics - Multi-Site

Border Provisioning Use Case in VXLAN BGP EVPN Fabrics - Multi-Site Border Provisioning Use Case in VXLAN BGP EVPN Fabrics - Multi-Site This chapter explains LAN Fabric border provisioning using EVPN Multi-Site feature. Overview, page 1 Prerequisites, page 1 Limitations,

More information

OPEN CONTRAIL ARCHITECTURE GEORGIA TECH SDN EVENT

OPEN CONTRAIL ARCHITECTURE GEORGIA TECH SDN EVENT OPEN CONTRAIL ARCHITECTURE GEORGIA TECH SDN EVENT sdn-and-nfv-technical---georgia-tech---sep-2013---v2 Bruno Rijsman, Distinguished Engineer 24 September 2013 Use Cases 2 Copyright 2013 Juniper Networks,

More information

Attilla de Groot Attilla de Groot Sr. Systems Engineer, HCIE #3494 Cumulus Networks

Attilla de Groot Attilla de Groot Sr. Systems Engineer, HCIE #3494 Cumulus Networks EVPN to the host Host multitenancy Attilla de Groot Attilla de Groot Sr. Systems Engineer, HCIE #3494 Cumulus Networks 1 Agenda EVPN to the Host Multi tenancy use cases Deployment issues Host integration

More information

Verified Scalability Guide for Cisco APIC, Release 3.0(1k) and Cisco Nexus 9000 Series ACI-Mode Switches, Release 13.0(1k)

Verified Scalability Guide for Cisco APIC, Release 3.0(1k) and Cisco Nexus 9000 Series ACI-Mode Switches, Release 13.0(1k) Verified Scalability Guide for Cisco APIC, Release 3.0(1k) and Cisco Nexus 9000 Series ACI-Mode Switches, Release 13.0(1k) Overview 2 General Scalability Limits 2 Fabric Topology, SPAN, Tenants, Contexts

More information

Integration of Hypervisors and L4-7 Services into an ACI Fabric. Azeem Suleman, Principal Engineer, Insieme Business Unit

Integration of Hypervisors and L4-7 Services into an ACI Fabric. Azeem Suleman, Principal Engineer, Insieme Business Unit Integration of Hypervisors and L4-7 Services into an ACI Fabric Azeem Suleman, Principal Engineer, Insieme Business Unit Agenda Introduction to ACI Review of ACI Policy Model Hypervisor Integration Layer

More information

Verified Scalability Guide for Cisco APIC, Release 3.0(1k) and Cisco Nexus 9000 Series ACI-Mode Switches, Release 13.0(1k)

Verified Scalability Guide for Cisco APIC, Release 3.0(1k) and Cisco Nexus 9000 Series ACI-Mode Switches, Release 13.0(1k) Verified Scalability Guide for Cisco APIC, Release 3.0(1k) and Cisco Nexus 9000 Series ACI-Mode Switches, Release 13.0(1k) Overview 2 General Scalability Limits 2 Fabric Topology, SPAN, Tenants, Contexts

More information

Architecting Scalable Clouds using VXLAN and Nexus 1000V

Architecting Scalable Clouds using VXLAN and Nexus 1000V Architecting Scalable Clouds using VXLAN and Nexus 1000V Lawrence Kreeger Principal Engineer Agenda Session Is Broken Into 3 Main Parts Part 1: VXLAN Overview What is a VXLAN? Why VXLANs? What is VMware

More information

Nexus 1000V in Context of SDN. Martin Divis, CSE,

Nexus 1000V in Context of SDN. Martin Divis, CSE, Nexus 1000V in Context of SDN Martin Divis, CSE, mdivis@cisco.com Why Cisco Nexus 1000V Losing the Edge Server Admin Host Host Host Host Server Admin manages virtual switching! vswitch vswitch vswitch

More information

Deploy Application Load Balancers with Source Network Address Translation in Cisco DFA

Deploy Application Load Balancers with Source Network Address Translation in Cisco DFA White Paper Deploy Application Load Balancers with Source Network Address Translation in Cisco DFA Last Updated: 1/27/2016 2016 Cisco and/or its affiliates. All rights reserved. This document is Cisco

More information

DCI. DataCenter Interconnection / Infrastructure. Arnaud Fenioux

DCI. DataCenter Interconnection / Infrastructure. Arnaud Fenioux DCI DataCenter Interconnection / Infrastructure Arnaud Fenioux What is DCI? DataCenter Interconnection Or DataCenter Infrastructure? 2 From interconnection to infrastructure Interconnection Dark fiber

More information

Cisco HyperFlex Systems

Cisco HyperFlex Systems White Paper Cisco HyperFlex Systems Install and Manage Cisco HyperFlex Systems in a Cisco ACI Environment Original Update: January 2017 Updated: March 2018 Note: This document contains material and data

More information

Cisco ACI Multi-Pod and Service Node Integration

Cisco ACI Multi-Pod and Service Node Integration White Paper Cisco ACI Multi-Pod and Service Node Integration 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 68 Contents Introduction... 3 Prerequisites...

