ENSA Module 13 Network Virtualization — Transcript
Full transcript
- 0:03[Music]
- 0:12hi
- 0:12hello there welcome to network
- 0:15virtualization
- 0:17so imagine you live in a two-bedroom
- 0:19house
- 0:20you use the second bedroom for storage
- 0:24the second bedroom is packed full of
- 0:26boxes
- 0:27but you still have more to place in
- 0:30storage
- 0:31so you should consider building an
- 0:32addition on your house
- 0:35it would be costly endeavor and you may
- 0:38not need that much space forever
- 0:40so you decide to rent a storage unit
- 0:44for the overflow so similar to storage
- 0:47unit
- 0:47network virtualization and cloud
- 0:50services
- 0:51can provide a business with options
- 0:53other than adding servers
- 0:55into their own data center in addition
- 0:58to storage
- 0:59it offers other advantages so get
- 1:02started with this module
- 1:03to learn more about what virtualization
- 1:06and cloud services can do
- 1:13so on this video lecture we will be
- 1:15talking about network virtualization
- 1:17and the module objective is to explain
- 1:19the purpose and characteristics of
- 1:21network virtualization
- 1:23so along with this we will be talking
- 1:25about the cloud computing
- 1:27virtualization the virtual network
- 1:29infrastructure
- 1:30the software defined networking and the
- 1:32controllers
- 1:37so let's start with cloud computing
- 1:40so cloud computing involves large
- 1:43numbers of computers connected to a
- 1:45network
- 1:46that can be physically located anywhere
- 1:49so providers
- 1:50rely heavily on virtualization to
- 1:52deliver their cloud
- 1:54computing services so cloud computing
- 1:56services can reduce operational costs
- 1:59by using resources more efficiently so
- 2:02cloud computing
- 2:03addresses a variety of data management
- 2:05issues
- 2:07like it enables access to organizational
- 2:10data
- 2:11anywhere and at any time
- 2:14next is it streamlines the
- 2:16organization's id operations
- 2:18by subscribing only to needed services
- 2:22okay next is it eliminates or reduces
- 2:26the need for on-site id equipment
- 2:28maintenance and management
- 2:32also it reduces cost of equipment
- 2:35energy physical plant requirements and
- 2:39personal training needs and the last one
- 2:42is
- 2:42it enables rapid responses to
- 2:45increasing data volume requirements so
- 2:48cloud computing
- 2:49with its pay-as-you-go model allows
- 2:52organization to trip
- 2:54computing and storage expenses more as
- 2:57utility
- 2:58rather than investing in the
- 2:59infrastructure so capital expenditures
- 3:03are transformed into operating
- 3:05expenditures
- 3:08okay so let's talk about cloud services
- 3:10now
- 3:13so cloud services are available in a
- 3:15variety of options
- 3:16tailored to meet customer requirements
- 3:19the three main cloud computing services
- 3:21defined by the national institute of
- 3:22standards in technology or nist
- 3:25in their special publication 800.145
- 3:29are as follows okay so the first one is
- 3:33software as a service or sas okay
- 3:37so the cloud provider is responsible for
- 3:39access to applications and services such
- 3:41as email
- 3:42communication and office 365
- 3:46that are delivered over the internet so
- 3:48the user does not manage
- 3:49any aspect of the cloud services except
- 3:52for limited
- 3:53user specific application settings so
- 3:56the user only needs to provide
- 3:58their data okay so the next one is
- 4:02platform as a service or us
- 4:05so the cloud provider is responsible for
- 4:07providing user access to the development
- 4:09tools and services
- 4:11used to deliver the applications the
- 4:14users are typically programmers
- 4:16and may have control over the
- 4:18configuration settings
- 4:20of the cloud provider's application
- 4:22hosting environment
- 4:25next is infrastructure as a service
- 4:28okay infrastructure as a service or eos
- 4:32the cloud provider is responsible for
- 4:34giving it managers
- 4:36access to network equipment virtualized
- 4:39network services
- 4:40and supporting network infrastructure so
- 4:43using this cloud service allows it
- 4:46manager
- 4:47to deploy and run software code which
- 4:49can include operating systems and
- 4:51applications
- 4:53all right so cloud service providers
- 4:56have extended this model
- 4:59to also provide an i.t support to each
- 5:01of the cloud computing services
- 5:02and what we have here is of course the
- 5:04it as a service
- 5:06or itas okay so for businesses
- 5:09itas can extend the capability of
- 5:12network without requiring investment in
- 5:14new infrastructure
- 5:15training new personnel or licensing new
- 5:18software
- 5:19so these services are available on
- 5:21demand and delivered economically
- 5:23to any device anywhere in the world
- 5:25without compromising security or
- 5:27function
- 5:37okay next is cloud models
- 5:41okay so there are four cloud models as
- 5:44shown in the figure here
- 5:46you've got hybrid public private and
- 5:49community
- 5:50okay so public clouds okay let's start
- 5:53with public clouds
- 5:54public clouds are cloud-based
- 5:56applications and services
- 5:58offered in public cloud that are made
- 6:00available
- 6:01to the general population so services
- 6:04may be free or
- 6:06are offered on a pay-per-use model such
- 6:09as paying for online storage
- 6:11okay so the public cloud uses the
- 6:14internet to provide services
- 6:16so the next one is private cloud okay
