Taiwan Advanced Research and Education Network (TWAREN) - Current status & Future Plan Dr. Te-Lung Liu Researcher National Center for High-Performance.

Slides:



Advertisements
Similar presentations
Electronic Visualization Laboratory University of Illinois at Chicago EVL Optical Networking Research Oliver Yu Electronic Visualization Laboratory University.
Advertisements

1 TWAREN Optical Networking on TANet2 and TWAREN Ray-Ming Hsu National Center for High-performance Computing Hsinchu Science Park, Taiwan February
TWAREN and Medical Collaborations Te-Lung Liu NCHC/TWARENhttp://
1 Lambda Networking in TWAREN New Architecture Design 2006 / 01 / 25 NCHC, Taiwan.
All rights reserved © 2000, Alcatel 1 CPE-based VPNs Hans De Neve Alcatel Network Strategy Group.
1 International IP Backbone of Taiwan Academic Networks Wen-Shui Chen & Yu-lin Chang APAN-TW APAN 2003 Academia Sinica Computing Center, Taiwan.
John Silvester University of Southern California APAN 33, Chiang Mai, Thailand Feb 14, 2012.
Multi-Layer Switching Layers 1, 2, and 3. Cisco Hierarchical Model Access Layer –Workgroup –Access layer aggregation and L3/L4 services Distribution Layer.
Module 5: Configuring Access for Remote Clients and Networks.
1 In VINI Veritas: Realistic and Controlled Network Experimentation Jennifer Rexford with Andy Bavier, Nick Feamster, Mark Huang, and Larry Peterson
RIT Campus Data Network. General Network Statistics Over 23,000 wired outlets Over 14,500 active switched ethernet ports > 250 network closets > 1,000.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Data Centers and IP PBXs LAN Structures Private Clouds IP PBX Architecture IP PBX Hosting.
(part 3).  Switches, also known as switching hubs, have become an increasingly important part of our networking today, because when working with hubs,
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
1 Design and Implementation of TWAREN Hybrid Network Management System National Center for High-Performance Computing Speaker: Ming-Chang Liang & Li-Chi.
Innovating the commodity Internet Update to CENIC 14-Mar-2007.
1 October 20-24, 2014 Georgian Technical University PhD Zaza Tsiramua Head of computer network management center of GTU South-Caucasus Grid.
May 2001GRNET GRNET2 Designing The Optical Internet of Greece: A case study Magda Chatzaki Dimitrios K. Kalogeras Nassos Papakostas Stelios Sartzetakis.
Circuit Services - IPTV Christian Todorov Internet2 Fall Member Meeting October 9, 2007.
IPv6 Activities and Future Strategies in Chunghwa Telecom Fu-Kuei Chung Data Communications Business Group Chunghwa Telecom 2003/02.
Chapter 4. After completion of this chapter, you should be able to: Explain “what is the Internet? And how we connect to the Internet using an ISP. Explain.
Next Generation Peering for Next Generation Networks Jacqueline Brown Executive Director International Partnerships Pacific Northwest Gigapop CANS2004,
Connect. Communicate. Collaborate VPNs in GÉANT2 Otto Kreiter, DANTE UKERNA Networkshop 34 4th - 6th April 2006.
1 R&E Network Planning, Engineering and OA&M Capabilities in Taiwan 2006 / 04 / 26 Jing-Jou Yen NCHC, Taiwan.
The Singapore Advanced Research & Education Network.
HOPI Update Rick Summerhill Director Network Research, Architecture, and Technologies Jerry Sobieski MAX GigaPoP and TSC Program Manager Mark Johnson MCNC.
Pacific NorthWest Gigapop, Pacific Wave & International Peering David Morton, PNWGP RENU Technology Workshop.
1 Second ATLAS-South Caucasus Software / Computing Workshop & Tutorial October 24, 2012 Georgian Technical University PhD Zaza Tsiramua Head of computer.
Title of Specific Talk IPv6 Forum IPv6 in Taiwan IPv6 World Congress Meeting Feb 21-23, 2006 Las Vegas Dr. Han-Chieh Chao NICI IPv6 R&D.
Network and Perimeter Security Paula Kiernan Senior Consultant Ward Solutions.
LCG-2 Plan in Taiwan Simon C. Lin and Eric Yen Academia Sinica Taipei, Taiwan 13 January 2004.
