Transforming Your Business Operations with SD-WAN September 19th, 2018 Raymond Yu Senior Director of Product Management for SD-WAN and Edge Computing Network Product Line Huawei Technologies Co., Ltd. Trend: Cloudification Drives the Transformation from Traditional WAN to SD-WAN Driving WAN transformation Traditional WAN services … Line Bandwidth Connection + VAS From Connection to Connection + VAS operation Carriers QoS Hybrid link Cloudification Digital services Improved services &Management Experience Enterprises Service Visible &controllable … Cloud services VAS AI Industry applications Cloud-network convergence SMEs Rapidly obtaining interconnection service package 2 Trend: Enterprise WAN Management and Operation Modes Accelerate Transformation Enterprise traffic surges by 30% Budget decreases by 10% Hybrid WAN Expand bandwidth and use Internet links Applications cannot be identified, poor experience for key applications. Multiple devices , Service provisioning takes more than three months Interconnection -> Services Management becomes complex. Application-based traffic steering and optimization VNF-based and automatic orchestration Visualized and automated network management Identify and guarantee the experience of key applications VNFs such as FW, WOC, and IPS All-in-one devices are used in branches. Intelligent fault location and troubleshooting methods 3 SD-WAN Advantages over Traditional Enterprise Private Lines: Applicationbased Traffic Steering, uCPEs (VASs), and Visualization Traditional box --> uCPEs and integration with VASs Traditional private line --> Application-based traffic steering CLI --> Visibility and simplified O&M Router WOC Firewall Firewall WAN acceleration … • Different routing policies are implemented for different applications, ensuring excellent service experience of enterprise applications. • Access the cloud locally: local breakout, improving cloud access experience for enterprises uCPE • Universal CPE (uCPE), supporting the universal computing architecture • Integration with third-party VASs, such as those of Riverbed, Fortinet, Check Point, etc. • Simplified management and service provisioning with ZTP, automatic configuration, automatic networking, etc. • GUIs for easy management and operations 4 SD-WAN : Hybrid WAN, Cloud Service VAS store ⚫ Self-service portal Slowly deployment: 3 months BSS/OSS Restful APIs Complex provisioning procedure Multi-devices coexist: FW, WOC, Router ⚫ Policy execution Control Plane vRR Complex O&M: Fault locating > 1 hour vRR MPLS LTE ⚫ xDSL/Eth/LTE/PON… Forwarding Plane … vCPE CPE/uCPE Data Center Cloud Intelligent O&M: Fault locating < 1min Telemetry-based real-time monitoring, locating faults in minutes Internet BGP EVPN Isolated operation: Multi-systems Isolated multi-platform supporting multi-service One solution adapt to only one-cloud vRR Service experience : Assured FPI +DPI + User-Defined Apps App-based traffic steering ⚫ Apps monitoring > 5 minutes, unable to monitor app/link quality in real time ⚫ ZTP ( Zero-Touch-Provisioning ) VAS application automatic orchestration Service experience: Non-guaranteed Application flow invisible Manually switchover the link ⚫ Efficient deployment: 1 day Agile Controller Management Plane ⚫ ⚫ vFW vWoC … uCPE Branch Unified operation: Open ecosystem Integrated based on 120+ APIs &10+ VASs Multi-cloud : Huawei, AWS, Azure CPE FPI: First Package Identification 5 ZTP for Plug-and-Play: Fast Service Provisioning in a Branch Within 30 minutes 1 days Configuration Before Email Register &Online 30 minutes Delivering CPE SD-WAN Powering on, activation by email Deployment efficiency at branches Branch Onsite configuration and deployment → One-click service provisioning MPLS coverage restriction → Wide coverage through the Internet, with 2 to 3-fold growth of customers IT professionals required → No need of professional engineers; self-handling by service persons 6 Simplified Use Case: NFV-based All-in-One Devices in Branches Allow Services to Be