Click here to load reader
View
313
Download
0
Embed Size (px)
CloudStack 4.0 Training - Example Content
Apache CloudStackModelos de Redes e SDNMarcelo Lima
1CloudStack Bootcamp 4.3
Sobre ...
Marcelo Lima [email protected]
Arquiteto de Cloud & Data Center da ShapeBlue BrasilEspecializado em...Design & Building de Clouds baseadas em Apache CloudStack / Citrix CloudPlatformInfraestruturas de Data CenterAutomao de InfraestruturaAmbientes de alta disponibilidade e escalabilidade
CertificaesCitrix Certified Professional Networking (CCP-N)F5 System Engineer LTM/GTM/ASMCisco Certified Internetwork Expert Data Center (CCIE-DC Written)Cisco Certified Network Professional Data Center (CCNP-DC)Cisco Certified Network Associate Data Center (CCNA-DC)Cisco Data Center Unified Computing Support SpecialistCisco Data Center Unified Computing Design SpecialistCisco Data Center Unified Fabric Support SpecialistCisco Data Center Unified Fabric Design Specialist
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
2CloudStack Bootcamp 4.3
Sobre a ShapeBlue
Somos um time de arquitetos e engenheiros especialistas em construo de infraestruturas para nuvens IaaS tanto pblicas quanto privadas.Somos lderes globais em consultoria e integrao independente de Apache CloudStack e Citrix CloudPlatformCopyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
3CloudStack Bootcamp 4.3
Sobre a ShapeBlueCopyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
4CloudStack Bootcamp 4.3
Ementa da apresentao
O que o Apache CloudStack?Tipos de redesBsicaAvanada com Grupos de SeguranaAvanada (Compartilhada, Isolada e VPC)SDN no Apache CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
5CloudStack Bootcamp 4.3
O que o Apache CloudStack?
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
Plataforma de orquestrao de infraestrutura, multiusurio e segura (multi-tenant)Plataforma confivel para entrega de Nuvem IaaSAgnstico quanto ao hypervisor, ou seja, independente do software de virtualizao utilizadoEscalvel, flexvel, seguro e abertoCdigo aberto, padres abertosImplementao privada (no prprio Data Center) ou como uma soluo hospedadaO que o CloudStackCopyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
7CloudStack Bootcamp 4.3
Plataforma aberta flexvel
Compute
Tipo de redeIsolamentoFirewallSLB/GSLBSDNRede
Disco localiSCSIFC / FCoENFSSwiftStorageStorage PrimrioStorage SecundrioVPNS3XenServerVmware(vCenter)KVMLXCXen ProjectBare metal(IPMI)Hyper-VCopyright ShapeBlue 2015. All rights reservedCIFS/SMB(Hyper-V)NFSCIFS/SMB(Hyper-V)CEPH(KVM)
Copyright ShapeBlue 2012. All rights reserved
8CloudStack Bootcamp 4.3
Um appliance fsico ou virtual que fornea servios de rede para o CloudStack, como por exemplo:Provedor de Servios de RedeVirtual RouterVPC Virtual RouterInternal LBVMCitrix NetScalerF5 BigIP - LTMJuniper SRX FirewallPalo AltoCisco VNMC/ASA 1000vMidoNetBigSwitch VnsNuage VSPVMware NSXJuniper ContrailOvs VXLANOpenDaylight (experimental)Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
Virtual RouterVPC Virtual RouterInternal Load Balancer VMCitrix NetScalerF5 Load BalancerJuniper SRX FirewallNicira Network Virtualization PlatformMidokura MidonetBigSwitch Virtual Network SegmentsCisco Virtual Network Management Center
9CloudStack Bootcamp 4.3
Tipos de rede no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
ZonasZona Bsica Compartilhada com Grupos de SeguranaZona Avanada Grupos de SeguranaZona Avanada Compartilhada, Isolada, VPCTipos de rede no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
11CloudStack Bootcamp 4.3
Zona Bsica Compartilhada com Grupos de SeguranaFornece uma nica rede onde o isolamento dos hspedes pode ser fornecido atravs da camada 3 (IP) utilizando grupos de segurana (filtragem por IP de origem)Uma nica rede FlatZona Bsica
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
12CloudStack Bootcamp 4.3
Rede Compartilhada Zona BsicaVMVMwww