Infrastructure and Applications Development of IPv6 in Taiwan 22nd APAN Meeting Singapore, July 18, 2006 Infrastructure and Applications Development of.
A Framework for Internetworking Heterogeneous High-Performance Networks via GMPLS and Web Services Xi Yang, Tom Lehman Information Sciences Institute (ISI)
Delivering Circuit Services to Researchers: The HOPI Testbed Rick Summerhill Director, Network Research, Architecture, and Technologies, Internet2 Joint.
APAN-Taiwan Status Report Yu-lin Chang, APAN-TW APAN 2003 Academia Sinica Computing Centre, Taiwan.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Introducing Network Design Concepts Designing and Supporting Computer Networks.
AARNet Copyright 2007 AARNet IPv6 Update IPv6 Workshop APAN 24, Xi’An 2007 Bruce Morgan.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 1: Introduction to Scaling Networks Scaling Networks.
Taiwan’s TWAREN Initiative Fay Sheu National Center for High-performance Computing Science-based Industrial Park Hsinchu, Taiwan.
© 2006 National Institute of Informatics 1 Jun Matsukata National Institute of Informatics SINET3: The Next Generation SINET July 19, 2006.
1 October 16, 2003 SIP-based VoIP Deployment in Taiwan Speaker: Dr. Quincy Wu National Telecommunications Program Office.
1 Light-path Monitor System of TWAREN Optical Network National Center for High-Performance Computing Speaker: Ming-Chang Liang.
Chapter2 Networking Fundamentals
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Introducing Network Design Concepts Designing and Supporting Computer Networks.
SDSS Data Transfer Jing-Jou Yen Division Manager National Center for High-Performance Computing (August 26, 2005)
1 Design of New TWAREN C. Eugene Yeh, Deputy Director The National Center for High-performance Computing 22 nd APAN Meeting Singapore, July 19, 2006.
I nternational C onnectivity U pdated S tatus for T aiwan 2004 / 01 / 28 Fay Sheu APAN, Honolulu Hsinchu Science Park, Taiwan.
NICI IPv6 Infrastructure Development Status IPv6 Summit in Taiwan 2005 Aug. 23 rd, 2005 Jing-Jou Yen National Center for High-Performance Computing.
Security fundamentals Topic 10 Securing the network perimeter.
TWAREN Update Shu-Cheng Lin NCHC, Taiwan. 2 Outline  New TWAREN International connections - TAIWANLight  TWAREN Optical Network Lab  TWAREN LightPath.
APAN Lambda BoF 1 TWAREN/TAIWANLight : Research and Development 2005 / 01 /26 Te-Lung Liu.
APAN Lambda BoF 1 TWAREN/TAIWANLight : Research and Development 2005 / 01 /26 Te-Lung Liu.
National Center for High-performance Computing1 The TWAREN Initiative An Update Fay Sheu The National Center for High-performance.
Dynamic Network Services In Internet2 John Vollbrecht /Dec. 4, 2006 Fall Members Meeting.
INDIANAUNIVERSITYINDIANAUNIVERSITY HOPI: Hybrid Packet and Optical Infrastructure Chris Robb and Jim Williams Indiana University 7 July 2004 Cairns, AU.
Connecting to the new Internet2 Network What to Expect… Steve Cotter Rick Summerhill FMM 2006 / Chicago.
NOC meeting report Aug. 29, 2003 Kazunori Konishi.
1 TWAREN 混合式網路 監控系統之設計與實作 國家高速網路與計算中心 網路服務組. 2 Outline  Introduction  Motivation  Issues  Design  Implementation  Future works.
HOPI Update Rick Summerhill Director Network Research, Architecture, and Technologies Internet2 Joint Techs 17 July 2006 University of Wisconsin, Madison,
The Internet2 Network and LHC Rick Summerhill Director Network Research, Architecture, and Technologies Internet2 LHC Meeting 23 October 2006 FERMI Lab,
An evolutionary approach to G-MPLS ensuring a smooth migration of legacy networks Ben Martens Alcatel USA.
AARNet Network Update IPv6 Workshop APAN 23, Manilla 2007 AARNet.
Dynamic Network Services In Internet2
Planning and Troubleshooting Routing and Switching
Securing the Network Perimeter with ISA 2004
Integration of Network Services Interface version 2 with the JUNOS Space SDK
AARNet Network Update IPv6 Workshop APAN 23, Manilla 2007 AARNet.
NTHU CS5421 Cloud Computing
Chapter 8 – Data switching and routing
Presentation transcript:

Taiwan Advanced Research and Education Network (TWAREN) - Current status & Future Plan Dr. Te-Lung Liu Researcher National Center for High-Performance Computing

2 Outline TWAREN Network Overview Development and Research Technologies

3 TWAREN Network Overview Development and Research Technologies

4 T ai W an A dvanced R esearch and E ducation N etwork TWAREN

5 What is TWAREN A physical network serves multiple purposes and logical networks TANet, connects to commodity Internet TWAREN research network experiment, testbed, special research Provisioning services on multiple layers L1 lightpaths L2 VLAN L3 IP has been successfully migrated from old backbone in Oct 2006

6 4 core nodes 20G backbone 12 GigaPops Connects HPC resources in North and South Taiwan TWAREN Architecture

7 TWAREN is part of “Challenge 2008”, a comprehensive six- year national development plan formulated by the government Build a highly reliable, stable and flexible R&E network for academic and research community in TW Provide advanced network services to satisfy the needs of academia field in TW. Increase the International and domestic collaboration Future infrastructure drives today’s research agenda Goals of TWAREN

8 TWAREN GigaPoPs

9 TWAREN Services ■ Broadband Connection Service ■ International Research Network Transit (Internet2) ■ Measurement / Network Management ■ Multimedia / Multicast ■ Lightpath provisioning ■ Virtual Private Network(VPN) ■ Native IPv6 Service ■ Internet access  MCU  Proxy Server  SourceForge  File Download Center  Consultation  Applications support

10 High reliability & availability (99.9%  99.99%)‏ fault tolerance automatic protection if possible automatic failure detection and locating Better performance: minimum number of routers between GigaPoPs Flexible: can be easily and quickly to set up a logical network per user’s request People skills: Optical network OAM TWAREN Achivements

11 STM-64 STM-16 NSYSU NCHU NCTU NTHU ASCC NCKU CCU TP HC TN TC NIU NDHU NCU NTU ONS15600 ONS15454 Optical Backbone

12 Interconnecting with L2/L3 devices STM64 STM16 10GE GE NSYSU NCHU NCTU NTHU ASCC NCCU NCKUCCU Taipei Hsinchu Tainan Taichung NCNU NIU NDHU NHLTC NTTU NCU ONS15600 ONS15454 GSR NTU

13 Protection Mechanism Circuit break: 2 levels of protection By carriers: SDH protected By architecture: Link b/w core nodes: VLAN are reconfigured with rapid spanning-tree protocol. (5s)‏ Link b/w GigaPOP and core node: the backup SNCP lightpaths are configured for automatic fail- over. (50ms)‏

14 Protection Mechanism Equipment protection Core node failure : Manually configure emergency lightpaths to re-route traffic from affected GigaPoPs to another core node. Emergency lightpaths need to be designed and documented. GigaPoP failure : Spare line cards

15 NTU Normal Traffic Flows

16 NTU In case of circuit break...

17 STM64 STM16 10GE GE NSYSU NCHU NCTU NTHU ASCC NCCU NCKUCCU Taipei Hsinchu Tainan Taichung NCNU NIU NDHU NHLTC NTTU NCU ONS15600 ONS15454 GSR NTU In case of core node failure...

18 NOC (Network Operation Center) Located at NCHC southern business unit in Tainan Science Park Goals: To ensure the 7x24 network operation Major works: Providing 7x24 network maintenance and operation Enhance the security capacity Provide network service Peering Light path provision Network architecture design TWAREN NOC

19 TANet VPN TANet VLAN NTU6509 NCCU6509 NDHU6509 TP7609C L2 Switch TC7609C L2 Switch HC7609C L2 Switch TN7609C L2 Switch NCHU6509 NTHU6509 NCTU6509 CCU6509 NTTU6509 NCKU6509 NSYSU6509 NHLUE6509 TN7609P MOEcc6509 TC7609 HC7609 NCU6509 One Subnet L2 VLAN

