SlideShare a Scribd company logo
vCloud Hybrid Service
Networking Technical
Deep Dive
HBC2068
Ninad Desai, VMware, Inc
David Hill, VMware, Inc
Disclaimer
•  This presentation may contain product features that are currently under development.
•  This overview of new technology represents no commitment from VMware to deliver these
features in any generally available product.
•  Features are subject to change, and must not be included in contracts, purchase orders, or
sales agreements of any kind.
•  Technical feasibility and market demand will affect final delivery.
•  Pricing and packaging for any new technologies or features discussed or presented have not
been determined.
CONFIDENTIAL 2
33
VMware vCloud
Hybrid Service VMware vCloud Air
VMworld 2014: vCloud Hybrid Service Networking Technical Deep Dive
VMworld 2014: vCloud Hybrid Service Networking Technical Deep Dive
What is vCloud Air Network
Services built on??
vCloud Air Networking – Built on vCNS …. Moving to NSX
Fully Integrated vCloud Stack
vCloud Management and Automation
vCloud Air Management Console
vCloud Infrastructure
vCloud Networking and Security
vCloud Director with vCloud Connector
vSphere / vCenter
Customer A
Physically Isolated
Servers Storage pool
VPN and Network
pool
…
Dedicated Cloud
•  Being replaced by NSX-v
manager in the vCloud Air
Management stack
•  Backward compatible with
current vCNS based stack
•  Existing policies and
features stay intact
•  Foundation for new
networking features
How do I connect to vCloud Air ?
Options to Connect to vCloud Air
z
Customer Data Center vCloud Air
Private WAN /
Direct Connect /
Cross Connect
IPsec Tunnel
Public
INTERNET
Many Connectivity Choices To
Support Many Use Cases
INTERNET
INTERNET
Connecting to vCloud Air
•  Over the Public Internet
–  With Public IPs
–  Use NAT for address translation
–  By default F/W set to deny all and NAT not configured
INTERNET
•  IPsec VPN
–  vCloud Air features include IPsec VPN
–  Multiple VPN tunnels can terminate to Edge Gateway
–  Can connect to most of the major on-prem VPN devices
•  Direct Connect
–  Dedicated private connection
–  Secure and high speed
–  Extension to customer’s MPLS or data center cage
Connecting via IPsec VPN
CONFIDENTIAL
VPN Traffic
INTERNET
vSphere Edge Gateway	

§  LEP – 10.0.1.150
§  Peer ID – 69.194.137.230
§  Peer IP – 69.194.137.230
10.0.10.0/24
10.0.10.1
10.0.1.150
10.0.1.1
68.108.102.47
IP Protocol ID 50 (ESP)
IP Protocol ID 51 (AH)
UDP Port 500 (IKE)
UDP Port 4500
69.194.137.230
192.168.109.2/24
192.168.109.1
Edge Gateway	

