SlideShare uma empresa Scribd logo
1 de 20
Copyright 2015 Alcatel-Lucent. All rights reserved.
Branching out with SDN
Alastair JOHNSON
Using SDN to build L2/L3VPNs
March 2015
Copyright 2015 Alcatel-Lucent. All rights reserved.
Agenda
1. Introduction
2. Technology recap
a. VXLAN
b. EVPN
3. Putting it together
4. Comparison
5. Conclusion
3/2/2015
2
Copyright 2015 Alcatel-Lucent. All rights reserved.
Introduction
 Software Defined Networking has significantly changed the
way that networking is deployed in some environments
 Research facilities, datacenters, etc
 Gaining traction in other parts of the network (core/edge, etc)
 SDN is about abstraction and separation of control and
forwarding functions, and the separation of hardware and
software
 It offers new ways of thinking about existing ways of working
3
3/2/2015
Copyright 2015 Alcatel-Lucent. All rights reserved.
 Decoupled architecture means each
vendor can focus on his strengths
 Decreased barrier to entry for startups
provides multiple choices for customers
 Feature stability, long hardware cycles do
not affect software features
Management, Policy
Hardware
OS
Controller
HardwareHardware
Software Defined Networking
4
28-Feb-15
Copyright 2015 Alcatel-Lucent. All rights reserved.
Introduction
 The WAN space has been relatively unchanged for the better part
of 15 years
 IP-VPNs are fundamentally the same as they were in 2000
 RFC2547 published March 1999
 L2VPNs are fundamentally the same as they were in 2007
 The CPE has remained unchanged for the same period of time
 Basically still the same device: vertically integrated hardware and software,
running routing protocols and a variety of LAN/WAN interfaces
 Maybe a little bit faster than it used to be
3/2/2015
5
Copyright 2015 Alcatel-Lucent. All rights reserved.
Software Defined VPN (SD-VPN)
 What if there was a new way of thinking about VPN services
which embraces the smart edge dumb core philosophy?
 What if there was a way to change the CPE paradigm?
 What if there was a way to transport L2 services over any L3
network?
 What if there was a way to do this operationally efficiently?
3/2/2015
6
Copyright 2015 Alcatel-Lucent. All rights reserved.
Technology recap: VXLAN
 VXLAN encapsulates Ethernet in IP
 Runs over IPv4 or IPv6
 Uses UDP, source port is a hash of MAC or IPs to provide load
balancing entropy
 8 byte VXLAN header provides 24 bit VXLAN Network
Identifier (VNI) and flags
 Total encapsulation overhead is ~50 bytes
 VXLAN is routable with IP, so the underlay network may
be any network that uses existing resiliency and load
balancing mechanisms
 ECMP
 IGPs/BGP
 IP FRR
 VXLAN tunnel endpoints can be on network equipment or
computing infrastructure
 Deliver a VPN straight to a hypervisor
IP Network
(IP FRR, ECMP, IGP)
IP Network
IP Network
Copyright 2015 Alcatel-Lucent. All rights reserved.
Data
Plane
Control
Plane
EVPN MP-BGP
draft-ietf-l2vpn-evpn
Technology Recap: EVPN
 EVPN over MPLS for VLL, VPLS
and E-Tree services
 All-active multihoming for VPWS
 RSVP-TE or LDP MPLS protocols
 EVPN with PBB PE functionality
for scaling very large networks
over MPLS
 All-active multihoming for PBB-
VPLS
 EVPN over NVO tunnels (VXLAN,
NVGRE, MPLSoGRE) for data
center fabric encapsulations
 Provides Layer 2 and Layer 3 DCI
Multiprotocol
Label Switching
(MPLS)
draft-ietf-l2vpn-evpn
Provider
Backbone Bridges
(PBB)
draft-ietf-l2vpn-pbb-evpn
Network
Virtualization Overlay
(NVO)
draft-sd-l2vpn-evpn-overlay
Copyright 2015 Alcatel-Lucent. All rights reserved.
Technology Recap: EVPN
 Brings proven and inherent BGP control plane scalability to MAC
routes
 Consistent signaled FDB in any size network instead of flooding
 Even more scalability and hierarchy with route reflectors
 BGP advertises MACs and IPs for next hop resolution with EVPN
NLRI
 AFI = 25 (L2VPN) and SAFI = 70 (EVPN)
 Fully supports IPv4 and IPv6 in the control and data plane
 Offers greater control over MAC learning
 What is signaled, from where and to whom
 Ability to apply MAC learning policies
 Maintains virtualization and isolation of EVPN instances
 Enables traffic load balancing for multihomed CEs with ECMP
MAC routes
Route Distinguisher (8 octets)
Ethernet Segment Identifier (10 octets)
Ethernet Tag ID (4 octets)
MAC Address Length (1 octet)
MAC Address (6 octets)
IP Address Length (1 octet)
IP Address (0 or 4 or 16 octets)
MPLS Label1 (3 octets)
MPLS Label2 (0 or 3 octets)
MAC Advertisement Route
(Light Green Fields are Optional)
Copyright 2015 Alcatel-Lucent. All rights reserved.
Putting it together
 EVPN delivers a control plane that can distribute MAC (L2) and IP (L3)
reachability information
 Scale is addressed: BGP has proven to scale well; federation becomes straight-
forward
