Data Center Interconnects
Data Center Interconnects
This material is copyrighted and licensed for the sole use by tEaM pHrOzEn-HeLL ([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
2 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations
Inputs:
• Business needs
• Generic technology requirements
• High-availability requirements
• Application structure and HA implementation
• Transport options
Design decisions:
• External routing
• Firewalling Covered in L3 DCI section
• Load balancing options
• Storage connectivity
• DCI type
© NIL Data
3 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Inputs
Business Needs
Disaster Recovery Site
• Secondary (cold) infrastructure activated after the recovery
Disaster Avoidance
• Migrate the workload before an anticipated disaster
• Data centers are concurrently active for a limited amount of time
• Target data center might already run other application loads
© NIL Data
4 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Inputs
Technology Requirements
Disaster Recovery Site
Network
• Storage replication to the DR site
• WAN connectivity at DR site
• Manual or orchestrated switchover or DR startup
Storage
Disaster Avoidance
+ Application load adjustment or live VM migration
+ WAN connectivity adjustments
+ Load balancing adjustments
© NIL Data
5 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Inputs
High-Availability Requirements
Disaster recovery
• Duplicated storage
• Servers (or VMs) are started on DR site after primary site failure
• Downtime: minutes or hours
Disaster avoidance
• Minimum downtime
• Local and global load balancing facilitates seamless Prefer
failover
• Live VMs moved to secondary site
Avoid
• Stretched cluster between sites (temporary or permanent)
26 This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Inputs
Transport Options
Dark fiber, SONET/SDH or DWDM VPLS Avoid
© NIL Data
7 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Decisions
Storage Connectivity
Synchronous
Long-distance block storage protocols: iSCSI or FC replication
• FCoE does not work due to PFC limitations
• Use checksum in iSCSI
1-WR
4-OK
WAN
2-WR
3-OK
Asynchronous
replication
Transport FC iSCSI
DWDM/fiber
1-WR
2-OK
WAN
Pseudowires FCIP 2-WR
3-OK
VPLS FCIP
IP FCIP
© NIL Data
8 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Decisions
© NIL Data
9 This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Design Considerations – Decisions
210This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
11This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI Overview
Classic Enterprise IP routing design
• Routing & bridging within each data center
• External connectivity from all data centers
• IP routing between data centers cores
Design considerations
• Workload distribution
• External routing
• Load balancing and NAT
• Firewalling
• High-availability and disaster avoidance procedures
© NIL Data
12This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
13This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
© NIL Data
14This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
fd00:0001::/32
fd00:0001::/32
target servers
Results:
• DCI failure causes traffic black holes DCI
• Heavy DCI utilization for inbound traffic
• Outbound traffic is optimal
• Asymmetric traffic flows
• Stateful firewalls not very useful
Distributed storage
315This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
fd00:0002::/32
fd00:0000::/30
fd00:0001::/32
fd00:0000::/30
FAIL
prefix for backup purposes
STOP
Results:
• Traffic flows are optimal DCI
• DCI heavily loaded during external
connectivity failures
• Use DNS-based load balancing
• Stateful firewalls will break TCP
sessions after external link
failure/recovery
Distributed storage
616This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
fd00:0002::/32
fd00:0001::/32
• DCI used only for inter-DC traffic
Results:
• Traffic flows are optimal DCI
Distributed storage
© NIL Data
17This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
18This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
Scalability/High-Availability Options
Scale up (bigger servers) or scale out (load balancing)?
