SlideShare a Scribd company logo
1 of 40
Download to read offline
Confidential │ ©2021 VMware, Inc.
Live Webinar EMEA
Deploying Elastic, Self-Service Load
Balancing for VMware NSX-T
Nicolas Bayle Technical Evangelist
Christoph Altherr VCN Lead Solution Engineer
October 21st, 2021
Confidential │ ©2020 VMware, Inc.
Agenda
2
NSX Data Center – Introduction
Avi / NSX Advanced Load Balancer – Introduction
Avi & NSX Integration Deep Dive
QA
Next Steps
3
Confidential │ ©2021 VMware, Inc.
VMware NSX
Data Center
Confidential │ ©2021 VMware, Inc. 4
Leads to security compromises
Traditional Network and Security Architectures
Realities
Complex to insert into the network
Unable to dynamically scale
Blind spots and lack of controls
Inconsistent and unmanageable
policy
Expensive
(HW, SW, maintenance, power,
cooling, cabling,
rack space,…)
IDS/IPS
FIREWALL / L3 Gateway
LOAD BALANCER
ANALYTICS
Confidential │ ©2019 VMware, Inc. 5
Traditional network & security
approach of the past 20 years
Built to meet the needs of
specific infrastructure
environments
(DC, Campus, Branch)
What’s needed: A new approach
for the next 20+ years
Flexible, programmable
network fabric designed to run
everywhere where applications
and
data reside
Confidential │ ©2021 VMware, Inc. 6
Provides complete coverage and eliminates blind spots
NSX distributes Network and Security features to every workload
Solution
Kernel-based L4-7 FW with
Advanced Threat Prevention
Distributed architecture eliminates
traffic hair pinning
Single management console
Easy to Deploy - no changes
required to physical
Agile (automatic policy provisioning
/ deprovisioning)
Consistent policy across all
workloads and multi-cloud
More cost effective
(up to 70%+ savings)
IDS/IPS
FIREWALL / L3 Gateway
LOAD BALANCER
ANALYTICS
Confidential │ ©2021 VMware, Inc. 7
VMware NSX is the
“Network & Security Hypervisor”
Confidential │ ©2021 VMware, Inc. 8
NSX Data Center
DATA CENTER
Virtualization Layer
NSX Platform
Physical
Infrastructure
Hypervisor
Confidential │ ©2021 VMware, Inc. 9
NSX Data Center
DATA CENTER
Virtualization Layer
NSX Platform
Workloads
vSwitch
Confidential │ ©2019 VMware, Inc. 10
Sysdig 2021
Container Security and Usage Report
Source: https://dig.sysdig.com/c/pf-2021-container-security-and-usage-report
Confidential │ ©2019 VMware, Inc. 11
Multi-cluster Policy and Visibility from NSX Manager
Kubernetes Solution Overview
App Dev and Ops
K8s Platform Ops
Network and Security Ops
VMware vSphere
Tanzu K8s Cluster
Antrea Ingress and ALB
Physical/Virtual Servers
Upstream K8s Cluster
Antrea Ingress and ALB
Kubernetes
VMware vSphere
OCP K8s Cluster
Antrea Ingress and ALB
NSX
NSX-T
Security Policies
Visibility and Troubleshooting
Security Policies within NSX-T for
both NSX-T and container cluster
endpoints
Unified Visibility and Operations across
Container and VM Networking and
Security
Support for Wide Variety of
Kubernetes Distributions
Confidential │ ©2021 VMware, Inc. 12
Network virtualization and security platform that enables a virtual cloud network
across data centers, clouds, and application frameworks
What is VMware NSX?
13
©2020 VMware, Inc.
Avi NSX Advanced Load Balancer
Intro
Confidential │ ©2019 VMware, Inc. 14
Load Balancing Is a Key Blocker for Digital Transformation
Not Flexible
Not Scalable Not Agile
AUTOMATION
C H A L L E N G E S
Compute
Storage
Load
Balancers
Drivers
Time to
Market
Modern
Apps
Cost
Efficiency
# Env/Infra
# Apps
# Changes
Increased
IT Demands
Network
Confidential │ ©2019 VMware, Inc. 15
Delivers agility, operational Simplicity, and cost savings
To Modern Distributed Architecture
Expensive, Inflexible, and Restrictive
Hardware/Virtual Load Balancer Challenges
Separate control points –
operational complexity, hard to
automate, painful upgrades
Capacity management – manual VIP
placement, costly overprovisioning,
no fungible capacity
Not designed for modern new
environments
On-premises Cloud
Data Center 1 Data Center 2
DEPT1 DEPT2
Active Standby
0% Used
Capacity
15% Used
Capacity
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Data Plane
Control Plane
Data Plane
Control Plane
Data Plane
Control Plane
Data Plane
Control Plane
Hard to troubleshoot, finger-pointing
between app and network team
Network Team
App Owners
?
Container
Confidential │ ©2019 VMware, Inc. 16