 Control is addressed: programmatic network topology, flexibility of routing
policies
 Efficiency is addressed: hybrid L2/L3 services over a single interface,
redundancy and multi-homing included
 VXLAN delivers a data plane that can deliver Ethernet frames over an L3
transport
 L2VPN, L3VPN, …the Internet
3/2/2015
10
Copyright 2015 Alcatel-Lucent. All rights reserved.
A new way of delivering VPNs
 Controller programs forwarding
plane for all CPEs
 Aware of all L2/L3 topology behind
each CPE
 Calculate once, program many
 CPE performs encapsulation of VPN
traffic (VXLAN)
 Traffic is carried encapsulated over
underlay network
 Underlay network could be any
infrastructure
 Unaware of topology of VPN service
CPE
Site 1
LAN
CPE
Site 3
LAN
CPE
Site 2
LAN
Underlay
Policy DB
SDN
Controllers
SP Central
Functions
Copyright 2015 Alcatel-Lucent. All rights reserved.
A new way of delivering VPNs
 OpenFlow provides a mechanism to program
the L2/L3 forwarding information base (FIB)
and provide notifications to the controller
 MAC/IP address learning on LAN ports are
alerted to the controller
 Controller determines whether the MAC/IP is
to be programmed into FIB
 Federation of topology between controllers
via BGP-EVPN
 MAC and IP reachability signaled
 VXLAN VNI information combined with
NEXT_HOP
 Redundancy of controllers is supported – CPE
vSwitch registers and determines
active/standby controllers
12
3/2/2015
CPE
SDN
Controller
OpenFlow
OVSDB
BGP EVPN
10.0.0.0/24 10.1.0.0/24
Copyright 2015 Alcatel-Lucent. All rights reserved.
A new way of delivering VPNs
 CPE forward directly between
each other using VXLAN as
overlay
 10.0.0.0/24 NEXT_HOP 192.0.2.1
VNI xyz
 10.1.0.0/24 NEXT_HOP 192.0.2.3
VNI xyz
 Underlay network sees VXLAN
traffic between endpoints
 Dataplane can be further
encapsulated for confidentiality
(e.g. IPsec)
13
3/2/2015
10.0.0.0/24 10.1.0.0/24
192.0.2.1 192.0.2.3
Copyright 2015 Alcatel-Lucent. All rights reserved.
VPN Flexibility
 Overlays simplify network
topology
 SP network needs to know less
about customer topology
 Increases flexibility of delivery
– L2 services over L3, On Net,
Off Net, Internet, etc
 Provisioning simplified
 Reuse of activation processes
from broadband networks
14
3/2/2015
VRF VRF
Many provisioning touch points
BGP
Routing Policy
RIB scale Failover Redundancy
LAN ports
WAN ports
Aggregation network
GRT GRT
Dynamic
Provisioning
One-time Provisioning
Copyright 2015 Alcatel-Lucent. All rights reserved.
Overlays enable service chaining
 Centralized policy enforcement
 Firewall
 Between zones/subnets/branch types
 Extranet applications
 To Internet through central functions
 Content filtering
 Selective content filtering (schools –
teacher/student; public WiFi in retail
environments bypasses)
 Network analytics and monitoring
 Tap and mirror
 IDS/IDP
 DPI and DLP
3/2/2015
15
LAN
WAN
CPE DC
LAN CPE
LAN
WAN
CPE
DC
LAN CPE
Copyright 2015 Alcatel-Lucent. All rights reserved.
Interworking
How do I connect the new to the
existing?
1. EVPN with VXLAN termination
direct into existing MPLS PE routers
 End-to-end network is BGP and
VXLAN aware allowing for PE routers
to act as VXLAN/MPLS interworking
function
 Streamlined and simplified routing
2. Use CPE as gateway
 Break VXLAN services out to Ethernet
VLANs at PE router
 Faster to deploy but less flexible
16
3/2/2015
GRT
VRF
Internet IP/MPLS
VRF
VRF
Internet
IP/MPLS
VRF
Traditional VPN environmentOverlay VPN Environment IWF
Traditional VPN environmentOverlay VPN Environment
Copyright 2015 Alcatel-Lucent. All rights reserved.
Comparison
Traditional VPN model
• Well understood and widely
deployed
• Expensive to maintain and scale
• Inflexible for “cloud scale” service
consumption
• Constrained by network reach
• Service chaining challenging to
deploy
Overlay VPN model
• New approach to networking that is
being aggressively proven in
datacenters
• Centralized control model reduces
direct operational cost
• Scales to cloud: speed, flexibility
• Service providers can extend services
out of network footprint and effectively
use all network assets
• Natively enables service-chaining
17
3/2/2015
Copyright 2015 Alcatel-Lucent. All rights reserved.
Conclusion
 SDN as a technology has now found proven deployment use-
cases that make sense
 Not just experiments or ‘doing the same thing but differently’
 Real service provider use-cases exist for leveraging the same
technology as deployed in datacenters
 Speed, flexibility, optimization of network service delivery points
3/2/2015
18
Copyright 2015 Alcatel-Lucent. All rights reserved.
nuagenetworks.net/vns @nuagenetworks
Copyright 2015 Alcatel-Lucent. All rights reserved.
References
 VXLAN
 RFC7348
 BGP MPLS-Based Ethernet VPN
 RFC7209
 RFC7432
 Greg Hankins’ NANOG presentation
 OpenVSwitch
3/2/2015
20

