
Several Internet Service Providers (ISP) are planning to innovate their infrastructures through a process of network softwarisation and programmability. The Software-Defined-Network (SDN) paradigm aims at improving the design, configuration, maintenance and service provisioning agility of the network through a centralised software control plane which is in charge of managing the entire system. This is easily achievable for local area networks, typical of data centres, where the benefits of having programmable access to the entire network is not restricted by latency. However, in Wide Area Networks, a centralised control plane limits the speed of responsiveness in reaction to time-constrained network events due to unavoidable latencies caused by physical distances. A logical step towards robustness in SDN is to distribute the load of the control plane between entities, each taking care of a portion of the entire geographical network and each providing an east-west communication interface to enable programmability of the entire network. Moreover, a key objective of an SDN control plane targeting an ISP networks is the east-west interface with external domains under the control of other providers. In this article we present ICONA (Inter Cluster Onos Network Application), a tool that has the objective of enabling programmable networks to span multiple clusters of controllers within either a single or multiple administrative domains. In particular, the paper describes the architecture behind ICONA and provides an initial evaluation obtained on a preliminary version of the tool, built on top of the cutting-edge network controller ONOS, Hummingbird release.
In this paper we show an SDN controller implementation named Basebox that listens to Linux Netlink and translates commands into OpenFlow rules to control a domain of OF-DPA based switches in an OpenStack cluster.
Network Functions Virtualization (NFV) aims at replacing proprietary hardware appliances with software running on a standardized, general purpose computing platforms. Recently, the concept has gained traction in the industry and major deployments have been announced. However, benchmarking the performance characteristics of virtualized network functions (VNFs) is still an active research topic. VNFs are supplied as software that is operated on the NFV infrastructure (NFVI) of a telecom provider. The performance as well as the accuracy and precision of performance measurements of VNFs are influenced by the NFVI they are running on. Furthermore, due to the introduction of new VNFs and NFVIs, a sharp increase in the need to conduct benchmarks is expected. Despite various efforts in this area by the research community and the industry there is no common understanding on how to approach this issue. To foster a common understanding in this area a structured approach to developing benchmarks for VNFs is proposed in this paper. The approach focuses on the most significant concepts and defines clear boundaries between them. The need to increase the efficiency of developing VNF benchmarks is addressed by the introduction of a hierarchical model with the aim to enable reuse of VNF benchmark components and results.
Life-cycle management of stateful VNF services is a complicated task, especially when automated resiliency and scaling should be handled in a secure manner, without service degradation. We present FlowSNAC, a resilient and scalable VNF service for user authentication and service deployment. FlowSNAC consists of both stateful and stateless components, some of that are SDN-based and others that are NFVs. We describe how it adapts to changing conditions by automatically updating resource allocations through a series of intermediate steps of traffic steering, resource allocation, and secure state transfer. We conclude by highlighting some of the lessons learned during implementation, and their wider consequences for the architecture of SDN/NFV management and orchestration systems.
This paper describes the architecture, use-case, and evaluation of a software-defined interconnect. Interconnects at Internet Exchange Points (IXPs) today comprise a layer-2 data-plane and BGP control-plane. We architect, implement, and deploy an SDN-based IXP using ONOS that provides equivalent functionality, while additionally supporting better ARP hygiene and enhanced traffic telemetry. Our system also provides private Internet peering, such as between an enterprise and a cloud provider. We demonstrate a novel use-case enabled by our system, wherein an enterprise can dynamically and transparently switch between public and private peering to access cloud services at appropriate quality and cost points. Evaluation of our solution with real traffic demonstrates that it enables enterprises to manage cloud connect costs flexibly without compromising quality, opening the door to innovative solutions not possible before.
Network Functions Virtualization (NFV) is now accepted in large production networks for agile introduction of various Network Functions (NFs). A service chaining technology that dynamically links multiple NFs over the entire network is a heart of the NFV concept. However, virtualizing NF-dedicated hardwares as virtual machines on IA servers brings performance problems, such as lower throughput, longer latency, and larger jitter. Various packet processing frameworks and virtual switches have been proposed to resolve the problems, but there is no comprehensive study of their performance characteristics focusing on both physical/virtual layers. In this paper, we evaluate fundamental throughput and latency/jitter of three packet processing architectures (NAPI, netmap, and DPDK) with six virtual switches (Linux Bridge, Open vSwitch, VALE, L2FWD-DPDK, OVS-DPDK, and Lagopus) for physical/virtual layers. Our experiments were performed on both Intel and Mellanox 40 GbE NICs. Finally, we discuss appropriate NFV host environment for commercial-use.
