当前位置:网站首页>LAN SDN technology hard core insider 13 II from LAN to Internet
LAN SDN technology hard core insider 13 II from LAN to Internet
2022-07-23 07:14:00 【User 8289326】
Mentioned earlier , Inside the data center , Through hierarchical port binding and EVPN, Cloud platform can teach virtual machines to be encapsulated by hardware switches VXLAN, Realize the interconnection of the same network segment and different network segments .
however , Whether it's a server , Or virtual machines , Ultimately, it is necessary to provide services outside the data center . Let's review the picture we saw at the beginning ——
In the picture , Every VPC Need to pass through vLB Provide external load balancing , adopt vFW Control the mutual access strategy of internal and external networks . about Neutron For native implementations ,vFW Use Linux Of iptables,vLB Using open source nginx or haproxy. just as OVS Forwarding efficiency of is affected by x86 The limitations of the architecture are the same ,iptables,nginx and haproxy Throughput 、 New connection rate and other key indicators , It is also easy to become a bottleneck in large-scale deployment .
On a large scale VPC In the scene of , Dedicated hardware firewall and LB The advantages of the equipment are reflected . generally speaking , They are dedicated FPGA, Or multi-core processor with network and security acceleration hardware , The maximum throughput of a single device can reach 2TB above , Support 2 More than 100 million concurrent connections .
So how to use dedicated hardware firewall and LB equipment , Instead of Neutron Born in the Central Plains vFW and vLB, Realization VPC Providing services to others ?
Neutron In order to use other software and hardware firewalls and LB equipment , Provides FWaaS and LBaaS These two characteristics . They are Firewall-as-a-Service and LoadBalance-as-a-Service Abbreviation , That is, the firewall and LB Features are provided to tenants in the form of services (VPC).
FWaaS Is in Neutron Of Router Implemented in , Default driver by iptables. Firewall manufacturers will this driver Replace it with its own plug-in , You can use hardware firewall as Neutron Provide FWaaS Yes .
Similarly ,LBaaS It can also be realized through hardware devices .
There's a problem :
We know , In the cloud platform , There may be multiple tenants , Theoretically, every tenant needs to call FWaaS and LBaaS Realize firewall and load balancing . that , Obviously, cloud platform investors cannot buy a set of hardware firewall and load balancing equipment for each tenant . Is there a way to put a firewall /LB The equipment is used by multiple tenants ?
We call this method device virtualization .
Virtualization can be implemented in two ways , One is called VS(Virtual System), In management , Put a firewall /LB Virtual multiple , various VS You can only see physical resources such as your own network interfaces , And enjoy the throughput bandwidth allocated to itself 、 Performance resources such as concurrent connections . For firewalls /LB The master of CPU The demand is higher , Therefore, the number of virtualization is generally limited .
Another virtualization implementation is called VRF(Virtual Routing & Forwarding). Yes , And router VRF equally . A firewall /LB Logically, it is still a device , Just for each VRF The instance maintains a routing forwarding table , each VRF Instances can use overlapping IP Address . This method can achieve a large number of virtualization , General equipment can support 1K To 4K individual .
With FWaaS and LBaaS drive , It can be realized by hardware VPC Network edge processing , Realize the external release of business from LAN to Internet .
In the following content , We will also have more wonderful presentations , Reveal more SDN Technology insider !
边栏推荐
- What if you need system permission to delete files? You need permission from system to delete the solution
- 如何让屏幕上的字显示更大(让大屏幕看文字更舒服的设置方法)
- Esphone's self-made infrared remote control is connected to ha to control lights, switches, etc. any remote control can be used
- What does DNS mean? What is the function of DNS
- 织梦dedecms忘记管理后台密码找回方法
- FileInputFormat.setInputPaths多路径读取规则
- 局域网SDN技术硬核内幕 - 02 前传 多核技术为摩尔定律续一秒
- 【随笔】再见IE浏览器,一个时代的印记从此消失
- Face algorithms
- 电脑一拖二显示器分辨率怎么调? 两个显示器设置不同分辨率的技巧
猜你喜欢

How to embed the monitoring image into wechat official account for live broadcast

AIRIOT答疑第5期|如何使用低代码业务流引擎?

After the applet wx.setstoragesync, sometimes it can't get data with getstoragesync

OWA动态密码短信认证方案,解决outlook邮件双因子认证问题

小黑啃leetcode:589. N 叉树的前序遍历

Livegbs design document of security camera internet live broadcast scheme

图像处理解决方案 veImageX 技术演进之路

低代码服务商ClickPaaS与毕普科技完成战略合并,共同打造工业数字化底座

【随笔】再见IE浏览器,一个时代的印记从此消失

Shell脚本
随机推荐
Analyse de la stratégie de lecture et d'écriture du cache
百度钱包帮你还信用卡 跨行还款0手续费 实时到帐 新人奖励5元
Is it safe to apply for a stock trading account online?
Stability control and Simulation of double inverted pendulum system (matlab/simulink)
Unable to open the proxy server. What should I do if the proxy server is not set to full access?
What if ICBC online banking assistant cannot be installed? ICBC online banking assistant installation failure solution
DataGrip使用教程(GIF版)
电脑如何快速关机 电脑关机命令分享
动作活体检测能力,构建安全可靠的支付级“刷脸”体验
Flink data source disassembly and analysis (Wikipedia editssource)
无法打开代理服务器提示代理服务器没有设置为完全访问该怎么办?
【高并发基石】多线程、守护线程、线程安全、线程同步、互斥锁
[FAQ] common reasons and solutions for the failure of in app payment services to pull up the payment page
How to quickly shut down the computer shut down command sharing
记事本文件太大打不开怎么办?TXT文件太大无法打开现象的解决办法介绍
微软测双胞胎工具twinsornot怎么玩?测双胞胎工具twinsornot玩法介绍
怎么看电脑是64位还是32位 电脑32位和64位的区别
如何让屏幕上的字显示更大(让大屏幕看文字更舒服的设置方法)
Demo19- (to be updated)
AWS uses EC2 to reduce the training cost of deep Racer practical operation of deep racer for cloud