SlideShare a Scribd company logo
CONFIDENTIAL
SDN ≠ NFV
Kurniawan Darmanto
w.darmanto@f5.com
Bandung, March 21st, 2016
© F5 Networks, Inc 2CONFIDENTIAL
SDN versus NFV
SDN
• Separate control plane from data
plane in forwarding elements
• API-driven forwarding rules
in data plane
• Initiated by Enterprise Sector
• Focused on L2-L4 forwarding
NFV
• Porting control & forwarding plane
network functions to COTS HW
• Dynamic provisioning and
orchestration of network functions
• Initiated by Telco / SP Sector
• Focused on entire OSI stack: L2-L7
SDN
Software-Defined Networking
© F5 Networks, Inc 4CONFIDENTIAL
What is SDN?
© F5 Networks, Inc 5CONFIDENTIAL
• Separation of control and forwarding functions
• Centralization of control
• Ability to program the behavior of the network using well-defined interfaces
• Better way to connect and control the explosion of virtual machines in the
data center
What SDN does for me?
© F5 Networks, Inc 6CONFIDENTIAL
Why SDN exists?
Challenges
Configure firewall rules as
required by the application
Configure Network to
insert Firewall
Configure firewall
network parameters
Configure Load Balancer as
required by the application
Configure Load Balancer
Network Parameters
Configure Router to steer traffic
to/from Load Balancer
Service insertion
takes days
Network configuration
is time consuming
and error prone
Difficult to track
configuration on
services
Service Insertion In traditional Networks
Server
vFW
Switch
Router
FW
Router
LB
© F5 Networks, Inc 7CONFIDENTIAL
API
Market drivers:
• OpEx reduction by automation
and centralization
• Rapid new application service
introduction
• Network to provide what
application service needs
• Reduction of Complexity and Cost
for Network Infra
SDN Architecture
Open Networking Foundation / OpenFlow
Source: Software-Defined Network Architecture, ONF White Paper, April 13, 2012
Application layer
Application layer
Control layer
SDN
Control
Software Network Services
API API
Control Data Plane interface (e.g., OpenFlow)
Infrastructure layer
Network Device Network Device Network Device
Network Device Network Device
© F5 Networks, Inc 8CONFIDENTIAL
No. F5 connects to those SDN vendors, such as:
• Cisco ACI
• VMware NSX
• Many more…
F5 approach is focus on application services (L4-L7). It’s called SDAS.
Does F5 have SDN solution?
© F5 Networks, Inc 9CONFIDENTIAL
Control
Plane
Data
Plane
Software-DefinedDataCenter
SDDC Orchestrator
SDN Controller
SDN Applications
LAYER 2-4
Stateless Fabric
Applications
NVGREVXLAN
Service Chaining
Virtual & Overlay Networks
L4-7 Stateful Services ???
OPEN
APIs
Architect / Lines of Business
© F5 Networks, Inc 10CONFIDENTIAL
Applications Rely on Stateful Layer 4-7 Services
Router Switch
LAYER 2-4
STATELESS
SERVICES
LAYER 4-7
STATEFUL
SERVICES
FirewallIdentity and
Access
DDoS
Protection
Global Load
Balancing
Malware
Detection
ADC Application
Security
Local Load
Balancing
Application
Performance
Secure Web
Gateway
VIRTUAL AND OVERLAY NETWORKING
© F5 Networks, Inc 11CONFIDENTIAL
SDN (L1-L3) + SDAS (L4-L7) = SDDC
Control
Plane
Data
Plane
Software-DefinedDataCenter
BIG-IQ
Security™
BIG-IQ
Cloud™
BIG-IQ
Device™
BIG-IQ
(SDAS Controller)
SDDC Orchestrator
SDN Controller
SDN Applications
LAYER 2-4
Stateless Fabric
F5 L4-7 SDAS Stateful Fabric
Applications
NVGREVXLAN
Service Chaining
iApps
OPEN
APIs
Architect / Lines of Business
© F5 Networks, Inc 12CONFIDENTIAL
Use Case: F5 + CISCO APIC/ACI Integration
ACI Fabric Virtual Edition Appliance Chassis
BIG-IQ
Device
Package
Device
Package
F5 Device Package Release
Deployment Model
BIG-IQ Integration with Cisco ACI
1
2
4a
BIG-IQ integration with APIC
1 - BIG-IP expose iApps to BIG-IQ
2 - BIG-IQ create custom device package
3 - Admin import BIG-IQ device package to APIC
4a - APIC sends iApp config to BIG-IQ -> BIG-IP
4b - APIC sends Device config to BIG-IP
BIG-IP integration with APIC
1 - Download device package from F5
2 - Admin import device package to APIC
