SlideShare a Scribd company logo
Cloud Networking - Leaving
the Physical Behind
Omer Anson
Software Physicist
Dragonflow PTL
Problem description (How we do it)
OpenStack networking is still physical
Still based on
Networks
Routers
Ports
Security groups
Why is that?
Current solution (How Kubernetes does it)
Every pod (Read: Network namespace) has a cluster-public IP
Services (Read: Load-balancer) have a virtual IP
Virtual IPs have names (DNS)
Security done with NetworkPolicy
but it’s beta
not everyone supports it
Lacks Power Of Openstack
Built-in VPN, Firewall, QoS, isolation
What we should do
VMs, or containers, or pods live in groups
Groups have a name
Open communication inside the group
Define which groups can inter-communicate
Networking can support
Firewall
Elastic load-balancing
VPN
What we should do
Elastic Load Balancing
API based access
With VPN!
Firewall
Integration
With Legacy networking
With Heat and Magnum
With SFC
Conclusion
Let’s leave the physical behind
Networking in cloud should say what can connect
Not how to connect
And then it’s also easy to add cool features
And it would probably be easiest to do it in Dragonflow!
Because unsolicited advertisement :)

More Related Content

PPTX
OpenDaylight Netvirt and Neutron - Mike Kolesnik, Josh Hershberg - OpenStack ...
PPTX
Scaling OpenStack Networking Beyond 4000 Nodes with Dragonflow - Eshed Gal-Or...
PPTX
Orchestration Tool Roundup - Arthur Berezin & Trammell Scruggs
PDF
[OpenStack Day in Korea 2015] Track 3-6 - Archiectural Overview of the Open S...
PDF
Tech Talk by Gal Sagie: Kuryr - Connecting containers networking to OpenStack...
PPTX
How Cloud Native VNFs Deployed on OpenStack Will Change the Telecom Industry ...
PPTX
OpenStack Discovery and Networking Assurance - Koren Lev - Meetup
PDF
OpenStack Astara
OpenDaylight Netvirt and Neutron - Mike Kolesnik, Josh Hershberg - OpenStack ...
Scaling OpenStack Networking Beyond 4000 Nodes with Dragonflow - Eshed Gal-Or...
Orchestration Tool Roundup - Arthur Berezin & Trammell Scruggs
[OpenStack Day in Korea 2015] Track 3-6 - Archiectural Overview of the Open S...
Tech Talk by Gal Sagie: Kuryr - Connecting containers networking to OpenStack...
How Cloud Native VNFs Deployed on OpenStack Will Change the Telecom Industry ...
OpenStack Discovery and Networking Assurance - Koren Lev - Meetup
OpenStack Astara

What's hot (20)

PPTX
OpenStack and OpenDaylight Workshop: ONUG Spring 2014
PPTX
OpenStack Neutron behind the Scenes
PPTX
Kuryr-Kubernetes: The perfect match for networking cloud native workloads - I...
PDF
Introduction to MidoNet
PPTX
Navigating OpenStack Networking
PPTX
Network Monitoring and Analytics
PDF
OpenStack and OpenDaylight: An Integrated IaaS for SDN/NFV
PPTX
How OpenStack is Built - Anton Weiss - OpenStack Day Israel 2016
PDF
OpenStack KOREA 정기 세미나_OpenStack meet iNaaS SDN Controller
PPTX
OpenStack and the Transformation of the Data Center - Lew Tucker
PPTX
Can the Open vSwitch (OVS) bottleneck be resolved? - Erez Cohen - OpenStack D...
PPTX
OpenStack Networking and Automation
PDF
[OpenStack Days Korea 2016] An SDN Pioneer's Vision of Networking
PPTX
Introduction to Openstack Network
PPTX
[2015-11월 정기 세미나] Cloud Native Platform - Pivotal
PPTX
Openstack Basic with Neutron
PPTX
Neutron Advanced Services - Akanda - Astara 201 presentation
PDF
Quantum - Virtual networks for Openstack
PDF
Neutron high availability open stack architecture openstack israel event 2015
PDF
Intro to OpenStack Astara (Spring '16)
OpenStack and OpenDaylight Workshop: ONUG Spring 2014
OpenStack Neutron behind the Scenes
Kuryr-Kubernetes: The perfect match for networking cloud native workloads - I...
Introduction to MidoNet
Navigating OpenStack Networking
Network Monitoring and Analytics
OpenStack and OpenDaylight: An Integrated IaaS for SDN/NFV
How OpenStack is Built - Anton Weiss - OpenStack Day Israel 2016
OpenStack KOREA 정기 세미나_OpenStack meet iNaaS SDN Controller
OpenStack and the Transformation of the Data Center - Lew Tucker
Can the Open vSwitch (OVS) bottleneck be resolved? - Erez Cohen - OpenStack D...
OpenStack Networking and Automation
[OpenStack Days Korea 2016] An SDN Pioneer's Vision of Networking
Introduction to Openstack Network
[2015-11월 정기 세미나] Cloud Native Platform - Pivotal
Openstack Basic with Neutron
Neutron Advanced Services - Akanda - Astara 201 presentation
Quantum - Virtual networks for Openstack
Neutron high availability open stack architecture openstack israel event 2015
Intro to OpenStack Astara (Spring '16)
Ad

