IP/MPLS VPN Protocol GAP Analysis For NVO3 draft-hy-nvo3-vpn-protocol-gap-analysis-02 Lucy Yong Susan Hares March 2013 Orlando FL.

Slides:



Advertisements
Similar presentations
MPLS VPN.
Advertisements

Copyright © 2004 Juniper Networks, Inc. Proprietary and Confidentialwww.juniper.net 1 E-VPN and Data Center R. Aggarwal
Deployment of MPLS VPN in Large ISP Networks
A Unified LISP Mapping Database for L2 and L3 Network Virtualization Overlays Draft-hertoghs-nvo3-lisp-unfied- control-plane Yves Hertoghs.
Juniper Networks, Inc. Copyright © L2 MPLS VPNs Hector Avalos Technical Director-Southern Europe
Ethernet VPN (EVPN) - Casos de Uso e Aplicação
Network Virtualization Overlay Control Protocol Requirements draft-kreeger-nvo3-overlay-cp-00 Lawrence Kreeger, Dinesh Dutt, Thomas Narten, David Black,
IPv4 - IPv6 Integration and Coexistence Strategies Warakorn Sae-Tang Network Specialist Professional Service Department A Subsidiary.
Transitioning to IPv6 April 15,2005 Presented By: Richard Moore PBS Enterprise Technology.
Layer 2 Gateway (L2GW) draft-xia-nvo3-l2gw-01
The Case for Enterprise Ready Virtual Private Clouds Timothy Wood, Alexandre Gerber *, K.K. Ramakrishnan *, Jacobus van der Merwe *, and Prashant Shenoy.
L3vpn end-system draft Pedro Marques. Overview Defines a mechanism to associate an end- system virtual interface to an L3VPN. – Co-located forwarder:
Network Overlay Framework Draft-lasserre-nvo3-framework-01.
PTX Use Cases Chris Whyte
MPLS L3 and L2 VPNs Virtual Private Network –Connect sites of a customer over a public infrastructure Requires: –Isolation of traffic Terminology –PE,
SMUCSE 8344 MPLS Virtual Private Networks (VPNs).
BGP L3VPN Virtual PE draft-fang-l3vpn-virtual-pe-01
MPLS And The Data Center Adrian Farrel Old Dog Consulting / Juniper Networks
IETF-82 draft-bitar-datacenter-vpn-applicability-01.txt Page - 1 Cloud Networking: Framework and VPN Applicability draft-bitar-datacenter-vpn-applicability-01.txt.
Network based IP VPN Architecture using Virtual Routers Jessica Yu CoSine Communications, Inc. Feb. 19 th, 2001.
IGP Multicast Architecture Lucy Yong, Weiguo Hao, Donald Eastlake Andrew Qu, Jon Hudson, Uma Chunduri February 2015 NVO3 Interim Meeting draft-yong-rtgwg-igp-mutlicast-arch-01.
Virtual Subnet : A L3VPN-based Subnet Extension Solution draft-xu-virtual-subnet-10 Xiaohu Xu (Huawei) Susan Hares (Huawei) Yongbing Fan.
MPLS - 73nd IETF Minneaplis1 Composite Transport Group (CTG) Framework and Requirements draft-so-yong-mpls-ctg-framework-requirement-00.txt draft-so-yong-mpls-ctg-framework-requirement-00.txt.
Data Center Network Redesign using SDN
Using LISP for Secure Hybrid Cloud Extension draft-freitasbellagamba-lisp-hybrid-cloud-use-case-00 Santiago Freitas Patrice Bellagamba Yves Hertoghs IETF.
Networking in the cloud: An SDN primer Ben Cherian Chief Strategy Midokura.
IETF-84 (29 July – 3 Aug. 2012) Cloud Computing, Networking, and Service (CCNS) Update for GISFI-10, New Delhi, India Sept Monday-10-September-20121IETF84.
Lucy Yong Susan Hares September 20, 2012 Boston
Layer 2 Gateway (L2GW) draft-xia-nvo3-l2gw-00 Liang Xia, Lucy Yong March 2014 London England.
Draft-bitar-nvo3-vpn-applicability-00.txt Page - 1 Cloud Networking: Framework and VPN Applicability draft-bitar-nvo3-vpn-applicability-00.txt Nabil Bitar.
61st IETF Washington DC November 2004 BGP/MPLS IP Multicast VPNs draft-yasukawa-l3vpn-p2mp-mcast-00.txt Seisho Yasukawa (NTT) Shankar Karuna (Motorola)
Virtual Subnet: A Scalable Cloud Data Center Interconnect Solution draft-xu-virtual-subnet-06 Xiaohu Xu IETF82, TAIWAN.
VPN4DC Discussion VPN4DC Team Taipei, Taiwan.