This demo paper presents an innovative Software Defined Networking (SDN) based approach to deploying Internet of Things (IoT) applications for Smart Cities. The Poznan Supercomputing and Networking Center (PSNC) together with NoviFlow Inc. and Spirent have jointly developed a demonstration showing how programmable SDN infrastructure can be utilized to significantly simplify the onboarding and provisioning of end-toend IoT solutions for use in multi-tenant networks. The demo features a dynamic global view of the deployed IoT resources with their associated network connections, and the use of OpenFlow Experimenter-based extensions to trigger automated detection and onboarding of IoT devices, ("things") as well as the insertion of metadata into IoT device flows to automate service provisioning. The demonstration also features an SDN application that interfaces between the SDN controller and the cloud orchestrator to instantiate dedicated IoT services inside LXC light containers. The demonstration architecture includes a variety of typical IoT sensors as well as a Spirent TestCenter (STC) emulating metro scale IoT network workflows, interconnected to the cloud via a network composed of NoviFlow 2128 OpenFlow 1.3 switches. To illustrate the use of the solution in a real-world setting, the Poznan Smart City use case is presented, showing how a single common SDN-based platform can be utilized to "slice" a city into multiple smart spaces running over a shared network and cloud infrastructure, and how OpenFlow-enabled network infrastructure can be used to automate the deployment of IoT devices for use in multi-tenant, cloud-based applications.
The EU funded FP7 project T-NOVA, with the specific goal of accelerating the evolution of NFV, proposes an open architecture to provide Virtual Network Functions as a Service (VNFaaS), together with a dynamic, and flexible platform for the management of Network Services (NSs) composed by those Virtual Network Functions (VNFs). This demo illustrates mature work carried out on the orchestration and deployment of NS over Network Function Virtualization Infrastructures (NFVI) using resource aware scheduling methods to ensure optimal use of resources and performance.
Internet Service Providers (ISPs) are struggling to cope with the growing volume of streaming video traffic in their network, and the problem will only exacerbate as Virtual Reality applications proliferate. To classify and manage bandwidth for video streams, current practise is to either sample traffic for offline analysis or deploy middle-boxes for in-line packet inspection - such solutions are inaccurate and/or expensive. In this paper we present Telescope, a low-cost system comprising a commodity SDN switch and a commodity server, to identify and profile individual video flows at line-rate. We develop an architecture that dynamically manages flow-table entries to classify video flows with minimal mirroring of packets, we prototype our solution using a Noviflow OpenFlow switch, coupled with the Bro packet inspection engine and our application on a Ryu controller, lastly, we validate our solution with real video streams in a campus WiFi network, and test its scaling to thousands of video flows using a hardware-based traffic generator. We believe our solution offers great potential for real-time video classification in an operational network at very low cost.
Network Functions Virtualization (NFV) has been expected to flexibly compose Virtual Network Functions (VNFs) by virtualizing existing network appliances and logically chaining them. Currently used VNFs are realized as VM-based appliances and shared by multiple users (VMs). However, the notion of NFV can be extended to reinforce network functionality of user VMs by introducing VM-dedicated VNFs. In this paper, we propose micro-VNFs (μVNFs) and a VM-dedicated service chaining framework (vNFChain). Micro-VNFs are VM-dedicated lightweight VNFs (application firewalls, monitoring, and logging), while typical VNFs (routers, firewalls, and load balancers) are centralized and shared. The vNFChain framework creates local service chains of uVNFs for each VM and transparently attaches a chain to the target VM. In practice, our framework supposes process-based uVNFs within a container and can efficiently chain these uVNFs in the context of DPDK/vhost-user mechanisms. We focus on architecture and implementation of the proposed framework in this paper. Evaluation results on commodity PCs showed that our approach achieved about 7.3 times (1 μVNF) and 160 times (6 μVNFs) throughputs with 64-byte packets compared to that of a VM-based service chaining using DPDK/vhost-user. In addition, latency was reduced 88 % with 6 μVNFs.
Network service composition is becoming increasingly flexible, thanks in part to advances in virtualisation and cloud technologies. As these penetrate further into networks, providers are often looking to leverage this infrastructure to improve their service delivery. This desire poses a number of obstacles, including a diversity in device capabilities and the need for a value exchange mechanism. In this demonstration, we present a platform that seeks to address a selection of these challenges.
The ETSI model defines a generic architecture to deploy and configure virtual network functions. While many efforts from both academia and industry focus on the problem of deploying those virtual network functions, little attention has been given to the interface needed to configure such applications. This paper explores the problem of dynamically configuring virtual network functions and proposes an implementation for the ETSI MANO OR-VNFM interface that supports generic network functions by exploiting a message bus and YANG models.
Software Defined Networking (SDN) architecture enables centralized control of the forwarding behavior of individual network elements. While SDN brings many well-known benefits, such as manageability and adaptability, it also poses some challenges. Scalability becomes an issue in highly dynamic, large scale networks, where the forwarding rules of single elements must be updated at a high pace by a central controller. This work proposes a novel type of flow rule to tackle this issue, the Dynamic Flow Rule (DFR). DFR enables the network elements to change their forwarding behavior locally, according to predefined instructions set up by the central controller. This paper introduces the DFR concept, discusses several plementation options and examines its performance in different use cases. The performance analysis shows that DFR effectively increases the programmability and adaptability of SDN network. It reduces the control plane signaling, reduces the network reaction time to changes, and alleviates the computing requirements at the controller, while retaining the central control of the network. And most importantly, since DFR leverages on the current processing capability of SDN switches, it provides a general and scalable control solution without additional performance penalty.
