5g/클라우드시대 데이터센터 · 2019-10-31 · wan interconnect policy / security zones l2...

31
© 2019 Nokia 1 5G/클라우드 시대 데이터센터 Enterprise Digital Transformation powered by Nokia 2019/09

Upload: others

Post on 24-Jun-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia11

5G/클라우드시대데이터센터Enterprise Digital Transformationpowered by Nokia

2019/09

Page 2: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia2

도시화에따른기반시설변화

기업및공공부문의효율증대

메가트렌드, 도전과제및기회들

디지털트랜스포메이션 = 4차산업혁명의모퉁잇돌모바일무선통신기술과 IoT는최근까지사람들의일상에변화를가져온것처럼앞으로는각산업군들과공공부문의진보를이루어갈핵심동인들이다.

공급망및수요의글로벌화

천연자원관리

0110

특정산업군은대규모의트랜스포메이션효과의잠재력보유

에너지 운송 제조 소매스포츠/엔터테인먼트

도시

최근의메가트렌드를포용

Page 3: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia3

Artificial

Intelligence5G 유즈케이스

Enterprise NFV

적용

인간 & 기계

상호

Edge Computing은새로운

서비스적용을가속화

하이퍼스케일클라우드로확장

큰변화의흐름은연결환경의변화

IoT

PeopleDevices }

Things

Page 4: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia4

Connected Plane

5 TB Per day

Smart Car

1 TB Per day

Intelligent Building

275 GB per day

Smart Hospital

3 TB per day

Public Safety

50 PB per day

Smart Grid

5GB per day

Weather sensors

10 MB per day

Connected Factory

3 PB per day

2020 – 사용자당하루트래픽 1.5GB

발생된트래픽중

10%만이유용

Source,: GE, Cisco

Page 5: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

5

Bell Labs Future-X

Page 6: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

6 © Nokia 2018

Nokia Bell Labs & Future-X Networks

Page 7: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2016 Nokia7

High level architecture: The Future X Network

Future X network: converged + cognitive + cloud-optimized network (r)evolution

longfibers

shortwaves & wires

ProgrammableNetwork OS

UniversalAdaptive Core

Humans& Machines

multi-operatorfederation

access agnosticconverged core

modular, decomposednetwork functions

MassiveScale Access

AccessRemote

mass edgemonitoring

new trustframework

ecosystemsharing

4

5

8

1

2

commondata layer

self-optimizedcoverage

& capacity

dynamicnetwork optimization

dynamiccustomer

servicesSDN NFV

Management &Orchestration

Dynamic Data Security

Smart Network Fabric3

machine

learning

analyticsAugmented

Cognition Systems

Externaldata sources Digital Value

Platforms Vertical apps

ConvergedEdge Cloud

7

6Open APIs

Page 8: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2018 Nokia8

Future-X 전략 for Enterprises

1.

2.

3.

단순화(Simplify)

Infrastructure

Business / Network Operation

클라우드화(Cloudify)

지능화(Smart)

Page 9: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2018 Nokia9

ConvergedEdge Cloud

Software-defined, end-to-end

Self-optimizedcoverage & capacity

Massive-ScaleAccess

Long fibers

AccessRemote

Shortwaves & wires

Humans& Machines

Smart NetworkFabric

5G Future X

Universal Adaptive Core

Programmable Network OS

Digital Value Platforms

Augmented Cognition Systems

향후 5년네트워크비젼

Robust Flexible Scalable Simplified Programmable

Intelligent “Zero Touch” Network – with 10 X factor

Automation

Open Architecture

Artificial Intelligence

Machine Learning

Real-time Analytics

Enablers

10x Lesser

Operating Cost

10x Simpler

Function Sales

10x Faster

design & delivery

10x Lesser

Complexity

10x Shorter E2E

Cycle Time

10x Better User

Experience

10x More use

cases enabled

Cloud-Native

5G Architecture

Network Slices

DevOps

Edge cloud for MEC

Page 10: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

10

5G to Enterprises ?

Page 11: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2018 Nokia11

Nokia market view5G 마켓은익스트림모바일브로드밴드로부터시작할것

Massivemachine

communication

ExtremeMobile

Broadband

Critical machine

communication

M2M/MTC 5G markets to start to develop 2022+• Early competition: NB-IoT/LTE-M

• MTC IoT needs coverage layer, and large volumes of low cost devices

• Verticals not expected to be early adopters for 5G (low expertise)

• Earlier trials to test technology and define business models

20202018 2019 2021

>6GHz

3-6 GHz• Megacity capacity densification

• 3 to 6GHz ~100MHz BW / <1GHz ~20MHz BW

• Dense urban grid

High capacity and coverageHigh capacity and coverage

Ultra high capacity

5G Fixed Wireless Access

Extreme mobile broadband market starts E2E solutions for all three markets

5G Fixed Wireless Access

• Extension of fiber access

• cm/mmWave

• Line of Sight (LOS)

• Ultra dense use cases

• cm/mmWave

• Short range

Ultra high capacity

Page 12: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

12 © Nokia 2019 | [email protected] | MN | CloudRAN Nokia Internal Use

What’s different?

