Module 9
Network Evolution
ITNET04
WAN Connectivity
Chapter 7 - Sections & Objectives
7.1 Internet of Things
• Explain the value of the Internet of Things.
• Describe the Cisco IoT System.
• Describe the pillars of the Cisco IoT System.
7.2 Cloud and Virtualization
• Explain why cloud computing and virtualization are necessary for evolving networks.
• Explain the importance of cloud computing.
• Explain the importance of virtualization.
• Describe the virtualization of network devices and services.
7.3 Network Programming
• Explain why network programmability is necessary for evolving networks.
• Describe software-defined networking.
• Describe controllers used in network programming.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2
7.1 Internet of Things
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
Internet of Things
What is the IoT?
It is predicted that the Internet will interconnect 50 billion things by 2020.
Using existing and new technologies, we are connecting the physical world to the
Internet.
It is by connecting the unconnected that we transition from the Internet to the
Internet of Things (IoT).
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
IoT Elements
The Converged Network and Things
Dissimilar networks are converging to share
the same infrastructure.
This infrastructure includes comprehensive
security, analytics, and management
capabilities.
The connection of the components into a
converged network that uses IoT
technologies increases the power of the
network to help people improve their daily
lives.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
IoT Elements
The Six Pillars of the Cisco IoT System
Cisco IoT System uses six pillars to identify foundational elements.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6
IoT Pillars
The Network Connectivity Pillar
All IoT devices (sensors, actuators, etc) need network connectivity to communicate and
perform automated tasks
Network equipment needed varies depending on the type of network.
LANs
PANs
WANs
WLANs
Home networks typically consist of a wireless broadband router, while business networks
will have multiple switches, APs, a firewall or firewalls, routers, and more.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7
IoT Pillars
The Fog Computing Pillar
Fog computing Client-Server Model
• This IoT network model identifies a computing
infrastructure closer to the network edge.
• Edge devices run applications locally and make
immediate decisions.
• Data does not need to be sent over network
connections.
• Enhances resiliency by allowing IoT devices to
operate when network connections are lost.
• Enhances security by keeping sensitive data
from being transported beyond the edge where
it is needed.
Cloud Computing Model
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8
IoT Pillars
The Fog Computing Pillar
Fog computing
• This IoT network model identifies a computing
infrastructure closer to the network edge.
• Edge devices run applications locally and make
immediate decisions.
• Data does not need to be sent over network
connections.
• Enhances resiliency by allowing IoT devices to
operate when network connections are lost.
• Enhances security by keeping sensitive data
from being transported beyond the edge where
it is needed.
Fog Computing Model
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
IoT Pillars
The Security Pillar
IoT introduces new attack vectors not typically encountered with normal enterprise networks.
Cybersecurity solutions include:
Operational Technology (OT) specific security – OT is the hardware and software that
keeps power plants running and manages factory process lines.
IoT Network security – Includes network and perimeter security devices.
IoT Physical security - Cisco Video Surveillance IP Cameras.
Cisco Video
Surveillance
Cisco Industrial Cisco FirePOWER Appliance Cameras
Security Appliance
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10
IoT Pillars
Data Analytics Pillar
IoT can connect billions of devices capable of creating exabytes of data every day. To provide
value, this data must be rapidly processed and transformed into actionable intelligence.
• Need to bring centers of data together and take advantage of data.
Integrate data in Extract valuable Automatically give Give personalized
the right context at information from feedback to people experiences for
the right time data in order to make people
better decisions
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11
IoT Pillars
Management and Automation Pillar
IoT expands the size and diversity of the network to include the billions of smart objects that sense,
monitor, control, and react. Each of these areas also has distinctive requirements, including the
need to track specific metrics.
Cisco management and automation products can be customized for specific industries to provide
enhanced security and control and support.
Management Tools: Cisco IoT Field Network Director, Cisco Prime, Cisco Video Surveillance
Manager, and more.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12
IoT Pillars
Application Enablement Platform Pillar
Provides the infrastructure for application hosting and application mobility between cloud
and Fog computing.
Cisco IOx which is a combination of Cisco IOS and Linux, allows routers to host
applications close to the objects they need to monitor, control, analyze, and optimize .
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13
7.2 Cloud and Virtualization
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
Cloud Computing
Cloud Computing Overview
If you were to host your own E-commerce website,
what hardware and software would you need?
What if you could just ‘rent’ everything and pay only
for what you use?
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
Cloud Computing
Cloud Computing Overview
• The “pay-as-you-go” model where capital expenditures are transferred to operating
expenses.
• Large numbers of networked computers physically located anywhere.
• Providers rely heavily on virtualization to allow customers to reduce operational costs by
using resources more efficiently.
