NKN - National Geophysical Research Institute

advertisement
CSIR
Vi t l Private
Virtual
P i t Network
N t
k
Over NKN
PIU, NKN
1
NKN TOPOLOGY
2
3
Application Requiring High Bandwidth
ƒ Virtual Laboratories
ƒ Collaborative Mega Science Projects
ƒ Innovative Info-Bio-Nano Experiments
ƒ Non-invasive
Non invasive Medicare for Diseases like Cancer
ƒ Diagnostic Domes as Public Health Centers in Rural
Areas
ƒ Country-wide Classroom
ƒ University without Walls
ƒ Voice Conferencing among Researchers
ƒ Video
Vid C
Conferencing
f
i among R
Researchers
h
ƒ On-line access to Electronic Resources
4
NKN Design Philosophy
ƒ To build a scalable network, which can expand both in
the Reach ((spread
p
in the country)
y) and Speed.
p
ƒ To be a common Network Backbone like national
highway, wherein different categories of users shall be
supported.
5
Features NKN
ƒ High Capacity
Capacity, Highly Scalable Backbone
ƒ Provide Quality of Service (QoS) and Security
ƒ Wide
Wid Geographical
G
hi l Coverage
C
ƒ Common Standard Platform
ƒ Bandwidth from Many NLD’s
ƒ Highly Reliable & Available by Design
ƒ Test beds ( for various implementation)
ƒ Dedicated
ed cated a
and
dO
Owned.
ed
6
NKN CLOUD
Educational
Ed
ti
l
Institutions
Research Labs
CSIR/DAE/ISRO/ICAR
NTRO
Cert-IN
EDUSAT
National
N
ti
l
Internet
Exchange
P i t (NIXI)
Points
NKN
INTERNET
Connections to
Global Networks
((e.g.
g GEANT))
MPL
S
Clou
ds
Broad Band
Clouds
National / State
Data Centers/ Networks
Fig-1 GENERIC MPLS CLOUD OF NKN
7
NKN offering MPLS VPN
CSIR
Rajasthan
CSIR
Orissa
MCU
CSIR
hyderabad
VOD
Server
CSIR Delhi
DNS
CSIR Roorkee
CSIR
Chennai
ISP
Internet
Internet
Gateway
NKN
MPLS - VPN Network
Internet
Gateway
ISP
Internet
CSIR
Gujarat
CSIR
Guwahati
CSIR
Kanpur
CSIR
Kharagpur
CSIR
Patna
Fig-2 CSIR VPN
CSIR
Mumbai
8
What NKN will provide?
ƒ Bandwidth
ƒ Availability and reliability
ƒ IP space/ Interface with the APNIC
ƒ NOC and DC
ƒ DR NOC and DC
ƒ 24 X 7 Support operations support
ƒ Common Services like Web/Mail/ MX/DNS etc.
ƒ All the
h MPLS VPN V4 / V6 and
d L2 VPN support.
ƒ Guidelines and Procedures to effectively use the NKN.
ƒR
Routing/
ti / S
Switching
it hi equipment
i
t att th
the end
d node
d tto
connect to the NKN.
9
What will NKN provide? Contd.
ƒ Internet bandwidth
ƒ Interface with other networks ( EU-GRID and others.)
ƒ Applications like Video on Demand would be hosted on
the Data Center
ƒ Any other PORTAL / APPLICATION is deemed fit to be
kept at Data center of NKN for efficient usage
10
Criterion to join NKN
ƒ Must
M t be
b aK
Knowledge
l d C
Creator
t
ƒ Participate in any of the killer applications that is
envisaged
ƒ Minimum bandwidth interface will be 100 Mbps
ƒ Must
M t comply
l tto the
th policies
li i off NKN
–IP Usage Policy
- Operations policy
–Security
y Policy
y
11
What logistics are expected from End
Nodes
ƒ Space for equipments. ( Router/ switch/ ups/ Racks from
NLD) Typically 12’ X 12’ kind of space.
ƒ Air- Conditioned Environment
ƒU
UPS
S (5 KVA & 10
0 KVA Based
ased o
on router
oute supplied)
supp ed)
ƒ 24 X 7 access to NKN personnel or persons authorized
by NKN.
ƒ Seating space for one NKN appointed person.
12
What logistics are expected from End
Nodes Contd..
ƒ Safety of the equipments supplied under NKN
NKN.
ƒ Cabling with in the user location for connecting to the
NKN router.
ƒ Right of Way with in the User Campus for cabling to be
done by the long distance providers.
ƒ Nodal Officer appointed will be the single point of
interface for NKN.
ƒ ( Passion to NKN)
13
What NKN will not provide?
ƒ Training
g / Troubleshooting
g on applications
pp
which are run
internally by the end user.
ƒ Interfacing with the end nodes which are not directly
connected to the NKN (this includes broadband users
users, any
end node of other MPLS cloud)
ƒ Campus
p LAN support
pp / maintenance inside the End Nodes (
whether connected directly or indirectly to NKN)
ƒ Addressing security issues inside the END NODES.
