Brocade Software Networking

1y ago
9 Views
2 Downloads
3.44 MB
25 Pages
Last View : 17d ago
Last Download : 3m ago
Upload by : Kaydence Vann
Transcription

Brocade Software Networking 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION

Agenda Industry Trends Quick SDN / NFV Overview Introduction of Brocade SDN / NFV Portfolio Brocade Flow Optimizer REN Use Cases 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 2

Agenda Industry Trends Quick SDN / NFV Overview Introduction of Brocade SDN / NFV Portfolio Brocade Flow Optimizer REN Use Cases 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 3

An Industry in Transition 7B 3rd Platform Mobile devices Intern et Users We bsit es 2015 100 M Mobile Expectations 2B Cloud Mobile “Digital business” Social Data AnalyticsIT Relevance 1B 2nd Platform devices 2700 Websites 16 M Gap Delivery Client-Server LAN/WAN ,Internet & IP Networks Internet Users 1995 1st Platform 1975 Mainframes, PCs SNA Arch, Private Lines 4 2014 BROCADE COMMUNICATIONS SYSTEMS, INC.

What the 3rd Platform Looks Like 7B 3rd Platform Mobile devices Intern et Users We bsit es New IP Orch Expectations 2B Closed Proprietary HW Proprietary OS Proprietary Apps Reactive Isolated elements Manual High cost Slow Overlay innovation Cloud Mobile “Digital business” Social Data Analytics 1B Open Commodity HW Open Source OS Interoperable Apps Proactive Integrated system Automated Low cost Rapid innovation NFV IT Relevance Gap Delivery To From SDN Underlay Fabrics Edge Compute Storage Networkin g 5 2014 BROCADE COMMUNICATIONS SYSTEMS, INC

New IP—Transformation of the A Customer Driven Disruption Network How You See It Today The New Vision Open with a purpose Open source, interoperable protocols Innovation at software speeds Agility, Training, Partnering, Services Ecosystem-compatible Legacy NG Features, Open solutions Interfaces Your pace, your path Solutions with interoperable components 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 6

Agenda Industry Trends Quick SDN / NFV Overview Introduction of Brocade SDN / NFV Portfolio Brocade Flow Optimizer REN Use Cases 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 7

Software Defined Networking (SDN) A Programmable Network—Design, Build, Manage Applications and Orchestration Frameworks Key Features Network algorithms decoupled from Hardware REST APIs Advantages Control Plane Basic Network Services: Topology Mgr, Switch Mgr, Host Tracker, Stats Mgr Network protocols like OpenFlow Data Plane Network automation can integrate with other disciplines Less lock-in; Users can choose features to suit their needs Networking control can innovate at software speeds 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 8

Network Functions Virtualization (NFV) Main Features Hardware Software Router Complex networking functions in software on commodity servers VPN Simpler networking functions in commodity networking devices Advantages Remove hardware lock-in Simplify resource planning Firewall Enable fast service innovation Soft upgrades Meet SLAs Reduce CAPEX/OPEX 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 9

Agenda Industry Trends Quick SDN / NFV Overview Introduction of Brocade SDN / NFV Portfolio Brocade Flow Optimizer REN Use Cases 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 10

Brocade Software Networking Agile, Open, Economics Brocade SDN Controller Web Server 1 Web Server 2 IPsec Web Client Brocade vRouter Brocade Brocade vRouter vADC Branch Cloud Web Server 3 Data Center Virtualized Core for Mobile 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 11

Brocade SDN Apps Brocade Flow Brocade Flow Brocade Visibility It delivers: Backbone Circuit Provisioning Provides Network sensor services without disruption Manages Brocade Packet Use Cases: Software Defined Backbone A) Threat Mitigation B) Large Flow Monitoring Optimization A) Traffic aggregation, and load-balancing to B) Advance/Expert Interface 3rd-party integration Target Production Backbone - Enterprise - REN - Colo DC Production Network: - Campus - DC Core/Border - ISP Peering Router - REN HPC Visibility Network: - Large Enterprise - REN - DC 2016 BROCADE COMMUNICATIONS SYSTEMS, INC 12

Brocade OpenFlow-capable Hardware Families The MLXe Router and ICX Campus product lines ICX 7450 Switch ICX 7250 Switch ICX 6610 Switch ICX 6450 Switch ICX 7750 Switch MLXe Series Routers 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 13

Agenda Industry Trends Quick SDN / NFV Overview Introduction of Brocade SDN / NFV Portfolio Brocade Flow Optimizer REN Use Cases 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 14

