SlideShare a Scribd company logo
OPENSTACK GROUP-
BASED POLICY
The Group-based Policy (GBP) abstractions for OpenStack
provide an intent-driven declarative policy model that presents
simplified application-oriented interfaces to the user.
1
Agenda
2
Openstack
Challenges
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Openstack
3
A free open source software platform for cloud
computing mostly deployed as IAAS
Started in 2010
At least two releases every year, current stable
release – Liberty 2015; upcoming is Mitaka April
2016
Thousands of contributors in over 100 countries
Openstack Architecture
4
Openstack Shared Services
SWIFT
CINDE
R
NOVA
GLANC
E
NEUTRO
N
HORIZON
GUI
STORAGE
HYPERVISORS
NETWORK
CLI
REST API
REST API
Users
Users
OPENSTACK DEMO
5
Demo
6
WEB
APP
DB
192.168.1.0/24 192.168.2.0/24 192.168.3.0/24
443
80
22
8080 446
Agenda
7
Openstack
Challenges
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Challenges
8
1
• Separating the Concerns
2
• Networking knowledge
3
• Need to manually maintain and refer virtual
infrastructure information for any deployment
4
• Introduces more complexity with new networking
features such as firewalling, load balancing
Agenda
9
Openstack
Challenges
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Group-Based Policy
10
GBP is available from Openstack Juno release
Developed by a community of engineers from IBM,
Cisco, Big Switch etc.
It was started around Sept 2014
It has the ability to separate the intent of the application
developer from the requirement of the infrastructure
operators
It runs on top of existing Openstack services
Designed to offer policy based abstractions to manage
Openstack infrastructure
Group-Based Policy
11
Openstack Shared Services
SWIFT
CINDE
R
NOVA
GLANC
E
NEUTRO
N
HORIZON
GUI
STORAGE
HYPERVISORS
NETWORK
CLI
REST API
REST API
Users
Users
Group-Based Policy Constructs
12
•Collection of network endpoints with their properties.
•Policy Target Group: Contains members [VMs]
•External Group: Contains the external connectivity defined by External Segment
Groups
•These are reusable rules that define connectivity between members of the group
Policy Rules
•These are collection of Policy rules
Policy Rule Set
•It defines port, protocol and direction
Classifier
•It can be of type ALLOW, REDIRECT (Service chaining)
Actions
Group-Based Policy Design
13
POLICY TARGET
GROUP
SUBNET
LAYER 2
POLICY
POLICY RULE
SET
POLICY RULE
POLICY RULE
POLICY RULE
CLASSIFIER
CLASSIFIER
ACTIONS
ACTIONS
POLICY TAGS
Port: 22
Protocol: TCP
Direction: Bi
ALLOW
GROUP-BASED
POLICY DEMO
14
POLICY
Demo
15 15
192.168.1.0/24 192.168.2.0/24 192.168.3.0/24
APP GROUP DB GROUPWEB GROUP
Agenda
16
Openstack
Challenges
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Overcoming Challenges
17
Non-GBP GBP
Separating the
Concerns
Networking
knowledge
Manually maintain
and refer info
More complexity
with new n/w
features
Separation of
Concerns
No Need to have
networking
knowledge
No Need to
maintain any
information
Complexity
removed with
service chaining
Agenda
18
Openstack
Challenges
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Group-Based Policy Under the
hood19
Neutron
Driver
HORIZON
GUICLI
ML2 Driver
Neutron
ODL
Driver
Vendor Driver
Network Infrastructure
Agenda
20
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Future
Q&A
More Features of Group-Based
Policy21
Service Chaining
NAT Pooling
SERVICE CHAINING
Service Chaining
22
WEB GROUP APP GROUP DB GROUP
CLASSIFIE
R
FIREWALL
LOAD
BALANCER
PORT
80
REDIRECT
Agenda
23
Group-Based Policy
Overcoming challenges
Under the hood
More Features
Future
Q&A
Future Group Based Policy
Experience24
It will become more
easier and more flexible
for vendors to integrate
with Openstack that are
offering policy based
solutions
More focus on
application deployment
and delivery
Integrating SDN based
solution will be easier
Agenda
25
Group-Based Policy
Overcoming challenges
Under the hood
ICF
More Features
Future
Q&A
Q&A
26
THANK YOU!
Shital Patil & Vinod Borole
27

