Enabling Long Distance Live Migration with F5 and VMware vmotion

Similar documents
Optimizing NetApp SnapMirror Data Replication with F5 BIG-IP WAN Optimization Manager

VMware vcenter Site Recovery Manager

Global Distributed Service in the Cloud with F5 and VMware

Unified Application Delivery

Distributing Applications for Disaster Planning and Availability

Archived. Configuring a single-tenant BIG-IP Virtual Edition in the Cloud. Deployment Guide Document Version: 1.0. What is F5 iapp?

Enhancing VMware Horizon View with F5 Solutions

Validating Microsoft Exchange 2010 on Cisco and NetApp FlexPod with the F5 BIG-IP System

Deploying WAN-Optimized Acceleration for VMware vmotion Between Two BIG-IP Systems

Improving VDI with Scalable Infrastructure

Prompta volumus denique eam ei, mel autem

Securing the Cloud. White Paper by Peter Silva

F5 and Nuage Networks Partnership Overview for Enterprises

Optimize and Accelerate Your Mission- Critical Applications across the WAN

Deploying the BIG-IP LTM with IBM QRadar Logging

DESIGN GUIDE. VMware NSX for vsphere (NSX-v) and F5 BIG-IP Design Guide

Managing the Migration to IPv6 Throughout the Service Provider Network White Paper

Data Center Virtualization Q&A

Geolocation and Application Delivery

Deploying the BIG-IP System with CA SiteMinder

Resource Provisioning Hardware Virtualization, Your Way

Deploying the BIG-IP System with Oracle Hyperion Applications

Archived. Deploying the BIG-IP LTM with IBM Cognos Insight. Deployment Guide Document version 1.0. What s inside: 2 Products and versions tested

The Programmable Network

Deploying the BIG-IP System v11 with DNS Servers

F5 iapps: Moving Application Delivery Beyond the Network

Managing BIG-IP Devices with HP and Microsoft Network Management Solutions

Complying with PCI DSS 3.0

Multi-Tenancy Designs for the F5 High-Performance Services Fabric

The F5 Intelligent DNS Scale Reference Architecture

F5 Reference Architecture for Cisco ACI

F5 VMware Virtual Community Roundtable. VMware Alliance F5

WHITE PAPER. F5 and Cisco. Supercharging IT Operations with Full-Stack SDN

F5 icontrol. In this white paper, get an introduction to F5 icontrol service-enabled management API. F5 White Paper

Deploying a Next-Generation IPS Infrastructure

Archived. h h Health monitoring of the Guardium S-TAP Collectors to ensure traffic is sent to a Collector that is actually up and available,

Server Virtualization Incentive Program

The F5 Application Services Reference Architecture

F5 in AWS Part 3 Advanced Topologies and More on Highly Available Services

Meeting the Challenges of an HA Architecture for IBM WebSphere SIP

Large FSI DDoS Protection Reference Architecture

Deploying a Next-Generation IPS Infrastructure

Session Initiated Protocol (SIP): A Five-Function Protocol

Cisco HyperFlex and the F5 BIG-IP Platform Accelerate Infrastructure and Application Deployments

21CTL Disaster Recovery, Workload Mobility and Infrastructure as a Service Proposal. By Adeyemi Ademola E. Cloud Engineer

Cisco CloudCenter Solution with Cisco ACI: Common Use Cases

Simplifying Security for Mobile Networks

Document version: 1.0 What's inside: Products and versions tested Important:

Secure Mobile Access to Corporate Applications

Cookies, Sessions, and Persistence

Myths of Bandwidth Optimization

Network Functions Virtualization - Everything Old Is New Again

Ordering and deleting Single-node Trial for VMware vcenter Server on IBM Cloud instances

VMware vsphere 4. The Best Platform for Building Cloud Infrastructures

Providing Security and Acceleration for Remote Users

Converting a Cisco ACE configuration file to F5 BIG IP Format

Archived. For more information of IBM Maximo Asset Management system see:

EBOOK: VMware Cloud on AWS: Optimized for the Next-Generation Hybrid Cloud

Load Balancing 101: Nuts and Bolts

Automating the Data Center

Load Balancing 101: Nuts and Bolts

Enhancing Oracle VM Business Continuity Using Dell Compellent Live Volume

Cloud Confidence: Simple Seamless Secure. Dell EMC Data Protection for VMware Cloud on AWS

Deploy F5 Application Delivery and Security Services in Private, Public, and Hybrid IT Cloud Environments

Protecting Against Application DDoS A acks with BIG-IP ASM: A Three- Step Solution

Considerations for VoLTE Implementation

TECHNICAL WHITE PAPER - MAY 2017 MULTI DATA CENTER POOLING WITH NSX WHITE PAPER

Cisco Virtualized Workload Mobility Introduction

Cisco Cloud Application Centric Infrastructure

Customer Onboarding with VMware NSX L2VPN Service for VMware Cloud Providers

QuickStart Guide vcenter Server Heartbeat 5.5 Update 1 EN

Executive Summary. The Need for Shared Storage. The Shared Storage Dilemma for the SMB. The SMB Answer - DroboElite. Enhancing your VMware Environment

PLEXXI HCN FOR VMWARE VSAN

The Cisco HyperFlex Dynamic Data Fabric Advantage

Citrix Federated Authentication Service Integration with APM

SNMP: Simplified. White Paper by F5

Private Cloud Public Cloud Edge. Consistent Infrastructure & Consistent Operations

Creating a Hybrid ADN Architecture with both Virtual and Physical ADCs

BIG-IP Global Traffic Manager

Transforming your IT infrastructure Journey to the Cloud Mike Sladin

SOLUTION BRIEF Enterprise WAN Agility, Simplicity and Performance with Software-Defined WAN

v.10 - Working the GTM Command Line Interface

VMware Hybrid Cloud Solution

Protect Against Evolving DDoS Threats: The Case for Hybrid

Prompta volumus denique eam ei, mel autem

Deploying the BIG-IP LTM with Oracle JD Edwards EnterpriseOne

Workload Mobility and Disaster Recovery to VMware Cloud IaaS Providers

Easy VMware Disaster Recovery & Business Continuity in Amazon Web Services

VMworld 2018 Content: Not for publication or distribution

Archived. Deploying the BIG-IP LTM with IBM Lotus inotes BIG-IP LTM , 10.1, 11.2, IBM Lotus inotes 8.5 (applies to 8.5.

Maintain Your F5 Solution with Fast, Reliable Support

BIG IQ Reporting for Subscription and ELA Programs

Addressing Security Loopholes of Third Party Browser Plug ins UPDATED FEBRUARY 2017

Cisco Spark Hybrid Media Service

VERITAS Volume Replicator. Successful Replication and Disaster Recovery

Webshells. Webshell Examples. How does a webshell attack work? Nir Zigler,

OPTIMIZE. MONETIZE. SECURE. Agile, scalable network solutions for service providers.

APM Cookbook: Single Sign On (SSO) using Kerberos

7 Things ISVs Must Know About Virtualization

Enterprise Architectures The Pace Accelerates Camberley Bates Managing Partner & Analyst

Transcription:

Enabling Long Distance Live Migration with F5 and VMware vmotion F5 Networks and VMware partner to enable live application and storage migrations between data centers and clouds, over short or long distances. White Paper by Alan Murphy

Introduction Cloud computing has become an important technology to consider for organizations that are looking to optimize their IT operations and reduce operating costs. Until now, leveraging the cloud involved either setting up and running applications in the cloud and managing them long-term off-premises, or running services as a one-time event. Migrating existing services, applications, and virtual machines to the cloud presented immense networking complexities, and if performed outside a local data center, was a non-trivial challenge. Moving live services without user interruption was virtually impossible. F5 and VMware have developed a joint solution to this overcome these limitations and enable enterprise customers to migrate application services between clouds without affecting users. Live virtual machine (VM) migration-moving a VM from one physical server to another while the machine is running and processing transactions-has been one of the core technologies propelling virtualization's mass adoption in the data center. Live migration enables a more dynamic and agile environment as virtual systems flow between hardware devices based on planned migrations-such as migrating a running virtual machine to a new or secondary data center-or unplanned movement due to usage, consumption, availability, and so on. VMware has been both a technological innovator and market leader in live system migration. Until recently, however, even this advanced technology was generally relegated to use within a local data center, staying confined to one physical network. The F5 and VMware cloud migration solution moves vmotion from the binds of the local data center and enables live migration of both VMs and the back-end storage across the WAN between data centers and clouds. F5 has created a workflow that allows the administrator to automate the majority of the migration, making it possible to execute these migrations with a minimum of manual configuration. VMware vmotion Basics 1