• Supports a variety of data management issues:
• Enables access to organizational data anywhere and at any time
• Streamlines the organization’s IT operations by subscribing only to needed services
• Eliminates or reduces the need for onsite IT equipment, maintenance, and management
• Reduces cost for equipment, energy, physical plant requirements, and personnel training needs
• Enables rapid responses to increasing data volume requirements
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
Cloud Computing
Cloud Services
Software as a Service (SaaS): Access to
services, such as email and Office 365 that are
delivered over the Internet.
Platform as a Service (PaaS): Access to the
development tools and services used to deliver
the applications.
Infrastructure as a Service (IaaS): Access to
the network equipment, virtualized network
services, and supporting network infrastructure.
IT as a Service (ITaaS): IT Professionals
support applications, platforms and
infrastructure.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17
Cloud Computing
Cloud Models
Public clouds:
• Application and services made available to the general population and uses the Internet to provide
services.
• Services may be free or are offered on a pay-per-use model
Private clouds:
• Applications and services are intended for a specific organization or entity, such as the government.
• Can be set up using the organization’s private network (expensive though!)
Hybrid clouds:
• Made up of two or more clouds (example: part private, part public), where each part remains a distinctive object,
but both are connected using a single architecture.
Community clouds:
• Created for exclusive use by a specific community. e.g. healthcare organizations must remain compliant
with policies and laws (e.g., HIPAA) that require special authentication and confidentiality.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18
Cloud Computing
Cloud Computing versus Data Center
Data center: Typically a data storage and processing facility run by an in-house IT
department or leased offsite.
Cloud computing: Typically an off-premise service that offers on-demand access to a
shared pool of configurable computing resources. These resources can be rapidly
provisioned and released with minimal management effort.
Cloud
Cloud computing
computing is
is often a service
possible
provided by data
because of
centers.
data centers.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19
Virtualization
Cloud Computing and Virtualization
Virtualization is the foundation of cloud computing. Without it, cloud computing would
not be possible.
Cloud computing separates the application from the hardware.
Virtualization separates the OS from the hardware.
Amazon Elastic Compute cloud (Amazon EC2) web service provides a simple way for
customers to dynamically provision the computer resources they need. These
virtualized instances of servers are created on demand in Amazon’s EC2.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Virtualization
Dedicated Servers
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
Virtualization
Server Virtualization
Hypervisor is a program, firmware, or
hardware that adds an abstraction layer on top
of the real physical hardware.
The abstraction layer is used to create virtual
machines which have access to all the
hardware of the physical machine such as
CPUs, memory, disk controllers, and NICs.
In the figure, the previous eight dedicated
servers have been consolidated into two
servers using hypervisors to support multiple
virtual instances of the operating systems.
It is not uncommon for 100 physical servers to
be consolidated as virtual machines on top of
10 physical servers that are using hypervisors.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
Virtualization
Abstraction Layers
A hypervisor is software installed between firmware and the OS that creates and runs virtual
machine instances
The computer, on which a hypervisor is supporting one or more VMs, is a host machine.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23
Virtualization
Hypervisors
Type 2 hypervisors (a.k.a hosted
hypervisors) and are installed on top of
the existing OS.
Examples:
• Virtual PC
• VMware Workstation
• Oracle VM VirtualBox
• VMware Fusion
• Mac OS X Parallels
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 24
Virtualization
Hypervisors
Type 1 hypervisors (a.k.a bare-metal hypervisors) are installed directly on the hardware.
Usually for enterprise servers and data centers
Have direct access to the hardware resources hence have better scalability,
performance, and robustness.
Examples:
• VMware ESXi
• Xen
• Microsoft Hyper-V
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
Virtual Network Infrastructure
Installing a VM on a Hypervisor
Type 1 hypervisors require a “management console” to manage the hypervisor.
Management software is used to manage multiple servers using the same hypervisor.
The management console can automatically consolidate servers and power on or off servers
as required.
Assume that Server1 in the
figure becomes low on
resources. To make more
resources available, the
management console moves
the Windows instance to the
hypervisor on Server2.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
Virtual Network Infrastructure
Installing a VM on a Hypervisor (Cont.)
The management
console provides
recovery from
hardware failure.
If a server component
fails, the management
console automatically
and seamlessly moves
the VM to another
server.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
Virtualization
Advantages of Virtualization
One major advantage of virtualization is overall reduced cost:
• Less equipment is required - Server consolidation and lower maintenance costs.
• Less energy is consumed - Consolidating servers lowers the monthly power and cooling
costs.
• Less space is required - Fewer servers, network devices, and racks reduce the amount of
required floor space.
Additional benefits of virtualization:
• Easier prototyping
• Faster server provisioning
• Increased server uptime
• Improved disaster recovery
• Legacy Support
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28
Virtual Network Infrastructure
Network Virtualization
Server virtualization hides server resources from server users. but can create problems used with
traditional network architectures.
Virtual LANs (VLANs) used by VMs must be assigned to the same switch port as the physical server
running the hypervisor
VMs are movable and network settings must migrate together with them.