Can I have the Best of Both Worlds?
The legacy VEs and cloud provider solutions are an unacceptable compromise
Load Balancing Challenges/Tradeoffs in the Public Cloud
Legacy
Virtual
LB
offers
features
Cloud
Provider LB
offers
automation &
elasticity
?
Tradeoff operational simplicity,
automation, and cloud-native
capabilities
Tradeoff features, multi-cloud
consistency, and portability
Confidential │ ©2019 VMware, Inc. 17
Consistent L4-L7 enterprise-grade app services across multi-cloud environments
Avi Networks (now VMware NSX Advanced Load Balancer)
App Analytics / Insights
Container Ingress Services
DNS and IP Address
Management (IPAM)
Web Application Firewall (WAF)
and App Security
Global Server Load Balancing
(GSLB)
Enterprise-grade Load
Balancing
NSX
Horizon(VDI)
vSphere/vCenter
Deliver
Any App
on
Any Cloud
with
One Platform
VCF
VMC
Tanzu
vRO/vRA
Confidential │ ©2019 VMware, Inc. 18
Control Plane
Bare Metal Virtualized Containers
ON PREMISES
PUBLIC CLOUD
Centralized policies and full lifecycle management
Avi Distributed Architecture for Multi-Cloud Application Services
Data Plane
Avi Controller
(Customer-managed | SaaS)
ELASTICITY
Application Services Fabric
ANALYTICS /
OBSERVABILITY
AUTOMATION
RESILIENCE
Avi PULSE
CENTRAL ORCHESTRATION
Confidential │ ©2019 VMware, Inc. 19
Consistent experience across multi-cloud envs.
Single LB Fabric Across Clouds
Single
Management
Point Centrally manage
multi-cloud deployments
Automate moves, adds,
and changes across clouds
No feature trade-offs
between on-prem vs cloud
Manage multi-site deployments
with GSLB
Bare Metal Virtualized Containers
Across On-prem and Public Cloud
Avi Controller
Confidential │ ©2019 VMware, Inc. 20
v2
Tenant 1
Always Active-Active, automatic failure handling
Resilient, Self-Healing Fabric
VIPs running on
Avi Service Engines
Active-Active
Per-tenant/per-app LB-tenant
isolation
Service Engines (SE) are
deployed in Active-Active
configuration with anti-
affinity rules
Automatically moves VIPs if SE
fails (e.g. accidental power off)
and instantiates new SE
Traffic is automatically rerouted
with moves and changes
Avi Controller
Tenant 2
Confidential │ ©2019 VMware, Inc. 21
Flexible, Non-Disruptive Upgrades
Tenant 1 Tenant 3
Tenant 2
v1 v1 v1 v1
v2
v2
Facilitates partial
(non-disruptive) upgrades
Upgrade select tenants or
SE groups within tenant to
V2 (after controller upgrade
or later time)
• Upgrade Tenant-2, Tenant-3 (SE
group 3) to V2
• Config allowed, but any config
changes to VSs in these SE groups
are queued until
SE group upgrade is completed
• Upgrade other tenants or SE groups
weeks later
Rollbacks of Controller and
SEs supported
Avi Controller
Confidential │ ©2019 VMware, Inc. 22
Simplify troubleshooting, eliminate TCP Dumps
Analytics and App Insights
Eliminate finger-pointing
Troubleshoot app performance, security and
end-user issues in minutes
Bare Metal Virtualized Containers
Avi Controller
• Connection log analytics
• Security insights: DDoS
• App performance metrics
• End user experience
End-to-End Timing
Total Response Time
End User
Client
RTT
Server
RTT
App
Response
Load
Balancer Server App
Confidential │ ©2019 VMware, Inc. 23
Simplify troubleshooting, eliminate TCP Dumps
Analytics and App Insights
Bare Metal Virtualized Containers
Eliminate finger-pointing
Troubleshoot app performance, security and
end-user issues in minutes
Avi Controller
• App performance metrics
• End user experience
• Connection log analytics
• Security insights: DDoS
End-to-End Timing
Total Response Time
End User
Client
RTT
Server
RTT
App
Response
Load
Balancer Server App
Confidential │ ©2019 VMware, Inc. 24
Simplify troubleshooting, eliminate TCP Dumps
Analytics and App Insights
Bare Metal Virtualized Containers
Eliminate finger-pointing
Troubleshoot app performance, security and
end-user issues in minutes
Avi Controller
• App performance metrics
• End user experience
• Connection log analytics
• Security insights: DDoS
End-to-End Timing
Total Response Time
End User
Client
RTT
Server
RTT
App
Response
Load
Balancer Server App
Confidential │ ©2019 VMware, Inc. 25
Scale vertically with more CPUs or horizontally with more Service Engines
Elastic Autoscaling
2x 1-core SEs
32x 1-core SEs
1 core
2,500 SSL TPS
5,000 SSL TPS
1M SSL TPS
