Documente Academic
Documente Profesional
Documente Cultură
Clouds are dynamic by design and require flexibility, scalability and programmability that todays data center networks do not provide. The physical network is an inflexible, complex and costly barrier to realizing the full agility now available to cloud service providers and large enterprise data centers. Networking has not kept pace with the dynamic requirements of cloud data centers and instead is bogged down in a 20-year-old operational model originally designed for manual provisioning on a device-by-device basis. Networks are overly complicated, fragile systems constructed from hundreds of individual devices tied together by complex and often vendor specific interfaces with no central programmatic control. Networks lack the fundamental operational characteristics to achieve efficiency and flexibility required by todays cloud data centers.
Virtualized Network
A Network Hypervisor
A network hypervisor must:
Completely decouple network services from underlying hardware. Faithfully reproduce physical network model in logical space. Operate on any existing IP network infrastructure. Integrate with any server virtualization solution. Allow logical networks to be programmatically provisioned and managed through central API. Bind network services to workloads, allowing dynamic placement and mobility of any workload, anywhere. Enable physical network capacity to scale independent of logical network con guration. Expose logical ports on physical access switches through integration with hardware partners.
A network hypervisor decouples network services from the underlying physical network hardware. Its software that operates at the edge of any existing IP network and faithfully reproduces the entire networking environment in logical space. A network hypervisor transforms a physical network into a generalized pool of network capacity, like a server hypervisor transforms physical servers into a pool of compute capacity.
Decoupling logical networks from the physical hardware allows you to scale the pool of network capacity without affecting the logical networks operating above it. Now delivering simple IP connectivity, the physical networks complexity is greatly reduced and any requirement for specialized hardware features is eliminated. Hardware independent capacity can be added as required without affecting the logical networks utilizing the physical infrastructure.
Beyond VLANs
Are you creating and managing complex L2 networks that require reconfiguration of hardware to extend VLANs to another part of the data center? Are VLAN limits one of your concerns? Would you like to be able to extend L2 connectivity into your customers data center? Do you want both physical and virtual workloads to be on the same L2 network? If you answered yes to any of these questions, you need to virtualize your network. A Nicira virtualized network supports 100s of thousands of dynamically provisioned, fully isolated logical networks, completely decoupled from the underlying network hardware. Logical networks are able to connect into existing physical VLANs, but VLANs are not required by the architecture. Each logical network is equivalent to a hardware-based Layer 2 switch, with all of the enterprise network services you expect. (See diagram to the right) The difference, of course, is that logical network ports are programmatically provisioned, attached to workloads and placed or moved on demand, anywhere in the data center.
Packet Forwarding
Logical Ports
Port Isolation (PVLAN) Port Security (Tie Port to MAC to IP) Port Visibility (NetFlow, RSPAN, SNMP) Port Performance Guarantees (QoS, Caps, Min/max w/ priority) Port Level Access Policy (ACLs, Firewall Rules) Port Level Accounting (RX/TX Packets/Bytes) Integrate with Layer 4-7 services (SLBs, IPSs, FWs)
Physical Ports
Everything Changes
Virtualize your network, and your cloud ascends into a new era of network computing where hardware limitations and physical boundaries vanish. Multi-tenant and fully-isolated Your cloud data center network has become a dynamic, highly scalable, multi-tenant environment in which 100s of thousands of logical Layer 2 networks are fully isolated from each other. Dynamically place any workload anywhere You can now programmatically place any workload, anywhere. Both physical and virtual workloads can be dynamically joined on the same logical networks that span physical IP subnets, across and between data centers and even into customer data centers. Accurate, pay-as-you-go accounting Fine grain port level visibility accurately measures usage on a, per-port-per-serviceper-hour basis, allowing you to tightly align costs with revenue and accurately bill on a usage basis. Dynamic security for clouds Security is configured centrally and enforced at the edge, completely changing the security equation and removing the traditional choke point network security model. IPv6 over existing IPv4 Infrastructure Nicira allows IPv6 end hosts to communicate seamlessly over logical networks on an existing IPv4 physical infrastructure.
No Rip-and-Replace
Nicira creates an intelligent network edge managed by a distributed central control system that transforms your existing physical network into an IP backplane and enables the programmatic creation of thousands of agile logical networks to connect workloads anywhere in your cloud. With this capability, everything changes...
Copyright Nicira Networks, Inc. All Rights Reserved.
How it Works
Nicira creates an intelligent network edge on your existing network, managed by a distributed system that transforms your physical network into an IP backplane and enables the programmatic creation of thousands of agile logical networks to connect workloads in your cloud. An intelligent edge Open vSwitch (OVS) is the core component on the intelligent edge. OVS is switch software designed for remote control. OVS is deployed in three possible forms at the edge of a Nicira virtualized network. See diagram below. First, and most widely deployed is OVS in the server hypervisor. A completely software solution that works with your existing VMware, Xen, Xen Server, KVM or Hyper-V hypervisor. Second, the Extender OVS in a virtual or physical x86 appliance. This is primarily deployed to integrate with legacy physical networks, for example, to connect an entire VLAN into the cloud data center on the same logical network. Third, the pSwitch OVS embedded in access switch hardware, supplied by partners. This is used to directly connect physical servers or to take advantage of hardware acceleration. A controller cluster The Nicira controller is a highly available clustered controller running on x86 servers that manages all virtualized network components and connections. The controller cluster exposes the web services API and defines logical networks. Capable of controlling and managing 10s of thousands of OVS edge devices, the controller does not sit in the data path.
V1 Virtual Machines V2 V3
Open vSwitch in Server Hypervisor for VMware, Xen, Xen Server, KVM & Hyper-V
DB1 V1 V2 V3 S1 S2
Controller Cluster
Logical Network Port Isolation Port Level Security & Access Control Port Level Performance Guarantees (QoS) Port Level Visibility Port Level Accounting Logical View
API
ligent Edge Intel
Internet
S1
S2 Customer VLAN