Huawei DC Solution Presentation
Huawei DC Solution Presentation
Мазитов Алмаз
Ведущий менеджер по сетевым продуктам HUAWEI
CloudEngine Series Data Center Switch Portfolio
CloudEngine 6881-48S6CQ
CloudEngine 6863-48S6CQ
48*10GE
Complete Solution
24*40GE
36*100GE Mapping Capabilities
Agile Controller-DCN provides simplified
deployment capabilities throughout the life cycle.
FabricInsight analyzes TCP flows and network-
36*40GE 18*100GE wide health.
CloudEngine 16800: 400G platform supports 10GE, 40GE, and 100GE interfaces, and AI engine.
Hardware Architecture: Industry-leading Architecture Design and Innovate Heat Dissipation
Mixed-flow Fan,
Strict Front-to-Back Airflow Non-blocking Switching VC Phase Change Heat
Orthogonal Architecture
Design Dissipation
Leading energy-saving design
VC heat Chip
dissipation
substrate
Mixed-flow fan,
Backplane-free cabling Independent front-to-back Cell switching, VoQ
airflow Balanced traffic distribution, higher VC phase change heat
Higher chassis bandwidth
Even heat dissipation, basic bandwidth usage dissipation
requirements for data centers Air volume three times higher than
the industry average, greatly
reducing noise
The CloudEngine16800 supports the network lifecycle of four generations of servers and smooth evolution to 400G.
Introduction to CloudEngine 16800
MPU 1+1
SFUs 6 (scalable to 9 for future expansion)
Architecture Clos switching architecture, cell switching, VoQ
The CloudEngine 16808
Number of fan trays 3 3 3
has three fan trays.
Number of power
The CloudEngine 16808 6 10 20
supplies
has up to nine SFUs and
supports N+1 or N+M DC: 2200 W (-48 V/-60 V)
Power input
redundancy. AC/HVDC: 3000 W (AC: 220 V, HVDC: 240 V/380 V)
CloudEngine 16800: 100G/40GE/10GE Line Cards
Item 100GE Line Card 40GE Line Card 10GE Line Card
Card name CEL36CQFD-G CEL18CQFD-G CEL36LQFD-G CEL24LQFD-G CEL48XSFD-G
FIB (IPv4/IPv6) Standard mode: 220K/80K Large routing mode: 256K/80K Large MAC mode: 128K/64K
ND Standard mode: 80K Large routing mode: 80K Large MAC mode: 64K
ARP
<Non-contiguous
Standard mode: 96K-220K Large routing mode: 96K-256K Large MAC mode: 96K-128K
and contiguous
MAC addresses>
ACL 6*7.5K 3*7.5K 3*7.5K 2*7.5K 1*7.5K
MPUs of the CloudEngine 16800
MPU Description
Half-width MPU, adapting to the CloudEngine
CE-MPUD-HALF
16804/CloudEngine 16808
SFU Performance
Number of SFUs
Device Model Card SFU Required for Line-
rate Forwarding
36*100GE CE-SFU04G-G/ CE-SFU08G-G/CE-SFU16G-G 5
CE-SFU04F-G/ CE-SFU08F-G/CE-SFU16F-G 4
36*40GE
CE-SFU04G-G/ CE-SFU08G-G/CE-SFU16G-G 4
CE-SFU04F-G/ CE-SFU08F-G/CE-SFU16F-G 4
CE 16804/ 48*10GE
CE16808/ CE-SFU04G-G/ CE-SFU08G-G/CE-SFU16G-G 4
CE16816
18*100GE CE-SFU04F-G/ CE-SFU08F-G/CE-SFU16F-G 5
CE-SFU04G-G/ CE-SFU08G-G/CE-SFU16G-G 5
Four fan trays (one fan 1+1 power redundancy Four fan trays (one fan 1+1 redundancy
module in each tray) module in each tray)
Diversified DC features: M-LAG, iStack, VXLAN, and BGP EVPN Diversified DC features: M-LAG, iStack, VXLAN, and BGP EVPN
Hardware-based BFD Hardware-based BFD
Telemetry and ERSPAN enhancement Telemetry and ERSPAN enhancement
Microsegmentation and NSH Microsegmentation and NSH
Performance Performance
FIB (v4/v6): 256K/80K, MAC: 256K, ARP: 256K FIB (v4/v6): 256K/80K, MAC: 256K, ARP: 256K
specifications specifications
Recommended Mapping Version for CloudFabric Solution V1R19C00
Device Series Device Model Software Version
(1) Network overlay: FusionCloud 6.5 (private cloud based on
Mitaka, supporting IPv6)
Cloud computing FusionCloud
(2) Network overlay: FusionCloud 6.3.1 (based on Mitaka, and
integrating some features of Ocata)
CE16800 series CE16800 series: CE16804, CE12808, and CE16816
V200R005C20
CE6800 series CE6863-48S6CQ and CE6881-48S6CQ
CE1800V (OpenStack Mitaka + KVM CentOS7.2, OpenStack
vSwitch Ocata + KVM CentOS7.3, OpenStack Queens + KVM (1) V100R019C00 (2) V100R002C10 (3) V100R002C00
CentOS7.5)
SdSec solution V100R019C00
Old hardware firewall:
USG6660/Eudemon1000E-N6, USG6670/Eudemon1000E-
Old hardware firewall: V500R005C20 (for both carriers and
N7, USG6680/Eudemon1000E-N7E,
enterprise networks)
USG9520/Eudemon8000E-X3, USG9560/Eudemon8000E-
X8, USG9580/Eudemon8000E-X16
...