Mais conteúdo relacionado

Mais procurados

Operationalizing EVPN in the Data Center: Part 2
Operationalizing EVPN in the Data Center: Part 2Operationalizing EVPN in the Data Center: Part 2
Operationalizing EVPN in the Data Center: Part 2Cumulus Networks
 
Access Network Evolution
Access Network Evolution Access Network Evolution
Access Network Evolution Cisco Canada
 
Designing Multi-tenant Data Centers Using EVPN
Designing Multi-tenant Data Centers Using EVPNDesigning Multi-tenant Data Centers Using EVPN
Designing Multi-tenant Data Centers Using EVPNAnas
 
VXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksVXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksAPNIC
 
Waris l2vpn-tutorial
Waris l2vpn-tutorialWaris l2vpn-tutorial
Waris l2vpn-tutorialrakiva29
 
MPLS-TP (MPLS Transport Profile)
MPLS-TP (MPLS Transport Profile)MPLS-TP (MPLS Transport Profile)
MPLS-TP (MPLS Transport Profile)Shivlu Jain
 
Application Engineered Routing Enables Applications and Network Infrastructur...
Application Engineered Routing Enables Applications and Network Infrastructur...Application Engineered Routing Enables Applications and Network Infrastructur...
Application Engineered Routing Enables Applications and Network Infrastructur...Cisco Service Provider
 
Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN
Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLANFlexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN
Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLANCisco Canada
 
Advanced Topics and Future Directions in MPLS
Advanced Topics and Future Directions in MPLS Advanced Topics and Future Directions in MPLS
Advanced Topics and Future Directions in MPLS Cisco Canada
 
Multi-Protocol Label Switching
Multi-Protocol Label SwitchingMulti-Protocol Label Switching
Multi-Protocol Label Switchingseanraz
 
An introduction to MPLS networks and applications
An introduction to MPLS networks and applicationsAn introduction to MPLS networks and applications
An introduction to MPLS networks and applicationsShawn Zandi
 
Cisco Packet Transport Network – MPLS-TP
Cisco Packet Transport Network – MPLS-TPCisco Packet Transport Network – MPLS-TP
Cisco Packet Transport Network – MPLS-TPCisco Canada
 
Dont forget-the-control-plane
Dont forget-the-control-planeDont forget-the-control-plane
Dont forget-the-control-planeMetaswitch NTD
 

Mais procurados (20)