- 6:20so cloud-based applications and services
- 6:22offered in private cloud
- 6:24are intended for specific organization
- 6:26or entity
- 6:28such as the government your private
- 6:30cloud can set up
- 6:31using the organization's private network
- 6:34so through this can be expensive to
- 6:36build
- 6:37okay and maintain so a private cloud can
- 6:41also be managed by an outside
- 6:43organization
- 6:45with strict access security
- 6:48next third one is the hybrid hybrid
- 6:51cloud
- 6:52okay so a hybrid cloud is made up of two
- 6:55or more clouds example
- 6:57part private and part public so
- 7:00where each part remains a separate
- 7:03object
- 7:04but both are connected using a single
- 7:07architecture
- 7:08so individuals on a hybrid cloud would
- 7:10be able to decree or to have
- 7:12degrees of access okay so to vary
- 7:15services
- 7:16based on the user access rights all
- 7:19right
- 7:19and the last one is the community clouds
- 7:22so a community cloud is created for
- 7:25exclusive use
- 7:26by a specific community so the
- 7:28differences between
- 7:30public clouds and community clouds are
- 7:32the functional needs
- 7:34that have been customized for the
- 7:35community for example
- 7:38healthcare okay healthcare organizations
- 7:41must remain compliant with policies and
- 7:44laws example the
- 7:45hipaa that requires special
- 7:48authentication and confidentiality
- 7:53right next cloud computing versus data
- 7:57center
- 7:58okay so the term data center and cloud
- 8:01computing are often used incorrectly
- 8:04okay so these are the correct
- 8:05definitions of data center and cloud
- 8:07computing
- 8:09so data center okay so typically
- 8:13an off premise or a data storage
- 8:17and processing facility run by an
- 8:19in-house id department or list
- 8:21offsite so that is a data center when
- 8:24you say cloud computing so typically
- 8:27this is an off-premise service that
- 8:30offers an
- 8:31on-demand access to a shared pool of
- 8:34configurable
- 8:35computing resources so these resources
- 8:38can be
- 8:38rapidly provisioned and released with
- 8:41minimal management effort
- 8:43so data centers are the physical
- 8:45facilities that provide the compute
- 8:47network and storage needs of cloud
- 8:50computing services
- 8:52while cloud service providers use data
- 8:55centers
- 8:56to host their cloud services and
- 8:59cloud-based resources
- 9:01all right
- 9:05let's talk about virtualization now
- 9:08okay so cloud computing and
- 9:11virtualization
- 9:12what's the difference so in the previous
- 9:15topic you learned about cloud services
- 9:17and cloud models
- 9:19so this topic will explain
- 9:21virtualization
- 9:23so the terms cloud computing and
- 9:25virtualization
- 9:26are often used interchangeably however
- 9:30they mean different things all right
- 9:33so virtualization is the foundation of
- 9:35cloud computing
- 9:36without it cloud computing as it is most
- 9:40widely
- 9:40implemented would not be possible so
- 9:44virtualization separates the operating
- 9:46systems or os
- 9:47from the hardware so various providers
- 9:50offer virtual cloud services that can
- 9:54dynamically provision servers
- 9:56as required for example amazon web
- 9:58services or aws
- 10:00provides a simple way for customers to
- 10:04dynamically provision
- 10:05the compute resources they need these
- 10:08virtualized instances of servers
- 10:11are created on demand okay
- 10:14so as shown in the figure here all right
- 10:18so the network administrator can deploy
- 10:20a variety of services from the aws
- 10:22management console
- 10:24including virtual machines web
- 10:26applications
- 10:27virtual servers and connections to iot
- 10:30devices
- 10:32all right okay let's talk about
- 10:35dedicated servers now
- 10:36so to fully appreciate virtualization it
- 10:39is first necessary to understand
- 10:41some of the history of the server
- 10:43technology
- 10:44so historically enterprise servers
- 10:47consisted
- 10:48of a server os such as windows server or
- 10:50linux server
- 10:52okay installed on the specific hardware
- 10:54as shown in the figure
- 10:56so all of the servers ram processing
- 10:58power
- 10:59and hard disk drive spaces were
- 11:02dedicated to the service provided
- 11:04example web email or email services
- 11:08and others so the major problem with
- 11:10this configuration is that
- 11:12when a component fails the service that
- 11:15is provided by that server becomes
- 11:17unavailable
- 11:18so this is known as a single point of
- 11:20failure
- 11:21another problem was that dedicated
- 11:24servers
- 11:25were underused right so dedicated
- 11:28servers
- 11:28can often sat idle for long periods of
- 11:31time
- 11:32so waiting until there was a need to
- 11:34deliver the specific service that they
- 11:36provide
- 11:37so this servers wasted energy and took
- 11:40up
- 11:40more space than was warranted by the
- 11:44amount of service provided
- 11:47this is known as the server sprawl
- 11:55all right so next is virtualization
- 11:58or server virtualization so server
- 12:01virtualization takes advantage of
- 12:04idle resources and consolidates the
- 12:06number of required servers
- 12:08so this also allows for multiple
- 12:10operating systems
- 12:12to exist on a single hardware platform
- 12:14for example
- 12:15in the figure the previous eight
- 12:17dedicated servers
- 12:19have been consolidated into two servers
- 12:21using hypervisors
- 12:23to support multiple virtual instances of