§  LEP – 69.194.137.230
§  Peer ID – 10.0.1.150
§  Peer IP – 68.108.102.47
EDGE
GATEWAY
EDGE
GATEWAY
What Networking Services
do we offer?
vCloud Air - Options and Gateway Choices..
CONFIDENTIAL 13
§  Shared Cloud
•  Logically separated network, compute and
storage
§  5GHz CPU (burstable to 10GHz)
§  20GB RAM, 2TB storage
§  No vDC segmentation
§  One Edge Gateway
§  Dedicated Cloud
•  Physically separated hosts
•  Logically separated network and storage
§  30GHz CPU, 120GB RAM, 6TB
§  Segment vDCs based on orgs
§  Multiple Edge Gateways
VDC1 VDC2
VDC3 VDC4
VDC
vCloud Air Basic Networking Constructs
INTERNET
Routed/Gateway
Networks
(up to 9 networks)
Isolated Network
External Network
(managed by VMware)
NAT
FW
Load Balancer
IPsec
DHCP
Static routing
Customers vDC
EDGE
GATEWAY
Configuration Access Options
CONFIDENTIAL 15
vCloud Air Management Web Portal
- For basic networking configurations
Configuration Access Options
CONFIDENTIAL 16
vCloud Air Management Web Portal
- For basic networking configurations
For Advanced
configurations
Configuration Access Options
CONFIDENTIAL 17
vCloud Director management portal
- For advanced networking configs
Can I bring my Private IP
space along?
Yes! Via Network Address Translation (NAT)
•  Need to create F/W rules to
allow traffic
•  IPv4 NAT
•  Source NAT & Destination NAT rules.
–  Supports multiple rules on multiple interfaces
•  Can use internal/private IP space
–  Bring your own internal IP space
–  Create/Manage subnets within IP space
–  Multiple IP space under the same gateway
NAT rules:
-  SNAT & DNAT rules
-  Options include protocol/port
selection
Gateway
Public IPs
Internal IPs
10.x.x.x 172.16.x.x 192.168.x.x
Organization Net 1 Organization Net 2 Organization Net 3
EDGE
GATEWAY
But …. Can I stretch my Layer 2
network on to vCloud Air?
vCloud Connector Data Center L2 Extension
CONFIDENTIAL 21
(192.168.50.0/24)
184.61.71.155
74.204.180.41
VPN Traffic
INTERNET
(192.168.50.0/24)
Default Gateway =
192.168.50.10
50.34 50.35
50.36 50.37
50.33
100.33
(192.168.50.0/24)
50.10
100.10
SSL
SSL
EDGE
GATEWAY
EDGE
GATEWAY
EDGE
GATEWAY
Corp
Firewall
Layer 2 Extensions – Updated with NSX
vCloud Air
INTERNET
INTERNET
VLAN 10 VLAN 11
SSL Client
Default
Router
vNIC
Trunk VLAN 10-11
Site A: Non-NSX VLAN Backed Network
L3 Network, VPN,
Direct Connect
EDGE
GATEWAY
(NSX)
vCloud Air
Client
Okay.. So I have a typical multi-tier app
(LAMP/WAMP stack)….
Can I bring it to vCloud Air?
Firewall for Multi-Tier Applications
Web tier App tier DB Tier
INTERNET
Firewall
•  5 Tuple F/W policies
–  Protocol, Source/Dest. IP, Source/Dest. Port
•  Stateful Firewall
•  FIPS-140-2 Crypto
•  Common Criteria EAL 4
Load Balancing
•  VIP and pool servers
•  Health check
Load
Balancing
Server Pool
VIP: 66.44.4.1
EDGE
GATEWAY
Direct Connect Use Cases
Direct Connect – Use Cases
26
Ø  Can I have a private connection to vCloud Air?
Ø  Can vCloud Air be part of my MPLS connection?
Ø  Can I cross connect in to vCloud Air?
Ø  Can I extend my layer 2 network on to this direct
connect interface?
vCloud Air Direct Connect
Customer Co-Lo Cage vCloud Air
Data Center owner operated/
managed
vCloud Air
connection point
Customer Data Center
vCloud Air
NSP connection
(MPLS, E-Line etc.)
vCloud Air
managed
vCloud Air
managed
Cross connect use case
WAN connectivity use case
vCloud Air
connection point
Direct Connect – With vCloud Air
28
DMZ Network
(192.168.52.0/24)
Private Network
(192.168.50.0/24)
Private Network
(192.168.100.x/24)
Headquarters
NSP termination
point
EDGE
GATEWAY
INTERNET
vCloud Air
Connection point
MDF/MMR
Untagged Layer 2
connection
(1G, 10G)
10.2.2.2
10.2.2.1
MPLS
(from NSP)
Private Network
(192.168.50.0/24)
Branch office
10.2.2..x/24
10.1.1.x/24
10.3.3.x/24
Direct Connect – With vCloud Air
29
DMZ Network
(192.168.52.0/24)
Private Network
(192.168.50.0/24)
Private Network
(192.168.50.x/24)
Headquarters
NSP termination
point
EDGE
GATEWAY
INTERNET
vCloud Air
Connection point
MDF/MMR
Untagged Layer 2
connection
(1G, 10G)
10.2.2.2
10.2.2.1
MPLS
(from NSP)
Private Network
(192.168.50.0/24)
Branch office
10.2.2..x/24
10.1.1.x/24
10.3.3.x/24
Direct Connect – Using Existing Security
CONFIDENTIAL 30
1 Gbps / 10 Gbps Direct Connect Traffic
DMZ Network
(192.168.52.0/24)
Internet
Private Network
(192.168.50.0/24)
Private Network
(192.168.110.0/24)
10.1.1.x/2410.1.1.x/24
EDGE
GATEWAY
IDS
Existing Security Policies & Appliances
IGW
Direct Connect –
Private Line
IPS
Cross Connect
CONFIDENTIAL 31
1 or 10 Gbps Direct Connect Traffic
DMZ Network
(192.168.52.0/24)
Private Network
(192.168.50.0/24)
Private Network
(192.168.110.0/24)
CUSTOMER CAGE
Direct Connect Line
EDGE
GATEWAY
Direct Connect – Extended Layer 2
CONFIDENTIAL 32
Internet
10.1.1.x/24
10.1.1.x/24
10.1.1.x/2410.1.1.x/24
Co-Lo cage
IDS
Existing Security Policies & Appliances
IGW
Direct Connect –
Private Line
IPS Direct
Access
Network
How about global
availability of applications?
Global Load Balancing – Dyn Example
CONFIDENTIAL
34
vCNS Virtual Server
192.240.153.11
vCNS Virtual Server
74.204.180.41
Virtual Private Cloud (West) Dedicated Cloud (East)
.11 .12 .11 .12
vCNS Pool Servers
192.168.109.11
192.168.109.12
vCNS Pool Servers
192.168.205.11
192.168.205.12
Traffic Director
INTERNET
DYN
Load Balancing
EDGE
GATEWAY
LB
EDGE
GATEWAY
LB
Advanced Networking - Hybrid Horizon View Logical
Architecture
WDC (On Premises)
EDGE
GATEWAY
EDGE
GATEWAY
(192.168.20.0/24
Public-NET)
IPSec VPNIPSec VPN
DT01 DT02
(192.168.3.0/24
Desktop-NET)
AD01
.41
AD02
.42
ViewCS
.5
vCloud Air Las Vegas
(IaaS)
ViewSS
.5
ViewSS
.5
(192.168.2.0/24
Public-NET)
view.vmtm.org
(192.168.1.0/24 Corp-NET)
66.45.200.37 69.194.137.139
PCoIP and Blast
vCloud Air and F5 – Global Load balancing
36
(192.168.100.0/24
Corp-NET)
AD05 AD06
(192.168.200.0/24
Public-NET)
(10.10.10.0/24 BIP-
Internal-NET)
BIP02
DNAT Any:Any
Firewall Any:Any
10.0.10.0/24
10.0.10.1
10.0.1.150
BIP02
INTERNET
EDGE
GATEWAY
..And what about network
security - IPS/IDS?
Trend Micro Based – IPS/IDS
CONFIDENTIAL 38
Firewall
Log
Inspection
Anti-Malware
Integrity
Monitoring
Web
Reputation
Intrusion
Prevention
Deep Security Manager and Relay
PROTECTION MODULES
Deep Security Database
MANAGEMENT
Protected VMs
Deep Security Manager
EDGE
GATEWAY
Deep Security
Agent
Database
vCloud Air – Security Solution via Trend Micro
CONFIDENTIAL 39
Choice of Networking Services Applications…
CONFIDENTIAL 40
Virtual
vCloud Air Recovery Service
“No.. No… the world was destroyed… this is a backup”
Recovery as a Service – Networking
Ø  How do I maintain the same network configs?
Ø  Do I need to re-do the network configs?
Ø  Do I need to ‘stretch’ my network?
Ø  How can I maintain my IP settings on VMs?
Disaster Recovery – Networking
•  Pre-create networks on DR cloud with same private IP space, name and relevant properties
•  When VMs are replicated, the IPs of the VMs are retaind
•  When a disaster occurs and VMs on the DR turn on, simply connect VMs to pre-existing
networks
43
WDC (On Premises)
DT01 DT02
(192.168.3.0/24
Desktop-NET)
AD01
.41
AD02
.42
ViewCS
.5
ViewSS
.5
(192.168.2.0/24
Public-NET)
(192.168.1.0/24 Corp-NET)
EDGE
GATEWAY
Replicate
EDGE
GATEWAY
(192.168.3.0/24
Desktop-NET)
(192.168.1.0/24 Corp-NET)
(192.168.2.0/24
Public-NET)
DR vDC
VMware vCloud Air - Virtual Private Cloud OnDemand
Interested in participating in the
vCloud Air OnDemand Beta
Progam?
The Product Team from vCloud Air is now
accepting candidates interested in participating
in the Fall 2014 beta program
44
Visit vmware.com/go/ondemand
to sign up
vmware.com/go/ondemand
VMware vCloud Air
5 Starting Points Program
VMworld 2014
45
Star%ng	
  Point	
   Session	
  ID	
   TOPIC
Dev/Test	
   HBC2577	
  
