云数据中心网络虚拟化全自动快速部署课件.pptx
- 【下载声明】
1. 本站全部试题类文档,若标题没写含答案,则无答案;标题注明含答案的文档,主观题也可能无答案。请谨慎下单,一旦售出,不予退换。
2. 本站全部PPT文档均不含视频和音频,PPT中出现的音频或视频标识(或文字)仅表示流程,实际无音频或视频文件。请谨慎下单,一旦售出,不予退换。
3. 本页资料《云数据中心网络虚拟化全自动快速部署课件.pptx》由用户(三亚风情)主动上传,其收益全归该用户。163文库仅提供信息存储空间,仅对该用户上传内容的表现方式做保护处理,对上传内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!
4. 请根据预览情况,自愿下载本文。本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
5. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007及以上版本和PDF阅读器,压缩文件请下载最新的WinRAR软件解压。
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 数据中心 网络 虚拟 全自动 快速 部署 课件
- 资源描述:
-
1、如何实现云数据中心虚拟网络全自动化快速部署如何实现云数据中心虚拟网络全自动化快速部署11大趋势与如何面对当前挑战2NSX网络虚拟化全自动部署架构3NSX网络虚拟化模版设计4混合云的NSX自动化部署5总结6有奖问答Agenda2各行业都在进行数字化转型中各行业都在进行数字化转型中Digital Transformation3IT仍然滞后业务转型仍然滞后业务转型The business wants their applications now!物理网络设计复杂物理网络设计复杂手动配置手动配置 投入大于产出投入大于产出slowrestrictiveriskyinconsistent大量的即刻应用需求
2、传统的应用部署周期长4传统的应用部署周期传统的应用部署周期长长Spin upVMConfigVLANConfigLBConfigRoutingCreateSecurityPoliciesTimeminsTime days/weeksServerSwitchingRoutingSecurityLoad Bal.Manual Tasks/Multiple Teams Can we automate and orchestrate?Can we maintain the same services-LB,Security?How about application mobility?What abo
3、ut Self Service IT?Multi Tenancy scale-security?5软件定义是云数据中心的必由之路软件定义是云数据中心的必由之路高效高效安全安全基于客户业务及应用需求快速部署安全而高效的云平台软件定义数据中心软件定义数据中心快速快速网络虚拟化网络虚拟化是关键基石是关键基石6Logical SwitchLogical RouterNSXLogical FirewallLogical Load BalancerNSX网络与安全一体化全自动部署网络与安全一体化全自动部署 Dynamic Configuration and Deployment of NSX Logica
4、l ServicesOn Demand Application DeliveryvRealize AutomationResource ReservationBlueprintService CatalogCloud Management PlatformNetwork ProfilesSecurity PoliciesSecurity GroupsWebAppDatabaseVMVMVMVMVMVMNSX网络与安全配置全自动化流程网络与安全配置全自动化流程1.NSX网络虚拟化配置:Initial network configuration in NSXExternal Networks an
5、d Network Profiles in vRA2.NSX安全策略配置:Distributed Firewall RulesSecurity Groups/Policies/Tags3.云架构蓝图设计:Blueprints include NSX Networks,Security components,Load Balancers,VMs,Apps and Cost Profile4.发布蓝图设计5.用户一键式部署:End-to-end provisioning:networks,NAT rules,security and LB configured at deployment网路管理员
6、网路管理员安全管理员安全管理员云架构师云架构师消费者消费者Network ProfilesExternal NetworksSecurity GroupsSecurity PoliciesSecurity TagsConvergedBlueprintsNSX Load Balancer12Service CatalogPublish345DefinesDefinesBuildsDeploys6NApplicationsOne TimeRecurring8网络虚拟化与安全策略一体化蓝图设计网络虚拟化与安全策略一体化蓝图设计Automated connectivity to existing or
7、 on-demand networksAutomated security policy enforcement thru NSX security policies,groups and tagsOn-demand dedicated NSX load balancer Parent component only,not application-levelNSX Integration for Blueprint Authoring&Deployment可视化模版设计,鼠标拖放功能9Multi-Tier App,Multiple NetworksMulti-Tier App,Single F
8、lat Network多层应用网络拓扑结构多层应用网络拓扑结构WebAppDatabaseVMVMVMVMVMVMVMVMVMVMVMVM10Dynamic Routing(OSPF,BGP)with ECMP自动部署模式自动部署模式预先部署预先部署ExternalNetworks2 Tiers of RoutingDistributed Logical Router for Application RouterNSX Edge for Provider RouterDynamic RoutingUse existing LS as external network profilesOne A
9、rm Load Balancing on demandProd-01Logical Switch Dev-01Logical Switch LB LB LBTransit Uplink 192.168.10.0/24(External Network Profile)Scale Out Provider Logical RouterApp 1 VMsApp 2 VMsApp 3 VMsPre-Created model is typically used with Production or more static workloads and the application topology
10、is multi-tier on a single networkProd Web SG AProd App SG AProd DB SG ADev Web SG ADev App SG ADev DB SG ADev Web SG BDev AppSG BDev DB SG BDistributed Logical RouterProd Web SG BProdApp SG BProd DB SG BApp 4 VMs LB172.16.50.0/24(External Network)172.16.60.0/24(External Network)Dynamic Routing(OSPF,
11、BGP)with ECMPProvider LogicalRouterExternalNetworks2 Tiers of RoutingDistributed Logical Router for Application RouterNSX Edge for Provider RouterDynamic Routing externallyDynamic Routing(DLR),NAT internally(Edge)Dynamic Routing(OSPF,BGP)Transit Uplink 192.168.10.0/24(External Network Profile)On Dem
12、and Model is typically used for more dynamic Test/Dev style workloads,particularly when there is a requirement for overlapping IP addressesDynamic Routing(OSPF,BGP)Web Logical Switch(Routed)DB Logical Switch(Routed)App 1RoutedApp LS(Routed)172.16.10.0/29172.16.10.8/29172.16.10.16/29Web Logical Switc
13、h(NAT)App LS(NAT)DB LS(NAT)App 2NAT172.16.100.0/24172.16.101.0/24172.16.102.0/24Web Logical Switch(NAT)App LS(NAT)DB LS(NAT)App 3NAT172.16.100.0/24172.16.101.0/24172.16.102.0/24Distributed Logical Router自动部署模式自动部署模式按需按需部署部署安全策略自动化部署安全策略自动化部署End-Users and Cloud Admins are able to select pre-defined s
14、ecurity policies already approved by the Security Admin in NSXSecurity policies are applied to one or more security groups where workloads are membersThese security groups are created on-demand by vRA at deployment timeUsers can also select pre-definedsecurity groups both ah Reservationand at bluepr
15、int levelsWHAT you want to protectHOW you want to protect itSECURITY GROUPSECURITY POLICYMembers(VM,vNIC)and Context(user identity,security posture)“Standard Web”Firewall allow inbound HTTP/S,allow outbound ANY IPS prevent DOS attacks,enforce acceptable use Services(Firewall,antivirus,IPS etc.)and P
展开阅读全文