SlideShare a Scribd company logo
1 of 37
Download to read offline
LAN, WAN, SAN upgrades.
Hyperconverged vs traditional vs cloud etc
Experiences of two merged colleges in Wales
Simon Palmer, Head of IT development, Coleg Sir Gar
• communities - like networkshop
• Member of the TTP thettp.org
• ITSYSMAN (FE IT Systems Managers, Wales)
• And conf: https://gregynogconference.wordpress.com/
• Linux, OSS, ethernet, IoT, wifi, IDM/AM, SAML, 802.1x etc
• Follow UKNOF, UKNOT and lots of jiscmail lists.
About me
2
Interest in:
Coleg Sir Gar and Coleg Ceredigion
3
•1,000 staff
•10,000 learners including
•14 -16 GCSE school links
•16-19 FE
•19+ HE
•Work Based Learning and
apprenticeships
Coleg Sir Gar and Coleg Ceredigion
4
•5 Coleg Sir Gar campuses
•“Coleg = college”, “Sir” = like “shire”,
“Gar” is “sea”
•2 Coleg Ceredigion campuses
•Aberystwyth and Cardigan (Welsh west
coast towns)
•Coleg Sir Gar merged with UWTSD
•Coleg Ceredigion merged with UWTSD
•Coleg Sir Gar merged with Coleg
Ceredigion
Coleg Sir Gar
5
•Development team:
•Me
•Sysadmin & php, linux
•2 x web developers (php, .net, java, sql, linux)
•Graphics/CSS/websites/content
•Support team:
•7 tech’s - recruiting now - on www.fejobs.com
Things we support
6
•7 Campuses
•2200 Windows 10 (LTSB)
•300 Macs OSX
•1000 Chromebooks
•300 Windows 10 Laptops
•200 iPads
•270 Wifi Access points (around 2.5k concurrent) (Aruba instant)
•91 “stacks” of switches (ExtremeNetworks x440 10G)
•ExtremeNetworks X670/x690 core, dual home switches and 20 VMWare/XEN hosts
•200 VMs (80% Linux, 20% Windows)
Things we support
7
•Mobile Device Management MDM Mobile Iron (previously Airwatch)
•Windows management with Zenworks
•OSX management with Jamf
•Finance, Personnel, Student Records platforms
•email, file/print, licensing, mobile phones, Moodle, Google G Suite,
Office 365, all software etc.
•Building Management BMS, Solar panel monitoring etc
Requirements
8
•Improve bandwidth for teaching & learning
•Google Drive Stream, and Onedrive/Sharepoint (vs USB!)
•Reduce single points of failure (No SAN at remote sites)
•Simplify - reduce maintenance time, OOH maintenance.
•Replace old kit with supported, secure, faster etc.
•Improve backup and restore time.
•Consolidate our HA and DR strategy to try and reduce cost, and
improve RPO/RTO etc
•Allow for future SIP (VoIP) trunks
Security Certifications
9
•ISO 27001
•Cyber Essentials Plus recently
•Improved change management (local Gitlab)
•Pen testing end user devices only (not servers/network)
•2 weeks to patch!
Project 1: Compute and SAN
•2 x HP C7000 Blade enclosures (4 active, 4 backup blades)
•256G, Vsphere 6.5, AMD 2x16 core
•Flex 10, Brocade 8GB Fibre Channel (FC)
•10 servers on 4 other sites (6-10 years old)
•2 x servers per site, running Xen hypervisor (not vmware)
•DR computing environment (4 x DL385s)
•2 x HP 3Par FC SANs 40TB
•2 x 9 year old FC Hitachi HDS 2300 SANs 18TB
•WAN…
•Almost everything really!!
10
Replace EOL kit:
Compute/SAN Project Options:
•Move all compute/storage to AWS/Azure/GCP
•Replace like for like
•Hyperconverged!?
•Simplify?
•Openstack, Ovirt, Red Hat, etc.
11
Disaster Recovery vs/& Business Continuity
•DC1 and DC2 at site 1
•DC1: 3Par Fibre Channel, HP C7000’s, 10G Flex10, 4 x BL465
G8, 256G
•DC2: 3Par Fibre Channel, HP C7000’s, 10G Flex10, 4 x BL465
G8, 256G
•DC3 at site 2
•Dell Compellent, 4 x HP DL385 servers, 10G ethernet
•Veeam replication and backup
•2 x 10G Infortrend 10G iSCSI SAN for Veeam and rsync backups
12
Project 2: WAN
13
•10 years ago, 100M fibre (OpenReach ethernet) circuit ring
•5 years ago, move to PSBA MPLS 100M/1000M circuits
(reduced cost)
•Now, consider 10G WAN, MPLS is too expensive, back to fibre!
•Except fibre links to Aberystwyth or Cardigan too far
PSBA (Public Sector Network in Wales)
14
•PSBA = “Public Sector Broadband Aggregation”
•Awarded to BT in 2017? (Used to be run by Logicalis)
•Health, Councils, FE, HE, Police, etc
•All Cisco based
•Local backhauls have been traditionally 1G, recently 10G
