SlideShare a Scribd company logo
1 of 18
Download to read offline
Data Intensive network
support at Cambridge
Bob Franklin <rcf34@cam.ac.uk>
UIS Networks, The University of Cambridge
The CUDN
Backbone network
• Backbone network ("CUDN" — Cambridge University Data
Network) runs like an ISP to 175 institutions (departments and
colleges)
• No border firewall — it's all "outside"
• Only simple access controls and DoS protection, typically for
the network itself
• Firewalling left to institutions: appropriate for them
• Easy to deliver unfiltered, maximum bandwidth connections
• Prices: 1G ~£2,500/year, 10G ~£4,500/year.
Security structure
Janet/Internet
3x 20G
{Backbone
10-40G
{Institution
inc. firewall
1/10G
Institutional
security
boundary
Backbone
security
boundary
Institutional VLANs
Distribution
routers
Institutional
firewall
PoP switch
"Office" data
outside VLAN
"Office" data
inside VLAN Voice
VLAN
WAP
VLAN
Non-firewalled
data VLAN(s)
2x 1G/10G multipath
2x 10G upgrading to
3x 40G multipath
Office HPC
VLAN options
• Layer 2 circuit [point-to-point VLAN] using EoMPLS
(undesirable)
• Layer 3 routed subnet with optional access lists
• Layer 3 routed subnet as part of MPLS VPN
• Creates a private network between a group of
institutions for a particular service or project
• Need a gateway router/firewall/server to get out of
the network to backbone/Janet
The GBN
Dark fibre network
• University and Colleges own a private dark fibre network covering relevant
parts of the city (the "GBN" — Granta Backbone Network)
• Redundant paths between most areas
• Circuits are singlemode and spliced end-to-end
• Anyone can rent circuits and build/extend their own network, (departments/
colleges, Janet, Anglia Ruskin University)
• (The CUDN rents circuits just like anyone else.)
• Ideal for delivering Janet Lightpath and Aurora services
• Bypasses security concerns when passing sensitive data?
• Price for A/Y 2016-17 is £13.22/100m/year
GBN
Data
Centre
Old Addenbrooke’s
University Press
Hills Road 6th Form
Strangeways
Clinical School
Chemistry
Architecture
Long Road 6th Form
Engineering
Fitzwilliam Museum
Peterhouse
Downing Site
New Museums Site
Trinity
St John’s
West
Lucy
Cavendish
Wolfson
CourtAstronomy
Mill Lane North
Cavendish
Sidgwick Site
Great St Mary’s
Gonville & Caius
King’s
St Catharine’s
Thompson’s Lane St John’s Road Park Parade
Queens’
East
Queens’
West
Darwin
Harvey Court
Caius Pavilion
Grasshopper
Lodge
Newnham
Owlstone Croft
South Green Lodge
Wolfson
Selwyn
Gardens
Leckhampton
St Chad’s Selwyn
Wilberforce Road
Sports Ground
Cripps
Court
Emmanuel
Christ’s
JesusSidney SussexADC
St Edmund’s Kettle’s Yard
Murray
EdwardsFitzwilliam
Churchill
Girton
University Farm
St John’s
East
Trinity Hall
Clare
Old
Schools
Botanic Garden
Chaucer Road
Latham Road
Downing Parker’s Piece
Fenners
St. Paul’s Road
Kelsey
Kerridge
Magdalene West
Magdalene East
Chesterton Lane
The Colony Shire Hall
Magrath Avenue
Corpus
Christi
Free School Lane
Cambridge
Assessment
Harvey Road
Open
University
Workers’
Educational
Association
Glisson Road
Gresham Road
Russell Street
Pembroke
Panton Street
CRUK
MRC LMB
Barton Road East
Grange Road
South
Newnham
Village
Newnham
House
Newnham
Terrace
Gwen
Raverat
Malting House
Hughes Hall
Mill Road West
Robinson
Library Memorial Court
KGH
Clare Hall
MathsIMS
Huntingdon Road
Madingley Road
East
Fossedene
Halifax Road
Westminster
Zoo Sub Dept
Madingley Hall
Whittle
UIS
Computer Lab
Earth Sciences
Soulsby
Veterinary Medicine
Gravel Hill Farm
Laundry Farm
Hauser Forum
Materials
Science
& Metallurgy
Sports
Centre
Institute for
Manufacturing
Residences
Grange Road
Forvie Site
Storey’s Way