Similar to Cloud Networking - Leaving the Physical Behind - Omer Anson - OpenStack Day Israel 2017 (20)

PDF
Openflow for Cloud Scalability
PPTX
Operators experience and perspective on SDN with VLANs and L3 Networks
PPTX
1_cloud_network_security_intro.pptx
PDF
Banv meetup 04162014
PDF
Connecting Docker for Cloud IaaS (Speech at CSDN-Oct18
PDF
Banv meetup-contrail
PDF
Software Defined Networks (SDN) na przykładzie rozwiązania OpenContrail.
PPTX
SDN_and_NFV_technologies_in_IoT_Networks
PDF
Private cloud networking_cloudstack_days_austin
PDF
A Novel Use of Openflow and Its Applications in Connecting Docker and Dummify...
PDF
Cloud Network Technology Development & Deployment Trends
PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
PPTX
DEVNET-1150 Under the Hood: Cisco Intercloud Services
PDF
Ct nyc-philly open stack meetups april 2014 final
PDF
Carrier-grade-virtual-platform-use-case
PPTX
Integrating OpenStack to Existing infrastructure
PPTX
SDN & Openflow
PPTX
Dave Chandler Presents SDN at World Wide Technology's TECday - St. Louis
PDF
OVNC 2015-성공적인 Customer Optimized Datacenter 구축 방안
PPTX
Deploying Apache CloudStack from API to UI
Openflow for Cloud Scalability
Operators experience and perspective on SDN with VLANs and L3 Networks
1_cloud_network_security_intro.pptx
Banv meetup 04162014
Connecting Docker for Cloud IaaS (Speech at CSDN-Oct18
Banv meetup-contrail
Software Defined Networks (SDN) na przykładzie rozwiązania OpenContrail.
SDN_and_NFV_technologies_in_IoT_Networks
Private cloud networking_cloudstack_days_austin
A Novel Use of Openflow and Its Applications in Connecting Docker and Dummify...
Cloud Network Technology Development & Deployment Trends
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
DEVNET-1150 Under the Hood: Cisco Intercloud Services
Ct nyc-philly open stack meetups april 2014 final
Carrier-grade-virtual-platform-use-case
Integrating OpenStack to Existing infrastructure
SDN & Openflow
Dave Chandler Presents SDN at World Wide Technology's TECday - St. Louis
OVNC 2015-성공적인 Customer Optimized Datacenter 구축 방안
Deploying Apache CloudStack from API to UI
Ad

More from Cloud Native Day Tel Aviv (20)

