SlideShare a Scribd company logo
Enabling Active Flow Manipulation In 
Silicon-based Network Forwarding 
Engines 
May 28-29, 2002 1 
Tal Lavian - tlavian@ieee.org 
Nortel Networks 
Advanced Technology Labs 
Open Source - http://www.openetlab.org 
DANCE Exposition
• AN technologies => Real Network Devices 
• Main thrust of the paper 
• Commercial Active Nets Platform 
• Application Example 1 – SSL 
• Application Example 2 – ASF 
• Next Generation AN Platform 
• Conclusion 
May 28-29, 2002 2 
Outline of the talk 
DANCE Exposition
May 28-29, 2002 3 
AN Technology Transfer 
DANCE Exposition 
Active Nets Community 
Realistic 
Mechanisms 
Great Ideas 
Usable/Realizable 
Mechanisms/Products 
Active Nets Community 
Active Nets 
Ideas 
Active Nets 
Ideas 
Real AN 
Network 
Products 
Internet
Great Active Nets CCoommmmuunniittyy SSoolluuttiioonnss 
• Active networks (AN) approach opens an exciting 
opportunity for individual applications to define the 
service provided by the network through 
programmability. 
• Active Networks technologies expose a novel approach that 
allows customer value-added services to be introduced to the 
network “on-the-fly”. 
• Active Nets program has produced a new network platform 
flexible and extensible at runtime to accommodate the rapid 
evolution and deployment of network technologies. 
• The exciting opportunity exists for network service providers and 
third parties, not just the network device providers, to program 
the network infrastructure and services. 
May 28-29, 2002 4 
DANCE Exposition
Lack of industrial-strength Active Network 
devices that dispel major concerns: 
May 28-29, 2002 5 
DANCE Exposition 
AANN iissssuueess 
• AN requires substantial supports from a NOS 
• AN introduces substantial software component, 
hence delay on the data path 
• AN lacks adequate measures to addressing integrity 
and security of network devices.
May 28-29, 2002 6 
Main contributions of the paper 
• Active Flow Manipulation Concept 
DANCE Exposition 
— Flow abstraction 
— Actions on Flows 
— Control/Data separation 
• Openet Platform 
— Commercial Network Devices 
— Runtime Environment 
— Active Services 
• Applications
May 28-29, 2002 7 
Openet: An active service platform 
User Oplets 
ORE JFWD 
CPU 
JNI/Native Code 
Monitor status 
DANCE Exposition 
JVM 
MEM … 
Filtered packets New forwarding rules 
Forwarding Engine 
OpletService, 
Shell, Logger 
Jcapture, HTTP, 
IpPacket 
Standard Services 
ANTS 
Application services Firewall, DiffServ 
Function Services 
Control Plane 
Data Plane
May 28-29, 2002 8 
Active Flow Manipulation 
DANCE Exposition 
Forwarding 
Processor 
Forwarding 
Processor 
Packet 
Policy 
Filters 
AFM 
Packet 
Filte 
r 
Packet 
Action 
• A key enabling 
technology of 
Openet 
• Two abstractions 
— Primitive flows 
— Primitive actions 
• Customer network 
services exercise 
active network 
control 
— Identifying specific flows 
— Apply actions to alter 
network behavior in real-time
May 28-29, 2002 9 
Openet Alteon Active Nets Platform 
= A Powerful Platform for AN 
Technologies Transfer 
DANCE Exposition 
• A powerful and 
extensible control 
and computational 
plane 
— Partitioning 
hardware/software 
resources 
— Active service enabling 
— Content filtering in real-time 
— Active services 
accommodation 
Optical 
Wireless 
Active 
Services 
router Content 
gateway 
Edge Device 
Content 
Aware 
Computation 
Power 
Dynamic 
Service Enabling
Nortel Networks’ contributions to 
Active Networks 
• Practical Active Networks Architecture on real 
network device. 
• First Commercial Active Networks platform. 