3 - APIC sends config to BIG-IP directly
downloads.f5.com
3
32
4b
1
F5SynthesisFabric
Device
Package
F5 Configuration
{'state': 1, 'transaction': 0,
'ackedState': 0, 'value': {(5,
'DestinationNetmask',
'Netmask1'): {'state': 1,
'transaction': 0,
'ackedState': 0, 'value':
'255.255.255.255'}, (5,
'DestinationPort', 'port1'):
{'state': 1, 'transaction': 0,
'ackedState': 0, 'value': '80'
BIG-IQ
Device
PackageF5 iApps Config
{'state': 1, 'transaction': 0,
'ackedState': 0, 'value': {(5,
'DestinationNetmask',
'Netmask1'): {'state': 1,
'transaction': 0,
'ackedState': 0, 'value':
'255.255.255.255'}, (5,
'DestinationPort', 'port1'):
{'state': 1, 'transaction': 0,
'ackedState': 0, 'value': '80'
F5 Device Config
{'state': 1, 'transaction': 0,
'ackedState': 0, 'value': {(5,
'DestinationNetmask',
'Netmask1'): {'state': 1,
'transaction': 0,
'ackedState': 0, 'value':
'255.255.255.255'}, (5,
'DestinationPort', 'port1'):
{'state': 1, 'transaction': 0,
'ackedState': 0, 'value': '80'
© F5 Networks, Inc 13CONFIDENTIAL
Use Case: F5 + VMware NSX Integration
NSX
Manager
NSX Management
Generic
Platform
iApps
NSX
Edge
NSX
vSwitch
User
Generic
Platform
Admin
Cloud Management
& Orchestration
Cloud Management
& Orchestration
Application Services
BIG-IP
Platform
Deploying L3–L7 Services
Application
Workloads
BIG-IQ Cloud and BIG-IQ Device
BIG-IP Local Traffic Manager
Simplified Business Models
• Operational agility at the network services
(Application Delivery Networking [ADN]) layer
• Operational agility for application-specific services
for acceleration, availability, and security (a rich
Layer 7 protocol)
• Delivering a consistent consumer experience
without consuming IT resources better spent
on strategic projects
Network Functions Virtualization
NFV
No Functional Value 
© F5 Networks, Inc 15CONFIDENTIAL
What is NFV?
© F5 Networks, Inc 16CONFIDENTIAL
NFV Market Drivers
© F5 Networks, Inc
• 68% consider NFV very important/essential in 2018 – 2020
• 58% of WW SPs are committed to implementing either SDN, NFV or both
82%
Increased
Operational
Efficiency
77%
Implementing NFV
to accelerate
revenue
55%
Realized new services
that were not possible
with current technologies
55%
Scaling services up
or down quickly
AutomationRevenue GenerationNetwork EfficiencyService Agility
Statistics provided by Infonetics Research and Heavy Reading
© F5 Networks, Inc 17CONFIDENTIAL
• Software/Functions will be totally decoupled from Hardware
• Reduce CapEx: allowing network functions to run on off-the-shelf hardware.
• Reduce OpEX: supporting automation and algorithm control through increased
programmability of network elements to make it simple to design, deploy, manage
and scale networks.
• Deliver Agility and Flexibility: helping organizations rapidly deploy new applications,
services and infrastructure to quickly meet their changing requirements.
• Enable Innovation: enabling organizations to create new types of applications,
services and business models.
What Problem NFV tries to Solve?
© F5 Networks, Inc 18CONFIDENTIAL
The Pillars of NFV
More than just virtualizing a network function
Virtualization
• Virtual network functions
(VNFs/VMs)
• Multi-tenancy
• High performance
• Comprehensive
hypervisor support
Abstraction
• Service and network
abstraction
• Configuration templates
• On demand resourcing
Programmability
• Data, control, and
management planes
• Open and production-
deployed APIs
• Developer-friendly
RESTful APIs
• Large dev community and
ecosystem
Orchestration
• Unified multi-vendor,
multi-service ecosystem
• Integration with major
vendors like VMware, HP,
OpenStack, ALU, CISCO
• Policy-driven flows and
steering
SDN + SDAS = SDDC
© F5 Networks, Inc 19CONFIDENTIAL
• ETSI NFV: F5 is a participant, that follows developments and attend meetings.
F5 also have representatives in the IETF meetings that refer to NFV
technologies.
• OPNFV: F5 currently studying membership/contribution options.