Network administrator must be able to add, drop, and change network resources and profiles.
Traffic flows differ substantially from the traditional client-server model.
Typically, a data center has a considerable amount of traffic being exchanged between virtual servers
(referred to as East-West traffic).
Traffic flows change in location and intensity over time, requiring a flexible approach to network
resource management.
Quality of Service (QoS) and security level reconfigurations for individual flows can be tiem
consuming in large enterprises using multivendor equipment
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29
7.3 Network Programming
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30
Software-Defined Networking
Control Plane and Data Plane
A network device contains the following planes:
• Control plane - Regarded as the brains of a device. Used to make forwarding decisions.
Information sent to the control plane is processed by the CPU.
• Data plane - Also called the forwarding plane, this plane is the switch fabric connecting the
various network ports on a device. The data plane of each device is used to forward traffic
flows.
CEF is an advanced, Layer 3 IP
switching technology that enables
forwarding of packets to occur at the data
plane without consulting the control
plane.
Packets are forwarded directly by the
data plane based on the information
contained in the Forwarding Information
Base (FIB) and adjacency table, without
needing to consult the information in the
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
control plane.
31
Software-Defined Networking
Control Plane and Data Plane (Cont.)
To virtualize the network, the control
plane function is removed from each
device and is performed by a
centralized controller.
The centralized controller
communicates control plane functions
to each device.
Each device can now focus on
forwarding data while the centralized
controller manages data flow,
increases security, and provides other
services.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32
Software-Defined Networking
Virtualizing the Network
Two major network architectures have been developed to support network virtualization:
• Software Defined Networking (SDN) - A network architecture that virtualizes the network.
• Cisco Application Centric Infrastructure (ACI) - A hardware solution for integrating cloud
computing and data center management.
These are some other network virtualization technologies, some of which are included
as components in SDN and ACI:
• OpenFlow - The OpenFlow protocol is a basic element in building SDN solutions.
• OpenStack - This approach is a virtualization and orchestration platform available to build
scalable cloud environments and provide an infrastructure as a service (IaaS) solution.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33
Software-Defined Networking
SDN Architecture
In a traditional router or switch
architecture, the control plane and data
plane functions occur in the same
device. Routing decisions and packet
forwarding are the responsibility of the
device operating system.
Software defined networking (SDN) is a
network architecture that virtualizes the
control plane. The control plane is from
each network device to a central
network intelligence and policy-making
entity called the SDN controller.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
Software-Defined Networking
SDN Architecture (Cont.)
The SDN controller enables network
administrators to manage and dictate how the
data plane of virtual switches and routers
should handle network traffic.
Northbound APIs communicate with the
upstream applications. These APIs help
network administrators shape traffic and deploy
services.
Southbound APIs control the behavior of virtual
switches and routers. OpenFlow is the original
and widely implemented southbound API.
Note: An API is a set of standardized requests
that define the methods by which an
application can request services from another
application.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
Controllers
SDN Controller and Operations
SDN controller defines the data flows that occur in the SDN
Data Plane. A flow could consist of all packets with the
same source and destination IP addresses, or all packets
with the same VLAN identifier.
Each flow traveling through the network must first get
permission from the SDN controller. If the controller allows
a flow, it computes a route for the flow to take and adds an
entry for that flow in each of the switches along the path.
The controller populates and the switches manage the flow
tables. Each OpenFlow switch connects to other OpenFlow
switches. They can also connect to end-user devices that
are part of a packet flow.
To the switch, a flow is a sequence of packets that matches
a specific entry in a flow table.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36
Controllers
SDN Types
• Device-based SDN
• The devices are programmable by applications
running on the device itself or on a server in the
network.
• Cisco OnePK is an example of a device-based
SDN. It enables programmers to build
applications to integrate and interact with Cisco
devices.
• Controller-based SDN
• Uses a centralized controller that has knowledge
of all devices in the network.
• The applications can interface with the controller
responsible for managing devices and
manipulating traffic flows throughout the network.
• The Cisco Open SDN Controller is a commercial
distribution of OpenDaylight.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37
Controllers
SDN Types (Cont.)
• Policy-based SDN
• Similar to controller-based SDN where a
centralized controller has a view of all
devices in the network.
• Includes an additional Policy layer. Uses
built-in applications that automate advanced
configuration tasks via a guided workflow
and user-friendly GUI.
• Considered to be most robust, providing for
a simple mechanism to control and manage
policies across the entire network.
• Cisco APIC-EM is an example of this type of
SDN.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 38
Questions?
1. Reflection paper for ITNET – September 24 (Friday) 9PM
2. Course feedback: September 20 (Monday) 9 PM
3. Case Project
- Docu and simulation: September 18 (Saturday)
- Peer Evaluation: September 21
Next Week
1. Final Exam: September 20 (Monday) 8-11 AM
2. *Data privacy review and end of course survey completion – September 25 (12 noon)
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 40