Showing posts with label HP. Show all posts
Showing posts with label HP. Show all posts

Friday, October 3, 2014

OpenDaylight - an alternative to VMware NSX and Cisco XNC.



Before I worked on this blog post, I always think that OpenDaylight is a SDN Controller.  While it is correct to say that OpenDaylight is a SDN controller, it is in fact an Open Source project in which the controller is the core functionality.  In OpenDaylight wiki page, we can see a list of projects that is under the umbrella of OpenDaylight Project from the Linux Foundation. 

OpenDaylight Project is described by this web site as:
The OpenDaylight Project is a collaborative open source project that aims to accelerate adoption of Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) for a more transparent approach that fosters new innovation and reduces risk. Founded by industry leaders and open to all, the OpenDaylight community is developing a common, open SDN framework consisting of code and blueprints

According to Neel Jacques, executive director of OpenDaylight:
“The OpenDaylight community has taken on the monumental task of bringing together all the disparate technologies, thoughts and ideas around SDN and forming it into a cohesive platform. The community has made amazing progress in a short amount of time as you can see in this second release which integrates more functionality, apps and use cases. Helium brings us one step closer to having one common platform the entire industry can standardize on.”

OpenStack name its release by city or street name.  OpenDaylight name its release by elements in the Periodic Table.  The first release was Hydrogen and the second release was Helium.  The OpenDaylight Helium release was available for download as of September 29, 1014.

Image source: https://www.sdncentral.com/wp-content/uploads/2014/09/opendaylight-project-helium-diagram.jpg

From OpenDaylight’s announcement “OpenDaylight paves way for innovation in SDN with latest open source software release”, I have summarized what’s new in the Helium release:

  • 11 new protocols, applications and technologies
  • New User Interface
  • Simpler and customizable installation process
  • User can build on-demand combinations of components and features to customize their solutions
  • Open vSwitch Database Integration Project that provides technology preview of advanced OpenStack features
  • High Availability
  • Clustering
  • Security
  • OpenFlow Table Type Patterns
  • Service Function Chaining

There are 3 things that I would like to highlight and comment:

1. Apache Karaf
One good feature for the Helium release is that user can build on-demand combinations of components and features for OpenDaylight.  This is done by Apache Karaf which is a small OSGi (Open Service Gateway initiative) based run time lightweight container where different components and applications can be deployed.  The best feature in my opinion is the ability to check for component dependencies.  Remember the days how we install packages onto a Linux system before apt-get or yum?

2. Integration with OpenStack
I believe for OpenDaylight to have more integration with OpenStack will entice more commercial IT vendors to embrace OpenDaylight.  Both VMware and Cisco announced integration with OpenStack and there are quite a few companies such as Rackspace, Metacloud, Mirantis, Cloudscaling, IBM and Red Hat that provide value added and easy installation for the Open Source OpenStack.

Work is done for the OVSDB (Open vSwitch Database) driver to provide features such as:

  • Distributed L3 Forwarding
  • Distributed ARP handling
  • Security Group
  • Load Balancing as a Service
  • Firewall as a Service

This makes OpenDaylight an attractive choice as a OpenStack Neutron back end.  Also, there is a new feature to provide VLAN networking in addition to the tunnel-based networking option when a virtual network is created in OpenStack Neutron.

Interface with OpenStack with Keystone via the OpenDaylight AAA project is a big step forward between OpenDaylight and OpenStack integration.

3. Security
In the Hydrogen release, there is the Defense4All project for mitigating Distributed DoS attacks.  In the Helium there are 2 new projects for security:

  1. Authentication, Authorization and Accounting (AAA)
  2. Secure Network Bootstrapping Infrastructure (SNBi) project.

In this article, author Sean Michael Kerner stated that “Security is a particular area of focus in the Helium release”.

Authentication, Authorization and Accounting
AAA has been around for some time and is a popular and widely used security architecture where user’s credential is authenticated and based on the outcome of the authentication process, access for resources are granted/authorized while accounting will record this process so as to provide an audit trail.

According to a Red Hat blog, AAA project provides:

  1. The ability to provide fine-grained permissions for resource usage
  2. The ability to share an external identity service with other platforms

In our case as mentioned on the previous section, the external identity service will be OpenStack Keystone.

Secure Network Bootstrapping Infrastructure
This feature helps to solve the problem of having to manually distribute keys for the different networking device to communicate with each other. 

This page has more information about how this works.