• OpenStack: F5 participates with Corporate Sponsor status
• ONF: F5 is a member
• IETF: F5 Working on the definition of SCF with NSH metadata
• Mobile World Congress: F5 participates in NFV demo/POC since 2014
F5 involvement with NFV
© F5 Networks, Inc 20CONFIDENTIAL
• Supports all major Hypervisors (e.g. VMware, KVM, Hyper-V, etc)
• Standard APIs and REST APIs
• Use ETSI NFV, IETF, OpenStack Forum, Open Networking Foundation and other
NFV/SDN standards
• Supports leading orchestration solutions:
• HP NFV Director
• Cisco NSO
• Nokia / ALU Cloudband
• OpenStack
• Puppet
• Many more…
Does F5 ready to be integrated with NFV?
VNF-M
NFV-O
VIM
VNFs
ETSI
VIM
VNFs
NSO
Network Service
Lifecycle Manager
ESC
Virtual Service
Lifecycle Manager
Openstack
Virtualized
Infrastructure Manager
AFM
Firewall
F5
LTM
Load
Balancer
F5
APM
Policy
Manager
F5
Network Service Orchestrator
Fulfillment & Assurance
VNF
Adapter
VNF Manager
(Embedded)
Global Resource
Orchestrator
VIM Adapter
(Openstack)
AFM
Firewall
F5
LTM
Load
Balance
r
F5
APM
Policy
Manager
F5
HP NFV Director
CLOUDBAND
ORCHESTRATOR
(NFV ORCHETSRATOR)
CPAAS LCM
(VNF MANAGER)
Virtualis
ed
Infrastr
ucture
Manag
er(s)
VIM
ALU Cloundband
Management
System
VNF Modeling (TOSCA)
(Device, VNFV &
Infrastructure
Description)
AFM
Firewall
F5
LTM
Load
Balanc
er
F5
APM
Policy
Manager
F5
ALU/Cloudband – F5 Integration HP NFV Director – F5 Integration Cisco NSO – F5 Integration
F5 Networks 2015 PROPRIETARY & CONFIDENTIAL
Adding F5 to the NFV Partner Architecture
© F5 Networks, Inc 22CONFIDENTIAL
• Deployment Guide
• https://support.f5.com/kb/en-us/products/big-iq-cloud/manuals/product/bigiq-
lbaas-openstack-plugin-setup-4-4-0.html
• Version Compatibility
• OpenStack: Grizzly/Havana
• BIG-IP VE: 11.3+ in OpenStack
• BIG-IQ Cloud: 4.4.0,4.5.0
• Features
• You need to provision BIG-IP VE
on OpenStack Environment
• Uses new iControl REST API
F5 Integration with OpenStack (Official Ed.)
© F5 Networks, Inc 23CONFIDENTIAL
F5 Service Aligns with “NFV” Approach
Os-Ma
Se-MaService, VNF, and
Infrastructure Description
NFV Management
and Orchestration
VirtualComputing
Hardware
VirtualStorage
Hardware
Virtual Network
Hardware
Ve-Vnfm
Vn-Nf
Nf-Vi
Or-Vi
Virtual
Infrastructure
Manager
NFVI
Virtualization Layer
Computing
Hardware
Storage
Hardware
Network
Hardware
OSS/BSS
Or-Vnfm
BIG-IP Virtual Edition
BIG-IQ
BIG-IQ
© F5 Networks, Inc 24CONFIDENTIAL
Use Cases: Being Deployed by Service Providers
© F5 Networks, Inc
81%
77%
68%
64%
55%
0% 10% 20% 30% 40% 50% 60% 70% 80% 90%
SERVICE
CHAINING
VIRTUAL IMS
VIRTUAL EPC
VIRTUAL CPE
VIRTUAL GI-LAN
Top NFV Use Cases
Statistics provided by Infonetics
© F5 Networks, Inc 25CONFIDENTIAL
Key Benefits:
• Self-Provisioned by Enterprise customers in need of services to support Enterprise IT
• Purchase Network services that are easy to provision, scale, and rapidly deploy
Deploy Virtual Firewall / Create
Business Rules
to allow only DNS
traffic to pass
vFW
Deploy Virtual Load Balancer &
update with Virtual Pool
Members
vLB
Deploy Virtual DNS pools
vDNS
WAN
Scalable
DNSaaS
Auto Deploy  Heal
Fully Automated
Deploy  Heal  Scale
Out  Scale In
LBaaSFWaaS
Management &
Network
Orchestration
Case Study: Orchestrated Scaled DNS Service Use Case
SDN + NFV
© F5 Networks, Inc 27CONFIDENTIAL
Today
© F5 Networks, Inc 28CONFIDENTIAL
NFV
© F5 Networks, Inc 29CONFIDENTIAL
NFV & SDN
© F5 Networks, Inc 30CONFIDENTIAL
F5 Well Positioned for NFV & SDN
• ADC Market Leader
• Accelerated Insertion of SP Security
• PEM gaining traction
• Big VE throughput  Higher Scalability
• Well Placed for Hybrid Networks
• New Licensing/Business Models
RICH PRODUCT PORTFOLIO
• BIG-IQ Enhancements
• Openstack plugin support
• Customizable plugins for 3rd party
MANAGEMENT & ORCHESTRATION
• ALU/Cloudband – ecosystem partner
• Cisco – APIC/ACI & NSO POCs
• HP – active collaboration
• Openstack – significant progress
• VMware – active collaboration
ESTABLISHED/GROWING ALLIANCES
• ALU/Nuage Integration
• Cisco ACI/APIC Integration
• SDAS Positioning gaining traction
• Strong SDDC portfolio
• VMware Integration
STRONG SDN STORY
© F5 Networks, Inc 31CONFIDENTIAL
Good to watch 
https://www.youtube.com/watch?v=P4EjobItPp0
© F5 Networks, Inc 32CONFIDENTIAL
SDN and NFV will help to…
© F5 Networks, Inc 33CONFIDENTIAL
Visit F5 Community to get more details!
