CSIR Vi t l Private Virtual P i t Network N t k Over NKN PIU, NKN 1 NKN TOPOLOGY 2 3 Application Requiring High Bandwidth Virtual Laboratories Collaborative Mega Science Projects Innovative Info-Bio-Nano Experiments Non-invasive Non invasive Medicare for Diseases like Cancer Diagnostic Domes as Public Health Centers in Rural Areas Country-wide Classroom University without Walls Voice Conferencing among Researchers Video Vid C Conferencing f i among R Researchers h On-line access to Electronic Resources 4 NKN Design Philosophy To build a scalable network, which can expand both in the Reach ((spread p in the country) y) and Speed. p To be a common Network Backbone like national highway, wherein different categories of users shall be supported. 5 Features NKN High Capacity Capacity, Highly Scalable Backbone Provide Quality of Service (QoS) and Security Wide Wid Geographical G hi l Coverage C Common Standard Platform Bandwidth from Many NLD’s Highly Reliable & Available by Design Test beds ( for various implementation) Dedicated ed cated a and dO Owned. ed 6 NKN CLOUD Educational Ed ti l Institutions Research Labs CSIR/DAE/ISRO/ICAR NTRO Cert-IN EDUSAT National N ti l Internet Exchange P i t (NIXI) Points NKN INTERNET Connections to Global Networks ((e.g. g GEANT)) MPL S Clou ds Broad Band Clouds National / State Data Centers/ Networks Fig-1 GENERIC MPLS CLOUD OF NKN 7 NKN offering MPLS VPN CSIR Rajasthan CSIR Orissa MCU CSIR hyderabad VOD Server CSIR Delhi DNS CSIR Roorkee CSIR Chennai ISP Internet Internet Gateway NKN MPLS - VPN Network Internet Gateway ISP Internet CSIR Gujarat CSIR Guwahati CSIR Kanpur CSIR Kharagpur CSIR Patna Fig-2 CSIR VPN CSIR Mumbai 8 What NKN will provide? Bandwidth Availability and reliability IP space/ Interface with the APNIC NOC and DC DR NOC and DC 24 X 7 Support operations support Common Services like Web/Mail/ MX/DNS etc. All the h MPLS VPN V4 / V6 and d L2 VPN support. Guidelines and Procedures to effectively use the NKN. R Routing/ ti / S Switching it hi equipment i t att th the end d node d tto connect to the NKN. 9 What will NKN provide? Contd. Internet bandwidth Interface with other networks ( EU-GRID and others.) Applications like Video on Demand would be hosted on the Data Center Any other PORTAL / APPLICATION is deemed fit to be kept at Data center of NKN for efficient usage 10 Criterion to join NKN Must M t be b aK Knowledge l d C Creator t Participate in any of the killer applications that is envisaged Minimum bandwidth interface will be 100 Mbps Must M t comply l tto the th policies li i off NKN –IP Usage Policy - Operations policy –Security y Policy y 11 What logistics are expected from End Nodes Space for equipments. ( Router/ switch/ ups/ Racks from NLD) Typically 12’ X 12’ kind of space. Air- Conditioned Environment U UPS S (5 KVA & 10 0 KVA Based ased o on router oute supplied) supp ed) 24 X 7 access to NKN personnel or persons authorized by NKN. Seating space for one NKN appointed person. 12 What logistics are expected from End Nodes Contd.. Safety of the equipments supplied under NKN NKN. Cabling with in the user location for connecting to the NKN router. Right of Way with in the User Campus for cabling to be done by the long distance providers. Nodal Officer appointed will be the single point of interface for NKN. ( Passion to NKN) 13 What NKN will not provide? Training g / Troubleshooting g on applications pp which are run internally by the end user. Interfacing with the end nodes which are not directly connected to the NKN (this includes broadband users users, any end node of other MPLS cloud) Campus p LAN support pp / maintenance inside the End Nodes ( whether connected directly or indirectly to NKN) Addressing security issues inside the END NODES. 