May 28-29, 2002 10 
DANCE Exposition
May 28-29, 2002 11 
Any AN products? 
DANCE Exposition 
Active Nets Community 
Active Nets Community 
Active Nets 
Ideas 
Active Nets 
Ideas 
Realistic 
Mechanisms 
Experimental/Laboratory 
Platforms 
Commercial AN Platform? 
? 
Nortel Networks 
AN Products 
SSSSLL AASSFF IDIDSS VVPPNN
• Client sends an HTTPS request 
• Switch redirects request on port 
443 to iSD-SSL 
• iSD-SSL completes SSL 
handshake 
• iSD-SSL initiates HTTP connection 
to server on port 80 
• Switch selects real server based 
on configured LB policy 
• Server responds to HTTP request 
and replies to the iSD-SSL 
• iSD-SSL encrypts session and 
sends HTTPS response to client 
HTTPS, SMTP-S, POP3-S and IMAP-S services 
May 28-29, 2002 12 
SSL Acceleration 
How Does the iiSSDD--SSSSLL AAcccceelleerraattoorr wwoorrkk?? 
DANCE Exposition
May 28-29, 2002 13 
Client And Server Authentication 
DANCE Exposition 
1 User opens session 
2 Sends server certificate 
Requests client certificate 3 
Serves request/response 
7 
Send encrypted data to back 
6 end 
Validates the client certificate info. 
5 
Private key 
Confidential 
4 
Client sends the certificate with public key 
Public key 
Published
May 28-29, 2002 14 
ASF – Alteon Switched Firewall 
DANCE Exposition
Relate AFS to AN Technology 
• The Alteon selectively redirects new 
connection requests to the Alteon Switched 
Firewall Director to perform policy checking. 
• The Director runs the Check Point FireWall-1 
engine as an Active Service. 
• The Active Service manages the connection 
table, specifies rules for handling packets in 
the session, passes the connection table to the 
Alteon Switched Accelerator. 
• 90% of traffic is accelerated, supporting a 
throughput of 3.2 Gbps. 
May 28-29, 2002 15 
DANCE Exposition
Alteon Security Cluster 
Acceleration and intelligent integration of security applications 
Single point of secure central management 
IDS IDS 
URL 
Filtering 
Virus 
Scan 
Nortel Appliance Acceleration Protocol 
(Enables application control of switch sessions) 
May 28-29, 2002 16 
BBI, CLI, SSI, Plug and Play 
DANCE Exposition 
Application Plane 
Security Appliance 
NAAP 
Control Plane 
Controller of accelerated 
sessions 
Management Plane 
IDS IDS IDS 
Fir Fi Firewall 
SSL SSL SSL 
Security Accelerator 
Data Plane 
Switch based acceleration of 
session data 
Fir Fi VPNs 
SSL SSL
May 28-29, 2002 17 
DANCE Exposition 
What next?
iSD 
iSD 
May 28-29, 2002 18 
Disaster Recovery concept 
OmniNet Control Plane 
DANCE Exposition 
Control 
Mesg 
8600 
8600 
OmniNet 
8600 
10G 
10G 
10G 
iSD 
1G 
1G 
1G 
A B 
C 
D 
X 
Y 
Z 
B2 
B3 
[Linux] 
TL1 
Alteon 
Alteon 
Alteon 
EvaQ8 
OG - 1 
EvaQ8 
OG -2 
EvaQ8 
OG - 3 
1. Normal App flow : Client X -> Server Z 
2. Disaster Strikes at Location Z 
3. EvaQ8 OG 3 sends a signal[RSVP] to 
OG1 
4. OG1 instructs Omnit net to connect B2 
& B3 ; Server Z and Server Y data 
syncd 
5. On successful sync, OG2 instructs 
OmniNet to connect B1->B2. 
6. Service Restored for Client X ->server 
Y 
Disaster Event/ 
Environ. Sensor 
B1 
Control 
Mesg
May 28-29, 2002 19 
What next? Quotes from VIPs 
DANCE Exposition
Service-centric Active Nets Platform 
May 28-29, 2002 20 
What after next? 
