22
FRS FY16 Confidential Network Infrastructure for Optimizing VDI July, 2016 Khuong Nguyen – Dell Networking South Asia

Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Embed Size (px)

Citation preview

Page 1: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

1 FRS FY16 Confidential

Network Infrastructure for Optimizing VDI

July, 2016

Khuong Nguyen – Dell Networking South Asia

Page 2: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Virtualization 1.0

Page 3: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Virtualization 2.0

Page 4: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

VDI Impact on Network Infrastructure

4

L2

iSCSIiSCSIiSCSIiSCSIiSCSI

iSCSIiSCSI

VM

Storage Compute

VDI User

iSCSI

Quality Of Experience

Boot Storm

Highly Virtualized

Users simultaneously boot their virtual desktops in the morning resulting in traffic spike

Each desktop session tends to use as much bandwidth as possible for better QoE

Desktop are small VMs deployed in large numbers, the endpoint density clutters management

Page 5: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

“The world’s most innovative, disruptive & visionary networking vendor”

Data Center

Page 6: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Operating System Network Overlay Control Plane

Software Defined Networking

Dell Open Networking

+ + +

Disaggregating networking technologies to maximize capability and choice

Switching Hardware

Switching Software

Physical Networking

Virtual Networking

Control Plane

Forwarding Plane

Open Networking is Dell’s SDN Strategy

Page 7: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Open Networking With Place in the Network

Linux on the switch, unified server, network management

Feature-rich L2/L3 Data Center networking

WAN, MPLS/VPLS functionality

• Network tapping

• Leaf-spine SDN fabric Fabric Switching

In Rack Switching

Distributed fabric with analytics & security

Feature-rich L2/L3 Data Center networking

Feature-rich L2/L3 Data Center networking

Page 8: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

8

Pluribus Open Netvisor Linux Fabric Introduction

“A computer cluster consists of a set of loosely or

tightly connected computers that work together so

that, in many respects, they can be viewed as a

single system”

ONVL Fabric is a software based, controller-less, fully distributed

and highly available server-style cluster of Ethernet Switches

Single CLI/API For Agility & Automation

Page 9: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Open Netvisor Linux Architecture

L2/L3 stack

Dell Open Networking

Open Networking

Java/C RESTful,

JSON API Ansible C API CLI OpenStack Python Fabric-wide Programmability

L2/L3 stack

L2/L3 stack

Controller-less Fabric Ubiquitous Control Without Controllers!

Agility, Automation

Telemetry, Visibility

Page 10: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

ONVL Advanced Features

Application flows Client-Server

connections Network Traffic

Tap-less Fabric Telemetry vPort

Visibility/control of end point/VM lifecycle across the fabric

vFlow

Granular flow control for security and QoS policies

Single CLI/API For Agility & Automation

Built on top of Open Networking Hardware…

…and standard L2/L3 protocols!

Page 11: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

How Pluribus ONVL for Dell Enhances VDI

Quality of Experience

Boot Storm

Highly Virtualized

Network Admin(login to any ONVL switch)

L2

iSCSIiSCSIiSCSIiSCSIiSCSIiSCSIiSCSI

VM

Storage Compute

VDI User

iSCSI

1MB

ONVL Fabric

Bandwidth

Hot spots

VMs mgmt and troublesh

ooting

Fabric-wide database to track

VM lifecycle through the fabric (vPort)

Heath map of storage and

desktop flows throughput/laten

cy

Fair share of bandwidth

to each desktop session (vFlow)

Page 12: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

L2

L3

L2

3rd Party

Spine

All Pluribus + Dell

All Pluribus + Dell

Brownfield Spine

Brownfield Spine

3rd Party

Spine

L3

L3

ONVL Controller-less Fabric POD Solutions

Controller-less fabric designed to work across 3rd party networks

L3 L3

L2

iSCSI

Page 13: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

13

How about Security?

Page 14: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Security begins with visibility

You can’t protect what you can’t see

Who is on the Network?

And what are they up to?

Page 15: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

Event: Attempted Privilege Gain

Target: 96.16.242.135

Event: Attempted Privilege Gain

Target: 96.16.242.135 (vulnerable)

Host OS: Blackberry

Applications: Mail, Browser, Twitter

Location: Whitehouse, US

Event: Attempted Privilege Gain

Target: 96.16.242.135 (vulnerable)

Host OS: Blackberry

Applications: Mail, Browswer, Twitter

Location: Whitehouse, US

User ID: bobama

Full Name : Barack Obama

Department: Executive Branch

Context is everything

Page 16: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

VCF IA Fit In Pluribus Architecture

16

L2/L3 stack

L2/L3 stack

L2/L3 stack

Dell ON Hardware

Open Networking

Virtualization-Centric Fabric Centralized control and programmability without

external controllers Netvisor Distributed Fabric

Built-in TCP Flow and Network Telemetry

Engines

(NO taps, NO brokers)

Fabric-wide Visibility and Aggregation of Telemetry Data

Fabric-wide API Programmability (REST, Java/C, CLI, Ansible)

VCF Insight Analytics Analytics Applications

(runs in a VM outside the switch)

Page 17: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

17 Dell - Internal Use - Confidential

What Can You Answer With VCF IA? – Examples 1. How many concurrent connections were

open between Client A to Server B between 2am and 5am last week (EST)? Did it happen before? Did client A try to flood other servers at the same time?

2. What was the average connection setup latency for the database server between 4pm and 4:15pm when user X reported slow responsiveness? How many concurrent clients were connected at that time?

3. Are we load balancing LDAP servers as expected? From which geography are most of the connections to my servers originating?

Page 18: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

18 Dell - Internal Use - Confidential

What Can You Answer With VCF IA? – Examples

4. What switch ports are transporting the most connections and are there any packet drops or errors on these ports?

5. Is any of my secure servers being accessed using unsecure protocols such as telnet/http/ftp? Which client is doing that?

6. How many times did user X connect to foo.com in the past 36 hours? Did anybody else behave the same in the last four weeks?

Page 19: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

19 Dell - Internal Use - Confidential

What Can You Answer With VCF IA? – Examples 7. How many connections have been reset

(RST) and closed on server Z since 5am today? Are these reset always associated to a specific application?

8. Who are the Top Talkers for Application Y on server Z since 2pm last Monday? And one week ago when the engineering team from our acquisition was still using the old server?

9. How many VM moves occurred on the Nutanix cluster since last week? Was the CVM unresponsive at any point in time (SYN)?

Page 20: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

VCF IA Deployment Model For Third Party Networks

ONVL Telemetry API

VCF-IA Server (VM)

Dell S4048 or S6000 Appliance as Flow Collector

$0

$100,000

$200,000

$300,000

$400,000

$500,000

$600,000

$700,000

$800,000

VCFIA

Other

5 Years TCO

Gigamon 48+ports

Tool/Appliance

Tools

Pkt Broker

~85% savings over traditional solutions

Page 21: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương

1. VDI requirements for Network Infrastructure

2. Dell Open Networking

3. Pluribus Open Netvisor Linux

4. Pluribus VCF IA for Security and Visibility

Page 22: Kiến trúc mạng cho hệ thống VDI - Mr Nguyễn Phạm Vĩnh Khương