Scale to millions of TPS
or hundreds of GBs of
throughput
Confidential │ ©2019 VMware, Inc. 26
Built-in ecosystem integration/cloud connectors
Automation / Self-Service
Bare Metal Virtualized Containers
Avi Controller
Operational Automation
vRO/vRA
Cisco
CloudCenter
Infrastructure Automation
Confidential │ ©2019 VMware, Inc. 27
VMware NSX Advanced Load Balancer
VMware NSX
Integration
+
Standalone
Multi-cloud
LB & WAF
NSX Data Center NSX Cloud
NSX Service Mesh
VMware Cloud on AWS (VMC)
VMware Horizon & UAG
28
Confidential │ ©2020 VMware, Inc.
Avi NSX-T integration Deep Dive
Confidential │ ©2020 VMware, Inc. 30
Overall Architecture
Avi and NSX-T Integration
NSX-T Manager
Avi management traffic over
secure channel API
vCenter
Avi Controller
Avi UI
API
REST API
ESXI
API
ESXI
Deploy SEs
on ESXi
ESXI
Notifications
Confidential │ ©2020 VMware, Inc. 31
Cloud Creation
Avi and NSX-T Integration
Admin 1. Configure Cloud
2. Fetch NSX-T Inventory
Logical Segments, NSGroups, Transport
Nodes
3. Fetch Content Library
4. Upload SE OVA to content library
NSX-T Manager
vCenter
ESXI ESXI ESXI
1
2
3
4
Avi Controller
Confidential │ ©2020 VMware, Inc. 32
Avi and NSX-T Integration
Demo 2: Virtual Service Creation
NSX-T Manager
vCenter
ESXI ESXI ESXI
Admin 1. Create Virtual Service
2. Create SE VMs & connect SE vNIC to Logical
Switch
3. Deploy SEs on ESXi
4. Create: Routes for VIP elastic scaling,
NSGroups for Avi Objects
1
2
3
Avi Controller
4
Confidential │ ©2020 VMware, Inc. 33
VIP Routes and Scale out automation
Demo 3: SE Auto Scale Out
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE1
Active SEs
S S
Redistribute tier 1 static
routes via BGP
Redistribute static
Routes form VIP subnet
App
Segment
VIP gets placed on one or
more SEs depending on HA
mode configured (Active-
Active in this case)
Static Route:
VIP → SE1
VIP static routes get created on
tier-1 to which the VIP logical
segment is connected
* All HA modes supported
Confidential │ ©2020 VMware, Inc. 34
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE1
Active SEs
S S
Redistribute tier 1 static
routes via BGP
Redistribute static
Routes form VIP subnet
App
Segment
* All HA modes supported
Increase of Traffic
VIP Routes and Scale out automation
Demo 3: SE Auto Scale Out
Confidential │ ©2020 VMware, Inc. 35
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE1
Active SEs
S S
Redistribute tier 1 static
routes via BGP
Redistribute static
Routes form VIP subnet
App
Segment
* All HA modes supported
Increase of Traffic
High CPU
detected
on SE1
VIP Routes and Scale out automation
Demo 3: SE Auto Scale Out
Confidential │ ©2020 VMware, Inc. 36
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE2
SE1
Active SEs
S S
Redistribute tier 1 static
routes via BGP
Redistribute static
Routes form VIP subnet
App
Segment
VIP gets placed on one or
more SEs depending on HA
mode configured (Active-
Active in this case)
Static Route:
VIP → SE1, SE2 data vnic IP
VIP static routes get created on
tier-1 to which the VIP logical
segment is connected
* All HA modes supported
VIP Routes and Scale out automation
Demo 3: SE Auto Scale Out
Confidential │ ©2020 VMware, Inc. 37
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE2
SE1
Active SEs
S S
App
Segment
* All HA modes supported
Avi and NSX-T Integration
Demo 4: Application Backend Scale Out
Confidential │ ©2020 VMware, Inc. 38
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE2
SE1
Active SEs
S S
App
Segment
NSX-T group
updated
* All HA modes supported
S
Avi and NSX-T Integration
Demo 4: Application Backend Scale Out
Confidential │ ©2020 VMware, Inc. 39
Tier-0
Tier-1
VIP/Data
Segment
Pool1
NSX-T Manager
Avi Controller
SE2
SE1
Active SEs
S S
App
Segment
Pool1 updated
NSX-T group
updated
* All HA modes supported
S
Avi and NSX-T Integration
Demo 4: Application Backend Scale Out
Confidential │ ©2021 VMware, Inc. 44
Next Steps
• Contact your VMware Sales representative
• Contact us: learnavi@vmware.com
• Attend one of our 4 days workshop:
https://info.avinetworks.com/workshops#allWorkshops
• Play with AVI via VMware HOL (hands-on Labs): https://labs.hol.vmware.com/
• Download and Install AVI in your own environment:
https://customerconnect.vmware.com/
• AVI docs: https://avinetworks.com/docs
Confidential │ ©2020 VMware, Inc.
Thank You