Operationalizing EVPN in the Data Center: Part 2
Operationalizing EVPN in the Data Center: Part 2Operationalizing EVPN in the Data Center: Part 2
Operationalizing EVPN in the Data Center: Part 2
 
Access Network Evolution
Access Network Evolution Access Network Evolution
Access Network Evolution
 
Designing Multi-tenant Data Centers Using EVPN
Designing Multi-tenant Data Centers Using EVPNDesigning Multi-tenant Data Centers Using EVPN
Designing Multi-tenant Data Centers Using EVPN
 
VXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building BlocksVXLAN BGP EVPN: Technology Building Blocks
VXLAN BGP EVPN: Technology Building Blocks
 
Waris l2vpn-tutorial
Waris l2vpn-tutorialWaris l2vpn-tutorial
Waris l2vpn-tutorial
 
Cisco MPLS
Cisco MPLSCisco MPLS
Cisco MPLS
 
MPLS-TP (MPLS Transport Profile)
MPLS-TP (MPLS Transport Profile)MPLS-TP (MPLS Transport Profile)
MPLS-TP (MPLS Transport Profile)
 
Application Engineered Routing Enables Applications and Network Infrastructur...
Application Engineered Routing Enables Applications and Network Infrastructur...Application Engineered Routing Enables Applications and Network Infrastructur...
Application Engineered Routing Enables Applications and Network Infrastructur...
 
MPLS ppt
MPLS pptMPLS ppt
MPLS ppt
 
Doc6 mpls vpn-ppt
Doc6 mpls vpn-pptDoc6 mpls vpn-ppt
Doc6 mpls vpn-ppt
 
10 fn s22
10 fn s2210 fn s22
10 fn s22
 
MPLS Tutorial
MPLS TutorialMPLS Tutorial
MPLS Tutorial
 
Seamless mpls
Seamless mpls Seamless mpls
Seamless mpls
 
Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN
Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLANFlexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN
Flexible Data Centre Fabric - FabricPath/TRILL, OTV, LISP and VXLAN
 
Advanced Topics and Future Directions in MPLS
Advanced Topics and Future Directions in MPLS Advanced Topics and Future Directions in MPLS
Advanced Topics and Future Directions in MPLS
 
Multi-Protocol Label Switching
Multi-Protocol Label SwitchingMulti-Protocol Label Switching
Multi-Protocol Label Switching
 
An introduction to MPLS networks and applications
An introduction to MPLS networks and applicationsAn introduction to MPLS networks and applications
An introduction to MPLS networks and applications
 
Cisco Packet Transport Network – MPLS-TP
Cisco Packet Transport Network – MPLS-TPCisco Packet Transport Network – MPLS-TP
Cisco Packet Transport Network – MPLS-TP
 
Mpls
MplsMpls
Mpls
 
Dont forget-the-control-plane
Dont forget-the-control-planeDont forget-the-control-plane
Dont forget-the-control-plane
 

Semelhante a Branching out with SDN

PLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data Center
PLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data CenterPLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data Center
PLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data CenterPROIDEA
 
Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)
Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)
Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)Gade Gowtham
 
International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)IJERD Editor
 
PLNOG 13: Nicolai van der Smagt: SDN
PLNOG 13: Nicolai van der Smagt: SDNPLNOG 13: Nicolai van der Smagt: SDN
PLNOG 13: Nicolai van der Smagt: SDNPROIDEA
 
evpn_in_service_provider_network-web.pdf
evpn_in_service_provider_network-web.pdfevpn_in_service_provider_network-web.pdf
evpn_in_service_provider_network-web.pdfThanhTrungBui5
 
Presentation on ccna
Presentation on ccnaPresentation on ccna
Presentation on ccnaRahul Kumar
 
Presentation on ccna
Presentation on ccnaPresentation on ccna
Presentation on ccnaRahul Kumar
 
Evolucion redes troncales_convergentes
Evolucion redes troncales_convergentesEvolucion redes troncales_convergentes
Evolucion redes troncales_convergentesTELECOM I+D
 
Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...
Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...
Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...ADVA
 

Semelhante a Branching out with SDN (20)

PLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data Center
PLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data CenterPLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data Center
PLNOG 13: Emil Gągała: EVPN – rozwiązanie nie tylko dla Data Center
 
Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)
Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)
Mondaygeneralhankinsvpn2 140605100226-phpapp01 (1)
 
International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)
 
