SlideShare a Scribd company logo
Real-world Deployment Scenarios for VMware NSX
Taruna Gandhi, VMware
Jeremy Hanmer, DreamHost
Funs Kessen, Schuberg Philis
NET5525
#NET5525
2
Agenda
 VMware NSX Overview
 Network Virtualization for Mission Critical Workloads
at Schuberg Philis
 Network Virtualization in DreamCompute using
Commodity Hardware
 Q&A
3
The Business Wants to Go FAST!
NSX is all about speed.
Hot, nasty, bad ass speed.
- Ricky Bobby
4
Provisioning Multi-tier Network Services Today
5
Provisioning Multi-tier Network Services Today
Compute
Network
DC Services
DB DB
App App
Web Web
Corpnet/Internet
 Provisioning is slow
 Placement is limited
 Mobility is limited
 Hardware dependent
 Operationally intensive
6
Provisioning Network Virtualization with NSX
 Programmatic provisioning
 Place any workload anywhere
 Move any workload anywhere
 Decoupled from hardware
 Operationally efficient
Compute
Network
DC Services
7
Provisioning Network Virtualization with NSX
 Programmatic provisioning
 Place any workload anywhere
 Move any workload anywhere
 Decoupled from hardware
 Operationally efficient
Compute
Network
VMware NSX
DC Services
8
VMware NSX – Networking & Security Capabilities
Any Application
(without modification)
Virtual Networks
VMware NSX Network Virtualization Platform
Logical L2
Any Network Hardware
Any Cloud Management Platform
Logical
Firewall
Logical
Load Balancer
Logical L3
Logical
VPN
Any Hypervisor
Logical Switching– Layer 2 over Layer 3,
decoupled from the physical network
Logical Routing– Routing between virtual
networks without exiting the software
container
Logical Firewall – Distributed Firewall,
Kernel Integrated, High Performance
Logical Load Balancer – Application Load
Balancing in software
Logical VPN – Site-to-Site & Remote
Access VPN in software
NSX API – RESTful API for integration into
any Cloud Management Platform
Partner Eco-System
9
VMware NSX – Networking & Security Capabilities
Rich Networking & Security Services
 Scalable Logical Switching
 Physical to Virtual L2 Bridging
 Dynamic L3 Routing: OSPF, BGP, IS-IS
 Logical Services:
Firewall, Identity-based Firewall, Load-balancing,
VPN (IPSec, SSL, L2VPN)
Automation & Operations
 API Driven Integration
 Service Composer for Security Workflows
 Server Access Monitoring
 Troubleshooting & Visibility
Partner Extensibility
 Physical ToR L2 Integration
 Security Services – IDS / IPS, AV, Vulnerability
Mgmt
 Network Services – Load Balancers, WAN
Optimization
Any Application
(without modification)
Virtual Networks
VMware NSX Network Virtualization Platform
Logical L2
Any Network Hardware
Any Cloud Management Platform
Logical
Firewall
Logical
Load Balancer
Logical L3
Logical
VPN
Any Hypervisor
10
VMware NSX – Network Virtualization Benefits
VMware NSX Transforms the Operational Model of the Network
 Network provisioning time
reduced from 7 days
to 30 sec
Reduce network
provisioning time from
days to seconds
Cost Savings
 Reduce operational
costs by 80%
 Increase compute asset
utilization upto 90%
 Reduce hardware costs
by 40-50%
Operational
Automation
Simplified IP hardware
Choice
 Any Hypervisor:
vSphere, KVM, Xen, HyperV
 Any CMP:
vCAC, Openstack
 Any Network Hardware
 Partner Ecosystem
Any hypervisor
Any CMP
with Partner
11
Results Speak Louder Than Slideware
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
–
–
–
–
–
–
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
–
–
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
–
•
•
•
–
•
•
–
–
–
–
–
•
•
–
–
–
–
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
Who Am I?
• Jeremy Hanmer (@fzylogic)
• 13 years of experience with DreamHost
• System Engineer -> Network Engineer ->...
• ... VP Security -> Cloud Architect
• Focusing on OpenStack and Network
Virtualization
DreamCompute’s
Networking Requirements
•
•
•
•
•
•
•
•
•
•
•
Why Virtualize?
• Customers deserve it
• Better Security (Isolate customers from one another)
• Live Migration (Zero-downtime maintenance!)
• Replicate their existing IP addressing schemes
• Easier administration
• Live Migration (Hypervisor maintenance becomes easy)
• Much easier to know what’s going on on the network
• Automating VLAN provisioning STINKS and doesn’t scale
• We’re now able to migrate workloads to avoid hot spots
Why VMware?
• Confident in their team
• Roadmap (It included IPv6!
I’m told it’s getting close!)
• Easy integration of our own Layer 3 services
• Community presence in OpenStack
is awesome
• Emphasis on ease of troubleshooting
• Super great support from the beginning
Why Cumulus?
•
•
•
•
•
•
•
•
•
•
•
•
Physical Network Design
• IPv6 Native
• Storage network is 100% IPv6
• Customers all receive a /64 of public IPv6 space
• Layer 2 domains terminate at the TOR
• OSPF v2/3 running on every switch
• 10G Ethernet to every server
• 40G Ethernet between spines
• Dedicated networks for storage (one frontend, one backend),
NSX, and administration
• Simple!
• VRRP, QFabric, HSRP often cause more problems than they fix
• Debugging Layer 3 is easy. Debugging Layer 2 is not
Rack Architecture
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
Virtualization Workflow
•
•
•
•
AKA: Why this is all so awesome
The Future!
• Migrate to NSX’s L3 services
• Just waiting for IPv6 to ship with BGP support
• Get Chef running on the Cumulus gear
• Hasn’t been a priority because of the nearly
identical configs
• Move to a full mesh architecture that wasn’t
possible before
“Pics or It Didn’t Happen!”
36
Thoughts & Questions
•
Fkessen
fkessen@schubergphilis.com
•
•
37
Other VMware Activities Related to This Session
 HOL:
HOL-SDC-1303
VMware NSX Network Virtualization Platform
 Group Discussions:
NET1001-GD
vCloud Networking and Security & NSX for VMware Environments with
Ray Budavari
THANK YOU
VMworld 2013: Real-world Deployment Scenarios for VMware NSX
Real-world Deployment Scenarios for VMware NSX
Taruna Gandhi, VMware
Jeremy Hanmer, DreamHost
Funs Kessen, Schuberg Philis
NET5525
#NET5525