More Related Content

Similar to Deploying Elastic Self-Service Load Balancing

Cloud_controllers_public_webinar_aug31_v1.pptx
Cloud_controllers_public_webinar_aug31_v1.pptxCloud_controllers_public_webinar_aug31_v1.pptx
Cloud_controllers_public_webinar_aug31_v1.pptxAvi Networks
 
Multi-Cloud Load Balancing – Separating Fact from Fiction
Multi-Cloud Load Balancing – Separating Fact from FictionMulti-Cloud Load Balancing – Separating Fact from Fiction
Multi-Cloud Load Balancing – Separating Fact from FictionAvi Networks
 
What's New VMware NSX Advanced Load Balancer (Avi Networks)
What's New VMware NSX Advanced Load Balancer (Avi Networks)What's New VMware NSX Advanced Load Balancer (Avi Networks)
What's New VMware NSX Advanced Load Balancer (Avi Networks)Avi Networks
 
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...Avi Networks
 
Enabling Remote Employees with Horizon VDI and Avi Networks
Enabling Remote Employees with Horizon VDI and Avi NetworksEnabling Remote Employees with Horizon VDI and Avi Networks
Enabling Remote Employees with Horizon VDI and Avi NetworksAvi Networks
 
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptxAvi Networks
 
Multi Cloud Load Balancing 101 and Hands On Lab
Multi Cloud Load Balancing 101 and Hands On LabMulti Cloud Load Balancing 101 and Hands On Lab
Multi Cloud Load Balancing 101 and Hands On LabAvi Networks
 
VMware Cloud on AWS - 100819.pdf
VMware Cloud on AWS - 100819.pdfVMware Cloud on AWS - 100819.pdf
VMware Cloud on AWS - 100819.pdfAmazon Web Services
 
One And Done Multi-Cloud Load Balancing Done Right.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptxOne And Done Multi-Cloud Load Balancing Done Right.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptxAvi Networks
 
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & PresidioPresidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & PresidioAmazon Web Services
 
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...Avi Networks
 
VMware - HCX - Architecture and Design .pdf
VMware - HCX - Architecture and Design .pdfVMware - HCX - Architecture and Design .pdf
VMware - HCX - Architecture and Design .pdfGiancarloSampaolesi
 
ENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWSENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWSAmazon Web Services
 
VMware Tanzu Service Mesh from the Developer’s Perspective
VMware Tanzu Service Mesh from the Developer’s PerspectiveVMware Tanzu Service Mesh from the Developer’s Perspective
VMware Tanzu Service Mesh from the Developer’s PerspectiveVMware Tanzu
 
Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...
Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...
Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...Amazon Web Services
 
VMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes ConnectVMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes ConnectVMware Tanzu
 
How to Extend Availability to the Application Layer Across the Hybrid Cloud -...
How to Extend Availability to the Application Layer Across the Hybrid Cloud -...How to Extend Availability to the Application Layer Across the Hybrid Cloud -...
How to Extend Availability to the Application Layer Across the Hybrid Cloud -...Veritas Technologies LLC
 
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation Avi Networks
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityMarketingArrowECS_CZ
 

Similar to Deploying Elastic Self-Service Load Balancing (20)

Cloud_controllers_public_webinar_aug31_v1.pptx
Cloud_controllers_public_webinar_aug31_v1.pptxCloud_controllers_public_webinar_aug31_v1.pptx
Cloud_controllers_public_webinar_aug31_v1.pptx
 
Multi-Cloud Load Balancing – Separating Fact from Fiction
Multi-Cloud Load Balancing – Separating Fact from FictionMulti-Cloud Load Balancing – Separating Fact from Fiction
Multi-Cloud Load Balancing – Separating Fact from Fiction
 
What's New VMware NSX Advanced Load Balancer (Avi Networks)
What's New VMware NSX Advanced Load Balancer (Avi Networks)What's New VMware NSX Advanced Load Balancer (Avi Networks)
What's New VMware NSX Advanced Load Balancer (Avi Networks)
 
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
 
Enabling Remote Employees with Horizon VDI and Avi Networks
Enabling Remote Employees with Horizon VDI and Avi NetworksEnabling Remote Employees with Horizon VDI and Avi Networks
Enabling Remote Employees with Horizon VDI and Avi Networks
 
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
 
Multi Cloud Load Balancing 101 and Hands On Lab
Multi Cloud Load Balancing 101 and Hands On LabMulti Cloud Load Balancing 101 and Hands On Lab
Multi Cloud Load Balancing 101 and Hands On Lab
 
VMware Cloud on AWS - 100819.pdf
VMware Cloud on AWS - 100819.pdfVMware Cloud on AWS - 100819.pdf
VMware Cloud on AWS - 100819.pdf
 
One And Done Multi-Cloud Load Balancing Done Right.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptxOne And Done Multi-Cloud Load Balancing Done Right.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptx
 
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & PresidioPresidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
 
Avi workshop-101
Avi workshop-101Avi workshop-101
Avi workshop-101
 
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
 
VMware - HCX - Architecture and Design .pdf
VMware - HCX - Architecture and Design .pdfVMware - HCX - Architecture and Design .pdf
VMware - HCX - Architecture and Design .pdf
 
ENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWSENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWS
 
VMware Tanzu Service Mesh from the Developer’s Perspective
VMware Tanzu Service Mesh from the Developer’s PerspectiveVMware Tanzu Service Mesh from the Developer’s Perspective
VMware Tanzu Service Mesh from the Developer’s Perspective
 
Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...
Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...
Transform Your Business with VMware Cloud on AWS, an Integrated Hybrid Approa...
 
VMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes ConnectVMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes Connect
 
How to Extend Availability to the Application Layer Across the Hybrid Cloud -...
How to Extend Availability to the Application Layer Across the Hybrid Cloud -...How to Extend Availability to the Application Layer Across the Hybrid Cloud -...
How to Extend Availability to the Application Layer Across the Hybrid Cloud -...
 