Wychfield
Saxon Street
Anglia Ruskin
University
Midsummer
Common
Newmarket
Road
Maids
Causeway
Histon Road
Canterbury Street
Jesus Green
River Cam
River Cam
Barton Road West
Mill Lane South
Boat Houses
Darwin Line
Book Line & Thinker
Turing Loop
Cats & Queens’
Storey’s Way to NMS
Zoo Line
Bumps & Bruises
Stars & Bytes
Newton Line
Interchange Stations
Under Consideration
Leased Fibre Line (Redstone)
Leased Fibre Line (Virgin)
Site Fibre Line (Clinical School)
The Janet Network
Faculty of Education
Homerton
Burrell’s Field
Needham
Research
Institute
Bene’t Street
Mornington Crescent
1 2 3 4 5 6 7 8 9
1 2 3 4 5 6 7 8 9
E
D
C
B
A
F
E
D
C
B
A
F
Transport for Cambridge
Chemical
Engineering &
Biotechnology
open summer ‘16
open summer ‘16
~6km
direct;~10km
by
fibre
Challenges
Dark fibre challenges
• The GBN is easy — buy your [cheap] switches
and transceivers; rent a circuit and feed your
VLAN across it
• Ideal for regular, point-to-point high bandwidth
data transfers (e.g. MRI brain scanner to HPC
cluster)
• Difficulty is scaling to become a multipoint
service: you end up building your own network
Active network challenges
• CUDN allows transfers across an existing connection, however...
• Institutions expect 10G links to run at 10G
• ... and without disruption to / because of their regular traffic
• Traffic spikes (to/from the institution or across the backbone) can
interrupt high speed flows and take time to recover (TCP
sawtooth problem)
• “I’m only getting 3Gbit/s” — could be the backbone, but could
also be the disk, transfer protocol, firewalls, local institutional
network, remote institutional network, remote server — testing
requires clean, directly-connection host with iperf
QoS?
• QoS may be necessary to smooth out flows and
avoid disruption — bandwidth might not be
sufficient if you're operating at near line rate
• We already do QoS for phones and (soon)
CCTV
• Remember — you can’t create bandwidth, just
decide how to use it (and is a political
problem)
Security developments
• University looking to harden the network and attached hosts
from cyber attacks
• New border IDS/IPS solution (NOT a firewall) — has to operate
at 20Gbit/s... at the moment
• Upgrading will be more expensive than just transceivers and
patch cords
• Push to introduce more institutional firewalls
• VLANs allow bypass but not if the clients can be separated
• Need to improve control plane security
Troubleshooting problems
• Output queue drops (link bandwidth exceeded)
• Input queue drops (exceeded internal switch capacity)
• Ask your vendor — they should have packet walks, block diagrams
of buses, bandwidth, port groups, buffer sizes and oversubscription
ratios
• We had to swap ports around on our core routers to better distribute
traffic across buses and solve problems (delivered speed increase
from 3-4Gbit/s to 8-9Gbit/s)
• Don't always go for the largest number of ports per slot, especially
towards the centre of the network
• Beware port aggregation and traffic hashing: 4x 10G LACP ≠ 40G
Things to remember
• Links are never 50% loaded — busy 50% of the
time, measured over a defined period: it’s either
busy or not busy; buffers cope with spikes
• Beware port aggregation and traffic hashing: 4x
10G LACP ≠ 40G
• We have 3x [2x 10GE] links to Janet: 60Gbit/s?
• Speeding up the network speeds up DoS attacks
Transferring data
• We leave this up to the scientists...
• But SSH implementations can have inherent
limitations, in particular OpenSSH
• Special version or hacks (our HPC have their
"SSH download accelerator”)
• We [Networks] don’t particularly care but we don’t
want them to bust the network for everyone else
End