PDF
Cloud Native is a Cultural Decision. By Reshef Mann
PDF
Container Runtime Security with Falco, by Néstor Salceda
PDF
Kafka Mirror Tester: Go and Kubernetes Powered Test Suite for Kafka Replicati...
PDF
Running I/O intensive workloads on Kubernetes, by Nati Shalom
PDF
WTF Do We Need a Service Mesh? By Anton Weiss.
PDF
Update Strategies for the Edge, by Kat Cosgrove
PDF
Building a Cloud-Native SaaS Product The Hard Way. By Arthur Berezin
PDF
The Four Questions (Every Monitoring Engineer gets asked), by Leon Adato
PDF
K8s Pod Scheduling - Deep Dive. By Tsahi Duek.
PDF
Cloud Native: The Cattle, the Pets, and the Germs, by Avishai Ish-Shalom
PDF
MySQL Shell: the daily tool for devs and admins. By Vittorio Cioe.
PDF
Cloud native transformation patterns, by Pini Reznik
PPTX
Cloud and Edge: price, performance and privacy considerations in IOT, by Tsvi...
PDF
Two Years, Zero servers: Lessons learned from running a startup 100% on Serve...
PDF
12 Factor Serverless Applications - Mike Morain, AWS - Cloud Native Day Tel A...
PDF
Not my problem! Delegating responsibilities to the infrastructure - Yshay Yaa...
PDF
Brain in the Cloud: Machine Learning on OpenStack & Kubernetes Done Right - E...
PPTX
A stateful application walks into a Kubernetes bar - Arthur Berezin, JovianX ...
PPTX
The story of how KubeMQ was born - Oz Golan, KubeMQ - Cloud Native Day Tel Av...
PPTX
I want it all: go hybrid - Orit Yaron, Outbrain - Cloud Native Day Tel Aviv 2018
Cloud Native is a Cultural Decision. By Reshef Mann
Container Runtime Security with Falco, by Néstor Salceda
Kafka Mirror Tester: Go and Kubernetes Powered Test Suite for Kafka Replicati...
Running I/O intensive workloads on Kubernetes, by Nati Shalom
WTF Do We Need a Service Mesh? By Anton Weiss.
Update Strategies for the Edge, by Kat Cosgrove
Building a Cloud-Native SaaS Product The Hard Way. By Arthur Berezin
The Four Questions (Every Monitoring Engineer gets asked), by Leon Adato
K8s Pod Scheduling - Deep Dive. By Tsahi Duek.
Cloud Native: The Cattle, the Pets, and the Germs, by Avishai Ish-Shalom
MySQL Shell: the daily tool for devs and admins. By Vittorio Cioe.
Cloud native transformation patterns, by Pini Reznik
Cloud and Edge: price, performance and privacy considerations in IOT, by Tsvi...
Two Years, Zero servers: Lessons learned from running a startup 100% on Serve...
12 Factor Serverless Applications - Mike Morain, AWS - Cloud Native Day Tel A...
Not my problem! Delegating responsibilities to the infrastructure - Yshay Yaa...
Brain in the Cloud: Machine Learning on OpenStack & Kubernetes Done Right - E...
A stateful application walks into a Kubernetes bar - Arthur Berezin, JovianX ...
The story of how KubeMQ was born - Oz Golan, KubeMQ - Cloud Native Day Tel Av...
I want it all: go hybrid - Orit Yaron, Outbrain - Cloud Native Day Tel Aviv 2018

Recently uploaded (20)

PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Empathic Computing: Creating Shared Understanding
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Modernizing your data center with Dell and AMD
PDF
Approach and Philosophy of On baking technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
cuic standard and advanced reporting.pdf
PPT
Teaching material agriculture food technology
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
Spectral efficient network and resource selection model in 5G networks
The Rise and Fall of 3GPP – Time for a Sabbatical?
Dropbox Q2 2025 Financial Results & Investor Presentation
“AI and Expert System Decision Support & Business Intelligence Systems”
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Electronic commerce courselecture one. Pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Empathic Computing: Creating Shared Understanding
NewMind AI Monthly Chronicles - July 2025
Review of recent advances in non-invasive hemoglobin estimation
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Modernizing your data center with Dell and AMD
Approach and Philosophy of On baking technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
cuic standard and advanced reporting.pdf
Teaching material agriculture food technology
NewMind AI Weekly Chronicles - August'25 Week I
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx

Cloud Networking - Leaving the Physical Behind - Omer Anson - OpenStack Day Israel 2017

  • 1. Cloud Networking - Leaving the Physical Behind Omer Anson Software Physicist Dragonflow PTL
  • 2. Problem description (How we do it) OpenStack networking is still physical Still based on Networks Routers Ports Security groups Why is that?
  • 3. Current solution (How Kubernetes does it) Every pod (Read: Network namespace) has a cluster-public IP Services (Read: Load-balancer) have a virtual IP Virtual IPs have names (DNS) Security done with NetworkPolicy but it’s beta not everyone supports it Lacks Power Of Openstack Built-in VPN, Firewall, QoS, isolation
  • 4. What we should do VMs, or containers, or pods live in groups Groups have a name Open communication inside the group Define which groups can inter-communicate Networking can support Firewall Elastic load-balancing VPN
  • 5. What we should do Elastic Load Balancing API based access With VPN! Firewall Integration With Legacy networking With Heat and Magnum With SFC
  • 6. Conclusion Let’s leave the physical behind Networking in cloud should say what can connect Not how to connect And then it’s also easy to add cool features And it would probably be easiest to do it in Dragonflow! Because unsolicited advertisement :)