FuncEdit
NETCONF CLI SSH SNMP OpenFlow gRPC
Forwarding chip
NETCONF
VRP Linux container
CPU
Linux and driver
Simplified Deployment
The SDN controller defines
FW IDS LB NAT
SFC in drag-and-drop mode.
Flexible Orchestration
Switch Switch Switch Decouple VAS functions from
A fabrics, providing flexible
orchestration.
App
WEB
Efficient Forwarding
Traffic diversion for one time,
VAS
resource saving ACL resources and
pool providing simple configuration
Microsegmentation Achieves Fine-grained Isolation and Service Security
Fine-grained Defense
Define applications based on VM
names and discrete IP
addresses, with fine granularity.
Distributed Security
Traffic of access switches is
filtered nearby and east-west
isolation is implemented
without using firewalls.
Flexible Deployment
Define services based on
VM 1 VM 2 VM 3 VM 4 VM 5 VM 6
application groups and decouple
1.1.1.1 1.1.1.2 1.1.1.3 2.2.2.1 2.2.2.2 2.2.2.3 them from subnets to achieve
flexible deployment.
As Is: Subnet-based isolation To Be: VM-level
isolation
Industry-leading Telemetry Technology Achieves Visualized and Controllable Networks or Services in
Real Time
As-Is: Network Device Used as Black Boxes To-Be: Visualized Network Management and Control
• SNMP/NETCONF query/response mechanism, and • gRPC subscription/active reporting mechanism, and millisecond-
minute-level reporting level reporting
• Microburst detection is not supported, and traffic details • The CloudEngine 16800 monitors the microburst status, detects
cannot be detected. traffic details, and predicts congestion in real time.
• The traditional network device reports only logs and • The CloudEngine 16800 uses the intelligent analysis algorithm to
alarms, but cannot collect packet characteristic detect packet characteristic information such as the delay,
information such as the delay and packet loss. packet loss, and packet loss location in real time.
Forwarding AI Forwarding
CPU CPU NP
chip Chip chip
CloudEngine fixed switches: Diversified Models in All Scenarios and Sustainable Supply
The model in red can be New Model in
Planning in V3R20C00
V2R5C20
CE5855-48T4S2Q-EI
supplied continuously.
GE
CE5855 CE5855-24T4S2Q-EI
100G
Fixed AI Fabric and 1588 1U:CE8851-32CQ8DQ-P
CE8850-32Q-EI CE8850-64CQ-EI
2 U: CE8852-96CQ-P
Note:
(1) CloudEngine 6881, CloudEngine 6863, and CloudEngine 6820: GA in September 30, 2019 GA.
(2) The models planned for V3R20C00 may change at any time. For the latest models, contact DCN product management personnel.