14 Start Using g NKN by y creating ga VPN connecting all the CSIRs Objective: Obj ti Objective: To T enable bl CSIRs CSIR to t advertise d ti the exisiting public IP segments (leased from ISPs) through NKN so that NKN connected institutes can reach any of the advertised public IPs through NKN links rather than spin around through ISPs 15 NKN link already in the institute and the NKN router is presently configured as a MPLS PE PE. Assumption: The Virtual Classrooms are on the NKN IP segment. Normally, segment Normally the Institute's Institute s campus LAN segments are terminated at a Core Switch, typically installed in the Computer Centre (CC). Internet access is provided through P /Fi Prxy/Firewall/UTM ll/UTM d devices. i The Institutes router (which is connected to ISP) shall be capable of peering a BGP session with NKN router and the Institute router shall announce p public IP segments g to this BGP session. This will help the other institutes in the NKN cloud to reach the public IPs (hence webserver and other content enabled services) through NKN link link. 16 How Do I start using the link immediately: Currently, NKN provides IP segments from RFC 1918 Currently 1918'ss 10.n.n.n. 10 n n n These IP segments could clash with the exisiting assigned segment in the Institutes and re-assigning of the NKN suggested segments may be a daunting task. task However, However for the specified projects, the NKN suggested IP segments can be assigned from the day one. Connect the NKN router to the Institute's gateway router. Configure the gateway router to do a BGP session with NKN router and announce the public segment (normally provided by the ISP). This link at the NKN router is configured to be in VRF instance called NKNGEN. The public IPs are announced through the NKN who are part of this VRF instance NKNGEN. This way every CSIR's can announce their public IP segments in NKN and hence all the Institutes which are part of the VRF NKNGEN can reach the respective CSIRs public segment through NKN. 17 How Do I start using the link immediately: IIn case the th NKN links li k to t the th Institutes I tit t fails, f il the th routes t (public ( bli segments) will automatically ceases to exist and reachability to the Institute's public segment falls back through ISP link. In case off NKN link li k failure f il th routes the t from f th NKN CLOUD will the ill cease to t exist and thereby the gateway of the institutes will start using the Internet link that they have for normal browsing. This way the i t internet t is i being b i delivered d li d through th h the th existing i ti provider. id To Achieve Fig-1 and Fig-3, and Fig-3 the CSIRs must connect the NKN router to the CC router and announce the IP number allocated to them either from the ISP ( currently providing the Internet) or ERNET to NKN. If the CSIR wants to announce some resource, then it can be made available to all the others in NKN. The resource can be kept at the CSIR itself or could be transferred to DATA CENTER proposed in NKN. 18 EXISTING ISP NKN NKN Router Placed inside the institute MAIL server WWW server Link between NKN – CSIR GW Layer 3 switch Proxy server Virtual Class Room on NKN private IP IInstitute Campus IP schema is tit t C IP h i not changed in the existing setup OSDD LAB with IP OSDD LAB ith IP schema which already exists Fig‐ 3 Inside the Institute 19 Internet Browsing Only using the NKN: Objective: Using Internet facility O f on an immediate basis through NKN. Refer Fig 4 20 How Do I start using Internet using the NKN: Assumption: The Public IP number provided by ISP deployed currently. In case the institute wants to have the internet facility from the NKN, then the following needs to be done: The proxy server must have the real IP provided to the institute as a part of NKN. This IP shall be advertised by the NKN to the Internet world and hence the browsing is made possible through the NKN link. link During this, this any failure in the NKN link will result in proxy not getting internet connectivity. The other resources like the web site / mail server etc will still use the ISP as the IP numbers belong to the ISP and has been leased out to the institute. institute Refer Fig 4 21 EXISTING ISP NKN NKN Router Placed inside the institute MAIL server Link between NKN – CSIR GW WWW server External Interface with NKN public IP Proxy server Proxy server Layer 3 switch IInstitute Campus IP schema is tit t C IP h i not changed in the existing setup Virtual Class Room on NKN private IP Block 1 GARUDA LAB with GARUDA LAB ith IP schema which already exists Block 2 Block N Fig‐ 4 Using a Proxy with NKN ext IP for browsing purpose. 