Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases now! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
VMware NSX Network Essentials
VMware NSX Network Essentials

VMware NSX Network Essentials: Join the revolution in Software Defined Networking

Arrow left icon
Profile Icon sreejith c
Arrow right icon
€20.98 €29.99
eBook Sep 2016 274 pages 1st Edition
eBook
€20.98 €29.99
Paperback
€36.99
Subscription
Free Trial
Renews at €18.99p/m
Arrow left icon
Profile Icon sreejith c
Arrow right icon
€20.98 €29.99
eBook Sep 2016 274 pages 1st Edition
eBook
€20.98 €29.99
Paperback
€36.99
Subscription
Free Trial
Renews at €18.99p/m
eBook
€20.98 €29.99
Paperback
€36.99
Subscription
Free Trial
Renews at €18.99p/m

What do you get with eBook?

Product feature icon Instant access to your Digital eBook purchase
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
Table of content icon View table of contents Preview book icon Preview Book

VMware NSX Network Essentials

Chapter 1. Introduction to Network Virtualization

Starting from the mainframe days, server virtualization has a long history. However, today's data centers use virtualization features to abstract physical hardware, which would be a pool of resources such as CPU, storage, and memory, to the end users in the form of virtual machines. The easiest way to ensure server resource utilization is improved is through virtualization techniques. Server virtualization success has been hailed as a transformational event in data centers primarily because a single physical machine can run multiple operating systems and each operating system can be managed like a dedicated physical machine. This is a very simple but highly powerful solution. There are different types of virtualization, such as server, storage, application, desktop, and the industry's newest buzzword is network virtualization. Network virtualization has been on the market for a long time. VLANs, VPNs, MPLS, VPLS, and VSS are all widely used examples of network virtualization. If you have worked in a data center, you would agree that networking is always challenging to work with. Network architects are forced to perform manual configuration, which results in configuring VLANs, ACLs, routing, firewall rules, QoS, load balancing, and so on. The drawback for this model is complex and slow, and in a dynamic cloud environment, the complexity would increase.

In this chapter, we will cover the following topics:

  • The traditional network model
  • The three pillars of a Software Defined Data Center (SDDC)
  • Introducing the NSX-V network virtualization platform
  • The power of server virtualization and network virtualization
  • How to leverage NSX
  • VMware NSX features

The traditional network model

Traditional architecture was built on a classic three-tier hierarchy. Each of these layers will have one or more network devices for redundancy and availability reasons:

  • Data Center Core Layer: The core layer is the backbone layer, which offers faster delivery of packets by getting interconnected to multiple aggregation layer devices that provide high-speed switching. It is best not to configure any traffic-filtering features at this layer.
  • Aggregation Layer: The aggregation layer is a mediator between the core and access layers. It is best to configure routing and filtering polices at this layer.
  • Access Layer: The access layer is ideally where end user machines are directly connected either to the top of rack (ToR) switch or at the end of row (EoR) based on the network design.

The following screenshot is an example of a classic three-tier network architecture:

The traditional network model

Let us now ask ourselves the following few questions:

  • How can my network, storage and server team work together if there is a performance bottleneck?
  • How many VLANs, STPs, LACPs, and routing configurations are required?
  • Will a change in application requirement demand a change in physical network?
  • Do I need to repeat initial configurations such as Vlans, STP, LACP, and routing?
  • Are all my features dependent on hardware devices?
  • Is isolation of tenants/virtual machines tied to VLANS?
  • Do I need to re-architect my applications before they can work with public cloud?
  • Does migrating, (VMotion) a VM from server-server will demand a change in physical network configuration?  
  • Do I have end-to-end network visibility from a single pane of glass?
  • Where is firewalling taking place, outside the rack or inside the rack?

The preceding Q&A list is long and, yes, networking is stuck in the past and there is only one solution—It's time to virtualize the network!

