Networks ∙ Services ∙ People Xavier Jeannin (RENATER) - presenter, Tomasz Szewczyk (PSNC), DI4R, Krakow, Poland MD-VPN and E-Infrastructure 30 Sept 2016
Networks ∙ Services ∙ People At Foundation level but still vital Network service is key success factor for your infrastructure Performance Safety / Redundancy / Reliability Distribution and Location of your data 2 What about network in building E-infrastructure?
Networks ∙ Services ∙ People Provider L2 and L3 Virtual Private Network: Point-to-Point Point-to-Point VPN allows to connect 2 sites located in different domains as they were in the same physical location Layer2 Redundant P2P L2VPN: End Users see other site as they were connected by wire (pseudo-wire)
Networks ∙ Services ∙ People Provider L2 and L3 Virtual Private Network: Multi-point Multi-point VPN allows to connect several sites located in different domains as they were in the same physical location Layer3 Layer2 Redundant L3VPN: End Users see other sites as they were connected to a virtual router L2VPN: End Users see other sites as they were connected to a virtual switch
Networks ∙ Services ∙ People A joint service provided by the GÉANT network and NRENs A seamless transport infrastructure that provides a connectivity service: Layer3 or Layer2 VPNs point-to-point or multipoint Multi-domain networking What is MD-VPN? The service provides a seamless, scalable transport infrastructure L3VPN P2P L2VPN IPv4IPv6 MP L2VPN
Networks ∙ Services ∙ People Configure only at the edge An end-to-end extensible and flexible service VPN Provisioning as easy as in a single-domain Lead-time reduced MD-VPN service highly scalable, seamless transport infrastructure VPN multiplexed Configure only at the edge
Networks ∙ Services ∙ People How to interconnect a NREN that does not provide MD-VPN? All types of site can be connected
Networks ∙ Services ∙ People Last mile problematic All types of site can be connected
Networks ∙ Services ∙ People MD-VPN provides the same level of security as VPN MPLS service, There was no security concern related to users or even to MD-VPN users But it is impossible to protect the access to VPNs if the core is compromised In case of MD-VPN, the core is multi-domain The only threats that can occur are a NREN attacking another NREN a NREN router compromised by a pirate Security level provided
Networks ∙ Services ∙ People Where can you use MD-VPN? MD-VPN service in the GÉANT portfolio – 18 NRENs connected (+ 1 NREN using MD-VPN Proxy + 1 NREN still working on) – Roughly 400 PoPs available that European scientist can already use MD-VPN
Networks ∙ Services ∙ People A redundant service Portal available at: atus_dashboard.jsp atus_dashboard.jsp Redundancy is crucial A redundant monitored service
Networks ∙ Services ∙ People Reliability demonstrated since August 2014 Statistics available at m.jsp m.jsp Reliability is crucial Redundancy
Networks ∙ Services ∙ People All scientific projects based on international collaboration LHCONE is an example of successful L3VPN multi-domain service ITER, CONFINE, Distributed digital infrastructure Grid – HPC center PRACE – Deployment ongoing Data Center Interconnection Scientific infrastructure: Telescope, sensor network Cloud Service Provider (Express route)* MD-VPN use cases A wide scope for MD-VPN use (*) Presentation from A. Sevasti in 1B
Networks ∙ Services ∙ People MD-VPN use cases A wide scope for MD-VPN use Quick P2P connection Conference demonstration P2P data transport between two sites Education Remote lecture E-learning Etc …
Networks ∙ Services ∙ People Users and their concern Who are the users? – End-users – They do not care about technology only the service count – E-infrastructures – They are the real interlocutors of NREN User concern – Can you connect all my sites thanks to MD-VPN? – Yes – Is the service reliable and redundant? – Yes – Can you tell me what will be the cost? – Yes, but it is far short of an automatic process
Networks ∙ Services ∙ People An innovative design with added value for end-users Safe infrastructure – Security opex saved on site – Reduce firewall usage Multi-domain seamless infrastructure – Highly scalable – Redundant and reliable – Short lead time – All types of site can be connected Reduce OPEX and CAPEX for use – Cost saving – VPN cheaper – Cost saving – No tender for each research project Cover a wide scope of use cases
Networks ∙ Services ∙ People A scientist project FIWARE A scientist project FIWARE FIWARE is a project of the European Public-Private-Partnership on Future Internet (FI-PPP) programmeFI-PPP 16 sites connected in 12 countries Using all types of connection: Direct connection Via VPN-Proxy Private companies not connected to any NREN First user testimony: XiFi/FIWARE project A large project using MD-VPN as network infrastructure provider
Networks ∙ Services ∙ People First user testimony: XiFi/FIWARE project Benefits Usage “In general I think that compared to the alternative (that we used in some cases, such as traditional VPNs), it was by far the best solution to federat the “private” traffic among the nodes.” Reliability “The service was very reliable (much more than the traditional Point- to-Point VPN used by some of the data centres, that caused some interruptions) and simpler to configure, but I am afraid it was not exploited as it could. ” Federico Michele Facca Technical Manager of XiFi project
Networks ∙ Services ∙ People Second user testimony Demonstration for a conference CARNetova korisnička konferencija - CUC 2014 Video project demonstration at CUC #mod_news P2P data transport between to sites (P2P L2VPN) Very short lead time (2 days)
Networks ∙ Services ∙ People Prospective Data Center Interconnect (DCI) – Ethernet VPN is a new L2 Multi Point VPN with dedicated features for DCI – Active- active multi-homing – Load balancing per flow – VM mobility – Scalability – Support different data-plane – Cloud of Data Centers – For a dedicated community (HEP, HPC, Biologist, …) or generalist cloud Automation – Scripting for VPN provisioning – VPN automation delivery
Networks ∙ Services ∙ People Prospective A distributed Internet eXchange Point for Data Center One EVPN instance connecting all DCs Route Server Science project A Peering between DC with route server Science project A Traffic between 2 DCs for scientific project A DC Router PE providing one EVI Stockholm Warsaw Geneva DC of institute X DC of institute Y DC of institute Z
Networks ∙ Services ∙ People MD-VPN: a network service for E-infrastructure A highly scalable and reliable seamless transport infrastructure – Provided by NRENs, GEANT and NORDUnet – No need to invite to tender A bundle of services ( IPv4, IPv6, P2P L2VPN, VPLS, L3VPN ) – Short lead time – All types of site can be connected – Large number of use cases – Prospective: Data Center Interconnect Ethernet VPN Broad European deployment – 18 connected NRENs
Networks ∙ Services ∙ People Thank you Networks ∙ Services ∙ People 23 Xavier.jeannin “at” renater “dot” fr Any Questions?