VMware vmotion Basics VMware's vmotion is a unique technology that moves running virtual machines from one physical server to another without interrupting the VM or the applications running on that VM. During a vmotion event, active memory and CPU running state (which combined include the current state of the network and any applications running on the VM) are transferred between physical systems as needed based on resource constraint, disaster avoidance planning, or functional changes (such as bringing down a physical server). The storage back-end associated with that virtual machine-the VMDK and configuration files located on the storage network-can also be migrated between storage networks with VMware Storage vmotion. Design Factors: vmotion Between Networks One of the primary design considerations for vmotion is network topology. During a vmotion migration, a snapshot of the running systems is transferred from one server to another. Since the running state of a system is a "moment in time" snapshot, there is no way to change anything in the running state, including the IP address of the virtual machine or any other network settings. For the VM to resume operations and keep running on the new server, the destination network must be exactly the same as the original network housing the VM, as must the network configuration of the VM itself. The virtual machine and physical server network configurations include the IP address of the VM, the IP network settings such as subnet mask and gateway address, and VLAN configurations on the VMware ESX server. The VM must stay within the same broadcast domain in order for the virtual network to resume without application data loss. 62% of IT organizations reported that the ability to move virtual machines between data centers (e.g. long distance vmotion) is valuable when choosing a cloud provider. Source: TechValidate TVID: A6D-C70-242 Design Factors: vmotion Over Distance 2

Design Factors: vmotion Over Distance Beyond local network topology issues, one of the common questions when deploying VMware as part of a cloud or high availability/disaster avoidance scenario is "Can I move virtual machines between data centers?" Some of the challenges with long distance live migration are the WAN bandwidth, latency, and packet loss limitations that are outside the control of most IT organizations. Many applications, including vmotion live migration, are susceptible to network issues across the WAN that can be exacerbated by distance and network quality. Although not as timesensitive as VM live migration, Storage vmotion can also suffer from latency issues over the WAN. If the conditions are bad enough, attempted vmotion events will simply fail. Other challenges with external data center vmotion events include managing user connections and application data during the migration, and IP management and reclamation. In a LAN migration, user connections are moved from one physical switch port to another. The VM and active user connections never leave their configured network nor is there a need to manage or change the VM IP address because that IP address stays within the local network. With a long distance or cloud vmotion move, however, the VM must traverse multiple networks without losing any user or application state information. The user connections are routed to a geographically removed location and IP addresses need to be managed between the two data centers. Each of these long distance challenges-wan constraints and user connection management-become more of an issue with "sticky apps": applications that have a very intensive user experience, such as web 2.0 applications. Connecting Clouds with BIG-IP Solutions F5 has been an Application Delivery Networking pioneer in managing traffic across distributed data centers and the cloud, as well as in optimizing application traffic in and out of the data center. By working with VMware to address the difficulties inherent in migrating an application to the cloud automatically and seamlessly, F5 has created a solution that optimizes, secures, and manages VM migration and user connections between data centers, effectively "connecting clouds." Beyond network optimizations and security, transitioning user connections from one cloud to another is the key element in moving VMs between data centers. User experience is paramount, and it's critical that the application does not suffer any significant downtime or loss of application data during or after a cross-site live migration. Building a Successful Data Center-to-Cloud Network 3