The three pillars of a Software Defined Data Center

In a SDDC, all elements of infrastructure, that is storage, networking, and compute are fully virtualized and delivered as a service. It is described by VMware as "A unified data center platform that provides unprecedented automation, flexibility, and efficiency to transform the way IT is delivered. Compute, storage, networking, security, and availability services are pooled, aggregated, and delivered as software, and managed by intelligent, policy-driven software". An SDDC is the mechanism through which cloud services can be delivered most efficiently. One of the key goals of an SDDC is to build a cloud-based data center. Vendors such as Amazon, Google, IBM, and VMware all have their own set of public cloud services running on an SDDC stack . Yes, now we have a next-generation data center wherein we could pool all physical servers and let applications run according to IT-defined policies.

As the heading suggests, the three pillars of SDDC are shown in the following screenshot:

The three pillars of a Software Defined Data Center

Let's go through each of them one by one:

  • In Compute virtualization, CPU and memory are decoupled from physical hardware and each application resides in a software object called a virtual machine. VMware VSphere, Microsoft Hyper-V, Citrix XenServer, Oracle VM are a few examples in that family.
  • Storage virtualization in a Software Defined Storage (SDS) environment is a hypervisor-based storage abstraction from the heterogeneous model of physical servers. Software that enables an SDS provides most of the traditional storage array features, such as replication, deduplication, thin provisioning, and snapshots. Since this is a completely software-defined storage, we have increased flexibility, ease of management, and cost efficiency. In this way, pooled storage resources can be automatically and efficiently mapped to application needs in a software-defined data center environment. VMware VSAN is a classic example of SDS since it is a distributed layer of software that runs natively as a part of an ESXi hypervisor.
  • Network virtualization is the third and most critical pillar of a Software Defined Data Center (SSDC) center and gives the full set of Layer 2-Layer 7 networking services such as routing, switching, firewall, load balancing, and QoS at the software layer. Network virtualization is the virtualization of network resources using software and networking hardware that enables faster provisioning and deployment of networking resources. The innovation speed of software is much faster than hardware and the answer for the future is not a hardware-defined data center but a Software Defined Data Center which will let us extend the virtualization layer across physical data centers. What makes Amazon and Google the world's largest data center is the brilliance of Software Defined Data Center. Network virtualization provides a strong foundation by effectively resolving all traditional network challenges to ensure we are getting a fully-fledged SDDC stack. As the cloud consumption model is being rapidly adopted across the industry, the need for on-demand provisioning of compute, storage, and networking resources is greater than ever. Network virtualization decouples the networking and security features from physical hardware and allows us to replicate similar network topology in a logical network.

Introducing the NSX-V network virtualization platform

Since we have defined what network virtualization is all about, let's discuss VMware NSX and its history. Nicira (NSX) was a company which focused on software-defined networking and network virtualization and was founded by Martin Casado, Nic Mckeown, and Scott Shenker in 2007. On July 23, 2012, VMware acquired Nicira and NSX is a product which was created from VMware vCloud Networking Security (vCNS) and the Nicira network virtualization platform. As of now VMware NSX-v can be integrated with vSphere, vCloud Director, and vCloud Automation Center which gives fully-fledged network automation in private cloud. A multi-hypervisor environment, such as Xen server, KVM, or VMware ESXi with a choice of cloud management solution such as vCloud automation center, OpenStack, and CloudStack, can also be integrated with VMware NSX. This book features the NSX-VMware (NSX-V) version of NSX only. NSX-V will be referred to as NSX for the rest of the book.

The power of server virtualization and network virtualization

Server virtualization is the mainframe for the 21st century. A key use of virtualization in modern-day business is to consolidate the existing infrastructure to fewer physical machines. All companies have already virtualized their infrastructure since that is a potential game changer as we could consolidate servers and management, and deployment became much simpler. A hypervisor is a piece of software that allows us to run multiple virtual machines. The following are two types of hypervisors:

  • Bare metal: Bare metal or type-1 hypervisors are pieces of software running directly on hardware, for example, VMware ESXi, KVM, Citrix XenServer, and Microsoft Hyper-V.
  • Hosted: Hosted or type-2 hypervisors run on an existing operating system. Basically, they abstract guest operating systems from the host operating system, for example, VirtualBox, VMware workstation, and VMware player.

