4. 2013 OpenFlow Korea All Rights Reserved
覲伎 碁
一危磯 2013 03 06 ()
企殊磯 讌 ろ語 覲伎 蠍一 譴伎
.覓朱Μ揃螳 ろ語 覲伎 誤襴れ 襴貅伎揃 語 蠍一 螻牛覃,
危朱伎 螻糾鴬螻 VM螳 螻糾鴬 覦危. 螳 貉碁,襯 伎 企 VM 碁曙
危覃, VM螳 碁曙 覦危螻, 螳 蟆 螳煙 螻牛も..
SDN central By: Nikos Theodosopoulos Posted: Feb. 08, 2013
What (if Any) Part of the Networking Value Chain Will Be Disrupted by SDN?
.Now lets look at Layer 4-7 (e.g. security, load balancing, application delivery
control, deep packet inspection etc.). What I find interesting here is several of the
SDN private company fund raising in the past several months were for companies
attacking this segment of the networking value chain. Several industry people I speak
to suggest that Layer 4-7 will actually be the first area of SDN deployment in data
centers given the need to provision and manage policies/applications/security at
scale in the data center, which proves to be difficult when managing multiple single
purpose appliances and that managing this in the application layer within the SDN
model potentially provides a more flexible, elegant and scalable solution..
5. 2013 OpenFlow Korea All Rights Reserved
覲伎 Open Source / 譴 螻
FortNOX: 覦 蠍磯 SE-FloodLight (Security Extended version of BigSwitch)襦
狩 蠍磯レ 譴觜 譴
螻糾鴬 螳讌 (蠍一ヾ 殊 蠍一 螳)
Authentication (蟯襴 語)
れ豺 Flow 豌襴 焔 螻
レ Launching 譴螻 語 螻
FRESCO: ろ襦 貊碁, ろ襦 襴貅伎 螻豸 伎 觜襯 覲伎
伎 螳讌 覈, 蠏碁Μ螻 企れ 蟲燕 覲伎 觜るゼ 螻殊
OpenFlow 襴貅伎 .
Resonance: NOX OpenFlow襯 NAC(Network Access Control)
襴貅伎 (Georgia Tech University)
Security Requirements in the Software Defined Networking Model : IETF
譴 襦貊企, ろ襦一 螳 SDN 貊碁,煙企 襴貅伎
伎 豢螳 蠍磯レ 襦
Cloud Management Platform (CMP) 螻
OpenStack Quantum (殊壱企 覲伎 煙 蠍磯 螻)
Stateful Firewall 蠍壱 覲伎 蠍磯
LBaaS (Load Balancing as a Service)
9. 2013 OpenFlow Korea All Rights Reserved
Qosmos/Insieme Networks: L4-7 覲伎
Data
Plane
Traffic
L4-7
襦貊 &
襴貅伎
蠍壱
P2P
e覃
觜
觜 豕
覿 : NBAD, DLP, TMS, NG Firewall
QoS/QoE
VoLTE
貉豸 磯 : SDN 貊碁, 磯
IM
10. 2013 OpenFlow Korea All Rights Reserved
vArmour: SDSec (Software Defined Security)
SDN
Controller
Stealthy SDN security play : (Total US$8M)襯 覦 螳覦 譴 SDSec
蠍一 螳: ASG(Application Security Gateway)螳 螳朱 覯 襦蠏(Rogue)
襴貅伎 螳讌覃 SDN 貊碁,襦 碁ゼ 覲企 貊碁,螳 ろ襦
れ豺 伎 (Forwarding Plane) 覲蟆渚 螳朱 覯襯 蟆襴
豺襭 れ れ 伎 覲糾 .
12. 2013 OpenFlow Korea All Rights Reserved
覲伎 觜讀 覈(): リ鍵 螻 覦覯
Orchestration Plane
Control Plane
SDN/MAC Learning
Data Plane
Underlying Network
VM
Tenant
1
vNIC
VM
Tenant
2
vNIC
VM
Tenant
1
vNIC
覓朱Μ れ豺螳 れ豺
危朱伎
螳 れ豺
危朱伎
NAT
覦覯
VPN
IP ろ語
Encapsulation: VLAN/GRE/VXLAN/NVFRE/STT.