Building a Successful Data Center-to-Cloud Network When designing a solution for vmotion over distance, F5's goal was to create a system that enables secure live migrations between multiple cloud-based data centers without any interruption in the application service or user downtime. F5 has accomplished this goal using a suite of existing F5 products and technologies that already plug into vcenter for VM application networking management: BIG-IP Local Traffic Manager (LTM), BIG-IP Global Traffic Manager (GTM), BIG-IP integrated WAN optimization services, isessions tunneling between data centers, and icontrol, the open API used to manage the migration through vcenter. Cloud-based live VM migration with F5 and vmotion Step-by-Step Solution Walkthrough 1. isessions Tunnel The first step in building an infrastructure to support secure live migration between clouds and data centers is to symmetrically connect each data center using a feature of F5 BIG-IP LTM: isessions tunnels. Using SSL and advanced data compression techiques, BIG-IP LTM creates secure and optimized tunnels between each data center to carry the vmotion traffic. This enables applications within each data center to communicate efficiently over the private connection and creates the infrastructure to support the storage and VM migrations. 2. Storage vmotion 4

Once the isessions infrastructure is in place, initiating a Storage vmotion event is the first step in actually moving the VM from one data center to the other. Different trigger mechanisms are possible (e.g. VMware vcenter Orchestrator); however, ultimately vcenter will trigger a Storage vmotion event and begin migrating the virtual disks between the primary and secondary data centers. All application traffic will continue to flow to the VM located in the primary data center and vcenter in that data center will still retain control over the VMs tied to the Storage vmotion event. The storage data is passed through the secure and optimized isesssions tunnel over the WAN connection. 3. VM vmotion Once the Storage vmotion event finishes, vcenter in the primary data center will trigger a standard vmotion event to move the running VM to the secondary data center. vmotion will be moving the VM over the isessions tunnel to an ESX server located in the secondary data center which, due to the isessions tunnel, is part of the same network as the primary data center. During the migration event, vcenter at the primary data center will remain in control of the transplanted VM. 4. Data Center Connection Redirection After successful completion of the vmotion migration event to the secondary data center, BIG-IP LTM at the secondary data center will recognize that the application is up and available. BIG-IP LTM at the primary data center will start routing existing connections through the isessions tunnel to the VM now running at the secondary data center. BIG-IP GTM will also begin sending any new connections directly to the migrated VM in the secondary data center. As the existing user connections naturally terminate, all application traffic will be routed natively to the secondary data center. 5. vcenter VM Re-registration After the migrated VM is up and running in the secondary data center and all application traffic is being routed to that machine, BIG-IP LTM will send an instruction to the vcenter consoles at both data centers, turning over VM management to vcenter in the secondary data center. vcenter in the primary data center will stop managing the migrated VM, thus completing the longdistance vmotion event. The entire VM bundle, from storage up through management, is now live and serving users out of the secondary data center, and the VM in the primary data center can be shut down. 6. IP Reclamation 5

In the event of a one-way move where the vmotion migration is a more permanent relocation-such as with a planned migration from one data center to another, or to a cloud deployment-the original IP space for the VM in the primary data center can be reclaimed and reused for other applications. Once the migration is complete-vcenter in the secondary data center has assumed control of the VM and all user connections are being routed to the secondary data center-the IP addresses in the primary data center (both local/internal and external) can be reclaimed and reused for other applications. Live Migration Use Cases There are two primary use cases for migrating a running virtual machine between data centers using live migration: planned and unplanned. Planned migrations between data centers is more common; however the F5 solution enables both planned and unplanned migrations over distance based on need. Planned Migrations As enterprises simultaneously scale out their data centers (either by building additional physical data center resources or by looking at off-premises cloud solutions) and consolidate the resources within those data centers, virtualization plays a major part in taking more control over existing resources. It is not uncommon for an enterprise to consolidate one data center by moving all the server resources to a virtual platform and then replicating that model out to additional data centers or cloud providers. Long distance live migration enables IT to populate and replicate services to additional data centers without affecting the application or the user experience. A common example of planned migration is when one company buys another and acquires additional data center resources, and needs to move virtual machines and applications from the acquired data center to the existing primary corporate data center. Existing running virtual machines can be migrated with vmotion to the primary data center without downtime, allowing the administrators to move users and connections with those virtual machines to the new location. This model also holds true for scaling out to a new data center or a cloud provider. Planned long distance live migrations provide total flexibility for when both the applications and the users are moved, allowing migrations for scale out, disaster planning, or data center management to occur as needed. Unplanned Migrations 6