More Related Content

PDF
VMworld 2013: Virtualized Network Services Model with VMware NSX
PPTX
VMUGbe 21 Filip Verloy
PDF
An Introduction to VMware NSX
PDF
VMware NSX primer 2014
PDF
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
PDF
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
PDF
The Future of Cloud Networking is VMware NSX
PDF
Si fa presto a dire SDDC: come, quando e perché?
VMworld 2013: Virtualized Network Services Model with VMware NSX
VMUGbe 21 Filip Verloy
An Introduction to VMware NSX
VMware NSX primer 2014
VMworld 2013: Bringing Network Virtualization to VMware Environments with NSX
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
The Future of Cloud Networking is VMware NSX
Si fa presto a dire SDDC: come, quando e perché?

What's hot (20)

PDF
The Vision for the Future of Network Virtualization with VMware NSX
PPTX
VMWare NSX Components
PPTX
NSX 9 Core Use Cases
PDF
VMworld 2015: The Future of Network Virtualization with VMware NSX
PDF
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
PDF
VMworld 2013: Advanced VMware NSX Architecture
PPTX
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
PDF
VMworld 2013: Deploying VMware NSX Network Virtualization
PDF
VMworld Europe 2014: Advanced Network Services with NSX
PDF
VMware NSX + Cumulus Networks: Software Defined Networking
PPTX
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
PDF
VMworld 2013: VMware NSX Integration with OpenStack
PDF
VMware NSX for vSphere - Intro and use cases
PPTX
VMworld 2016: Advanced Network Services with NSX
PDF
VMworld 2013: Operational Best Practices for NSX in VMware Environments
PPTX
VMworld 2015: VMware NSX Deep Dive
PDF
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
PDF
VMworld 2014: Virtualize your Network with VMware NSX
PDF
VMworld 2014: Introduction to NSX
The Vision for the Future of Network Virtualization with VMware NSX
VMWare NSX Components
NSX 9 Core Use Cases
VMworld 2015: The Future of Network Virtualization with VMware NSX
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
VMworld 2013: Advanced VMware NSX Architecture
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
VMworld 2013: Deploying VMware NSX Network Virtualization
VMworld Europe 2014: Advanced Network Services with NSX
VMware NSX + Cumulus Networks: Software Defined Networking
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
VMworld 2013: VMware NSX Integration with OpenStack
VMware NSX for vSphere - Intro and use cases
VMworld 2016: Advanced Network Services with NSX
VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld 2015: VMware NSX Deep Dive
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
VMworld 2014: Virtualize your Network with VMware NSX
VMworld 2014: Introduction to NSX
Ad

