Sunteți pe pagina 1din 6

WHITE PAPER: Steelhead Hybrid Networking

STEELHEAD
HYBRID
NETWORKING
INCREASE NETWORK APPLICATION PERFORMANCE
AND AVAILABILITY WHILE REDUCING COSTS WITH
RIVERBED PATH SELECTION
THE RISE OF THE HYBRID INFRASTRUCTURE
Today, businesses are rapidly adopting cloud Until recently, enterprises followed a model Global enterprises are rapidly
infrastructure and SaaS applications broadly where the vast majority of applications adopting cloud infrastructure and
across the enterprise. Enterprise workforces where hosted within private datacenters, SaaS applications broadly, and
are using applications, managing data, with standardized WAN on MPLS network the Internet is now a part of their
and conducting research along with other services. In a world with public and private
business critical infrastructure.
activities on the Internet and in the Cloud. resources, however, a hybrid network that
In fact, more than half of all enterprises combines the strengths of highly reliable With combined public and private
are using the cloud for storage, ERP, email, MPLS networks with the ubiquity and lower resources, the network itself
collaboration, and more. cost of Internet infrastructure can be more needs to go hybrid, combining the
economical. strengths of the highly reliable
Yet data, including large files, unified
communications, recreational traffic, and MPLS with the ubiquity, price, and
more that are destined for the public speed of the Internet. The hybrid
Internet still travel through the costly MPLS networking model from Riverbed
network. That’s an inefficient way to access
Technology enables organizations to
services and applications, such as cloud
collaboration or cloud CRM, which can be adopt hybrid networks to maximize
accessed directly on the Internet without the performance of applications,
ever touching the corporate MPLS network. increase network availability, and
And the cost is high, especially when reduce costs while retaining IT
compared to broadband Internet. Typical control and minimizing complexity.
studies tell us that a MPLS megabyte can
cost up to 200 times more than a broadband This paper explains how Riverbed
megabyte, per month.
path selection technology is a
superior approach for designing
1
2012 Cisco Global Cloud Networking Survey
hybrid networks.
2
http://www.networkworld.com/community/blog/why-does-mpls-cost-so-much-more-internet-connectivity
WHITE PAPER: Steelhead Hybrid Networking

CREATING A NETWORK THAT MAKES MORE SENSE


Enterprises have three new compelling options involving an hybrid of MPLS and Internet:

Move from MPLS to MPLS + Internet Leverage local-Internet breakouts Turn unused backup-lines into
backhaul and triple the available for SaaS traffic business lines
bandwidth Hybrid networks can be used to easily direct Many enterprises use a primary MPLS
For enterprises struggling with demand for a selected part of the Internet traffic to local network backed up by an IPSec-based Internet
bandwidth, moving from a pure MPLS to a Internet gateways. line that is reserved only for MPLS failover.
hybrid network truly combining MPLS and In other words, that backup line typically sits
Let’s consider a user in San Francisco, who is
Internet-based links to backhaul traffic to the unused and lonely for traffic. Hybrid networks
forced to go through MPLS to a default central
datacenter is a cost effective option. It can let you convert that rarely used Internet link
Internet breakout in New York to access a
yield a dramatic 300% growth of the available into an active business line by routing certain
SaaS application, which is actually hosted in
bandwidth on branches, without increasing types of traffic over it, such as non-business-
a datacenter based in Seattle. This situation
overall networking budget. critical traffic.
creates a “tromboning” effect marked by
added latency and unnecessary usage of
expensive MPLS bandwidth. If a local Internet
connection is present in the San Francisco
branch, hybrid networks can selectively direct
the user’s SaaS traffic to be forwarded directly
to the Seattle-based datacenter, while other
Internet traffic could continue to flow through
the New York secured gateway. The result is
faster performance and a smarter utilization of
network resources.

