SlideShare a Scribd company logo
Operator's experience and perspective
on SDN with VLANs and L3 Networks
@tcpcloud
OpenStack Summit Austin 2016
Presentation Agenda
• About tcp cloud & workday
• OpenStack Networking/SDN
• SDN key criteria for enterprises
• SDN operation Use Cases
• Comparison of SDN
About tcp cloud
❖ Active in global community (OpenStack, OpenContrail, SaltStack, etc…)
❖ Partnership (Canonical, Juniper, Arrow ECS, etc…)
❖ Own Hi-Tech Datacenter (TIER III, 20kW per rack, hundreds 10Gbps ports, etc…)
❖ Focused on private open cloud solutions and services (since 2011)
❖ References (AVG Technologies, Czech Railways, Mall.cz, 100%IT)
❖ Two directions:
➢ Enterprise Private Cloud solutions (OpenStack, Kubernetes)
➢ IoT (SmartCity projects)
About Workday
● On-demand (cloud-based) financial
management and human capital management
software vendor.
● Juniper Contrail
● L3 fabric network
• All clouds are about networking
• Key and the most controversial component of
OpenStack
• High Availability, Scalability, Migration, Multi-tenancy,
Performance, Security
• LBaaS, FWaaS, VPNaaS, Service Chainning
• Multiple solutions
• 30+ plugin drivers
• It is almost impossible to choose right way
OpenStack Networking/SDN
Multiple Openstack Neutron SDN
• Provide secure multi-tenancy using strong network isolation
• Policy driven network access control within (and across)
projects/domains
• Support software driven network functions
• LBaaS, DNSaaS, etc.
• Interconnect OpenStack with bare metal storage/analytics
services
• Provide an ability for product engineering teams to define a
network topology via REST APIs
• Associate network objects dynamically with VMs, Projects
• Create and manage network access control policies within
and across projects
• Enable easier integration of applications on partner
infrastructure
General SDN Objectives
First step = Overlay or not Overlay
Cloud native way
• Cloud native apps
• No overlapping (callico
can)
• No IP failover
• No Live Migration
• No L2 between VMs
• Suitable for containers
VLANs
• 4k limit
• No failure isolation
domain
• Spanning many ToRs
• Physical device
configuration
Overlay
• Simple physical
network
• L3 between ToRs
• Controllers
orchestrate tunnel
mesh for VM
• Overlapping, NFV, VNF
First step = Overlay or not Overlay
Cloud native way
• Cloud native apps
• No overlapping (callico
can)
• No IP failover
• No Live Migration
• No L2 between VMs
• Suitable for containers
VLANs
• 4k limit
• No failure isolation
domain
• Spanning many ToRs
• Physical device
configuration
Overlay
• Simple physical
network
• L3 between ToRs
• Controllers
orchestrate tunnel
mesh for VM
• Overlapping, NFV, VNF
Legacy - not
suitable for
cloud
Future - cloud
native
applications
• NFV & VNF - LBaaS, VPNaaS
• Direct traffic datapath - East-West & North-South
• North-South - must be routed on physical routers
• Multiple external networks
• Performance & Scaling
• Bare metal connection (non virtualized servers)
SDN key criterias for enterprise
• Open source
• L3VPN, EVPN capabilities
• Multi cloud solution - Kubernetes, KVM, other
hypervisors
• Integration of physical LbaaS
• IPv6 support
• Intel DPDK, SR-IOV
SDN optionals for service providers
• Linux bridge, OVS
• External network in
port to each
compute
• L2 underlay only
• No analytics
• Too complex
Neutron DVR Complexity
• L3/L2 compatible
• open source
• no too complex
OpenContrail
• No network node
• No proprietary gateway node
(appliances)
• MPLSoverGRE or VXLAN termination in
Network devices
• L3VPN, EVPN, OVS-DB
Direct datapath North-South, East-West
• depends on encapsulation
• depends on NIC offloading
• 4 % payload overhead
• 9.6 Gbits/s North-South, East-West with MPLSoverGRE
• 5.2 Gbits/s with OVS VXLAN
Data Plane Performance
Multi Cloud networking
Multi Cloud networking
Bare metal integration
Physical LbaaS integration
IPv6 Integration
Openstack Cluster Deployment - sample logical
Openstack Cluster Deployment - sample
OpenContrail vs Neutron DVR vs Other
OpenContrail Neutron DVR Other SDN
Licensing Fully Open Source
(Commercial
support from
Juniper)
Open Source Depends
Hypervisors
Orchestrator
KVM, VMware,
Kubernetes
KVM, VMware (limited),
Docker
Depends
Gateway
Routing
(South-
North)
Any arbitrary Edge
Router (supports
MPLS, GRE) Juniper
MX, Cisco ASR, etc.
Direct from each
compute.
External routing is
provided at appliances
not network devices.
Performance Near the line speed
for both directions
(9.6 Gbits on
10Gbits)
6 Gbits for East-West
and North-South
6 Gbits for East-West. For
North-South depends on
gateway appliances, but
not more than 6Gbit.
• SDN is core capability to us offer a secure multi-
tenant cloud platform
• overlay solutions provide a strong network isolation
and access control
• Overlay provide tight container - VM integration
SDN Conclusion
Contrail is available as Open Source
www.opencontrail.org. Commercial support available from Juniper.
www.opentcpcloud.org Reference Architecture for OpenStack
deployment
Same features and scaling as commercial version
Uses proven stable standards. Production-Ready.
Permissive license
Apache 2.0
tcp cloud is main contributor
Join us at OpenContrail Community
Questions?
Marek Celoud
marek.celoud@tcpcloud.eu
@MCeloud
Jakub Pavlík
jakub.pavlik@tcpcloud.eu
@JakubPav
@tcpcloud
OpenStack Summit Austion 2016

