SlideShare a Scribd company logo
1 of 29
Download to read offline
Maximizing SD-WAN with
Service Insertion/Chaining Architectures
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Steve Woo, VP Products & Co-founder
VeloCloud Networks, Inc. | Proprietary & Confidential | © Copyright 2016
Service chaining
verb / serv-ice chain-ing
: interconnecting a set of services through the network
: simplified with both SDN [SD-WAN] and NFV
: meet expectations of dynamic insertion without
topology reconfigurations
Businesses Blocked by WAN Challenges
App Performance / Bandwidth
Expense & Constraint Issues
Branch deployment
Complexity
Cloud migration Not supported
by static architectures
X
X
X
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Enterprise Legacy WAN
Datacenter
BranchBranch
• Network topology based physical service insertion
• Complex routing – difficult to distribute / disaggregate services
to regional “service” hubs
• Internet traffic backhauled – not optimal for migration to cloud
MPLS
Firewall
Web
security
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Alternative to Backhaul: Direct Internet Breakout
Datacenter
BranchBranch
• “Direct” to Internet
• Cost and operational support for hardware services in branch
• Or complexity of forwarding to cloud based security
• Best effort for availability and performance
MPLS
INTERNET
Firewall with UTM
Cloud Security
MPLS
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Why Software-Defined WAN?
Requirement
Simplicity &
Manageability
• Simplify and expedite new branch rollouts, and
configuration across large number of sites
App performance • Ensure performance and availability of apps, especially
real-time
Bandwidth & Transport
cost
• Leverage economical bandwidth additions
Cloud migration • Optimize access to multiple cloud destinations, with
performance, security and manageability
Services delivery • Virtual services delivery including SD-WAN
• Simplify service chaining to distributed services
Flexible / Incremental
deployment
• Incremental migration, and legacy interoperability
• Avoid capex, proprietary hardware
VeloCloud Networks Proprietary & Confidential | © Copyright 2016







