SlideShare a Scribd company logo
Science DMZ
DrAlan Buxey, Loughborough University, Campus network engineering workshop
19/10/2016
1
“Science DMZ”
Or “exo-perimeter safe-harboured
segmented network architecture facilitating
science and research data transfer and
access”
JISC e2e event, 19th Oct 2016
Dr Alan Buxey
Loughborough University
Science DMZ
• An overview of the concept
• In one slide!
• Versus the typical ‘ad-hoc’ deployment
• Deployment…and onwards....
Consists of three key components, all required:
• “Friction free” network path
– Highly capable network devices (wire-speed, deep queues)
– Virtual circuit connectivity option
– Security policy and enforcement specific to science workflows
– Located at or near site perimeter if possible
• Dedicated, high-performance Data Transfer Nodes (DTNs)
– Hardware, operating system, libraries all optimized for transfer
– Includes optimized data transfer tools such as Globus Online and GridFTP
• Performance measurement/test node
– perfSONAR
Did we say *3* components?
• Engagement with end users
Details at http://fasterdata.es.net/science-dmz/
The Science DMZ* in 1 Slide
* Science DMZ is a trademark of The Energy Sciences Network (ESnet)
Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science
Ad Hoc DTN Deployment
If present, perfSONAR is at the border
• This is a good start
• Need a second one next to the
DTN
Entire LAN path has to be sized for data
flows
Entire LAN path is part of any
troubleshooting exercise
This usually fails to provide the
necessary performance.
15 – ESnet Science Engagement (engage@es.net) - 1/27/14
10GE10G
Site Border
Router
WAN
Buildingor Wiring
Closet Switch/Router
Perimeter Firewall
Site/ Campus
LAN
Highperformance
DataTransfer Node
withhigh-speedstorage
Globalsecuritypolicy
mixesrulesforscience
andbusinesstraffic
DTNtrafficsubjecttofirewall
limitations
perfSONAR
Testandmeasurement
notalignedwithdata
resourceplacement
DTNtrafficsubjecttolimitationsof
general-purposenetworking
equipment/config
Note:Siteborder
routerandperimeter
firewallareoftenthe
samedevice
Conflictingrequirements
resultinperformance
compromises
This is often what gets tried first
Data transfer node deployed where the owner has space
• This is often the easiest thing to do at the time
• Straightforward to turn on, hard to achieve performance
Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science
A better approach: simple Science DMZ
10GE
10GE
10GE
10GE
10G
Border Router
WAN
Science DMZ
Switch/Router
Enterprise Border
Router/Firewall
Site / Campus
LAN
High performance
Data Transfer Node
with high-speed storage
Per-service
security policy
control points
Clean,
High-bandwidth
WAN path
Site / Campus
access to Science
DMZ resources
perfSONAR
perfSONAR
perfSONAR
Familiar?
• Presented at JISC e2e performance initiative event in
2015
• Presented at Networkshop 44
• Presented at TNC2016
Getting the concept and message out there 
Who/what/where?
• DTN / HPC
• Have requirements for 10Gbit data transfer
• Access/control now self-contained
• SDN experiments
• Out of the way, isolated from inside production
• IPv6 experiments
• ditto
Cost/benefits
10G firewalls (Palo Alto) – campus traffic already using that budget (e.g. students)
“We need to transfer data….need 10Gbit...”
$$$$$$ for bigger firewalls, ‘small change’ for suitable 10G (and higher!) switches
Start small, build the environment
• Basic small L2/L3 switch e.g. catalyst 3750
• Route statically from the external
• (then find out about buffers, QoS limitations etc ;-) )
• Measurement tools e.g. PerfSONAR
• Be ready to see difference
• Inside/outside (can use to e.g. verify firewall)
• Engage with local community, propose idea
• Trust!
Looks like… (Nexus 9372PX-E)
Image during staging. 2x10G to border, 2x10G to HPC, 2x10G VCP, 1G
keepalive/heartbeat
(40G optics not in use at this stage), long loopy fibres due to flexibility ;-)
PerfSONAR MadDash (small nodes)
IPv4 throughput IPv6 throughput
eduPERT
A small amount of packet loss makes a HUGE difference in TCP performance
The future?
file://localhost/.file/id
=6571367.66263948
Inspiring Winners Since 1909
Thank you!
Alan Buxey
a.l.m.buxey@lboro.ac.uk

