VMWARE SOLUTIONS AND THE DATACENTER Fredric Linder
MORE THAN VSPHERE vsphere vcenter Core vcenter Operations Suite vcenter Operations Management Vmware Cloud vcloud Director Chargeback VMware IT Business Management Suite Offering Vmware View VDI / Applications DR / Replication Site Recovery Manager Storage Appliance 2 Copyright 2012 Juniper Networks, Inc. www.juniper.net
INFRASTRUCTURE AS A SERVICE (IAAS) Most commonly adaptable strategy in the Enterprise Building resource pools for consumption CPU Memory Server Virtualization Storage SAN Network QoS, VLAN, Bandwith Requirements: Vmware vsphere vcloud Suite Dedicate resources based on service demands Monitor resource out take to guarantee resources 3 Copyright 2012 Juniper Networks, Inc. www.juniper.net
PLATFORM AS A SERVICE (PAAS) Delivering the foundation to building new SaaS applications. New application platform to build NextGen Applications Distributed application model Metering and subscription based model IaaS aware Requirements: Vmware vsphere vfabric Suite Dedicate resources based on service demands Monitor resource out take to guarantee resources Metering and subscription infrastructure 4 Copyright 2012 Juniper Networks, Inc. www.juniper.net
SOFTWARE AS A SERVICE (SAAS) Delivering SaaS applications. SLA driven Model End user experience Pay per use Vmware vsphere Operations Suite IT Buiness Management Suite Requirements: Dynamic resource allocation based on service demands Continues End-to-End SLA metering Automatic End-to-End adaptation of resources to meet SLA 5 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VMWARE VSPHERE AND VCENTER SERVER Clusters Datastores Portgroups and Resource Pools Provide cloud compute DRS is a requirement for the cluster Shared storage vmotion compatible or EVC enabled Provide cloud storage Abstract away underlying storage type Provide cloud networking Abstract away underlying networking infrastructure vswitch, vnetwork Distributed Switch or Nexus 1000V, IBM 5000v Resource Pools vcenter Server vnetwork Distributed Switch ESXi/ESX hosts iscsi Storage FC Storage NFS Storage 6 Copyright 2012 Juniper Networks, Inc. www.juniper.net
NETWORKING OPTIONS IN VMWARE vswitch Types - vswitch - One or more per host Basic functionality vnetwork Distributed Switch One or more per cluster LACP, BPDU filters, Port Mirroring, SR-IOV Requirement for 3 rd party switches VXLAN support (With vshield and Security Package) 7 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VXLAN - PRINCIPLES Identifier : 24bit segment VNI (up to 16M VXLAN) Only VMs in the same VXLAN (VNI) can communicate together Tunneling L2 over L3 (MAC-over-UDP, UDP port not defined at this time) VM are not aware of VXLAN, only VTEP. Today VXLAN Tunnel End Point (VTEP) would be setup on vswitch, but could be on physical switches, routers or servers (VXLAN gateways) 8 Copyright 2012 Juniper Networks, Inc. www.juniper.net
DRS CLUSTER DESIGN (8-12 HOSTS PER CLUSTER) V M V M 9 Copyright 2012 Juniper Networks, Inc. www.juniper.net
ACTIVE PASSIVE DESIGN V M V M V M V M Storage Replication NFS, iscsi, FCoE 10 Copyright 2012 Juniper Networks, Inc. www.juniper.net NFS, iscsi, FCoE
STETCHED CLUSTER DESIGN V M Affinity Groups V M Affinity Groups V M Storage Replication NFS, iscsi, FCoE 11 Copyright 2012 Juniper Networks, Inc. www.juniper.net NFS, iscsi, FCoE
VMWARE VCLOUD COMPONENTS VMware vsphere and vcenter Servers VMware vcloud Director vshield for VMware Cloud Director 12 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VMWARE VCLOUD DIRECTOR Define Define Create Provide Provide standard infrastructure tiers called Virtual Datacenters Pool virtualized infrastructure resources across multiple vcenter Servers standard collections of VMs called vapps Organizations and manage users UI for users to self provision vapps into Virtual Datacenters secure multi-tenancy using vshield Edge 13 Copyright 2012 Juniper Networks, Inc. www.juniper.net
(Gold) (Silver) (Bronze) VMWARE VCLOUD STACK VMware vcloud Director Organization: Marketing Organization: Finance Users & Policies Organization VDCs Catalogs Users & Policies Organization VDCs Catalogs Provider Virtual Datacenters VMware vcenter Server Resource Pools Datastores Port Groups VMware vsphere Secure Private Cloud 14 Copyright 2012 Juniper Networks, Inc. www.juniper.net