Hybrid	
  Sandboxing	
  –	
  Create	
  the	
  
Ul>mate	
  On	
  and	
  Off	
  Premises	
  Test/Dev	
  
Factory	
  
Extend	
  Exis>ng	
  
Applica>ons	
   HBC2066	
  
Architect	
  the	
  Hybrid	
  Cloud	
  for	
  
Exchange	
  and	
  Lync	
  
Disaster	
  Recovery	
   HBC	
  1534	
  
Recovery	
  as	
  a	
  Service	
  (RaaS)	
  with	
  
vCloud	
  Hybrid	
  Service	
  
Modernize	
  
Enterprise	
  
Applica>ons	
  
HBC	
  2609	
  
Smells	
  Like	
  Team	
  Spirit:	
  Achieve	
  Hybrid	
  
Opera>ons	
  Nirvana	
  with	
  vCloud	
  Hybrid	
  
Service	
  
Create	
  Next	
  
Genera>on	
  
Applica>ons	
  
HBC	
  1917	
  
Build	
  Your	
  First	
  Mobile	
  Applica>on…In	
  
the	
  Cloud…In	
  60	
  minutes	
  
Learn the fundamentals on vCloud Air
by attending any or all of our
5 Starting Point breakout sessions
within the Hybrid Cloud Track
45
Attend any of these breakout sessions and
earn a free vCloud Air “Dilbert” t-shirt.
Hybrid Cloud Hands On Labs
Check out the Expert Led and Self Paced vCloud Air Hands on Labs
CONFIDENTIAL 46
HOL: Expert-Led Workshop ELW-HBD-1481 Hybrid Cloud Jumpstart Workshop
HOL: Expert-Led Workshop ELW-HBD-1484 Disaster Recovery to the Cloud Workshop
HOL: Self Paced Lab SPL-HBD-1481 vCloud Hybrid Service - Jump Start for vSphere Admins
HOL: Self Paced Lab SPL-HBD-1482 vCloud Hybrid Service - Networking & Security
HOL: Self Paced Lab SPL-HBD-1483 vCloud Hybrid Service - Manage Your Cloud
Session ID Title Learn the fundamentals on
vCloud Air by attending any
or all of our 5 Starting Point
breakout sessions within the
Hybrid Cloud Track as well
as our Hands on Labs
Try any of these HOLs
and earn a free vCloud Air
“Dilbert” t-shirt.
Hybrid Cloud Theater Schedule - VMware Booth (Solutions Exchange)
47
In addition to the breakout
sessions within the Hybrid
Cloud track, check out our
THEATER schedule for the
week from the VMware
booth at the Solutions
Exchange
Sunday 5:00pm - What is this Hybrid Cloud Thing Anyway?
Monday 12:15pm - Getting Started with Hybrid Cloud - 5 Use Cases
Monday 1:30pm - vCloud Air OnDemand
Monday 3:45pm - What is this Hybrid Cloud Thing, Anyway?
Monday 5:30pm - Hybrid Cloud DevOps: How to keep your Devs from Running Wild
Tuesday 12:15pm - Project NEE - Delivering Hands-on Education at Cloud Scale
Tuesday 1:00pm - vCloud Air Network
Tuesday 2:45pm - Disaster Recovery with vCloud Air
Tuesday 4:00pm - Getting Started with Hybrid Cloud - 5 Use Cases
Tuesday 5:30pm - Hybrid Management on vCloud Air
Wednesday 10:15am - vCloud Air OnDemand
Wednesday 12:45pm - The Internet of Things: Virtual Machines, vCloud Air, vCenter Operations and
the Intel IoT Gateway
Wednesday 2:15pm - Disaster Recovery with vCloud Air
Wednesday 3:30pm - Another Day in Paradise....Going Full Hybrid with vCloud Air
Wednesday 4:30pm - RAD in the Hybrid Cloud
Thank You
Q&A
Thank You
Fill out a survey
Every completed survey is entered into a
drawing for a $25 VMware company store
gift certificate
vCloud Hybrid Service
Networking Technical
Deep Dive
HBC2068
Ninad Desai, VMware, Inc
David Hill, VMware, Inc