RIVERBED PATH SELECTION TECHNOLOGY MAKES


HYBRID NETWORKS EASY
Until now, creating seamless hybrid networking With Riverbed, organizations can embrace • Is application-aware and able to precisely
architecture has been obstructed by the hybrid networks to maximize the performance distinguish business-critical applications
complexity of defining which traffic goes of business-critical applications, boost network from less important applications
on which network. Hard-coded router availability, and reduce costs while retaining IT
• Constantly senses path availability in real
configurations and policy-based routing are an control and minimizing complexity.
time using active probes for dynamic
intrusive burden on network administration,
With Riverbed® Optimization System (RiOS®) path failover
and ultimately neither are reliable nor granular
8.5 path selection technology, IT organizations
enough to provide value. Without a simple • Is simple to manage with centralized
can deploy and manage complex hybrid
way to define rules and configure the hybrid user interfaces
networks to deliver greater application reliability
network, implementation of hybrid networking
and performance for less cost. (RiOS is the • Works with application visibility and
has remained difficult.
software that runs inside Riverbed Steelhead® WAN optimization for complete
WAN optimization solutions). Unlike legacy management of business critical
policy-based routing technologies, Riverbed applications over the WAN
path selection technology:

APPLICATION-AWARE
Legacy solutions classify traffic using port complexity and increased operational risks. For example, it even offers the ability to
numbers and IP addresses. Business applications With Riverbed path selection technology, flows clearly distinguish between SSL-encrypted
based on HTTP are by default classified in the are classified using deep packet inspection applications. Or instead of looking at Facebook
same bucket as non-critical YouTube traffic. (DPI)-based application awareness allowing as a consumer app, it can allow Facebook news
This can only be resolved using classification to precisely steer traffic on different paths feeds and updates but block non-business
based on IP addresses, leading to configuration according to their true nature and criticality. applications such as Farmville.
WHITE PAPER: Steelhead Hybrid Networking

ACTIVELY SENSING PATHS AVAILABILITY


In legacy solutions, path availability is importance applications over less reliable paths a good quality of experience. Path selection
determined using routing-based metrics that like Internet. With Riverbed path selection, rapidly and dynamically adapts the paths before
are slow to converge and unable to report path availability is constantly monitored; end users are impacted, thus allowing even
brownout situations (when the network link active probes rapidly detect both blackout business-critical applications to utilize paths like
is still up but quality of the path is below the and brownout situations where the path the Internet if needed.
usability threshold). As a result, organizations quality is degraded to the point that sensitive
are not compelled to offload more than low applications can no longer be delivered with

TRANSPARENCY AND SIMPLICITY


Unlike other approaches, Riverbed path with complex rules. Thus, the technology is
selection technology utilizes a transparent transparent to the existing network and is easy
overlay service versus changing the packet- to configure through an intuitive graphical
forwarding plane. This approach results in interface.
a clean abstraction between network layers
and obviates the need to reconfigure routers

WORKS WITH APPLICATION VISIBILITY AND WAN OPTIMIZATION


Path selection technology is an integrated and monitoring with application-level Quality
element of an application performance suite. of Service (QoS). It also provides a range of
The suite provides integrated application application optimizations to ensure peak
visibility that simplifies policy construction and performance of critical applications.
troubleshooting. Deployed across the network,
the suite allows for network configuration

BUSINESS IMPERATIVES
This shift to a hybrid network satisfies the core imperatives for any enterprise network:

• Lower costs • Increased performance • Increased reliability


Growing a network with commercial- When a hybrid network is managed A hybrid network driven by Riverbed
grade Internet to complement with path selection, the bandwidth path selection technology offers
premium-priced MPLS bandwidth available to applications is a rapid failover capability. When
lets you scale the network to match dramatically improved. Internet links the primary network becomes
growth and usage patterns, with a can be fully utilized, freeing precious unavailable, the other becomes an
flat or even reduced impact on IT MPLS bandwidth. Bottlenecks and instant backup, leading to an overall
spend. latency are minimized. That translates increase of network reliability.
into optimal performance and high
levels of user satisfaction.
WHITE PAPER: Steelhead Hybrid Networking