22 Using the NKN when the USER has PUBLIC IP from APNIC/ ARIN: That is: /24 or more from APNIC/ARIN 23 Using the NKN when USER has PUBLIC IP from APNIC/ ARIN: The following are the assumptions for scenario in (Fig5): •User User with public IP pool •Multi-homing to NKN & other ISP with separate local routers (running BGP between them). USER Requirement R i t •Primary (NKN) ISP & Backup (non-NKN) ISP •Exit/Entryy via Primaryy or Backup on Primaryy Fails Solution for preferred exit point •Mark updates from NKN only with higher local preference. Solution for preferred entry point •Advertise self public pool with AS ( number of NKN itself) path prepend to other ISP only and to NKN have a ibgp session. NKN’ Role NKN’s R l •Accept only end node’s prefixes & filter •Advertise to the Internet with the ISPs connected to NKN 24 EXISTING ISP NKN Institute has IP number (public) provided by APNIC (public) provided by APNIC / ARIN iBGP between the NKN – CSIR GW MAIL server WWW server NKN Router Placed inside the institute External Interface with NKN public IP Proxy server Proxy server Layer 3 switch Virtual Class Room on NKN private IP Block 1 GARUDA LAB with GARUDA LAB ith IP schema which already exists Block 2 Block N Institute Campus IP schema is not changed in the existing g g setup Fig‐ 5 institutes having their own PUBLIC IP from APNIC/ARI N 25 Fanning-Out NKN P P PoP NKN P P PoP E i Engineering i collège Poly--tech Poly Egress NKN Router NKN Cloud Ingress NKN Router Some NLD providing connectivity Médical collège Education community VPN Green Site DAE LAB VPN Blue Site BIO TECH PE -NKN NKN MAIN UNIVERSITY With IN CAMPUS Colleges/ dpts 26 Short Term Migrating to NKN LAB #1 NKN IP Address Scheme Internet Service Provider NKN IP Address Scheme LAB #4 124.124.1.0-255 202.141.40.0-255 NKN RESOURCE DATA CENTER NKN CLOUD Internet Service Provider Internet Service Provider 121.121.240.0-255 NKN IP Address Scheme NKN IP Address Scheme 203.197.140.0-255 LAB #2 LAB #3 27 Migrating to NKN Institute #1 NKN IP SCHEMA CWCR Internet Service Provider NKN IP SCHEMA CWCR Institute #4 124.124.1.0-255 202.141.40.0-255 NKN RESOURCE DATA CENTER NKN CLOUD Internet Service Provider Internet Service Provider 121.121.240.0-255 NKN IP SCHEMA CWCR NKN IP SCHEMA CWCR 203.197.140.0-255 Institute #2 Institute #3 28 Short Term Migration Each one of the closed user group can g the NKN. ( It advertise the IP numbers through will be the Public IP given to the organisation by the ISP currently engaged.) A separate VRF will be created which will allow the organisation to browse the others in the closed l d user group. This will also provide Internet facility. Provision can also be made on a short term basis for public IP for the organisation from NKN to cater to the PUBLIC/ INTERNET demands. 29 Killer Applications Peer to Peer Collaboration Desktop Video Enterprise ERP Central Web Based Applications Library resources MOST IMPORTANTLY A DESIGN THAT CAN CATER TO FURTURE INOOVATIVE IDEAS 30 HOW TO CONNECT EXISTING GARUDA LAB TO NKN? 31 HOW TO CONNECT GARUDA LABS? GARUDA: It has been decided to provide the bandwidth to Garuda through NKN. It is important that the LAB taking part in the GARUDA project gets a link from the router provided to the institutions through NKN project. Suggestion: The LAB has to extend the link from the NKN router which in many cases will be in the Computer Center and in some cases it could be a part of some other project like ERNET PoP. The approximate distance is 0-2 KM in most cases. Connect the cable provided to the NKN router in the institute and Garuda LAB. ( responsibility of GARUDA) 32 NKN ISP Reliance/Bharti/TATA New Delhi/Hyderabad Internet Gateway Primary For NKN Institute Institute Tier‐1/2/3 POP PE Router ISP Backup PE Institute Network Tier‐1/2/3 POP PE Routers NKN MPLS Backbone Tier‐1/2 POP PE Router Proxy server MAIL server WWW server Tier‐1 POP P Router GARUDA LAB Details within the INSTITUTE Internal Cabling Fig: 6 Connecting Garuda lab to NKN 33 THANK YOU For further information: Contact: piu@nkn.in 34