DANCE Exposition 
Manage 
Service 
Enabling 
SERVICES 
Control 
Matching 
Impedance 
Intra-Service 
Comm 
Security 
• Service Enabling API 
• Control API 
• Impedance Matching API 
• Security API 
• Management API 
• Intra-service Communications API
May 28-29, 2002 21 
DANCE Exposition 
Summary 
• AN Technologies Transfer => Nortel AN 
Platform 
• New AN platform: Openet + Alteon + iSD 
— Alteon: AN platform advanced content filtering 
— iSD: powerful & extensible computation plane 
• Important Applications 
• Impact of AN on next generation networks
OpenetLab – Nortel Networks: http://www.openetlab.org/ 
May 28-29, 2002 22 
QQ&&AA 
DANCE Exposition
May 28-29, 2002 23 
BBaacckkuupp SSlliiddeess 
DANCE Exposition
May 28-29, 2002 25 
Secure XL & NAAP in Action 
TCP session 
Alteon Switched Firewall (ASF) 
5 
Update 
Conn. 
DANCE Exposition 
1 SYN 
Policy 
Check 
1 
1 
Add 
Conn. 
(F2F) 
1 
2 SYN/ACK 
3 
Update 
Conn. 
6 
4 TCP 3-way handshake complete, data for the session accelerated 
5 FIN-1 
6 FIN-2 
7 ACK 
Update 
Conn. 
Delete 
Conn. 
7 
Clients 
Servers 
3 ACK 
(TCP 3-way 
handshake 
complete)
New Focus on Integrated 
Management and Flow 
Application Clusters 
SSL FW VPN IDS Virus 
• Shift from physical management to logical management 
• Central management of multiple services 
May 28-29, 2002 27 
Intelligent Flow Management 
Security Dashboard 
• Plug and play simplicity and scalability 
DANCE Exposition 
Scanning 
URL 
SSL FW VPN IDS Virus Filtering 
Scanning 
URL 
SSL FW VPN IDS Virus Filtering 
Scanning 
URL 
SSL FW VPN IDS Virus Filtering 
Scanning 
URL 
SSL FW VPN IDS Virus Filtering 
Scanning 
URL 
SSL FW VPN IDS Virus Filtering 
Scanning 
URL 
Filtering

More Related Content

PPT
Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines
PPT
Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines
PDF
Embracing SDN in the Next Gen Network
PDF
Time Sensitive Networks: How changes to standard Ethernet enable convergence ...
PPTX
OpenStack As A Strategy For Future Growth at Cisco
PPT
Mngn2005 wireless security
PDF
Agile network agile world, tayo ashiru, huawei
PPTX
Arista reinventing data center switching
Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines
Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines
Embracing SDN in the Next Gen Network
Time Sensitive Networks: How changes to standard Ethernet enable convergence ...
OpenStack As A Strategy For Future Growth at Cisco
Mngn2005 wireless security
Agile network agile world, tayo ashiru, huawei
Arista reinventing data center switching

What's hot (20)

PDF
Introduction to SDN
PPT
Active Nets Technology Transfer through High-Performance Network Devices
PPTX
TechTalk: Connext DDS 5.2.
PPTX
OpenContrail Silicon Valley Meetup Aug 25 2015
PDF
Industrial Internet of Things: Protocols an Standards
PDF
System integration in offshore supply vessels – how we applied DDS and redefi...
PPTX
443029825 cloud-computing-week8-9-pptx
PDF
The Inside Story: Leveraging the IIC's Industrial Internet Security Framework
PDF
Disaggregated Networking - The Drivers, the Software & The High Availability
PDF
btNOG 5: Network Automation
PDF
Upgrade Your System’s Security - Making the Jump from Connext DDS Professiona...