Mpls vpn
Mpls vpnMpls vpn
Mpls vpn
 
MPLS Presentation
MPLS PresentationMPLS Presentation
MPLS Presentation
 
Mellanox Approach to NFV & SDN
Mellanox Approach to NFV & SDNMellanox Approach to NFV & SDN
Mellanox Approach to NFV & SDN
 
PLNOG 13: Nicolai van der Smagt: SDN
PLNOG 13: Nicolai van der Smagt: SDNPLNOG 13: Nicolai van der Smagt: SDN
PLNOG 13: Nicolai van der Smagt: SDN
 
Opencontrail network virtualization
Opencontrail network virtualizationOpencontrail network virtualization
Opencontrail network virtualization
 
Новый функционал JunOS для маршрутизаторов
Новый функционал JunOS для маршрутизаторовНовый функционал JunOS для маршрутизаторов
Новый функционал JunOS для маршрутизаторов
 
evpn_in_service_provider_network-web.pdf
evpn_in_service_provider_network-web.pdfevpn_in_service_provider_network-web.pdf
evpn_in_service_provider_network-web.pdf
 
S5850 datasheet
S5850 datasheetS5850 datasheet
S5850 datasheet
 
S5850 3-datasheet
S5850 3-datasheetS5850 3-datasheet
S5850 3-datasheet
 
S5850 datasheet
S5850 datasheetS5850 datasheet
S5850 datasheet
 
S5850 3-datasheet
S5850 3-datasheetS5850 3-datasheet
S5850 3-datasheet
 
S5850 datasheet
S5850 datasheetS5850 datasheet
S5850 datasheet
 
S5850 3-datasheet
S5850 3-datasheetS5850 3-datasheet
S5850 3-datasheet
 
Presentation on ccna
Presentation on ccnaPresentation on ccna
Presentation on ccna
 
Presentation on ccna
Presentation on ccnaPresentation on ccna
Presentation on ccna
 
Evolucion redes troncales_convergentes
Evolucion redes troncales_convergentesEvolucion redes troncales_convergentes
Evolucion redes troncales_convergentes
 
Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...
Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...
Orchestration of Ethernet Services in Software-Defined and Flexible Heterogen...
 

Mais de APNIC

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119APNIC
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119APNIC
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119APNIC
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119APNIC
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...APNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonAPNIC
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonAPNIC
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPNIC
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6APNIC
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!APNIC
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023APNIC
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAPNIC
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAPNIC
 

Mais de APNIC (20)

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment Status
 

Último

Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.soniya singh
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Servicegwenoracqe6
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebJames Anderson
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.soniya singh
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445ruhi
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...Diya Sharma
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Call Girls in Nagpur High Profile
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls DubaiEscorts Call Girls
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)Delhi Call girls
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtrahman018755
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...Escorts Call Girls
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersDamian Radcliffe
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLimonikaupta
 

Último (20)

Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Connaught Place ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
Dwarka Sector 26 Call Girls | Delhi | 9999965857 🫦 Vanshika Verma More Our Se...
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 