More Related Content

What's hot

Switching techniques
Switching techniquesSwitching techniques
Switching techniquesGupta6Bindu
 
10 Circuit Packet
10 Circuit Packet10 Circuit Packet
10 Circuit PacketWaqas !!!!
 
Contention Evalution Factors-8 ccategories
Contention Evalution Factors-8 ccategoriesContention Evalution Factors-8 ccategories
Contention Evalution Factors-8 ccategoriesjaya shanmuga
 
Packet switching
Packet switchingPacket switching
Packet switchingVikash Dhal
 

What's hot (7)

Switching techniques
Switching techniquesSwitching techniques
Switching techniques
 
10 Circuit Packet
10 Circuit Packet10 Circuit Packet
10 Circuit Packet
 
packet switching
packet switchingpacket switching
packet switching
 
Contention Evalution Factors-8 ccategories
Contention Evalution Factors-8 ccategoriesContention Evalution Factors-8 ccategories
Contention Evalution Factors-8 ccategories
 
22 circuits
22 circuits22 circuits
22 circuits
 
Packet switching
Packet switchingPacket switching
Packet switching
 
Dynamic Adaptive Streaming over HTTP Dataset
Dynamic Adaptive Streaming over HTTP DatasetDynamic Adaptive Streaming over HTTP Dataset
Dynamic Adaptive Streaming over HTTP Dataset
 

Similar to Data intensive network support at Cambridge

DITEC - Fundamentals in Networking
DITEC - Fundamentals in NetworkingDITEC - Fundamentals in Networking
DITEC - Fundamentals in NetworkingRasan Samarasinghe
 
Building rugged and reliable networks with fiber automation.com
Building rugged and reliable networks with fiber   automation.comBuilding rugged and reliable networks with fiber   automation.com
Building rugged and reliable networks with fiber automation.comShane Duffy
 
ITN3052_04_Switched_Networks.pdf
ITN3052_04_Switched_Networks.pdfITN3052_04_Switched_Networks.pdf
ITN3052_04_Switched_Networks.pdfssuser2d7235
 
Network Fundamentals: Ch9 - Ethernet
Network Fundamentals: Ch9 - EthernetNetwork Fundamentals: Ch9 - Ethernet
Network Fundamentals: Ch9 - EthernetAbdelkhalik Mosa
 
Introduction to Networking
Introduction to NetworkingIntroduction to Networking
Introduction to NetworkingMohammed Adam
 
Future services on Janet
Future services on JanetFuture services on Janet
Future services on JanetJisc
 
Top schools in faridabad
Top schools in faridabadTop schools in faridabad
Top schools in faridabadEdhole.com
 
Top schools in faridabad
Top schools in faridabadTop schools in faridabad
Top schools in faridabadEdhole.com
 
Top schools in faridabad
Top schools in faridabadTop schools in faridabad
Top schools in faridabadEdhole.com
 
3_Internet_Architecture (2).pdf
3_Internet_Architecture (2).pdf3_Internet_Architecture (2).pdf
3_Internet_Architecture (2).pdfchrisoliveira37
 
presentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptpresentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptDrPreethiD1
 
presentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptpresentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptDrPreethiD1
 
presentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptpresentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptDrPreethiD1
 
Tutorial: Maximizing Performance and Network Utility with a Science DMZ
Tutorial: Maximizing Performance and Network Utility with a Science DMZTutorial: Maximizing Performance and Network Utility with a Science DMZ
Tutorial: Maximizing Performance and Network Utility with a Science DMZGlobus
 
Top schools in india
Top schools in indiaTop schools in india
Top schools in indiaEdhole.com
 