- 12:25the operating systems
- 12:29the use of virtualization normally
- 12:31includes redundancy to protect
- 12:33from a single point of failure so
- 12:35redundancy can be implemented in
- 12:37different ways
- 12:38if the high fare buys or fails the
- 12:41virtual machine can be restarted on
- 12:43another hypervisor also the same vm
- 12:47can run on two hypervisors concurrently
- 12:50so copying the ram and cpu instructions
- 12:53between them
- 12:55so if one hypervisor fails the virtual
- 12:58machine continues
- 13:00running on another hypervisor
- 13:03okay so the services running on the vms
- 13:06are also virtual
- 13:08and can be dynamically installed or
- 13:10uninstalled as needed
- 13:12so the hypervisor is a program or
- 13:14firmware
- 13:15or hardware that adds an abstraction
- 13:17layer
- 13:18okay on top of the physical hardware
- 13:21so the abstraction layer is used to
- 13:23create a virtual machines
- 13:25which have access to all the hardware of
- 13:28the physical machines such as cpus
- 13:30memory disk controllers and network
- 13:33interface cards
- 13:36so each of these virtual machines runs
- 13:38on a consolidated number of servers they
- 13:41require
- 13:41for example it is not uncommon
- 13:45for 100 physical servers to be
- 13:47consolidated as virtual machines on top
- 13:49of
- 13:5010 physical servers that are using
- 13:52hypervisors
- 13:54okay so let's talk about the advantages
- 13:56of virtualization now
- 13:58so one major advantage of virtualization
- 14:01is
- 14:02overall reduced cost so you've got less
- 14:05equipment is required
- 14:06less energy is consumed and less space
- 14:10is required okay now
- 14:13with less equipment is required
- 14:15virtualization enables server
- 14:17consolidation
- 14:18which requires fewer physical servers
- 14:21fewer networking devices
- 14:23and less supporting infrastructure so it
- 14:25means lower maintenance
- 14:28cost so the next one is less energy is
- 14:31consumed
- 14:32so consolidating servers lowers the
- 14:34monthly power and cooling costs
- 14:37so reduced consumption helps enterprises
- 14:39to achieve a smaller carbon footprint
- 14:42okay when you say less space is required
- 14:46server consolidation with virtualization
- 14:49reduces the overall footprint of the
- 14:51data center
- 14:52so fewer servers network devices
- 14:56and racks reduce the amount of the
- 14:57required floor spaces
- 15:00okay so there are additional benefits of
- 15:03virtualization so like
- 15:05easier prototyping so self-contained
- 15:08labs operating on isolated networks can
- 15:12be rapidly created for testing and
- 15:13prototyping network deployments
- 15:16so if a mistake is made an administrator
- 15:19can simply revert
- 15:20their previous version so the testing
- 15:23environment can be online
- 15:25but isolate that from the end users so
- 15:28when testing is completed
- 15:29the servers and systems can be deployed
- 15:32to the end servers and end users
- 15:36okay the next one is faster server
- 15:39provisioning
- 15:40so creating a virtual server is far
- 15:42faster than provisioning a physical
- 15:44server
- 15:45okay next is increased server uptime
- 15:49most server utilization or
- 15:51virtualization
- 15:53platforms now offer advanced redundant
- 15:55fault tolerance of features such as
- 15:57live migration storage migration high
- 16:01availability
- 16:02and distributed resource scheduling
- 16:05okay so next additional benefits
- 16:08would be improved disaster recovery
- 16:12so virtualization offers advanced
- 16:14business continuity solutions
- 16:16so it provides hardware abstraction
- 16:18capability
- 16:20so that the recovery site no longer
- 16:22needs to have hardware
- 16:23that is identical to the hardware in
- 16:25their production environment
- 16:27so most enterprises or enterprise server
- 16:30virtualization platform
- 16:32also have software that can help test
- 16:34and automate
- 16:35the failover over or before a disaster
- 16:39does happen okay so the last one is
- 16:43legacy support so virtualization can
- 16:45extend the life of oss
- 16:47and application providing more time for
- 16:50organization
- 16:51to migrate to newer solutions
- 16:55okay
- 16:58now let's talk about obstruction layers
- 17:01okay so to help explain
- 17:03how virtualization works it helps to use
- 17:06layers of obstruction in computer
- 17:08architecture
- 17:09the computer system consists of the
- 17:11following abstraction layers as
- 17:13illustrated here
- 17:14so you've got hardware which includes
- 17:16cpu memory and ic and disk or hard disk
- 17:19storage
- 17:20you've got firmware or rom okay the
- 17:23operating systems are os
- 17:25and the services like web email and
- 17:28file service okay so at each of these
- 17:32layers of abstraction
- 17:34some type of programming code is used
- 17:37as an interface between the layer below
- 17:40the layer above
- 17:42okay so that is between the layer below
- 17:45and the layer above so for example
- 17:47the c programming language is often used
- 17:49to program the firmware
- 17:51that accesses the hardware so an example
- 17:54of virtualization is shown in the figure
- 17:57okay so a hypervisor is installed
- 18:00between the firmware
- 18:01okay and the os
- 18:05okay so the hypervisor can support
- 18:07multiple instances of oss
- 18:10like what you see here in the diagram
- 18:12okay so this hypervisor
- 18:15has three oss running on top of it so
- 18:18that means