Similar to how a virtual machine is created, monitored, and deleted, NSX for vSphere offers logical switching, hypervisor level routing, virtual NIC-level firewall protection and Layer 4-Layer 7 load balancing service which can be provisioned, monitored, and deleted from a single pane of glass. As a result, a virtualized network is much more scalable and cost-effective compared with traditional physical network provisioning and management. Because of its native integration with other VMware products such as VRealize Automation and VCloud Director, a customer would use NSX in most of the VMware environments.

The following figure depicts server virtualization and network virtualization:

The power of server virtualization and network virtualization

How to leverage NSX

When it comes to leveraging NSX features, customers have the following three options:

  • Installing NSX in private cloud and leveraging NSX features.

    VMware NSX can be integrated with vSphere, vCloud Director, vCloud Automation Center and VMware Integrated Openstack. A multi-hypervisor environment, such as Xen Server, KVM or VMware ESXi with a choice of cloud management solution such as vCloud Automation Center.

  • VMware vCloud Air, which is a public cloud, delivers advanced networking service networking and security features powered by NSX.

    Customer can secure networking in a public cloud built on the same platform as vSphere. Mirror on-premises networks in the cloud with minimal changes to design and networking topology. Manage at scale with controls and constructs familiar to network security administrators, minimizing operational disruption and need for retraining.

  • For true network hybridity, a customer can have NSX in a private cloud and VMware vCloud Air as the public cloud.

    Cloud networking is an essential component of cloud computing and forms the foundation for the hybrid cloud. Every vCloud Air service includes a connection to the Internet, one or more public IP addresses, and critical networking capabilities such as load balancing, a firewall, Network Address Translation (NAT), and VPN connectivity via the Edge Gateway. NSX in vCloud Air supports Border Gateway Protocol (BGP) and Open Shortest Path First (OSPF) routing to simplify the integration of a customer's public cloud workloads and on-premises applications and resources.

A simple diagram describing the same is shown in the following figure:

How to leverage NSX

Feature-rich networking and security services on both private and public clouds ensure both the environments are secured and, most importantly, no application remodification is required while moving the workloads back and forth. The rest of the integration and design between private cloud with NSX and vCloud Air is beyond the scope of this book. We will have a quick look at NSX features and where they will fit in our current data center deployment scenarios.

It is very important to understand the nature of our application that is driving the network traffic in any data center environment. Traditional network architectures were based on a series of switches and routers, and those types of network architecture would perfectly fit in a client-server environment. Today's application workloads are highly in need of reducing the number of hops when they are communicating in a network. In modern-day application requirements, virtual machines talk to each other sitting in the same rack or a different rack before sending a reply packet to the client which is outside the data center. Workloads are moving from server memory to server flash drives for analysis. Big data, virtualization, and cloud have highly contributed to such types of traffic. Hence, we certainly need an intelligent networking for such big application workloads. Lack of speed and flexibility in provisioning a network is addressed with the help of network virtualization features.

With that said, let's have a look at the following diagram, which explains types of traffic in a data center environment. Networking traffic flow in a data center environment is of two types: East-West and North-South:

How to leverage NSX

Let's have a look at an example. Let's assume we have a private data center and we need to access some applications which are hosted in a virtualized server from outside the data center:

  • East-West traffic: Traffic between virtual machines in the same data center
  • North-South traffic: Traffic which is coming into and going out of the data center

VMware NSX features

VMware NSX is the network virtualization platform for the Software Defined Data Center (SDDC), which is a completely non-disruptive solution as it reproduces the entire networking infrastructure in software which includes L2-L7 network services. NSX allows virtual networks to connect to physical networks by maintaining fine-grained security as per virtual NIC:

VMware NSX features

Let's discuss NSX features:

  • Logical switching: NSX allows the ability to create logical switches which are nothing but vSphere port groups for workload isolation and separation of IP address space between logical networks. This means you are no longer limited to 4096 physical broadcast domains primarily because of VXLAN overlay networks. We will be discussing VXLAN during logical switch modules in more detail in Chapter 4, NSX Virtual Networks and Logical Router.
  • Gateway services: The Edge Gateway service interconnects your logical networks with your physical networks. This means a virtual machine connected to a logical network can send and receive traffic directly to your physical network through the gateway. Edge Gateway provides perimeter services such as DHCP, VPN, dynamic/static routing, NAT, firewall, load balancing, DNS relay, and High Availability.
  • Logical routing: NSX logical routing functionality allows a hypervisor to learn and route between different logical networks by limiting the North-South direction of traditional data center routing. Logical routers also can provide North-South connectivity, allowing access to workloads living in the physical networks. Both static and dynamic routing (OSPF, BGP, ISIS) are supported in NSX Edge.
  • Logical firewall: Switching from a perimeter-centric security approach to per virtual machine level protection was not achievable till NSX was introduced. This has been of significant impact in on-demand cloud and VDI environments. Instead of sticking with  traditional per data center level firewall protection, logical firewall gives per VM level protection and policies can be created, deleted with few clicks and policies remain intact even if virtual machines migrates from one host to another host. VMware NSX allows us to make use of a distributed logical firewall and an Edge firewall for use within your software-defined networking architecture. A distributed logical firewall allows you to build rules based on attributes that include not just IP addresses and VLANs but also virtual machine names and vCenter objects. The Edge Gateway features a firewall service that can be used to impose security and access restrictions on North-South traffic.
  • Extensibility: Using the NSX extensibility feature, third-party VMware partner solutions can be integrated directly into the NSX platform that allows for a vendor choice in multiple service offerings. There are many VMware partners who offer solutions such as antivirus protection, IPS/IDS, and next-generation firewall services that can integrate directly into NSX, palo-alto for example. In addition to that, NSX admin can manage security polices and rules from a single pane of glass.
  • Load balancer: NSX Edge offers a variety of network and security services and logical load balancer is one of them. There are two types of logical load balancer that NSX supports:
    • Proxy mode load balancer
    • Inline mode load balancer

      The logical load balancer distributes incoming requests among multiple servers to allow for load distribution while abstracting this functionality from end users. To ensure your application has the most up-time, we can configure the high availability feature for NSX Edge and that way it would be a highly available load balancer.

  • Dynamic Host Configuration Protocol (DHCP): NSX Edge offers DHCP services that allows for IP address pooling and also static IP assignments. An administrator can now rely on the DHCP service to manage all IP addresses in your environment rather than having to maintain a separate DHCP service. The DHCP service also can relay DHCP requests to your existing DHCP server as well. The NSX Edge DHCP service can relay any DHCP requests generated from your virtual machines to a pre-existing physical or virtual DHCP server without any interruptions.
  • Virtual Private Networks (VPN): The Edge offers the VPN service that allows you to create secure encrypted connectivity for end users to your applications and workloads hosted in private and public cloud. Edge VPN service offers SSL-VPN plus that allows for user access and IPSEC-policy-based site-to-site connectivity that allows for two sites to be interconnected securely.
  • Domain Name System Relay (DNS): NSX Edge offers a DNS service that can relay any DNS requests to an external DNS server.
  • Service composer: Service composer allows you to provision and assign network security features to the applications hosted in a virtualized infrastructure. Network policies are automatically applied to virtual machines whenever they are added in virtual network.
  • Data security: NSX data security provides visibility into sensitive data and ensures data protection and reports back on any compliance violations. A data security scan on designated virtual machines allows NSX to analyze and report back on any violations based on the security policy that applies to these virtual machines.
  • Trace flow: Trace flow is a new feature added to NSX 6.2 which allows us to follow a packet from source to destination. Using the trace flow feature, we can monitor link utilization and troubleshoot network failures.
  • Flow monitoring: Flow monitoring is a traffic analysis feature which provides a granular level of information in terms of number of packets transmitted per session, ports being used, and so on, and later an administrator can allow or block actions depending upon the output and business requirement.
  • Activity monitoring: For detailed visibility per application, activity monitoring adds a lot of value. By doing so, an administrator will be able to monitor users and application-level information.