IETF 81 Quebec City1 Requirements and Framework of VPN-oriented Data Center Services Ning
Network Virtualization Overlay Use Cases Lucy Yong, Mehmet Toy, Aldrin Isaac, Vishwas Manral, Linda Dunbar July 2013 Berlin Germany draft-ietf-nvo3-use-case-02.
Vic Liu Liang Xia Zu Qiang Speaker: Vic Liu China Mobile Network as a Service Architecture draft-liu-nvo3-naas-arch-01.
1 © OneCloud and/or its affiliates. All rights reserved. VXLAN Overview Module 4.
BGP L3VPN Virtual CE draft-fang-l3vpn-virtual-ce-01 Luyuan Fang Cisco John Evans Cisco David Ward Cisco Rex Fernando Cisco John Mullooly Cisco Ning So.
1MPLS QOS 10/00 © 2000, Cisco Systems, Inc. rfc2547bis VPN Alvaro Retana Alvaro Retana
BGP L3VPN Virtual PE draft-fang-l3vpn-virtual-pe-04 Luyuan Fang David Ward Rex Fernando Maria Napierala Nabil Bitar Dhananjaya Rao Bruno Rijsman Ning So.
Network Virtualization Overlay Use Cases Lucy Yong, Mehmet Toy, Aldrin Isaac, Vishwas Manral, Linda Dunbar September 20, 2012 Boston draft-mity-nvo3-use-case.
NVO3 Framework and Data Plane Requirement Addition Lucy Yong Linda Dunbar March 2013 Orlando FL draft-yong-nvo3-frwk-dpreq-addition-00.
Inter-AS Options for NVO3 and BGP/MPLS VPN Weiguo Hao, Lucy Yong, Sue Hares, Robert Raszuk Luyuan Fang, Osama Zia, Shahram Davari, Andrew Qu March 2015.
Network Virtualization Overlays Use Cases draft-timy-nvo3-use-case-01 Lucy Yong Mehmet Toy Aldrin Isaac Vishwas Manral Linda Dunbar Vancouver July 31,
NVO3 Anycast Layer 3 Gateway draft-hao-nvo3-anycast-gw-00 July 20141NVO3 Anycast Gateway Weiguo Hao(Huawei) Lucy Yong(Huawei) Yizhou Li(Huawei) Feng Wang(H3C)
Network Virtualization Overlay Control Protocol Requirements draft-kreeger-nvo3-overlay-cp Lawrence Kreeger, Dinesh Dutt, Thomas Narten, David Black, Murari.
1/13 draft-carpenter-nvo3-addressing-00 Brian Carpenter Sheng Jiang IETF 84 Jul/Aug 2012 Layer 3 Addressing Considerations for Network Virtualization Overlays.
VS (Virtual Subnet) draft-xu-virtual-subnet-03 Xiaohu Xu IETF 79, Beijing.
Inter-AS Option C between NVO3 and BGP/MPLS IP VPN network draft-hao-bess-inter-nvo3-vpn-optionc-00 Weiguo Hao Lucy Yong Susan Hares Nov, 2014 Honolulu.
BGP L3VPN Virtual PE draft-fang-l3vpn-data-center-interconnect-01 L. Fang R. Fernando D. Rao S. Boutros Cisco IETF 86, Orlando, FL, 3/16/2013.
XRBLOCK IETF 85 Atlanta Network Virtualization Architecture Design and Control Plane Requirements draft-fw-nvo3-server2vcenter-01 draft-wu-nvo3-nve2nve.
Recent Progress in Routing Standardization An IETF update for UKNOF 23 Old Dog Consulting Adrian
EVPN: Or how I learned to stop worrying and love the BGP
EVPN: Or how I learned to stop worrying and love the BGP Tom Dwyer, JNCIE-ENT #424 Clay Haynes, JNCIE-SEC # 69 JNCIE-ENT # 492.
MPLS Virtual Private Networks (VPNs)
TRILL DataCenter/Campus/PBB Inter-connect over IP core with BGP
VPN Extension Requirements for Private Clouds
Examples based on draft-cheng-supa-applicability-00.txt
Network Virtualization Overlay Use Cases
Applicability Statement for Layer 1 Virtual Private Networks (L1VPNs) Basic Mode draft-takeda-l1vpn-applicability-basic-mode-00.txt Deborah Brungard (AT&T)
Virtual Subnet : A L3VPN-based Subnet Extension Solution
TRILL MPLS-Based Ethernet VPN
Multicast in Virtual Router-based IP VPNs
Private Network Laid Over ThinCPEs routing area related work
Extending MPLS/BGP VPNs to End-Systems
NTHU CS5421 Cloud Computing
Kireeti Kompella Juniper Networks
EVPN a very short introduction
IS-IS VPLS for Data Center Network draft-xu-l2vpn-vpls-isis-02
Applicability of EVPN to NVO3 Networks
Presentation transcript:

IP/MPLS VPN Protocol GAP Analysis For NVO3 draft-hy-nvo3-vpn-protocol-gap-analysis-02 Lucy Yong Susan Hares March 2013 Orlando FL