Ba

nd

wid

thLatency

10kbps

1Mbps

100Mbps

10Gbps 360 Video VR+VRAN+Vehicles

People & Things System Control

1ms10ms100ms1s10s 100us

Expanding scope of business-critical applicationsTo unlock it, we must become adept at controlling the physical with digital means: go beyond physical-to-digital transformation

Page 13: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia13

클라우드는분산구조및모든사물에최적화되는형태로변화될것

현재구성… 향후클라우드구성….

10Mbps

100ms

10B

$1000

Months

10Gbps

1ms

100B+

$1

Days

People

Devices

People

Devices

Things

Page 14: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia14

어플리케이션은엣지방향의네트워크로변화될것

Edge CloudCore Cloud

Ba

nd

wid

thLatency

10kbps

1Mbps

100Mbps

10Gbps

1ms10ms100ms1s10s 100us

Video

Things

VR/AR

SystemControl

latency

GB/user/Mo

2025

887

3,360

5,903

2020

360

4K Moderate VR Ubiquitous VR

Global-local alliance/Convergence

Local delivery with global reach• Telco and IT datacenter

• Fixed – Mobile service

• RAN Cloudification & Evolution to 5G

• Local service performance, efficiency and customization

Central Cloud

Edge Cloud

Edge Cloud

Edge Cloud

예상할수없는데이터성장에만족

고객경험향상Better

healthcare

New

tooling

VR/AR

Higher productivityImproved safety

IoT

초기 5G 유즈케이즈

Drones

High Bandwidth

Page 15: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia15

Public/Private Cloud and open ecosystem for innovation moving to Edge

Fixed Access Network Transformation

END USER METRO/CORE

Data CenterDistribute

Small nodes

Virtualize

CentralizeCO

Scale

Latency

Consolidate

FIXED ACCESS

COCOCOCO

Edge Cloud

CO

DistributedEdge Data Centers

SDN

NFV

Cloud computingLatency, bandwidth, and security critical use cases (IoT, MEC)

B2B

B2C

Local content Local data routing Local data processing

Local network functions

Live VR with 4K video and

full stereo audio

Interactive AR-based

wayfinding

Local (temporary) eMBMS

for high density locations

100X faster delivery of

real time video

80-90% elimination of

upstream IoT data

Assured end-to-end

latency <<20ms

Full survivability based on

local EPC components

8X acceleration of cloud-

based enterprise appl’s

신규비지니스기회는엣지방향의네트워크로변화될것Starting points to incrementally realize the target over time

RAN Cloudification & Evolution to 5G

Massivemachine

communication

ExtremeMobile

Broadband

Critical machine

communication

Virtualized & distributed IP Edge

EPC 5GCNBNG VAS

Page 16: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2018 Nokia16

Network Services on-demand

Smart factories

Transport

Cameras at public site

V2X Connectivity-Automated Driving

HD maps

Infotainment

Public Safety-Video Surveillance

Emergency Team

eSports

Health

Cloud Gaming

신규비지니스기회는엣지방향의네트워크로변화될것

Page 17: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

17<Change information classification in footer>

Enterprise SDDC SDN

Page 18: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

18 © Nokia 2019

Pre-integrated Data Center

Modular Data Center

Containerized Data Center

Data Center Solution AirFrame Hardware

Rackmount and Open Compute Platform (OCP) Data Center HW Manager

Nuage Networks

SW Defined Networking Data Center Fabric

Cloud Core Solutions

VoX Solution SDM SolutionE2E Core Solution

Central Data Center

Edge Data Center

Security

NF

V-O

VN

F-M

Services

Data Center Services

Transformation consulting

Design & build

Operate & maintain

Infrastructure SW

MANO

Network Security

EndpointSecurity

Cloud Security

Security Management

NetGuard

CBAM & CBND

노키아 End-to-End 클라우드코어솔루션

Page 19: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

19 © Nokia 2019 네트워크프로세스로인한서비스제공속도저하

Compute is Virtualized

Available in Minutes

NetworkConfiguration

Compute Management

신규테넌트 / 어플리케이션요청

Auto-instantiation

Compute Request

completed in

Minutes

Help Desk

Change Control

Project

Coordinator

IP

Address

VLAN

Address

Firewall

Configuration

LAN (VLAN)