More Related Content

PDF
Science DMZ at Imperial
PPT
Solving Network Throughput Problems at the Diamond Light Source
PPTX
Archiving data from Durham to RAL using the File Transfer Service (FTS)
PPTX
Enabling efficient movement of data into & out of a high-performance analysis...
PPTX
Provisioning Janet
PPTX
perfSONAR: getting telemetry on your network
PPT
Impact of Grid Computing on Network Operators and HW Vendors
PDF
Pic archiver stansted
Science DMZ at Imperial
Solving Network Throughput Problems at the Diamond Light Source
Archiving data from Durham to RAL using the File Transfer Service (FTS)
Enabling efficient movement of data into & out of a high-performance analysis...
Provisioning Janet
perfSONAR: getting telemetry on your network
Impact of Grid Computing on Network Operators and HW Vendors
Pic archiver stansted

What's hot (20)

PDF
Stansted slides-desy
PPT
Grid optical network service architecture for data intensive applications
PPT
DIET_BLAST
PPTX
Network Engineering for High Speed Data Sharing
PDF
40 Powers of 10 - Simulating the Universe with the DiRAC HPC Facility
PPTX
20181219 ucc open stack 5 years v3
PPTX
Challenges and Issues of Next Cloud Computing Platforms
PDF
CloudLab Overview
PPTX
CERN IT Monitoring
PPTX
An Overview of Bionimbus (March 2010)
PPTX
NERSC, AI and the Superfacility, Debbie Bard
PDF
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
PPTX
Open Science Data Cloud - CCA 11
PPTX
Stanford/SLAC Cryo-EM Computing and Storage, Yee-Ting Li
PPT
Large Scale On-Demand Image Processing For Disaster Relief
PDF
DSD-INT 2015 - Data management with open earth datalabs - Gerben de Boer, van...
PDF
How HPC and large-scale data analytics are transforming experimental science
PPT
Lessons Learned from a Year's Worth of Benchmarking Large Data Clouds (Robert...
PPTX
Open Science Data Cloud (IEEE Cloud 2011)
PDF
CloudLightning and the OPM-based Use Case
Stansted slides-desy
Grid optical network service architecture for data intensive applications
DIET_BLAST
Network Engineering for High Speed Data Sharing
40 Powers of 10 - Simulating the Universe with the DiRAC HPC Facility
20181219 ucc open stack 5 years v3
Challenges and Issues of Next Cloud Computing Platforms
CloudLab Overview
CERN IT Monitoring
An Overview of Bionimbus (March 2010)
NERSC, AI and the Superfacility, Debbie Bard
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
Open Science Data Cloud - CCA 11
Stanford/SLAC Cryo-EM Computing and Storage, Yee-Ting Li
Large Scale On-Demand Image Processing For Disaster Relief
DSD-INT 2015 - Data management with open earth datalabs - Gerben de Boer, van...
How HPC and large-scale data analytics are transforming experimental science
Lessons Learned from a Year's Worth of Benchmarking Large Data Clouds (Robert...
Open Science Data Cloud (IEEE Cloud 2011)
CloudLightning and the OPM-based Use Case
Ad

Viewers also liked (13)

PPTX
110G networking within JASMIN
PPTX
Challenges in end-to-end performance
PPTX
Science DMZ security
PPTX
The Science DMZ
PPTX
Electron Microscopy Between OPIC, Oxford and eBIC
PDF
Protecting our customers - BT security
PPTX
Data and information governance: getting this right to support an information...
PPTX
Cyber Crime - "Who, What and How"
PPT
Role of the CISO in Higher Education
PPTX
Mitigation starts now
PPTX
Certifying and Securing a Trusted Environment for Health Informatics Research...
PPT
Working with students and ISO27001
PPTX
Closing plenary and keynote from Lauren Sager Weinstein
110G networking within JASMIN
Challenges in end-to-end performance
Science DMZ security
The Science DMZ
Electron Microscopy Between OPIC, Oxford and eBIC
Protecting our customers - BT security
Data and information governance: getting this right to support an information...
Cyber Crime - "Who, What and How"
Role of the CISO in Higher Education
Mitigation starts now
Certifying and Securing a Trusted Environment for Health Informatics Research...
Working with students and ISO27001
Closing plenary and keynote from Lauren Sager Weinstein
Ad

Similar to Science DMZ (20)