- 18:19we could have multiple oss running and
- 18:23its os could run its own service
- 18:26all right
- 18:30next let's talk about type 2 hypervisors
- 18:34so a type to hypervisor is software
- 18:37that creates and runs virtual machine
- 18:39instances
- 18:41so the computer on which a hypervisor is
- 18:43supporting one or more vms
- 18:45is a host machine so type 2 hypervisors
- 18:48are also called hosted
- 18:50hypervisors this is because the
- 18:53hypervisor
- 18:54is installed on top of the existing
- 18:56operating systems such as mac os
- 18:59windows or linux then
- 19:02one or more additional os instances are
- 19:04installed on top of the hypervisor
- 19:06as shown here in the diagram okay so for
- 19:09instance
- 19:10we have here a single host okay so
- 19:12definitely we have the shared resources
- 19:14or hardware
- 19:15and then we have what you call the host
- 19:17operating system
- 19:19okay on top of this host operating
- 19:21system we have a hypervisor running
- 19:24which is hosting different oss on top of
- 19:27it
- 19:28now in this example we are running three
- 19:30virtual machines
- 19:31powered by windows os linux os and
- 19:34the unix oss okay so the big advantage
- 19:38of a type to hypervisor is that
- 19:40management console software is not
- 19:43required
- 19:44okay so the type to hypervisor are very
- 19:47popular with
- 19:48consumers for organizations
- 19:50experimenting with virtualization
- 19:53so common type to hypervisor includes
- 19:55virtual pc
- 19:57or the vmware workstation you've got the
- 19:59oracle virtual box
- 20:02vmware fusion and the mac os x
- 20:05parallels okay so many of these type two
- 20:09hypervisors are free
- 20:10however some hypervisors offer more
- 20:13advanced features for a fee
- 20:16okay so note that it is important to
- 20:19make sure that the host machine is
- 20:20robust
- 20:21enough to install and run the virtual
- 20:23machines
- 20:24so that it does not run out of the
- 20:27resources
- 20:28because everything is shared when you
- 20:30run
- 20:31and use a type to hypervisors
- 20:38okay so let's talk about virtual network
- 20:41infrastructure
- 20:43okay so under virtual network
- 20:46infrastructure we've got the type
- 20:481 hypervisor so in the previous topic
- 20:51you learned about virtualization
- 20:53this topic will cover the virtual
- 20:55network infrastructure
- 20:58all right so type 1 hypervisors are also
- 21:01called bare metal approach
- 21:03because the hypervisor is installed
- 21:05directly on the hardware
- 21:07so type 1 hypervisors are usually used
- 21:10on enterprise servers and data center
- 21:12networking devices
- 21:14so with type 1 hypervisor the hypervisor
- 21:18is installed directly
- 21:19on the server or network hardware then
- 21:22instances
- 21:23of an operating systems are installed on
- 21:25the hypervisor
- 21:26as on in the diagram here okay so we
- 21:30have the server
- 21:31the hardware hypervisor oss
- 21:34are installed directly on the hypervisor
- 21:36so we don't have a host os here
- 21:38on the physical device all right
- 21:42so we type 1 hypervisor the hypervisor
- 21:44is installed directly on the server
- 21:46or networking hardware then instances of
- 21:49an os are installed on the hypervisor
- 21:52as i shown you earlier okay
- 21:55so type 1 hypervisor have direct access
- 21:58to the hardware resources
- 22:00therefore they are more efficient than
- 22:03hosted architectures
- 22:05so type 1 hypervisors improve
- 22:08scalability
- 22:09performance and robustness
- 22:15how to install a virtual machine on a
- 22:17hypervisor
- 22:18so when a type 1 hypervisor is installed
- 22:21and the server is rebooted
- 22:23only basic information is displayed such
- 22:25as the os version
- 22:27the amount of rom and the ip addresses
- 22:30so an os instance cannot be created from
- 22:33this screen
- 22:34type 1 hypervisors require a management
- 22:37console
- 22:38to manage the hypervisor so management
- 22:41software is used to manage multiple
- 22:43servers
- 22:44using the same hypervisor so the
- 22:46management console can automatically
- 22:48consolidate servers
- 22:50and power on and off servers as required
- 22:57okay so for example assume that server
- 23:00one
- 23:01in the figure okay becomes law on
- 23:05resources
- 23:06so to make more resources available the
- 23:08network administrator
- 23:10uses the management console
- 23:13to move the windows instance to the
- 23:15hypervisor on server too
- 23:18all right so the management console can
- 23:21also be programmed
- 23:22with thresholds that will trigger more
- 23:25automatically
- 23:27okay so it could also trigger the
- 23:29movement
- 23:30of this windows os automatically
- 23:34okay now the figure here
- 23:37below okay the management console
- 23:40provides recovery from hardware failure
- 23:42so if a server component fails the
- 23:45management console
- 23:46automatically moves the virtual machine
- 23:48to another server
- 23:50so the management console for the cisco
- 23:52unified computing system or ucs manager
- 23:55is shown here in the figure so the cisco
- 23:58ucs manager controls
- 23:59multiple servers and manages resources
- 24:01for thousands of
- 24:03virtual machines so some management
- 24:05consoles also allow server over
- 24:08allocation over allocation is
- 24:11when multiple os instances are installed
- 24:13but their memory allocation exceeds
- 24:16the total amount of memory that the
- 24:18server has for example