F5 perspective of nfv+sdn (SDN NFV Day ITB 2016)

More Related Content

PDF
F5 Networks - - OpenStack Summit 2016/Red Hat NFV Mini Summit
PDF
Brocade Software Networking (SDN NFV Day ITB 2016)
PDF
SDN/NFV Industry analysis
PDF
APAC Webinar: Learn how to maximise the benefits of NFV
PDF
Juniper Unified SDN Technical Presentation (SDN Day ITB 2016)
PPTX
SDN & NFV: Driving Additional Value into Managed Services
PDF
Networking Technology Transformation to SDN and NFV
PDF
How to Implement SDN Technology in ITB
F5 Networks - - OpenStack Summit 2016/Red Hat NFV Mini Summit
Brocade Software Networking (SDN NFV Day ITB 2016)
SDN/NFV Industry analysis
APAC Webinar: Learn how to maximise the benefits of NFV
Juniper Unified SDN Technical Presentation (SDN Day ITB 2016)
SDN & NFV: Driving Additional Value into Managed Services
Networking Technology Transformation to SDN and NFV
How to Implement SDN Technology in ITB

What's hot (20)

PDF
Sdn nfv-day-2016
PPTX
SDN & NFV Orchestration
PPTX
Ons 2013-nv
PDF
OVNC 2015-THE NEW IP - Open Networking Architecture with SDN & NFV
PDF
Introduction to SDN and Network Programmability - BRKRST-1014 | 2017/Las Vegas
PDF
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
PDF
The Cloudification of the Data Center Network
PDF
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
PDF
PLNOG14: The benefits of "OPEN" in networking for operators - Joerg Ammon, Br...
PPTX
Introduction to SDN and NFV
PPTX
Software-Defined Networking(SDN):A New Approach to Networking
PDF
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
PDF
vCloud NFV - Accelerating deployment of the Telco Cloud (SDN NFV Day ITB 2016)
PDF
9th SDN Expert Group Seminar - Session3
PDF
Building the SD-Branch using uCPE
PPTX
7 - Introduction to OpenStack & SDN by Ady Saputra
PDF
9th SDN Expert Group Seminar - Session1
PDF
CisCon 2018 - Overlay Management Protocol e IPsec
PPT
IBM Software Defined Networking for Virtual Environments (IBM SDN VE)
PDF
Security and Virtualization in the Data Center
Sdn nfv-day-2016
SDN & NFV Orchestration
Ons 2013-nv
OVNC 2015-THE NEW IP - Open Networking Architecture with SDN & NFV
Introduction to SDN and Network Programmability - BRKRST-1014 | 2017/Las Vegas
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
The Cloudification of the Data Center Network
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
PLNOG14: The benefits of "OPEN" in networking for operators - Joerg Ammon, Br...
Introduction to SDN and NFV
Software-Defined Networking(SDN):A New Approach to Networking
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
vCloud NFV - Accelerating deployment of the Telco Cloud (SDN NFV Day ITB 2016)
9th SDN Expert Group Seminar - Session3
Building the SD-Branch using uCPE
7 - Introduction to OpenStack & SDN by Ady Saputra
9th SDN Expert Group Seminar - Session1
CisCon 2018 - Overlay Management Protocol e IPsec
IBM Software Defined Networking for Virtual Environments (IBM SDN VE)
Security and Virtualization in the Data Center
Ad

Similar to F5 perspective of nfv+sdn (SDN NFV Day ITB 2016) (20)

PPTX
How to use SDN to Innovate, Expand and Deliver for your business
PPTX
Integrated SDN/NFV Framework for Transitioning to Application Delivery Model
PPTX
SDN and NFV Friends or Enemies ?