PPTX
Future services on Janet
PDF
Tutorial: Maximizing Performance and Network Utility with a Science DMZ
PDF
Research data zone: veilige en geoptimaliseerde netwerkomgeving voor onderzoe...
PPTX
On SDN Research Topics - Christian Esteve Rothenberg
PPTX
Network research
PDF
A University Network Design Exercise
PDF
Pronet Public Presentation v1 2
PPTX
The Pacific Research Platform
PDF
Future Internet: Managing Innovation and Testbed
PDF
Enhancing Performance with Globus and the Science DMZ
PDF
Science DMZ as a Service: Creating Science Super- Facilities with GENI
PDF
SDN-based Inter-Cloud Federation for OF@TEIN
PDF
OpenFlow: Enabling Innovation in Campus Networks
PDF
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
PPTX
Feec telecom-nw-softwarization-aug-2015
PPT
Naveen nimmu sdn future of networking
PPT
Naveen nimmu sdn future of networking
PDF
Common Design Elements for Data Movement Eli Dart
PDF
10 fn s03
PDF
10 fn s03
Future services on Janet
Tutorial: Maximizing Performance and Network Utility with a Science DMZ
Research data zone: veilige en geoptimaliseerde netwerkomgeving voor onderzoe...
On SDN Research Topics - Christian Esteve Rothenberg
Network research
A University Network Design Exercise
Pronet Public Presentation v1 2
The Pacific Research Platform
Future Internet: Managing Innovation and Testbed
Enhancing Performance with Globus and the Science DMZ
Science DMZ as a Service: Creating Science Super- Facilities with GENI
SDN-based Inter-Cloud Federation for OF@TEIN
OpenFlow: Enabling Innovation in Campus Networks
07 (IDNOG02) SDN Research activity in Institut Teknologi Bandung by Affan Bas...
Feec telecom-nw-softwarization-aug-2015
Naveen nimmu sdn future of networking
Naveen nimmu sdn future of networking
Common Design Elements for Data Movement Eli Dart
10 fn s03
10 fn s03

More from Jisc (20)

PPTX
Strengthening open access through collaboration: building connections with OP...
PPTX
Andrew-Brown-JUSP-showcase-20240730.pptx
PPTX
JUSP Showcase - Rebuilding Data presentation
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
FE Accessibility training matrix partnership - information session
PPTX
Procuring a research management system: why is it so hard?
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
How libraries can support authors with open access requirements for UKRI fund...
PPTX
Supporting (UKRI) OA monographs at Salford.pptx
PPTX
The approach at University of Liverpool.pptx
PPTX
Jisc's value to HE: the University of Sheffield
PPTX
Towards a code of practice for AI in AT.pptx
PPTX
Jamworks pilot and AI at Jisc (20/03/2024)
PPTX
Wellbeing inclusion and digital dystopias.pptx
PPTX
Accessible Digital Futures project (20/03/2024)
PPTX
Procuring digital preservation CAN be quick and painless with our new dynamic...
PPTX
International students’ digital experience: understanding and mitigating the ...
PPTX
Digital Storytelling Community Launch!.pptx
PPTX
Open Access book publishing understanding your options (1).pptx
PPTX
Scottish Universities Press supporting authors with requirements for open acc...
Strengthening open access through collaboration: building connections with OP...
Andrew-Brown-JUSP-showcase-20240730.pptx
JUSP Showcase - Rebuilding Data presentation
Adobe Express Engagement Webinar (Delegate).pptx
FE Accessibility training matrix partnership - information session
Procuring a research management system: why is it so hard?
Adobe Express Engagement Webinar (Delegate).pptx
How libraries can support authors with open access requirements for UKRI fund...
Supporting (UKRI) OA monographs at Salford.pptx
The approach at University of Liverpool.pptx
Jisc's value to HE: the University of Sheffield
Towards a code of practice for AI in AT.pptx
Jamworks pilot and AI at Jisc (20/03/2024)
Wellbeing inclusion and digital dystopias.pptx
Accessible Digital Futures project (20/03/2024)
Procuring digital preservation CAN be quick and painless with our new dynamic...
International students’ digital experience: understanding and mitigating the ...
Digital Storytelling Community Launch!.pptx
Open Access book publishing understanding your options (1).pptx
Scottish Universities Press supporting authors with requirements for open acc...

Recently uploaded (20)

PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Approach and Philosophy of On baking technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
A Presentation on Artificial Intelligence
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Electronic commerce courselecture one. Pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Approach and Philosophy of On baking technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
Unlocking AI with Model Context Protocol (MCP)
A Presentation on Artificial Intelligence
20250228 LYD VKU AI Blended-Learning.pptx
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
MIND Revenue Release Quarter 2 2025 Press Release
Spectral efficient network and resource selection model in 5G networks
Per capita expenditure prediction using model stacking based on satellite ima...
Electronic commerce courselecture one. Pdf
Group 1 Presentation -Planning and Decision Making .pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
“AI and Expert System Decision Support & Business Intelligence Systems”
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Network Security Unit 5.pdf for BCA BBA.
Advanced methodologies resolving dimensionality complications for autism neur...