14
Start Using
g NKN by
y creating
ga
VPN connecting all the CSIRs
Objective:
Obj ti
Objective:
To
T enable
bl CSIRs
CSIR to
t advertise
d ti
the exisiting public IP segments (leased
from ISPs) through NKN so that NKN
connected institutes can reach any of the
advertised public IPs through NKN links
rather than spin around through ISPs
15
NKN link already in the institute and the NKN
router is presently configured as a MPLS PE
PE.
ƒ Assumption: The Virtual Classrooms are on the NKN IP
segment. Normally,
segment
Normally the Institute's
Institute s campus LAN segments
are terminated at a Core Switch, typically installed in the
Computer Centre (CC). Internet access is provided through
P /Fi
Prxy/Firewall/UTM
ll/UTM d
devices.
i
ƒ
ƒ The Institutes router (which is connected to ISP) shall be
capable of peering a BGP session with NKN router and the
Institute router shall announce p
public IP segments
g
to this
BGP session. This will help the other institutes in the NKN
cloud to reach the public IPs (hence webserver and other
content enabled services) through NKN link
link.
16
How Do I start using the link immediately:
Currently, NKN provides IP segments from RFC 1918
Currently
1918'ss 10.n.n.n.
10 n n n
These IP segments could clash with the exisiting assigned
segment in the Institutes and re-assigning of the NKN suggested
segments may be a daunting task.
task However,
However for the specified
projects, the NKN suggested IP segments can be assigned from
the day one.
Connect the NKN router to the Institute's gateway router.
Configure the gateway router to do a BGP session with NKN
router and announce the public segment (normally provided by the
ISP). This link at the NKN router is configured to be in VRF
instance called NKNGEN.
The public IPs are announced through the NKN who are part of
this VRF instance NKNGEN. This way every CSIR's can
announce their public IP segments in NKN and hence all the
Institutes which are part of the VRF NKNGEN can reach the
respective CSIRs public segment through NKN.
17
How Do I start using the link immediately:
IIn case the
th NKN links
li k to
t the
th Institutes
I tit t fails,
f il the
th routes
t (public
( bli
segments) will automatically ceases to exist and reachability to
the Institute's public segment falls back through ISP link. In case
off NKN link
li k failure
f il
th routes
the
t from
f
th NKN CLOUD will
the
ill cease to
t
exist and thereby the gateway of the institutes will start using the
Internet link that they have for normal browsing. This way the
i t
internet
t is
i being
b i delivered
d li
d through
th
h the
th existing
i ti provider.
id
To Achieve Fig-1 and Fig-3, and Fig-3 the CSIRs must connect
the NKN router to the CC router and announce the IP number
allocated to them either from the ISP ( currently providing the
Internet) or ERNET to NKN.
If the CSIR wants to announce some resource, then it can be
made available to all the others in NKN. The resource can be kept
at the CSIR itself or could be transferred to DATA CENTER
proposed in NKN.
18
EXISTING ISP NKN
NKN Router Placed inside
the institute
MAIL server WWW server Link between NKN – CSIR
GW
Layer 3 switch
Proxy server Virtual Class Room on NKN private IP
IInstitute Campus IP schema is tit t C
IP h
i
not changed in the existing setup
OSDD LAB with IP OSDD
LAB ith IP
schema which already exists
Fig‐ 3 Inside the Institute 19
Internet Browsing Only using
the NKN:
Objective: Using Internet facility
O
f
on an
immediate basis through NKN.
Refer Fig 4
20
How Do I start using Internet using the NKN:
Assumption: The Public IP number provided by ISP
deployed currently.
In case the institute wants to have the internet facility from
the NKN, then the following needs to be done:
The proxy server must have the real IP provided to the
institute as a part of NKN. This IP shall be advertised by
the NKN to the Internet world and hence the browsing is
made possible through the NKN link.
link During this,
this any
failure in the NKN link will result in proxy not getting
internet connectivity.
The other resources like the web site / mail server etc will
still use the ISP as the IP numbers belong to the ISP and
has been leased out to the institute.
institute
Refer Fig 4
21
EXISTING ISP NKN
NKN Router Placed inside
the institute
MAIL server Link between NKN – CSIR
GW
WWW server External Interface with NKN public IP Proxy server Proxy server Layer 3 switch
IInstitute Campus IP schema is tit t C
IP h
i
not changed in the existing setup
Virtual Class Room on NKN private IP
Block 1
GARUDA LAB with GARUDA
LAB ith
IP schema which already exists
Block 2
Block N
Fig‐ 4 Using a Proxy with NKN ext IP for browsing purpose. 22
Using the NKN when the USER has
PUBLIC IP from APNIC/ ARIN:
That is: /24 or more from APNIC/ARIN
23
Using the NKN when USER has PUBLIC IP
from APNIC/ ARIN:
The following are the assumptions for scenario in (Fig5):
•User
User with public IP pool
•Multi-homing to NKN & other ISP with separate local routers
(running BGP between them).