More Related Content

PPTX
OpenStack Ousts vCenter for DevOps and Unites IT Silos at AVG Technologies
PPTX
OpenContrail Implementations
PPTX
OpenContrail Experience tcp cloud OpenStack Summit Tokyo
PPTX
CERN User Story
PDF
10 Years of OpenStack at CERN - From 0 to 300k cores
PDF
OpenStack and OpenDaylight: An Integrated IaaS for SDN/NFV
PDF
OpenStack Journey in Tieto Elastic Cloud
PPTX
20161025 OpenStack at CERN Barcelona
OpenStack Ousts vCenter for DevOps and Unites IT Silos at AVG Technologies
OpenContrail Implementations
OpenContrail Experience tcp cloud OpenStack Summit Tokyo
CERN User Story
10 Years of OpenStack at CERN - From 0 to 300k cores
OpenStack and OpenDaylight: An Integrated IaaS for SDN/NFV
OpenStack Journey in Tieto Elastic Cloud
20161025 OpenStack at CERN Barcelona

What's hot (20)

PPTX
20150924 rda federation_v1
PDF
Containers on Baremetal and Preemptible VMs at CERN and SKA
PPTX
OpenStack and NetApp - Chen Reuven - OpenStack Day Israel 2017
PDF
Moving from CellsV1 to CellsV2 at CERN
PPTX
20170926 cern cloud v4
PDF
Future Science on Future OpenStack
PDF
Open Stack Days israel Keynote 2017
PDF
Cloudify NFV Orchestrator for Optimal Performance
PPTX
Neutron Updates - Liberty Edition
PPTX
The OpenStack Cloud at CERN - OpenStack Nordic
PDF
OpenNebula Conf | Lightning talk: Managing a Scientific Computing Facility wi...
PDF
Cern Cloud Architecture - February, 2016
PDF
Bringing Private Cloud computing to HPC and Science - EGI TF tf 2013
PDF
OpenNebula Conf 2014 | Bootstrapping a virtual infrastructure using OpenNebul...
PDF
CERN OpenStack Cloud Control Plane - From VMs to K8s
PPTX
Sahara Updates - Liberty Edition
PDF
[OpenStack Day in Korea 2015] Keynote 1 - OpenStack Mission Update
PDF
Deploying openstack using ansible
PDF
What's new in openstack ocata
PPTX
Success With OpenStack in Production - Frank Weyns - Openstack Day Israel 2016
20150924 rda federation_v1
Containers on Baremetal and Preemptible VMs at CERN and SKA
OpenStack and NetApp - Chen Reuven - OpenStack Day Israel 2017
Moving from CellsV1 to CellsV2 at CERN
20170926 cern cloud v4
Future Science on Future OpenStack
Open Stack Days israel Keynote 2017
Cloudify NFV Orchestrator for Optimal Performance
Neutron Updates - Liberty Edition
The OpenStack Cloud at CERN - OpenStack Nordic
OpenNebula Conf | Lightning talk: Managing a Scientific Computing Facility wi...
Cern Cloud Architecture - February, 2016
Bringing Private Cloud computing to HPC and Science - EGI TF tf 2013
OpenNebula Conf 2014 | Bootstrapping a virtual infrastructure using OpenNebul...
CERN OpenStack Cloud Control Plane - From VMs to K8s
Sahara Updates - Liberty Edition
[OpenStack Day in Korea 2015] Keynote 1 - OpenStack Mission Update
Deploying openstack using ansible
What's new in openstack ocata
Success With OpenStack in Production - Frank Weyns - Openstack Day Israel 2016
Ad