SD-WAN Service Insertion & Chaining benefits
SD-WAN Advantages
Branch
Edges
Cloud Gateways
SaaS
Zero touch deployments, simplified
operations, one-click service
insertion
Direct cloud access with
performance, reliability and security
Simplified WAN
Management
Managed on-ramp
to the cloud
Datacenter Edges
Transport independent performance for the
most demanding apps, leverages economical
bandwidth
SD-WAN Overlay
Assured Application
Performance
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Cloud-Delivered SD-WAN Architecture
Branch Site Enterprise DC
Hub Edge
Branch
Edge
Enterprise DC
Hybrid Cloud
Traditional
Private
Datacenters
INTERNET
Cloud Gateways
Orchestrator
Private - MPLS
Controllers
Private & Internet circuits, Enterprise & SaaS applications, On premise & Cloud deployments
Service
Insertion Points
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Service Insertion at Branch
vCPE platform
OS + HW
Branch Services Insertion
SD-WAN
VNF
FW
VNF
WOC
VNF
Orchestration
General Purpose
Virtual CPE
3
HW = hardware; vCPE = virtualized CPE; OS = operating system
= Cloud Delivered
SDWAN
SDWAN Virtual
Services Platform
SDWAN
FW
VNF
X
VNF
SDWAN Orchestration
SD-WAN Virtual
Services Platform
L7
Fire
wall
Dyn
Multi
Path
VPN NAT
SDWAN
SD-WAN CPE
with virtualized services
Embedded Services
 Services on / off
 Granular policies by L7 traffic profile
Multiple CPE options:
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN
SD-WAN Policy-Based Service Chaining
SaaS / IaaS
Enterprise DC
Branch
Web
Cloud
Gateways
Different service chains applied by policy
Services can be at branch only or dual ended
SD-WAN Edge
SD-WAN
Edge
VPN
Fire
wall
Dyn
Multi
Path
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Multi-Path Optimization Service
Assured Application performance over MPLS, Internet broadband and LTE circuits
Continuous Link Monitoring
Drives automation and
optimization
Dynamic Per Packet Steering
Sub-second steering
without session drops
Aggregated bandwidth for
single flows
On Demand Remediation
Protects against
concurrent degradation
Enables single link
performanceVeloCloud Networks Proprietary & Confidential | © Copyright 2016
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Cloud VPN Service
Branch Site Enterprise DC
Hub Edge
Branch
Edge
Enterprise DC
Traditional
Private
Datacenters
INTERNET
Cloud Gateways
Private - MPLS
IPsec VPN
Unified VPN over all transports
Cloud VPN eliminates backhaul
Automated VPN to cloud via gateway
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Extensible Virtual Services
Application Firewall
L7 stateful firewall
Cloud Web Security
Identity Based Access Control
802.1x authenticated access
Automated Monitoring
Deep Application Recognition
Packet inspection for application
recognition
Application & Link Visibility
Link status and application usage
Application Performance
Application network performance statistics
Security Services
Assured WAN Performance
Dynamic Multi-Path Optimization
Application steering and link remediation
Business Policy
Application prioritization and network service
insertion
Comprehensive LAN Services
3rd Party
Ecosystem partner apps
Auto IP Address
Management
By sites and profiles
DHCP, DNS, WLAN…
LAN network services
Policy Based NAT
Source and destination based
Secure Overlay
Cloud VPN
Auto IPsec VPN between Edges and
3rd party devices
Hybrid VPN
IPsec VPN and MPLS
Regional / Enterprise Services
Internet Backhaul is Complex With Traditional WAN
Challenges with Traditional WAN
 Not performance-aware
 Policy definition at L3 only
 Requires touching every branch
 Per-application tuning difficult
 More complex with multiple links
Branch
Headend
Advertise
0.0.0.0/0
(Preferred)
Advertise
0.0.0.0/0
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Policy-based Internet Backhaul to Regional DCs
 Backhaul ALL or subset of Internet traffic
 Flexible link steering policy
Branch
Edge
Primary
Hub Edge
Secondary
Hub Edge
Primary path Secondary path
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN Distributed Services Insertion for Internet
Branch Site
Distributed Regional Mini-
Datacenters
On Premise
Email DLP
Firewalls
Enterprise
Applications
Enterprise Datacenters
Distributed Service Insertion
• SD-WAN one-click app aware service insertion
• Enables disaggregation and distribution of services to
multiple regional mini-datacenters
• Same or different service chains by DC
• SD-WAN optimal for SDN instantiated virtual services in DC
• Reduces branch complexity and attack surface
SD-WAN
Edges
SD-WAN
Edges
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN Distributed Services Insertion for B2B
Branch Site
Distributed Regional Mini-
Datacenters
Firewalls
Distributed Service Insertion
• Regionalize services even for branch to branch traffic
• Next gen firewall can apply rules by application
SD-WAN
Edges
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN Multi-DC Services Insertion for Internet
Branch Site
Datacenter 1
SVC
1
Multi-DC Service Insertion
• Dynamic routing for service insertion
Datacenter 2
SVC
2
SD-WAN
Edges
SD-WAN
Edge
SD-WAN
Edge
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Cloud / SP Services
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN Hybrid Services Insertion
Branch Site
Enterprise Hub
On Premises
Security
Other Web traffic
Salesforce.com
Web email
Internet
• Backhaul to on-premises services
– Regional and central
• SD-WAN performance service-chained to cloud security services
• One-click, by application Cloud
Security
Services
SD-WAN service chaining for hybrid services
SD-WAN
Edge
Cloud Services Chaining
Enterprise A
VLAN 1
VLAN 2
VLAN 3
VLAN 4
Enterprise B VRF A
VLAN 1
VLAN 2
VLAN 3
VLAN 4
Multi-Tenant
SD-WAN Cloud
Gateway
VRF 3
VRF 4
• Services by Enterprise – VRF mapping
• Services granularity by VLAN tag
VRF B-4
VRF B-3
SP NFV Orchestrator
SD-WAN
Edge
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
SD-WAN
Service Chained Optimization
MPLS/Private
QoE Service Chaining
 WAN edge QoS (prioritization, bandwidth allocation)
 SD-WAN multi-path optimization with MPLS CoS
 MPLS core with CoS
 Interoperable data plane signaling
CoS outside
SDWAN
encapsulation
CoS inside
SDWAN
encapsulation
Policy based CoS
setting
SD-WAN
Edge
Summary: Service Chaining Use Cases
 At branch CPE, enterprise DC, or cloud service
 Within SD-WAN CPE, or SD-WAN as VNF
 Distributed regional service centers
 Branch-to-branch and branch-to-Internet traffic
 Multi-hop service centers
 Hybrid on-premises and cloud services
 Cloud services by enterprise and segment
 SD-WAN to SP optimization
SD-WAN Interoperability
SD-WAN policy-based interoperability support:
• Data plane
– TOS/CoS
– VLANs
– Upcoming: IETF draft: NSH
• Orchestration
– MEF OpenLSO
– CORD
– Linux Foundation OPEN-O
– ONUG Open SDWAN Exchange
VeloCloud Networks Proprietary & Confidential | © Copyright 2016
Q&A
www.velocloud.com/sd-wan-dummies