Copyright ShapeBlue 2015. All rights reserved
VMVMVM
VR
Copyright ShapeBlue 2012. All rights reserved
Traffic between VMs within an Account, and their Virtual Router, Physical Load Balancer or Physical Firewall
13CloudStack Bootcamp 4.3
Zona Avanada Compartilhada com Grupo de SeguranaSemelhante a zona Bsica porm fornece mais de rede onde o isolamento dos hspedes pode ser fornecido atravs da camada 3 (IP) utilizando grupos de segurana (filtragem por IP de origem)Mais de uma rede FlatZona Avanada com SG
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
14CloudStack Bootcamp 4.3
Zona Avanada com SGVRVMVMwwwVRVMVMVRVMVM
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
Traffic between VMs within an Account, and their Virtual Router, Physical Load Balancer or Physical Firewall
15CloudStack Bootcamp 4.3
Zona Avanada Compartilhada, Isolada ou VPCEsse modelo de rede fornece maior flexibilidade na definio de redes Guest e fornece ofertas/servios de rede personalizadas, tais como firewall, VPN, Load Balancer e recursos de VPC. O isolamento dos Guests realizado atravs da camada-2 (Ethernet) usando VLANs, por exemplo, VLANs ou SDN.
Zona Avanada
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
16CloudStack Bootcamp 4.3
Rede Guest Compartilhada Zona AvanadawwwVRVMVMLayer3VRVMVMVRVMVMShared 01Shared 02Shared 03
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
Traffic between VMs within an Account, and their Virtual Router, Physical Load Balancer or Physical Firewall
17CloudStack Bootcamp 4.3
Rede Guest Isolada Zona AvanadaVirtual RouterVMVMVMVirtual RouterVMVMVMwwwVirtual RouterVMVMVMIsolated 01Isolated 02Isolated 03
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
Traffic between VMs within an Account, and their Virtual Router, Physical Load Balancer or Physical Firewall
18CloudStack Bootcamp 4.3
Rede VPC Virtual Private Cloud Zona AvanadaVirtual RouterwwwLBVMVMVMVMVMVMVMVMCamada WebCamada AppCamada DB
Copyright ShapeBlue 2015. All rights reservedLBVM
Copyright ShapeBlue 2012. All rights reserved
Traffic between VMs within an Account, and their Virtual Router, Physical Load Balancer or Physical Firewall
19CloudStack Bootcamp 4.3
SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
SDN em Cloud ComputingNo podemos limitar SDN apenas em gerenciamento de fluxos. SDN em cloud no se limita apenas em OpenFlow.Servios gerenciados via software, entre eles Firewall (filtros e nat), Load Balancing (slb e gslb), VPN (c2s, s2s), AutoScaling, OpenFlow, VXLAN, NVGRE, STT, GRE, ODL, etc.SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
21CloudStack Bootcamp 4.3
O limitador 802.1q (Vlan)Limita o isolamento entre clientes/usurios ao nmero de vlans suportado pelos switches L2 utilizados na infraestrutura. No melhor dos casos 4094 redes.Extenso de vlans entre Data Centers pode ser um problema.
SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
22CloudStack Bootcamp 4.3
As alternativasVXLAN Virtual eXtensible Local Area NetworkGRE Ovs Generic Routing Encapulation over Open vSwitchSTT Stateless Transport Tunnel
SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
23CloudStack Bootcamp 4.3
VXLAN - Virtual eXtensible Local Area NetworkO frame L2 original encapsulado dentro de pacote UDP.O switch no precisa aprender o mac de cada VM, consequentemente reduz o tamanho da tabela mac dos switches.Necessita roteamento multicast caso haja equipamentos L3 entre VTEPs.No necessita Gateway VXLAN pois somente para trfego Guest.Altamente escalvel, 2^24 (16M).VXLANs podem ser extendidas entre Data Centers via L3.+ 54 bytes por pacote.
SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
24CloudStack Bootcamp 4.3
SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved
A Zone can be either Basic OR Advanced
25CloudStack Bootcamp 4.3
SDN no CloudStack
Copyright ShapeBlue 2015. All rights reserved
Copyright ShapeBlue 2012. All rights reserved