Similar to Operators experience and perspective on SDN with VLANs and L3 Networks (20)

PPTX
Midokura OpenStack Meetup Taipei
PDF
[OpenStack Day in Korea 2015] Track 3-6 - Archiectural Overview of the Open S...
PDF
State of the OpenDaylight Union
PDF
CloudKC: Evolution of Network Virtualization
PDF
From Nova-Network to Neutron and Beyond: A Look at OpenStack Networking
PDF
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
PDF
The Future of SDN in CloudStack by Chiradeep Vittal
PDF
Yechielthur1100red hat-cloud-infrastructure-networking-deep-dive-140417165107...
PPTX
Midokura OpenStack Day Korea Talk: MidoNet Open Source Network Virtualization...
PDF
Midokura @ OpenStack Seattle
PDF
What's the deal with Neutron?
PPTX
Understanding and deploying Network Virtualization
PDF
Directions for CloudStack Networking
PDF
Introduction to SDN
PDF
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
PPTX
MidoNet Overview - OpenStack and SDN integration
PDF
ONUG Tutorial: Bridges and Tunnels Drive Through OpenStack Networking
PDF
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
PDF
Introduction to OpenNetwork and SDN
PDF
Open stack networking_101_update_2014-os-meetups
Midokura OpenStack Meetup Taipei
[OpenStack Day in Korea 2015] Track 3-6 - Archiectural Overview of the Open S...
State of the OpenDaylight Union
CloudKC: Evolution of Network Virtualization
From Nova-Network to Neutron and Beyond: A Look at OpenStack Networking
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
The Future of SDN in CloudStack by Chiradeep Vittal
Yechielthur1100red hat-cloud-infrastructure-networking-deep-dive-140417165107...
Midokura OpenStack Day Korea Talk: MidoNet Open Source Network Virtualization...
Midokura @ OpenStack Seattle
What's the deal with Neutron?
Understanding and deploying Network Virtualization
Directions for CloudStack Networking
Introduction to SDN
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
MidoNet Overview - OpenStack and SDN integration
ONUG Tutorial: Bridges and Tunnels Drive Through OpenStack Networking
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
Introduction to OpenNetwork and SDN
Open stack networking_101_update_2014-os-meetups
Ad

More from Jakub Pavlik (6)

PPTX
Mirantis - Continuous Deployment of Infrastructure, Platform, and Application...
PDF
Evolve or Die: Enterprise Ready OpenStack upgrades with Kubernetes
PDF
Kubernetes SDN performance and architecture
PDF
SmartCity IoT on Kubernetes and OpenStack
PPTX
OpenStack High Availability
PPTX
OpenContrail deployment experience
Mirantis - Continuous Deployment of Infrastructure, Platform, and Application...
Evolve or Die: Enterprise Ready OpenStack upgrades with Kubernetes
Kubernetes SDN performance and architecture
SmartCity IoT on Kubernetes and OpenStack
OpenStack High Availability
OpenContrail deployment experience

Recently uploaded (20)

PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
Big Data Technologies - Introduction.pptx
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Approach and Philosophy of On baking technology
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Cloud computing and distributed systems.
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
cuic standard and advanced reporting.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Encapsulation theory and applications.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Unlocking AI with Model Context Protocol (MCP)
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Big Data Technologies - Introduction.pptx
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Approach and Philosophy of On baking technology
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Per capita expenditure prediction using model stacking based on satellite ima...
Digital-Transformation-Roadmap-for-Companies.pptx
Cloud computing and distributed systems.
Building Integrated photovoltaic BIPV_UPV.pdf
Spectral efficient network and resource selection model in 5G networks
cuic standard and advanced reporting.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Encapsulation_ Review paper, used for researhc scholars
Encapsulation theory and applications.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