More Related Content

PDF
VMware NSX - Lessons Learned from real project
PDF
Software Defined Networking (SDN) with VMware NSX
PDF
Business Agility and Security with VMware
PDF
Sdc 2012-how-can-hypervisors-leverage-advanced-storage-features-v7.6(20-9-2012)
PDF
An Introduction to VMware NSX
PPTX
VMUGbe 21 Filip Verloy
PPTX
vSphere Container Storage
PDF
VMworld 2013: Virtualized Network Services Model with VMware NSX
VMware NSX - Lessons Learned from real project
Software Defined Networking (SDN) with VMware NSX
Business Agility and Security with VMware
Sdc 2012-how-can-hypervisors-leverage-advanced-storage-features-v7.6(20-9-2012)
An Introduction to VMware NSX
VMUGbe 21 Filip Verloy
vSphere Container Storage
VMworld 2013: Virtualized Network Services Model with VMware NSX

What's hot (20)

PDF
Network Virtualization with VMware NSX
PDF
VMworld 2013: vSphere Distributed Switch – Design and Best Practices
PPTX
VMworld 2015: Just Because You COULD, Doesn’t Mean You SHOULD – vSphere 6.0 A...
PPTX
Rearchitecting Storage for Server Virtualization
PDF
VMworld Europe 2014: Advanced Network Services with NSX
PDF
VMworld 2014: Virtualize your Network with VMware NSX
PDF
The Future of Cloud Networking is VMware NSX
PPTX
Cisco cloud computing deploying openstack
PDF
VMworld 2014: Introduction to NSX
PPTX
Nsx security deep dive
PPTX
Citrix Cloud Master Class June 2014
PPTX
Designing your xen desktop 7.5 environment with training guide
PPTX
Power vc for powervm deep dive tips & tricks
PDF
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
PDF
VMworld 2013: Advanced VMware NSX Architecture
PDF
VMworld 2013: Operational Best Practices for NSX in VMware Environments
PDF
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
PDF
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
PDF
UCS Automation through the use of API's and UCS PowerTool
PPT
Power systems virtualization with power kvm
Network Virtualization with VMware NSX
VMworld 2013: vSphere Distributed Switch – Design and Best Practices
VMworld 2015: Just Because You COULD, Doesn’t Mean You SHOULD – vSphere 6.0 A...
Rearchitecting Storage for Server Virtualization
VMworld Europe 2014: Advanced Network Services with NSX
VMworld 2014: Virtualize your Network with VMware NSX
The Future of Cloud Networking is VMware NSX
Cisco cloud computing deploying openstack
VMworld 2014: Introduction to NSX
Nsx security deep dive
Citrix Cloud Master Class June 2014
Designing your xen desktop 7.5 environment with training guide
Power vc for powervm deep dive tips & tricks
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
VMworld 2013: Advanced VMware NSX Architecture
VMworld 2013: Operational Best Practices for NSX in VMware Environments
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
UCS Automation through the use of API's and UCS PowerTool
Power systems virtualization with power kvm
Ad

Viewers also liked (20)

PPTX
IIJ GIOアカデミー / ハイブリッドクラウド(基礎編)
 
PDF
VMware vCloud Air: Networking
PPTX
【検証してみた】いま話題のVMware on IBM Cloud SoftLayer 配布版
PDF
Orange is v cloud 3
PDF
VMworld 2013: Moving Beyond Infrastructure: Meeting Demands on App Lifecycle ...
PDF
L2 over L3 ecnaspsulations
PPTX
VMworld 2015: vCloud Air 2015 – Getting Started with Hybrid Cloud
PDF
S10 日本東西リージョンでのディザスタ リカバリ環境の実現
PDF
S06 Azure バックアップを利用した Microsoft Azure 仮想マシンのバックアップ
PDF
GAMO VMware vCloud Air
PDF
EC2でkeepalived+LVS(DSR)
PPTX
vCloud Air - Infrastructure and Application Services for the Enterprise
PDF
VMware + IBM Cloudで広がるハイブリッド・クラウドの世界
PDF
リクルートにおけるVDI導入 ~働き方変革とセキュリティ向上の両立を目指して~
PDF
Aerospike on IDCF Cloud
PDF
AWS Blackbelt 2015シリーズ Amazon EC2 Windows インスタンス
PDF
AWS 初級トレーニング (Windows Server 2012編)
PPTX
SORACOM Bootcamp Rec5 - SORACOM Funnel
PDF
【ネットワーク仮想化 事例セミナー 2017/2/28】Juniper x VMware アンダーレイソリューション デモンストレーション
PPTX
VMworld 2016: The KISS of vRealize Operations!
IIJ GIOアカデミー / ハイブリッドクラウド(基礎編)
 