Science DMZ

  • 1. Science DMZ DrAlan Buxey, Loughborough University, Campus network engineering workshop 19/10/2016 1
  • 2. “Science DMZ” Or “exo-perimeter safe-harboured segmented network architecture facilitating science and research data transfer and access” JISC e2e event, 19th Oct 2016 Dr Alan Buxey Loughborough University
  • 3. Science DMZ • An overview of the concept • In one slide! • Versus the typical ‘ad-hoc’ deployment • Deployment…and onwards....
  • 4. Consists of three key components, all required: • “Friction free” network path – Highly capable network devices (wire-speed, deep queues) – Virtual circuit connectivity option – Security policy and enforcement specific to science workflows – Located at or near site perimeter if possible • Dedicated, high-performance Data Transfer Nodes (DTNs) – Hardware, operating system, libraries all optimized for transfer – Includes optimized data transfer tools such as Globus Online and GridFTP • Performance measurement/test node – perfSONAR Did we say *3* components? • Engagement with end users Details at http://fasterdata.es.net/science-dmz/ The Science DMZ* in 1 Slide * Science DMZ is a trademark of The Energy Sciences Network (ESnet)
  • 5. Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science Ad Hoc DTN Deployment If present, perfSONAR is at the border • This is a good start • Need a second one next to the DTN Entire LAN path has to be sized for data flows Entire LAN path is part of any troubleshooting exercise This usually fails to provide the necessary performance. 15 – ESnet Science Engagement (engage@es.net) - 1/27/14 10GE10G Site Border Router WAN Buildingor Wiring Closet Switch/Router Perimeter Firewall Site/ Campus LAN Highperformance DataTransfer Node withhigh-speedstorage Globalsecuritypolicy mixesrulesforscience andbusinesstraffic DTNtrafficsubjecttofirewall limitations perfSONAR Testandmeasurement notalignedwithdata resourceplacement DTNtrafficsubjecttolimitationsof general-purposenetworking equipment/config Note:Siteborder routerandperimeter firewallareoftenthe samedevice Conflictingrequirements resultinperformance compromises This is often what gets tried first Data transfer node deployed where the owner has space • This is often the easiest thing to do at the time • Straightforward to turn on, hard to achieve performance
  • 6. Lawrence Berkeley National Laboratory U.S. Department of Energy | Office of Science A better approach: simple Science DMZ 10GE 10GE 10GE 10GE 10G Border Router WAN Science DMZ Switch/Router Enterprise Border Router/Firewall Site / Campus LAN High performance Data Transfer Node with high-speed storage Per-service security policy control points Clean, High-bandwidth WAN path Site / Campus access to Science DMZ resources perfSONAR perfSONAR perfSONAR
  • 7. Familiar? • Presented at JISC e2e performance initiative event in 2015 • Presented at Networkshop 44 • Presented at TNC2016 Getting the concept and message out there 
  • 8. Who/what/where? • DTN / HPC • Have requirements for 10Gbit data transfer • Access/control now self-contained • SDN experiments • Out of the way, isolated from inside production • IPv6 experiments • ditto
  • 9. Cost/benefits 10G firewalls (Palo Alto) – campus traffic already using that budget (e.g. students) “We need to transfer data….need 10Gbit...” $$$$$$ for bigger firewalls, ‘small change’ for suitable 10G (and higher!) switches
  • 10. Start small, build the environment • Basic small L2/L3 switch e.g. catalyst 3750 • Route statically from the external • (then find out about buffers, QoS limitations etc ;-) ) • Measurement tools e.g. PerfSONAR • Be ready to see difference • Inside/outside (can use to e.g. verify firewall) • Engage with local community, propose idea • Trust!
  • 11. Looks like… (Nexus 9372PX-E) Image during staging. 2x10G to border, 2x10G to HPC, 2x10G VCP, 1G keepalive/heartbeat (40G optics not in use at this stage), long loopy fibres due to flexibility ;-)
  • 12. PerfSONAR MadDash (small nodes) IPv4 throughput IPv6 throughput
  • 13. eduPERT A small amount of packet loss makes a HUGE difference in TCP performance
  • 15. Inspiring Winners Since 1909 Thank you! Alan Buxey a.l.m.buxey@lboro.ac.uk

Editor's Notes

  • #15: ACI (application centric infrastructure) Native VxLAN, netflow in ACI mode (next year)… NXOS supports Puppet, Chef, and Ansible, Python, POAP (power on autoprovisioning) etc etc 10/25 40/100 , using Cisco silicon "Superbowl” ASIC and not previous merchant silicon (was Broadcom Trident not Tomahawk)