Provisioned Within Minutes One Service One Device Difficult to Change Service Intelligent Open Automatic Service Chain Orchestration Cloud Internet SD-WAN MPLS OPEN uCPE vRouter LTE vFW vWOC X86 or ARM64 Multi-Devices to 1 uCPE + VASs Branch I need deploy WOC in Hannover Office for accelerating CAD transmission in this week. Inflexible Services Change to On-demand VASs VAS Provisioning from months to minutes 7 Simplified Intelligent Open Simplified Branch Deployment, Full-Process Automation, and Service Rollout in Minutes Reduce OPEX Hybrid WAN, simplified networking in all scenarios … Self-service portal Full series of CPEs, including the CPE, uCPE, and vCPE 10+ WAN interfaces and Hybrid Bonding Automatic configuration of IaaS/SaaS connections BSS/OSS VAS Store ZTP and device plug-and-play Automated service chain orchestration Internet MPLS LTE Automatic orchestration for overlay tunnels Flexible deployment modes (email, DHCP, and USB) and device plug-and-play Batch deployment of multiple sites ZTP Automatic configuration of overlay tunnels and fast networking Automatic configuration of overlay tunnels and multi-VPN service template configuration On-demand selection of Hub-Spoke, full-mesh, and partialmesh networking modes Hybrid WAN for All Scenarios … vFW vWoC uCPE vCPE Branch Cloud HQ/Data center Automated service chain orchestration and VAS service provisioning in minutes Open x86 & ARM64 uCPE, 10+ mainstream VASs (Riverbed, Checkpoint, etc.) Automated service chain orchestration and one-click delivery 8 Use Case: Adaptive FEC Intelligently Optimizes Audio and Video Experience As-Is: link flapping (packet loss ratio > 5%), and audio and video frame freezing Simplified Intelligent Open To-Be: Internet packet loss ratio of 20%, and no erratic display or frame freezing for audio and video services Experience 100% guarantee Poor audio and video experience 30%↓ Bandwidth consumption Adaptive FEC Adjust the FEC protection window based on the link quality. Internet link quality: packet loss ratio larger than 10% or delay larger than 400 ms AR (WOC) AR router (WOC) Internet Internet Branch 1 Branch 2 Original Redundant packet frame Branch 2 Transparent transmission Transparent transmission Original Packge Branch 1 Packet loss Received packet Check link quality in real time and adjust the FEC protection window as required Packet loss during transmission Enable FEC on the receiving device and restore the original video frame 9 Use Case: Fillps Transfer Files at High Speed, and the File Transfer Speed Increases 100-Fold As-Is: 1 Gbit/s bandwidth, 100-ms delay, and 1% packet loss ratio, with file transfer speed of 1.8 Mbit/s Simplified Intelligent Open To-Be: 1 Gbit/s bandwidth, 100-ms delay, and 1% packet loss ratio, with file transfer speed of 946 Mbit/s • Fillps for fast file transfer: packet loss tolerance and fast retransmission, quickly freeing up memory to make full use of bandwidth • Precise flow control at the transmit end: Data is sent on demand. Packetlosssensitive • Dual-acknowledgment mechanism for packet loss: The transmit end retransmits lost packets. AR (WOC) AR (WOC) Internet Branch 1 TCP Branch 2 TCP Fillps Internet Branch 1 Branch 2 Data packets enter into the transmission queue as required. Packet loss during transmission The NACK mechanism is used to monitor the packet loss in real time, and the receive end can rapidly retransmit the lost packets. 