Monday, November 11, 2013

ACI Launch

Tech Field Day brought me to the Cisco Application Centric Infrastructure launch event last week in New York. I attended at someone else's expense, but that doesn't mean my opinions are for sale, etc...

If you're totally unfamiliar with ACI (formerly Insieme), I recommend listening to Episode 12 of the Class C Block podcast with guest Joe Onisick. This was far more informative than anything I encountered at the actual launch event, probably because the Tech Field Day crew went straight from the John Chambers presentation into a room where we recorded a roundtable discussion. There may have been some technical discussion going on next door, but I missed it.

There's no shortage of people expressing opinions about ACI and what it will or won't do for you, most of whom have beaten me to the punch by several days. I'm going to post instead about a few details of the launch that I found interesting.

Defining Policy Might Not Be Easy
ACI requires that applications (really application owners) express to it the relationships between nodes before any traffic is allowed to flow. There are countless ways this might happen, but they all boil down to figuring out which ports on virtual or physical switches need to communicate to make the application run. There are the obvious flows, like the ones between middleware and database, and then the less obvious ones like syslog, DHCP, DNS, RADIUS, etc... All communications will need to be identified to the ACI controller, and I worry that it will turn out to be nontrivial.

While commercial applications generally have their requirements spelled out pretty clearly for firewall purposes, I've found that in-house applications often do not. The application developers know their components, but often don't know what's really happening under the covers. Too often I have conversations about firewall policy that include statements like the following: "It's not UDP or TCP. I keep telling you, I'm using an MQ library!"

Canned Policies?
Somebody (I think it was Pete Welcher?) speculated that software vendors might decide to ship ACI policies with their products. In the same way that we deploy virtual appliances, large software packages could come with canned ACI policies. That would certainly make things easy for rollout of a multi-tier software package onto an ACI environment.

Ultimately, The Policy Expresses What Now?
If I understand things correctly, the policy exists to fit switchports into categories and then to express which categories of ports may talk to one another. The categorization can be based on all sorts of criteria including things that might be reminiscent of firewall policy. The Cisco folks even evoke firewall notions when they explain that the system defaults to no communication: "Hosts can't talk without a policy explicitly allowing it."

The security angle is compelling, but don't confuse it with a packet filter. Think of it more like a policy which assigns assets to VLANs in a router-free environment. Once the assignment is done, any and all communication is possible between assets which have been bucket-ized together. The "express communication requirements to the network in application terms" business isn't a packet filter.

About ASICs
Cisco's "merchant silicon plus" strategy with the Nexus 9500 speaks volumes about the future of packet forwarding hardware. There's a proud tradition of using in-house ASICs at Cisco, and they're backing away from it. Sure, they're shipping ACI-specific hardware along with the Broadcom Trident II. It does things that the Broadcom Trident II can't do, like routing between VXLAN and NVGRE overlays. I'm betting that the ACI-specific hardware will sit completely idle at a large percentage of customers, meaning that the Nexus 9500 is a commodity switch running stripped down (there was a slide about this, but I can't find a citation - edit: Gideon Tam shares this slide from the presentation) version of NX-OS.

Fabric Modules
Nexus 7000 fabric modules aren't much to look at. They're inexpensive (compared to the rest of the platform components), don't generate much heat, etc... Nexus 9500 represents a big departure from the arbiter-controlled fabric of the 7000 series, because they've got switching ASICs (two to four Trident IIs per fabric module) onboard, making the Nexus 95xx a "clos-in-a-box" architecture. I'm anxious to see the packet walk for multicast and broadcast traffic from the Cisco Live presentation next year.

No Midplane
Apparently the 9500 is entirely open from front to back, which is new for Cisco. I guess the line cards and fabric modules connect directly to one another (I haven't seen it yet). This is nifty, because it allows front-to-back airflow without lots of crazy ducting like the Nexus 7010, which seems like it's half duct/half switch.

BiDi Optics
This is cool stuff. Is it unique to Cisco? There's no QSFP module with an LC connector listed on Finisar's site right now.

