SlideShare a Scribd company logo
Optimizing NFV Service Chains
on OpenStack using Docker
Meenakshi Sundaram Lakshmanan, Rahul Krishna Upadhyaya,
CB Ananth Padmanabhan, Satya Routray.
28 Apr 2016
Docker – What is it ?
Docker containers wrap up a piece of software in a complete filesystem that contains everything it needs to run: code,
runtime, system tools, system libraries – anything you can install on a server. This guarantees that it will always run the same,
regardless of the environment it is running in.
Docker Instance vs Virtual Machine
• Better utilization of resources, hence higher density of workloads.
• Hyper-call overhead is reduced since there is no hypervisor layer. With SR-IOV/DPDK near
metal perf
• Faster provisioning and easier Devops, easy to replicate, share.
Advantages
Challenges
• Docker had issues with mutli-host networking. Solved using overlay since Docker
Version 1.9.
• Docker has security related challenges. VM generally termed as more secure given the
isolation.
• Performance of network functions. Many of which have been addressed with DPDK/SR-
IOV with some trade-offs
Docker Instance vs Virtual Machine
• They are network appliances other than switches and routers.
• Deployed for increasing security and performance
• Very effective solution for ServiceAssurance, Traffic Analysis, Traffic filtering
etc.,
Drawbacks
• Hardware middle boxes are difficult to manage
• Difficult to scale on demand
• Virtual middle boxes (NFV) need an orchestrator to provision them
• In a public cloud environment, placement of virtual components may not be
always under control
Middle Boxes
SDN (Software Defined Networking) :
It is an approach to computer networking that allows network administrators to manage
network services through abstraction of higher-level functionality.
NFV (Network Function Virtualization) :
It is a network architecture concept that uses the technologies of IT virtualization to virtualize
entire classes of network node functions into building blocks that may connect, or chain
together, to create communication services.
SFC (Service Function Chaining) :
It consists of a set of network functions, such as firewalls or application delivery controllers
(ADCs) that are interconnected through the network to support an application.
SDN, NFV and SFC
• SDN and NFV solve independent problems, and are even more
effective when they work together.
• They simplify the service chaining process by reducing the number
of devices a data packet needs to travel through
• Answers the questions of ‘who controls what’ from ‘what runs where’
• Allows a Service Provider to create service chains for each type of
traffic and provide multitenancy through the cloud infrastructure
SDN or NFV?
Open Networking Foundation
As SDN and NFV gained popularity, there was a need to create a standard way for SDN to
control Network functions. Hence ONF was formed
OpenFlow
Widely considered the first SDN standard. Defines a model for how traffic is organized into
different flows and how it can be controlled centrally.
OpenDayLight
An Opensource SDN project hosted by the Linux Foundation, which supports many
protocols including the OpenFlow protocol. Offers a complete functional SDN platform
without the need for any other component.
OPNFV
Linux Foundation introduced another platform, Open Platform for NFV, an integrated