•CSG was DDoS’d in 2014 14-17Gbps broke lots of West Wales
•(We caught Daniel Kelley, due sentencing soon…)
Project 3: Janet connection upgrade
15
•PSBA CPE equipment EOL from Cisco
•1G primary, 1G backup
•PSBA said 4G over 10G bearer (backhauls being 10G)
•Web filtering (iBoss)
•Firewall (PfSense)
•Want to move to BGP (OSPF currently and HSRP)
•Thinking about using quagga on PfSense vs Extreme Networks
BGP
•HRSP means both connections flap when attacked.
•HSRP has a single point of failure in our design (our link)
Why so much bandwidth?!
16
•Cloud! Google Drive Stream, Onedrive, Sharepoint.
•(We’ve been holding back)
•Updates! (Out of hours patching - 20Gbps at HQ)
•Adobe patching!
•Accidental patching, mismanaged/no QOS.
•Locally: Imaging, software distribution, patching etc
•(Our record for imaging is 1000 Windows 10 devices/day).
•Even some Android/IOS updates are now 1GB+
•Wifi usage is 1/3 of total traffic, pictures, video uploads. And
So, decisions:
17
•Weighed up costs:
•No need for servers at remote site IF “resilient” 10G/20G
•10G MPLS too expensive (because of NTE costs), so move back
to openreach 10G P2P
•So we will build a “ring” around Carmarthenshire
•AWS/Azure/GCP pricing worked out quite expensive… (scary)
•Some SAN/HCI vendor pricing was even more scary!
•£120K - £500+K
Telecoms
18
•All VOIP, except PRI/ISDN30 inbound links
•DDoS in 2013-2014 reduced our confidence in cloud SIP
•We found the attacker’s home IP by matching netflow, HTTP and
full logging of DNS queries around attack times, included using
the eDNS “Client Subnet” and PowerDNS.
Pricing openreach circuits
19
•Really transparent pricing (£5.5k install, £5.5k annual)
•Portal gives a good shopping cart idea of what’s available
•Resilience, Optical Spectrum Access (OSA) etc
•More cost effective than we expected
Connecting dual 10G circuits at each site
20
•Extreme X670’s (48 SFP+) at all sites, 10G stacks (SM&MM)
•Improve with X690’s at HQ and DR, (re-use X670’s at CC)
•Gives us 4 x QSFP28’s (breakouts to 16 x 25Gbps) per switch
•Or 4 x 100G ports/switch
•2 switches at each site
Where to put a cluster quorum?
21
•Reduce “split brain” risk as much as possible
•Does network team talk to storage team?
•Quorum on cloud?
•Quorum on 3rd site?
•Quorum at DR site?
•Quorum at HQ seems to make sense
•HQ has 50+% of people
•HQ has business critical services locally
•Still some SPOF areas, ducts, BT exchange etc.
Resilience limitations
22
•Fibre in ducts
23
SW1 SW2
SW1 SW2
SW1 SW2
HQ
DC1
DR
DC2
SW1 SW2
SW1 SW2
Quorum?
24
SW1 SW2
SW1 SW2
SW1 SW2
HQ
DC1
DR
DC2
SW1 SW2
SW1 SW2
Quorum?
UDP QOS by udp/physical port
25
•WOL
•PXE
•TFTP
•DHCP
•VOIP
•Priority all UDP from VM host!
MPLS vs circuits vs fibre
26
•MPLS -
•expensive Network Termination Equipment (NTE) (£20K+)
•MPLS +
•Cloud type architecture
•Cheaper for long distance links than fibre
Access Control List management
27
Switch management (ssh)
•Cluster ssh csshX
•Parallel ssh pssh
•For loop in bash
•Others
28
•Whole config backups
•Change management requirements
•Subscribe to change notifications
Switch management (git)
29
Bandwidth/problem monitoring
•Cacti & php weathermap
•Nagios (Want to move to Icinga2)
•Graylog
30
How to get quotes for BT circuits
31
Janet network connection upgrade
32
•2 sites with internet breakout
•Web filtering (iBoss)
•Firewall (PfSense)
•Want to move to BGP (OSPF
currently)
•Thinking about using quagga on
PfSense vs Extreme Networks BGP
VXLAN
33
•Switches support it
•Resilience/DR for ESXi hosts in 2
Ceredigion sites
•(Spread L2 VLAN over MPLS L3
links)
Compatible Optics
34
•We’re using throughout - saved
LOTS of money
•<£150/10G LX SFP+
•10G DAC’s ~£30 each
DAC and QSFP28 breakout cables
35
•100G to 4 x 25G
•Flex 10 is active/passive in C7000
•4 x 10G DAC cables per
active/backup Flex10 card
iSCSI and data network over 100G ?
36
•Segment by VLAN in host vs
external to host?
New build problem
37
•Network design spec given to
contractor
•CCTV install bypassed, Cat5e, no
patch panel even!