10 Simplified Intelligent Open Use Case: Intelligent Traffic Steering Delivers Optimal Application Experience, and Maximizes Bandwidth Utilization Scenario: During peak hours, non-key services preempt the bandwidth of highlevel video conferences. As a result, the conference experience is affected. Video conference • Intelligent application identification SaaS first-packet identification User-defined applications based on the quintuple or URL Office365 Yes AS-IS: peak the key services experience is poor TO BE:During Assured keyhours, application experience MPLS FPI No DPI Offce365 Video conference User-Defined Application HQ Branch uCPE Internet YouTube Offce365 Others • Traditional SD-WAN interconnection Bandwidth utilization >90% <50% Hybrid WAN Load balancing based on application priorities and application-based traffic steering Application-based traffic steering, delivering optimal application experience and maximizing bandwidth utilization Differentiated route selection based on application priorities Load balancing of key applications during peak hours Internet SLA decrease and application-based traffic steering 11 EN Application-driven Intelligent Experience Optimization and Lossless Service Experience Simplified Intelligent Open FPI + DPI intelligent identification for visualized and controllable network-wide applications SaaS first-time correct route selection, and in-depth identification of complex applications User-defined applications based on the quintuple or URL Application-based traffic steering, delivering optimal application experience and maximizing bandwidth utilization User-defined applications (VIP) SaaS first-packet identification Application-based traffic steering Intelligent load balancing of key applications during peak hours Application SLA decrease and intelligent link switching Application identification VAS Branch Nextgeneration AR WOC vCPE Cloud Transmission optimization of audio, video, and large files Ultra-fast Fillps, accelerating file transfer 100-fold and saving bandwidth by 70% Adaptive FEC, no frame freezing of audio and video services with the packet loss ratio of 20% 12 Simplified Intelligent Open Use Case: Intelligent O&M and Fault Location Within Minutes As-Is: Complex O&M, Fault locating > 1 hour To-Be: Intelligent O&M, Fault locating < 1min • WAN monitoring every 5+ minutes • Telemetry-based real-time monitoring • Single dimension report based on link • 45+ multi-dimension reports based on app, user, link… • Experience-based analysis, average fault locating time > 1 • Machine learning based intelligent analysis , locating faults in hour minutes 13 Simplified O&M and Visualized Management Reduce OPEX by 80% Video BYOD service Teleconference Intent template Traffic analysis Intelligent O&M Correlation analysis Application profile NETCONF Optimization policy (rate limiting for non-key applications, transmission link adjustment, and WAN optimization) Continuous monitoring of traffic or network status … vFW vWoC uCPE vCPE Data center Cloud Fault tracing Link profile Telemetry Branch Open • Real-time monitoring based on Telemetry (link branch status at each link or time, bandwidth usage of each application, and application quality) Analyzer Policy association Intelligent Link/Application profile Email Fault prediction Simplified Big Data analytics • Dynamic baseline, correlation analysis, and fault knowledge base • Dynamic baseline and application quality evaluation based on supervised algorithms • The dynamic baseline is learned from the fault knowledge base to determine new problems. Intelligent O&M • The results based on Big Data analytics help locate faults within minutes. 14 Building Cloud-based Security Architecture Key technology Service Security: Provide E2E security portfolio for enterprises ❑ Cloud Security Self-service Portal VAS Store BSS/OSS HTTPS Rights- and domain-based management Huawei Security Analyzer • Rights- and domain-based management • Huawei Security Analyzer • Deployment of firewalls and DDoS devices Log analysis on the Agile Controller Deployment of firewalls and DDoS devices on the Agile Controller Traffic analysis Document behavior ❑ Connection Security SSH-encrypted NETCONF & Bidirectional Identity Authentication Device Security CPE OS • SSH-encrypted NETCONF • Bidirectional Identity Authentication IPS/URL/DPI/FW between AC and CPE Built-in IPS/IDS/ URL/FW filtering CPE • IPSec VPN MPLS IPSeC VPN Huawei or 3rd Party’s VNF AV SSL NGFW DDOS IPS DPI ❑ Device Security Internet • Basic firewall: URL filtering,ACL,IPS, Anti-DDOS, IPSec VPN,NAT Built-in Security VNF uCPE • Advanced