About this Draft Analyze IP MPLS L2/L3VPN protocol applicability and gaps for NVO3 Intend to stay at neutral regarding – Should extend and/or simplify the VPN protocols or – Develop a new protocol solution for NVO3 The document is organized: – IP/MPLS L2/L3 VPN Highlight – L2/L3 VPN for NVO3 – L2/L3 VPN for DCI when NVO3 is used – Operator Aspects 2

NVO3 Requirements Many NVOs are built on a common infrastructure with: – Traffic isolation among one another – Independent address space in each and isolated from infrastructure’s – Flexible VM placement and move from one server to another without physical network limitation (no change on VM addresses when move) – No Communication b/w an end system in an overlay and a transport underlay – Scalability and security support An NVO may be L2 or L3 based where: – The Tenant System (TS) may be VM or Server – Network Virtual Edge (NVE ) may be on Server or ToR – Server may run as a host or a network overlay edge in DC underlying network Interwork with other NVO instances Allow external user to access an NVO 3 NVE TS Tunnel NVO3 Model VM UN VM DC Site VM NVO1 NVO2

Quick Comparison Assumption: TS CE, NVE PE, Tunnel b/w NVEs Tunnel b/w PEs Notation: Support ( √ ), May Support (≤), Not Support(×), Not Apply (≠) 4 NVO3 Requirements VPN Clarification Traffic Isolation√ Own Address Space√ Be L2 or L3 based√ Decouple from underlying transport√VPN traffic is decoupled from underlay transport VM Mobility×support cold move in L2VPN, but not hot move Flexible VM placement operation≠host placement is at CE site, VPN has no visibility to it NVE on ToR√when ToR supports VPN PE function TS and NVE on a Server≠PE and CE are physically separated VM as Tenant System≤via hypervisor Server as Tenant System√like CE as a host NVE is on a server that is a host in UN≠ use tunnel? need /32 host routing VNI Table ≤ support well if NVE is on ToR, may not if NVE on Server Reachbility advertisement√Via control/data plane protocol, or static configuration Tunneling≤ VPN uses MPLS LSP Tunnel, rarely others

Quick Comparison Cont. NVO3 RequirementsVPN Clarification Auto discovery√ NVE discovery Load Balancing≤ECMP function in WAN may not be sufficient for NVO3 Broadcast or Multicast√May not good enough Underlying Network Design≤DC network design may or may not be same as WAN’s Gateway≤L3VPN GW may not be sufficient for NVO3, L2VPN has no Multi data plane interworking×Only support one data plane schema Inter ASs×, √ L3VPN support, not L2VPN NVO Access externally×, √ L2VPN does not have it, L3VPN supports extranet access Scalability≤Depend on the configuration, i.e. NVE is on ToR or on server. Operation Aspect×DC operation model may be very different from SP model SDN controller managementx this is new to VPN 5 Notation: Support ( √ ), May Support (≤), Not Support(×), Not Apply (≠) Clearly, commons and gaps exist between IP/MPLS VPN and NVO3 requirements Sum: √ (11), ≤ (7), × (6), ≠ (3)

6 VPN Interconnect DC Underlay Networks IP/MPLS VPN interconnects DC underlay networks – VPN does not have the visibility of any network virtual overlays – PE connects to DCGW (as CE) via a local interface or sub-interface – PE may run OSPF, eBGP, etc, DCGW peers with PE only, not remote GW An NVO span across DC sites w/o PE/DCGW awareness – Overlay tunnels are built between any pair of NVEs directly – NVO control plane runs independently from WAN VPN control plane VPN for NVO and VPN for DCI are orthogonal in this case VM UN VM DCGW VM DC Site A VM NVO1 NVO2 VM PE VM UN VM DC Site B VM NVO1 NVO3 DCGW PE IP/MPLS VPN

7 DC NVO Access via a WAN VPN DC NVO may be accessed via an IP/MPLS VPN – VPN connects to both DC NVO and Enterprise sites – PE may peer with Enterprise sites – VPN CP needs to interwork with NVO CP and Enterprise CP – An NVO GW entity is necessary on the DCGW – Be the member of DC NVO and terminate NVO tunnels – May perform routing, NAT, policy, firewall functions – PE may perform some gateway function too DCGW may be configured with many NVO GW entities for diff. customers If NVO uses VPN solution, this will be like inter-AS scenario in RFC4364 This may require VPN enhancement – Interwork with NVO Control Plane, support VM mobility, optimize traffic path, etc DC Site A WAN VM NVO DCGW IP/MPLS VPN PE VM PE NVO VM DC Site B DCGW Enterprise Site 1 Enterprise Site 2 CE

Next Step Welcome comments and suggestions Ask chair suggestion for the next draft-hy-nvo3-vpn-protocol-gap-analysis-02 8