Branching out with SDN

  • 1. Copyright 2015 Alcatel-Lucent. All rights reserved. Branching out with SDN Alastair JOHNSON Using SDN to build L2/L3VPNs March 2015
  • 2. Copyright 2015 Alcatel-Lucent. All rights reserved. Agenda 1. Introduction 2. Technology recap a. VXLAN b. EVPN 3. Putting it together 4. Comparison 5. Conclusion 3/2/2015 2
  • 3. Copyright 2015 Alcatel-Lucent. All rights reserved. Introduction  Software Defined Networking has significantly changed the way that networking is deployed in some environments  Research facilities, datacenters, etc  Gaining traction in other parts of the network (core/edge, etc)  SDN is about abstraction and separation of control and forwarding functions, and the separation of hardware and software  It offers new ways of thinking about existing ways of working 3 3/2/2015
  • 4. Copyright 2015 Alcatel-Lucent. All rights reserved.  Decoupled architecture means each vendor can focus on his strengths  Decreased barrier to entry for startups provides multiple choices for customers  Feature stability, long hardware cycles do not affect software features Management, Policy Hardware OS Controller HardwareHardware Software Defined Networking 4 28-Feb-15
  • 5. Copyright 2015 Alcatel-Lucent. All rights reserved. Introduction  The WAN space has been relatively unchanged for the better part of 15 years  IP-VPNs are fundamentally the same as they were in 2000  RFC2547 published March 1999  L2VPNs are fundamentally the same as they were in 2007  The CPE has remained unchanged for the same period of time  Basically still the same device: vertically integrated hardware and software, running routing protocols and a variety of LAN/WAN interfaces  Maybe a little bit faster than it used to be 3/2/2015 5
  • 6. Copyright 2015 Alcatel-Lucent. All rights reserved. Software Defined VPN (SD-VPN)  What if there was a new way of thinking about VPN services which embraces the smart edge dumb core philosophy?  What if there was a way to change the CPE paradigm?  What if there was a way to transport L2 services over any L3 network?  What if there was a way to do this operationally efficiently? 3/2/2015 6
  • 7. Copyright 2015 Alcatel-Lucent. All rights reserved. Technology recap: VXLAN  VXLAN encapsulates Ethernet in IP  Runs over IPv4 or IPv6  Uses UDP, source port is a hash of MAC or IPs to provide load balancing entropy  8 byte VXLAN header provides 24 bit VXLAN Network Identifier (VNI) and flags  Total encapsulation overhead is ~50 bytes  VXLAN is routable with IP, so the underlay network may be any network that uses existing resiliency and load balancing mechanisms  ECMP  IGPs/BGP  IP FRR  VXLAN tunnel endpoints can be on network equipment or computing infrastructure  Deliver a VPN straight to a hypervisor IP Network (IP FRR, ECMP, IGP) IP Network IP Network
  • 8. Copyright 2015 Alcatel-Lucent. All rights reserved. Data Plane Control Plane EVPN MP-BGP draft-ietf-l2vpn-evpn Technology Recap: EVPN  EVPN over MPLS for VLL, VPLS and E-Tree services  All-active multihoming for VPWS  RSVP-TE or LDP MPLS protocols  EVPN with PBB PE functionality for scaling very large networks over MPLS  All-active multihoming for PBB- VPLS  EVPN over NVO tunnels (VXLAN, NVGRE, MPLSoGRE) for data center fabric encapsulations  Provides Layer 2 and Layer 3 DCI Multiprotocol Label Switching (MPLS) draft-ietf-l2vpn-evpn Provider Backbone Bridges (PBB) draft-ietf-l2vpn-pbb-evpn Network Virtualization Overlay (NVO) draft-sd-l2vpn-evpn-overlay
  • 9. Copyright 2015 Alcatel-Lucent. All rights reserved. Technology Recap: EVPN  Brings proven and inherent BGP control plane scalability to MAC routes  Consistent signaled FDB in any size network instead of flooding  Even more scalability and hierarchy with route reflectors  BGP advertises MACs and IPs for next hop resolution with EVPN NLRI  AFI = 25 (L2VPN) and SAFI = 70 (EVPN)  Fully supports IPv4 and IPv6 in the control and data plane  Offers greater control over MAC learning  What is signaled, from where and to whom  Ability to apply MAC learning policies  Maintains virtualization and isolation of EVPN instances  Enables traffic load balancing for multihomed CEs with ECMP MAC routes Route Distinguisher (8 octets) Ethernet Segment Identifier (10 octets) Ethernet Tag ID (4 octets) MAC Address Length (1 octet) MAC Address (6 octets) IP Address Length (1 octet) IP Address (0 or 4 or 16 octets) MPLS Label1 (3 octets) MPLS Label2 (0 or 3 octets) MAC Advertisement Route (Light Green Fields are Optional)
  • 10. Copyright 2015 Alcatel-Lucent. All rights reserved. Putting it together  EVPN delivers a control plane that can distribute MAC (L2) and IP (L3) reachability information  Scale is addressed: BGP has proven to scale well; federation becomes straight- forward  Control is addressed: programmatic network topology, flexibility of routing policies  Efficiency is addressed: hybrid L2/L3 services over a single interface, redundancy and multi-homing included  VXLAN delivers a data plane that can deliver Ethernet frames over an L3 transport  L2VPN, L3VPN, …the Internet 3/2/2015 10