More information

Segment Routing on Cisco Nexus 9500, 9300, 9200, 3200, and 3100 Platform Switches

Segment Routing on Cisco Nexus 9500, 9300, 9200, 3200, and 3100 Platform Switches White Paper Segment Routing on Cisco Nexus 9500, 9300, 9200, 3200, and 3100 Platform Switches Authors Ambrish Mehta, Cisco Systems Inc. Haider Salman, Cisco Systems Inc. 2017 Cisco and/or its affiliates.

More information

VXLAN Multipod Design for Intra-Data Center and Geographically Dispersed Data Center Sites

VXLAN Multipod Design for Intra-Data Center and Geographically Dispersed Data Center Sites White Paper VXLAN Multipod Design for Intra-Data Center and Geographically Dispersed Data Center Sites May 17, 2016 Authors Max Ardica, Principal Engineer INSBU Patrice Bellagamba, Distinguish System Engineer

More information

Migration from Classic DC Network to Application Centric Infrastructure

Migration from Classic DC Network to Application Centric Infrastructure Migration from Classic DC Network to Application Centric Infrastructure Kannan Ponnuswamy, Solution Architect, Cisco Advanced Services Acronyms IOS vpc VDC AAA VRF STP ISE FTP ToR UCS FEX OTV QoS BGP PIM

More information

Real World ACI Deployment and Migration Kannan Ponnuswamy, Solutions Architect BRKACI-2601

Real World ACI Deployment and Migration Kannan Ponnuswamy, Solutions Architect BRKACI-2601 Real World ACI Deployment and Migration Kannan Ponnuswamy, Solutions Architect BRKACI-2601 Icons and Terms APIC Application Policy Infrastructure Controller (APIC) Cisco Nexus 9500 Cisco Nexus 9300 Nexus

More information

Cisco Dynamic Fabric Automation Architecture. Miroslav Brzek, Systems Engineer

Cisco Dynamic Fabric Automation Architecture. Miroslav Brzek, Systems Engineer Cisco Dynamic Fabric Automation Architecture Miroslav Brzek, Systems Engineer mibrzek@cisco.com Agenda DFA Overview Optimized Networking Fabric Properties Control Plane Forwarding Plane Virtual Fabrics

More information

Cisco ACI Virtual Machine Networking

Cisco ACI Virtual Machine Networking This chapter contains the following sections: Cisco ACI VM Networking Supports Multiple Vendors' Virtual Machine Managers, page 1 Virtual Machine Manager Domain Main Components, page 2 Virtual Machine

More information

Implementing DCI VXLAN Layer 3 Gateway

Implementing DCI VXLAN Layer 3 Gateway This chapter module provides conceptual and configuration information for Data Center Interconnect (DCI) VXLAN Layer 3 Gateway on Cisco ASR 9000 Series Router. Release Modification Release 5.3.2 This feature

More information

Intended status: Standards Track. Cisco Systems October 22, 2018

Intended status: Standards Track. Cisco Systems October 22, 2018 BESS WorkGroup Internet-Draft Intended status: Standards Track Expires: April 25, 2019 Ali. Sajassi Mankamana. Mishra Samir. Thoria Patrice. Brissette Cisco Systems October 22, 2018 AC-Aware Bundling Service

More information

Cisco ACI Multi-Pod Design and Deployment

Cisco ACI Multi-Pod Design and Deployment Cisco ACI Multi-Pod Design and Deployment John Weston Technical Marketing Engineer Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the

More information

Cisco Dynamic Fabric Automation Architecture

Cisco Dynamic Fabric Automation Architecture Cisco Dynamic Fabric Automation Architecture Lukas Krattiger Technical Marketing Engineer Agenda DFA Requirements and Functions Fabric Management Workload Automation Optimised Network Fabric Properties

More information

H3C S7500E-X Switch Series

H3C S7500E-X Switch Series H3C S7500E-X Switch Series EVPN Configuration Guide Hangzhou H3C Technologies Co., Ltd. http://www.h3c.com Software version: S7500EX-CMW710-R7523P01 Document version: 6W100-20160830 Copyright 2016, Hangzhou

More information

ACI Terminology. This chapter contains the following sections: ACI Terminology, on page 1. Cisco ACI Term. (Approximation)

ACI Terminology. This chapter contains the following sections: ACI Terminology, on page 1. Cisco ACI Term. (Approximation) This chapter contains the following sections:, on page 1 Alias API Inspector App Center Alias A changeable name for a given object. While the name of an object, once created, cannot be changed, the Alias

More information

Virtualization Design

Virtualization Design VMM Integration with UCS-B, on page 1 VMM Integration with AVS or VDS, on page 3 VMM Domain Resolution Immediacy, on page 6 OpenStack and Cisco ACI, on page 8 VMM Integration with UCS-B About VMM Integration

More information

Higher scalability to address more Layer 2 segments: up to 16 million VXLAN segments.