platform that brings together Enterprises, Service Providers, Cloud & Infrastructure vendors
and customers to accelerate innovation & deployment of NFV
SDN & NFV today
• Firewalls
• Packet Filters
• Virtual Routers – quagga, openwrt
• Load Balancers
• WAN Optimizers
• Intrusion Detection
• Virtual CPE
Network Functions
NFV in Container and Docker World
• Consistent and quick way of deploying and re-deploying NFVs
• Very easy to scale on demand
• Low latency
• No Hypervisor overload
• Presence of established tools to deploy and manage containers
• There is lot of work underway in bringing NFV and Containers together
• Service chaining the network traffic locally.
• Having faster, re-useable, dynamic NF deployments with low overhead of
NFs to the infrastructure.
• Avoiding the loss in performance of the network functions due to
virtualization overhead.
What are we trying to achieve
Solution Design – Deployment
k
Host1
Host2
Host3
OpenStack Controller
Nova
Neutron
Glance
Cinder
…
Service Controller
Can make
admin calls to
OS services
Dockerd
Dockerd
Dockerd
Docker
Registry
KVM
KVM
KVM
VM VM
VMVM
VMVM
VMVM
VMVM
VMVM
A
G
E
N
T
A
G
E
N
T
A
G
E
N
T
SFC
SFC
SFC
SFC
SFC
SFC
Tenant1
Tenant2
Tenant3
Design – Per Node
Docker Daemon
OVS
Agent
Each Host in OS Cloud
VM
VM
VM
Docker
Network
Function Docker
Network
Function
Docker
Network
Function
Service Function Chain
KVM
Exteranal Communication
via Host NIC
Configures
Controller
Connection to SDN
Controller (Ex. ODL)
How it Flows
Docker Daemon
OVS
Agent
Each Host in OS Cloud
VM
VM
VM
Virtual
Firewall
Docker
Instance
vRouter
Docker
Instance
Service Function Chain
KVM
Exteranal Communication
via Host NIC
Configures
Controller
2
1
3
4
4
How it Service Chains – Routing between VNFs
Switch Match Action
local input port: 1, src ip: VM1 output port: 2
local input port: 2, src ip: VM1 output port: 3
local input port: 3, src ip: VM1 output port: 4
OpenVswitch (local)
VM1
1
2 3
4
FirewallVRouter
Flow Table
External Nic
Depending upon what the VNF
needs to do, different kind of routing
models could be used.
Advantages of the Design
High Density – Better utilization of resources.
Performance – Near metal performance of network functions by using SR-IOV/DPDK. No hyper-call overhead due to
usage of containers as Network Functions.
Low Latency – Service chaining completed locally. The packets don’t have to move through lengths of the cloud to
get processed.
Docker native advantages – Taking advantage of native docker advantages like quicker build/ship model carried
forward.
Public cloud model– Will work well with clouds deployments where you have no control over placement of
infrastructure components.
Implementation - Areas of Work
Running Docker and KVM on the same host machine
- Changes on the compute-scheduler
- Changes on the OVS agent side (Cleanup)
Configuring the OVS
- Creating service chains using OVS-OpenFlow Rule Modification
- Performance, HA and load-balancing.
- Choose the best kind of routing of packets based on type of NFV
Docker Daemon Interactions
- Creating network function containers on demand.
- Tenant based visibility/segregation of the docker containers.
- Storing of Stateful docker images for VNFs
Implementation of the Controller & Agent.
Q&A
OpenStack Summit
Austin, Texas 2016