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivity
 

More from Avi Networks

DR On Demand At Fraction of the Cost (1).pptx
DR On Demand At Fraction of the Cost (1).pptxDR On Demand At Fraction of the Cost (1).pptx
DR On Demand At Fraction of the Cost (1).pptxAvi Networks
 
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load BalancerTop 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load BalancerAvi Networks
 
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptxEnterprises-Have-Replaced-12000-ADCs-See-Why.pptx
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptxAvi Networks
 
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
 Virtualize Application Security Today - Hardware is No Longer Needed.pptx Virtualize Application Security Today - Hardware is No Longer Needed.pptx
Virtualize Application Security Today - Hardware is No Longer Needed.pptxAvi Networks
 
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
Bringing SaaS Simplicity to Proactive Support & Live Threat UpdatesBringing SaaS Simplicity to Proactive Support & Live Threat Updates
Bringing SaaS Simplicity to Proactive Support & Live Threat UpdatesAvi Networks
 
Multi-Cloud Load Balancing 101 and Hands-On Lab
Multi-Cloud Load Balancing 101 and Hands-On LabMulti-Cloud Load Balancing 101 and Hands-On Lab
Multi-Cloud Load Balancing 101 and Hands-On LabAvi Networks
 
Advanced Web Application Security with an Intelligent WAF
Advanced Web Application Security with an Intelligent WAFAdvanced Web Application Security with an Intelligent WAF
Advanced Web Application Security with an Intelligent WAFAvi Networks
 
State of Load Balancing 2020
State of Load Balancing 2020State of Load Balancing 2020
State of Load Balancing 2020Avi Networks
 
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...Avi Networks
 
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud WorldDelivering Applications with Full Lifecycle Automation in a Multi-Cloud World
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud WorldAvi Networks
 
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)Avi Networks
 
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
Accelerating Public Cloud Migration with Multi-Cloud Load BalancingAccelerating Public Cloud Migration with Multi-Cloud Load Balancing
Accelerating Public Cloud Migration with Multi-Cloud Load BalancingAvi Networks
 
Prevent threats With Analytics Driven Web Application Firewall
Prevent threats With Analytics Driven Web Application FirewallPrevent threats With Analytics Driven Web Application Firewall
Prevent threats With Analytics Driven Web Application FirewallAvi Networks
 

More from Avi Networks (13)

DR On Demand At Fraction of the Cost (1).pptx
DR On Demand At Fraction of the Cost (1).pptxDR On Demand At Fraction of the Cost (1).pptx
DR On Demand At Fraction of the Cost (1).pptx
 
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load BalancerTop 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
 
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptxEnterprises-Have-Replaced-12000-ADCs-See-Why.pptx
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
 
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
 Virtualize Application Security Today - Hardware is No Longer Needed.pptx Virtualize Application Security Today - Hardware is No Longer Needed.pptx
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
 
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
Bringing SaaS Simplicity to Proactive Support & Live Threat UpdatesBringing SaaS Simplicity to Proactive Support & Live Threat Updates
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
 
Multi-Cloud Load Balancing 101 and Hands-On Lab
Multi-Cloud Load Balancing 101 and Hands-On LabMulti-Cloud Load Balancing 101 and Hands-On Lab
Multi-Cloud Load Balancing 101 and Hands-On Lab
 
Advanced Web Application Security with an Intelligent WAF
Advanced Web Application Security with an Intelligent WAFAdvanced Web Application Security with an Intelligent WAF
Advanced Web Application Security with an Intelligent WAF
 
State of Load Balancing 2020
State of Load Balancing 2020State of Load Balancing 2020
State of Load Balancing 2020
 
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
 
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud WorldDelivering Applications with Full Lifecycle Automation in a Multi-Cloud World
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
 
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
 
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
Accelerating Public Cloud Migration with Multi-Cloud Load BalancingAccelerating Public Cloud Migration with Multi-Cloud Load Balancing
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
 
Prevent threats With Analytics Driven Web Application Firewall
Prevent threats With Analytics Driven Web Application FirewallPrevent threats With Analytics Driven Web Application Firewall
Prevent threats With Analytics Driven Web Application Firewall
 

Recently uploaded

HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comFatema Valibhai
 
DNT_Corporate presentation know about us
DNT_Corporate presentation know about usDNT_Corporate presentation know about us
DNT_Corporate presentation know about usDynamic Netsoft
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio, Inc.
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...ICS
 
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...soniya singh
 
Project Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanationProject Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanationkaushalgiri8080
 
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)OPEN KNOWLEDGE GmbH
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsAlberto González Trastoy
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVshikhaohhpro
 
The Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfThe Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfPower Karaoke
 
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASEBATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASEOrtus Solutions, Corp
 
why an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfwhy an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfjoe51371421
 
XpertSolvers: Your Partner in Building Innovative Software Solutions
XpertSolvers: Your Partner in Building Innovative Software SolutionsXpertSolvers: Your Partner in Building Innovative Software Solutions
XpertSolvers: Your Partner in Building Innovative Software SolutionsMehedi Hasan Shohan
 
Engage Usergroup 2024 - The Good The Bad_The Ugly
Engage Usergroup 2024 - The Good The Bad_The UglyEngage Usergroup 2024 - The Good The Bad_The Ugly
Engage Usergroup 2024 - The Good The Bad_The UglyFrank van der Linden
 
cybersecurity notes for mca students for learning
cybersecurity notes for mca students for learningcybersecurity notes for mca students for learning
cybersecurity notes for mca students for learningVitsRangannavar
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...gurkirankumar98700
 