Similar to VMworld 2013: Real-world Deployment Scenarios for VMware NSX (20)

PDF
Banv meetup-contrail
PDF
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
PDF
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
PPTX
6WINDGate™ - Enabling Cloud RAN Virtualization
PDF
Automation in Network Lifecycle Management - Bay Area Juniper Meetup
PPTX
VMworld 2015: VMware NSX Deep Dive
PPTX
VMware nsx network virtualization tool
PPTX
Reston Virtualization Group 9-18-2014
PDF
VMworld 2013: An Introduction to Network Virtualization
PDF
GAMO VMware vCloud Air
PDF
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
PPTX
6WINDGate™ - Powering the New-Generation of IPsec Gateways
PDF
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
PDF
Cozystack: Free PaaS platform and framework for building clouds
PPTX
Bbva bank on Open Stack
PDF
5G Core Network - ZTE 5g Cloude ServCore
 
PDF
Accelerated SDN in Azure
PPTX
OpenStack: Changing the Face of Service Delivery
PPTX
OpenStack: Changing the Face of Service Delivery
PPTX
Midokura OpenStack Day Korea Talk: MidoNet Open Source Network Virtualization...
Banv meetup-contrail
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
6WINDGate™ - Enabling Cloud RAN Virtualization
Automation in Network Lifecycle Management - Bay Area Juniper Meetup
VMworld 2015: VMware NSX Deep Dive
VMware nsx network virtualization tool
Reston Virtualization Group 9-18-2014
VMworld 2013: An Introduction to Network Virtualization
GAMO VMware vCloud Air
VMworld 2013: Case Study: VMware vCloud Ecosystem Framework for Network and S...
6WINDGate™ - Powering the New-Generation of IPsec Gateways
VMworld 2013: Designing Network Virtualization for Data-Centers: Greenfield D...
Cozystack: Free PaaS platform and framework for building clouds
Bbva bank on Open Stack
5G Core Network - ZTE 5g Cloude ServCore
 
Accelerated SDN in Azure
OpenStack: Changing the Face of Service Delivery
OpenStack: Changing the Face of Service Delivery
Midokura OpenStack Day Korea Talk: MidoNet Open Source Network Virtualization...
Ad

More from VMworld (20)