- 24:20a server has 16 gb of ram but the
- 24:23administrator creates
- 24:25four os instances with 10 gb allocated
- 24:28to it
- 24:29so this type of overall allocation is a
- 24:32common practice because
- 24:34all four os instances rarely require
- 24:37the full 10 gb of ram at
- 24:40any one moment okay
- 24:48the complexity of network virtualization
- 24:51okay so how complex virtualization or
- 24:54network virtualization is
- 24:56so server virtualization hides server
- 24:59resources
- 25:00such as the number and identity of
- 25:02physical servers processors
- 25:04and oss from server users so this
- 25:08practice can create
- 25:09problems if the data center is using
- 25:11traditional network architectures for
- 25:14example
- 25:15virtual lands or vlans used by vms must
- 25:18be assigned to the same
- 25:19switch port as the physical server
- 25:22running on the hypervisor
- 25:23however vms are movable
- 25:27and the network administrator must be
- 25:29able to add
- 25:30drop or change network resources and
- 25:32profiles
- 25:33so this process would be manual and time
- 25:36consuming
- 25:36with additional network switches so
- 25:39another problem
- 25:40is that traffic flows differ
- 25:42substantially from
- 25:44the traditional client server model so
- 25:46typically
- 25:47a data center has a considerable amount
- 25:50of traffic being exchanged between
- 25:52virtual servers such as
- 25:53the ucl servers okay as shown here in
- 25:57the diagram
- 26:00all right so this uses a ucs server
- 26:04now these flows are called east west
- 26:07traffic
- 26:08okay and can change in location and
- 26:11intensity over time
- 26:13so the north south traffic of course
- 26:15between the distribution and the core
- 26:16layers
- 26:18all right so you've got the north south
- 26:20traffic between the core
- 26:21and then the distribution layers okay
- 26:24so north south traffic occurs between
- 26:26the distribution and the core layer and
- 26:28is typically
- 26:29traffic distant for off-site locations
- 26:32such as another data center
- 26:34other cloud providers or the internet
- 26:38right so the east-west traffic is
- 26:41within the ucs servers that is connected
- 26:43to the access layer
- 26:44switches
- 26:49next so let's talk about the complexity
- 26:51of network virtualization
- 26:53okay on dynamic ever-changing traffic
- 26:56requires a flexible approach
- 26:58on network resource management okay so
- 27:01existing network
- 27:02infrastructure can respond to changing
- 27:05requirements related to the management
- 27:07of traffic flows by using the quality of
- 27:09service or qos
- 27:11and security level configurations for
- 27:13individual flaws
- 27:15however in large enterprises using
- 27:18multi-vendor equipment
- 27:20each time a new virtual machine is
- 27:22enabled
- 27:23the necessary reconfiguration can be
- 27:26very time consuming
- 27:28so the network infrastructure can also
- 27:30benefit from virtualization
- 27:32so network functions can be virtualized
- 27:35each network device
- 27:36can be segmented into multiple virtual
- 27:39devices
- 27:40that operate as independent devices
- 27:43examples includes sub-interfaces
- 27:46virtual interfaces vlans and routing
- 27:49tables
- 27:50so virtualized routing is called virtual
- 27:53routing
- 27:54and forwarding or vrf
- 27:58okay now how is the network virtualized
- 28:02the answer is found on how a networking
- 28:05device
- 28:06operates using a data plane and control
- 28:08pane
- 28:09as discussed on the next topic
- 28:14let's talk about the software defined
- 28:15networking now
- 28:19the previous topic explained virtual
- 28:21network infrastructure
- 28:22this topic will cover the software
- 28:24defined networking
- 28:27so a network device contains the
- 28:29following planes you've got the control
- 28:31plane
- 28:31and the data plane now the control plane
- 28:36this is typically regarded as the brains
- 28:38of the device
- 28:39so it is used to make forwarding
- 28:41decisions the control plane
- 28:44contains layer 2 and layer 3 route
- 28:46forwarding mechanisms
- 28:48such as routing protocol neighbor tables
- 28:51and topology tables ipb4 and ipv6
- 28:54routing tables
- 28:56stp and the arp table
- 28:59so information sent to the control plane
- 29:02is processed by
- 29:03the cpu now on the data plane
- 29:07also called the forwarding plane this
- 29:10plane is typically in the switch fabric
- 29:12connecting the various network ports on
- 29:15a device
- 29:16so the data plane of each device is used
- 29:19to forward traffic flows
- 29:21routers and switches use information
- 29:23from the control plane
- 29:25to forward incoming traffic out of the
- 29:28appropriate egress interfaces
- 29:30so information in the data plane is
- 29:32typically processed by special data
- 29:34plane processor
- 29:36without the cpu getting involved
- 29:42now illustration and explanation of the
- 29:44difference between the operation of
- 29:46localized
- 29:46control on a layer 3 switch and a
- 29:49centralized controller is the end
- 29:51follows okay so
- 29:55beginning with the layer 3 switch and
- 29:58ceph or the cisco express forwarding
- 30:00okay now this figure here illustrates
- 30:04how cisco
- 30:05express forwarding or cf uses the
- 30:07control plane
- 30:08and data plane to process packets
- 30:11you've got the control plane on top and
- 30:13the data plane at the bottom
- 30:15okay egress interface that is where the
- 30:18packet is coming in