DESIGNING HYBRID NETWORKS WITH


CASE IN POINT RIVERBED PATH SELECTION TECHNOLOGY
Zero Dollars and 3x the Bandwidth Path selection technology in Steelhead in cascading order. The path selection
A large engineering firm with 180 solutions empowers IT organizations technology deterministically redirects
with greater controls to maximize select traffic and application flows
offices in 31 countries needed to
multiple WAN services based on business through alternate networks based on
support the traffic from their traditional needs, service quality, and costs. It service metrics, such as path availability,
enterprise applications and their ever- redirects specific traffic or applications application priority, and the rules
increasing web traffic. Buying more Control:
through one of three alternate paths
determined by destination availability
you create.
WAN bandwidth was an unsustainable
approach. Their goal was to increase
What’s NEW with Path Selection
aggregate bandwidth across the WAN
Internet   Cloud  
(from 3 Gbps to 9 Gbps) with a flat
budget impact.
MPLS  
They deployed Steelhead appliances Branch  Office   Data  Center  

to continue to backhaul all Internet-


destined traffic to headquarters for Path
Classification Forward Monitor
Failover
a simplified Internet security design,
while augmenting their bandwidth with •  Application •  Next Hop MAC •  End-to-end path •  Apps configured
Flow Engine address availability with prioritized
commodity Internet links and IPSec- classification monitoring list of paths
based Virtual Private Networks (VPNs) •  Packet rule •  Upstream •  Active probing •  Dynamic path
for greater aggregate bandwidth. classification policy based selection in case
routing of performance
degradation
Figure 1. The four functions of RiOS 8.5 Path Selection Technology

At its broadest level, path selection technology performs four critical functions:

Classifies traffic on. In this way, operators can the Steelhead solution is not in a default and a prioritized set
Steelhead solutions use instruct Steelhead solutions to the same Layer 2 domain, the of backup paths. Should the
information from the Riverbed precisely associate applications to Steelhead appliance uses DSCP default path be unavailable, the
Application Flow Engine about networks based on their nature, marking with upstream policy- higher-priority backup is instantly
more than 600 individual performance requirements, and based routing. used (and then the lower one
applications and processes to business criticality. if needed). Operators can even
Monitors availability
understand where data is coming decide to block certain type of
Forwards packets Steelhead solutions monitor path
from, which application sent it, applications when the primary
Once the Steelhead solution availability and quality end-to-end. path becomes unavailable with a
and what function that application
has selected the right path, You define the endpoint IP address goal of reserving the remaining
is trying to accomplish. The
the preferred next step is for for every path, and the Steelhead available bandwidth for more
Riverbed Application Flow Engine
it to steer traffic to the newly solution will send an ICMP ping critical applications. As soon as the
utilizes a variety of techniques,
selected path. This operation is every two seconds. To validate default path becomes available,
often in combination, like port-
transparent to the client, server, availability, each path can have a traffic is routed back to it.
based classification, application
and any networking devices different remote host.
signature matching, protocol
such as routers or switches. It
dissection, behavioral classification Manages failover
can either be performed directly
and others. Traffic can also be If three consecutive pings are
using distinct Steelhead physical
classified using the full assortment missed, the path is considered
interfaces or indirectly using MAC
of packet rules, including IP to be unavailable, and the
address rewriting. When that’s not
addresses, 5-tuple, DCSP, TCP backup path is selected. Every
possible, for instance with virtual
and UDP port numbers, and so application has a list of paths:
in-path deployments or where
WHITE PAPER: Steelhead Hybrid Networking

BRANCH DEPLOYMENT EXAMPLES


CASE IN POINT The examples that follow illustrate a network with a single Steelhead appliance
connected to multiple upstream routers, and a network with a second Steelhead
Hybrid Networks To Increase appliance for redundancy. Each router is the gateway to a particular path. Both
Performance and Reduce Costs examples show MPLS and Internet/VPN.
A global consumer goods company
was approaching a major MPLS WAN
refresh cycle and contract renewal. But
growing the existing infrastructure to 1
3
meet projected bandwidth needs would
be very costly. The company wanted to
control MPLS circuit upgrades, and, at
2 3
the same time, expand network capacity
significantly.