More Related Content

PPTX
Day1 assignment
PPTX
The IANA Stewardship Transition Overview & Background
PPTX
APNIC Update - PacNOG20
PPTX
APNIC Technical Assistance Service, IDNIC OPM 2016
PPTX
Bluetooth 5
PDF
Why OpenDaylight
PDF
PPTX
Bab 2 cookbook reload fahrudin
Day1 assignment
The IANA Stewardship Transition Overview & Background
APNIC Update - PacNOG20
APNIC Technical Assistance Service, IDNIC OPM 2016
Bluetooth 5
Why OpenDaylight
Bab 2 cookbook reload fahrudin

Viewers also liked (20)

PDF
Fashion is fed and stayl is eternal
DOCX
HKES SVP DEGREE COLLEGE, SADASHIVANAGAR, BANGALORE-560080.
PDF
Assignment 3 - Certification in Dispute Management
PDF
SystemsOverview
DOC
Unit 57 terminology becky doyle
PDF
Extensive sampling of basidiomycete genomes demonstrates inadequacy of the wh...
PDF
Vancouver executive briefing seminar by csr training institute
PDF
Kudavi 1.26.2016
PPTX
The four agreements
PDF
Emai m03t11
PPT
Vocabulario animales de granja
PPTX
Vkdt sspipe-software-intro
PDF
Composer Helpdesk
PDF
Chuong 2 rui ro tham hut tai khoa
XLSX
Tabla de materiales y precios de colciencias (1)
PPTX
1041 Sophomores LR Lecture 1
PDF
Modul e book wenni mts-muh 1 bjm
PPTX
RESA Commercial DRAFT
PPT
Electrons and Chemical Bonding Day 1
PPTX
Charles dickens power point pressentation
Fashion is fed and stayl is eternal
HKES SVP DEGREE COLLEGE, SADASHIVANAGAR, BANGALORE-560080.
Assignment 3 - Certification in Dispute Management
SystemsOverview
Unit 57 terminology becky doyle
Extensive sampling of basidiomycete genomes demonstrates inadequacy of the wh...
Vancouver executive briefing seminar by csr training institute
Kudavi 1.26.2016
The four agreements
Emai m03t11
Vocabulario animales de granja
Vkdt sspipe-software-intro
Composer Helpdesk
Chuong 2 rui ro tham hut tai khoa
Tabla de materiales y precios de colciencias (1)
1041 Sophomores LR Lecture 1
Modul e book wenni mts-muh 1 bjm
RESA Commercial DRAFT
Electrons and Chemical Bonding Day 1
Charles dickens power point pressentation
Ad

Similar to Openstack Group-Based Policy (20)