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideBuilding Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideChristina Lin
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...OnePlan Solutions
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantAxelRicardoTrocheRiq
 

Recently uploaded (20)

HR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.comHR Software Buyers Guide in 2024 - HRSoftware.com
HR Software Buyers Guide in 2024 - HRSoftware.com
 
DNT_Corporate presentation know about us
DNT_Corporate presentation know about usDNT_Corporate presentation know about us
DNT_Corporate presentation know about us
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
 
Project Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanationProject Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanation
 
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)
 
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time ApplicationsUnveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
Unveiling the Tech Salsa of LAMs with Janus in Real-Time Applications
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
The Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfThe Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdf
 
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...Call Girls In Mukherjee Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
 
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASEBATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
 
why an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfwhy an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdf
 
XpertSolvers: Your Partner in Building Innovative Software Solutions
XpertSolvers: Your Partner in Building Innovative Software SolutionsXpertSolvers: Your Partner in Building Innovative Software Solutions
XpertSolvers: Your Partner in Building Innovative Software Solutions
 
Engage Usergroup 2024 - The Good The Bad_The Ugly
Engage Usergroup 2024 - The Good The Bad_The UglyEngage Usergroup 2024 - The Good The Bad_The Ugly
Engage Usergroup 2024 - The Good The Bad_The Ugly
 
cybersecurity notes for mca students for learning
cybersecurity notes for mca students for learningcybersecurity notes for mca students for learning
cybersecurity notes for mca students for learning
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
 
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideBuilding Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service Consultant
 