VMware vCloud Air: Networking
【検証してみた】いま話題のVMware on IBM Cloud SoftLayer 配布版
Orange is v cloud 3
VMworld 2013: Moving Beyond Infrastructure: Meeting Demands on App Lifecycle ...
L2 over L3 ecnaspsulations
VMworld 2015: vCloud Air 2015 – Getting Started with Hybrid Cloud
S10 日本東西リージョンでのディザスタ リカバリ環境の実現
S06 Azure バックアップを利用した Microsoft Azure 仮想マシンのバックアップ
GAMO VMware vCloud Air
EC2でkeepalived+LVS(DSR)
vCloud Air - Infrastructure and Application Services for the Enterprise
VMware + IBM Cloudで広がるハイブリッド・クラウドの世界
リクルートにおけるVDI導入 ~働き方変革とセキュリティ向上の両立を目指して~
Aerospike on IDCF Cloud
AWS Blackbelt 2015シリーズ Amazon EC2 Windows インスタンス
AWS 初級トレーニング (Windows Server 2012編)
SORACOM Bootcamp Rec5 - SORACOM Funnel
【ネットワーク仮想化 事例セミナー 2017/2/28】Juniper x VMware アンダーレイソリューション デモンストレーション
VMworld 2016: The KISS of vRealize Operations!
Ad

Similar to VMworld 2014: vCloud Hybrid Service Networking Technical Deep Dive (20)

PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
PDF
VMworld 2014: How I Learned to Stop Worrying and Love the Public Cloud
PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
PDF
Private cloud networking_cloudstack_days_austin
PPTX
Leveraging the Cloud for Continuous Delivery while Protecting your IP
PDF
Cisco Connect Toronto 2018 consuming public and private clouds
PDF
Openstack Summit Vancouver 2018 - Multicloud Networking
PDF
PDF
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
PPTX
Cloud Aggregation: Smart Access to a Smarter Cloud
PPTX
ServedBy the Net Products 2017
PDF
AWS VPC NOTES _ LEARN AWS EFFECTIVELY and Easily
PPTX
AWS Certified Solutions Architect Professional Course S6-S9
PDF
Criando o seu datacenter virtual vpc e conectividade
PDF
VMworld 2014: How to Build a Hybrid Cloud
PPTX
Public Cloud Security DIY @ IGT 2013
PDF
Cisco connect montreal 2018 vision mondiale analyse locale
PPTX
Introduction to AWS VPC & Networking
PDF
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
VMworld 2014: How I Learned to Stop Worrying and Love the Public Cloud
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
Private cloud networking_cloudstack_days_austin
Leveraging the Cloud for Continuous Delivery while Protecting your IP
Cisco Connect Toronto 2018 consuming public and private clouds
Openstack Summit Vancouver 2018 - Multicloud Networking
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cloud Aggregation: Smart Access to a Smarter Cloud
ServedBy the Net Products 2017
AWS VPC NOTES _ LEARN AWS EFFECTIVELY and Easily
AWS Certified Solutions Architect Professional Course S6-S9
Criando o seu datacenter virtual vpc e conectividade
VMworld 2014: How to Build a Hybrid Cloud
Public Cloud Security DIY @ IGT 2013
Cisco connect montreal 2018 vision mondiale analyse locale
Introduction to AWS VPC & Networking
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...

More from VMworld (20)

PPTX
VMworld 2016: vSphere 6.x Host Resource Deep Dive
PPTX
VMworld 2016: Troubleshooting 101 for Horizon
PPTX
VMworld 2016: Advanced Network Services with NSX
PPTX
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
PPTX
VMworld 2016: Enforcing a vSphere Cluster Design with PowerCLI Automation
PPTX
VMworld 2016: What's New with Horizon 7
PPTX
VMworld 2016: Virtual Volumes Technical Deep Dive
PPTX
VMworld 2016: Advances in Remote Display Protocol Technology with VMware Blas...
PPTX
VMworld 2016: Getting Started with PowerShell and PowerCLI for Your VMware En...
PPTX
VMworld 2016: Ask the vCenter Server Exerts Panel
PPTX
VMworld 2016: Virtualize Active Directory, the Right Way!
PPTX
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
PPTX
VMworld 2015: Troubleshooting for vSphere 6
PPTX
VMworld 2015: Monitoring and Managing Applications with vRealize Operations 6...
PPTX
VMworld 2015: Advanced SQL Server on vSphere
PPTX
VMworld 2015: Virtualize Active Directory, the Right Way!
PPTX
VMworld 2015: Site Recovery Manager and Policy Based DR Deep Dive with Engine...
PPTX
VMworld 2015: Building a Business Case for Virtual SAN
PPTX
VMworld 2015: Explaining Advanced Virtual Volumes Configurations
PPTX
VMworld 2015: Virtual Volumes Technical Deep Dive
VMworld 2016: vSphere 6.x Host Resource Deep Dive
VMworld 2016: Troubleshooting 101 for Horizon
VMworld 2016: Advanced Network Services with NSX
VMworld 2016: How to Deploy VMware NSX with Cisco Infrastructure
VMworld 2016: Enforcing a vSphere Cluster Design with PowerCLI Automation
VMworld 2016: What's New with Horizon 7
VMworld 2016: Virtual Volumes Technical Deep Dive
VMworld 2016: Advances in Remote Display Protocol Technology with VMware Blas...
VMworld 2016: Getting Started with PowerShell and PowerCLI for Your VMware En...
VMworld 2016: Ask the vCenter Server Exerts Panel
VMworld 2016: Virtualize Active Directory, the Right Way!
VMworld 2016: Migrating from a hardware based firewall to NSX to improve perf...
VMworld 2015: Troubleshooting for vSphere 6
VMworld 2015: Monitoring and Managing Applications with vRealize Operations 6...
VMworld 2015: Advanced SQL Server on vSphere
VMworld 2015: Virtualize Active Directory, the Right Way!
VMworld 2015: Site Recovery Manager and Policy Based DR Deep Dive with Engine...
VMworld 2015: Building a Business Case for Virtual SAN
VMworld 2015: Explaining Advanced Virtual Volumes Configurations
VMworld 2015: Virtual Volumes Technical Deep Dive