More Related Content

What's hot

SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?Haris Chughtai
 
Software-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success StorySoftware-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success StoryCisco Enterprise Networks
 
Aruba 2930 f switch campus switching
Aruba 2930 f switch   campus switching Aruba 2930 f switch   campus switching
Aruba 2930 f switch campus switching Eketerina Dyakova
 
Aruba presentation solutions overview - v1
Aruba presentation   solutions overview - v1Aruba presentation   solutions overview - v1
Aruba presentation solutions overview - v1Hasan Zuberi
 
SD WAN Technology Overview
SD WAN Technology OverviewSD WAN Technology Overview
SD WAN Technology OverviewI Nyoman Sujana
 
Transforming Private 5G Networks
Transforming Private 5G NetworksTransforming Private 5G Networks
Transforming Private 5G Networksinside-BigData.com
 
Introduction to Software Defined WANs
Introduction to Software Defined WANsIntroduction to Software Defined WANs
Introduction to Software Defined WANsAPNIC
 
Cisco Meraki- Simplifying IT
Cisco Meraki- Simplifying ITCisco Meraki- Simplifying IT
Cisco Meraki- Simplifying ITCisco Canada
 
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...ThousandEyes
 
Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016
Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016
Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016Bruno Teixeira
 
Software Defined networking (SDN)
Software Defined networking (SDN)Software Defined networking (SDN)
Software Defined networking (SDN)Milson Munakami
 
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXCustomer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXssuser5824cf
 
FUTURE-PROOFING DATA CENTRES from Connectivity Perspective
FUTURE-PROOFING DATA CENTRES from Connectivity PerspectiveFUTURE-PROOFING DATA CENTRES from Connectivity Perspective
FUTURE-PROOFING DATA CENTRES from Connectivity PerspectiveMyNOG
 

What's hot (20)

SD-WAN
SD-WANSD-WAN
SD-WAN
 
SDWAN.pdf
SDWAN.pdfSDWAN.pdf
SDWAN.pdf
 
Meraki Overview
Meraki OverviewMeraki Overview
Meraki Overview
 
SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?
 