PDF
Next Steps in the SDN/OpenFlow Network Innovation
PDF
How to Cut $2 Million of Your Safety Cert Costs
PPTX
OpenStack and the Transformation of the Data Center - Lew Tucker
PDF
how to simulate ACI
PDF
How to Design Distributed Robotic Control Systems
PPTX
How APIs are Transforming Cisco Solutions and Catalyzing an Innovation Ecosystem
PPT
Open Programmability
PDF
LF_DPDK17_DPDK on Microsoft Azure
PPTX
The Juniper SDN Landscape
Introduction to SDN
Active Nets Technology Transfer through High-Performance Network Devices
TechTalk: Connext DDS 5.2.
OpenContrail Silicon Valley Meetup Aug 25 2015
Industrial Internet of Things: Protocols an Standards
System integration in offshore supply vessels – how we applied DDS and redefi...
443029825 cloud-computing-week8-9-pptx
The Inside Story: Leveraging the IIC's Industrial Internet Security Framework
Disaggregated Networking - The Drivers, the Software & The High Availability
btNOG 5: Network Automation
Upgrade Your System’s Security - Making the Jump from Connext DDS Professiona...
Next Steps in the SDN/OpenFlow Network Innovation
How to Cut $2 Million of Your Safety Cert Costs
OpenStack and the Transformation of the Data Center - Lew Tucker
how to simulate ACI
How to Design Distributed Robotic Control Systems
How APIs are Transforming Cisco Solutions and Catalyzing an Innovation Ecosystem
Open Programmability
LF_DPDK17_DPDK on Microsoft Azure
The Juniper SDN Landscape
Ad

Similar to Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines (20)

PPT
Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines
PPTX
Research Challenges and Opportunities in the Era of the Internet of Everythin...
PDF
Too soft[ware defined] networks SD-Wan vulnerability assessment
PDF
SDN and NFV: Facts, Extensions, and Carrier Opportunities
PDF
Enabling Active Networks Services on a Gigabit Routing Switch
PPT
Active Network Node in Silicon-Based L3 Gigabit Routing Switch
PPT
Open Networking
PDF
Security Delivery Platform: Best practices
PDF
May The Data Stay with U! Network Data Exfiltration Techniques - Brucon 2017.
PDF
Rise of Network Virtualization
PPT
Open Networking through Programmability
PPSX
Network & security startup
PDF
RESOLVING NETWORK DEFENSE CONFLICTS WITH ZERO TRUST ARCHITECTURES AND OTHER E...
PDF
RESOLVING NETWORK DEFENSE CONFLICTS WITH ZERO TRUST ARCHITECTURES AND OTHER E...
PDF
Taking DataFlow Management to the Edge with Apache NiFi/MiNiFi
PDF
infraxstructure: Piotr Wojciechowski "Secure Data Center"
PPTX
Introduction to SDN: Software Defined Networking
PDF
ICCES_2016_Security Analysis of Software Defined Wireless Network Monitoring ...
PPTX
Introduction to OpenFlow, SDN and NFV
PDF
PLNOG 9: Peter Springl - Next Generation Network Traffic Monitoring and Anoma...
Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines
Research Challenges and Opportunities in the Era of the Internet of Everythin...
Too soft[ware defined] networks SD-Wan vulnerability assessment
SDN and NFV: Facts, Extensions, and Carrier Opportunities
Enabling Active Networks Services on a Gigabit Routing Switch
Active Network Node in Silicon-Based L3 Gigabit Routing Switch
Open Networking
Security Delivery Platform: Best practices
May The Data Stay with U! Network Data Exfiltration Techniques - Brucon 2017.
Rise of Network Virtualization
Open Networking through Programmability
Network & security startup
RESOLVING NETWORK DEFENSE CONFLICTS WITH ZERO TRUST ARCHITECTURES AND OTHER E...
RESOLVING NETWORK DEFENSE CONFLICTS WITH ZERO TRUST ARCHITECTURES AND OTHER E...