• “Scale out” requires multiple parallel application copies
• Easy for web-based applications
• Oracle RAC supports active/active clusters
• MySQL 7.0 supports local active/active clusters and row-based
replication
Load balancing
• Within a data center (ACE/BIG-IP LTM)
• Between data centers (LB with source NAT)
• Globally with DNS-based load balancing (GSS/BIG-IP GTM)
© NIL Data
19This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
© NIL Data
20This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
© NIL Data
21This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
Process
LB to DC-B
• Graceful shutdown of DCI
servers in DC A
• Start new servers in DC B
• Load balancers shift load
toward DC B
• No Layer-2 DCI or vMotion required
822This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
23This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI
DC core DC core
PE-DC-A PE-DC-B
Requirements
• Layer-3 connectivity between data centers (reduce VLAN/STP domain size)
• Maintain separation between security zones (DMZ, applications, database, storage)
Solutions
• Multi-VRF + multiple (routed) VLANs across WAN link (simple)
• Single-hop MPLS/VPN across L2 interconnect link (technology-independent)
• Private MPLS/VPN backbone (multiple DC)
© NIL Data
24This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI with Path Isolation
© NIL Data
25This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI with Path Isolation
802.1Q
© NIL Data
26This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI with Path Isolation
© NIL Data
27This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI with Path Isolation
MPLS/VPN
MPLS/VPN
MPLS
DB
MGMT
IP
© NIL Data
28This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-3 DCI with Path Isolation
MPLS/VPN
MPLS/VPN
DB
MGMT
© NIL Data
29This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
30This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
Introduction to LISP
MR MS
Alternative
topology (ALT)
IP backbone
ITR ETR
RLOC EID
© NIL Data
31This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
LISP Terminology
MR MS
Alternative
topology (ALT)
IP backbone
ITR ETR
RLOC EID
© NIL Data
32This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
IP backbone
ITR ETR
RLOC EID
© NIL Data
33This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
Data-driven actions
• ITR receives IP packet addressed to unknown EID
• ITR sends Map-Request to local MR
• MR forwards Map-Request onto ALT topology
• Map-Request reaches ETR
• ETR responds with Map-Reply (Map-Reply can be based on ITR location)
• Map-Reply reaches ITR
• ITR installs the reply into local LISP EID-to-RLOC mapping cache
© NIL Data
34This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
• LISP will reach its full potential with global RLOC EID
deployment (every CE-router is an ITR)
• Local LISP deployment relies on proxy services
• PITR advertises EID prefixes into non-LISP IP backbone to attract traffic
• PITR performs IP-to-LISP translation
• Return traffic can flow through PITR, a dedicated PETR, or directly
• LISP and non-LISP IP traffic can use the same IP backbone
© NIL Data
35This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
• L3 (LISP) transport
between PITR and
Nexus 1000V
• L2 DCI is no longer
required
© NIL Data
36This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
LISP in Layer-3 DCI
DC LISP Caveats
Traffic flow issues
Internet
• LISP with DC PITR does not solve PITR PITR
ingress routing
• Output traffic flow is optimal Nexus 1000V MR MR Nexus 1000V
MS MS
Scalability
• EID prefix = host route (VM IP address)
• PITR EID-to-RLOC cache entry must expire soon after vMotion event
• Low TTL must be set on LISP mappings
• High volume of Map-Requests from PITRs
• Potential TCAM overflow on PITR
© NIL Data
37This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
38This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Drivers
VM load distribution
• Requirement: Migrate running VMs from overloaded data center
• Probable result: Overloaded WAN links due to traffic trombones
Stretched clusters
• Requirement: Cluster members spread across multiple data centers
• Perfect recipe for disaster: DCI WAN link becomes the weakest link
• Split-brain problems
© NIL Data
39This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
40This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Stretched cluster issues
• Lost cluster quorum and split brain disasters
• Long-distance flooding
• Asymmetric traffic flows and traffic trombones
Long-distance vMotion issues
• Traffic trombones
Bridging-related problems
• Broadcast storms propagated over WAN
• Widespread spanning tree-related outages
Bridging over WAN has never worked well. Why should it work in a Data Center?