20 TWAREN Research VPN Research VLAN NTU7609P ASCC7609P NDHU7609P TP7609C Switch TC7609C Switch HC7609C Switch TN7609C Switch NCHU7609P NCNU7609P NTHU7609P HC7609P NCTU7609P CCU7609P TN7609P NCKU7609P NSYSU7609P TN12816R TP12816R TC12816P HC12816R NCU7609P TN12816P TP12816P TC12816R HC12816P NIU7609P TAIWANLightTAIWANLight TANet (MOEcc6509) TWGATE Internet ISP Peering ASCC APAN TAIWANLightTAIWANLight TAIWANLightTAIWANLight ISP Peering iBGP RR

21 VPN Services Multipoint-to-Multipoint Layer2 VPN (VPLS) Multiple VPNs over single architecture Cross-area campuses and offices can be connected within single administrative domain Provide dynamic creation of VPNs for National- wide integrated projects User-based SSL VPN Access Access to different VPN according to login name and password authentication Researchers and Professors could access their own research resources from home or outside

22 VPLS Architecture

23 User-Based SSL VPN Access SSL VPN TWAREN VPLS Backbone Core HsinChu Org 1 Org 2 Org 3 Org n Web Browser Users Core Tainan

24 TWAREN’s International Connections  Pacific Crossing to USA’s west coast upgraded to 5 Gb/s  Connections between LA, Palo Alto, Chicago, and New York are 2.5 Gb/s  Connects to the rest of the world via the U.S.’s Abilene Network  Connection expanded to Europe in 2006 (IEEAF donated 622 Mbps of bandwidth/fiber optic cable)‏

25 NCU TP TN-15600TC HC HC TN NCHU-15454CCU-15454NCKU-15454NCSYSU ASCC NIU NDHU NTU-15454NCTU NTHU TP TWAREN Optical Network Palo Alto Chicago LA NY TAIWANLightTAIWANLight Combined TWAREN/TAIWANLight Lambda Testbed

26 TWAREN’s International Peerings  TWAREN made peerings with international NRENs at Los Angeles, Chicago, New York and Seattle (through Pacific Wave).

27 TWAREN’s Direct Peerings Coverage  TWAREN's direct peering covers most area in America, Asia, Australia and New Zealand, and will soon be expanded to Europe.

28 TWAREN/TAIWANLight and GLIF TWAREN is a member of GLIF (Global Lambda Integrated Facility)‏ TAIWANLight is an official optical exchange - GOLE (GLIF Open Lightpath Exchange)

29 TWAREN Network Overview Development and Research Technologies

30 Future Internet Taiwan

31 Future Internet There are many serious limitations in current Internet. Scalability Security QoS Virtualization Future Internet is a summarizing term for worldwide research activities dedicated to the further development of the original Internet. (From Wiki)

32 Future Internet Testbed For innovations and researches in Future Internet, the testbed requires some advanced concepts: Programmability Virtualization End-to-end slice

33 OpenFlow Make deployed networks programmable Makes innovation easier No more special purpose test-beds Validate your experiments on production network at full line speed

34 TWAREN OpenFlow Testbed in 2010 TWAREN L3 Network NOX OpenFlow Switch iCAIR Capsulator OpenFlow OpenFlow NCHC NCKU and KUAS are pilot universities that connected with the Testbed The OpenFlow Testbed is extended to Capsulator (Ethernet-in-IP tunnel) is used to emulate pure L2 network for OpenFlow 34

35 TWAREN VPLS KUAS 35 OpenFlow Switch NCKU OpenFlow Switch CHT-TL OpenFlow Switch NCU OpenFlow Switch NCHC OpenFlow Switch NTUST OpenFlow Switch OpenFlow Switch Capsulator TWAREN OpenFlow Testbed in 2011 NTUST, NCU and CHT-TL joined the Testbed. For TWAREN connectors (NCKU, KUAS and NCU), a dedicated VPLS VLAN is allocated for better transmission performance. lightpath

36 Emulab/ProtoGENI Testbed TWISC (Taiwan Information Security Research and Education Center) operats 206 nodes of Emulab Testbed in Taiwan. Third largest Emulab in the world is operated by NCKU team and co-located in NCHC A portion of the testbed is planned to try ProtoGENI test with University of Utah. A lightpath is provisioned between NCHC and iCAIR shared by both OpenFlow and Emulab/ProtoGENI 36