These modules run 40Gb/s Ethernet for up to 150m over just two strands of MMF. Prior to the introduction of this module, 40Gb/s Ethernet required a 12 strand MPO connector. I've been advising customers for years to populate their data centers with pre terminated MPO stuff, I particularly like the high density offerings from Corning.

Customers who already have MPO don't have any worries, but for folks with minimal LC connectors at top of rack, Cisco claims their QSFP-40G-SR-BD module is a big cost saver because no new fiber needs to be installed for the upgrade from 10Gb/s to 40Gb/s. Yes, the idea of saving money with Cisco optics is hilarious. :) Pricing isn't out yet.

12 comments:

  1. The latest version of Delta Executor also includes internal fixes that help reduce lag and unexpected shutdowns. These behind‑the‑scenes optimizations make the tool more dependable compared to older versions.
    https://deltaapk.com.mx/

    ReplyDelete
  2. win rupes is an emerging online earning platform in Pakistan designed for users who want to monetize their spare time through mobile gaming. The website offers a variety of simple, interactive games that allow users to earn rewards and cash prizes without needing professional gaming skills. With a focus on local accessibility, WinRupees stands out by offering seamless withdrawal options through popular Pakistani payment gateways like Easypaisa and JazzCash.

    ReplyDelete
  3. It’s interesting to see how these concepts continue to influence modern data center design, and many professionals now focus on building deeper expertise through structured paths like Arista training to better understand evolving network architectures and automation.

    ReplyDelete
  4. A good online platform is not only about appearance but also about usability and performance. Many visitors appreciate how 2888pak login provides a straightforward browsing experience without unnecessary complications, making it easy for both new and experienced users to navigate comfortably.

    ReplyDelete
  5. Another reason behind the growing popularity of pkrspin login is its focus on user convenience and responsive performance. The platform supports commonly used payment methods in Pakistan and offers a straightforward setup process that allows users to start quickly without unnecessary complications.

    ReplyDelete
  6. Consistency in branding builds recognition over time. Using Letras Diferentes helps maintain a cohesive look across all social media platforms. By adopting unique fonts that match your brand’s tone, you reinforce your identity and make your content instantly recognizable. Over time, this consistency strengthens your brand image, increases trust among followers, and creates a lasting impression in the digital space. https://letrasdiferent.com.br/

    ReplyDelete
  7. I also find it impressive how virtual events create opportunities for people from different countries and professional backgrounds to connect with one another. These interactions Pk1947 Game lead to new ideas, collaborations, and long-term professional relationships that may not have been possible otherwise. Another important advantage of online learning is the ability to revisit information whenever needed. Recorded sessions, shared resources, and digital materials allow participants to review concepts multiple times, making it easier to fully understand complex topics.

    ReplyDelete
  8. 여러 장점을 고루 갖춘 유용한 정보라고 생각합니다. 비용 부담을 줄이는 데 도움이 되었고 상품권할인 혜택을 활용하면서 만족스러운 소비 경험을 할 수 있었습니다.

    ReplyDelete
  9. 사용하지 않던 상품권을 새로운 용도로 활용할 수 있어 좋았습니다. 빠른 진행과 편한 절차가 장점이며 상품권매입 이용한 뒤에는 관리가 더욱 쉬워지고 실생활에서 활용도가 높아지는 점이 만족스러웠습니다.

    ReplyDelete
  10. 시간 활용의 폭이 넓고 자신의 계획에 맞게 업무를 조절할 수 있다는 점이 큰 장점입니다. 밤알바 관련 정보를 확인하면서 다양한 기회를 알아볼 수 있었고 경제적인 부분뿐 아니라 새로운 경험과 자신감을 얻는 데도 긍정적인 영향을 줍니다.

    ReplyDelete
  11. 피곤한 일상 속에서 효율적으로 휴식을 챙길 수 있는 좋은 선택이었습니다. 출장마사지 서비스를 이용한 후 컨디션이 한결 좋아진 느낌이라 추천하고 싶습니다.

    ReplyDelete
  12. Thobe (thawb), similar to how it is originally an Arabic word meaning garment, is also a native tradition of Arab countries. However, with the rising trend of thobes now spreading across the globe, this customary tradition has contemporarily transitioned into a fashion testament.
    Men Thobes UK

    ReplyDelete