Taking DataFlow Management to the Edge with Apache NiFi/MiNiFi
infraxstructure: Piotr Wojciechowski "Secure Data Center"
Introduction to SDN: Software Defined Networking
ICCES_2016_Security Analysis of Software Defined Wireless Network Monitoring ...
Introduction to OpenFlow, SDN and NFV
PLNOG 9: Peter Springl - Next Generation Network Traffic Monitoring and Anoma...
Ad

More from Tal Lavian Ph.D. (20)

PDF
Ultra low phase noise frequency synthesizer
PDF
Ultra low phase noise frequency synthesizer
PDF
Photonic line sharing for high-speed routers
PDF
Systems and methods to support sharing and exchanging in a network
PDF
Systems and methods for visual presentation and selection of IVR menu
PDF
Grid proxy architecture for network resources
PDF
Ultra low phase noise frequency synthesizer
PDF
Systems and methods for electronic communications
PDF
Ultra low phase noise frequency synthesizer
PDF
Ultra low phase noise frequency synthesizer
PDF
Radar target detection system for autonomous vehicles with ultra-low phase no...
PDF
Grid proxy architecture for network resources
PDF
Method and apparatus for scheduling resources on a switched underlay network
PDF
Dynamic assignment of traffic classes to a priority queue in a packet forward...
PDF
Method and apparatus for using a command design pattern to access and configu...
PDF
Reliable rating system and method thereof
PDF
Time variant rating system and method thereof
PDF
Systems and methods for visual presentation and selection of ivr menu
PDF
Ultra low phase noise frequency synthesizer
PDF
Ultra low phase noise frequency synthesizer
Ultra low phase noise frequency synthesizer
Ultra low phase noise frequency synthesizer
Photonic line sharing for high-speed routers
Systems and methods to support sharing and exchanging in a network
Systems and methods for visual presentation and selection of IVR menu
Grid proxy architecture for network resources
Ultra low phase noise frequency synthesizer
Systems and methods for electronic communications
Ultra low phase noise frequency synthesizer
Ultra low phase noise frequency synthesizer
Radar target detection system for autonomous vehicles with ultra-low phase no...
Grid proxy architecture for network resources
Method and apparatus for scheduling resources on a switched underlay network
Dynamic assignment of traffic classes to a priority queue in a packet forward...
Method and apparatus for using a command design pattern to access and configu...
Reliable rating system and method thereof
Time variant rating system and method thereof
Systems and methods for visual presentation and selection of ivr menu
Ultra low phase noise frequency synthesizer
Ultra low phase noise frequency synthesizer

Recently uploaded (20)

PPTX
making presentation that do no stick.pptx
PPTX
Operating System Processes_Scheduler OSS
PPTX
Embeded System for Artificial intelligence 2.pptx
PPTX
Entre CHtzyshshshshshshshzhhzzhhz 4MSt.pptx
PPTX
02fdgfhfhfhghghhhhhhhhhhhhhhhhhhhhh.pptx
PPTX
Fundamentals of Computer.pptx Computer BSC
PPTX
Lecture-3-Computer-programming for BS InfoTech
DOCX
fsdffdghjjgfxfdghjvhjvgfdfcbchghgghgcbjghf
PPTX
了解新西兰毕业证(Wintec毕业证书)怀卡托理工学院毕业证存档可查的
PPTX
Lecture 3b C Library _ ESP32.pptxjfjfjffkkfkfk
DOCX
A PROPOSAL ON IoT climate sensor 2.docx
PPT
Lines and angles cbse class 9 math chemistry