Panorama of CloudEngine Modular Switches: Continuous Expansion in Installed Base Markets and
Steady Switching in New Markets
New Model Planning in
The model in red can be supplied continuously. V3R20C00
in V2R5C20
GE 10GE 40GE 100GE 400GE
16
CEL48XSFD-G CEL36LQFD-G CEL36CQFD-G
04 72*25/10G+4*100G 36*400G
CEL72XSHGA-P 48*100G CEL36DQHG-P
-P series cards CEL48CQHG-P
48*25/10G+4*100G 48*400G
CloudEngine16800 CEL48XSHGA-P CEL48DQHG-P
Note:
(1) CloudEngine 16804/CloudEngine 16808/CloudEngine 16816 and all its cards reach GA on September 30, 2019.
(2) The models planned for V3R20C00 may change at any time. For the latest models, contact DCN product management personnel.
SDN Baseline Networking of Category C Cards: Layer 3 Architecture Scenario
Design principle:
The solution does not support automatic loop acknowledgment in loop detection, suspected loop reporting, or path detection based on ICMP packets. The solution
supports path detection based on TCP/UDP packets.
The solution in which FabricInsight is used supports IPv4 and does not support IPv6. The solution does not support overlay multicast or traffic statistics collection on
Layer 2 sub-interfaces.
CloudFabric N1 Software Package Covers All Scenarios, Hardware, and Features
Agile Controller-DCN FabricInsight
Purchase or prepare the hardware platform Purchase or prepare the hardware platform Sales of fixed devices: underlay and third-party
and operating system as required. and operating system as required.
controller interconnection scenario
Agile Controller-DCN software platform free
FabricInsight big data analytics platform
of charge
Management Add-on
software package software Hicare
CloudEngine hardware switch CloudEngine 1800V (The default value of maintenance
SnS is 0, excluding
package service
Add-on software package
AI Fabric package
Value-added scenario function Software switch new functions of the (AI Fabric, unchanged
Security package (MACsec) software package.) MACsec, etc.)
Intelligent network analysis value-added package (traffic analysis)
Telco cloud DC gateway package (NEs managed by Agile Controller-DCN)
Solution sales: Agile Controller-DCN + FusionInsight
N1 Advanced
Promotes Sales of Hardware Switches in Virtualization
software package (A)
N1 premier software package All functions of the
and Cloud-Network Integration Scenarios
Enterprise edition (future)
All functions of the Advanced software package Foundation software Foundation
Intent assurance package...
package software Advanced
LB, NAT, DHCP, container package software Package Hicare
N1 Advanced software package SDN enhancement scenario (single-
+ (Single DC, package (single-DC maintenance
All functions of the Foundation software package N1 Foundation basic functions (single-DC enhancement service
MPLS/SR and NSH-based SFC
DC enhancement and multi-DC)
V1R19C10: multi-DC automation (MDO)... software package + of Agile enhancement and multi-DC) unchanged
Basic software, Controller-DCN and multi-DC)
CE1800V managed by Agile + FusionInsight)
N1 Foundation software package Single-DC SDN scenario
All functions of the Management software package
Controller-DCN
Telemetry, VS, PTP (1588v2), and number of CE switches managed by Agile Controller-DCN Solution sales: CE1800V and Agile Controller-DCN Are
FabricInsight intelligent network analysis basic package (V1R19C00, only for the
CE16800&CE6800) Sold as a Bundle in Container Interconnection Scenarios
Commercial Comparison of Solution Sales Scenarios: Simplified Quotation, Low Price, and Flexible License Transfer (SnS)
Traditional Model N1 Model
Unit List Unit Total List
Model Description Quantity
Model Description Price Quantity Total List Price Price Price
Agile Controller-DCN software N1-CloudFabric Foundation SW License for
AC-DCN-SW Platform 10,000 3 30,000 N1-CE68LIC-CFFD 9,900 50 495,000
platform CloudEngine 6800
AC-DCN-SW Platform- Three-year SnS of Agile Controller- N1-CloudFabric Foundation SW License for
5,100 3 15,300 N1-CE68CFFD-SnS1Y 1,980 150 297,000
SnS-3Y DCN software platform CloudEngine 6800-SnS-1 Year
Management of each fixed device Total 792,000
AC-DCN-Fixed 11,800 50 590,000
by Agile Controller-DCN
Cost-effective price and simple quotation: The controller platform is free of charge, which reduces the
Three-year SnS of management of threshold for using the solution. The total list price of a single TOR N1 software package is reduced by
AC-DCN-Fixed-SnS-3Y each fixed device by Agile 6,018 50 300,900 40% compared with the traditional model. For example, in the case of 50 TOR switches, the total list price of
Controller-DCN the N1 model is reduced by 50% compared with that of the traditional model, which is the same as that of CE
CloudEngine 6800 VXLAN switches. The order placement process is simpler.