PPTX
Know about SDN and NFV
PPTX
SDN and NFV: Friends or Enemies
PPTX
SDN and NFV Value in Business Services - A Presentation By Cox Communications
PDF
Why Network Functions Virtualization sdn?
PPTX
443029825 cloud-computing-week8-9-pptx
PPTX
SDN and NFV Value in Business Services
PPTX
2017 dagstuhl-nfv-rothenberg
PPTX
WAN Summit NYC: SDN, SD-WAN, NFV - I'm Confused!
PPTX
SDN NFV PERIYAR MANIAMMAI UNIVERSITY software defined networks and network fu...
PDF
How can SDN and NFV Improve Your Business_ - Techwave.pdf
PDF
How will virtual networks, controlled by software, impact OSS systems?
PPTX
Research Challenges and Opportunities in the Era of the Internet of Everythin...
PPTX
Dynamic Software Defined Network Infrastructure Test Bed at Marist College
PDF
Ch 01 --- introduction to sdn-nfv
PDF
SDN and NFV: Facts, Extensions, and Carrier Opportunities
PPTX
10. Lec X- SDN.pptx
PPTX
bruce-sdn.pptx
How to use SDN to Innovate, Expand and Deliver for your business
Integrated SDN/NFV Framework for Transitioning to Application Delivery Model
SDN and NFV Friends or Enemies ?
Know about SDN and NFV
SDN and NFV: Friends or Enemies
SDN and NFV Value in Business Services - A Presentation By Cox Communications
Why Network Functions Virtualization sdn?
443029825 cloud-computing-week8-9-pptx
SDN and NFV Value in Business Services
2017 dagstuhl-nfv-rothenberg
WAN Summit NYC: SDN, SD-WAN, NFV - I'm Confused!
SDN NFV PERIYAR MANIAMMAI UNIVERSITY software defined networks and network fu...
How can SDN and NFV Improve Your Business_ - Techwave.pdf
How will virtual networks, controlled by software, impact OSS systems?
Research Challenges and Opportunities in the Era of the Internet of Everythin...
Dynamic Software Defined Network Infrastructure Test Bed at Marist College
Ch 01 --- introduction to sdn-nfv
SDN and NFV: Facts, Extensions, and Carrier Opportunities
10. Lec X- SDN.pptx
bruce-sdn.pptx
Ad

More from SDNRG ITB (8)

PDF
SDN & NFV Introduction (SDN NFV Day ITB 2016)
PDF
Network Function Virtualization - Telkomsel Perspective (SDN NFV Day ITB 2016)
PDF
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
PDF
1 - SDNRG ITB, 10 minutes intro by Affan Basalamah
PPTX
4 - OpenFlow Intro & Testbed by Pories Ediansyah
PPTX
5 - SDN Mininet experiments by Bagus Aditya & Hamzah Mustakim
PPT
3 - Introducing NFV by Adrie Taniwidjaja
PPTX
6 - Custom Mininet Topology Experiment by Dwina Fitriyandini Siswanto & Siti ...
SDN & NFV Introduction (SDN NFV Day ITB 2016)
Network Function Virtualization - Telkomsel Perspective (SDN NFV Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
1 - SDNRG ITB, 10 minutes intro by Affan Basalamah
4 - OpenFlow Intro & Testbed by Pories Ediansyah
5 - SDN Mininet experiments by Bagus Aditya & Hamzah Mustakim
3 - Introducing NFV by Adrie Taniwidjaja
6 - Custom Mininet Topology Experiment by Dwina Fitriyandini Siswanto & Siti ...

Recently uploaded (20)

PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Empathic Computing: Creating Shared Understanding
PPTX
A Presentation on Artificial Intelligence
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Dropbox Q2 2025 Financial Results & Investor Presentation
“AI and Expert System Decision Support & Business Intelligence Systems”
NewMind AI Weekly Chronicles - August'25 Week I
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Review of recent advances in non-invasive hemoglobin estimation
Empathic Computing: Creating Shared Understanding
A Presentation on Artificial Intelligence
Per capita expenditure prediction using model stacking based on satellite ima...
Encapsulation_ Review paper, used for researhc scholars
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Digital-Transformation-Roadmap-for-Companies.pptx
Network Security Unit 5.pdf for BCA BBA.
