Monday, February 18, 2013

Automate Network Configuration with Puppet for Junos OS

With the exponential growth in the numbers of servers in Enterprise Data Center and the corresponding complexity and confusion that can follow the need for management automation of server resources is well understood by the IT staff. However for every server there are one or more network connections that need to be configured and managed and until recently this was still a manual process.  Juniper Networks has addressed this challenge with the release of Puppet for Junos OS.

Why Resource Automation is Needed
Driven to reduce costs while providing high levels of computing power, enterprises are adopting cloud-based computing models based on large numbers of low-cost processors and virtual machines. This is fueling an exponential increase in the volume and complexity of server and network management. Meanwhile, understaffed IT organizations are tasked with supporting the business, as the organizations they serve are under pressure to move with agility in a competitive business environment.

Saturday, February 16, 2013

Build your Network with the Vertical Campus Implementation Guide

Designing a large campus network can be a daunting task. It is certainly a complex undertaking. It can be especially difficult if you have to configure equipment that you haven’t worked with before. You might find yourself wishing that someone would write a how to guide. At Juniper Network we hear you and that’s why we’ve published another one of our Implementation guides. This one is for the Vertical Campus. It will show you the way to set up Juniper LAN, WLAN, and security devices and help you get up and running in a shorter time, with a tested and proven design.

The Vertical Campus Implementation Guide
The Juniper Networks® Vertical Campus Implementation Guide provides a simple, tested, step-by-step process for rapidly deploying a large campus solution. The design incorporates the most commonly used enterprise network technologies to provide a simple and scalable network architecture that includes LAN, WLAN, and security components. The guide presents a specific configuration of Juniper Networks hardware and software platforms that have been tested and provide a reliable foundation on which to base a customized network for your business.

Sunday, January 27, 2013

Inter Data Center Workload Mobility with VMware

Server virtualization has increasing become implemented in the data center because it enables higher utilization of physical servers increasing their value to the organization. By abstracting the server operating system from the server hardware, virtualization allows physical resources to be shared among many virtual machines. The capabilities of cloning, suspending, and migrating live VMs among a cluster of physical hosts enhances resiliency and performance of applications. Advancements in networking technology allow servers within a single cluster to be located across the entire data center, or in another data center some distance away, further enhancing application availability, but making this technology work isn’t simple.

The Case for Live Migration
There are may use cases put forward for live workload migration and they are covered in the document, and were also covered in my previous blog “Making the Case for Long Distance Virtual Machine Mobility.” These use cases include optimizing server resource utilization, optimizing resource consumption at various locations, hybrid cloud where overflow workloads move to another data center, and disaster avoidance were workloads are moved to saftey, as well as a follow the sun model where workloads move according to the time zone of users. Some scenarios for data center migration for live workloads can be accomplished without implementing complicated first-hop-responder and route-optimization techniques. Other scenarios are possible however, they require implementing protocols that share state and fate, thereby increasing the complexity and reducing the reliability of the connected data centers. As a result of these considerations the network is a critical factor.

Sunday, January 13, 2013

Integrating SRX Security Services with QFabric in the Data Center

The data center is a concentrated deployment environment for networking equipment, consisting of thousands of servers that are accessed by tens of thousands of client systems. The need for large-scale access creates a complex set of data flows to business applications that must be protected. Determining firewall deployment configurations and sizing in a data center is a considerable effort and firewall performance is critical to handle the volume of connections per second, and sustained connections. To address these challenges, Juniper Networks created a new class of security products, the SRX Series Services Gateways, to provide the ability to scale in the data center.

Implementation Guide for the SRX in the Data Center
To help customers deploy the SRX Juniper has created an implementation guide that provides various design considerations and implementation guidelines to deploy firewall services in a Juniper QFabric switch-based data center. The guide is intended for architects, network engineers and operators, and those who require technical knowledge regarding integrating the SRX Series with QFabric technology. The guide reviews the technical concepts of the SRX Series Services Gateways related to design and implementation of firewall services. Deployment scenarios are based on a single logical switch design using the Qfabric.