Allocating resources to virtualized network functions and services to meet service level agreements is a challenging task for NFV management and orchestration systems. This becomes even more challenging when agile development methodologies, like DevOps, are applied. In such scenarios, management and orchestration systems are continuously facing new versions of functions and services which makes it hard to decide how much resources have to be allocated to them to provide the expected service performance. One solution for this problem is to support resource allocation decisions with performance behavior information obtained by profiling techniques applied to such network functions and services. In this position paper, we analyze and discuss the components needed to generate such performance behavior information within the NFV DevOps workflow. We also outline research questions that identify open issues and missing pieces for a fully integrated NFV profiling solution. Further, we introduce a novel profiling mechanism that is able to profile virtualized network functions and entire network service chains under different resource constraints before they are deployed on production infrastructure.
The ability of SOHO networks to connect to the Internet through several Internet service providers, gives high potential to enable rich cloud-based network services for enterprises. Nevertheless, it remains a huge challenge for SOHOs to leverage such multi-homing and cloud networking capabilities. For such a reason, we introduce the vSP concept (virtual Service Provider). The idea of vSP is to hide the technical complexity inherent to multi-homing and allow SOHOs to seamlessly use their cloud resources. The role of the vSP is to orchestrate traffic between the different Internet Services Providers (ISPs) in order to maximize the cloud service performance without requiring any intervention of the SOHO network administrator.
At the core of any network control and management system is the representation and maintenance of network topology information. Software-Defined Networking (SDN) treats topology abstractions as one of the cornerstones towards rethinking network architectures and the way they are operated. Recently, motivated by the scalability and performance needs of cloud applications, Graph Databases are being adopted as appealing alternatives to traditional relational models when data is highly interconnected and extensible schemas are called for. In addition, the use of metadata to describe how data is interconnected by means of Web Semantic standards is increasingly gaining ground. At the crossroads of these trends, this paper presents an approach to augment SDN network state with a semantic model leveraging graph database technologies. In particular, our proposal imports the Network Mark up Language (NML) model into a scalable graph database (Neo4j). For validation purposes, we evaluate our proof of concept implementation against a representative set of SDN application primitives.
The DynPaC (Dynamic Path Computation) framework has been designed to provide resilient on-demand Layer 2 services with bandwidth constraints in Software-Defined Networks, more specifically in Open Flow networks. It has been implemented using the Open Daylight platform as base Open Flow controller, which has been extended with custom modules that provide resiliency, scheduling, monitoring and network resource optimisation. Thanks to an advanced Path Computation Element, DynPaC is able to take into account the available bandwidth in the network to assign the best possible path, in this case the shortest one, to the requested services. Furthermore, DynPaC supports service reservation, and takes into account already reserved services at the time of computing the paths for new service demands thanks to a powerful and novel scheduling mechanism based on network snapshots. In addition, DynPaC is able to maximise the network resources' utilisation through a service reallocation and disaggregation mechanism. Of special interest is the flow disaggregation algorithm, which makes use of the Open Flow's high granularity to divide the original service into the minimum number of sub-services and reallocate them in the network to free enough network resources to accept new service demands.
We propose a high-performance virtual network interface card framework for hypervisor-based NFV with user space virtual switch. We extend the virtio-net framework to achieve high-performance I/O and to provide DPDK-compatible APIs for a DPDK-enabled NFV app on a guest hypervisor-based VM with DPDK-enabled user space vSwitch. The framework provides a device status tracking mechanism between DPDK-enabled NFV app and a vSwitch as well as service maintenance supports such as reboot and restart of a guest VM or in a vSwitch in order to increase flexibility and agility in a carrier network operation for NFV. The vNIC archived over-120-Gbps throughput and over-14.2-MPPS I/O processing.
In general, modern high-performance computing systems are built as cluster systems. We have been investigating the feasibility of optimizing MPI communications by integrating the dynamic network control realized by SDN. In this paper, we present a concept of a generic SDN enhanced MPI framework, an application-aware network control mechanism specifically for MPI applications.
The Runos is a C++ OpenFlow controller that has been developing since 2014 in order to answer on the well-known question "Could an OpenFlow controller be both easy to develop applications for and also high performance?" [1]. The controller includes the most fruitful techniques from the latest research on simplifying SDN programming such as Pyretic and Maple and combines them in right way to achieve high performance and production quality, programmability, usability. Runos is widely used in different POCs showing interests for third-party developers. The project is in http://arccn.github.io/runos/.