PPTX
PLC ANALOGUE DONE BY KISMEC KULIM TD 5 .0
PPTX
Embedded for Artificial Intelligence 1.pptx
PPTX
quadraticequations-111211090004-phpapp02.pptx
PPTX
ERP good ERP good ERP good ERP good good ERP good ERP good
PPTX
Computers and mobile device: Evaluating options for home and work
PDF
Smarter Security: How Door Access Control Works with Alarms & CCTV
PDF
Prescription1 which to be used for periodo
PPTX
Wireless and Mobile Backhaul Market.pptx
making presentation that do no stick.pptx
Operating System Processes_Scheduler OSS
Embeded System for Artificial intelligence 2.pptx
Entre CHtzyshshshshshshshzhhzzhhz 4MSt.pptx
02fdgfhfhfhghghhhhhhhhhhhhhhhhhhhhh.pptx
Fundamentals of Computer.pptx Computer BSC
Lecture-3-Computer-programming for BS InfoTech
fsdffdghjjgfxfdghjvhjvgfdfcbchghgghgcbjghf
了解新西兰毕业证(Wintec毕业证书)怀卡托理工学院毕业证存档可查的
Lecture 3b C Library _ ESP32.pptxjfjfjffkkfkfk
A PROPOSAL ON IoT climate sensor 2.docx
Lines and angles cbse class 9 math chemistry
PLC ANALOGUE DONE BY KISMEC KULIM TD 5 .0
Embedded for Artificial Intelligence 1.pptx
quadraticequations-111211090004-phpapp02.pptx
ERP good ERP good ERP good ERP good good ERP good ERP good
Computers and mobile device: Evaluating options for home and work
Smarter Security: How Door Access Control Works with Alarms & CCTV
Prescription1 which to be used for periodo
Wireless and Mobile Backhaul Market.pptx

Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines

  • 1. Enabling Active Flow Manipulation In Silicon-based Network Forwarding Engines May 28-29, 2002 1 Tal Lavian - tlavian@ieee.org Nortel Networks Advanced Technology Labs Open Source - http://www.openetlab.org DANCE Exposition
  • 2. • AN technologies => Real Network Devices • Main thrust of the paper • Commercial Active Nets Platform • Application Example 1 – SSL • Application Example 2 – ASF • Next Generation AN Platform • Conclusion May 28-29, 2002 2 Outline of the talk DANCE Exposition
  • 3. May 28-29, 2002 3 AN Technology Transfer DANCE Exposition Active Nets Community Realistic Mechanisms Great Ideas Usable/Realizable Mechanisms/Products Active Nets Community Active Nets Ideas Active Nets Ideas Real AN Network Products Internet
  • 4. Great Active Nets CCoommmmuunniittyy SSoolluuttiioonnss • Active networks (AN) approach opens an exciting opportunity for individual applications to define the service provided by the network through programmability. • Active Networks technologies expose a novel approach that allows customer value-added services to be introduced to the network “on-the-fly”. • Active Nets program has produced a new network platform flexible and extensible at runtime to accommodate the rapid evolution and deployment of network technologies. • The exciting opportunity exists for network service providers and third parties, not just the network device providers, to program the network infrastructure and services. May 28-29, 2002 4 DANCE Exposition
  • 5. Lack of industrial-strength Active Network devices that dispel major concerns: May 28-29, 2002 5 DANCE Exposition AANN iissssuueess • AN requires substantial supports from a NOS • AN introduces substantial software component, hence delay on the data path • AN lacks adequate measures to addressing integrity and security of network devices.