More Related Content

PPTX
Optimising nfv service chains on open stack using docker
PPTX
Next Generation Network Developer Skills
PPTX
OpenDaylight Netvirt and Neutron - Mike Kolesnik, Josh Hershberg - OpenStack ...
PPTX
Network Monitoring and Analytics
PPTX
Superfluidity, Infrastructure for mixed workloads in Mobile Edge Computing - ...
PPTX
Openstack Neutron Insights
PPTX
OpenStack and OpenDaylight Workshop: ONUG Spring 2014
PPTX
OpenStack Discovery and Networking Assurance - Koren Lev - Meetup
Optimising nfv service chains on open stack using docker
Next Generation Network Developer Skills
OpenDaylight Netvirt and Neutron - Mike Kolesnik, Josh Hershberg - OpenStack ...
Network Monitoring and Analytics
Superfluidity, Infrastructure for mixed workloads in Mobile Edge Computing - ...
Openstack Neutron Insights
OpenStack and OpenDaylight Workshop: ONUG Spring 2014
OpenStack Discovery and Networking Assurance - Koren Lev - Meetup

What's hot (20)

PPTX
Navigating OpenStack Networking
PPTX
Lessons learned from global telecom operators' cloud journeys - Zeev Likworni...
PPTX
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
PPTX
SDN Scale-out Testing at OpenStack Innovation Center (OSIC)
PDF
Unified Underlay and Overlay SDNs for OpenStack Clouds
PDF
Multisite OpenStack for NFV: Bridging the Gap
PPTX
Symantec SDN Deployment
PDF
SDN Service Provider use cases Network Function Virtualization (NFV)
PDF
MidoNet Future -ミドネットの未来-
PDF
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
PPTX
How Cloud Native VNFs Deployed on OpenStack Will Change the Telecom Industry ...
PDF
OpenStack and OpenDaylight: An Integrated IaaS for SDN/NFV
PPTX
OpenStack Neutron behind the Scenes
PPTX
Midokura Enterprise MidoNet Overview
PDF
VOID19 Cloud Transformation at Viettel accelerate faster with open infrastru...
PDF
Managed Cloud Platform
PPTX
OpenStack Collaboration made in heaven with Heat, Mistral, Neutron and more..
PPTX
Software Defined Networking(SDN) and practical implementation_trupti
ODP
Network Monitoring in the age of the Cloud
PPTX
OpenContrail deployment experience
Navigating OpenStack Networking
Lessons learned from global telecom operators' cloud journeys - Zeev Likworni...
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
SDN Scale-out Testing at OpenStack Innovation Center (OSIC)
Unified Underlay and Overlay SDNs for OpenStack Clouds
Multisite OpenStack for NFV: Bridging the Gap
Symantec SDN Deployment
SDN Service Provider use cases Network Function Virtualization (NFV)
MidoNet Future -ミドネットの未来-
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
How Cloud Native VNFs Deployed on OpenStack Will Change the Telecom Industry ...
OpenStack and OpenDaylight: An Integrated IaaS for SDN/NFV
OpenStack Neutron behind the Scenes
Midokura Enterprise MidoNet Overview
VOID19 Cloud Transformation at Viettel accelerate faster with open infrastru...
Managed Cloud Platform
OpenStack Collaboration made in heaven with Heat, Mistral, Neutron and more..
Software Defined Networking(SDN) and practical implementation_trupti
Network Monitoring in the age of the Cloud
OpenContrail deployment experience
Ad

Viewers also liked (10)

PPTX
Multi tenancy for docker
PDF
About Brain4Net, Inc. - July 2015
PPSX
FD.io Vector Packet Processing (VPP)
PPTX
Monitoring Docker Containers and Dockererized Application
PPTX
What is Virtualization. Talk from Pycon 2013 India.
PPTX
Openstack Rally - Benchmark as a Service. Openstack Meetup India. Ananth/Rahul.
PPTX
Openstack Magnum: Container-as-a-Service
PPTX
Monitoring docker container and dockerized applications
PPTX
Multi tenancy for docker
PPTX
KubeCon EU 2016: Multi-Tenant Kubernetes
Multi tenancy for docker
About Brain4Net, Inc. - July 2015
FD.io Vector Packet Processing (VPP)
Monitoring Docker Containers and Dockererized Application
What is Virtualization. Talk from Pycon 2013 India.
Openstack Rally - Benchmark as a Service. Openstack Meetup India. Ananth/Rahul.
Openstack Magnum: Container-as-a-Service
Monitoring docker container and dockerized applications
Multi tenancy for docker
KubeCon EU 2016: Multi-Tenant Kubernetes
Ad

Similar to Optimising nfv service chains on open stack using docker (20)