USER Requirement
R
i
t
•Primary (NKN) ISP & Backup (non-NKN) ISP
•Exit/Entryy via Primaryy or Backup on Primaryy Fails
Solution for preferred exit point
•Mark updates from NKN only with higher local preference.
Solution for preferred entry point
•Advertise self public pool with AS ( number of NKN itself) path
prepend to other ISP only and to NKN have a ibgp session.
NKN’ Role
NKN’s
R l
•Accept only end node’s prefixes & filter
•Advertise to the Internet with the ISPs connected to NKN
24
EXISTING ISP NKN
Institute has IP number (public) provided by APNIC
(public) provided by APNIC / ARIN
iBGP between the
NKN – CSIR GW
MAIL server WWW server NKN Router Placed inside
the institute
External Interface with NKN public IP Proxy server Proxy server Layer 3 switch
Virtual Class Room on NKN private IP
Block 1
GARUDA LAB with GARUDA
LAB ith
IP schema which already exists
Block 2
Block N
Institute Campus IP schema is not changed in the existing g
g
setup
Fig‐ 5 institutes having their own PUBLIC IP from APNIC/ARI N
25
Fanning-Out
NKN
P P
PoP
NKN
P P
PoP
E i
Engineering
i
collège
Poly--tech
Poly
Egress NKN Router
NKN
Cloud
Ingress NKN Router
Some NLD
providing
connectivity
Médical
collège
Education
community
VPN Green Site
DAE LAB
VPN Blue Site
BIO TECH
PE -NKN
NKN
MAIN UNIVERSITY
With IN CAMPUS
Colleges/ dpts
26
Short Term Migrating to NKN
LAB #1
NKN IP Address
Scheme
Internet
Service
Provider
NKN IP Address
Scheme
LAB #4
124.124.1.0-255
202.141.40.0-255
NKN RESOURCE
DATA CENTER
NKN
CLOUD
Internet
Service
Provider
Internet
Service
Provider
121.121.240.0-255
NKN IP Address
Scheme
NKN IP Address
Scheme
203.197.140.0-255
LAB #2
LAB #3
27
Migrating to NKN
Institute #1
NKN IP SCHEMA
CWCR
Internet
Service
Provider
NKN IP SCHEMA
CWCR
Institute #4
124.124.1.0-255
202.141.40.0-255
NKN RESOURCE
DATA CENTER
NKN
CLOUD
Internet
Service
Provider
Internet
Service
Provider
121.121.240.0-255
NKN IP SCHEMA
CWCR
NKN IP SCHEMA
CWCR
203.197.140.0-255
Institute #2
Institute #3
28
Short Term Migration
ƒ Each one of the closed user group can
g the NKN. ( It
advertise the IP numbers through
will be the Public IP given to the organisation
by the ISP currently engaged.)
ƒ A separate VRF will be created which will allow
the organisation to browse the others in the
closed
l
d user group.
ƒ This will also provide Internet facility.
ƒ Provision can also be made on a short term
basis for public IP for the organisation from
NKN to cater to the PUBLIC/ INTERNET
demands.
29
Killer Applications
ƒ Peer to Peer Collaboration
ƒ Desktop Video
ƒ Enterprise ERP
ƒ Central Web Based Applications
ƒ Library resources
ƒ MOST IMPORTANTLY A DESIGN THAT
CAN CATER TO FURTURE
INOOVATIVE IDEAS
30
HOW TO CONNECT EXISTING
GARUDA LAB TO NKN?
31
HOW TO CONNECT GARUDA LABS?
GARUDA: It has been decided to provide the bandwidth to
Garuda through NKN. It is important that the LAB taking
part in the GARUDA project gets a link from the router
provided to the institutions through NKN project.
Suggestion:
The LAB has to extend the link from the NKN router which
in many cases will be in the Computer Center and in some
cases it could be a part of some other project like ERNET
PoP.
The approximate distance is 0-2 KM in most cases.
Connect the cable provided to the NKN router in the
institute and Garuda LAB. ( responsibility of GARUDA)
32
NKN
ISP
Reliance/Bharti/TATA
New Delhi/Hyderabad
Internet Gateway
Primary For NKN
Institute Institute
Tier‐1/2/3 POP
PE Router
ISP
Backup
PE
Institute Network
Tier‐1/2/3 POP
PE Routers
NKN MPLS Backbone
Tier‐1/2 POP
PE Router
Proxy server MAIL server WWW server Tier‐1 POP
P Router
GARUDA LAB
Details within the INSTITUTE
Internal Cabling
Fig: 6 Connecting Garuda lab to NKN
33
THANK YOU
For further information:
Contact: piu@nkn.in
34
Download