PPTX
VMworld 2016: vSphere 6.x Host Resource Deep Dive
PPTX
VMworld 2016: Troubleshooting 101 for Horizon
PPTX
VMworld 2016: Enforcing a vSphere Cluster Design with PowerCLI Automation
PPTX
VMworld 2016: What's New with Horizon 7
PPTX
VMworld 2016: Virtual Volumes Technical Deep Dive
PPTX
VMworld 2016: Advances in Remote Display Protocol Technology with VMware Blas...
PPTX
VMworld 2016: The KISS of vRealize Operations!
PPTX
VMworld 2016: Getting Started with PowerShell and PowerCLI for Your VMware En...
PPTX
VMworld 2016: Ask the vCenter Server Exerts Panel
PPTX
VMworld 2016: Virtualize Active Directory, the Right Way!
PPTX
VMworld 2015: Troubleshooting for vSphere 6
PPTX
VMworld 2015: Monitoring and Managing Applications with vRealize Operations 6...
PPTX
VMworld 2015: Advanced SQL Server on vSphere
PPTX
VMworld 2015: Virtualize Active Directory, the Right Way!
PPTX
VMworld 2015: Site Recovery Manager and Policy Based DR Deep Dive with Engine...
PPTX
VMworld 2015: Building a Business Case for Virtual SAN
PPTX
VMworld 2015: Explaining Advanced Virtual Volumes Configurations
PPTX
VMworld 2015: Virtual Volumes Technical Deep Dive
PPTX
VMworld 2015: Networking Virtual SAN's Backbone
PPTX
VMworld 2015: The Best SDDC!
VMworld 2016: vSphere 6.x Host Resource Deep Dive
VMworld 2016: Troubleshooting 101 for Horizon
VMworld 2016: Enforcing a vSphere Cluster Design with PowerCLI Automation
VMworld 2016: What's New with Horizon 7
VMworld 2016: Virtual Volumes Technical Deep Dive
VMworld 2016: Advances in Remote Display Protocol Technology with VMware Blas...
VMworld 2016: The KISS of vRealize Operations!
VMworld 2016: Getting Started with PowerShell and PowerCLI for Your VMware En...
VMworld 2016: Ask the vCenter Server Exerts Panel
VMworld 2016: Virtualize Active Directory, the Right Way!
VMworld 2015: Troubleshooting for vSphere 6
VMworld 2015: Monitoring and Managing Applications with vRealize Operations 6...
VMworld 2015: Advanced SQL Server on vSphere
VMworld 2015: Virtualize Active Directory, the Right Way!
VMworld 2015: Site Recovery Manager and Policy Based DR Deep Dive with Engine...
VMworld 2015: Building a Business Case for Virtual SAN
VMworld 2015: Explaining Advanced Virtual Volumes Configurations
VMworld 2015: Virtual Volumes Technical Deep Dive
VMworld 2015: Networking Virtual SAN's Backbone
VMworld 2015: The Best SDDC!

Recently uploaded (20)

PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
cuic standard and advanced reporting.pdf
PPT
Teaching material agriculture food technology
PDF
Empathic Computing: Creating Shared Understanding
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Cloud computing and distributed systems.
“AI and Expert System Decision Support & Business Intelligence Systems”
The Rise and Fall of 3GPP – Time for a Sabbatical?
Building Integrated photovoltaic BIPV_UPV.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Spectral efficient network and resource selection model in 5G networks
Digital-Transformation-Roadmap-for-Companies.pptx
cuic standard and advanced reporting.pdf
Teaching material agriculture food technology
Empathic Computing: Creating Shared Understanding
Encapsulation_ Review paper, used for researhc scholars
20250228 LYD VKU AI Blended-Learning.pptx
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
NewMind AI Monthly Chronicles - July 2025
Mobile App Security Testing_ A Comprehensive Guide.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Understanding_Digital_Forensics_Presentation.pptx
Reach Out and Touch Someone: Haptics and Empathic Computing
Cloud computing and distributed systems.