Unplanned Migrations Although not as common, the same infrastructure that enables planned long distance live migrations also supports unplanned migrations of running virtual machines without disruptions. Once a secondary or cloud data center has been populated to mirror the primary data center, moving users to the new location becomes a feasible option for any reason. Cloudbursting is the act of dynamically scaling out resources based on need: as new resources are needed, new virtual machines are created and managed as part of the available application pool through BIG-IP LTM. Although it is possible to scale out for a cloudbursting event manually, it is typically an automated trigger that kicks off the event. For example, BIG-IP LTM may detect an application has reached 80 percent capacity and instruct VMware vcenter to provision a new virtual machine to accommodate the load. Once the new virtual machine is available, BIG-IP LTM can begin moving existing connections from the original virtual machine to the newly provisioned one. In a distributed data center model, it becomes possible to dynamically provision the new virtual machine and migrate existing user connections to an off-premises location over distance using vmotion. Through a long distance live migration, the entire application workload can be migrated to the off-site data center while continuing to service user connections and without interruption to the application. This model becomes more compelling in the case of a hybrid cloud environment, where an off-premises cloud provider is hosting a private VMware cloud solution for the enterprise. By connecting the cloud provider with the existing data center, BIG- IP LTM and vmotion enable the enterprise to dynamically scale virtual machines over distance without manual intervention. Conclusion VMware has changed the way we build data centers, and cloud computing is changing how we think about local and remote data centers. Moving applications and running servers between hardware platforms enables us to create a very fluid and agile IT infrastructure to support new business needs. Yet these solutions are not seamless out of the box and often don't factor in the application needs and user experience. Not only does F5 enable planned and unplanned long distance live migration events from cloud to cloud, but the same solution can be deployed within the local data center to migrate running VMs from one physical network to another physical network (assuming the VM network configuration remains unaltered). This solution can help move VMs from the dev/staging network into production, or move a running VM between security zones such as the DMZ and the private network. Regardless of whether you're using F5 BIG-IP solutions to manage vmotion events 7

Regardless of whether you're using F5 BIG-IP solutions to manage vmotion events within the data center, between private clouds, or between private and public clouds, the application delivery technology remains the same. isessions keeps the data secure in transit and optimizes the WAN for accelerated and reliable delivery of the storage and VM data. The VMware API enables BIG-IP solutions to request reregistration of the migrated VMs within vcenter in the destination cloud or data center. BIG-IP LTM and BIG-IP GTM manage user connections to the application to ensure that no user data is lost and that the applications remain online and available. This integrated solution between F5 and VMware enables long distance live migration with vmotion for the first time between data centers and clouds. The solution works with your existing network and IT infrastructure; it does not require a re-architecture of your local or remote networks. This seamless solution uses existing technologies from both F5 and VMware to enable transparent live VM migration over long distances, guaranteeing the applications are migrated in a secure and optimized manner and always remain available before, during, and after the vmotion migration. Moving your applications and services transparently between clouds is now possible with F5 and VMware. F5 Networks, Inc. 401 Elliott Avenue West, Seattle, WA 98119 888-882-4447 www.f5.com Americas info@f5.com Asia-Pacific apacinfo@f5.com Europe/Middle-East/Africa emeainfo@f5.com Japan f5j-info@f5.com 2015 F5 Networks, Inc. All rights reserved. F5, F5 Networks, and the F5 logo are trademarks of F5 Networks, Inc. in the U.S. and in certain other countries. Other F5 trademarks are identified at f5.com. Any other products, services, or company names referenced herein may be trademarks of their respective owners with no endorsement or affiliation, express or implied, claimed by F5. CS01-00038 0113 8