PPTX
SDN and NFV Friends or Enemies ?
PPTX
Know about SDN and NFV
PDF
NFV Linaro Connect Keynote
PPTX
Software defined networking(sdn) vahid sadri
PDF
Building a sdn solution for the deployment of web application stacks in docker
PPTX
Midokura OpenStack Day Korea Talk: MidoNet Open Source Network Virtualization...
PPTX
MidoNet Overview - OpenStack and SDN integration
PPTX
Understanding and deploying Network Virtualization
PPTX
SDN 101: Software Defined Networking Course - Sameh Zaghloul/IBM - 2014
PPTX
Openstack Overview
PDF
Radisys/Wind River: The Telcom Cloud - Deployment Strategies: SDN/NFV and Vir...
PDF
ONP 2.1 platforms maximize VNF interoperability
PDF
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
PPTX
SDN and NFV: Friends or Enemies
PDF
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
PPTX
OpenStack Networking and Automation
PDF
High performance and flexible networking
PDF
Summit 16: ARM Mini-Summit - NXP QorIQ NFV Solutions - NXP Semiconductors
PPTX
Introduction to Software Defined Networking (SDN)
PDF
Introduction to Software Defined Networking (SDN) presentation by Warren Finc...
SDN and NFV Friends or Enemies ?
Know about SDN and NFV
NFV Linaro Connect Keynote
Software defined networking(sdn) vahid sadri
Building a sdn solution for the deployment of web application stacks in docker
Midokura OpenStack Day Korea Talk: MidoNet Open Source Network Virtualization...
MidoNet Overview - OpenStack and SDN integration
Understanding and deploying Network Virtualization
SDN 101: Software Defined Networking Course - Sameh Zaghloul/IBM - 2014
Openstack Overview
Radisys/Wind River: The Telcom Cloud - Deployment Strategies: SDN/NFV and Vir...
ONP 2.1 platforms maximize VNF interoperability
Tech Talk by John Casey (CTO) CPLANE_NETWORKS : High Performance OpenStack Ne...
SDN and NFV: Friends or Enemies
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
OpenStack Networking and Automation
High performance and flexible networking
Summit 16: ARM Mini-Summit - NXP QorIQ NFV Solutions - NXP Semiconductors
Introduction to Software Defined Networking (SDN)
Introduction to Software Defined Networking (SDN) presentation by Warren Finc...

Recently uploaded (20)

PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Electronic commerce courselecture one. Pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Encapsulation_ Review paper, used for researhc scholars
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Machine learning based COVID-19 study performance prediction
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
KodekX | Application Modernization Development
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
Electronic commerce courselecture one. Pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Dropbox Q2 2025 Financial Results & Investor Presentation
Encapsulation_ Review paper, used for researhc scholars
“AI and Expert System Decision Support & Business Intelligence Systems”
Machine learning based COVID-19 study performance prediction
MYSQL Presentation for SQL database connectivity
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
NewMind AI Monthly Chronicles - July 2025
Unlocking AI with Model Context Protocol (MCP)
KodekX | Application Modernization Development
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Reach Out and Touch Someone: Haptics and Empathic Computing
The AUB Centre for AI in Media Proposal.docx
Diabetes mellitus diagnosis method based random forest with bat algorithm
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...

