DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
TIME Journey to the SPACE
1. 1
Time Journey to the SPACE
James Chin Sze Yih, Principle Engineer
james.chin@time.com.my
The Road to Virtualization: our deployment experience, technical
implications and impact on operations
MYNOG 2019
2. Index
• Background/Drivers for SDN/NFV Deployment
• Key Enablers
• Use Cases
• SDN/NFV Deployment Challenges
• Essential Skills for Next Generation Network Engineers
July 2, 2019 MYNOG 2019 2
3. 3
Flexibility
• High cost and complexity for new
service
• Elastic Capacity
• New Business Models
• Faster Time to Market for New
Services
• Slow service rollout and scaling
• On-demand Service
• Doing more with less
• Reduce OpEx: Operational
Efficiency
• Reduce CapEx: Costs Rise
Faster than ARPU
SPEED COSTFlexibility
Business Challenges in current Service Provider Environment
July 2, 2019 MYNOG 2019
4. Business Challenges in current Service Provider Environment
4
FlexibilitySPEED COSTFlexibility
Automation Virtualization
July 2, 2019 MYNOG 2019
5. The materials to create Rocket
July 2, 2019 5
SDN
approach to network management
that enables dynamic,
programmatically efficient network
configuration in order to improve
network performance and monitoring
making it more like cloud computing
than traditional network management.
ETSI
An independent standardization
organization, that has been
instrumental in developing standards
for ICT within Europe. The WG
develops NFV standards and proofs-
of-concept.
NFV
A network architecture concept
that uses the technologies of IT
Virtualization to virtualize entire
classes of network node functions
OPEN STACK
A Cloud computing platform for
public/private clouds that abstracts
data centers intopools of resources
MYNOG 2019
6. OpenStack Overview
• Cloud computing platform for
Public/Private Cloud
• Abstract data centers into pool of
resources
• Provides management layer for efficient,
automated allocation of resource
• Empower operators, admins, users via
self service portal
• Provides API to develop cloud-aware
application
Image Source: www.openstack.org
API
July 2, 2019 MYNOG 2019 6
7. Network Function Virtualization Overview
Network
Function
Capacity
(Hardware)
Decoupling
Server x86
Hypervisor
VM
OS
Router
VM
OS
Switch
VM
OS
Load
Balancer
VM
OS
Firewall
VM
OS
Media
Server
Approach
July 2, 2019 MYNOG 2019 7
8. VNF Deployment Options
July 2, 2019 8
Bare Metal
• Dedicated Hardware
• High Performance
• Easy to secure
• No Virtualization
overhead
Virtual Machine
• Shared host for
multiple VNF
• Performance limited
by virtualization
• No shared kernel->
More secure
Containers
• Shared host for
multiple VNF
• Bare metal
performance
• Share kernel with
host -> less secure
Image Source: Cisco MYNOG 2019
9. NFV or VNF or Service Chain
• Network Function Virtualization
• Refers to the idea of replacing dedicated network appliances (such as routers and
firewalls) with software running on standard servers.
• Typically includes a Hypervisor and the software runs as a Virtual Machine
• Virtual Network Function
• One or more Virtual Machines performing a single network function
• Service Chain
• Collection of 1 or more VNFs providing a network service
July 2, 2019 MYNOG 2019 9
11. Network Function Virtualization framework (NFV MANO)
• Three functional blocks
• Virtualized Infrastructure Manager (VIM)
• VNF Manager (VNFM)
• NFV Orchestrator (NFVO)
• Main function
• The “brain” of NFV architecture
• End-to-end service and NFV network mapping
• Managing the life cycle of VNFs
• Create VNF
• Scale VNF (increase or reduce the capacity
of the VNF)
• Terminate VNF
• Interfacing with OSS systems
July 2, 2019 MYNOG 2019 11
12. What is SDN ?
Many different thing to many different people
July 2, 2019 MYNOG 2019 12
13. SDN - The Programmable Network Overview
Source: www.opennetworking.org
Southbound API
Northbound API
(Network abstraction)
E.g. RESTAPI,JSON,XML
Centrally managed:
Network intelligence is (logically) centralized in
software-based SDN controllers that maintain a
global view of the network, which appears to
applications and policy engines as a single, logical
switch.
Southbound API
(Vendor-neutral)E.g.
Openflow,SNMP,NETCONF,etc…
July 2, 2019 MYNOG 2019 13
Northbound API
14. SDN-DC based provisioning with OpenStack
Tenant Portal Admin Portal
Orchestration
Tenant Carrier Admini
SDN-O NFVO
RESTful RESTful
VNFMSDN Controller
self-service purchase,
One-Click Delivery
NetConf
Service Provisioning
1. Create Tenant
2. Create Network (Layer-2 Segment)
3. Attach VM to Network
4. L2 and Layer-3 VXLAN Services is
Configured across the Managed Leafs
Live Migration
1. Create Tenant at new host
2. Create Network (Layer-2 Segment)
3. Attach VM to Network
4. L2 and Layer-3 VXLAN Services is
Configured across the Managed Leafs
Slide with animation
Rack 1
SPINE
SWITCH
LEAF
SWITCH
July 2, 2019 MYNOG 2019 14
Rack 2
15. Use Case 1-Virtual Managed Service
July 2, 2019 MYNOG 2019 15
LAN GW
Internet
MPLS L2VPN VxVLAN
LAN GW
CPE
vCPE /vFWPress Release
16. Use Case 2-Virtual Carrier WiFi Core
July 2, 2019 MYNOG 2019 16
Internet
MPLS L3VPN VxVLANData Plane
DHCP AAA
Landing Page
vCGNAT
Wireless AC
MPLS L3VPN VxVLANControl Plane
17. Use Cases-Secured Public Cloud Service
July 2, 2019 MYNOG 2019 17
LAN GW
Internet
CPE
WAF / LBUTM
IAM / PAM
Secured Remote
Access
Security Services Layer Cloud Compute Resource
18. Future Plan- End-to-end Service Orchestration
July 2, 2019 MYNOG 2019 18
Tenant Portal Admin Portal
Self-Activation & Self-Service
LAN GW
Internet
CPE
Service Orchestrator
SDN-WAN Controller SDN-DC Controller MANO
19. Building Block of the design
19
Application Layer/ App Server
Integrate/Install/Test
Big Data Analytics
Orchestration
VIM Management System
SDN Controller
Operating Systems
IO Abstraction & Accelerator
Hardware
July 2, 2019 MYNOG 2019
20. The Challenges of SDN/NFV
May Not be That Simple As it Appears
Focus and choice
July 2, 2019 MYNOG 2019 20
22. Essential Skills for Next Generation Network Engineers
July 2, 2019 MYNOG 2019 22
Python
XML/JSON
BGP
EVPN
NETCONF/
YANG
Container
Virtualization
Linux Shell
SCRIPTING
NETWORK
PROGRAMMING
SERVER
DC Network
OPPORTUNITIES
VXLAN
Segment
Routing
23. Summary
• Business Challenges in current Service Provider Environment
• Drivers for SDN/NFV Deployment from Operator’s view
• OpenStack Overview
• Network Function Virtualization Overview
• ETSI NFV Architectural Framework
• SDN - The Programmable Network Overview
• Use Cases
• SDN/NFV Deployment Challenges
• Essential Skills for Next Generation Network Engineers
July 2, 2019 MYNOG 2019 23