+41This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Stretched Clusters
High Availability Clusters (typical implementation)
• Multiple servers offering the same service
• Active/standby configuration
• Peer failure detection through network heartbeat, LUN locking or
shared file system
• Example: Windows Server Failover Clustering (WSFC)
Stretched clusters
• Members of the same cluster in different data centers
• Often requires L2 connectivity between cluster members
© NIL Data
42This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Issues
• Unpredictable or
suboptimal traffic
flows
Distributed storage
© NIL Data
43This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Internet
HSRP peers
Same IP subnet
Pseudowire or
VPLS service
Shared IP address
© NIL Data
45This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Distributed storage
© NIL Data
46This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Extremely hard to
recover extensive
rollback or restore
Distributed storage
© NIL Data
47This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Internet
HSRP peers
Same IP subnet
FAILED
Shared IP address
Internet
WAN
MS NLB
cluster
549This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI caveats
Stretched cluster issues
• Lost cluster quorum and split brain disasters
• Long-distance flooding
• Asymmetric traffic flows and traffic trombones
Long-distance vMotion issues
• Traffic trombones
Bridging-related problems
• Broadcast storms propagated over WAN
• Widespread spanning tree-related outages
Bridging over WAN has never worked well. Why should it work in a Data Center?
© NIL Data
50This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Internet
WAN
Hypervisor Hypervisor
Distributed storage
751This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Proper fix: scalable application architecture and L3 DCI with load balancing
© NIL Data
52This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Internet
WAN
FHRP 10.0.0.1 Block HSRP FHRP 10.0.0.1
MAC address
253This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
WAN core
WAN
FHRP 10.0.0.1 Block HSRP+LB FHRP 10.0.0.1
MAC address
654This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI caveats
Stretched cluster issues
• Lost cluster quorum and split brain disasters
• Long-distance flooding
• Asymmetric traffic flows and traffic trombones
Long-distance vMotion issues
• Traffic trombones
Bridging-related problems
• Broadcast storms propagated over WAN
• Widespread spanning tree-related outages
Bridging over WAN has never worked well. Why should it work in a Data Center?
© NIL Data
55This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Broadcast Storms
Data Center A
Data Center B
FF FF FF FF FF
FF
WAN
FF FF FF FF
© NIL Data
56This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
Data Center B
Data Center A
FF FF FF FF FF
traffic rate
FF
WAN
FF FF FF FF
Apply per-server or on
WAN edge
© NIL Data
57This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats
STP root
Data Center A
Data Center B
WAN
Spanning Tree Protocol must be used in most bridged environments to prevent loops
• Half of the DCI bandwidth is wasted
• Failures close to the root bridge affect both data centers
• Every DCI failure causes topology change and massive flooding in DC B
258This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats – Spanning Tree
MST Region 1
MST Region 2
in each DC
• VLANs mapped to
non-default MST WAN
instances
• IST = Internal ST
• CIST = Common and
Internal ST
• Half of the DCI bandwidth is still wasted
• Failures in one DC do not propagate to the other DC (hidden inside MST region)
• DCI failures cause CIST topology change, but not MSTI topology change
• DCI failure affect only inter-DC traffic
© NIL Data
59This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats – Spanning Tree
STP domain
STP domain
inter-DC LAG bundle
• Independent STP WAN
instance in each DC
© NIL Data
60This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Caveats – Spanning Tree
STP domain
STP domain
WAN
Non-STP
bridging
© NIL Data
61This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Agenda
External routing
Load balancing
Design
considerations Layer-3 DCI
Path isolation
Inter-DC vMotion
Drivers
Data Center
Layer-2 DCI Challenges
Interconnects
Technologies
© NIL Data
62This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI
© NIL Data
63This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Technology Options
Data Center B
Data Center A
Service Provider
© NIL Data
64This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Technology Options
Data Center B
Data Center A
Service Provider
• Any core topology can be used
Platforms: Nexus 7000/w FP
Caveats:
• Per-VLAN dedicated forwarder
Exception: VPC+ with FP on Nexus 7000
• Check the integration with L3 forwarding
Data Center C
(keep L3 separate)
• Check the PW transparency and MTU size