CE68-LIC-VXLAN 8,000 50 400,000
Function Flexible license transfer to protect customers' investment. The license is more flexible. The software
CE68-LIC-TLM CE6800 Telemetry Function 6,000 50 300,000 used on the old hardware can be switched to the new hardware that is upgraded based on the old
Total 1,636,200 hardware, building customer loyalty. The customer does not need to purchase the software again,
which protects the customer's software investment.
Commercial Comparison of Pure Hardware Device Sales Scenario: New Hardware, More Functions, and Lower Price
Traditional Model N1 Model
Model Description List Price Model Description List Price
CE6857-48S6CQ-EI switch(48*10GE SFP+,6*100GE CE6881-48S6CQ-B switch (48*10G SFP+, 6*100G QSFP28, 2*AC
CE6881-48S6CQ-B 14400
CE6857-EI-B-B0B QSFP28,2*AC power modules,4*fan modules,port-side 18900 power modules, 4*fan modules, port-side intake)
intake) N1-CE68LIC-CFMM,N1-CloudFabric Management SW License for
N1-CE68LIC-CFMM 4500
CE68-LIC-VXLAN CloudEngine 6800 VXLAN Function 8000 CloudEngine 16800
The hardware price of new models is gradually shifted to software. In the project, try to persuade customers to configure VXLAN on uplink 100G ports. The CE6820 is recommended in non-
VXLAN scenarios. The CE6820 has a lower price than the CE6881.
The N1 Foundation software package is recommended if required functions are not included in the Management software package.
Commercial Comparison: N1 Management software package ($4,500) + Telemetry ($6,000) > N1 Foundation software package ($9,900)
24*40GE 18*100GE
08 GA on September 30, 2019 V2R5C20
04
72*25/10+6*100GE 48*100GE 36*400GE
48*25/10+4*100GE 48*400GE POC
V3R20C00 has not passed the PDCP, and the roadmap planning may change. Therefore,
V3R20C00 cannot be used as a formal commitment to customers.
CloudEngine TOR Switch Roadmap
GE VXLAN
GE CE5855 CE5880
V2R5C20
ENP CE6880
GA on September 30, 2019
High
CE6870 CE6875
(Large buffer)
10G CE6851
V3R20C00
Middle CE6857 CE6881 2020.7.30GA
CE6856
40G CE7855
CE8852: 96*100GE
100G
CE8860 CE8861
400G
Introduction to RDMA/RoCE
Current RDMA Network Bearer Solutions (IB
vs. CEE)
RDMA over InfiniBand RDMA over CEE (current)
Proprietary Technology,
Open Ethernet, Converged
Dedicated Network
Network
Advantage: Zero packet loss, low latency,
vs.
and high throughput Advantage: SDN automation, low
Disadvantage: Manual O&M performed price
by dedicated personnel, high cost Disadvantage: High latency and
low throughput
Challenges:
Packet loss: The packet loss rate of 1% decreases the RoCE throughput from
Technical description: 100% to 0. However, packet loss on traditional Ethernet networks in best-
RDMA technology implements kernel bypass and zero copy of the buffer, effort (BE) mode is inevitable.
provides RDMA read/write access between remote nodes, and
implements the control plane protocol in the NIC hardware. IB CEE
RDMA technology is used in HPC, distributed storage, and AI scenarios to Performance High Low
reduce the CPU load and latency, greatly improving the application O&M Difficult Easy
performance. Price High Low
RoCEv2 migrates RDMA traffic to the ETH/IP network. In this way, the Scale Small Ultra-large
Cloud-
ETH/IP network supports HPC, distributed storage, and AI application Others
Dedicated
network
network
deployment, and is required to provide the same network performance synergy
as memory access.
AI Fabric Implements Zero Packet Loss, Low Latency, and High Throughput Based on the Ethernet to Meet Service
Requirements in the AI Era
Basic Flow Control Model
• Set priorities through multiple queues
PFC threshold ECN threshold • Prevent packet loss through PFC Question: The CPU sensitivity is
backpressure Statically configured a key indicator.
• Use ECN to notify the transmit end to threshold
avoid congestion The queue type and
Queue Static queue type
threshold are the key.
