Example: confidence

Best Practice Network Design for the Data Center

1 best Practice Network Design for the Data CenterMihai Dumitru, CCIE2 # 39 employees, 3 national offices Focus on large enterprise customers from banking and retail, plus education Specializing in: System integration (consulting, project management, Network equipment sale and deployment, maintenance) Managed services (operational support, Network management, server hosting and business continuity) Cisco Gold Partner One triple CCIE, one dual CCIE and Solarwinds Gold PartnerA Few Words about Cronus eBusiness:3 Classical Data Center Network Architecture Impact of new features and products on hierarchical Design for data Center networks Data Center services insertion Layer 3 features and best practices Layer 2 features, enhancements and best practicesWhat We Will Cover In This Session:4 Data Center CoreEnterprise NetworkAggregationAccessLayer 3 LinksLayer 2 TrunksHierarchical Design Network Layers: Data Center CoreRouted l

Node 3 has gone down. I better remove Node 3’s routes from the table immediately… Node 1 Node 2 Node 3 Node 4 X Network “B” Network “A” IGP Hello and Dead/Hold Timers Behavior Over Layer-3 Links Upon device or link failure, routing protocol immediately removes routes from failed peer based on interface down state.

Tags:

  Network, Design, Practices, Best, Best practice network design for the

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Best Practice Network Design for the Data Center

1 1 best Practice Network Design for the Data CenterMihai Dumitru, CCIE2 # 39 employees, 3 national offices Focus on large enterprise customers from banking and retail, plus education Specializing in: System integration (consulting, project management, Network equipment sale and deployment, maintenance) Managed services (operational support, Network management, server hosting and business continuity) Cisco Gold Partner One triple CCIE, one dual CCIE and Solarwinds Gold PartnerA Few Words about Cronus eBusiness:3 Classical Data Center Network Architecture Impact of new features and products on hierarchical Design for data Center networks Data Center services insertion Layer 3 features and best practices Layer 2 features, enhancements and best practicesWhat We Will Cover In This Session:4 Data Center CoreEnterprise NetworkAggregationAccessLayer 3 LinksLayer 2 TrunksHierarchical Design Network Layers.

2 Data Center CoreRouted layer which is distinct from enterprise Network coreProvides scalability to build multiple aggregation blocks Aggregation LayerProvides the boundary between layer-3 routing and layer-2 switchingPoint of connectivity for service devices (firewall, SLB, etc.) Access LayerProvides point of connectivity for servers and shared resourcesTypically layer-2 switchingDefining the Terms5 Data Center CoreEnterprise NetworkMultiple Aggregation Blocks/PodsScaling the Topology With a Dedicated Data Center Core A dedicated Data Center Core provides layer-3insulation from the rest of the Network Switch port density in the DC Core is reserved forscaling additional DC Aggregation blocks or pods Provides single point of DC route summarization6 Data Center CoreAggregationAccessServer PodNetwork EquipmentNetwork RackServer RackMapping Network Topology tothe Physical Design Design the Data

3 Center topology in a consistent, modular fashion for ease of scalability, support, and troubleshooting Use a pod definition to map an aggregation block or other bounded unit of the Network topology to a single pod The server access connectivity model can dictate port count requirements in the aggregation and affect the entire design7 Traditional Data Center ServerAccess Models End-of-Row (EoR)High density chassis switch at end or middle ofa row of racks, fewer overall switchesProvides port scalability and local switching, maycreate cable management challenges Top-of-Rack (ToR)Small fixed or modular switch at the top ofeach rack, more devices to manageSignificantly reduces bulk of cable by keepingconnections local to rack or adjacent rack Integrated SwitchingSwitches integrated directly into blade server chassis enclosureMaintaining feature consistency is critical to Network management.

4 Sometimes pass-through modules are used8 Impact of New Features and Products On Hierarchical Design forData Center Networks9 AggregationAccessVirtual-AccessNexus 2000 Nexus 1000vData Center CoreLayer 3 LinksLayer 2 TrunksVMsBladeSwitch 3100 Building the Access Layer using Virtualized Switching Virtual Access LayerStill a single logical tier oflayer-2 switchingCommon control plane withvirtual hardware and software based I/O modules Cisco Nexus 2000 Switching fabric extender moduleActs as a virtual I/O module supervised by Nexus 5000 Nexus 1000vSoftware-based Virtual Distributed Switch for server virtualization Data and Storage AggregationEthernet Fibre ChannelEthernet plus FCoEMigration to a Unified Fabric at the Access Supporting Data and Storage Nexus 5000 Series switches support integration of both IP dataand Fibre Channel over Ethernet at the Network edge FCoE traffic may be broken out on native Fibre Channel interfaces from the Nexus 5000 to connect to the Storage Area Network (SAN) Servers require Converged Network Adapters (CNAs)