Recently uploaded (20)

PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Empathic Computing: Creating Shared Understanding
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Diabetes mellitus diagnosis method based random forest with bat algorithm
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
20250228 LYD VKU AI Blended-Learning.pptx
MIND Revenue Release Quarter 2 2025 Press Release
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Digital-Transformation-Roadmap-for-Companies.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?
Machine learning based COVID-19 study performance prediction
Programs and apps: productivity, graphics, security and other tools
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Review of recent advances in non-invasive hemoglobin estimation
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Empathic Computing: Creating Shared Understanding

VMworld 2014: vCloud Hybrid Service Networking Technical Deep Dive

  • 1. vCloud Hybrid Service Networking Technical Deep Dive HBC2068 Ninad Desai, VMware, Inc David Hill, VMware, Inc
  • 2. Disclaimer •  This presentation may contain product features that are currently under development. •  This overview of new technology represents no commitment from VMware to deliver these features in any generally available product. •  Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind. •  Technical feasibility and market demand will affect final delivery. •  Pricing and packaging for any new technologies or features discussed or presented have not been determined. CONFIDENTIAL 2
  • 6. What is vCloud Air Network Services built on??
  • 7. vCloud Air Networking – Built on vCNS …. Moving to NSX Fully Integrated vCloud Stack vCloud Management and Automation vCloud Air Management Console vCloud Infrastructure vCloud Networking and Security vCloud Director with vCloud Connector vSphere / vCenter Customer A Physically Isolated Servers Storage pool VPN and Network pool … Dedicated Cloud •  Being replaced by NSX-v manager in the vCloud Air Management stack •  Backward compatible with current vCNS based stack •  Existing policies and features stay intact •  Foundation for new networking features
  • 8. How do I connect to vCloud Air ?
  • 9. Options to Connect to vCloud Air z Customer Data Center vCloud Air Private WAN / Direct Connect / Cross Connect IPsec Tunnel Public INTERNET Many Connectivity Choices To Support Many Use Cases
  • 10. INTERNET INTERNET Connecting to vCloud Air •  Over the Public Internet –  With Public IPs –  Use NAT for address translation –  By default F/W set to deny all and NAT not configured INTERNET •  IPsec VPN –  vCloud Air features include IPsec VPN –  Multiple VPN tunnels can terminate to Edge Gateway –  Can connect to most of the major on-prem VPN devices •  Direct Connect –  Dedicated private connection –  Secure and high speed –  Extension to customer’s MPLS or data center cage
  • 11. Connecting via IPsec VPN CONFIDENTIAL VPN Traffic INTERNET vSphere Edge Gateway §  LEP – 10.0.1.150 §  Peer ID – 69.194.137.230 §  Peer IP – 69.194.137.230 10.0.10.0/24 10.0.10.1 10.0.1.150 10.0.1.1 68.108.102.47 IP Protocol ID 50 (ESP) IP Protocol ID 51 (AH) UDP Port 500 (IKE) UDP Port 4500 69.194.137.230 192.168.109.2/24 192.168.109.1 Edge Gateway §  LEP – 69.194.137.230 §  Peer ID – 10.0.1.150 §  Peer IP – 68.108.102.47 EDGE GATEWAY EDGE GATEWAY
  • 13. vCloud Air - Options and Gateway Choices.. CONFIDENTIAL 13 §  Shared Cloud •  Logically separated network, compute and storage §  5GHz CPU (burstable to 10GHz) §  20GB RAM, 2TB storage §  No vDC segmentation §  One Edge Gateway §  Dedicated Cloud •  Physically separated hosts •  Logically separated network and storage §  30GHz CPU, 120GB RAM, 6TB §  Segment vDCs based on orgs §  Multiple Edge Gateways VDC1 VDC2 VDC3 VDC4 VDC
  • 14. vCloud Air Basic Networking Constructs INTERNET Routed/Gateway Networks (up to 9 networks) Isolated Network External Network (managed by VMware) NAT FW Load Balancer IPsec DHCP Static routing Customers vDC EDGE GATEWAY
  • 15. Configuration Access Options CONFIDENTIAL 15 vCloud Air Management Web Portal - For basic networking configurations
  • 16. Configuration Access Options CONFIDENTIAL 16 vCloud Air Management Web Portal - For basic networking configurations For Advanced configurations
  • 17. Configuration Access Options CONFIDENTIAL 17 vCloud Director management portal - For advanced networking configs
  • 18. Can I bring my Private IP space along?
