Leaf Spine Architecture - High Level DC Design
Leaf Spine Architecture - High Level DC Design
Enabling Technology
Objectives
Project Scope
The existing Datacenter Network design/topology of SAPT Network architecture
High Level Design for SAPT DCN Revamp
Edge Firewall design
DC FW Design
TOR Switching Design
High Availability / Load Balancing
Management and Security Features
Proposed Design Decisions
Migration Strategy
Proposed Project Plan
Project Scope
Supply of DC/Edge/Access Network and NGFW equipment as per the required BoQ at Karachi SAPT Port
Design of DCN Architecture
Physical – HA within Primary DC
Logical – L2/L3 Topology
TOR Switching Design – Loop free topology
Optimal Edge/DC NGFW Design with no or minimal down time
High Availability
Use Cases
Traffic Flows
Migration Strategy
Phased Approach
Transit to End State
Documentation of proposed design and changes
Deployment and Migration of Edge/DC NGFW and TOR switches at SAPT Network environment
Deployment of Huawei SecoManager and AAA
Integration with existing Core, Access LAN and NMS
Industry best practices for implementing recommended security features
Existing Network Design
OSPF routing protocol is widely used, while a limited static routing is also
configured
Edge segment consist a pair of Cisco ASA 5516 firewalls in Active/Standby
mode
A partial implementation of BGP exists at Internet Routers with 3 x ISPs
(PTCL, Cybernet & TWA)
Existing Network Topology
TOWARDS KICTL
ISP 1 ISP 2 ISP 3
PTCL CYBERNET TWA
DMZ SEGMENT
PRIMARY DATACENTER
EDGE FIREWALL
CISCO ASA 5516
B2B SEGMENT
ACTIVE/STANDBY
DC FIREWALL
CISCO ASA 5585
ACTIVE/STANDBY
Peer Link
CISCO NEXUS TOR SWITCH 9K CISCO NEXUS TOR SWITCH 9K CISCO NEXUS TOR SWITCH 9K
DISTRIBUTION SWITCHES
ACCESS SWITCHES
Proposed High Level Network Topology Routers
replaced by
ACTIVE/STANDBY
eBis Firewall
HUAWEI USG6685F
DC FIREWALL
eBis-FW
CISCO ASA 5516
Migration
ACTIVE/STANDBY
DC Firewalls
CISCO NEXUS CORE SWITCH 9K IT/OT SEGMENT
Peer Link
F5 LB
Migration
Keep Alive Link
F5 LB
VPC
i-Stack i-Stack
TOR Switches
Migration
i-Stack
DC FAILOVER/
HUAWEI TOR SWITCH HUAWEI TOR SWITCH
CE6881 CE6881
HUAWEI TOR SWITCH
CE6863E
SECONDARY
DATACENTER
SERVER FARM
Huawei
SecoManager
SECOMANAGER - VM AAA iMaster NCE
ACCESS SWITCHES
Existing Edge Design
ISP 1 ISP 2 ISP 3
PTCL CYBERNET TWA
CISCO ASA5516
EDGE FIREWALL
DMZ SEGMENT
ACTIVE/STANDBY
VPC
Proposed Edge Design
ISP 1 ISP 2 ISP 3 INTERNET
PTCL CYBERNET TWA
i-Stack
CISCO
DUO MFA SSL REMOTE VPN
SSL REMOTE VPN
BGP AS#
HUAWEI S5731
• BGP Configuration
EDGE SWITCHES • Routing Policies
• Traffic Filtering
Eth-Trunk Eth-Trunk
HUAWEI USG6635
EDGE FIREWALL
DMZ SEGMENT • Policies/Services Migration
• SSL VPN with MFA
ACTIVE/STANDBY
Peer Link
VPC
CISCO NEXUS TOR SWITCH 9K CISCO NEXUS TOR SWITCH 9K CISCO NEXUS TOR SWITCH 9K
SERVER FARM
PROPOSED DC FW Design
HUAWEI USG6685F DC FIREWALL
FAILOVER LINK/HEARTBEAT
VPC
East West Traffic Default Gateway DC FW
SERVER FARM
Peer Link
10G 10G
Eth-Trunk LACP 10G
i-Stack i-Stack
Eth-Trunk LACP
Eth-Trunk LACP
10G
SERVER FARM
Failover Scenarios
Primary DC
Active Edge Firewall Fails – Traffic will continue to flow from Standby
FW
Primary ISP Link Fails - Traffic will continue to flow from secondary ISP
Internet Switch Fails - Traffic will continue to flow from secondary
switch in virtualized stack
Active DC FW Fails - Traffic will continue to flow from Standby DC FW
Primary TOR Switch Fails - Traffic will continue to flow from Secondary
switch in virtualized stack
In case of dual failure of a critical component e.g. both DC FW fail –
manual intervention may be required to run the services from
secondary/failover DC
Load Balancing
Design Decision 1: NAT will be performed at Huawei Edge Firewall. Currently it is being done at Internet Routers
Design Decision 2: BGP configuration and routing policies will be done at Huawei Edge Switches
Design Decision 3: Edge switches will form Ether-Trunk (Port Channel) with ISPs if possible, to provide full
redundancy of switch failure
Design Decision 4: Separate Ether-Trunks (Port Channels) for each DC firewall at Core layer
Design Decision 5: Virtualized stacking i.e. Huawei i-Stack will be used at TOR switching layer, forming Ether-
Trunk (Port channel) with the Cisco VPC at core switches
Migration Strategy
Phased Approach – The Strategy is to have the Parallel setup as much as possible while
maintaining the zero or minimal downtime for services migration –
Description of Multiple milestones
Phase 1 – Deployment of Internet Edge design (FW & Internet Switches) – Service
Migration