Higher scalability to address more Layer 2 segments: up to 16 million VXLAN segments. This chapter tells how to configure Virtual extensible LAN (VXLAN) interfaces. VXLANs act as Layer 2 virtual networks over Layer 3 physical networks to stretch Layer 2 networks. About VXLAN Encapsulation

More information

EVPN for VXLAN Tunnels (Layer 3)

EVPN for VXLAN Tunnels (Layer 3) EVPN for VXLAN Tunnels (Layer 3) In This Chapter This section provides information about EVPN for VXLAN tunnels (Layer 3). Topics in this section include: Applicability on page 312 Overview on page 313

More information

MPLS VPN--Inter-AS Option AB

MPLS VPN--Inter-AS Option AB The feature combines the best functionality of an Inter-AS Option (10) A and Inter-AS Option (10) B network to allow a Multiprotocol Label Switching (MPLS) Virtual Private Network (VPN) service provider

More information

VXLAN EVPN Multi-Site Design and Deployment

VXLAN EVPN Multi-Site Design and Deployment White Paper VXLAN EVPN Multi-Site Design and Deployment 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 55 Contents What you will learn... 4

More information

Weiterentwicklung von OpenStack Netzen 25G/50G/100G, FW-Integration, umfassende Einbindung. Alexei Agueev, Systems Engineer

Weiterentwicklung von OpenStack Netzen 25G/50G/100G, FW-Integration, umfassende Einbindung. Alexei Agueev, Systems Engineer Weiterentwicklung von OpenStack Netzen 25G/50G/100G, FW-Integration, umfassende Einbindung Alexei Agueev, Systems Engineer ETHERNET MIGRATION 10G/40G à 25G/50G/100G Interface Parallelism Parallelism increases

More information

Multi-Site Use Cases. Cisco ACI Multi-Site Service Integration. Supported Use Cases. East-West Intra-VRF/Non-Shared Service

Multi-Site Use Cases. Cisco ACI Multi-Site Service Integration. Supported Use Cases. East-West Intra-VRF/Non-Shared Service Cisco ACI Multi-Site Service Integration, on page 1 Cisco ACI Multi-Site Back-to-Back Spine Connectivity Across Sites Without IPN, on page 8 Bridge Domain with Layer 2 Broadcast Extension, on page 9 Bridge

More information

Application Centric Infrastructure

Application Centric Infrastructure Application Centric Infrastructure Design pro řešení na zelené louce i do stávajícího DC DCA4 Miroslav Brzek, Systems Engineer Agenda Modern DC infrastructure Customer requirements What s Application Centric

More information

Open Compute Network Operating System Version 1.1

Open Compute Network Operating System Version 1.1 Solution Guide Open Compute Network Operating System Version 1.1 Data Center Solution - EVPN with VXLAN 2016 IP Infusion Inc. All Rights Reserved. This documentation is subject to change without notice.

More information

Layer 4 to Layer 7 Design

Layer 4 to Layer 7 Design Service Graphs and Layer 4 to Layer 7 Services Integration, page 1 Firewall Service Graphs, page 5 Service Node Failover, page 10 Service Graphs with Multiple Consumers and Providers, page 12 Reusing a

More information

21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal. By Adeyemi Ademola E. Cloud Engineer

21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal. By Adeyemi Ademola E. Cloud Engineer 21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal By Adeyemi Ademola E. Cloud Engineer 1 Contents Introduction... 5 1.2 Document Purpose and Scope...5 Service Definition...

More information

Cisco IT Compute at Scale on Cisco ACI

Cisco IT Compute at Scale on Cisco ACI Cisco IT ACI Deployment White Papers Cisco IT Compute at Scale on Cisco ACI This is the fourth white paper in a series of case studies that explain how Cisco IT deployed ACI to deliver improved business

More information

InterAS Option B. Information About InterAS. InterAS and ASBR

InterAS Option B. Information About InterAS. InterAS and ASBR This chapter explains the different InterAS option B configuration options. The available options are InterAS option B, InterAS option B (with RFC 3107), and InterAS option B lite. The InterAS option B

More information

Building Blocks in EVPN VXLAN for Multi-Service Fabrics. Aldrin Isaac Co-author RFC7432 Juniper Networks

Building Blocks in EVPN VXLAN for Multi-Service Fabrics. Aldrin Isaac Co-author RFC7432 Juniper Networks Building Blocks in EVPN VXLAN for Multi-Service Fabrics Aldrin Isaac Co-author RFC7432 Juniper Networks Network Subsystems Network Virtualization Bandwidth Broker TE LAN Fabric WAN Fabric LAN WAN EVPN

More information

Technical Brief. Achieving a Scale-Out IP Fabric with the Adaptive Cloud Fabric Architecture.

Technical Brief. Achieving a Scale-Out IP Fabric with the Adaptive Cloud Fabric Architecture. Technical Brief Achieving a Scale-Out IP Fabric with the Adaptive Cloud Fabric Architecture www.pluribusnetworks.com Terminology Reference This is a glossary of acronyms and terms used throughout this

More information