firewall: vFW 15 Simplified Intelligent Open Open Ecosystem Overview Huawei SD-WAN Capability Openness Cloud openness • • Service applications The Agile Controller is deployed on the cloud, reducing costs. vCPEs are deployed on the cloud, optimizing SaaS access experience. … VNF Market Self-Service Portal Business Openness E2E solution • BSS/OSS RESTful API Cloud management platform Integration solution • API openness • The Agile Controller provides open northbound APIs for easy integration. Interconnection • 10+ mainstream VASs, flexible service selection vWoC vFW Internet uCPE Branch/HQ MPLS E2E solution + third-party orchestrator Full-decoupling solution NETCONF … VAS openness CPE + basic routing + SDWAN VNF + AC + thirdparty VAS vCPE Cloud • CPE + basic router • SD-WAN VNF + Agile Controller + third-party orchestrator 16 Simplified Intelligent Open Huawei SD-WAN Cooperation Ecosystem At MWC 2018, Huawei, Microsoft, Riverbed, and F5 & EANTC jointly release the SD-WAN cooperation ecosystem. At HAS 2018, Ping An Technologies Co., Ltd. signs an intentdriven network joint innovation agreement with Huawei and releases SD-WAN innovative business practices. Public Cloud VAS Standards & Organizations Architecture 17 Business Suggestions: Major Scenarios of Enterprise SD-WAN Global Interconnection Global unified networking and management, optimizing experience of cross-border applications Evolution from the live network Compatibility with the live network and gradual evolution to SD-WAN 18 Main Scenarios of Enterprise SD-WAN Construction Global Interconnection Evolution from the Live Network Hybrid link access, smooth evolution of the live network, and visualized O&M Global unified networking and management, optimizing experience of cross-border applications 1. Distributed controller + multi-PoP networking, hybrid link access, unified 1. Hybrid WAN, unified management, and visualized O&M management, and visualized O&M 2. IaaS/SaaS application access, and experience optimization 2. Cross-border application experience assurance 3. Smooth evolution to SD-WAN and gradual migration to protect investments 3. All-in-one devices, accelerating the TTM • Bandwidth increases by 10%, budget decreases by 10%. • The costs of traditional MPLS capacity expansion are high. • Applications experience is poor during peak hours. • Branch services traverse the HQ and reach the cloud, resulting in • O&M teams are deployed globally and perform O&M separately. • Stacking of devices (FW, WOC…) from vendors in branches, manual onsite configuration, TTM > 3 months Multinational enterprises long delay and poor user experience. • SD-WAN needs to be introduced step by step. SD-WAN and traditional MPLS networks coexist. Typical customer: Ping An Technology 19 Global WAN: Global Unified Networking, Unified Management, and High-Quality Experience of Cross-Border Services HQ (global DC) • Architecture: global interconnection CPE + SD-WAN + distributed controller and third-party VASs (optional) Agile Controller Cross-border Public cloud MPLS international private line Internet international private line • Reliable: hierarchical networking and Hybrid WAN Hierarchical networking, over 10 interface types to flexibly support MPLS, Internet, and LTE access of different carriers, and high reliability … vCPE Regional center Country B Country A China Cross-border deployment: high reliability and smooth capacity expansion Regional center Regional center Internet Internet • Country C MPLS MPLS … Intelligent Route Policy based on SLA, bandwidth, load balancing, priority, and QoS, providing WAN optimization or intelligent policies for key applications … vFW vWOC Site Site Site Site Site Site uCPE • Visualization Traditional Network Interworking Quick: Fast branch networks and services Provisioning ZTP (email/USB/DHCP) and network deployment within minutes Open uCPE supports over 10 mainstream VNFs Application-based Traffic Steering and Acceleration Multi-POP Optimized: application-based traffic