The AUB Centre for AI in Media Proposal.docx
Spectral efficient network and resource selection model in 5G networks
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Mobile App Security Testing_ A Comprehensive Guide.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025

F5 perspective of nfv+sdn (SDN NFV Day ITB 2016)

  • 1. CONFIDENTIAL SDN ≠ NFV Kurniawan Darmanto w.darmanto@f5.com Bandung, March 21st, 2016
  • 2. © F5 Networks, Inc 2CONFIDENTIAL SDN versus NFV SDN • Separate control plane from data plane in forwarding elements • API-driven forwarding rules in data plane • Initiated by Enterprise Sector • Focused on L2-L4 forwarding NFV • Porting control & forwarding plane network functions to COTS HW • Dynamic provisioning and orchestration of network functions • Initiated by Telco / SP Sector • Focused on entire OSI stack: L2-L7
  • 4. © F5 Networks, Inc 4CONFIDENTIAL What is SDN?
  • 5. © F5 Networks, Inc 5CONFIDENTIAL • Separation of control and forwarding functions • Centralization of control • Ability to program the behavior of the network using well-defined interfaces • Better way to connect and control the explosion of virtual machines in the data center What SDN does for me?
  • 6. © F5 Networks, Inc 6CONFIDENTIAL Why SDN exists? Challenges Configure firewall rules as required by the application Configure Network to insert Firewall Configure firewall network parameters Configure Load Balancer as required by the application Configure Load Balancer Network Parameters Configure Router to steer traffic to/from Load Balancer Service insertion takes days Network configuration is time consuming and error prone Difficult to track configuration on services Service Insertion In traditional Networks Server vFW Switch Router FW Router LB
  • 7. © F5 Networks, Inc 7CONFIDENTIAL API Market drivers: • OpEx reduction by automation and centralization • Rapid new application service introduction • Network to provide what application service needs • Reduction of Complexity and Cost for Network Infra SDN Architecture Open Networking Foundation / OpenFlow Source: Software-Defined Network Architecture, ONF White Paper, April 13, 2012 Application layer Application layer Control layer SDN Control Software Network Services API API Control Data Plane interface (e.g., OpenFlow) Infrastructure layer Network Device Network Device Network Device Network Device Network Device
  • 8. © F5 Networks, Inc 8CONFIDENTIAL No. F5 connects to those SDN vendors, such as: • Cisco ACI • VMware NSX • Many more… F5 approach is focus on application services (L4-L7). It’s called SDAS. Does F5 have SDN solution?
  • 9. © F5 Networks, Inc 9CONFIDENTIAL Control Plane Data Plane Software-DefinedDataCenter SDDC Orchestrator SDN Controller SDN Applications LAYER 2-4 Stateless Fabric Applications NVGREVXLAN Service Chaining Virtual & Overlay Networks L4-7 Stateful Services ??? OPEN APIs Architect / Lines of Business
  • 10. © F5 Networks, Inc 10CONFIDENTIAL Applications Rely on Stateful Layer 4-7 Services Router Switch LAYER 2-4 STATELESS SERVICES LAYER 4-7 STATEFUL SERVICES FirewallIdentity and Access DDoS Protection Global Load Balancing Malware Detection ADC Application Security Local Load Balancing Application Performance Secure Web Gateway VIRTUAL AND OVERLAY NETWORKING
  • 11. © F5 Networks, Inc 11CONFIDENTIAL SDN (L1-L3) + SDAS (L4-L7) = SDDC Control Plane Data Plane Software-DefinedDataCenter BIG-IQ Security™ BIG-IQ Cloud™ BIG-IQ Device™ BIG-IQ (SDAS Controller) SDDC Orchestrator SDN Controller SDN Applications LAYER 2-4 Stateless Fabric F5 L4-7 SDAS Stateful Fabric Applications NVGREVXLAN Service Chaining iApps OPEN APIs Architect / Lines of Business
  • 12. © F5 Networks, Inc 12CONFIDENTIAL Use Case: F5 + CISCO APIC/ACI Integration ACI Fabric Virtual Edition Appliance Chassis BIG-IQ Device Package Device Package F5 Device Package Release Deployment Model BIG-IQ Integration with Cisco ACI 1 2 4a BIG-IQ integration with APIC 1 - BIG-IP expose iApps to BIG-IQ 2 - BIG-IQ create custom device package 3 - Admin import BIG-IQ device package to APIC 4a - APIC sends iApp config to BIG-IQ -> BIG-IP 4b - APIC sends Device config to BIG-IP BIG-IP integration with APIC 1 - Download device package from F5 2 - Admin import device package to APIC 3 - APIC sends config to BIG-IP directly downloads.f5.com 3 32 4b 1 F5SynthesisFabric Device Package F5 Configuration {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': {(5, 'DestinationNetmask', 'Netmask1'): {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': '255.255.255.255'}, (5, 'DestinationPort', 'port1'): {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': '80' BIG-IQ Device PackageF5 iApps Config {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': {(5, 'DestinationNetmask', 'Netmask1'): {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': '255.255.255.255'}, (5, 'DestinationPort', 'port1'): {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': '80' F5 Device Config {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': {(5, 'DestinationNetmask', 'Netmask1'): {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': '255.255.255.255'}, (5, 'DestinationPort', 'port1'): {'state': 1, 'transaction': 0, 'ackedState': 0, 'value': '80'
  • 13. © F5 Networks, Inc 13CONFIDENTIAL Use Case: F5 + VMware NSX Integration NSX Manager NSX Management Generic Platform iApps NSX Edge NSX vSwitch User Generic Platform Admin Cloud Management & Orchestration Cloud Management & Orchestration Application Services BIG-IP Platform Deploying L3–L7 Services Application Workloads BIG-IQ Cloud and BIG-IQ Device BIG-IP Local Traffic Manager Simplified Business Models • Operational agility at the network services (Application Delivery Networking [ADN]) layer • Operational agility for application-specific services for acceleration, availability, and security (a rich Layer 7 protocol) • Delivering a consistent consumer experience without consuming IT resources better spent on strategic projects
  • 15. © F5 Networks, Inc 15CONFIDENTIAL What is NFV?
  • 16. © F5 Networks, Inc 16CONFIDENTIAL NFV Market Drivers © F5 Networks, Inc • 68% consider NFV very important/essential in 2018 – 2020 • 58% of WW SPs are committed to implementing either SDN, NFV or both 82% Increased Operational Efficiency 77% Implementing NFV to accelerate revenue 55% Realized new services that were not possible with current technologies 55% Scaling services up or down quickly AutomationRevenue GenerationNetwork EfficiencyService Agility Statistics provided by Infonetics Research and Heavy Reading
  • 17. © F5 Networks, Inc 17CONFIDENTIAL • Software/Functions will be totally decoupled from Hardware • Reduce CapEx: allowing network functions to run on off-the-shelf hardware. • Reduce OpEX: supporting automation and algorithm control through increased programmability of network elements to make it simple to design, deploy, manage and scale networks. • Deliver Agility and Flexibility: helping organizations rapidly deploy new applications, services and infrastructure to quickly meet their changing requirements. • Enable Innovation: enabling organizations to create new types of applications, services and business models. What Problem NFV tries to Solve?
  • 18. © F5 Networks, Inc 18CONFIDENTIAL The Pillars of NFV More than just virtualizing a network function Virtualization • Virtual network functions (VNFs/VMs) • Multi-tenancy • High performance • Comprehensive hypervisor support Abstraction • Service and network abstraction • Configuration templates • On demand resourcing Programmability • Data, control, and management planes • Open and production- deployed APIs • Developer-friendly RESTful APIs • Large dev community and ecosystem Orchestration • Unified multi-vendor, multi-service ecosystem • Integration with major vendors like VMware, HP, OpenStack, ALU, CISCO • Policy-driven flows and steering SDN + SDAS = SDDC
  • 19. © F5 Networks, Inc 19CONFIDENTIAL • ETSI NFV: F5 is a participant, that follows developments and attend meetings. F5 also have representatives in the IETF meetings that refer to NFV technologies. • OPNFV: F5 currently studying membership/contribution options. • OpenStack: F5 participates with Corporate Sponsor status • ONF: F5 is a member • IETF: F5 Working on the definition of SCF with NSH metadata • Mobile World Congress: F5 participates in NFV demo/POC since 2014 F5 involvement with NFV
  • 20. © F5 Networks, Inc 20CONFIDENTIAL • Supports all major Hypervisors (e.g. VMware, KVM, Hyper-V, etc) • Standard APIs and REST APIs • Use ETSI NFV, IETF, OpenStack Forum, Open Networking Foundation and other NFV/SDN standards • Supports leading orchestration solutions: • HP NFV Director • Cisco NSO • Nokia / ALU Cloudband • OpenStack • Puppet • Many more… Does F5 ready to be integrated with NFV?