  • 6. May 28-29, 2002 6 Main contributions of the paper • Active Flow Manipulation Concept DANCE Exposition — Flow abstraction — Actions on Flows — Control/Data separation • Openet Platform — Commercial Network Devices — Runtime Environment — Active Services • Applications
  • 7. May 28-29, 2002 7 Openet: An active service platform User Oplets ORE JFWD CPU JNI/Native Code Monitor status DANCE Exposition JVM MEM … Filtered packets New forwarding rules Forwarding Engine OpletService, Shell, Logger Jcapture, HTTP, IpPacket Standard Services ANTS Application services Firewall, DiffServ Function Services Control Plane Data Plane
  • 8. May 28-29, 2002 8 Active Flow Manipulation DANCE Exposition Forwarding Processor Forwarding Processor Packet Policy Filters AFM Packet Filte r Packet Action • A key enabling technology of Openet • Two abstractions — Primitive flows — Primitive actions • Customer network services exercise active network control — Identifying specific flows — Apply actions to alter network behavior in real-time
  • 9. May 28-29, 2002 9 Openet Alteon Active Nets Platform = A Powerful Platform for AN Technologies Transfer DANCE Exposition • A powerful and extensible control and computational plane — Partitioning hardware/software resources — Active service enabling — Content filtering in real-time — Active services accommodation Optical Wireless Active Services router Content gateway Edge Device Content Aware Computation Power Dynamic Service Enabling
  • 10. Nortel Networks’ contributions to Active Networks • Practical Active Networks Architecture on real network device. • First Commercial Active Networks platform. May 28-29, 2002 10 DANCE Exposition
  • 11. May 28-29, 2002 11 Any AN products? DANCE Exposition Active Nets Community Active Nets Community Active Nets Ideas Active Nets Ideas Realistic Mechanisms Experimental/Laboratory Platforms Commercial AN Platform? ? Nortel Networks AN Products SSSSLL AASSFF IDIDSS VVPPNN
  • 12. • Client sends an HTTPS request • Switch redirects request on port 443 to iSD-SSL • iSD-SSL completes SSL handshake • iSD-SSL initiates HTTP connection to server on port 80 • Switch selects real server based on configured LB policy • Server responds to HTTP request and replies to the iSD-SSL • iSD-SSL encrypts session and sends HTTPS response to client HTTPS, SMTP-S, POP3-S and IMAP-S services May 28-29, 2002 12 SSL Acceleration How Does the iiSSDD--SSSSLL AAcccceelleerraattoorr wwoorrkk?? DANCE Exposition
  • 13. May 28-29, 2002 13 Client And Server Authentication DANCE Exposition 1 User opens session 2 Sends server certificate Requests client certificate 3 Serves request/response 7 Send encrypted data to back 6 end Validates the client certificate info. 5 Private key Confidential 4 Client sends the certificate with public key Public key Published
  • 14. May 28-29, 2002 14 ASF – Alteon Switched Firewall DANCE Exposition
  • 15. Relate AFS to AN Technology • The Alteon selectively redirects new connection requests to the Alteon Switched Firewall Director to perform policy checking. • The Director runs the Check Point FireWall-1 engine as an Active Service. • The Active Service manages the connection table, specifies rules for handling packets in the session, passes the connection table to the Alteon Switched Accelerator. • 90% of traffic is accelerated, supporting a throughput of 3.2 Gbps. May 28-29, 2002 15 DANCE Exposition
  • 16. Alteon Security Cluster Acceleration and intelligent integration of security applications Single point of secure central management IDS IDS URL Filtering Virus Scan Nortel Appliance Acceleration Protocol (Enables application control of switch sessions) May 28-29, 2002 16 BBI, CLI, SSI, Plug and Play DANCE Exposition Application Plane Security Appliance NAAP Control Plane Controller of accelerated sessions Management Plane IDS IDS IDS Fir Fi Firewall SSL SSL SSL Security Accelerator Data Plane Switch based acceleration of session data Fir Fi VPNs SSL SSL
  • 17. May 28-29, 2002 17 DANCE Exposition What next?