Dc ch10 : circuit switching and packet switching
Dc ch10 : circuit switching and packet switchingDc ch10 : circuit switching and packet switching
Dc ch10 : circuit switching and packet switchingSyaiful Ahdan
 

Similar to Data intensive network support at Cambridge (20)

1.CN-PPT.ppt
1.CN-PPT.ppt1.CN-PPT.ppt
1.CN-PPT.ppt
 
DITEC - Fundamentals in Networking
DITEC - Fundamentals in NetworkingDITEC - Fundamentals in Networking
DITEC - Fundamentals in Networking
 
Building rugged and reliable networks with fiber automation.com
Building rugged and reliable networks with fiber   automation.comBuilding rugged and reliable networks with fiber   automation.com
Building rugged and reliable networks with fiber automation.com
 
ITN3052_04_Switched_Networks.pdf
ITN3052_04_Switched_Networks.pdfITN3052_04_Switched_Networks.pdf
ITN3052_04_Switched_Networks.pdf
 
Switching
SwitchingSwitching
Switching
 
Network Fundamentals: Ch9 - Ethernet
Network Fundamentals: Ch9 - EthernetNetwork Fundamentals: Ch9 - Ethernet
Network Fundamentals: Ch9 - Ethernet
 
Introduction to Networking
Introduction to NetworkingIntroduction to Networking
Introduction to Networking
 
Basic networking
Basic networkingBasic networking
Basic networking
 
Week 3
Week 3Week 3
Week 3
 
Future services on Janet
Future services on JanetFuture services on Janet
Future services on Janet
 
Top schools in faridabad
Top schools in faridabadTop schools in faridabad
Top schools in faridabad
 
Top schools in faridabad
Top schools in faridabadTop schools in faridabad
Top schools in faridabad
 
Top schools in faridabad
Top schools in faridabadTop schools in faridabad
Top schools in faridabad
 
3_Internet_Architecture (2).pdf
3_Internet_Architecture (2).pdf3_Internet_Architecture (2).pdf
3_Internet_Architecture (2).pdf
 
presentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptpresentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.ppt
 
presentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptpresentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.ppt
 
presentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.pptpresentation_intro_to_networking_1457926557_181219.ppt
presentation_intro_to_networking_1457926557_181219.ppt
 
Tutorial: Maximizing Performance and Network Utility with a Science DMZ
Tutorial: Maximizing Performance and Network Utility with a Science DMZTutorial: Maximizing Performance and Network Utility with a Science DMZ
Tutorial: Maximizing Performance and Network Utility with a Science DMZ
 
Top schools in india
Top schools in indiaTop schools in india
Top schools in india
 
Dc ch10 : circuit switching and packet switching
Dc ch10 : circuit switching and packet switchingDc ch10 : circuit switching and packet switching
Dc ch10 : circuit switching and packet switching
 

More from Jisc

Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxJisc
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jisc
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxJisc
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Jisc
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Jisc
 
International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...Jisc
 
Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxJisc
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxJisc
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Jisc
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...Jisc
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptxJisc
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxJisc
 
The Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxJisc
 
Are we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxAre we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxJisc
 
JiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJisc
 
UWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxUWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxJisc
 
An introduction to Cyber Essentials
An introduction to Cyber EssentialsAn introduction to Cyber Essentials
An introduction to Cyber EssentialsJisc
 

More from Jisc (20)

Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...
 
Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptx
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptx
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptx
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptx
 
The Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptx
 
Are we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxAre we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptx
 
JiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptx
 
UWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxUWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptx
 
An introduction to Cyber Essentials
An introduction to Cyber EssentialsAn introduction to Cyber Essentials
An introduction to Cyber Essentials
 

Recently uploaded

Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxVishalSingh1417
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxVishalSingh1417
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityGeoBlogs
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin ClassesCeline George
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104misteraugie
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfSanaAli374401
 
Seal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptxSeal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptxnegromaestrong
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxVishalSingh1417
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...christianmathematics
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17Celine George
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhikauryashika82
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxDenish Jangid
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxAreebaZafar22
 
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...KokoStevan
 

Recently uploaded (20)

Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptx
 
Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdf
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Seal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptxSeal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptx
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
 

Data intensive network support at Cambridge

  • 1. Data Intensive network support at Cambridge Bob Franklin <rcf34@cam.ac.uk> UIS Networks, The University of Cambridge
  • 3. Backbone network • Backbone network ("CUDN" — Cambridge University Data Network) runs like an ISP to 175 institutions (departments and colleges) • No border firewall — it's all "outside" • Only simple access controls and DoS protection, typically for the network itself • Firewalling left to institutions: appropriate for them • Easy to deliver unfiltered, maximum bandwidth connections • Prices: 1G ~£2,500/year, 10G ~£4,500/year.
  • 4. Security structure Janet/Internet 3x 20G {Backbone 10-40G {Institution inc. firewall 1/10G Institutional security boundary Backbone security boundary
  • 5. Institutional VLANs Distribution routers Institutional firewall PoP switch "Office" data outside VLAN "Office" data inside VLAN Voice VLAN WAP VLAN Non-firewalled data VLAN(s) 2x 1G/10G multipath 2x 10G upgrading to 3x 40G multipath Office HPC
  • 6. VLAN options • Layer 2 circuit [point-to-point VLAN] using EoMPLS (undesirable) • Layer 3 routed subnet with optional access lists • Layer 3 routed subnet as part of MPLS VPN • Creates a private network between a group of institutions for a particular service or project • Need a gateway router/firewall/server to get out of the network to backbone/Janet
  • 8. Dark fibre network • University and Colleges own a private dark fibre network covering relevant parts of the city (the "GBN" — Granta Backbone Network) • Redundant paths between most areas • Circuits are singlemode and spliced end-to-end • Anyone can rent circuits and build/extend their own network, (departments/ colleges, Janet, Anglia Ruskin University) • (The CUDN rents circuits just like anyone else.) • Ideal for delivering Janet Lightpath and Aurora services • Bypasses security concerns when passing sensitive data? • Price for A/Y 2016-17 is £13.22/100m/year