Static ECN: Local device-level intelligence Dynamic ECN: Local device-level intelligence AI ECN: Global network-level intelligence
(implemented by the CPU) (implemented by the intelligent chip) (optimal application experience)
AI chip
Intelligent
CPU CPU
chip November
2019
Local optimal threshold based on Local optimal threshold based on Application-oriented optimal
CPU’s dynamic ECN intelligent chip detection queue on the entire network
Static ECN performance: 30% higher than that Static ECN performance: 50% higher than that
The threshold is setted by CPU of other vendors
of other vendors
Set the optimal threshold based on Set the optimal threshold based on the Application-based priority queues are generated
the current traffic model. current traffic model. based on application requirements.
CloudEngine Layer 2 VTEP Network overlay Network overlay Network overlay extension
Hybrid overlay CloudEngine 1800V
Scenario 1: Underlay, without the Scenario 3: computing and hosting with the controller but no cloud platform
cloud platform or controller
Computing Network
Hosting Network
Computing administrator
Third-party configuration tools administrator
administrator
such as Ansible or Microsoft Azure
System Center Agile Controller-DCN Agile Controller-DCN
/vCenter SecoManager SecoManager
Remarks: The network overlay supports centralized and distributed deployment. The distributed solution is recommended. The
centralized mode does not continue to evolve. The hybrid overlay supports only the distributed mode.
Overall Container Intent SFC Microsegmentation Summary
Cloud
Cloud management Hosting Microsoft VMware Third-party
management FusionSphere Kubernetes
platform (No cloud platform) System Center vCenter OpenStack
platform
Active/Standby controller Supported Supported
Supported Supported Supported Not supported
cluster
Controller RTT of remote controller
cluster < 50 ms (less Supported Supported Supported Supported Supported Supported
than 250 km)
Network overlay Network overlay
Overlay mode Network overlay Network overlay Network overlay Network overlay
Hybrid overlay Extend
IPv4 microsegmentation
(new models) Supported Supported Supported Supported Supported Not supported
L4-L7 security
Not supported
IPv4 SFC Supported Supported Supported Supported Supported
FusionCompute
Server access Type N/A Microsoft Hyper-V VMware ESXi KVM Container
BMS
DCI Interconnection type IPv4 L2&L3 IPv4 L2&L3 IPv4 L2&L3 IPv4 L2&L3 IPv4 L2&L3 IPv4 L2&L3
Overall Container Intent SFC Microsegmentation Summary
NSH: NSH Copes with Challenges Brought by Diversified DC Security to the Network
Diversified policies are deployed, and ACLs Inline deployment causes complex configuration of The security service is coupled with the physical
become the bottleneck. the control plane. topology, leading to low scalability.
• The switch needs to eliminate • Security policies need to be configured • Security devices are pooled,
the ACL bottleneck. on the GUI. implementing scaling on demand.
Overall Container Intent SFC Microsegmentation Summary
WAN VM
Product selection:
CloudEngine CE5880, CloudEngine 6880CloudEngine 6881, CloudEngine
Resource pooling 6863, CloudEngine 12800E, CloudEngine 16800
deployment
Highlights:
Standard SFC: complies with RFC, provides good interoperability, and
Service leaf maintains compatibility with third-party NSH devices.
Large specifications: The chip supports 20K SFC entries, which is two times
OVS higher than commercial chip.
VM
VM
VM
VAS resource pool
Traditional security depends on different Traditional isolation brings traffic Due to diversified isolation policies, ACLs
service partitions. bypassing. become scarce resources.
Segmentation
Spine
Subnet
Web App Database
• Cloud sharing and security isolation create a • Access switches support security isolation. • Switches need to eliminate the
conflict. ACL bottleneck.
Overall Container Intent SFC Microsegmentation Summary
Microsegmentation
IP MAC VLAN=10
Microsegmentation solves the problem of the zero-trust security model. Compared with the zero-trust security
model, microsegmentation provides security isolation in a more fine-grained manner. It covers physical machines
and addresses east-west security issues.
Overall Container Intent SFC Microsegmentation Summary
External External
network network
Unified isolation
①North-south
isolation Microsegmentation implements the zero-trust security model. It provides security
Border leaf
isolation based on discrete IP addresses and VM names, and covers PMs. It can
uniformly isolate traffic of VMs and BMs.