- 30:19and egress interface would be the output
- 30:22or the
- 30:23packets going out okay now ceph
- 30:26is an advanced layer 3 ip switching
- 30:29technology
- 30:30that enables forwarding to packets or of
- 30:32packets to occur
- 30:34at the data plane without consulting the
- 30:36control pane
- 30:37in ceph the control plane's routing
- 30:40table
- 30:41pre-populates the cef forwarding
- 30:43information base or fib table
- 30:45in the data plane so the control plane's
- 30:48arp
- 30:49table pre-populates the adjacency table
- 30:52so packets are then forwarded directly
- 30:55by the data plane
- 30:56based on the information contained in
- 30:58the fib and adjacency table
- 31:01without needing to consult information
- 31:04in the control plane
- 31:08okay so the next one is the software
- 31:11defined networking
- 31:13okay so which is basically the
- 31:14separation of the control plane and data
- 31:16plane
- 31:17the control plane function is removed
- 31:19from each device and is performed by a
- 31:22centralized controller
- 31:23as shown in the figure here okay so if
- 31:26you will observe here
- 31:28if you have different devices what is
- 31:30left
- 31:31on the device is just the data plane now
- 31:34the control plane was removed
- 31:35from this device okay and is
- 31:38placed on a centralized controller okay
- 31:42now the centralized controller
- 31:43communicates control plane functions to
- 31:45each device
- 31:47each device can now focus on forwarding
- 31:49data
- 31:50while the centralized controller manages
- 31:52data flow increases security and
- 31:54provides other services
- 32:00so the management plane is the plane
- 32:03which is responsible for managing a
- 32:05device
- 32:06through its connection to the network
- 32:08network administrators and systems
- 32:10administrators
- 32:11use the application such as secure shell
- 32:14or ssh
- 32:15the trivial file transfer protocol or
- 32:17tftp
- 32:19the secure ftp and the secure hyper text
- 32:22transfer protocol or
- 32:24https to access the management plane and
- 32:27configure a device
- 32:28so the management plane is how you have
- 32:31accessed and configured devices in your
- 32:34networking studies
- 32:36in addition protocols like simple
- 32:39network management protocol or snmp
- 32:42is used in the management plan
- 32:49so there are two major network
- 32:51architectures that have been developed
- 32:53to support the network virtualization
- 32:55okay
- 32:56so over a decade ago vmware developed a
- 32:59virtualizing technology
- 33:01that enabled a host os to support one or
- 33:04more of client voices
- 33:06most virtualization technologies are now
- 33:08based on this technology
- 33:10the transformation of dedicated servers
- 33:12to virtualized servers
- 33:14has or has been embraced and is rapidly
- 33:17being implemented
- 33:18in data centers and enterprise networks
- 33:21okay now the two major network
- 33:25architectures
- 33:26are the software defined networking for
- 33:28sdn
- 33:30and the cisco application centric
- 33:31infrastructure or the aci
- 33:34now sdn is a network architecture that
- 33:37virtualizes the network
- 33:39offering a new approach to network
- 33:41administration
- 33:42and management that seeks to simplify
- 33:45and streamline the administration
- 33:46process
- 33:48now the cisco application centric
- 33:50infrastructure or aci
- 33:53a purpose built hardware solution
- 33:57for integrating cloud computing and data
- 33:59center management
- 34:05now here are the components of the sdn
- 34:08okay so with it which includes an open
- 34:10flow
- 34:10and open stop with other components
- 34:15okay so open flow this
- 34:18approach was developed at the stanford
- 34:20university
- 34:21to manage traffic between routers such
- 34:23as wireless access points and the
- 34:25controller
- 34:26so the open flow protocol is a basic
- 34:29element in building the sdn solutions
- 34:32okay so search for open flow and open
- 34:35networking foundation
- 34:37for more information on it now the open
- 34:40stack
- 34:41this approach is a virtualization and
- 34:43orchestration platform
- 34:45designed to build scalable cloud
- 34:47environments
- 34:48and provide an iaas
- 34:53okay or eos solution openstack
- 34:56is often used with cisco aci
- 35:00orchestration and networking is the
- 35:02process of automating and provisioning
- 35:05of network components
- 35:06such as servers storage switches
- 35:10routers and applications so if you want
- 35:13to learn more about openstack
- 35:14go ahead and search it on the internet
- 35:18now other components include interface
- 35:21to the routing system
- 35:23or i2rs transparent interconnection
- 35:27of lots of links or trill you've got the
- 35:30cisco fabric
- 35:31path or fp and the ieee 802.1
- 35:35aq shortest pass bridging or spb
- 35:44okay so in traditional and sdn
- 35:47architectures
- 35:48okay so in traditional router or sewage
- 35:51architecture the control plane and data
- 35:52plane functions occur on the same device
- 35:55so routing decisions and packet
- 35:57forwarding are the responsibility of the
- 36:00device operating system
- 36:02so in sdn or software defined networking
- 36:05management of the control plane is moved
- 36:07to a centralized sdn controller
- 36:10now the figure compares traditional
- 36:14and the sdn architecture so on
- 36:17traditional architecture if you will
- 36:18observe
- 36:19we have here three devices and each
- 36:21device
