Private Cloud
Computing
Consolidation, Virilization,
and
Service-Oriented
Infrastructure
Stephen
R. Smoot
Nam
K. Tan
ELSEVIERAMSTERDAM • BOSTON •HEIDELBERG• LONDON
NEWYORK•OXFORD•PARIS•SAN DIEGO
SAN FRANCISCO•SINGAPORE•SYDNEY•TOKYO
MorganKaufmann Isanimprintof Elsevier
Contents
Acknowledgments
xiiiIntroduction xv
Aboutthe Authors xvii
CHAPTER
1 Next-Generation IT Trends 1Layers
of function: the service-oriented infrastructure framework 3Blocks of function: the cloud modules 4
Server module 5
Storage
module 5Fabric module 6
WAN module 6
End-usertypeI—branch office 7
End-user typeII—mobile 8
Cloud
computing
characteristics 8Cloud
computing
taxonomy 9Deployment
models 9Service models 10
Tying
it alltogether
10Summary 11
CHAPTER 2
Next-Generation Data CenterArchitectures
andTechnologies
13The data centerconsolidation and virtualizationmodus
operandi
15Serverconsolidation drivers 16
The Classic Server
Sprawl Syndrome
16Application
silos andstovepiped
data 16Servervirtualization 17
Virtual machines and
hypervisor
18VMware
Networking
Primer 19The CiscoNexus 1000V Switch 22 ESXServer
storage networking
overview 31Storage
virtualization 35Block
aggregation
36Symmetric
andasymmetric
storage virtualization 37Layer
2 evolution 40Virtual
port
channels: the STP makeover 42vPC
design
brief 45Unified data center fabric 51
10-gigabit
Ethernet 52Ethernet reloaded 52
The FCoE solution 57
FCoE data
plane
58FCoE control
plane
62I/O Consolidationwith FCoE 65
Summary
70CHAPTER
3
Next-Generation WAN and ServiceIntegration
73Service
integration
in the datacenter 73Firewall virtualization 75
Server load
balancing
and virtualization 76Infrastructure
segmentation
80Layer
2 andlayer
3segmentations
80The
next-generation enterprise
WAN 85MPLS VPN
prelude
85Multi-VPN service from a service
provider
87MPLS over L2 circuits 88
DM VPN overview 90
DMVPN per VRF 93
MPLS VPN overDMVPN
(hub
andspoke only)
94Summary
97CHAPTER 4
Branch Consolidation and WANOptimization
99What is the WAN
performance challenge?
100 Firstchallenge:
limited bandwidth 100 Secondchallenge:
high
latency
in WAN connections 100Solution: WAN
optimization
103WAN
optimization
benefits 104Bandwidth
savings
through compression
anddeduplication
104Speeding
up theapplication layer
106TCP acceleration 112
Requirements
forWANoptimization deployment
114Getting
holdoftraffic 115Identifying
anoptimization
partner 117What does
optimized
traffic looklike? 117Implications
ofoptimized
trafficonmonitoring
andprioritization
122Remote office virtualization
designs
122CHAPTER
5
SessionInterception Design
andDeployment
, 127Selecting
aninterception
mechanism 127Placement decision 128
Operational impact
128Manageability
128The WCCP
deep
dive 128WCCP definitions 129
WCCP control
plane
messages 130WCCP service groups 133
WCCP
interception operation
135WCCP redirection schemes > 136
WCCP
assignment
methods 137WCCPreturnschemes 140
WAN
optimizer
egress methods 140WCCPserver
platform
considerations 142WCCP
design examples
145WCCP
configuration example
153In-path
deployment
in brief 160PBR
deployment
overview 161PBRfailover 163
Summary
165CHAPTER
6 WANOptimization
in the Private Cloud 167WAN
optimization
requirements
in the cloud 168Interception
atthe VM level 168Cloud
interception
with VRF-awareWCCP 169 Cloudinterception
with non-VRF-aware WCCP 176VRF Select 176
TheWCCPv2two-way
connectivity challenge
177The Not-So-VRF solution 179
The Not-So-VRF illustration 180
Interception
at the servicesaggregation layer
189Services chassis
requirements
190Admin context 190
Usercontext 197
ACESM
interception:
bridged
mode 199 ACESMinterception:
routed mode 209 Healthmonitoring
withprobes
211WAN
optimizer
farmredundancy
213CHAPTER 7
SAN Extensions and IPStorage
219SAN extension overview 220
Data recoverymetrics 222
Preliminary design
considerations 222Optical networking
solutions 229Dark fiber 229 DWDM 230 CWDM 234
SONET/SDH
services 236SONET/SDH
topologies
237 FCIP 238 FCIPprimer
239 FCIPtopologies
242 FCIP HA 243FCIP
performance
tuning
245FCIP
security
254iSCSI 254
iSCSI
protocol
overview 255iSCSI
deployments
261iSCSIHA 263
iSCSI
security
263Putting
it alltogether
265Summary
266CHAPTER 8
Cloud Infrastructure as a Service 267Cloud
security
267Virtual switch
security
270Endpoint security
277Virtual DMZ 277
Unified
computing system
278UCS
Enabling Technologies
279UCScomponents 281 Cloud management 285 Hierarchical
management
285Policy-based
management 286Management
mediation 287 Automation 288 User self-service 288 XML-ization 289 Cloud IaaS: thebig
picture
289Virtual machinesubmodule 291
Virtual
access-layer
submodule 292Compute
submodule 292Storage
array submodule 293SAN submodule 293 SAN extensionsubmodule 293
Access-layer
submodule 293Aggregation-layer
submodule 294Core-layer
submodule 294Peering
submodule 294Next-generation
WAN submodule 295Cloud infrastructure management
platform
295End-user workloads and
applications
296ThecloudIaaS
overlay
296Summary
• 297CHAPTER 9
Case Studies 299Virtual
access-layer
design
study
299Nexus 1000V components 300
Design examples
301ERSPAN
design
study 307ERSPANsource interfaces 307
ERSPAN
design example
307ERSPAN basic
configurations
309Deployment guidelines
andrestrictions 309WAN
optimization
study 310Unified fabric
design
study
311FCoE
access-layer
design
311Top-of-rack
architecturedesign
study
319ToR
design
with Nexus 5000 and 2000 320ToR
design example:
lGE-attached servers 321FEX basic
configurations
324BasicvPC
design
study
329Basic vPC
configurations
330SAN extension
design
study
339Simple
FCIPdesign
example
339Service-oriented infrastructure
design study
353Virtual
access-layer high-level design
354Compute
submodulehigh-level design
355Storage
modulehigh-level design
358Services
aggregation layer high-level design
363 WAN modulehigh-level design
366Design
comments 368Summary
369Appendix
AAcronyms
and Abbreviations 371References 381