Friday, December 21, 2012

Network Functions Virtualization is Changing How Services are Delivered

As Service Providers are faced with increased competition from Over the Top Providers they are seeking new markets to enter. However, as they look to create and launch new services they must grapple with the growing number and complexity of hardware devices in their networks. This creates challenges due to the time it takes to certify equipment and with staffing and training of skilled operators for many devices. It also creates cost pressure with the need for more space and power at a time when these resources are becoming ever more expensive. Making upfront capital outlays for equipment in anticipation of revenue that ramps up over time can stress budgets. As a result Service Providers are looking to change how network services are deployed and some are finding Network Functions Virtualization (NFV) as the answer to their problems.

Defining Network Functions Virtualization Services
Network Functions Virtualization is transforming how network operators architect networks by enabling the consolidation of network services onto industry standard servers, which can be located in Data Centers, on Network Nodes or at the user premises. NFV involves delivering network functions as software that can run as virtualized instances and that can be deployed at locations in the network as required, without the need to install equipment for each new service. Network Functions Virtualization is applicable to any network function in both mobile and fixed networks. Network Functions Virtualization is complementary to Software Defined Networking (SDN) but not dependant on it. Virtual appliances might be configured using SDN capabilities and they might be connected via overlay network tunnels in clusters based on an application or based on the needs of an organization.

Monday, December 10, 2012

Achieving Single Touch Provisioning of Services Across The Network

Service provider networks are continually growing and evolving in order to provide a rich end user experience. Ethernet-based services are increasing rapidly to deliver high bandwidth and anytime access to video, voice, and broadband applications. In order to meet the needs of their customers, service providers have built complex networks consisting of thousand of high capacity Ethernet ports on devices in many locations. Typically these devices need to be provisioned, configured, and managed separately, which increases operating costs and time to deploy new services. The challenge is how to achieve single touch provisioning of services across the network.

Most factors contributing to the complexity of service provider networks revolve around the need to provision and manage separate physical platforms. The majority of the service provider’s OpEx cost results from the necessity to have the technical support infrastructure required to maintain and deploy services in a distributed network. Case studies show that by eliminating the need to manage individual devices separately can reduce the service provider’s OpEx by 70%.

Juniper Networks understands the challenges faced by service providers in today’s environment and has created a system called the Junos® Node Unifier (JNU) that enables centralized management, provisioning, and single touch deployment of services across thousands of Ethernet ports. The JNU solution is Juniper’s way to simplify today’s networks. JNU consists of satellite devices connected to a hub, where the satellites can be configured, provisioned, and managed from the hub device, giving a single unified node experience to network operators.

Friday, December 7, 2012

Securing Virtualization in the Cloud-Ready Data Center

With the rapid growth in the adoption of server virtualization new requirements for securing the data center have emerged. Today’s data center contains a combination of physical servers and virtual servers. With the advent of distributed applications traffic often travels between virtual servers and might not be seen by physical security devices. This means that security solutions for both environments are needed. As organizations increasingly implement cloud computing security for the virtualized environment is as integral a component as traditional firewalls have been in physical networks.

Juniper's Integrated Portfolio Delivers a Solution
With a long history of building security products Juniper Networks understands the security requirements of the new data center, and Juniper’s solutions are designed to address these changing needs. The physical security portfolio includes the Juniper Networks SRX3000 and SRX5000 line of services gateways, and the Juniper Networks STRM Series Security Threat Response Managers. These physical devices are integrated with the Juniper Networks vGW Virtual Gateway software firewall that integrates with the VMware vCenter and the VMware ESXi server infrastructure.

Fundamental to virtual data center and cloud security is the control of access to virtual machines (VMs) and the applications running on them, for the specific business purposes sanctioned by the organization. At its foundation, the vGW is a hypervisor-based, VM safe certified, stateful virtual firewall that inspects all packets to and from VMs, blocking all unapproved connections. Administrators can enforce stateful virtual firewall policies for individual VMs, logical groups of VMs, or all VMs. Global, group, and single VM rules ensure easy creation of “trust zones” with strong control over high value VMs, while enabling enterprises to take full advantage of many virtualization benefits. vGW integration with the STRM and SRX Series provides a complete solution for the mixed physical and virtualized workloads.