App VM App VM App VM Application Network FW vshield Organisation Network FW vshield External Network 15 Copyright 2012 Juniper Networks, Inc. www.juniper.net
EXTERNAL NETWORK: OVERVIEW Created at the vsphere level as a port group on a vss or vds Port group is mapped to a vcloud Director external network Mapping is on a one to one basis Use cases Internet access Provider supplied network endpoints IP based storage Backup servers Access to physical managed services Backhauled networking to a customer datacenter VPN access to a private cloud MPLS termination 16 Copyright 2012 Juniper Networks, Inc. www.juniper.net
EXTERNAL NETWORKS: IN VSPHERE Dedicate vds for statically mapped networks i.e. Provider vds Avoid vss unless using scripting to duplicate port groups to hosts Use unique VLANs per port group to avoid broadcast overlap Below is an example of VLAN isolated External Networks: 17 Copyright 2012 Juniper Networks, Inc. www.juniper.net
EXTERNAL NETWORKS: IN VMWARE VCLOUD DIRECTOR In VMware vcloud Director, create an external network by mapping it to a portgroup 18 Copyright 2012 Juniper Networks, Inc. www.juniper.net
ORGANIZATION NETWORKS: OVERVIEW Contained within an organization Allows vapps within the organization to communicate with each other or external endpoints Can be connected to external networks as: Public (External Org Direct) Bridged connection to an external network Others outside the organization can see Private Routed (External Org NAT-Routed) Connected to an External Network through a vshield Edge Can be configured for NAT & Firewall or left unconnected to external Private Internal (Internal Org) No External connectivity Backed by Network Pools 19 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VAPP NETWORKS: OVERVIEW Contained within a vapp Inherently Private Internal Allows VMs in a vapp to communicate with each other or by connecting them to Org networks, other vapps Can be connected to Org Networks as Public (Direct) Bridged connection to a organization network Private Routed Connected to a organization network through a vshield Edge Can be configured for NAT & Firewall Backed by a Network Pool 20 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VMware vshield Provides network edge security Provides firewall, NAT, port forwarding, IP masquerading and DHCP functionality (enforces multi-tenancy) Edge appliances deployed and managed by VMware vcloud Director on vsphere. App VM App VM Application Network FW Organisation Network App VM vshield NOTE: Does not include site-to-site VPN and load balancer FW vshield External Network 21 Copyright 2012 Juniper Networks, Inc. www.juniper.net
TYPES OF NETWORK POOLS Portgroup-backed Create isolated portgroups in vsphere manually or with automation Attach a collection of them to VMware vcloud Director VLAN-backed VMware vcloud Director will automatically create portgroups as needed, and use a range of VLANs to isolate them VMware vcloud Director Network Isolation-backed Proprietary network isolation technology Network Pool VLAN Backed Building Blocks vnetwork Distributed Switch + VLAN tags VCDNI vnetwork Distributed Switch + one VLAN for transport Portgroup backed vnetwork Distributed Switch or vswitch portgroups 22 Copyright 2012 Juniper Networks, Inc. www.juniper.net
App VM App VM App VM AppNet (vcd-ni) FW vshield OrgNet (vcd-ni) FW vshield ExternalNet (VLAN) 23 Copyright 2012 Juniper Networks, Inc. www.juniper.net
TRAFFIC FLOW EXAMPLE 24 Copyright 2012 Juniper Networks, Inc. www.juniper.net
TRAFFIC FLOW EXAMPLE 25 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VCLOUD API RESTful Designed for web infrastructure Extensible, Modular Released Spans 100% VIM With in Open form Version 0.9 currently public vcenter Instances Operate across multiple vcenter Servers Virtual API Unchanged OVF standard, unlocks ability to move vapps across clouds (Hybrid cloud use case) 26 Copyright 2012 Juniper Networks, Inc. www.juniper.net
2 LOGICAL APIS FOR VMWARE VCLOUD DIRECTOR 2: vcloud API Standard way to consume vcloud Resources 1: VMware vcloud Director Admin API Automate VCD Management Attach virtual/physical resources Manage organizations, users, etc. RESTful for loose coupling to existing systems 27 Copyright 2012 Juniper Networks, Inc. www.juniper.net