Configuration

WAN (IP)

Configuration

Security / QA

Team

00:01

WAN

L2 Networking- VLAN separation- xSTP or MC-LAG- Vendor specific L2

enhancements

Network Change

completed in

days/Weeks

현재데이터센터네트워크 (without SDN)The BIG Challenge

Page 20: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

20 © Nokia 2019

Compute Management

신규테넌트 / 어플리케이션요청Networking

Security/

Compliance

네트워크프로세스로인한서비스제공속도저하없음

Auto-instantiation

Compute Request

completed in Minutes

00:01

IP address

WAN interconnect

Policy / Security Zones

L2 /L3 Service AD

Service chaining

Templates

Nuage Networks VSP

Policy Instantiation• IP address 10.x.y.z• VLAN configuration• WAN configuration• Security / FW

settings• QoS parameters• …

Network Change

Completed automatically

00:01

자동화된클라우드네트워크The RIGHT SDN

Page 21: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

21 © Nokia 2019

Nuage Networks Virtualized Services Platform

BMS – Multi VTEP support

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

VM- Multi-Hypervisor Support

Hybrid-connectivityContainers- Openshift, Kubernetes, Mesos

Virtualized Services Directory (VSD)

VSP: Unified Multi-tenanted Policy and Control

Virtualized Services Controller (VSC)

Security AnalyticsVSAP Assurance

VCS: Virtualized Cloud Services

SD-WAN

VNS: Virtualized Network Services

Site A

Site B

Site C

VPN

PNF- WAN

Physical Network

VPN

DC-GW

Private-Public CloudCloud Native

Page 22: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

22 © Nokia 2016

(구성예시) 다양한 IT 환경 지원

컨테이너(VM)

VSD

VSC VSC

VSP (Virtualized Services Platform)

Overlay Network (VxLAN)

Kubernetes vCenter

Bare-Metal Server

Public Cloud

Bare-Metal Server

ESXi ESXi

컨테이너(물리서버)

Nuage 가상스위치

컨테이너(VM)

Kubernetes

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

가상서버물리서버

B C

KVM

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

가상서버

KVM

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

가상서버컨테이너

(VM)

KVM

Kubernetes

A

VM 인스턴스

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

Hypervisor

D

RESTful API 기반Plugin 연동

RESTful API 기반Plugin 연동

Page 23: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

23 © Nokia 2016

(아키텍처) Nuage VSP 플랫폼 아키텍처

물리서버가상서버 컨테이너

SDDC#1

VSD

VSC VSC VSCVSC VSC

VSP (Virtualized Services Platform)

1

2 3 4

가상스위치 HW VTEP

Underlay Network

Overlay Network (VxLAN)

LB IPAM 방화벽

SDDC 오케스트레이터

RESTful API

Openflow / OVSDB

MP-BGP

단일오케스트레이션플랫폼A

✓ 모든 SDDC 네트워킹에대한

통합웹 GUI 제공

✓ N/W, 보안템플릿기반일관된

정책적용지원

✓ RESTful API 기반 NBI 제공

검증된아키텍처안정성B

✓ SP용라우터망에서검증된

SR-OS 라우팅엔진기반

✓ 삼중화 VSD, 이중화 VSC 기반

안정적 VSP 아키텍처

✓ 검증된표준기반연동

네트워크기능연계기반D

✓ 트래픽포워딩기반 LB, 방화벽

등연동플랫폼역할

✓ 검증된 3rd-party 상용 LB, 방화벽,

IPAM 제품제공

✓ 표준기반서비스체이닝연동

B C

D

하이퍼스케일지원확장성C

✓ 제어평면엔진 VSC의 MP-BGP

기반Scale-out 지원

✓ 물리서버 10,000 대, 16,000

VPC(*)까지 단일 VSD에서지원

✓ 대규모상용레퍼런스검증

(*) VPC: Virtual Private Cloud의 악어

통합 GUIA

SDDC#2

4 지점

Public Cloud

Page 24: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

24 © Nokia 2016

(클라우드/가상화 보안) Nuage VSS 아키텍처

물리서버가상서버 컨테이너

SDDC#1

SDDC#2

VSD + VSS

VSC VSC

VSP (Virtualized Services Platform)

1

2 3 3 4 지점

Public Cloud

가상스위치 HW VTEP

Underlay Network

Overlay Network (VxLAN)