The features are summed up perfectly in the following block diagram:

VMware NSX features

VMware NSX includes a library of logical networking services - logical switches, logical routers, logical firewalls, logical load balancers, logical VPN, and distributed security. You can create custom combinations of these services in isolated software-based virtual networks that support existing applications without modification, or deliver unique requirements for new application workloads.

Note

NSX 6.2.3 is the current NSX version at time of writing.

Summary

We started this chapter with an introduction to network virtualization and software-defined networking. We discussed concepts of network virtualization and introduced VMware's NSX network virtualization platform. We then discussed different NSX features and services, including logical switching, logical routing, Edge Gateway services, extensibility, service composer, and data security.

In the next chapter, we will discuss the NSX architecture.

Left arrow icon Right arrow icon

Key benefits

  • Experience the dynamism and flexibility of a virtualized software defined data center with NSX
  • Find out how to design your network infrastructure based on what your organization needs
  • From security to automation, discover how NSX’s impressive range of features can unlock a more effective and intelligent approach to system administration

Description

VMware NSX is at the forefront of the software-defined networking revolution. It makes it even easier for organizations to unlock the full benefits of a software-defined data center – scalability, flexibility – while adding in vital security and automation features to keep any sysadmin happy. Software alone won’t power your business – with NSX you can use it more effectively than ever before, optimizing your resources and reducing costs. Getting started should be easy – this guide makes sure it is. It takes you through the core components of NSX, demonstrating how to set it up, customize it within your current network architecture. You’ll learn the principles of effective design, as well as some things you may need to take into consideration when you’re creating your virtual networks. We’ll also show you how to construct and maintain virtual networks, and how to deal with any tricky situations and failures. By the end, you’ll be confident you can deliver, scale and secure an exemplary virtualized network with NSX.

Who is this book for?

If you’re a network administrator and want a simple but powerful solution to your network virtualization headaches, look no further than this fast-paced, practical guide.

What you will learn

  • Deep dive into NSX-v Manager, Controller deployment, and design decisions
  • Get to know the strategies needed to make decisions on each mode of VXLAN that is based on physical network design
  • Deploy Edge Gateway and leverage all the gateway features and design decisions
  • Get to grips with NSX-v Security features and automate security
  • Leverage Cross VC, identify the benefits, and work through a few deployment scenarios
  • Troubleshoot an NSX-v to isolate problems and identify solutions through a step-by-step process

Product Details

Country selected
Publication date, Length, Edition, Language, ISBN-13
Publication date : Sep 30, 2016
Length: 274 pages
Edition : 1st
Language : English
ISBN-13 : 9781782172949
Vendor :
VMware
Tools :

What do you get with eBook?

Product feature icon Instant access to your Digital eBook purchase
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want

Product Details

Publication date : Sep 30, 2016
Length: 274 pages
Edition : 1st
Language : English
ISBN-13 : 9781782172949
Vendor :
VMware
Tools :

Packt Subscriptions

See our plans and pricing
Modal Close icon
€18.99 billed monthly
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Simple pricing, no contract
€189.99 billed annually
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just €5 each
Feature tick icon Exclusive print discounts
€264.99 billed in 18 months
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just €5 each
Feature tick icon Exclusive print discounts

Frequently bought together


Stars icon
Total 119.97
Building VMware Software-Defined Data Centers
€49.99
VMware NSX Network Essentials
€36.99
Learning VMware NSX, Second Edition
€32.99
Total 119.97 Stars icon