L2 / L3 Firewall Bypass Science-DMZ Use Case WAN/ Internet Brocade Flow Optimizer recognizes this as a trusted flow and programs Brocade MLXe using the controller to bypass the firewall for this flow 4 Incoming flow from upstream network Brocade Flow Optimizer Brocade SDN Controller Open Daylight 3 L3 MLXe: VRF (1 & 6) and OF, or PBR (2) for one arm FW traffic and OF (1 & 6) BFO 1.2 can ensure flow in both directions is redirected via two action policies (stateful FW) 1 Sent to Firewall for processing 2 5 Firewall Brocade MLXe Router 6 ”White-listed” flow now bypasses Firewall and data transfer is faster and more efficient HPC/DTN Network HPC: High Performance Computing DTN: Data Transfer Nodes 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 15

Priority Data Superhighway Campus Slowpath-Bypass Use Case Brocade Flow Optimizer recognizes this as a trusted flow and that it is either a “large flow” or “priority application”. Programs Brocade ICX/MLXe using the controller to re-direct the traffic to priority path for this flow 4 Incoming flow from High Performance Workstation/server Brocade Flow Optimizer Brocade SDN Controller Open Daylight 3 L2 or L3 redirect action Need to ensure flow in both directions is redirected via policy 5 1 Brocade ICX or MLXe ”White-listed” flow now placed on priority path and data transfer is faster and more efficient Routed using normal routed/switched path 2 6 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 16

Summary of Additional REN Use Cases REST API L7 / Botnet Attack Mitigation Internet L2-L4 Volumetric Attack Mitigation Brocade Flow Optimizer BGP Remote Triggered Black Hole (RTBH) Mitigation Brocade SDN Controller Open Daylight Brocade MLXe DC Flow Management for Policy-based Security 2016 BROCADE COMMUNICATIONS SYSTEMS, INC 17

Thank you 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 18

Backup 2015 BROCADE COMMUNICATIONS SYSTEMS, INC. COMPANY PROPRIETARY INFORMATION 19

L7 and Botnet Attack Mitigation REST API Internet Brocade Flow Optimizer initiates mirror action. 5 1 Incoming Attack Flow 2 IDS detects L7 attack (Example; SYN Flood). API to BFO to discard flow. Brocade Flow Optimizer Brocade SDN Controller Open Daylight 3 6 Adds ability for advanced DDoS detection, up to L7 Based upon the IDS (Palo Alto, Arbor etc.) detection capability API from IDS to BFO initiates additional discard actions MLXe mirrors flows to IDS. OF “mirror normal” action. Brocade MLXe 4 OF discard action. Brocade MLXe Brocade MLXe 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 20

L2-L4 Volumetric Attack Mitigation Internet Brocade Flow Optimizer recognizes this as a L2-L4 Volumetric Attack. 3 1 Incoming Attack Flow Brocade Flow Optimizer Brocade SDN Controller Open Daylight Local Mitigation: Discard Flow (Redirect Optional) 4 2 Recommended when incoming aggregate attack traffic is 50% or less L2 – L4 local mitigation, based on sFlow sampling and DDoS policy OF discard action (Automated, Manual) Brocade MLXe Brocade MLXe 5 Brocade MLXe 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 21

BGP Remote Triggered Black-Hole (RTBH) Mitigation Internet Brocade Flow Optimizer recognizes this as a L2-L4 Volumetric Attack. 3 Brocade SDN Controller Flow Optimizer initiates CLI static route to MLXe. Open Daylight 6 4 2 L2 – L4 local mitigation does not protect upstream link If upstream link is congested above 50% by DDoS, add ability for RTBH to uncongest RTBH is a well known Internet operation Automated RTBH reduces mitigation 8 7 MLXe advertises BGP Route (ex: /32, /28, /24, /23) Brocade Flow Optimizer Upstream BGP router: A) Discards flow to null0, or B) Re-directs traffic to cleaning site Brocade MLXe 1 Incoming Attack Flow Mitigation: Discard Flow Brocade MLXe (Triggering Device) 5 Brocade MLXe 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 22

L2 Firewall Bypass Science-DMZ Use Case WAN/ Internet Brocade Flow Optimizer recognizes this as a trusted flow and programs Brocade MLXe using the controller to bypass the firewall for this flow 4 Incoming flow from upstream network Brocade Flow Optimizer Brocade SDN Controller Open Daylight 3 1 Sent to Firewall for processing 2 5 Firewall Brocade MLXe Router L2 MLXe BFO 1.2 can ignore, push, pop or modify VLAN ID BFO 1.2 can ensure flow in both directions is redirected via two action policies (stateful FW) 6 ”White-listed” flow now bypasses Firewall and data transfer is faster and more efficient HPC/DTN Network HPC: High Performance Computing DTN: Data Transfer Nodes 2016 BROCADE COMMUNICATIONS SYSTEMS, INC 23