ORCHESTRATION + VMWARE CLOUD DIRECTOR Orchestration Engine User Portal + vcloud API 1. User Workflow Initiation End Users 2. User Resource Interaction Financial Systems vcloud API VMware vcloud IaaS VCD Redwood Portal Portal vcenter Chargeback Approval Systems Asset Systems vsphere API Hosts CMDB. Physical Config VMware vsphere 28 Copyright 2012 Juniper Networks, Inc. www.juniper.net Datastores
JUNIPER SOLUTIONS 29 Copyright 2012 Juniper Networks, Inc. www.juniper.net
JUNIPER SOLUTIONS App VM App VM App VM AppNet (vcd-ni) FW vshield OrgNet (vcd-ni) FW vshield ExternalNet (VLAN) 30 Copyright 2012 Juniper Networks, Inc. www.juniper.net
JUNIPER SOLUTIONS App VM vgw App VM App VM AppNet (vcd-ni) FW vshield OrgNet (vcd-ni) FW vshield ExternalNet (VLAN) 31 Copyright 2012 Juniper Networks, Inc. www.juniper.net FW SRX
JUNIPER SOLUTIONS App VM vgw App VM App VM AppNet (vcd-ni) FW vshield OrgNet (vcd-ni) FW vshield ExternalNet (VLAN) 32 Copyright 2012 Juniper Networks, Inc. www.juniper.net FW vsrx
App VM vgw App VM App VM AppNet (vcd-ni) FW vsrx OrgNet (vcd-ni) FW vsrx ExternalNet (VLAN) 33 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VGW NETWORK VISIBILITY Benefits: Visibility to all VM communications Ability to spot design issues with security policies Single click to more detail on VMs Export flows for analysis See traffic flows Troubleshoot Navigate 34 Copyright 2012 Juniper Networks, Inc. www.juniper.net
35 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VGW INTROSPECTION X-ray VMs and automate compliance enforcement Benefits: Know exactly what s installed in a VM Automatically attach relevant security policy! Define & enforce a gold image (template or VM) 36 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VGW SMART GROUPS Smart Groups allow for the use of attributes to create dynamic system associations. Benefits: Tie vgw product discoveries to Smart Group definitions. Tie vcenter and VM config attributes to Smart Group definitions Attributes are read real time so if a VM changes in vcenter, it s instantly updated in vgw Smart Groups help capability allows administrator to see name, description and values of attributes Priority and precedence level can be defined to Tier Groups easily 37 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VGW AND HOW VGW CAN HELP ORHESTRATE SECURITY VM1 VM2 VM3 ALTOR vgw Orchistration API s vgw VMware vsphere Zone Synchronization Traffic Mirroring to IPS Central Policy Management Firewall Event Syslogs Netflow for Inter-VM Traffic STRM Network Juniper EX Switch Juniper SRX with IDP 38 Copyright 2012 Juniper Networks, Inc. www.juniper.net
DC MANAGEABILITY CHALLENGES WITH SERVER VIRTUALIZATION Physical n/w B Network Admin 1. Blurred roles between the server and network admin. Virtual n/w A P P A 2. No automation/ orchestration to sync-up the 2 networks. VM1 VM2 VM3 VM1 VM2 Server Admin 3. VM Migration can fail. 4. Proprietary products & protocols 39 Copyright 2012 Juniper Networks, Inc. www.juniper.net
SOLUTIONS WITH JUNOS SPACE VIRTUAL CONTROL A Physical n/w Virtual n/w A P A P A A Virtual Control A Network Admin 1. Clear roles and responsibilities 2. Automated orchestration between physical and virtual networks VM1 VM2 VM3 VM1 VM2 Server Admin 3. Scalable solution allows VMs to move freely 4. Open Architecture 40 Copyright 2012 Juniper Networks, Inc. www.juniper.net
NETWORK RELATED ACCESS Server Admin should not have the following access Move network This can be a security concern Configure network Remove network Server Admin should have Assign network To assign a network to a VM 41 Copyright 2012 Juniper Networks, Inc. www.juniper.net
WILL QFABRIC HELP ME ORCHESTRATE One device One hop Non Blocking QFabric Director As Qfabric Director acts a the brain for the fabric you only have to request relevant information to this device in order to guarantee required characteristics from the application Orchestration Engine Less devices to orchestrate Less complex Simpler to deploy applications based on SLA Application 42 Copyright 2012 Juniper Networks, Inc. www.juniper.net
XML API, Junos Scripting Junos Space Openflow Windows Linux PHP Java Rails Node.js Service JUNIPER S OPEN CLOUD ORCHESTRATION MODEL Juniper provides an open interface model for cloud orchestration Cloud Governance and Lifecycle Management Network Abstraction, Orchestration and Automation Network Compute Storage Routing Hyper-V KVM Switching Security Virtual Machines Containers x86 - Platform from Intel 43 Copyright 2012 Juniper Networks, Inc. www.juniper.net
QUESTIONS?