37
Introduction to NSX 1

Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

  • Upload
    others

  • View
    26

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Introduction to NSX

1

Page 2: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Going beyond servervirtualization

Page 3: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Going beyond servervirtualization

Page 4: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

IT’S TIME FOR A NEW IT APPROACH

SLOW TECHNOLOGYADOPTION RATES

HIGH USER EXPECTATIONS

SLOW REPONSES

PRIVACYISSUES

INTEGRATION PROBLEMS

SERVICE OUTAGES

SHORTAGE OF RIGHT SKILLS

DECLINING BUDGET

DIFFERENT APPLICATIONS AGING INFRASTRUCTURE

SECURITY

PROLIFERATIONOF DEVICES

FRAGMENTEDDATA CENTER

LIMITED RESOURCES

CLOUD SILOSSECURITY

PROLIFERATIONOF DEVICES

FRAGMENTEDDATA CENTER

CLOUD SILOS

Page 5: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

It’s Time to Virtualize the WHOLE Data Center

EFFICIENT SECURE

Optimized for rapid

development and delivery

of all applications, for safe

consumption on any device

The Software Defined

Data Center

AGILE

Network Virtualization is Key

Page 6: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Data Center Virtualization Layer

Intelligence in SoftwareOperational Model of VM for Data CenterAutomated Configuration & Management

What is a Software Defined Data Center (SDDC)?

Intelligence in HardwareDedicated, Vendor Specific InfrastructureManual Configuration & Management

Software

Hardware Compute, Network and Storage CapacityPooled, Vendor Independent, Best Price/Performance InfrastructureSimplified Configuration & Management

Page 7: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Network Virtualization is at the core of an SDDC approach

Network, storage, compute

Virtualization layer

Non-Disrupting Deployment

Page 8: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Network, storage, compute

Virtualization layer

“Network hypervisor”

Virtual Data Centers

Network Virtualization is at the core of an SDDC approach

Non-Disrupting Deployment

Page 9: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

The Power of Distributed Services

Switching

Routing

Firewalling/ACLs

Load Balancing

Network and security services now distributed in the hypervisor

Page 10: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Switching

Routing

Firewalling/ACLs

Load Balancing

High throughput rates

East-west firewalling

Native platform capability

The Power of Distributed Services

Page 11: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

A Traditional “Virtual Switch”

Page 12: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Traditional Layer 3 Routing?

Page 13: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

A Virtual Network?

Page 14: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

A Virtual Network?

Page 15: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Non-Disruptive Deployment

Page 16: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Programmatically Provisioned

Page 17: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Network & Security Services Distributed to the Virtual SwitchPhysical Network becomes high-speed IP backplane

Page 18: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

DR Today (simple view)

10.0.10/24 10.0.20/24

10.0.10.21 10.0.20.21 MajorRTOImpact

Change IP AddressReconfig Security4

Primary Site Recovery Site

Recoverthe VM

3

Replicate VM & Storage

2Physical Network Infrastructure Physical Network Infrastructure

SAN

1Snapshot VM

SAN

Step 1&2(e.g VMware SRM)

18

Page 19: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

DR with NSX Network Virtualization (simple view)

SAN SAN

10.0.30.21 10.0.30.21

Virtual Network10.0.30/24

80%RTONSX Controller NSX Controller

Snapshot Network &

Security

2b

Primary Site Recovery Site

1Snapshot VM Network & Security

already exists

Recoverthe VM

3

Physical Network Infrastructure Physical Network Infrastructure2a

Replicate VM & Storage

10.0.10/24 10.0.20/24

Step 1&2(e.g VMware SRM)

19

Virtual Network10.0.30/24

Page 20: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Support for Physical Workloads and VLANs

Page 21: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Support for Physical Workloads and VLANs

Page 22: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Non-Disruptive Deployment

Page 23: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

The Power of Distributed Network & Security Services & Policies

Page 24: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Problem: Data Center Network SecurityPerimeter-centric network security has proven insufficient, and micro-segmentation is operationally infeasible

Little or no

lateral controls

inside perimeter

Internet Internet

Insufficient OperationallyInfeasible

Page 25: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Why traditional approaches are operationally infeasible…

25

Internet

Perimeter Firewalls

• Create firewall rules before provisioning

• Update Firewall rules when move or change

• Delete firewall rules when app decommissioned

• Problem increases with more East-West traffic

Page 26: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

How an SDDC approach makes micro-segmentation feasible

26

Internet

Security Policy

Perimeter Firewalls

CloudManagement

Platform

Page 27: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

There is a BIG difference…

Page 28: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

NSX Distributed Firewalling Performance

28

20Gbps Per Host of Firewall Performancewith Negligible CPU Impact

Page 29: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

NSX Distributed Firewalling Performance

CONFIDENTIAL 29

80K CPS with 100+ Rules per Host

A Typical Virtual Appliance does ~6K CPS per VMA Physical Appliance performs 300K – 400K CPS per appliance

Page 30: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Align type of controls to what you are protecting

Isolation Explicit Allow Comm. Secure Communications

NGFW

IPS

IPS

NGFW

Se

rvic

e I

nse

rtio

n

Application A

Application B

App Tier

DB Tier

(e.g

TC

P,1

433)

No Communication Path

Page 31: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Advanced Services Insertion – Example: Palo Alto Networks NGFW

Internet

Security Policy

TrafficSteering

Page 32: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Intelligent groupingGroups defined by customized criteria

Operating System Machine Name

Application Tier

Services

Security PostureRegulatory

Requirements

Page 33: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Automated Security in a Software-Defined Data CenterData Center Micro-Segmentation

CONFIDENTIAL 33

Page 34: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Automated Security in a Software-Defined Data CenterData Center Micro-Segmentation

CONFIDENTIAL 34

Page 35: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Benefits of Taking a Software Defined Data Center Approach

35

Multi-tenant Infrastructure

IT Automating IT

Developer CloudDMZ Anywhere

Micro-segmentation

Secure End User

Metro Pooling

Hybrid Cloud Networking

Reduce infrastructure

provisioning time from

weeks to minutes

Secure infrastructure

at 1/3 the cost

Reduce RTO by 80%

Disaster Recovery

Security Speed & Agility Application Continuity

Value

Page 36: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

NSX partner ecosystem

Physical Infrastructure

Security

Operations

Application Delivery

Page 37: Introduction to NSX - CSL · DR with NSX Network Virtualization (simple view) SAN SAN 10.0.30.21 10.0.30.21 Virtual Network 10.0.30/24 80% NSX Controller NSX Controller RTO Snapshot

Thank you