Table of Contents

8 Chapters
1. Introduction to Network Virtualization Chevron down icon Chevron up icon
2. NSX Architecture Chevron down icon Chevron up icon
3. NSX Manager Installation and Configuration Chevron down icon Chevron up icon
4. NSX Virtual Networks and Logical Router Chevron down icon Chevron up icon
5. NSX Edge Services Chevron down icon Chevron up icon
6. NSX Security Features Chevron down icon Chevron up icon
7. NSX Cross vCenter Chevron down icon Chevron up icon
8. NSX Troubleshooting Chevron down icon Chevron up icon
Get free access to Packt library with over 7500+ books and video courses for 7 days!
Start Free Trial

FAQs

How do I buy and download an eBook? Chevron down icon Chevron up icon

Where there is an eBook version of a title available, you can buy it from the book details for that title. Add either the standalone eBook or the eBook and print book bundle to your shopping cart. Your eBook will show in your cart as a product on its own. After completing checkout and payment in the normal way, you will receive your receipt on the screen containing a link to a personalised PDF download file. This link will remain active for 30 days. You can download backup copies of the file by logging in to your account at any time.

If you already have Adobe reader installed, then clicking on the link will download and open the PDF file directly. If you don't, then save the PDF file on your machine and download the Reader to view it.

Please Note: Packt eBooks are non-returnable and non-refundable.

Packt eBook and Licensing When you buy an eBook from Packt Publishing, completing your purchase means you accept the terms of our licence agreement. Please read the full text of the agreement. In it we have tried to balance the need for the ebook to be usable for you the reader with our needs to protect the rights of us as Publishers and of our authors. In summary, the agreement says:

  • You may make copies of your eBook for your own use onto any machine
  • You may not pass copies of the eBook on to anyone else
How can I make a purchase on your website? Chevron down icon Chevron up icon

If you want to purchase a video course, eBook or Bundle (Print+eBook) please follow below steps:

  1. Register on our website using your email address and the password.
  2. Search for the title by name or ISBN using the search option.
  3. Select the title you want to purchase.
  4. Choose the format you wish to purchase the title in; if you order the Print Book, you get a free eBook copy of the same title. 
  5. Proceed with the checkout process (payment to be made using Credit Card, Debit Cart, or PayPal)
Where can I access support around an eBook? Chevron down icon Chevron up icon
  • If you experience a problem with using or installing Adobe Reader, the contact Adobe directly.
  • To view the errata for the book, see www.packtpub.com/support and view the pages for the title you have.
  • To view your account details or to download a new copy of the book go to www.packtpub.com/account
  • To contact us directly if a problem is not resolved, use www.packtpub.com/contact-us
What eBook formats do Packt support? Chevron down icon Chevron up icon

Our eBooks are currently available in a variety of formats such as PDF and ePubs. In the future, this may well change with trends and development in technology, but please note that our PDFs are not Adobe eBook Reader format, which has greater restrictions on security.

You will need to use Adobe Reader v9 or later in order to read Packt's PDF eBooks.

What are the benefits of eBooks? Chevron down icon Chevron up icon
  • You can get the information you need immediately
  • You can easily take them with you on a laptop
  • You can download them an unlimited number of times
  • You can print them out
  • They are copy-paste enabled
  • They are searchable
  • There is no password protection
  • They are lower price than print
  • They save resources and space
What is an eBook? Chevron down icon Chevron up icon

Packt eBooks are a complete electronic version of the print edition, available in PDF and ePub formats. Every piece of content down to the page numbering is the same. Because we save the costs of printing and shipping the book to you, we are able to offer eBooks at a lower cost than print editions.

When you have purchased an eBook, simply login to your account and click on the link in Your Download Area. We recommend you saving the file to your hard drive before opening it.

For optimal viewing of our eBooks, we recommend you download and install the free Adobe Reader version 9.