  • 11. Copyright 2015 Alcatel-Lucent. All rights reserved. A new way of delivering VPNs  Controller programs forwarding plane for all CPEs  Aware of all L2/L3 topology behind each CPE  Calculate once, program many  CPE performs encapsulation of VPN traffic (VXLAN)  Traffic is carried encapsulated over underlay network  Underlay network could be any infrastructure  Unaware of topology of VPN service CPE Site 1 LAN CPE Site 3 LAN CPE Site 2 LAN Underlay Policy DB SDN Controllers SP Central Functions
  • 12. Copyright 2015 Alcatel-Lucent. All rights reserved. A new way of delivering VPNs  OpenFlow provides a mechanism to program the L2/L3 forwarding information base (FIB) and provide notifications to the controller  MAC/IP address learning on LAN ports are alerted to the controller  Controller determines whether the MAC/IP is to be programmed into FIB  Federation of topology between controllers via BGP-EVPN  MAC and IP reachability signaled  VXLAN VNI information combined with NEXT_HOP  Redundancy of controllers is supported – CPE vSwitch registers and determines active/standby controllers 12 3/2/2015 CPE SDN Controller OpenFlow OVSDB BGP EVPN 10.0.0.0/24 10.1.0.0/24
  • 13. Copyright 2015 Alcatel-Lucent. All rights reserved. A new way of delivering VPNs  CPE forward directly between each other using VXLAN as overlay  10.0.0.0/24 NEXT_HOP 192.0.2.1 VNI xyz  10.1.0.0/24 NEXT_HOP 192.0.2.3 VNI xyz  Underlay network sees VXLAN traffic between endpoints  Dataplane can be further encapsulated for confidentiality (e.g. IPsec) 13 3/2/2015 10.0.0.0/24 10.1.0.0/24 192.0.2.1 192.0.2.3
  • 14. Copyright 2015 Alcatel-Lucent. All rights reserved. VPN Flexibility  Overlays simplify network topology  SP network needs to know less about customer topology  Increases flexibility of delivery – L2 services over L3, On Net, Off Net, Internet, etc  Provisioning simplified  Reuse of activation processes from broadband networks 14 3/2/2015 VRF VRF Many provisioning touch points BGP Routing Policy RIB scale Failover Redundancy LAN ports WAN ports Aggregation network GRT GRT Dynamic Provisioning One-time Provisioning
  • 15. Copyright 2015 Alcatel-Lucent. All rights reserved. Overlays enable service chaining  Centralized policy enforcement  Firewall  Between zones/subnets/branch types  Extranet applications  To Internet through central functions  Content filtering  Selective content filtering (schools – teacher/student; public WiFi in retail environments bypasses)  Network analytics and monitoring  Tap and mirror  IDS/IDP  DPI and DLP 3/2/2015 15 LAN WAN CPE DC LAN CPE LAN WAN CPE DC LAN CPE
  • 16. Copyright 2015 Alcatel-Lucent. All rights reserved. Interworking How do I connect the new to the existing? 1. EVPN with VXLAN termination direct into existing MPLS PE routers  End-to-end network is BGP and VXLAN aware allowing for PE routers to act as VXLAN/MPLS interworking function  Streamlined and simplified routing 2. Use CPE as gateway  Break VXLAN services out to Ethernet VLANs at PE router  Faster to deploy but less flexible 16 3/2/2015 GRT VRF Internet IP/MPLS VRF VRF Internet IP/MPLS VRF Traditional VPN environmentOverlay VPN Environment IWF Traditional VPN environmentOverlay VPN Environment
  • 17. Copyright 2015 Alcatel-Lucent. All rights reserved. Comparison Traditional VPN model • Well understood and widely deployed • Expensive to maintain and scale • Inflexible for “cloud scale” service consumption • Constrained by network reach • Service chaining challenging to deploy Overlay VPN model • New approach to networking that is being aggressively proven in datacenters • Centralized control model reduces direct operational cost • Scales to cloud: speed, flexibility • Service providers can extend services out of network footprint and effectively use all network assets • Natively enables service-chaining 17 3/2/2015
  • 18. Copyright 2015 Alcatel-Lucent. All rights reserved. Conclusion  SDN as a technology has now found proven deployment use- cases that make sense  Not just experiments or ‘doing the same thing but differently’  Real service provider use-cases exist for leveraging the same technology as deployed in datacenters  Speed, flexibility, optimization of network service delivery points 3/2/2015 18
  • 19. Copyright 2015 Alcatel-Lucent. All rights reserved. nuagenetworks.net/vns @nuagenetworks
  • 20. Copyright 2015 Alcatel-Lucent. All rights reserved. References  VXLAN  RFC7348  BGP MPLS-Based Ethernet VPN  RFC7209  RFC7432  Greg Hankins’ NANOG presentation  OpenVSwitch 3/2/2015 20

Notas do Editor

  1. Ask Rotem to clarify the slides