The company deployed Steelhead


Figure 2. Single Steelhead Appliance (with multiple upstream routers) in a Layer-Two Connected Branch
solutions to fully leverage a hybrid
network combining MPLS, Internet 1. Traffic from the clients 2. Traffic is then 3. The appropriate
backhauling, and local Internet arrives at the active forwarded from the upstream router receives
breakouts. Riverbed path selection Steelhead appliance Steelhead WAN interface the traffic (based on the
and is classified by path and sent to that updated destination MAC address)
ensures the right traffic travels the
selection rules. That MAC address. and forwards it down the
right path. That means directing high- traffic’s source and appropriate path.
bandwidth internal applications (such as destination MAC address
internal videos, email, anti-virus updates, updated appropriately.
Microsoft SCCM and SharePoint, and
In this configuration, failure is best handled through a Steelhead appliance’s “fail to
backup and replication) to Internet VPN
wire” setting, which directly connects LAN and WAN as if the Steelhead appliance
links. Internet and SaaS traffic is sent to was not part of the network flow. This causes all traffic to flow down the default,
the public Internet in regional hubs. routed path in the event of an appliance failure.

2 3

2 3

Figure 3. Dual Steelhead Appliances in Redundant Branch

1. Traffic from the clients 2. Traffic is then 3. The appropriate


arrives at the active forwarded out the upstream router receives
Steelhead appliance appropriate Steelhead the traffic and forwards
and is classified by path appliance’s WAN interface it down the appropriate
selection rules. according to the rules. path.

In this configuration, failure is best handled through a Steelhead appliance’s “fail to


block” setting, which sends the traffic to the redundant Steelhead appliance.
WHITE PAPER: Steelhead Hybrid Networking

DESIGN CONSIDERATIONS
Return traffic flows in Firewalls and application Client default gateways for
the Datacenter flow engine detection single-subnet branches
As a transparent overlay solution, path The Riverbed Application Flow Engine (all If path selection technology is deployed
selection technology does not interfere Deep Packet Inspection—DPI—technologies in a branch with clients on the same
with the routing layer. Accordingly, to for that matter) can require multiple packets subnet as the routers terminating the
ensure both directions of a given flow to appropriately classify an application. different paths, care must be taken to
use the same path, customers should place ensure the clients’ default gateway IP
Stateful inspection firewalls generally need
Steelhead appliances with the same path address remains highly available. Riverbed
to see all traffic on a flow, starting with the
selection policy configuration on both recommends using Virtual Router
initial SYN packet. Because of that, firewalls
sides of the path. Redundancy Protocol (VRRP), or a similar
merit special consideration if using AFE-based
mechanism, to ensure responses to client
rules for traffic selection.
Address Resolution Protocol (ARP) requests
If path selection using AFE-based rules in the event of router failure.
classifies an application after the initial SYN
packet, and then switches that path to a path
with a firewall running stateful inspection,
that firewall will most likely drop that flow,
as the firewall has no connection entry for
that session. You can resolve this by making
the firewall path the “default” path for
unclassified traffic. (See the Path Selection
Design Guide for the Steelhead Product
Family for full details.)

LEARN MORE ABOUT HYBRID NETWORKING


A hybrid network—when controlled by Riverbed path selection technology for Steelhead solutions—combines the WAN and
private and public Internet to increase available bandwidth and increase application performance and network reliability at the
lowest cost possible. It allows enterprises to get the benefits of a hybrid network without the underlying complexity of managing
multiple links in a branch. Steelhead appliances with path selection technology can help you maximize return on your application
and infrastructure investments. To learn all the details, contact us today at http://www.riverbed.com/hybridnetwork

ABOUT RIVERBED
Riverbed® Technology is the leader in Application Performance Infrastructure, delivering the most complete platform for location-
independent computing. Location-independent computing turns location and distance into a competitive advantage by allowing IT
to have the flexibility to host applications and data in the most optimal locations while ensuring applications perform as expected,
data is always available when needed, and performance issues are detected and fixed before end users notice. Riverbed’s 24,000+
customers include 97% of the Fortune 100 and 95% of the Forbes Global 100. Learn more at www.riverbed.com.

©2014 Riverbed Technology. All rights reserved. Riverbed and any Riverbed product or service name or logo used herein are trademarks of Riverbed Technology. All other trademarks used
herein belong to their respective owners. The trademarks and logos displayed herein may not be used without the prior written consent of Riverbed Technology or their respective owners.

S-ar putea să vă placă și