Conclusion:
Besides, OpenStack integration and security both High Availability and clustering are important feature for the enterprise. OpenDaylight Helium is a big step forward from the Hydrogen release and hopefully more vendors will embrace OpenDaylight and provide this as an alternative to 

  • Cisco - Extensible Network Controller
  • HP - Virtual Application Networks (VAN) Controller
  • NEC - ProgrammableFlow PF6800 Controller
  • Nuage Networks - Virtualized Services Controller  
  • VMware - NSX Controller


Monday, September 1, 2014

VMware NSX and HP VAN SDN Controller - a value added solution



I am a software developer and for a long time when I implement a feature SNMP support for the feature is always done last and sometime delayed to a future release.  Back then, functionality of the feature was the most important thing in my mind.  As I venture into server virtualization, I start to see the perspective of a system administrator or a network administrator.  Monitoring and reporting is very important and sometimes more important than a feature set delivered by the vendor.  Of course maintaining the five 9s of uptime is always the highest priority.

These days I am looking into NSX.  Derek Seaman has a blog post on “VMworld 2014: Future Direction of NSX” where he summarize session NET1674.  Chris Wahl has a post on NSX 6.1 (4.2 for the NSX Multi-hypervisor).

I came across an article with the title “The industry’s east-west federated solution”.

After reading the title, 2 questions come to my mind.  What is:

  • East-West traffic?
  • The solution for what problem?

East-West Traffic
In simple term, east-west traffic refers to the traffic between servers in a data center.  There is another term – north south traffic and this refers to the traffic between clients and servers in a data center.  Traffic from client to the server will be northern bound traffic while traffic from server to the client is called southern traffic.



A Solution to a problem
First of all what is this solution?  What problem is this trying to solve?  The problem is that virtual network has not visibility to the physical network.  For a user or virtualization/network administrator this is not a big problem.  This will just be an inconvenience because there are tools to monitor, view and debug the virtual and physical network individual.  At the end of the day, user still has the tools to perform their job.

From the perspective of automation or orchestration, this is a big problem. 

A Federated Solution
Why federated?  The solution calls for a federation of 2 products to solve the problem.  The 2 products are VMware’s NSX and HP’s VAN Controller which one of HP’s SDN solution.

VMware NSX
Tons of information can be found about VMware’s NSX.  Not too many people have the luxury of having the opportunity to play around with this product.  In VMworld 2014, VMware announced a new certification track for Network Virtualization which has high NSX concentration.  Information on this certification track can be found here.


Image source: http://blogs.vmware.com/education/files/2014/08/VMW_14Q3_Cert_Roadmap_Network_Virtualization_R3.jpg

As of this writing, I see on twitter that a few people had sit for the VCP-NV certification and a few already achieved VCDX-NV status and they we being introduced on VMworld 2nd day Keynote session.  The VCIX-NV is not available yet and this should be equal as getting a VCAP level certification and one of the requirements to sit for this certification is a person is a CCNP or CCIE holder.  This requirement shows that VMware is trying to get Cisco certification holders to get into VMware’s SDN solution.

When we look at VMware NSX, we can approach this from 2 angels.  Its capabilities and its components

VMware’s NSX has the following Capabilities:

  • Logical Switches
  • Logical Routers
  • Logical Firewall
  • Logical VPN
  • Logical Load Balancer

VMware’s NSX has the following components

  • NSX Manager
  • NSX vSwitch
  • NSX Controller
  • NSX Edge

All the NSX components can be configured using vSphere Client, VMware command line interface (CLI) and REST API. 
The REST API is essential for 3rd party software entities to interface with NSX.

HP’s SDN Technology
This page contains a very comprehensive description of HP’s SDN technology.  One of HP’s SDN offering is HP Virtual Application Network SDN Controller.  It is described as a control point in an OpenFlow-enabled network, simplifying management, provisioning, and orchestration. This enables delivery of a new generation of application-based network services and provides open application program interfaces (APIs) that allow third-party developers to deliver innovative solutions to dynamically link business requirements to network infrastructure via either custom Java programs or general-purpose RESTful control interfaces. HP VAN SDN Controller Software is designed to operate in campus, data center, or service provider environments

This HP VAN SDN controller is recommended to run on an Ubuntu 64-bit server with 12.04 LTS.  It requires a back end database.  The recommended database platform is PostgreSQL 9.1.  OpenJDK 7 JVM is also required.

Integrating VMware and HP’s solution
The 2 companies has entered into a joint development of a solution that will combine the strength of the 2 SDN solutions that according to a white paper to provide customers unified automation and visibility of the physical and virtual data center networks, enabling  business agility and improving business continuity.


The integration of the 2 controllers is using OSVDB (Open vSwitch Database Management Protocol).  The HP controller is acting as an OSVDB server while the VMware NSX controller is acting as an OSVDB client.  Both controller are able to communicate with each other via the OSVDB federated API.

HP blog is saying the integration is at the control plan.  When I look into OSVDB, I believe this should be the combination of the management and control plan where OSVDB is for management similar to NETCONF and control plan is where the OpenFlow protocol resides in which is being use to program traffic flows.
This solution will be available in the 4th quarter of 2014.