Software-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success StorySoftware-Defined WAN: A Real World Success Story
Software-Defined WAN: A Real World Success Story
 
Aruba 2930 f switch campus switching
Aruba 2930 f switch   campus switching Aruba 2930 f switch   campus switching
Aruba 2930 f switch campus switching
 
Secure Your Network for Scale & the Cloud
Secure Your Network for Scale & the CloudSecure Your Network for Scale & the Cloud
Secure Your Network for Scale & the Cloud
 
Cisco ASA Firewalls
Cisco ASA FirewallsCisco ASA Firewalls
Cisco ASA Firewalls
 
Aruba presentation solutions overview - v1
Aruba presentation   solutions overview - v1Aruba presentation   solutions overview - v1
Aruba presentation solutions overview - v1
 
SD WAN Technology Overview
SD WAN Technology OverviewSD WAN Technology Overview
SD WAN Technology Overview
 
Transforming Private 5G Networks
Transforming Private 5G NetworksTransforming Private 5G Networks
Transforming Private 5G Networks
 
Software Defined WAN – SD-WAN
Software Defined WAN – SD-WANSoftware Defined WAN – SD-WAN
Software Defined WAN – SD-WAN
 
Introduction to Software Defined WANs
Introduction to Software Defined WANsIntroduction to Software Defined WANs
Introduction to Software Defined WANs
 
Cisco Meraki- Simplifying IT
Cisco Meraki- Simplifying ITCisco Meraki- Simplifying IT
Cisco Meraki- Simplifying IT
 
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
 
Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016
Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016
Cisco Live! :: Carrier Ethernet 2.0 :: BRKSPG-2720 | Las Vegas July/2016
 
Software Defined networking (SDN)
Software Defined networking (SDN)Software Defined networking (SDN)
Software Defined networking (SDN)
 
Campus Network Design version 8
Campus Network Design version 8Campus Network Design version 8
Campus Network Design version 8
 
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXCustomer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
 
FUTURE-PROOFING DATA CENTRES from Connectivity Perspective
FUTURE-PROOFING DATA CENTRES from Connectivity PerspectiveFUTURE-PROOFING DATA CENTRES from Connectivity Perspective
FUTURE-PROOFING DATA CENTRES from Connectivity Perspective
 

Similar to Maximizing SD-WAN Architecture with Service Chaining - VeloCloud

SD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloudSD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloudVeloCloud Networks, Inc.
 
A Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloudA Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloudVeloCloud Networks, Inc.
 
Under the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloudUnder the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloudVeloCloud Networks, Inc.
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityMarketingArrowECS_CZ
 
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloudCloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloudVeloCloud Networks, Inc.
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
SD-WAN 2.0: Building a Better SD-WAN, October 2016
SD-WAN 2.0: Building a Better SD-WAN, October 2016SD-WAN 2.0: Building a Better SD-WAN, October 2016
SD-WAN 2.0: Building a Better SD-WAN, October 2016ADVA
 
Amplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloudAmplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloudVeloCloud Networks, Inc.
 
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...SWITCHPOINT NV/SA
 
Tech Talk by Tim Van Herck: SDN & NFV for WAN
Tech Talk by Tim Van Herck: SDN & NFV for WANTech Talk by Tim Van Herck: SDN & NFV for WAN
Tech Talk by Tim Van Herck: SDN & NFV for WANnvirters
 
SD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital TransformationSD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital TransformationRalph Santitoro
 
Using a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business networkUsing a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business networkNetpluz Asia Pte Ltd
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
Cisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation BranchCisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation BranchCisco Canada
 
Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...
Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...
Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...James Kelly
 
CloudGenix_Customer Presentation
CloudGenix_Customer PresentationCloudGenix_Customer Presentation
CloudGenix_Customer PresentationSyed Arsalan
 
SDWAN Introduction presentation & Public Speaking
SDWAN Introduction presentation & Public SpeakingSDWAN Introduction presentation & Public Speaking
SDWAN Introduction presentation & Public Speakingdatnc09
 
Cisco Intelligent Branch - Enabling the Next Generation Branch
Cisco Intelligent Branch - Enabling the Next Generation BranchCisco Intelligent Branch - Enabling the Next Generation Branch
Cisco Intelligent Branch - Enabling the Next Generation BranchCisco Canada
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 

