Brocade Flow Optimizer

Slides:



Advertisements
Similar presentations
Towards Software Defined Cellular Networks
Advertisements

Layer 3 Switching. Routers vs Layer 3 Switches Both forward on the basis of IP addresses But Layer 3 switches are faster and cheaper However, Layer 3.
Firewalls By Tahaei Fall What is a firewall? a choke point of control and monitoring interconnects networks with differing trust imposes restrictions.
IUT– Network Security Course 1 Network Security Firewalls.
Use Cases for I2RS I2RS Interim Meeting Nicolai Leymann, Deutsche Telekom AG
Multi-Layer Switching Layers 1, 2, and 3. Cisco Hierarchical Model Access Layer –Workgroup –Access layer aggregation and L3/L4 services Distribution Layer.
CSCI 530 Lab Firewalls. Overview Firewalls Capabilities Limitations What are we limiting with a firewall? General Network Security Strategies Packet Filtering.
ViSION Status Update Dan Savu Stefan Stancu 1D. Savu - CERN openlab.
SDN and Openflow.
1 Version 3.0 Module 8 Virtual LANs. 2 Version 3.0.
NetFlow Analyzer Drilldown to the root-QoS Product Overview.
Jaehoon (Paul) Jeong, Hyoungshick Kim, and Jung-Soo Park
A Guide to major network components
Transport SDN: Key Drivers & Elements
© 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION Mohammad Hanif June 2015 Optimal Flow Placement in SDN Networks.
Networking Components Chad Benedict – LTEC
Virtual LANs. VLAN introduction VLANs logically segment switched networks based on the functions, project teams, or applications of the organization regardless.
Networking Components
Workshop on Software Defined Networks Spring 2014.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Introducing Routing and Switching in the Enterprise – Chapter 1 Networking.
Cellular Core Network Architecture
CONVERGENCE KO Meeting EXPRESS: Implementing an SDN infrastructure over a federation of testbeds (experiment within the OpenLab project) Stefano Salsano.
AIMS’99 Workshop Heidelberg, May 1999 Ko / CP 4/99 Linkage between Internet Service Architectures and ATM
OpenFlow: Enabling Technology Transfer to Networking Industry Nikhil Handigol Nikhil Handigol Cisco Nerd.
Software-Defined Networks Jennifer Rexford Princeton University.
LARK Bringing Distributed High Throughput Computing to the Network Todd Tannenbaum U of Wisconsin-Madison Garhan Attebury
Software-defined Networking Capabilities, Needs in GENI for VMLab ( Prasad Calyam; Sudharsan Rajagopalan;
Othman Othman M.M., Koji Okamura Kyushu University 1.
Firewall Network Processor™: Technical Concept and Business Solutions FNP™ – is a trademark of Fractel Inc. December 2008 Columbus.
INTERNATIONAL NETWORKS At Indiana University Hans Addleman TransPAC Engineer, International Networks University Information Technology Services Indiana.
Network Presence, LLC SM Innovative Security Solutions SM Understanding, Planning For, and Responding To Denial of Service Attacks SANS 2001.
Chapter 5: Implementing Intrusion Prevention
Othman Othman M.M., Koji Okamura Kyushu University 1.
WLCG Networking Tony Cass, Edoardo Martelli 11 th April 2015.
Networks and Protocols CE Week 2a. Network hardware.
© 2015 BROCADE COMMUNICATIONS SYSTEMS, INC THAT’S THE ANSWER WHAT’S THE QUESTION? Software Defined Networking Dan DeBacker Principal.
Content-oriented Networking Platform: A Focus on DDoS Countermeasure ( In incremental deployment perspective) Authors: Junho Suh, Hoon-gyu Choi, Wonjun.
Securing the Network Infrastructure. Firewalls Typically used to filter packets Designed to prevent malicious packets from entering the network or its.
Thanks to Edoardo Martelli, Stefan Stancu and Adam Krajewski
SDN AND OPENFLOW SPECIFICATION SPEAKER: HSUAN-LING WENG DATE: 2014/11/18.
Chapter 3 - VLANs. VLANs Logical grouping of devices or users Configuration done at switch via software Not standardized – proprietary software from vendor.
SDN and Openflow. Motivation Since the invention of the Internet, we find many innovative ways to use the Internet – Google, Facebook, Cloud computing,
An Application of VoIP and MPLS Advisor: Dr. Kevin Ryan
1 | © 2015 Infinera Open SDN in Metro P-OTS Networks Sten Nordell CTO Metro Business Group
CellSDN: Software-Defined Cellular Core networks Xin Jin Princeton University Joint work with Li Erran Li, Laurent Vanbever, and Jennifer Rexford.
SOFTWARE DEFINED NETWORKING/OPENFLOW: A PATH TO PROGRAMMABLE NETWORKS April 23, 2012 © Brocade Communications Systems, Inc.
Brocade Flow Optimizer CERN openlab
Networking Components Assignment 3 Corbin Watkins.
BEIJING-LCG Network Yan Xiaofei
Why Fabric? 1 Complicated technology/vendor/device specific provisioning for networks, especially heterogeneous network DC Network – STP, TRILL, SPB, VXLAN,
Juniper Networks Mobile Security Solution Nosipho Masilela COSC 356.
Time Series Data Repository #ODSummit - The Generic, Extensible, and Elastic Data Repository in OpenDaylight for Advanced Analytics.
100GE Upgrades at FNAL Phil DeMar; Andrey Bobyshev CHEP 2015 April 14, 2015.
Multiprotocol Label Switching (MPLS) Routing algorithms provide support for performance goals – Distributed and dynamic React to congestion Load balance.
OpenFlow: What’s it Good for? Apricot 2016 Pete Moyer Principal Solutions Architect.
Brocade Software Networking Openness. Agility. Economics. © 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION Curt Beckmann EMEA.
أمن المعلومات لـ أ. عبدالرحمن محجوب حمد mtc.edu.sd أمن المعلومات Information Security أمن المعلومات Information Security  أ. عبدالرحمن محجوب  Lec (5)
InterVLAN Routing 1. InterVLAN Routing 2. Multilayer Switching.
Denial of Service Mitigation with OpenFlow using SciPass
SDN challenges Deployment challenges
Distributed Mobility Management for Future 5G Networks : Overview and Analysis of Existing Approaches IEEE Wireless Communications January 2015 F. Giust,
University of Maryland College Park
Computer Data Security & Privacy
Virtual LANs.
The Stanford Clean Slate Program
* Essential Network Security Book Slides.
ClosedFlow: OpenFlow-like Control over Proprietary Devices
Chapter 3 VLANs Chaffee County Academy
OpenSec:Policy-Based Security Using Software-Defined Networking
Intelligent Network Services through Active Flow Manipulation
Presentation transcript:

Brocade Flow Optimizer 05/11/2015 Openlab Technical Workshop Adam Krajewski Edoardo Martelli Stefan Stancu

Brocade Flow Optimizer software An SDN application for optimal network traffic flow management OpenDaylight controller for OpenFlow-based network control sFlow for monitoring the network traffic Flow management through policies Traffic pattern match Decision how to handle the flow (drop, redirect etc) User friendly GUI provides interactive and real-time events logs and traffic statistics Collaboration goal: Enhance and generalize the Brocade Flow Optimizer architecture to meet CERN requirements 05/11/2015 IT-CS-CE - CERN openlab

IT-CS-CE - CERN openlab Use case 1: Intelligent Dynamic Policy Based Routing Open Daylight Brocade Flow Optimizer Internet traffic (non-physics) accidentally arriving via “physics” network. physics data Two distinct external networks Internet LHC dedicated (physics data) Use Brocade Flow Optimizer to ensure that: Physics data stays on the physics network Internet data stays on the campus network 05/11/2015 IT-CS-CE - CERN openlab

Use case 2: firewall offload Use Brocade Flow Optimizer to: Identify top talkers The user can decide what to do with such flows: Discard (e.g. DDoS attack) Bypass Firewall (know trusted traffic) Don’t touch (neutral internet traffic) Twofold optimization Offload firewall (expensive resource) from handling high amounts of trusted traffic Higher bandwidth for physics research traffic Brocade Flow Optimizer Open Daylight 05/11/2015 IT-CS-CE - CERN openlab

Use case 3: IDS traffic mirroring Use OpenFlow technology OpenFlow gives high flexibility for specific fields to be matched for traffic flows Use Brocade Flow Optimizer for scalable and flexible flow mirroring distributed mirroring traffic matching IP=***0  mirror to port 1 (IDS - 1) traffic matching IP=***1  mirror to port 2 (IDS - 2) don't mirror trusted traffic traffic matching trusted IP  “forward normal” Open Daylight Brocade Flow Optimizer 05/11/2015 IT-CS-CE - CERN openlab

IT-CS-CE - CERN openlab Current status Current status: Lab environment ready ICX Campus LAN switches at CERN MLX Series Core Routers at Brocade Fellow integrated with the Brocade developer team Playing an active role in the development Some code already pushed and merged successfully Firewall offload use case already addressed in the Brocade Flow Optimizer 1.1 release Other use cases to be tackled in the future releases 05/11/2015 IT-CS-CE - CERN openlab