steering and acceleration CPE/uCPE/VNF Integration • Bandwidth increases but budget decreases • Applications experience is poor during peak hours. • Multi-devices (FW, WOC…) ,manual onsite configuration, • Visible: unified management and configuration of the distributed controller and visualized O&M Reports based on applications, sites, users, and links, and fault location within minutes Distributed AC 20 Smooth Evolution of the Live Network with Hybrid WAN and Visualized O&M Solution Highlights HQ (global DC) Core Service Internet services Non-critical services such as office • Agile Controller CPE + SD-WAN + centralized controller Hybrid WAN, interworking with traditional MPLS domains, gradual migration, and smooth migration from the live network to SD-WAN to protect investments Regional aggregation IGW MPLS Architecture: live network evolution Public cloud Internet LTE • Centralized deployment Compatible with non SD-WAN configuration, protect current network investment Support SD-WAN and non SD-WAN automation configuration, simplify current network management, and support the gradual evolution to SD-WAN Local access • … Traditional site Multi-POP CPE/uCPE/VNF • Traditional MPLS capacity expansion is costly. • Branch services traverse the headquarters and reach the cloud, resulting in long delay and poor Visualization Traditional Network Interworking Integration Distributed AC Huawei‘ all-serials CPEs support SD-WAN, Enterprise can migrate Service gradually, ensure smooth operation of the business SD-WAN site Application-based Traffic Steering and Acceleration user experience. • SD-WAN and traditional network coexist, the current business gradually migrate • Visible: simplified, low-cost O&M Reports based on applications, sites, users, and links, and fault location within minutes ZTP deployment (email/USB/DHCP) and network deployment within minutes SD-WAN and traditional MPLS networks coexist. 21 Enterprise Business Model: Provides SD-WAN or Basic O&M Editions for Flexible Selection 1 • • License Enterprise customer VNF management SD-WAN WOC Service consultation and planning SD-WAN 2 Overlay and route selection Controller purchase Device management 1 2 New site Old site CPE purchase Traditional CPEs gradually upgraded and migrated to SD-WAN. CPE/uCPE/vCPE: Huawei Agile Controller: Huawei ➢ Device management + SD-WAN license (mandatory) ➢ WAN optimization and VNF management (optional) ➢ Old devices must be upgraded to support SD-WAN through software upgrade. Basic O&M, SD-WAN ready • • • CPE/uCPE/vCPE: Huawei Agile Controller: Huawei ➢ Device management license (mandatory) Capability to evolve for SD-WAN in the future SD-WAN 22 Huawei SD-WAN Solution Product Portfolio Mainstream VNFs On-demand VAS provisioning Advanced vCPE Extends SD-WAN to the Cloud AR1000V Eth/IP Agile Controller Router VPN Security High performance: scale up to 320G ⚫ Multi-platform compatibility: KVM, QoS FusionSphere, VMware, etc. Hypervisor (KVM/VMWare/FusionSphere) Universal Server ⚫ Huawei Flexible deployment: USG6000V Eudemon1000E-V (X86 architecture) Automation and visibility ⚫ ⚫ branch/PoP/DC/public cloud Multi-tenant: automatic and unified SD-WAN CPE management of up to 20,000 CPEs at Flexible networking 10,000 sites; multi-tenant O&M ⚫ Public cloud deployment: AWS, ⚫ uCPE ⚫ Azure, HUAWEI CLOUD AR650 Series AR1600 Series AR2600 Series ⚫ ⚫ Openness: standard northbound APIs ⚫ for easy service integration with thirdparty self-service Portal, BSS/OSS, etc. ⚫ CPE ⚫ AR160 Series AR2240 Series AR3200 Series Multi-service convergence: data, voice, security, WLAN, and LTE Optimal branch service experience: multi-core architecture and excellent performance Modular design, covering all types of branch scenarios In-depth ICT convergence, uBox design, and dynamic loading of VAS applications NFV architecture, automatic management of local VASs, and fast VAS provisioning Flexible deployment modes, such as email and barcode scanning, simplifying management 23 uCPE with x86 Open