Optimising nfv service chains on open stack using docker

  • 1. Optimizing NFV Service Chains on OpenStack using Docker Meenakshi Sundaram Lakshmanan, Rahul Krishna Upadhyaya, CB Ananth Padmanabhan, Satya Routray. 28 Apr 2016
  • 2. Docker – What is it ? Docker containers wrap up a piece of software in a complete filesystem that contains everything it needs to run: code, runtime, system tools, system libraries – anything you can install on a server. This guarantees that it will always run the same, regardless of the environment it is running in.
  • 3. Docker Instance vs Virtual Machine
  • 4. • Better utilization of resources, hence higher density of workloads. • Hyper-call overhead is reduced since there is no hypervisor layer. With SR-IOV/DPDK near metal perf • Faster provisioning and easier Devops, easy to replicate, share. Advantages Challenges • Docker had issues with mutli-host networking. Solved using overlay since Docker Version 1.9. • Docker has security related challenges. VM generally termed as more secure given the isolation. • Performance of network functions. Many of which have been addressed with DPDK/SR- IOV with some trade-offs Docker Instance vs Virtual Machine
  • 5. • They are network appliances other than switches and routers. • Deployed for increasing security and performance • Very effective solution for ServiceAssurance, Traffic Analysis, Traffic filtering etc., Drawbacks • Hardware middle boxes are difficult to manage • Difficult to scale on demand • Virtual middle boxes (NFV) need an orchestrator to provision them • In a public cloud environment, placement of virtual components may not be always under control Middle Boxes
  • 6. SDN (Software Defined Networking) : It is an approach to computer networking that allows network administrators to manage network services through abstraction of higher-level functionality. NFV (Network Function Virtualization) : It is a network architecture concept that uses the technologies of IT virtualization to virtualize entire classes of network node functions into building blocks that may connect, or chain together, to create communication services. SFC (Service Function Chaining) : It consists of a set of network functions, such as firewalls or application delivery controllers (ADCs) that are interconnected through the network to support an application. SDN, NFV and SFC
  • 7. • SDN and NFV solve independent problems, and are even more effective when they work together. • They simplify the service chaining process by reducing the number of devices a data packet needs to travel through • Answers the questions of ‘who controls what’ from ‘what runs where’ • Allows a Service Provider to create service chains for each type of traffic and provide multitenancy through the cloud infrastructure SDN or NFV?
  • 8. Open Networking Foundation As SDN and NFV gained popularity, there was a need to create a standard way for SDN to control Network functions. Hence ONF was formed OpenFlow Widely considered the first SDN standard. Defines a model for how traffic is organized into different flows and how it can be controlled centrally. OpenDayLight An Opensource SDN project hosted by the Linux Foundation, which supports many protocols including the OpenFlow protocol. Offers a complete functional SDN platform without the need for any other component. OPNFV Linux Foundation introduced another platform, Open Platform for NFV, an integrated platform that brings together Enterprises, Service Providers, Cloud & Infrastructure vendors and customers to accelerate innovation & deployment of NFV SDN & NFV today
  • 9. • Firewalls • Packet Filters • Virtual Routers – quagga, openwrt • Load Balancers • WAN Optimizers • Intrusion Detection • Virtual CPE Network Functions
  • 10. NFV in Container and Docker World • Consistent and quick way of deploying and re-deploying NFVs • Very easy to scale on demand • Low latency • No Hypervisor overload • Presence of established tools to deploy and manage containers • There is lot of work underway in bringing NFV and Containers together
  • 11. • Service chaining the network traffic locally. • Having faster, re-useable, dynamic NF deployments with low overhead of NFs to the infrastructure. • Avoiding the loss in performance of the network functions due to virtualization overhead. What are we trying to achieve
  • 12. Solution Design – Deployment k Host1 Host2 Host3 OpenStack Controller Nova Neutron Glance Cinder … Service Controller Can make admin calls to OS services Dockerd Dockerd Dockerd Docker Registry KVM KVM KVM VM VM VMVM VMVM VMVM VMVM VMVM A G E N T A G E N T A G E N T SFC SFC SFC SFC SFC SFC Tenant1 Tenant2 Tenant3
  • 13. Design – Per Node Docker Daemon OVS Agent Each Host in OS Cloud VM VM VM Docker Network Function Docker Network Function Docker Network Function Service Function Chain KVM Exteranal Communication via Host NIC Configures Controller Connection to SDN Controller (Ex. ODL)
  • 14. How it Flows Docker Daemon OVS Agent Each Host in OS Cloud VM VM VM Virtual Firewall Docker Instance vRouter Docker Instance Service Function Chain KVM Exteranal Communication via Host NIC Configures Controller 2 1 3 4 4
  • 15. How it Service Chains – Routing between VNFs Switch Match Action local input port: 1, src ip: VM1 output port: 2 local input port: 2, src ip: VM1 output port: 3 local input port: 3, src ip: VM1 output port: 4 OpenVswitch (local) VM1 1 2 3 4 FirewallVRouter Flow Table External Nic Depending upon what the VNF needs to do, different kind of routing models could be used.
  • 16. Advantages of the Design High Density – Better utilization of resources. Performance – Near metal performance of network functions by using SR-IOV/DPDK. No hyper-call overhead due to usage of containers as Network Functions. Low Latency – Service chaining completed locally. The packets don’t have to move through lengths of the cloud to get processed. Docker native advantages – Taking advantage of native docker advantages like quicker build/ship model carried forward. Public cloud model– Will work well with clouds deployments where you have no control over placement of infrastructure components.
  • 17. Implementation - Areas of Work Running Docker and KVM on the same host machine - Changes on the compute-scheduler - Changes on the OVS agent side (Cleanup) Configuring the OVS - Creating service chains using OVS-OpenFlow Rule Modification - Performance, HA and load-balancing. - Choose the best kind of routing of packets based on type of NFV Docker Daemon Interactions - Creating network function containers on demand. - Tenant based visibility/segregation of the docker containers. - Storing of Stateful docker images for VNFs Implementation of the Controller & Agent.
  • 18. Q&A