L3 Firewall Bypass Science-DMZ Use Case WAN/ Internet Brocade Flow Optimizer recognizes this as a trusted flow and programs Brocade MLXe using the controller to bypass the firewall for this flow 4 Incoming flow from upstream network Brocade Flow Optimizer Brocade SDN Controller Open Daylight 3 L3 MLXe: VRF (1 & 6) and OF, or PBR (2) for one arm FW traffic and OF (1 & 6) BFO 1.2 can ensure flow in both directions is redirected via two action policies (stateful FW) 1 Sent to Firewall for processing 2 5 Firewall Brocade MLXe Router 6 ”White-listed” flow now bypasses Firewall and data transfer is faster and more efficient HPC/DTN Network HPC: High Performance Computing DTN: Data Transfer Nodes 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. 24

Enterprise DC Flow Management for Policy-Based Security Operator driven or sFlow threshold driven policy enforcement for large trusted flows Enterprise Datacenter 1 Enterprise Datacenter 2 One-armed Firewall Inline Firewall WAN Brocade Flow Optimize r Default Traffic Flow Trusted Traffic Flow Brocade Internet SDN Controll er 2016 BROCADE COMMUNICATIONS SYSTEMS, INC.

Brocade SDN Controller Brocade vADC Web Server 1 Web Server 2 Web Server 3 Data Center Virtualized Core for Mobile. 12 Brocade SDN Apps Brocade Flow Brocade Flow Brocade Visibility It delivers: Backbone Circuit Provisioning Provides Network sensor services without disruption Manages Brocade Packet Use Cases: Software Defined

Related Documents:

Brocade ICX 6430 Brocade ICX 6450 Brocade FCX Brocade ICX 6610 Access Edge Brocade FastIron SX Brocade MLXe Brocade ICX 6610 Aggregation/Core Brocade ICX 6650 Brocade ICX 6610 FCX-E / FCX-I ToR/EoA CAMPUS NON-FABRIC DC Brocade ICX 6650 Brocade Network Advisor Brocade ICX 7750 Brocade ICX 7750 A COMPREHENSIVE CAMPUS

Brocade 6505 switch Brocade 6510 switch Brocade 6520 switch Brocade 7800 extension switch Brocade 8000 FCoE switch Brocade VA-40FC Brocade Encryption Switch Brocade DCX Brocade DCX-4S Brocade DCX 8510-4 Brocade DCX 8510-8 What's new in this document Updated for Brocade Fabric OS v7.1.0, including .

Brocade DCX-6730-76 Brocade VDX 6730-32 (3759-C32) Brocade DCX-6730-32 IBM Network Advisor Enterprise & Pro IBM SAN06B-R (FC 7732) Brocade 7800 IBM 2498-384 (FC 3890) Brocade FX8-24 IBM 2498-384 (FC 3880) Brocade DCX IBM (69Y1909) Brocade 8470 IBM SAN32B-E4 (2498-E32) Brocade BES

Brocade X6-4 Director and Brocade X6-8 Director with one or more Brocade SX6 Extension Blades Brocade DCX 8510-4 Backbone and Brocade DCX 8510-8 Backbone with one or more Brocade FX8-24 Extension Blades As described in this configuration guide, the software supported is Brocade Fabric OS 8.2.1. Brocade Fabric OS Extension User Guide, 8.2.1

Brocade Access Gateway features in Fabric OS 8.2.1 are supported on the following hardware platforms. Brocade Gen 5 Platform (16Gb/s) Fixed-Port Switches Brocade 6505 Switch Brocade 6510 Switch Brocade M6505 blade server SAN I/O module Brocade 6542 blade server SAN I/O module Brocade 6543 blade server SAN I/O module

Brocade MIB Reference Manual v3.0 53-0000134-03 July 2001 Brocade MIB Reference Manual v3.0, 4.0 53-0000184-02 March 2002 Brocade MIB Reference Manual (v4.1, v4.0.x, v3.1, v3.0.x, v2.6.x) . Brocade 300, 5100, and 5300 switches. March 2008 Brocade Fabric OS MIB Reference 53-1001156-01 Updated to support the Brocade DCX-4S and Brocade

compatibility matrix, brocade firmware upgrade procedure, brocade firmware version, brocade firmwaredownload command, brocade firmware upgrade steps, brocade firmware latest version Jun 22, 2016 — How to update the firmware on a Brocade 300

Coding CRUD with PHP and MySQL is one of the basics. PHP web programmers must be able to code it with less effort. We can perform this task using any of the three PHP Database extensions: 1. Using the MySQL extension . 2. Using the MySQLi extension . 3. Using the PDO extension . PHP 5.5 deprecated the MySQL extension. It is not recommended to .