Architecture and On-demand VASs Intel 4/8 XEON, supporting SD-WAN AR650 Series AR1610-X6 AR2600 Series high-performance forwarding NFV open platform based on the x86 architecture, achieving architecture decoupling LTE flexible extension card, supporting It is the next-generation image of Huawei's uCPE. It allows multiple VNFs to be installed, and supports scalable hard disk and LTE interfaces. on-demand expansion of 4G services ——Good Design Award Judging Panel 24 CPE with Next-generation ARM Architecture Helps Build Cost-effective Networking SD-WAN service performance 40G AR3660 10G AR3260 AR1600/AR2600 Series 1G Huawei-developed ARM chip, with over 30% higher performance than equivalent products of other vendors Multi-service integration including voice, security, VPN, and WOC AR1200/2200 AR650 Series 500M Modular design for cards and flexible expansion of cards such as LTE, xDSL, and PON cards AR160 Series Traditional CPE, supporting SD-WAN evolution Next-generation CPE ARM platform, delivering high performance 25 High-performance Multi-platform vCPE Allows Services to Be Extended to the Cloud Compatible with mainstream virtual platforms, AR1000V AR1000V VPC Multi-Cloud service flexible choice VPC Private Cloud Public Cloud Huawei Cloud:FusionSphere 6.0/6.1 Amazon AWS: Amazon Machine Image Microsoft Azure: Hyper-V VMWare 5.5/6.0 Internet MPLS Red Hat KVM LTE Optimal path to Cloud IaaS Access Speed 5X CPE/uCPE Multiple clouds for enterprise businesses The AR1000V is directly connected to the cloud to avoid bypassing the headquarters Branch 26 Industry-wide Recognition of Huawei SD-WAN Solution One of the world's most popular SDWAN Solution Providers A survey of more than 1200 enterprises from across the globe A Preferred SD-WAN Solution Provider From 2017 SD-WAN and Virtual Edge Report The Evolving SD-WAN, vCPE and uCPE Landscape The Only SD-WAN Solution Provider to Pass EANTC Testing The scalability, CPE, link resiliency, and application visibility of Huawei SD-WAN Solution has been tested. The test results show that Huawei passes EANTC's stringent testing. ONUG: Right Stuff Innovation Award With its SD-WAN solution and CloudAPP, Huawei competed with vendors from North America for the first time. After stringent evaluation tests, Huawei stood out and received praise from the judges. https://www.onug.net/about/press-info/recipientsinnovation-awards-recognized-onug-fall-2017/ http://www.huawei.com/cn/news/2017/10/SD-WANONUG-Right-Stuff-Innovation-Award AR650: Good Design Award It is the next-generation image of Huawei's uCPE. It allows multiple VNFs to be installed, and supports scalable hard disk and LTE interfaces.” ——Good Design Award Judging Panel http://www.g-mark.org/award/describe/45177 http://e.huawei.com/cn/news/china/2017/201 710171507 27 Huawei SD-WAN Solution Helps Ping An Technology Quickly Roll Out AI Customer Service Business Value Customer Requirements ⚫ Increasing bandwidth requirements ⚫ Network deployment taking several days. ⚫ 2000+ sites, difficulty in locating faults Leased line cost 40% ⚫ ⚫ 10M-30M Internet replaces 2M10M MPLS link. Application-based traffic steering ⚫ Network deployment OPEX 30 minutes 75% No trained personnel are required and deployment is carried out remotely. ⚫ Visualization based on the entire network, branch, users, and applications 28 Huawei Uses SD-WAN to Achieve 100 ms Latency for Branches Worldwide and Optimize Connectivity and Application Experience Business Value Customer Requirements 1000+ sites, 955 private lines, 600G, 160 countries • ↑40% YoY in WAN traffic with ↑10% YoY budget • Poor experiences for bandwidth conflicts of 600+ apps • New Remote Branch Service TTM > 3 months Bandwidth cost Application experience VAS provisioning O&M cost 80% 20% 5x 30 minutes Hybrid WAN, Bandwidth usage: 60% -> 90% Optimize cloud and remote branch application experience Fast provisioning of VASs such as Riverbed vWOC and F5 Proxy 45+ reports by application, link, site, and user, and fault prediction 29 Thank You