VM
Tenant
2
NIC
Quantum
Operation
&
Monitoring
Plane
sFlow
Ganglia
Puppet
13. 2013 OpenFlow Korea All Rights Reserved
Quantum API
Clients
Cloud Management Platform
(CMP) 螻れ
覲旧 Tenant 螳讌: 覦覯曙
Tenant 覲襦 蟲覿 碁曙
蟆襴 覦覯 豈 ろ
OpenFlow vSwitch: 磯
覦覯 蠍磯 螻
Quantum Firewall: 螳 Tenant
Firewall agent Linux Firewall Box
Quantum 焔: OpenStack
Quantum 譴
伎 企轟: Cloud 觜 伎
蟆渚 覿譟 覦 覲伎 企轟
覿覿 覲 譟一
觜讀 蟆: 蟲襷 企 螻 襷
企轟 蠍一 危 螳
CMP 蟆曙 螳 覃,
企ゼ 螻ろ 觜讀 覈 螳
Orchestration Plane
Control Plane
SDN/MAC Learning
Data Plane
Underlying Network
VM
Tenant
1
vNIC
VM
Tenant
2
vNIC
VM
Tenant
1
vNIC
覓朱Μ れ豺螳 れ豺
危朱伎
螳 れ豺
危朱伎
NAT
覦覯
VPN
IP ろ語
Encapsulation: VLAN/GRE/VXLAN/NVFRE/STT.
VM
Tenant
2
NIC
Quantum
覲伎 觜讀 覈(): リ鍵 螻 覦覯
14. 2013 OpenFlow Korea All Rights Reserved
OpenFlow Area
Drop Actions
OpenFlow pSwitch
Data Center
3. Drop or QoS Action
2. Security Event
1. IDS/IPS Snort Suricata
OpenFlow/SDN Controller
14
覲伎 觜讀 覈(): IDS/IPS
螻れ
OpenFlow 磯 IDS 殊 :
谿/ 豺 OpenFlow
vSwitch/pSwitch
FortNOX SE-FloodLight
螳
レ: 覲旧 SDN
貊碁, 郁屋 螻
譴蟯襴
螳
覲旧 Tenant 螳讌 (IDSaaS)
CMP(Quantum) 螻
Embedded SDN 蟆 螻
OpenFlow based vSwitch
MAC
Srce.
MAC
Dest.
Srce.
IP
Dest.
IP
Source
TCP Port
Dest. TCP
Port
Action
* * 192.168.10.20 * * * Drop
15. 2013 OpenFlow Korea All Rights Reserved
覲伎 觜讀 覈(): TMS
MAC
Srce.
MAC
Dest.
Srce.
IP
Dest.
IP
Source
TCP Port
Dest. TCP
Port
Action
* * * 192.168.10.20 80 * Port 3
螻れ
DDoS 螻糾鴬 谿 TMS
(Treat Management
System)
覿 DDoS 讌
殊れ 蟯襴
蟆危語 碁
觜 ろ SDN
貊碁, 磯
譴蟯襴
SDN 貊碁, (螳讌
Target IP 譯殊 碁
TMS 壱 覈 Flow)
FortNOX SE-
FloodLight 螳
螳
覲旧 Tenant 螳讌
CMP(Quantum) 螻
pSwitch/vSwitch pSwitch/vSwitch
OpenFlow/SDN Controller
TMS
3. DDoS 螻糾鴬 Target Host IP 譯殊 碁曙 TMS襦 襦 覲蟆
Target Host
1. DDoS 殊 蟆危語伎
螻糾鴬 螳讌 Target Host IP 譯殊襯
SDN 貊碁,襦
2. DDoS 螻糾鴬 磯 碁曙
16. 2013 OpenFlow Korea All Rights Reserved
譴 螻
覲伎 觜讀 覈() : SP
Core
Metro
MetroData Center
Hybrid SDN
Overlaid SDN
Embedded SDN
Access
Slice Service
覲伎 觜
Multi-Tenant
SDN Agent
SDN Agent
SDN Agent
SDN Agent
Slice/DevOps
蟯襴 ろ
螻れ
螳螳 蟆襴
碁 覈
レ
譴蟯襴
覲旧 Tenant 螳讌
覲伎 螳ロ SP Last
Mile OpenFlow れ豺