  • 21. VNF-M NFV-O VIM VNFs ETSI VIM VNFs NSO Network Service Lifecycle Manager ESC Virtual Service Lifecycle Manager Openstack Virtualized Infrastructure Manager AFM Firewall F5 LTM Load Balancer F5 APM Policy Manager F5 Network Service Orchestrator Fulfillment & Assurance VNF Adapter VNF Manager (Embedded) Global Resource Orchestrator VIM Adapter (Openstack) AFM Firewall F5 LTM Load Balance r F5 APM Policy Manager F5 HP NFV Director CLOUDBAND ORCHESTRATOR (NFV ORCHETSRATOR) CPAAS LCM (VNF MANAGER) Virtualis ed Infrastr ucture Manag er(s) VIM ALU Cloundband Management System VNF Modeling (TOSCA) (Device, VNFV & Infrastructure Description) AFM Firewall F5 LTM Load Balanc er F5 APM Policy Manager F5 ALU/Cloudband – F5 Integration HP NFV Director – F5 Integration Cisco NSO – F5 Integration F5 Networks 2015 PROPRIETARY & CONFIDENTIAL Adding F5 to the NFV Partner Architecture
  • 22. © F5 Networks, Inc 22CONFIDENTIAL • Deployment Guide • https://support.f5.com/kb/en-us/products/big-iq-cloud/manuals/product/bigiq- lbaas-openstack-plugin-setup-4-4-0.html • Version Compatibility • OpenStack: Grizzly/Havana • BIG-IP VE: 11.3+ in OpenStack • BIG-IQ Cloud: 4.4.0,4.5.0 • Features • You need to provision BIG-IP VE on OpenStack Environment • Uses new iControl REST API F5 Integration with OpenStack (Official Ed.)
  • 23. © F5 Networks, Inc 23CONFIDENTIAL F5 Service Aligns with “NFV” Approach Os-Ma Se-MaService, VNF, and Infrastructure Description NFV Management and Orchestration VirtualComputing Hardware VirtualStorage Hardware Virtual Network Hardware Ve-Vnfm Vn-Nf Nf-Vi Or-Vi Virtual Infrastructure Manager NFVI Virtualization Layer Computing Hardware Storage Hardware Network Hardware OSS/BSS Or-Vnfm BIG-IP Virtual Edition BIG-IQ BIG-IQ
  • 24. © F5 Networks, Inc 24CONFIDENTIAL Use Cases: Being Deployed by Service Providers © F5 Networks, Inc 81% 77% 68% 64% 55% 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% SERVICE CHAINING VIRTUAL IMS VIRTUAL EPC VIRTUAL CPE VIRTUAL GI-LAN Top NFV Use Cases Statistics provided by Infonetics
  • 25. © F5 Networks, Inc 25CONFIDENTIAL Key Benefits: • Self-Provisioned by Enterprise customers in need of services to support Enterprise IT • Purchase Network services that are easy to provision, scale, and rapidly deploy Deploy Virtual Firewall / Create Business Rules to allow only DNS traffic to pass vFW Deploy Virtual Load Balancer & update with Virtual Pool Members vLB Deploy Virtual DNS pools vDNS WAN Scalable DNSaaS Auto Deploy Heal Fully Automated Deploy Heal Scale Out Scale In LBaaSFWaaS Management & Network Orchestration Case Study: Orchestrated Scaled DNS Service Use Case
  • 27. © F5 Networks, Inc 27CONFIDENTIAL Today
  • 28. © F5 Networks, Inc 28CONFIDENTIAL NFV
  • 29. © F5 Networks, Inc 29CONFIDENTIAL NFV & SDN
  • 30. © F5 Networks, Inc 30CONFIDENTIAL F5 Well Positioned for NFV & SDN • ADC Market Leader • Accelerated Insertion of SP Security • PEM gaining traction • Big VE throughput  Higher Scalability • Well Placed for Hybrid Networks • New Licensing/Business Models RICH PRODUCT PORTFOLIO • BIG-IQ Enhancements • Openstack plugin support • Customizable plugins for 3rd party MANAGEMENT & ORCHESTRATION • ALU/Cloudband – ecosystem partner • Cisco – APIC/ACI & NSO POCs • HP – active collaboration • Openstack – significant progress • VMware – active collaboration ESTABLISHED/GROWING ALLIANCES • ALU/Nuage Integration • Cisco ACI/APIC Integration • SDAS Positioning gaining traction • Strong SDDC portfolio • VMware Integration STRONG SDN STORY
  • 31. © F5 Networks, Inc 31CONFIDENTIAL Good to watch  https://www.youtube.com/watch?v=P4EjobItPp0
  • 32. © F5 Networks, Inc 32CONFIDENTIAL SDN and NFV will help to…
  • 33. © F5 Networks, Inc 33CONFIDENTIAL Visit F5 Community to get more details!