LB IPAM 방화벽

E2E 네트워크제어및마이크로세그멘테이션A

✓ VM, 컨테이너, 물리서버, 클라우드 VM, 지점포트등

E2E 전체네트워크에대한개별제어

✓ 개별 VM/컨테이너/포트단위마이크로세그멘테이션

실시간보안관제및어플리케이션 가시성확보B

✓ ACL Hit/Deny, 트래픽 TCA 기반보안관제및자동

조치연동

✓ Flow 정보수집을통한어플리케이션가시성확보

보안방어조치자동수행 및연동C

✓ 네트워크정책제어, 동적서비스체이닝구성, 트래픽

미러링, VM 차단등의방어조치자동수행

✓ VM/컨테이너/포트태깅기반개별보안조치적용및

트래픽처리지원

✓ SIEM, DDoS 차단센터등연동지원

A

B

C

SIEM,

DDoS 차단센터

Page 25: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

25 © Nokia 2016

(DC 외부 확장) SD-WAN 아키텍처

SDDC#1

SDDC#2

VSD

VSC VSC

VSP (Virtualized Services Platform)

1

4

지점/협력사

Public Cloud

가상스위치 HW VTEP

Underlay Network

Overlay Network (VxLAN)

LB IPAM 방화벽

DC 및지점 SDN 통합오케스트레이션A

✓ DC 네트워크와지점간의 SDN을단일 VSD에서

네트워크및보안정책일원화

✓ DC 및지점간네트워크의멀티테넌트지원

올인원지점장비B

✓ 라우터, 방화벽, IP QoS 및 WAN 가속기능까지

내장된지점용 CPE 장비

✓ 모든기능들에대한단일정책기반중앙집중식운영

지점환경별최적의 WAN 링크구성C

✓ MPLS, 인터넷, 3G/LTE 등의다양한 WAN 링크들의

조합으로물리적연결구성가능

✓ 회선비용최소화, 장애대비이중화및이동성지원

✓ 어플리케이션별 QoS 정책기반처리로다중링크

활용효율극대화및어플리케이션품질보장

MPLS

인터넷

3G/LTECPE

CPE

B

라우터 방화벽 IP QoSWAN

가속(*)

C

A

Page 26: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

26<Change information classification in footer>

Distributed Data Centers

Page 27: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2018 Nokia27

Edge cloud is an integral part of the FutureX Network

ConvergedEdge Cloud

Universal Adaptive Core

Programmable Network OS

MassiveScale Access

Digital Value Platforms

ANP, CSP, ICP, Vertical apps

Augmented Cognition Systems

Machine learningAnalytics

Emerging Devices & Sensors

Dynamic Data Security

Smart Network Fabric

Access agnosticconverged core

modular, decomposednetwork functions

Common data layer

Dynamiccustomerservices

Dynamicnetwork optimization

Management &Orchestration

SDN NFV

Multi-operatorfederation

New 5G applications (AR/VR, IoT, industrial automation)

Edge cloud AI/MLAdaptive slice operations

Zero-touch network & service automation

Wireless/wireline convergence

5G Cloud RANSD-PON

High scale adaptive edge security

Seamless network/cloud IP/optical fabric

Page 28: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2018 Nokia28

CentralRegionalAggregated edge Far edge

Central data centersEdge data centers

레이어드아키텍쳐로 Latency와 Cost 관리

Sites 100-1000’s 10-100’s Few ~3

Footprint Smallest Small Large Large

Power budget Low Medium High HighRackmount or OCP

Rackmount or OCP

Rackmount or OCP

Signaling drivenLowest latency / high throughput

AirFrame Open Edge Server

Page 29: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia29

Distributed Data Centers VisionDistributed Data Centers – High Level Architecture (Network & DC Views)

Access: Enterprise / Residential / Mobile

Multiservice Backbone / Underlay

…Edge DCTier3

Edge DCTier3

Edge DCTier3

SDN Overlay

Central DCTier 4/3

Central DCTier 4/3

Internet

GlobalOrchestration

SDN Management

Unified Cloud Management

Global Network Functions

PublicClouds

3rd PtyPrivateClouds

Network View Data Center View

Central/Edge DCL2/L3/SDN

IBBSDN-C

VNFM

Infrastructure BB

VNF VNF VNF…

CloudInfra/VIM

Hardware

SDNOverlay

Underlay

Page 30: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation

© 2019 Nokia30

MICROSEGMENTATION for ANY end point, VMs, CONTAINERS

PaaS

L4 Stateful FW

Visibility Reports

Physical &Bare Metals

Nuage VSG

Page 31: 5G/클라우드시대 데이터센터 · 2019-10-31 · WAN interconnect Policy / Security Zones L2 /L3 Service AD Service chaining Templates Nuage Networks VSP Policy Instantiation