Similar to Maximizing SD-WAN Architecture with Service Chaining - VeloCloud (20)

SD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloudSD-WAN for Public & Private Clouds - VeloCloud
SD-WAN for Public & Private Clouds - VeloCloud
 
A Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloudA Better Architecture for Hybrid WAN - VeloCloud
A Better Architecture for Hybrid WAN - VeloCloud
 
Under the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloudUnder the Hood of Cloud-Delivered SD-WAN - VeloCloud
Under the Hood of Cloud-Delivered SD-WAN - VeloCloud
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivity
 
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloudCloud-Delivered SD-WAN is Earth Friendly - VeloCloud
Cloud-Delivered SD-WAN is Earth Friendly - VeloCloud
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
SD-WAN 2.0: Building a Better SD-WAN, October 2016
SD-WAN 2.0: Building a Better SD-WAN, October 2016SD-WAN 2.0: Building a Better SD-WAN, October 2016
SD-WAN 2.0: Building a Better SD-WAN, October 2016
 
Turbo-boosting Hybrid WAN using SD-WAN
Turbo-boosting Hybrid WAN using SD-WANTurbo-boosting Hybrid WAN using SD-WAN
Turbo-boosting Hybrid WAN using SD-WAN
 
Amplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloudAmplify Hybrid WAN ROI with SD-WAN - VeloCloud
Amplify Hybrid WAN ROI with SD-WAN - VeloCloud
 
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
Silver Peak presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
 
Tech Talk by Tim Van Herck: SDN & NFV for WAN
Tech Talk by Tim Van Herck: SDN & NFV for WANTech Talk by Tim Van Herck: SDN & NFV for WAN
Tech Talk by Tim Van Herck: SDN & NFV for WAN
 
SD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital TransformationSD-WAN and the Multi-Cloud Digital Transformation
SD-WAN and the Multi-Cloud Digital Transformation
 
Using a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business networkUsing a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business network
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
Cisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation BranchCisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation Branch
 
Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...
Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...
Contrail SD-WAN: Secure, Automated Multicloud and Multi-site SD-Branch Connec...
 
CloudGenix_Customer Presentation
CloudGenix_Customer PresentationCloudGenix_Customer Presentation
CloudGenix_Customer Presentation
 
SDWAN Introduction presentation & Public Speaking
SDWAN Introduction presentation & Public SpeakingSDWAN Introduction presentation & Public Speaking
SDWAN Introduction presentation & Public Speaking
 
Cisco Intelligent Branch - Enabling the Next Generation Branch
Cisco Intelligent Branch - Enabling the Next Generation BranchCisco Intelligent Branch - Enabling the Next Generation Branch
Cisco Intelligent Branch - Enabling the Next Generation Branch
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 

Recently uploaded

Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMKumar Satyam
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)Samir Dash
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard37
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKJago de Vreede
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 

Recently uploaded (20)

Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 

Maximizing SD-WAN Architecture with Service Chaining - VeloCloud

  • 1. Maximizing SD-WAN with Service Insertion/Chaining Architectures VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Steve Woo, VP Products & Co-founder
  • 2. VeloCloud Networks, Inc. | Proprietary & Confidential | © Copyright 2016 Service chaining verb / serv-ice chain-ing : interconnecting a set of services through the network : simplified with both SDN [SD-WAN] and NFV : meet expectations of dynamic insertion without topology reconfigurations
  • 3. Businesses Blocked by WAN Challenges App Performance / Bandwidth Expense & Constraint Issues Branch deployment Complexity Cloud migration Not supported by static architectures X X X VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 4. Enterprise Legacy WAN Datacenter BranchBranch • Network topology based physical service insertion • Complex routing – difficult to distribute / disaggregate services to regional “service” hubs • Internet traffic backhauled – not optimal for migration to cloud MPLS Firewall Web security VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 5. Alternative to Backhaul: Direct Internet Breakout Datacenter BranchBranch • “Direct” to Internet • Cost and operational support for hardware services in branch • Or complexity of forwarding to cloud based security • Best effort for availability and performance MPLS INTERNET Firewall with UTM Cloud Security MPLS VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 6. Why Software-Defined WAN? Requirement Simplicity & Manageability • Simplify and expedite new branch rollouts, and configuration across large number of sites App performance • Ensure performance and availability of apps, especially real-time Bandwidth & Transport cost • Leverage economical bandwidth additions Cloud migration • Optimize access to multiple cloud destinations, with performance, security and manageability Services delivery • Virtual services delivery including SD-WAN • Simplify service chaining to distributed services Flexible / Incremental deployment • Incremental migration, and legacy interoperability • Avoid capex, proprietary hardware VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 7.
  • 9. SD-WAN Advantages Branch Edges Cloud Gateways SaaS Zero touch deployments, simplified operations, one-click service insertion Direct cloud access with performance, reliability and security Simplified WAN Management Managed on-ramp to the cloud Datacenter Edges Transport independent performance for the most demanding apps, leverages economical bandwidth SD-WAN Overlay Assured Application Performance VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 10. Cloud-Delivered SD-WAN Architecture Branch Site Enterprise DC Hub Edge Branch Edge Enterprise DC Hybrid Cloud Traditional Private Datacenters INTERNET Cloud Gateways Orchestrator Private - MPLS Controllers Private & Internet circuits, Enterprise & SaaS applications, On premise & Cloud deployments Service Insertion Points VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 12. vCPE platform OS + HW Branch Services Insertion SD-WAN VNF FW VNF WOC VNF Orchestration General Purpose Virtual CPE 3 HW = hardware; vCPE = virtualized CPE; OS = operating system = Cloud Delivered SDWAN SDWAN Virtual Services Platform SDWAN FW VNF X VNF SDWAN Orchestration SD-WAN Virtual Services Platform L7 Fire wall Dyn Multi Path VPN NAT SDWAN SD-WAN CPE with virtualized services Embedded Services  Services on / off  Granular policies by L7 traffic profile Multiple CPE options: VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 13. VeloCloud Networks Proprietary & Confidential | © Copyright 2016 SD-WAN SD-WAN Policy-Based Service Chaining SaaS / IaaS Enterprise DC Branch Web Cloud Gateways Different service chains applied by policy Services can be at branch only or dual ended SD-WAN Edge SD-WAN Edge VPN Fire wall Dyn Multi Path
  • 14. VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Multi-Path Optimization Service Assured Application performance over MPLS, Internet broadband and LTE circuits Continuous Link Monitoring Drives automation and optimization Dynamic Per Packet Steering Sub-second steering without session drops Aggregated bandwidth for single flows On Demand Remediation Protects against concurrent degradation Enables single link performanceVeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 15. VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Cloud VPN Service Branch Site Enterprise DC Hub Edge Branch Edge Enterprise DC Traditional Private Datacenters INTERNET Cloud Gateways Private - MPLS IPsec VPN Unified VPN over all transports Cloud VPN eliminates backhaul Automated VPN to cloud via gateway