  • 19. Yes! Via Network Address Translation (NAT) •  Need to create F/W rules to allow traffic •  IPv4 NAT •  Source NAT & Destination NAT rules. –  Supports multiple rules on multiple interfaces •  Can use internal/private IP space –  Bring your own internal IP space –  Create/Manage subnets within IP space –  Multiple IP space under the same gateway NAT rules: -  SNAT & DNAT rules -  Options include protocol/port selection Gateway Public IPs Internal IPs 10.x.x.x 172.16.x.x 192.168.x.x Organization Net 1 Organization Net 2 Organization Net 3 EDGE GATEWAY
  • 20. But …. Can I stretch my Layer 2 network on to vCloud Air?
  • 21. vCloud Connector Data Center L2 Extension CONFIDENTIAL 21 (192.168.50.0/24) 184.61.71.155 74.204.180.41 VPN Traffic INTERNET (192.168.50.0/24) Default Gateway = 192.168.50.10 50.34 50.35 50.36 50.37 50.33 100.33 (192.168.50.0/24) 50.10 100.10 SSL SSL EDGE GATEWAY EDGE GATEWAY EDGE GATEWAY Corp Firewall
  • 22. Layer 2 Extensions – Updated with NSX vCloud Air INTERNET INTERNET VLAN 10 VLAN 11 SSL Client Default Router vNIC Trunk VLAN 10-11 Site A: Non-NSX VLAN Backed Network L3 Network, VPN, Direct Connect EDGE GATEWAY (NSX) vCloud Air Client
  • 23. Okay.. So I have a typical multi-tier app (LAMP/WAMP stack)…. Can I bring it to vCloud Air?
  • 24. Firewall for Multi-Tier Applications Web tier App tier DB Tier INTERNET Firewall •  5 Tuple F/W policies –  Protocol, Source/Dest. IP, Source/Dest. Port •  Stateful Firewall •  FIPS-140-2 Crypto •  Common Criteria EAL 4 Load Balancing •  VIP and pool servers •  Health check Load Balancing Server Pool VIP: 66.44.4.1 EDGE GATEWAY
  • 26. Direct Connect – Use Cases 26 Ø  Can I have a private connection to vCloud Air? Ø  Can vCloud Air be part of my MPLS connection? Ø  Can I cross connect in to vCloud Air? Ø  Can I extend my layer 2 network on to this direct connect interface?
  • 27. vCloud Air Direct Connect Customer Co-Lo Cage vCloud Air Data Center owner operated/ managed vCloud Air connection point Customer Data Center vCloud Air NSP connection (MPLS, E-Line etc.) vCloud Air managed vCloud Air managed Cross connect use case WAN connectivity use case vCloud Air connection point
  • 28. Direct Connect – With vCloud Air 28 DMZ Network (192.168.52.0/24) Private Network (192.168.50.0/24) Private Network (192.168.100.x/24) Headquarters NSP termination point EDGE GATEWAY INTERNET vCloud Air Connection point MDF/MMR Untagged Layer 2 connection (1G, 10G) 10.2.2.2 10.2.2.1 MPLS (from NSP) Private Network (192.168.50.0/24) Branch office 10.2.2..x/24 10.1.1.x/24 10.3.3.x/24
  • 29. Direct Connect – With vCloud Air 29 DMZ Network (192.168.52.0/24) Private Network (192.168.50.0/24) Private Network (192.168.50.x/24) Headquarters NSP termination point EDGE GATEWAY INTERNET vCloud Air Connection point MDF/MMR Untagged Layer 2 connection (1G, 10G) 10.2.2.2 10.2.2.1 MPLS (from NSP) Private Network (192.168.50.0/24) Branch office 10.2.2..x/24 10.1.1.x/24 10.3.3.x/24
  • 30. Direct Connect – Using Existing Security CONFIDENTIAL 30 1 Gbps / 10 Gbps Direct Connect Traffic DMZ Network (192.168.52.0/24) Internet Private Network (192.168.50.0/24) Private Network (192.168.110.0/24) 10.1.1.x/2410.1.1.x/24 EDGE GATEWAY IDS Existing Security Policies & Appliances IGW Direct Connect – Private Line IPS
  • 31. Cross Connect CONFIDENTIAL 31 1 or 10 Gbps Direct Connect Traffic DMZ Network (192.168.52.0/24) Private Network (192.168.50.0/24) Private Network (192.168.110.0/24) CUSTOMER CAGE Direct Connect Line EDGE GATEWAY
  • 32. Direct Connect – Extended Layer 2 CONFIDENTIAL 32 Internet 10.1.1.x/24 10.1.1.x/24 10.1.1.x/2410.1.1.x/24 Co-Lo cage IDS Existing Security Policies & Appliances IGW Direct Connect – Private Line IPS Direct Access Network
  • 33. How about global availability of applications?
  • 34. Global Load Balancing – Dyn Example CONFIDENTIAL 34 vCNS Virtual Server 192.240.153.11 vCNS Virtual Server 74.204.180.41 Virtual Private Cloud (West) Dedicated Cloud (East) .11 .12 .11 .12 vCNS Pool Servers 192.168.109.11 192.168.109.12 vCNS Pool Servers 192.168.205.11 192.168.205.12 Traffic Director INTERNET DYN Load Balancing EDGE GATEWAY LB EDGE GATEWAY LB
  • 35. Advanced Networking - Hybrid Horizon View Logical Architecture WDC (On Premises) EDGE GATEWAY EDGE GATEWAY (192.168.20.0/24 Public-NET) IPSec VPNIPSec VPN DT01 DT02 (192.168.3.0/24 Desktop-NET) AD01 .41 AD02 .42 ViewCS .5 vCloud Air Las Vegas (IaaS) ViewSS .5 ViewSS .5 (192.168.2.0/24 Public-NET) view.vmtm.org (192.168.1.0/24 Corp-NET) 66.45.200.37 69.194.137.139 PCoIP and Blast
  • 36. vCloud Air and F5 – Global Load balancing 36 (192.168.100.0/24 Corp-NET) AD05 AD06 (192.168.200.0/24 Public-NET) (10.10.10.0/24 BIP- Internal-NET) BIP02 DNAT Any:Any Firewall Any:Any 10.0.10.0/24 10.0.10.1 10.0.1.150 BIP02 INTERNET EDGE GATEWAY
  • 37. ..And what about network security - IPS/IDS?