37 Lightpath and VLAN setup NCHC OF sw AOF sw B iCAIR 7609V NCKU Vlan 462 Vlan 1548 NCKU 7609V NCKU EE Emulab/ProtoGENI – Vlan 462 Lab Vlan 2782 NCKU OF (with iCAIR) – Vlan 1548 Vlan 462 Vlan 1548 Trunk Vlan 462 Vlan 2782 iCAIR OF (with NCKU) – Vlan 2782 Trunk port Vlan 2782 Emulab/ProtoGENI – Vlan 462 Vlan 462 Vlan 2782 Vlan 462 Vlan 2782 Vlan 1548 Vlan 1555 Vlan 1548 Vlan 1555 Vlan

38 iGENI - Taiwan Integrated Research Network 38

39 Multi-Domain OpenFlow Management Each network domain has its own OF Controller Each Controller manages topology and flow provisioning inside the domain Inter-domain flow could be made by connecting partial flows provisioned by controllers of each cloud Lack of global view for inter-domain flows No loops allowed for inter-domain topology Difficult to support QoS or SLA functions across domains Inter-domain topology auto-discovery is required for multi-domain management 39

40 OpenFlow Controller just only knows its directly connected switches. ENVI is a useful GUI tool to show OpenFlow topology under single controller. 40 Controller 1 OF A OF B OF C OF D OF A OF B Topology of Domain1 Controller 2 OF C OF D Topology of Domain2 UI Domain Inter-Domain Topology Discovery (I)

41 We add additional contents in LLDP packet to let Controllers have its neighbors’ connectivity details. ENVI is also modified to show the whole topology. 41 Controller 1 OF A OF B OF C OF D Controller 2 OF A OF B OF C OF D UI Domain Topology of Domain1 & 2 Inter-Domain Topology Discovery (II)

42 Results 42 Physical OpenFlow Network Topology Multi-Domain Network Topology shown in GUI

43 GLIF & SC11 Demo Joint Demo among NCHC/TW, iCair/US, and CRC/Canada

44 Information Security Activity Detection over High-Speed Backbone

45 Security Detection over High- Speed Backbone Normally, we don’t install IDS/IDP in backbone for performance issue. IDS/IDP are placed at user’s local sites Backbone traffic is hard to mirroring due to its large amount and high-speed It’s impossible to do packet analysis Packet header analysis is available with Netflow/sFlow Information Security Activity Detection over High-Speed Backbone Integrate fast packet header analysis with attack information from user’s local site

46 Invasion and attack info from user’s local sites Users’ IDS/IDP Users’ HoneyPot Users’ Log analyzer Security Collect Search Orientation Trace-back Notification Block Backbone’s Netflow data Netflow Data from Backbone/User Routers Users’ Netflow data Notify User with Suspicious Activities Backbone network, peering partner, User network System Architecture

47 Design Concepts Distributed Computing For monitoring netflow data in real-time Fast Search Effective Tree-Searching algorithm Expandable Simply add more machines when larger data analysis is required Remote Backup Separate different computing nodes in order to provide robust analysis service Single Portal All input can be submit to single portal with Global Server Load- Balancing technology Cooperate with Researchers/Developers Will design an open API for developers to contribute their own ideas

48 Design Blocks Controller 2 Distributor 1 Distributor 2 Filter 1Filter 2Filter 3Filter N Analyzer 1Analyzer 2Analyzer 3Analyzer N Controller 1 Router1 Router2 Router3RouterN IDS/IDP Honey... Syslog IPPortTypeAnalyzerAnalyzer Port…… A.A.A.A1234botnet13333 B.B.B.B4321Fake-IP24444 C.C.C.C1122Cracker35555 Blacklist Analyzer 1 P3333 Analyzer 2 P4444 Analyzer 3 P5555 Blacklist Search Tree Update Blacklist Update Search Tree Netflow packet Matched Netflow raw Netflow packet result

49 Numerical Results of Tree Creation

50 Numerical Results of Real-time Matching

51

52

53

54

55

56

57

58 Thank You ! For more information, please see :