Deploying Elastic Self-Service Load Balancing

  • 1. Confidential │ ©2021 VMware, Inc. Live Webinar EMEA Deploying Elastic, Self-Service Load Balancing for VMware NSX-T Nicolas Bayle Technical Evangelist Christoph Altherr VCN Lead Solution Engineer October 21st, 2021
  • 2. Confidential │ ©2020 VMware, Inc. Agenda 2 NSX Data Center – Introduction Avi / NSX Advanced Load Balancer – Introduction Avi & NSX Integration Deep Dive QA Next Steps
  • 3. 3 Confidential │ ©2021 VMware, Inc. VMware NSX Data Center
  • 4. Confidential │ ©2021 VMware, Inc. 4 Leads to security compromises Traditional Network and Security Architectures Realities Complex to insert into the network Unable to dynamically scale Blind spots and lack of controls Inconsistent and unmanageable policy Expensive (HW, SW, maintenance, power, cooling, cabling, rack space,…) IDS/IPS FIREWALL / L3 Gateway LOAD BALANCER ANALYTICS
  • 5. Confidential │ ©2019 VMware, Inc. 5 Traditional network & security approach of the past 20 years Built to meet the needs of specific infrastructure environments (DC, Campus, Branch) What’s needed: A new approach for the next 20+ years Flexible, programmable network fabric designed to run everywhere where applications and data reside
  • 6. Confidential │ ©2021 VMware, Inc. 6 Provides complete coverage and eliminates blind spots NSX distributes Network and Security features to every workload Solution Kernel-based L4-7 FW with Advanced Threat Prevention Distributed architecture eliminates traffic hair pinning Single management console Easy to Deploy - no changes required to physical Agile (automatic policy provisioning / deprovisioning) Consistent policy across all workloads and multi-cloud More cost effective (up to 70%+ savings) IDS/IPS FIREWALL / L3 Gateway LOAD BALANCER ANALYTICS
  • 7. Confidential │ ©2021 VMware, Inc. 7 VMware NSX is the “Network & Security Hypervisor”
  • 8. Confidential │ ©2021 VMware, Inc. 8 NSX Data Center DATA CENTER Virtualization Layer NSX Platform Physical Infrastructure Hypervisor
  • 9. Confidential │ ©2021 VMware, Inc. 9 NSX Data Center DATA CENTER Virtualization Layer NSX Platform Workloads vSwitch
  • 10. Confidential │ ©2019 VMware, Inc. 10 Sysdig 2021 Container Security and Usage Report Source: https://dig.sysdig.com/c/pf-2021-container-security-and-usage-report
  • 11. Confidential │ ©2019 VMware, Inc. 11 Multi-cluster Policy and Visibility from NSX Manager Kubernetes Solution Overview App Dev and Ops K8s Platform Ops Network and Security Ops VMware vSphere Tanzu K8s Cluster Antrea Ingress and ALB Physical/Virtual Servers Upstream K8s Cluster Antrea Ingress and ALB Kubernetes VMware vSphere OCP K8s Cluster Antrea Ingress and ALB NSX NSX-T Security Policies Visibility and Troubleshooting Security Policies within NSX-T for both NSX-T and container cluster endpoints Unified Visibility and Operations across Container and VM Networking and Security Support for Wide Variety of Kubernetes Distributions
  • 12. Confidential │ ©2021 VMware, Inc. 12 Network virtualization and security platform that enables a virtual cloud network across data centers, clouds, and application frameworks What is VMware NSX?
  • 13. 13 ©2020 VMware, Inc. Avi NSX Advanced Load Balancer Intro
  • 14. Confidential │ ©2019 VMware, Inc. 14 Load Balancing Is a Key Blocker for Digital Transformation Not Flexible Not Scalable Not Agile AUTOMATION C H A L L E N G E S Compute Storage Load Balancers Drivers Time to Market Modern Apps Cost Efficiency # Env/Infra # Apps # Changes Increased IT Demands Network
  • 15. Confidential │ ©2019 VMware, Inc. 15 Delivers agility, operational Simplicity, and cost savings To Modern Distributed Architecture Expensive, Inflexible, and Restrictive Hardware/Virtual Load Balancer Challenges Separate control points – operational complexity, hard to automate, painful upgrades Capacity management – manual VIP placement, costly overprovisioning, no fungible capacity Not designed for modern new environments On-premises Cloud Data Center 1 Data Center 2 DEPT1 DEPT2 Active Standby 0% Used Capacity 15% Used Capacity Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Data Plane Control Plane Data Plane Control Plane Data Plane Control Plane Data Plane Control Plane Hard to troubleshoot, finger-pointing between app and network team Network Team App Owners ? Container
  • 16. Confidential │ ©2019 VMware, Inc. 16 Can I have the Best of Both Worlds? The legacy VEs and cloud provider solutions are an unacceptable compromise Load Balancing Challenges/Tradeoffs in the Public Cloud Legacy Virtual LB offers features Cloud Provider LB offers automation & elasticity ? Tradeoff operational simplicity, automation, and cloud-native capabilities Tradeoff features, multi-cloud consistency, and portability
  • 17. Confidential │ ©2019 VMware, Inc. 17 Consistent L4-L7 enterprise-grade app services across multi-cloud environments Avi Networks (now VMware NSX Advanced Load Balancer) App Analytics / Insights Container Ingress Services DNS and IP Address Management (IPAM) Web Application Firewall (WAF) and App Security Global Server Load Balancing (GSLB) Enterprise-grade Load Balancing NSX Horizon(VDI) vSphere/vCenter Deliver Any App on Any Cloud with One Platform VCF VMC Tanzu vRO/vRA
  • 18. Confidential │ ©2019 VMware, Inc. 18 Control Plane Bare Metal Virtualized Containers ON PREMISES PUBLIC CLOUD Centralized policies and full lifecycle management Avi Distributed Architecture for Multi-Cloud Application Services Data Plane Avi Controller (Customer-managed | SaaS) ELASTICITY Application Services Fabric ANALYTICS / OBSERVABILITY AUTOMATION RESILIENCE Avi PULSE CENTRAL ORCHESTRATION
  • 19. Confidential │ ©2019 VMware, Inc. 19 Consistent experience across multi-cloud envs. Single LB Fabric Across Clouds Single Management Point Centrally manage multi-cloud deployments Automate moves, adds, and changes across clouds No feature trade-offs between on-prem vs cloud Manage multi-site deployments with GSLB Bare Metal Virtualized Containers Across On-prem and Public Cloud Avi Controller
  • 20. Confidential │ ©2019 VMware, Inc. 20 v2 Tenant 1 Always Active-Active, automatic failure handling Resilient, Self-Healing Fabric VIPs running on Avi Service Engines Active-Active Per-tenant/per-app LB-tenant isolation Service Engines (SE) are deployed in Active-Active configuration with anti- affinity rules Automatically moves VIPs if SE fails (e.g. accidental power off) and instantiates new SE Traffic is automatically rerouted with moves and changes Avi Controller Tenant 2