PDF
Group Based Policy: Open Source Policy in OpenDaylight and OpenStack Neutron
PPTX
Group-based Policy For OpenStack Networking
PPTX
Group-based Policy for Networking
PPTX
TFI2014 Session I - State of SDN - Scott Sneddon
PDF
Neutron Networking: Service Groups, Policies and Chains
PPTX
Open stack gbp final sn-4-slideshare
PPTX
Mb openstack-nov2013v7
PDF
Managing infrastructure with Application Policy by Mike Cohen
PDF
Troubleshooting for Intent-based Networking
PPTX
Developing, Deploying, and Consuming L4-7 Network Services in an OpenStack Cloud
PDF
How Enterprises will Benefit from SDN
PDF
Nuage Networks, A Policy Driven Approach to SDN - Interop Tokyo 2014
PDF
You can't make a (Denver) omelette without breaking eggs: Using OpenStack pol...
PDF
HP Helion Webinar #5 - Security Beyond Firewalls
PDF
OpenStack: Security Beyond Firewalls
PDF
Openstack: security beyond firewalls
PDF
ONUG Tutorial: Bridges and Tunnels Drive Through OpenStack Networking
PPTX
Lightweight network-automation-orchestration-framework-v-1-3
PPTX
Some Advanced OpenStack Overview Document
PDF
Ct nyc-philly open stack meetups april 2014 final
Group Based Policy: Open Source Policy in OpenDaylight and OpenStack Neutron
Group-based Policy For OpenStack Networking
Group-based Policy for Networking
TFI2014 Session I - State of SDN - Scott Sneddon
Neutron Networking: Service Groups, Policies and Chains
Open stack gbp final sn-4-slideshare
Mb openstack-nov2013v7
Managing infrastructure with Application Policy by Mike Cohen
Troubleshooting for Intent-based Networking
Developing, Deploying, and Consuming L4-7 Network Services in an OpenStack Cloud
How Enterprises will Benefit from SDN
Nuage Networks, A Policy Driven Approach to SDN - Interop Tokyo 2014
You can't make a (Denver) omelette without breaking eggs: Using OpenStack pol...
HP Helion Webinar #5 - Security Beyond Firewalls
OpenStack: Security Beyond Firewalls
Openstack: security beyond firewalls
ONUG Tutorial: Bridges and Tunnels Drive Through OpenStack Networking
Lightweight network-automation-orchestration-framework-v-1-3
Some Advanced OpenStack Overview Document
Ct nyc-philly open stack meetups april 2014 final
Ad

Recently uploaded (20)

PDF
NewMind AI Monthly Chronicles - July 2025
PPTX
Big Data Technologies - Introduction.pptx
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Machine learning based COVID-19 study performance prediction
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
KodekX | Application Modernization Development
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
A Presentation on Artificial Intelligence
NewMind AI Monthly Chronicles - July 2025
Big Data Technologies - Introduction.pptx
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Machine learning based COVID-19 study performance prediction
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
KodekX | Application Modernization Development
“AI and Expert System Decision Support & Business Intelligence Systems”
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Network Security Unit 5.pdf for BCA BBA.
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
The AUB Centre for AI in Media Proposal.docx
Dropbox Q2 2025 Financial Results & Investor Presentation
NewMind AI Weekly Chronicles - August'25 Week I
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Chapter 3 Spatial Domain Image Processing.pdf
Understanding_Digital_Forensics_Presentation.pptx
A Presentation on Artificial Intelligence

Openstack Group-Based Policy

Editor's Notes

  • #7: Application developers, the real users of the cloud infrastructure, need to think about different layers of the Open Systems Interconnection (OSI) stack as they deploy their applications. So although the detailed network configuration is very natural for a networking team, in many cases it adds unnecessary complexity and confusion for application developers. This complexity only increases as new features such as network services are added to the mix. Application developers just want to describe the network and security requirements of their applications in the simplest terms possible.
  • #9: Application developers, the real users of the cloud infrastructure, need to think about different layers of the Open Systems Interconnection (OSI) stack as they deploy their applications. So although the detailed network configuration is very natural for a networking team, in many cases it adds unnecessary complexity and confusion for application developers. This complexity only increases as new features such as network services are added to the mix. Application developers just want to describe the network and security requirements of their applications in the simplest terms possible.
  • #11: OpenStack Group-based Policy was designed to offer a new set of abstractions to manage OpenStack infrastructure. The solution was designed to separate the intent of the application developer from the requirements of the infrastructure operators to offer a powerful yet simple set of APIs. The solution runs on top of existing OpenStack services in a non-disruptive manner and has been developed by a community of engineers from Big Switch, Cisco, IBM, Juniper, Midokura, Nuage Networks, and One Convergence. GBP is available now on Stack-Forge and is designed to work with the OpenStack Juno release.
  • #13: To address additional network services like firewalling, load balancing; service chaining can be used.
  • #25: Future IaaS environments need to focus on deployment and delivery of applications and services with speed, agility, flexibility, security, and scale rather than just orchestration of infrastructure components