VMworld 2013: Real-world Deployment Scenarios for VMware NSX

  • 1. Real-world Deployment Scenarios for VMware NSX Taruna Gandhi, VMware Jeremy Hanmer, DreamHost Funs Kessen, Schuberg Philis NET5525 #NET5525
  • 2. 2 Agenda  VMware NSX Overview  Network Virtualization for Mission Critical Workloads at Schuberg Philis  Network Virtualization in DreamCompute using Commodity Hardware  Q&A
  • 3. 3 The Business Wants to Go FAST! NSX is all about speed. Hot, nasty, bad ass speed. - Ricky Bobby
  • 5. 5 Provisioning Multi-tier Network Services Today Compute Network DC Services DB DB App App Web Web Corpnet/Internet  Provisioning is slow  Placement is limited  Mobility is limited  Hardware dependent  Operationally intensive
  • 6. 6 Provisioning Network Virtualization with NSX  Programmatic provisioning  Place any workload anywhere  Move any workload anywhere  Decoupled from hardware  Operationally efficient Compute Network DC Services
  • 7. 7 Provisioning Network Virtualization with NSX  Programmatic provisioning  Place any workload anywhere  Move any workload anywhere  Decoupled from hardware  Operationally efficient Compute Network VMware NSX DC Services
  • 8. 8 VMware NSX – Networking & Security Capabilities Any Application (without modification) Virtual Networks VMware NSX Network Virtualization Platform Logical L2 Any Network Hardware Any Cloud Management Platform Logical Firewall Logical Load Balancer Logical L3 Logical VPN Any Hypervisor Logical Switching– Layer 2 over Layer 3, decoupled from the physical network Logical Routing– Routing between virtual networks without exiting the software container Logical Firewall – Distributed Firewall, Kernel Integrated, High Performance Logical Load Balancer – Application Load Balancing in software Logical VPN – Site-to-Site & Remote Access VPN in software NSX API – RESTful API for integration into any Cloud Management Platform Partner Eco-System
  • 9. 9 VMware NSX – Networking & Security Capabilities Rich Networking & Security Services  Scalable Logical Switching  Physical to Virtual L2 Bridging  Dynamic L3 Routing: OSPF, BGP, IS-IS  Logical Services: Firewall, Identity-based Firewall, Load-balancing, VPN (IPSec, SSL, L2VPN) Automation & Operations  API Driven Integration  Service Composer for Security Workflows  Server Access Monitoring  Troubleshooting & Visibility Partner Extensibility  Physical ToR L2 Integration  Security Services – IDS / IPS, AV, Vulnerability Mgmt  Network Services – Load Balancers, WAN Optimization Any Application (without modification) Virtual Networks VMware NSX Network Virtualization Platform Logical L2 Any Network Hardware Any Cloud Management Platform Logical Firewall Logical Load Balancer Logical L3 Logical VPN Any Hypervisor
  • 10. 10 VMware NSX – Network Virtualization Benefits VMware NSX Transforms the Operational Model of the Network  Network provisioning time reduced from 7 days to 30 sec Reduce network provisioning time from days to seconds Cost Savings  Reduce operational costs by 80%  Increase compute asset utilization upto 90%  Reduce hardware costs by 40-50% Operational Automation Simplified IP hardware Choice  Any Hypervisor: vSphere, KVM, Xen, HyperV  Any CMP: vCAC, Openstack  Any Network Hardware  Partner Ecosystem Any hypervisor Any CMP with Partner
  • 11. 11 Results Speak Louder Than Slideware
  • 26. Who Am I? • Jeremy Hanmer (@fzylogic) • 13 years of experience with DreamHost • System Engineer -> Network Engineer ->... • ... VP Security -> Cloud Architect • Focusing on OpenStack and Network Virtualization
  • 28. Why Virtualize? • Customers deserve it • Better Security (Isolate customers from one another) • Live Migration (Zero-downtime maintenance!) • Replicate their existing IP addressing schemes • Easier administration • Live Migration (Hypervisor maintenance becomes easy) • Much easier to know what’s going on on the network • Automating VLAN provisioning STINKS and doesn’t scale • We’re now able to migrate workloads to avoid hot spots
  • 29. Why VMware? • Confident in their team • Roadmap (It included IPv6! I’m told it’s getting close!) • Easy integration of our own Layer 3 services • Community presence in OpenStack is awesome • Emphasis on ease of troubleshooting • Super great support from the beginning
  • 31. Physical Network Design • IPv6 Native • Storage network is 100% IPv6 • Customers all receive a /64 of public IPv6 space • Layer 2 domains terminate at the TOR • OSPF v2/3 running on every switch • 10G Ethernet to every server • 40G Ethernet between spines • Dedicated networks for storage (one frontend, one backend), NSX, and administration • Simple! • VRRP, QFabric, HSRP often cause more problems than they fix • Debugging Layer 3 is easy. Debugging Layer 2 is not
  • 34. The Future! • Migrate to NSX’s L3 services • Just waiting for IPv6 to ship with BGP support • Get Chef running on the Cumulus gear • Hasn’t been a priority because of the nearly identical configs • Move to a full mesh architecture that wasn’t possible before
  • 35. “Pics or It Didn’t Happen!”
  • 37. 37 Other VMware Activities Related to This Session  HOL: HOL-SDC-1303 VMware NSX Network Virtualization Platform  Group Discussions: NET1001-GD vCloud Networking and Security & NSX for VMware Environments with Ray Budavari
  • 40. Real-world Deployment Scenarios for VMware NSX Taruna Gandhi, VMware Jeremy Hanmer, DreamHost Funs Kessen, Schuberg Philis NET5525 #NET5525