  • 21. Confidential │ ©2019 VMware, Inc. 21 Flexible, Non-Disruptive Upgrades Tenant 1 Tenant 3 Tenant 2 v1 v1 v1 v1 v2 v2 Facilitates partial (non-disruptive) upgrades Upgrade select tenants or SE groups within tenant to V2 (after controller upgrade or later time) • Upgrade Tenant-2, Tenant-3 (SE group 3) to V2 • Config allowed, but any config changes to VSs in these SE groups are queued until SE group upgrade is completed • Upgrade other tenants or SE groups weeks later Rollbacks of Controller and SEs supported Avi Controller
  • 22. Confidential │ ©2019 VMware, Inc. 22 Simplify troubleshooting, eliminate TCP Dumps Analytics and App Insights Eliminate finger-pointing Troubleshoot app performance, security and end-user issues in minutes Bare Metal Virtualized Containers Avi Controller • Connection log analytics • Security insights: DDoS • App performance metrics • End user experience End-to-End Timing Total Response Time End User Client RTT Server RTT App Response Load Balancer Server App
  • 23. Confidential │ ©2019 VMware, Inc. 23 Simplify troubleshooting, eliminate TCP Dumps Analytics and App Insights Bare Metal Virtualized Containers Eliminate finger-pointing Troubleshoot app performance, security and end-user issues in minutes Avi Controller • App performance metrics • End user experience • Connection log analytics • Security insights: DDoS End-to-End Timing Total Response Time End User Client RTT Server RTT App Response Load Balancer Server App
  • 24. Confidential │ ©2019 VMware, Inc. 24 Simplify troubleshooting, eliminate TCP Dumps Analytics and App Insights Bare Metal Virtualized Containers Eliminate finger-pointing Troubleshoot app performance, security and end-user issues in minutes Avi Controller • App performance metrics • End user experience • Connection log analytics • Security insights: DDoS End-to-End Timing Total Response Time End User Client RTT Server RTT App Response Load Balancer Server App
  • 25. Confidential │ ©2019 VMware, Inc. 25 Scale vertically with more CPUs or horizontally with more Service Engines Elastic Autoscaling 2x 1-core SEs 32x 1-core SEs 1 core 2,500 SSL TPS 5,000 SSL TPS 1M SSL TPS Scale to millions of TPS or hundreds of GBs of throughput
  • 26. Confidential │ ©2019 VMware, Inc. 26 Built-in ecosystem integration/cloud connectors Automation / Self-Service Bare Metal Virtualized Containers Avi Controller Operational Automation vRO/vRA Cisco CloudCenter Infrastructure Automation
  • 27. Confidential │ ©2019 VMware, Inc. 27 VMware NSX Advanced Load Balancer VMware NSX Integration + Standalone Multi-cloud LB & WAF NSX Data Center NSX Cloud NSX Service Mesh VMware Cloud on AWS (VMC) VMware Horizon & UAG
  • 28. 28 Confidential │ ©2020 VMware, Inc. Avi NSX-T integration Deep Dive
  • 29. Confidential │ ©2020 VMware, Inc. 30 Overall Architecture Avi and NSX-T Integration NSX-T Manager Avi management traffic over secure channel API vCenter Avi Controller Avi UI API REST API ESXI API ESXI Deploy SEs on ESXi ESXI Notifications
  • 30. Confidential │ ©2020 VMware, Inc. 31 Cloud Creation Avi and NSX-T Integration Admin 1. Configure Cloud 2. Fetch NSX-T Inventory Logical Segments, NSGroups, Transport Nodes 3. Fetch Content Library 4. Upload SE OVA to content library NSX-T Manager vCenter ESXI ESXI ESXI 1 2 3 4 Avi Controller
  • 31. Confidential │ ©2020 VMware, Inc. 32 Avi and NSX-T Integration Demo 2: Virtual Service Creation NSX-T Manager vCenter ESXI ESXI ESXI Admin 1. Create Virtual Service 2. Create SE VMs & connect SE vNIC to Logical Switch 3. Deploy SEs on ESXi 4. Create: Routes for VIP elastic scaling, NSGroups for Avi Objects 1 2 3 Avi Controller 4
  • 32. Confidential │ ©2020 VMware, Inc. 33 VIP Routes and Scale out automation Demo 3: SE Auto Scale Out Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE1 Active SEs S S Redistribute tier 1 static routes via BGP Redistribute static Routes form VIP subnet App Segment VIP gets placed on one or more SEs depending on HA mode configured (Active- Active in this case) Static Route: VIP → SE1 VIP static routes get created on tier-1 to which the VIP logical segment is connected * All HA modes supported
  • 33. Confidential │ ©2020 VMware, Inc. 34 Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE1 Active SEs S S Redistribute tier 1 static routes via BGP Redistribute static Routes form VIP subnet App Segment * All HA modes supported Increase of Traffic VIP Routes and Scale out automation Demo 3: SE Auto Scale Out
  • 34. Confidential │ ©2020 VMware, Inc. 35 Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE1 Active SEs S S Redistribute tier 1 static routes via BGP Redistribute static Routes form VIP subnet App Segment * All HA modes supported Increase of Traffic High CPU detected on SE1 VIP Routes and Scale out automation Demo 3: SE Auto Scale Out
  • 35. Confidential │ ©2020 VMware, Inc. 36 Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE2 SE1 Active SEs S S Redistribute tier 1 static routes via BGP Redistribute static Routes form VIP subnet App Segment VIP gets placed on one or more SEs depending on HA mode configured (Active- Active in this case) Static Route: VIP → SE1, SE2 data vnic IP VIP static routes get created on tier-1 to which the VIP logical segment is connected * All HA modes supported VIP Routes and Scale out automation Demo 3: SE Auto Scale Out
  • 36. Confidential │ ©2020 VMware, Inc. 37 Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE2 SE1 Active SEs S S App Segment * All HA modes supported Avi and NSX-T Integration Demo 4: Application Backend Scale Out
  • 37. Confidential │ ©2020 VMware, Inc. 38 Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE2 SE1 Active SEs S S App Segment NSX-T group updated * All HA modes supported S Avi and NSX-T Integration Demo 4: Application Backend Scale Out
  • 38. Confidential │ ©2020 VMware, Inc. 39 Tier-0 Tier-1 VIP/Data Segment Pool1 NSX-T Manager Avi Controller SE2 SE1 Active SEs S S App Segment Pool1 updated NSX-T group updated * All HA modes supported S Avi and NSX-T Integration Demo 4: Application Backend Scale Out
  • 39. Confidential │ ©2021 VMware, Inc. 44 Next Steps • Contact your VMware Sales representative • Contact us: learnavi@vmware.com • Attend one of our 4 days workshop: https://info.avinetworks.com/workshops#allWorkshops • Play with AVI via VMware HOL (hands-on Labs): https://labs.hol.vmware.com/ • Download and Install AVI in your own environment: https://customerconnect.vmware.com/ • AVI docs: https://avinetworks.com/docs
  • 40. Confidential │ ©2020 VMware, Inc. Thank You