- 36:22combines the control plane and the data
- 36:24plane now with the implementation of the
- 36:26sdn architecture
- 36:28this control plane from the traditional
- 36:30architecture were moved out
- 36:33okay and it is now
- 36:36on the same location or centralized
- 36:38location okay in this case the sdn
- 36:40controller
- 36:41which uses an open flow to manage this
- 36:44devices here now the sdn controller is a
- 36:48logical entity that enables network
- 36:50administrators
- 36:51to manage and dictate how the data plane
- 36:54of switches and routers should handle
- 36:55network traffic
- 36:57it orchestrates or mediates and
- 37:00facilitates communication
- 37:02between application and the network
- 37:06elements
- 37:08so the complete sdn framework is shown
- 37:10in the figure
- 37:12so note the use of application
- 37:14programming interfaces or apis
- 37:16within the sdn framework okay
- 37:19so an api is a set of standard requests
- 37:23or standardized requests that define the
- 37:26proper way for an application to request
- 37:27services
- 37:28from other application so the sdn
- 37:31controller uses a northbound apis
- 37:34but the northbound api is here okay
- 37:38to communicate with the upstream
- 37:39applications
- 37:41this apis can help network
- 37:43administrators
- 37:45shape traffic and deploy services the
- 37:47sdn controller also uses a southbound
- 37:50apis so to define the behavior of the
- 37:54data planes
- 37:55on downstream switches and routers
- 37:58so open flow is the original and widely
- 38:01implemented
- 38:02southbound api
- 38:10so next is controller
- 38:14right so sdn controllers and operations
- 38:18so the previous topic covered sdn this
- 38:20topic will explain
- 38:22controllers now the sdn controllers
- 38:25define the data flows between the
- 38:27centralized control plane
- 38:29and the data planes on individual
- 38:31routers or switches
- 38:33okay now each flow traveling through the
- 38:36network
- 38:36must first get permission from the sdn
- 38:39controller
- 38:40which verifies that the communication is
- 38:42permissible according to the network
- 38:44policy
- 38:45so if the controller allows a flow
- 38:48it computes a route for the flow to take
- 38:52and add
- 38:52an entry for that flow in each of the
- 38:55switches along the path
- 38:57so all complex functions are performed
- 39:00by the controller so the controller
- 39:03populates
- 39:04flow tables so switch manage
- 39:07the flow tables so in the figure the sdn
- 39:10controller
- 39:11communicates with open flow compatible
- 39:13switches
- 39:14using the open flow protocols
- 39:17okay so you've got an open flow switch
- 39:19here and it uses an open flow protocols
- 39:22to communicate among the switches
- 39:26now this protocol uses a tls or the
- 39:29transport layer security to securely
- 39:31send control plane
- 39:33communications over the network so each
- 39:35op and flow switch
- 39:37connects to other open flow switches
- 39:40they can also connect to the end user
- 39:41devices that are part of the patent flow
- 39:49now within each switches a series of
- 39:51tables implemented in hardware or
- 39:53firmware
- 39:54are used to manage the flow of packets
- 39:56through the switch
- 39:58so to the switch a flow is a sequence of
- 40:01packets that matches a specific entry
- 40:03in flow table now the three table types
- 40:07shown in the previous figure are as
- 40:09follows
- 40:10so you've got a flow table a group table
- 40:13and a meter table now the flow table
- 40:17this table matches incoming packets to a
- 40:19particular flow
- 40:21and specifies the functions that are to
- 40:23be performed in the packets
- 40:25so there are multiple flow tables that
- 40:28operate in the pipeline fashion
- 40:31group table a table may direct a flow
- 40:34to a group table so which may trigger
- 40:38a variety of actions that affect one or
- 40:41more flows
- 40:44mirror table this table triggers a
- 40:46variety of
- 40:47performance related actions on flow
- 40:50including the ability to rate
- 40:52limit the traffic
- 41:07okay so next is the cisco aci
- 41:11so very few organizations actually have
- 41:13the desire
- 41:14or skill to program the network using
- 41:16sdn tools
- 41:18however the majority of the
- 41:20organizations
- 41:21want to automate the network accelerate
- 41:23the application deployments
- 41:25and align their id infrastructure to
- 41:28better meet
- 41:29business requirements so cisco developed
- 41:31the
- 41:32application centric infrastructure or
- 41:34aci
- 41:35to meet these objectives in more
- 41:37advanced and innovative ways
- 41:39than earlier sdn approaches now cisco
- 41:42azi
- 41:43is a hardware solution for integrating
- 41:46cloud computing and data center
- 41:48management
- 41:49so at a high level the policy element of
- 41:52the network is removed from the data
- 41:54plane
- 41:55just simplifies the data center networks
- 41:57are created
- 42:02so there are three components or core
- 42:05components of the aci architecture
- 42:07which includes the application network
- 42:09profile or a and p
- 42:11an anp is a collection of endpoint
- 42:14groups or
- 42:14epg their connections and the policies
- 42:18that define those connections
- 42:20the epgs shown in the figure such as
- 42:23vlans
- 42:25okay web services and applications
- 42:28are just examples an anp
- 42:31is often much more complex so figure
- 42:34on the next slide now the next one is