5 To consolidate this communication over one interface, saving on cabling and power11 A cohesive system including a virtualized layer-2 access layer supporting unified fabric with central management and provisioning Optimized for greater flexibility and ease of rapid server deployment in a server virtualization environment From a topology perspective, similar to the Nexus 5000 and 2000 seriesCisco Unified Computing System (UCS)LANU nifiedComputingVirtual AccessSANIP Data AggregationEthernet Fibre ChannelUCS FEX UplinksDual SANF abricsUCS 6100 SeriesFabric InterconnectsUCS 5100 EnclosureUCS B-Series ServersUCS 2100 Fabric ExtendersUCS I/O Adapters12 Nexus 7000 Series Virtual Device Contexts (VDCs) Virtualization of the Nexus 7000 Series ChassisUp to 4 separate virtual switches from a singlephysical chassis with common supervisor module(s)

6 Separate control plane instances andmanagement/CLI for each virtual switchInterfaces only belong to one of the active VDCsin the chassis, external connectivity required topass traffic between VDCs of the same switch Designing with VDCsVDCs serve a role in the topology similar to aphysical switch; core, aggregation, or accessTwo VDCs from the same physical switch shouldnot be used to build a redundant networklayer physical redundancy is more robust 13 CoreAggregation VDCA ccessSub-AggregationVDC6500 Services ChassisEnterprise Network Virtual Device Context Example: Multiple VDCs used to sandwich services between switching layersAllows services to remain transparent (layer-2) with routing provided by VDCsAggregation blocks only communicate through the core layer Design considerations.

7 Access switches requiring services are connected to sub-aggregation VDCA ccess switches not requiring servicesmay be connected to aggregation VDCA llows firewall implementations not toshare interfaces for ingress and egressFacilitates virtualized services byusing multiple VRF instances inthe sub-aggregation VDCS ervices VDC Sandwich14 Data Center Service Insertion15 Data Center CoreAggregationAccessServicesData Center Service Insertion: Appliances directly connectedto the aggregation switchesService device type and Routedor Transparent mode can affectphysical cabling and traffic flows. Transparent modeASA example:Each ASA dependant onone aggregation switchSeparate links for fault toleranceand state traffic either run through aggregation or directlyDual-homed with interface redundancy feature is an optionCurrently no EtherChannelsupported on ASAD irect Services Appliances16 Data Center CoreAggregationAccessServicesData Center Service Insertion.

8 Dual-homed Catalyst 6500 Services do not depend on asingle aggregation switchDirect link between chassis forfault-tolerance traffic, may alternatively trunk these VLANs through Aggregation Dedicated integration pointfor multiple data centerservice devicesProvides slot real estate for6500 services modulesFirewall Services Module (FWSM)Application Control Engine (ACE) ModuleOther services modules, alsobeneficial for appliancesExternal Services Chassis17 Enterprise NetworkVLAN 161 VLANs171,172 VLAN 163 VLAN 170 Web Server FarmVLAN 162 Transparent FWSM Context TransparentACE ContextAggregationVDCS ervicesSub-AggregationVDCA ccessVLAN 180 Data CenterCoreClient-Server FlowUsing Virtualization and Service Insertion to Build Logical Topologies Logical topology exampleusing services VDC sandwich physical modelLayer-2 only services chassis with transparent service contextsVLANs above, below.

9 And between service modules are a single IP subnetSub-aggregation VDC is a layer-3 hop running HSRP providing defaultgateway to server farm subnetsMultiple server farm VLANS can beserved by a single set of VLAN sthrough the services modulesTraffic between server VLANs does not need to transit services device, but may be directed through services using virtualization18FT VLANsEnterprise NetworkVLAN 161 VLAN 163FT VLANWeb/AppServer FarmTransparent FWSM Contexts TransparentACE ContextsVRF InstancesAggregation VDCS ervicesSub-Agg VDCA ccessVLAN 180 Data Center CoreVLAN 153 VLAN 152 VLAN 181FT VLANsFT VLANDB ServerClusterVLAN 151 Client-Server FlowServer to Server FlowVLAN 162 Logical Topology to support multi-tier application traffic flowSame physical VDC serviceschassis sandwich modelAddition of multiple virtual contexts to the transparent services modulesAddition of VRF routing instances within the sub-aggregation VDCS

10 Ervice module contexts and VRFs are linked together by VLANs toform logical traffic pathsExample Web/App server farmand Database server cluster homedto separate VRFs to direct traffic through the servicesUsing Virtualization and Service Insertion to Build Logical Topologies19(VDC max = 4)(ASA max = 50 VCs)(FWSM max = 250)(ACE max = 250 VCs)(VS max = 4)Nexus7000 ASAACEIPS/IDS(ACE 4710 = 20 VCs)Active-Active Solution Virtual Components Nexus 7000 VDCs, VRFs, SVIs ASA 5580 Virtual Contexts ACE Service ModuleVirtual Contexts, Virtual IPs (VIPs) IPS 4270 Virtual Sensors Virtual Access LayerVirtual Switching SystemNexus 1000vVirtual Blade Switching20 Layer 3 Features and best Practices21 Data Center CoreEnterprise NetworkAggregationAccessLayer 3 Layer 2 Layer-3 Feature Configurationin the Data Center Summarize IP routes at the DC Aggregation or Core to advertise fewer destinations to the enterprise core Avoid IGP peering of aggregation switches through the access layer by setting VLAN interfaces as passive Use routing protocol authentication to help prevent unintended peering If using OSPF, set consistent reference bandwidth at 10.


Related search queries