automating network services provisioning for multi-tenant data centers
DESCRIPTION
TRANSCRIPT
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1Cisco Confidential© 2011 Cisco and/or its affiliates. All rights reserved. 1
Automating Network Services Provisioning in Multi-Tenant Data CentersBrian PromesProduct Line Manager– Cloud Manageability
Cisco Cloud and System Management Technology GroupJune 2012
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2
Cloud Enabled InfrastructureFully isolated tenant environment (integrated security)
Abstraction of complexities (enables speed)
Automated processes and controls (ensures scale)
Streamlined, holistic coordination of resources and services (maximizes capacity)
Customizable service definitions and implementation (shortens time to market)
Proven, tested solutions – infrastructure and automation/orchestration (reduces risk)
Customer 2Customer 1
Virtualized Multi-tenant Data Center
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
Network Services as Monolithic Containers?Bronze
Load Balancing 1 VLAN
Virtual Firewall and Private VLANs
Shared VMFS and No Data Protection
Silver
Multiple VLANs
System Configuration
Virtual Firewall and Private VLANs
Dedicated VMFS and DP Through Snapshots
SLB and SSL Offload
Platinum
Multiple VLANs
System Configuration
Virtual Firewall and Private VLANs
Dedicated VMFS ,100% DP, and Cloning
VPN Offload Firewall
SLB and SSL Offload
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
Flexible Network ServicesTenant Creation
Basic Network Container
Enhanced Network Container
Large Network Container
Multi-Tiered Network Containers Behind Firewalls
Security and Load Balancing Services
TNC
(DB)(App)
Mgmt. VLAN
EnterpriseVPN
(Web)
Internet
FW FW
FW/LB
Designed to Your Requirements Using Flexible Models
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
Service Use Cases Using Network ContainersSample Customer Use Case• Computing and storage resources attached to a routable VLAN• Capability to partition and zone virtual machines and access within their containers• Accessible from a VPN connections (hybrid cloud)
This use case supports creation of a protected private zone. The customer requires that the only way to reach this zone is through a private VPN (MPLS, SSL, and IPsec). To build this solution, Cisco® Network Services Manager will build both the private zone and the network container within it.
Router and PE
Distribution
Layer 2 Aggregation
Layer 2 Aggregation
Access
Services
Device Roles
Virtual machine is deployed outside Cisco Network Services Manager
NC Topology: VPN with Network Container
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6
Cisco Network Services Manager Operational Model
Cisco® Network Services Manager Engine
Abstracted Business Model
Abstracted Services and Topology Model
Abstracted Operational Model
Cisco Network Services Manager Controller
Cisco Network Services Manager Controller
Cisco Network Services Manager Controller
Pod/Block Pod/Block Pod/Block
Com
pute
Net
wor
k
Sto
rage
Com
pute
Net
wor
k
Sto
rage
Com
pute
Net
wor
k
Sto
rage
NB API
JMS Transport
Network Services Manager allows administrators the ability to define the logical constructs of their cloud (access/security, tiers of service, resources and constraints).
Tenant Container Tenant Container
EnterpriseNetwork
NetworkContainer
Tenant Network Container
Tenant Network Container
NetworkContainer
Tenant Network Container
Network Container(Application)
Internet
Network Container
(Web)
FW
FW
MPLS Network
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 777
Cisco Network Services ManagerBuilt-in Flexibility
This use case shows a combination of a set of the 4 possible zones in Network Services Manager
Note that the models will allow each combination in every zone - all possible combinations are shown but in this case distributed across the 4 zones - they could all be built in any zone
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8
Common abstraction layer
Standardized API
Flexible, easily consumable interface
Cisco and 3rd party physical and virtual platforms
Fastest deployment and lowest operating costs for cloud
Cisco Network Services Manager Key Takeaways
OrchestrationModule
Automation Module Service Catalog Service Portal
Cisco® Network Services Manager
SP VMDC Pod Enterprise VMDC Pod
Open REST APIAbstraction Layer
VNMC
© 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
Thank you.