  • 16. VeloCloud Networks Proprietary & Confidential | © Copyright 2016 Extensible Virtual Services Application Firewall L7 stateful firewall Cloud Web Security Identity Based Access Control 802.1x authenticated access Automated Monitoring Deep Application Recognition Packet inspection for application recognition Application & Link Visibility Link status and application usage Application Performance Application network performance statistics Security Services Assured WAN Performance Dynamic Multi-Path Optimization Application steering and link remediation Business Policy Application prioritization and network service insertion Comprehensive LAN Services 3rd Party Ecosystem partner apps Auto IP Address Management By sites and profiles DHCP, DNS, WLAN… LAN network services Policy Based NAT Source and destination based Secure Overlay Cloud VPN Auto IPsec VPN between Edges and 3rd party devices Hybrid VPN IPsec VPN and MPLS
  • 18. Internet Backhaul is Complex With Traditional WAN Challenges with Traditional WAN  Not performance-aware  Policy definition at L3 only  Requires touching every branch  Per-application tuning difficult  More complex with multiple links Branch Headend Advertise 0.0.0.0/0 (Preferred) Advertise 0.0.0.0/0 VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 19. Policy-based Internet Backhaul to Regional DCs  Backhaul ALL or subset of Internet traffic  Flexible link steering policy Branch Edge Primary Hub Edge Secondary Hub Edge Primary path Secondary path VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 20. SD-WAN Distributed Services Insertion for Internet Branch Site Distributed Regional Mini- Datacenters On Premise Email DLP Firewalls Enterprise Applications Enterprise Datacenters Distributed Service Insertion • SD-WAN one-click app aware service insertion • Enables disaggregation and distribution of services to multiple regional mini-datacenters • Same or different service chains by DC • SD-WAN optimal for SDN instantiated virtual services in DC • Reduces branch complexity and attack surface SD-WAN Edges SD-WAN Edges VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 21. SD-WAN Distributed Services Insertion for B2B Branch Site Distributed Regional Mini- Datacenters Firewalls Distributed Service Insertion • Regionalize services even for branch to branch traffic • Next gen firewall can apply rules by application SD-WAN Edges VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 22. SD-WAN Multi-DC Services Insertion for Internet Branch Site Datacenter 1 SVC 1 Multi-DC Service Insertion • Dynamic routing for service insertion Datacenter 2 SVC 2 SD-WAN Edges SD-WAN Edge SD-WAN Edge VeloCloud Networks Proprietary & Confidential | © Copyright 2016
  • 23. Cloud / SP Services
  • 24. VeloCloud Networks Proprietary & Confidential | © Copyright 2016 SD-WAN Hybrid Services Insertion Branch Site Enterprise Hub On Premises Security Other Web traffic Salesforce.com Web email Internet • Backhaul to on-premises services – Regional and central • SD-WAN performance service-chained to cloud security services • One-click, by application Cloud Security Services SD-WAN service chaining for hybrid services SD-WAN Edge
  • 25. Cloud Services Chaining Enterprise A VLAN 1 VLAN 2 VLAN 3 VLAN 4 Enterprise B VRF A VLAN 1 VLAN 2 VLAN 3 VLAN 4 Multi-Tenant SD-WAN Cloud Gateway VRF 3 VRF 4 • Services by Enterprise – VRF mapping • Services granularity by VLAN tag VRF B-4 VRF B-3 SP NFV Orchestrator SD-WAN Edge
  • 26. VeloCloud Networks Proprietary & Confidential | © Copyright 2016 SD-WAN Service Chained Optimization MPLS/Private QoE Service Chaining  WAN edge QoS (prioritization, bandwidth allocation)  SD-WAN multi-path optimization with MPLS CoS  MPLS core with CoS  Interoperable data plane signaling CoS outside SDWAN encapsulation CoS inside SDWAN encapsulation Policy based CoS setting SD-WAN Edge
  • 27. Summary: Service Chaining Use Cases  At branch CPE, enterprise DC, or cloud service  Within SD-WAN CPE, or SD-WAN as VNF  Distributed regional service centers  Branch-to-branch and branch-to-Internet traffic  Multi-hop service centers  Hybrid on-premises and cloud services  Cloud services by enterprise and segment  SD-WAN to SP optimization
  • 28. SD-WAN Interoperability SD-WAN policy-based interoperability support: • Data plane – TOS/CoS – VLANs – Upcoming: IETF draft: NSH • Orchestration – MEF OpenLSO – CORD – Linux Foundation OPEN-O – ONUG Open SDWAN Exchange VeloCloud Networks Proprietary & Confidential | © Copyright 2016