- 42:37the application infrastructure
- 42:39controller
- 42:40or the apic now the apic
- 42:43is considered to be the brains of the
- 42:45aci architecture
- 42:47apic is a centralized software
- 42:49controller that manages and operates a
- 42:51scalable aci clustered fabric
- 42:53it is designed for programmability and
- 42:56centralized management it translates
- 42:58application policies into network
- 43:01programming
- 43:02okay so the last one is the cisco nexus
- 43:059000 series switches
- 43:07so this switches provides an application
- 43:10aware switching fabric
- 43:11and work with apic to manage the virtual
- 43:14and physical network infrastructure
- 43:19so the apic is positioned between the
- 43:22apn
- 43:23and the aci enabled devices
- 43:27okay so the apic translates the
- 43:29application requirements
- 43:30into network configuration to meet those
- 43:33needs
- 43:34okay within the network infrastructure
- 43:40okay so next is the spine lift topology
- 43:44the cisco aci fabric is composed of the
- 43:47apic
- 43:48and the cisco nexus 9000 series switches
- 43:50using a two tier
- 43:52spine lift topology as shown in diagram
- 43:54here
- 43:55okay now the leaf switches always attach
- 43:59to the spines
- 44:00but they never attach to each other so
- 44:03similarly
- 44:04the spine switches only attach to the
- 44:06leaf and
- 44:07core switches okay of course not shown
- 44:09here on the diagram
- 44:11now in this two tier topology everything
- 44:14is one hub
- 44:15from everything else okay so
- 44:19the cisco apic and all other devices in
- 44:22the network basically attached to lift
- 44:23switches so when compared to sdn
- 44:27the ap controller does not manipulate
- 44:30the data path
- 44:31directly instead the apic centralizes
- 44:34the policy definition
- 44:36and programs the leaf switches to
- 44:38forward topic
- 44:39based on the defined policies
- 44:45so the following are the sdn types okay
- 44:48so the cisco application policy
- 44:50infrastructure controller
- 44:52the enterprise module apic em extends
- 44:55the aci
- 44:56aimed at enterprise and campus
- 44:58deployments
- 44:59so to better understand the apec em it
- 45:02is helpful
- 45:03to take a broader look at the three
- 45:05types of sdn so the first one
- 45:07is the device based sdn
- 45:10now in this type of sdn the devices are
- 45:13programmable by applications running on
- 45:16in the device itself
- 45:17or on a server in the network as shown
- 45:20in the figure here
- 45:22okay so the cisco one pk
- 45:27is an example of a device based sdn
- 45:31it enables programmers to build
- 45:33applications
- 45:34using c language and java with
- 45:38python to integrate and interact with
- 45:41the cisco devices
- 45:45so the second type of controller or sdn
- 45:48type
- 45:49is a controller based sdn now this type
- 45:52of sdn uses a centralized controller
- 45:54that has knowledge
- 45:56of all the devices in this in this
- 45:58network
- 46:00okay now the applications can
- 46:03interface with the controller
- 46:06responsible for managing devices and
- 46:08manipulating traffic flows
- 46:10throughout the network so the cisco open
- 46:13sdn controller is a commercial
- 46:15distribution of
- 46:17open daylight okay
- 46:21so next is a policy based sdn
- 46:24now this type of sdn is similar to
- 46:26controller controller-based sdn
- 46:28where a centralized controller has a
- 46:30view of all the devices in the network
- 46:32as shown in the diagram here
- 46:34okay now policy-based sdn includes an
- 46:38additional policy layer that operates
- 46:40at a higher level of abstraction so it
- 46:43uses a built-in applications that
- 46:45automate advanced configuration tasks
- 46:48via a guided workflow and user-friendly
- 46:51gui
- 46:52so no programming skills are required
- 46:55the open
- 46:56or the apic em is an example of this
- 46:59type of
- 47:00sdn all right
- 47:06now this is an ap em features
- 47:10so each type of sdn has its own features
- 47:12and advantages
- 47:14the policy-based sdn is the most robust
- 47:17okay providing a simple mechanism to
- 47:20control and manage policies across the
- 47:21entire network
- 47:23now the cisco apic em is an example of
- 47:25policy-based sdn
- 47:27cisco em provides a single interface for
- 47:30network management
- 47:32including discovering and accessing
- 47:34device
- 47:35and host inventories viewing the
- 47:38topology
- 47:39as shown here on the diagram all right
- 47:42so tracing a path
- 47:43between endpoints and setting policies
- 47:51now the ap em pass trace
- 47:54allow the administrator to easily
- 47:56visualize traffic flows and discover
- 47:58any conflicting duplicate or shadowed
- 48:01acl entries
- 48:02so this tool examines specific acls on
- 48:05the path
- 48:06between two end nodes displaying any
- 48:08potential issues
- 48:10you can see where any acls along the
- 48:13path
- 48:14either permitted or denied your traffic
- 48:17okay so notice how branch router 2
- 48:21okay permits all traffic
- 48:25okay the network administrator can now
- 48:28make adjustments if necessary
- 48:30to better filter this traffic all right
- 48:34so we have reached the end of this video
- 48:37lecture
- 48:38have a great day see you on the next
- 48:44video
About this transcript
This page contains the full transcript of ENSA Module 13 Network Virtualization by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 5,923 words across 1,230 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.