  • 38. Trend Micro Based – IPS/IDS CONFIDENTIAL 38 Firewall Log Inspection Anti-Malware Integrity Monitoring Web Reputation Intrusion Prevention Deep Security Manager and Relay PROTECTION MODULES Deep Security Database MANAGEMENT Protected VMs Deep Security Manager EDGE GATEWAY Deep Security Agent Database
  • 39. vCloud Air – Security Solution via Trend Micro CONFIDENTIAL 39
  • 40. Choice of Networking Services Applications… CONFIDENTIAL 40 Virtual
  • 41. vCloud Air Recovery Service “No.. No… the world was destroyed… this is a backup”
  • 42. Recovery as a Service – Networking Ø  How do I maintain the same network configs? Ø  Do I need to re-do the network configs? Ø  Do I need to ‘stretch’ my network? Ø  How can I maintain my IP settings on VMs?
  • 43. Disaster Recovery – Networking •  Pre-create networks on DR cloud with same private IP space, name and relevant properties •  When VMs are replicated, the IPs of the VMs are retaind •  When a disaster occurs and VMs on the DR turn on, simply connect VMs to pre-existing networks 43 WDC (On Premises) DT01 DT02 (192.168.3.0/24 Desktop-NET) AD01 .41 AD02 .42 ViewCS .5 ViewSS .5 (192.168.2.0/24 Public-NET) (192.168.1.0/24 Corp-NET) EDGE GATEWAY Replicate EDGE GATEWAY (192.168.3.0/24 Desktop-NET) (192.168.1.0/24 Corp-NET) (192.168.2.0/24 Public-NET) DR vDC
  • 44. VMware vCloud Air - Virtual Private Cloud OnDemand Interested in participating in the vCloud Air OnDemand Beta Progam? The Product Team from vCloud Air is now accepting candidates interested in participating in the Fall 2014 beta program 44 Visit vmware.com/go/ondemand to sign up vmware.com/go/ondemand
  • 45. VMware vCloud Air 5 Starting Points Program VMworld 2014 45 Star%ng  Point   Session  ID   TOPIC Dev/Test   HBC2577   Hybrid  Sandboxing  –  Create  the   Ul>mate  On  and  Off  Premises  Test/Dev   Factory   Extend  Exis>ng   Applica>ons   HBC2066   Architect  the  Hybrid  Cloud  for   Exchange  and  Lync   Disaster  Recovery   HBC  1534   Recovery  as  a  Service  (RaaS)  with   vCloud  Hybrid  Service   Modernize   Enterprise   Applica>ons   HBC  2609   Smells  Like  Team  Spirit:  Achieve  Hybrid   Opera>ons  Nirvana  with  vCloud  Hybrid   Service   Create  Next   Genera>on   Applica>ons   HBC  1917   Build  Your  First  Mobile  Applica>on…In   the  Cloud…In  60  minutes   Learn the fundamentals on vCloud Air by attending any or all of our 5 Starting Point breakout sessions within the Hybrid Cloud Track 45 Attend any of these breakout sessions and earn a free vCloud Air “Dilbert” t-shirt.
  • 46. Hybrid Cloud Hands On Labs Check out the Expert Led and Self Paced vCloud Air Hands on Labs CONFIDENTIAL 46 HOL: Expert-Led Workshop ELW-HBD-1481 Hybrid Cloud Jumpstart Workshop HOL: Expert-Led Workshop ELW-HBD-1484 Disaster Recovery to the Cloud Workshop HOL: Self Paced Lab SPL-HBD-1481 vCloud Hybrid Service - Jump Start for vSphere Admins HOL: Self Paced Lab SPL-HBD-1482 vCloud Hybrid Service - Networking & Security HOL: Self Paced Lab SPL-HBD-1483 vCloud Hybrid Service - Manage Your Cloud Session ID Title Learn the fundamentals on vCloud Air by attending any or all of our 5 Starting Point breakout sessions within the Hybrid Cloud Track as well as our Hands on Labs Try any of these HOLs and earn a free vCloud Air “Dilbert” t-shirt.
  • 47. Hybrid Cloud Theater Schedule - VMware Booth (Solutions Exchange) 47 In addition to the breakout sessions within the Hybrid Cloud track, check out our THEATER schedule for the week from the VMware booth at the Solutions Exchange Sunday 5:00pm - What is this Hybrid Cloud Thing Anyway? Monday 12:15pm - Getting Started with Hybrid Cloud - 5 Use Cases Monday 1:30pm - vCloud Air OnDemand Monday 3:45pm - What is this Hybrid Cloud Thing, Anyway? Monday 5:30pm - Hybrid Cloud DevOps: How to keep your Devs from Running Wild Tuesday 12:15pm - Project NEE - Delivering Hands-on Education at Cloud Scale Tuesday 1:00pm - vCloud Air Network Tuesday 2:45pm - Disaster Recovery with vCloud Air Tuesday 4:00pm - Getting Started with Hybrid Cloud - 5 Use Cases Tuesday 5:30pm - Hybrid Management on vCloud Air Wednesday 10:15am - vCloud Air OnDemand Wednesday 12:45pm - The Internet of Things: Virtual Machines, vCloud Air, vCenter Operations and the Intel IoT Gateway Wednesday 2:15pm - Disaster Recovery with vCloud Air Wednesday 3:30pm - Another Day in Paradise....Going Full Hybrid with vCloud Air Wednesday 4:30pm - RAD in the Hybrid Cloud
  • 50. Fill out a survey Every completed survey is entered into a drawing for a $25 VMware company store gift certificate
  • 51. vCloud Hybrid Service Networking Technical Deep Dive HBC2068 Ninad Desai, VMware, Inc David Hill, VMware, Inc