Operators experience and perspective on SDN with VLANs and L3 Networks

  • 1. Operator's experience and perspective on SDN with VLANs and L3 Networks @tcpcloud OpenStack Summit Austin 2016
  • 2. Presentation Agenda • About tcp cloud & workday • OpenStack Networking/SDN • SDN key criteria for enterprises • SDN operation Use Cases • Comparison of SDN
  • 3. About tcp cloud ❖ Active in global community (OpenStack, OpenContrail, SaltStack, etc…) ❖ Partnership (Canonical, Juniper, Arrow ECS, etc…) ❖ Own Hi-Tech Datacenter (TIER III, 20kW per rack, hundreds 10Gbps ports, etc…) ❖ Focused on private open cloud solutions and services (since 2011) ❖ References (AVG Technologies, Czech Railways, Mall.cz, 100%IT) ❖ Two directions: ➢ Enterprise Private Cloud solutions (OpenStack, Kubernetes) ➢ IoT (SmartCity projects)
  • 4. About Workday ● On-demand (cloud-based) financial management and human capital management software vendor. ● Juniper Contrail ● L3 fabric network
  • 5. • All clouds are about networking • Key and the most controversial component of OpenStack • High Availability, Scalability, Migration, Multi-tenancy, Performance, Security • LBaaS, FWaaS, VPNaaS, Service Chainning • Multiple solutions • 30+ plugin drivers • It is almost impossible to choose right way OpenStack Networking/SDN
  • 7. • Provide secure multi-tenancy using strong network isolation • Policy driven network access control within (and across) projects/domains • Support software driven network functions • LBaaS, DNSaaS, etc. • Interconnect OpenStack with bare metal storage/analytics services • Provide an ability for product engineering teams to define a network topology via REST APIs • Associate network objects dynamically with VMs, Projects • Create and manage network access control policies within and across projects • Enable easier integration of applications on partner infrastructure General SDN Objectives
  • 8. First step = Overlay or not Overlay Cloud native way • Cloud native apps • No overlapping (callico can) • No IP failover • No Live Migration • No L2 between VMs • Suitable for containers VLANs • 4k limit • No failure isolation domain • Spanning many ToRs • Physical device configuration Overlay • Simple physical network • L3 between ToRs • Controllers orchestrate tunnel mesh for VM • Overlapping, NFV, VNF
  • 9. First step = Overlay or not Overlay Cloud native way • Cloud native apps • No overlapping (callico can) • No IP failover • No Live Migration • No L2 between VMs • Suitable for containers VLANs • 4k limit • No failure isolation domain • Spanning many ToRs • Physical device configuration Overlay • Simple physical network • L3 between ToRs • Controllers orchestrate tunnel mesh for VM • Overlapping, NFV, VNF Legacy - not suitable for cloud Future - cloud native applications
  • 10. • NFV & VNF - LBaaS, VPNaaS • Direct traffic datapath - East-West & North-South • North-South - must be routed on physical routers • Multiple external networks • Performance & Scaling • Bare metal connection (non virtualized servers) SDN key criterias for enterprise
  • 11. • Open source • L3VPN, EVPN capabilities • Multi cloud solution - Kubernetes, KVM, other hypervisors • Integration of physical LbaaS • IPv6 support • Intel DPDK, SR-IOV SDN optionals for service providers
  • 12. • Linux bridge, OVS • External network in port to each compute • L2 underlay only • No analytics • Too complex Neutron DVR Complexity
  • 13. • L3/L2 compatible • open source • no too complex OpenContrail
  • 14. • No network node • No proprietary gateway node (appliances) • MPLSoverGRE or VXLAN termination in Network devices • L3VPN, EVPN, OVS-DB Direct datapath North-South, East-West
  • 15. • depends on encapsulation • depends on NIC offloading • 4 % payload overhead • 9.6 Gbits/s North-South, East-West with MPLSoverGRE • 5.2 Gbits/s with OVS VXLAN Data Plane Performance
  • 21. Openstack Cluster Deployment - sample logical
  • 23. OpenContrail vs Neutron DVR vs Other OpenContrail Neutron DVR Other SDN Licensing Fully Open Source (Commercial support from Juniper) Open Source Depends Hypervisors Orchestrator KVM, VMware, Kubernetes KVM, VMware (limited), Docker Depends Gateway Routing (South- North) Any arbitrary Edge Router (supports MPLS, GRE) Juniper MX, Cisco ASR, etc. Direct from each compute. External routing is provided at appliances not network devices. Performance Near the line speed for both directions (9.6 Gbits on 10Gbits) 6 Gbits for East-West and North-South 6 Gbits for East-West. For North-South depends on gateway appliances, but not more than 6Gbit.
  • 24. • SDN is core capability to us offer a secure multi- tenant cloud platform • overlay solutions provide a strong network isolation and access control • Overlay provide tight container - VM integration SDN Conclusion
  • 25. Contrail is available as Open Source www.opencontrail.org. Commercial support available from Juniper. www.opentcpcloud.org Reference Architecture for OpenStack deployment Same features and scaling as commercial version Uses proven stable standards. Production-Ready. Permissive license Apache 2.0 tcp cloud is main contributor Join us at OpenContrail Community