• SP pseudowire aggregation technology (Q-in-Q or MAC-in-MAC) might interfere
with SPB
© NIL Data
65This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Technology Options
Data Center B
Data Center A
Service Provider
© NIL Data
66This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI Technology Options
Data Center B
Data Center A
Provider VPLS
IP subnet with MPLS/LDP
© NIL Data
67This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI – VPLS overview
Introduction to VPLS
Prerequisites: IP or IP+MPLS core
Data Center B
Data Center A
Concept:
• Full mesh of pseudowires
between PE-routers emulates a LAN IP+MPLS core
• Separate full mesh per VLAN
Transport: AToM or L2TPv3
Signaling: Directed LDP or BGP
Autodiscovery: BGP
Scalability: H-VPLS (full mesh of trees + Q-in-Q) Data Center C
+68This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI – VPLS overview
Data Center B
Data Center A
• Catalyst 6500/Cisco 7600 only
• ES or SIP linecard on the IP+MPLS core
WAN side
• No MPLS support in NX-OS
Redundancy solutions:
• Spanning tree on “loopback” pseudowires
• EEM-based loopback interface tracking
• A-VPLS with VSS
© NIL Data
69This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI – VPLS overview
BPDU
• VPLS does not provide this functionality
BLOCK
BPDU
Solutions:
• Run STP on the pseudowire between redundant switches
• Enable/disable pseudowires on backup device based on
reachability of loopback interface on primary device (EEM based)
• VSS (A-VPLS)
470This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI – VPLS overview
What is A-VPLS
A-VPLS = VPLS + Cisco Enhancements Data Center WAN core
VSS support
• Solves redundant design issues
• VSS appears as a single PE-device
• NSF/SSO for pseudowires
Enhanced load balancing
• Multiple LSPs/GRE tunnels per pseudowire
VSS
• Port-channel-like load balancing between parallel LSPs
• Extra “flow” label to enable intra-LSP balancing in the MPLS core
Reduced configuration complexity
• interface virtual-ethernet behaves like a trunking LAN interface
• Parallel per-VLAN pseudowires are established automatically
© NIL Data
71This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
L2 DCI – VPLS overview
L2 payload L2 payload
Flow label PW label LDP label L2 header
+72This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI
© NIL Data
73This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI – IP core
Data Center B
Core IP
backbone
Port Channel
© NIL Data
74This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI – IP core
Data Center B
Data Center A
IP core
375This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI – IP core
Data Center B
Data Center A
IP core
+76This material
© NIL Data Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI – IP core
OTV Terminology
Edge device: device performing Ethernet-to-IP encapsulation
Internal interface: DC-facing interface on edge device
Data Center A
• Regular L2 interface
IP core
Join interface: WAN-facing uplink interface on edge device
• Routed interface
• Edge device is an IP host
Overlay interface: virtual interface with OTV configuration
• Logical multi-access multicast-capable interface
• No spanning tree on overlay interface
ARP ND cache: ARP snooping reduces inter-site ARP traffic
Site VLAN: VLAN used for edge device discovery
• Must be configured on internal interface(s)
Authoritative Edge Device
• Edge device performing internal-to-overlay forwarding for a VLAN
© NIL Data
77This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI – IP core
© NIL Data
78This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Layer-2 DCI – IP core
Data Center B
Data Center A
True Layer-2 MPLS/VPN
• RD identifies unique MAC-VPN instances IP+MPLS core
EtherIP caveats:
• No STP across EtherIP tunnel
• Network design must ensure loop-free topology
© NIL Data
80This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Conclusions
DCI is primarily a design problem
• Start with application architecture and business requirements
• Prefer L3 DCI (consider path isolation) and heavy use of local and
global load balancing
• Try to avoid live VM migration between data centers
Layer-3 DCI
• Use separate IP prefix for each data center
• Use DNS-based load balancing for application migration
• Use Multi-VRF (simple) or MPLS/VPN (scalable) for path isolation
© NIL Data
81This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Conclusions
Layer-2 DCI has numerous challenges
• Split subnets and split clusters after DCI failure
• Traffic trombones
• Broadcast storms
• Spanning tree issues (avoid long-distance STP)
© NIL Data
82This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars
Questions?
© NIL Data
83This material Communications
is copyrighted and2010 Data
licensed for the sole Center
use 3.0 forpHrOzEn-HeLL
by tEaM the Networking Engineers
([email protected] [8.28.167.154]). More information at http://www.ipSpace.net/Webinars