  • 18. iSD iSD May 28-29, 2002 18 Disaster Recovery concept OmniNet Control Plane DANCE Exposition Control Mesg 8600 8600 OmniNet 8600 10G 10G 10G iSD 1G 1G 1G A B C D X Y Z B2 B3 [Linux] TL1 Alteon Alteon Alteon EvaQ8 OG - 1 EvaQ8 OG -2 EvaQ8 OG - 3 1. Normal App flow : Client X -> Server Z 2. Disaster Strikes at Location Z 3. EvaQ8 OG 3 sends a signal[RSVP] to OG1 4. OG1 instructs Omnit net to connect B2 & B3 ; Server Z and Server Y data syncd 5. On successful sync, OG2 instructs OmniNet to connect B1->B2. 6. Service Restored for Client X ->server Y Disaster Event/ Environ. Sensor B1 Control Mesg
  • 19. May 28-29, 2002 19 What next? Quotes from VIPs DANCE Exposition
  • 20. Service-centric Active Nets Platform May 28-29, 2002 20 What after next? DANCE Exposition Manage Service Enabling SERVICES Control Matching Impedance Intra-Service Comm Security • Service Enabling API • Control API • Impedance Matching API • Security API • Management API • Intra-service Communications API
  • 21. May 28-29, 2002 21 DANCE Exposition Summary • AN Technologies Transfer => Nortel AN Platform • New AN platform: Openet + Alteon + iSD — Alteon: AN platform advanced content filtering — iSD: powerful & extensible computation plane • Important Applications • Impact of AN on next generation networks
  • 22. OpenetLab – Nortel Networks: http://www.openetlab.org/ May 28-29, 2002 22 QQ&&AA DANCE Exposition
  • 23. May 28-29, 2002 23 BBaacckkuupp SSlliiddeess DANCE Exposition
  • 24. May 28-29, 2002 25 Secure XL & NAAP in Action TCP session Alteon Switched Firewall (ASF) 5 Update Conn. DANCE Exposition 1 SYN Policy Check 1 1 Add Conn. (F2F) 1 2 SYN/ACK 3 Update Conn. 6 4 TCP 3-way handshake complete, data for the session accelerated 5 FIN-1 6 FIN-2 7 ACK Update Conn. Delete Conn. 7 Clients Servers 3 ACK (TCP 3-way handshake complete)
  • 25. New Focus on Integrated Management and Flow Application Clusters SSL FW VPN IDS Virus • Shift from physical management to logical management • Central management of multiple services May 28-29, 2002 27 Intelligent Flow Management Security Dashboard • Plug and play simplicity and scalability DANCE Exposition Scanning URL SSL FW VPN IDS Virus Filtering Scanning URL SSL FW VPN IDS Virus Filtering Scanning URL SSL FW VPN IDS Virus Filtering Scanning URL SSL FW VPN IDS Virus Filtering Scanning URL SSL FW VPN IDS Virus Filtering Scanning URL Filtering

Editor's Notes

  • #3: Here is the outline of the talk. First I will identify several driving forces that led us in this direction of programmable networking Next, I review some basic functionality of a routing network element. Then I introduce our idea when we develop the AFM concept I will describe a framework for which AFM can be applied I will also describe several relevant examples using AFM and the platform Finally I conclude with a hint of what we go from here.
  • #4: To us as researchers: to be able to implement several of our new ideas on a real router. For Nortel Networks (if I am not wrong): potential revenue generating direction by inventing and developing advanced technology/ By looking at the Internet from users’ perspective, service providers’ perspective and network providers’ perspective, we have identified several driving forces that steered us in this direction of research: Users want intelligent services Service providers want to differentiate their service by offering new services, time to market, flexibility in managing their services Network Providers want to manage their services efficiently and economically. They want to sell, lease their resources at premium price. They want to sell bandwidth on-demand, etc.
  • #7: Above all we need programmability in network devices for introducing, enabling all kinds of intelligent services. What we need : a framework, a platform independent API.
  • #9: Database of what to be done based on SLA Database of possible filters of interests AFM defines a set of primitive flows and operation to obtain composite flows AFM defines a set of primitive actions Flow and Action can form an algebra in the most general sense. One can actually design machine with this algebra. The main interest is in identifying specific flows and applying actions to alter the behaviour in real-time.
  • #28: Shift from physical management to logical management o        Manage the data based on flows and apply the services depending on the user and flow o        Simplify the configuration significantly o        Essentially separate data plane from control plane to enable effective management Central management of multiple services o        Eliminate multiple points of management o        Scale management to control devices and applications Plug and play simplicity and scalability