  • 9. GBN Data Centre Old Addenbrooke’s University Press Hills Road 6th Form Strangeways Clinical School Chemistry Architecture Long Road 6th Form Engineering Fitzwilliam Museum Peterhouse Downing Site New Museums Site Trinity St John’s West Lucy Cavendish Wolfson CourtAstronomy Mill Lane North Cavendish Sidgwick Site Great St Mary’s Gonville & Caius King’s St Catharine’s Thompson’s Lane St John’s Road Park Parade Queens’ East Queens’ West Darwin Harvey Court Caius Pavilion Grasshopper Lodge Newnham Owlstone Croft South Green Lodge Wolfson Selwyn Gardens Leckhampton St Chad’s Selwyn Wilberforce Road Sports Ground Cripps Court Emmanuel Christ’s JesusSidney SussexADC St Edmund’s Kettle’s Yard Murray EdwardsFitzwilliam Churchill Girton University Farm St John’s East Trinity Hall Clare Old Schools Botanic Garden Chaucer Road Latham Road Downing Parker’s Piece Fenners St. Paul’s Road Kelsey Kerridge Magdalene West Magdalene East Chesterton Lane The Colony Shire Hall Magrath Avenue Corpus Christi Free School Lane Cambridge Assessment Harvey Road Open University Workers’ Educational Association Glisson Road Gresham Road Russell Street Pembroke Panton Street CRUK MRC LMB Barton Road East Grange Road South Newnham Village Newnham House Newnham Terrace Gwen Raverat Malting House Hughes Hall Mill Road West Robinson Library Memorial Court KGH Clare Hall MathsIMS Huntingdon Road Madingley Road East Fossedene Halifax Road Westminster Zoo Sub Dept Madingley Hall Whittle UIS Computer Lab Earth Sciences Soulsby Veterinary Medicine Gravel Hill Farm Laundry Farm Hauser Forum Materials Science & Metallurgy Sports Centre Institute for Manufacturing Residences Grange Road Forvie Site Storey’s Way Wychfield Saxon Street Anglia Ruskin University Midsummer Common Newmarket Road Maids Causeway Histon Road Canterbury Street Jesus Green River Cam River Cam Barton Road West Mill Lane South Boat Houses Darwin Line Book Line & Thinker Turing Loop Cats & Queens’ Storey’s Way to NMS Zoo Line Bumps & Bruises Stars & Bytes Newton Line Interchange Stations Under Consideration Leased Fibre Line (Redstone) Leased Fibre Line (Virgin) Site Fibre Line (Clinical School) The Janet Network Faculty of Education Homerton Burrell’s Field Needham Research Institute Bene’t Street Mornington Crescent 1 2 3 4 5 6 7 8 9 1 2 3 4 5 6 7 8 9 E D C B A F E D C B A F Transport for Cambridge Chemical Engineering & Biotechnology open summer ‘16 open summer ‘16 ~6km direct;~10km by fibre
  • 11. Dark fibre challenges • The GBN is easy — buy your [cheap] switches and transceivers; rent a circuit and feed your VLAN across it • Ideal for regular, point-to-point high bandwidth data transfers (e.g. MRI brain scanner to HPC cluster) • Difficulty is scaling to become a multipoint service: you end up building your own network
  • 12. Active network challenges • CUDN allows transfers across an existing connection, however... • Institutions expect 10G links to run at 10G • ... and without disruption to / because of their regular traffic • Traffic spikes (to/from the institution or across the backbone) can interrupt high speed flows and take time to recover (TCP sawtooth problem) • “I’m only getting 3Gbit/s” — could be the backbone, but could also be the disk, transfer protocol, firewalls, local institutional network, remote institutional network, remote server — testing requires clean, directly-connection host with iperf
  • 13. QoS? • QoS may be necessary to smooth out flows and avoid disruption — bandwidth might not be sufficient if you're operating at near line rate • We already do QoS for phones and (soon) CCTV • Remember — you can’t create bandwidth, just decide how to use it (and is a political problem)
  • 14. Security developments • University looking to harden the network and attached hosts from cyber attacks • New border IDS/IPS solution (NOT a firewall) — has to operate at 20Gbit/s... at the moment • Upgrading will be more expensive than just transceivers and patch cords • Push to introduce more institutional firewalls • VLANs allow bypass but not if the clients can be separated • Need to improve control plane security
  • 15. Troubleshooting problems • Output queue drops (link bandwidth exceeded) • Input queue drops (exceeded internal switch capacity) • Ask your vendor — they should have packet walks, block diagrams of buses, bandwidth, port groups, buffer sizes and oversubscription ratios • We had to swap ports around on our core routers to better distribute traffic across buses and solve problems (delivered speed increase from 3-4Gbit/s to 8-9Gbit/s) • Don't always go for the largest number of ports per slot, especially towards the centre of the network • Beware port aggregation and traffic hashing: 4x 10G LACP ≠ 40G
  • 16. Things to remember • Links are never 50% loaded — busy 50% of the time, measured over a defined period: it’s either busy or not busy; buffers cope with spikes • Beware port aggregation and traffic hashing: 4x 10G LACP ≠ 40G • We have 3x [2x 10GE] links to Janet: 60Gbit/s? • Speeding up the network speeds up DoS attacks
  • 17. Transferring data • We leave this up to the scientists... • But SSH implementations can have inherent limitations, in particular OpenSSH • Special version or hacks (our HPC have their "SSH download accelerator”) • We [Networks] don’t particularly care but we don’t want them to bust the network for everyone else
  • 18. End