More Related Content

What's hot

Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...gogo6
 
Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44Jisc
 
Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44Jisc
 
CEI-56G - Testing Considerations
CEI-56G - Testing Considerations CEI-56G - Testing Considerations
CEI-56G - Testing Considerations Deborah Porchivina
 
Data Center Interconnectivity Trends and Their Effect on Optical Networking
Data Center Interconnectivity Trends and Their Effect on Optical NetworkingData Center Interconnectivity Trends and Their Effect on Optical Networking
Data Center Interconnectivity Trends and Their Effect on Optical NetworkingADVA
 
Introducing the Future of Data Center Interconnect Networks
Introducing the Future of Data Center Interconnect NetworksIntroducing the Future of Data Center Interconnect Networks
Introducing the Future of Data Center Interconnect NetworksADVA
 
Evolution of Network Synchronization Technologies
Evolution of Network Synchronization TechnologiesEvolution of Network Synchronization Technologies
Evolution of Network Synchronization TechnologiesADVA
 
Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...
Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...
Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...ADVA
 
Cloud Traffic Engineer – Google Espresso Project by Shaowen Ma
Cloud Traffic Engineer – Google Espresso Project  by Shaowen MaCloud Traffic Engineer – Google Espresso Project  by Shaowen Ma
Cloud Traffic Engineer – Google Espresso Project by Shaowen MaMyNOG
 
Synchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation NetworksSynchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation NetworksADVA
 
Open stackdaykorea2016 wedge
Open stackdaykorea2016 wedgeOpen stackdaykorea2016 wedge
Open stackdaykorea2016 wedgeJunho Suh
 
PLNOG 13: Piotr Szolkowski: 100G Ethernet – Case Study
PLNOG 13: Piotr Szolkowski: 100G Ethernet – Case StudyPLNOG 13: Piotr Szolkowski: 100G Ethernet – Case Study
PLNOG 13: Piotr Szolkowski: 100G Ethernet – Case StudyPROIDEA
 
Preliminary Test Results: High Performance Optically Pumped Cesium Beam Clock
Preliminary Test Results: High Performance Optically Pumped Cesium Beam ClockPreliminary Test Results: High Performance Optically Pumped Cesium Beam Clock
Preliminary Test Results: High Performance Optically Pumped Cesium Beam ClockADVA
 
ENRZ Advanced Modulation for Low Latency Applications
ENRZ Advanced Modulation for Low Latency ApplicationsENRZ Advanced Modulation for Low Latency Applications
ENRZ Advanced Modulation for Low Latency ApplicationsDeborah Porchivina
 
PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland
PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland
PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland PROIDEA
 
OIF 2015 FOE Architecture Presentation
OIF 2015 FOE Architecture PresentationOIF 2015 FOE Architecture Presentation
OIF 2015 FOE Architecture PresentationDeborah Porchivina
 
Sspi day out_2014_advantech-mario_jorge
Sspi day out_2014_advantech-mario_jorgeSspi day out_2014_advantech-mario_jorge
Sspi day out_2014_advantech-mario_jorgeSSPI Brasil
 

What's hot (20)

Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
 
Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44
 
Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44
 
CEI-56G - Testing Considerations
CEI-56G - Testing Considerations CEI-56G - Testing Considerations
CEI-56G - Testing Considerations
 
05 - IDNOG04 - Bambang Gunawan (Juniper) - Segment Routing
05 - IDNOG04 - Bambang Gunawan (Juniper) - Segment Routing05 - IDNOG04 - Bambang Gunawan (Juniper) - Segment Routing
05 - IDNOG04 - Bambang Gunawan (Juniper) - Segment Routing
 
Data Center Interconnectivity Trends and Their Effect on Optical Networking
Data Center Interconnectivity Trends and Their Effect on Optical NetworkingData Center Interconnectivity Trends and Their Effect on Optical Networking
Data Center Interconnectivity Trends and Their Effect on Optical Networking
 
Introducing the Future of Data Center Interconnect Networks
Introducing the Future of Data Center Interconnect NetworksIntroducing the Future of Data Center Interconnect Networks
Introducing the Future of Data Center Interconnect Networks
 
Evolution of Network Synchronization Technologies
Evolution of Network Synchronization TechnologiesEvolution of Network Synchronization Technologies
Evolution of Network Synchronization Technologies
 
Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...
Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...
Introducing the ADVA FSP 150 ProVM – Assured Virtual Network Functions at the...
 
Cloud Traffic Engineer – Google Espresso Project by Shaowen Ma
Cloud Traffic Engineer – Google Espresso Project  by Shaowen MaCloud Traffic Engineer – Google Espresso Project  by Shaowen Ma
Cloud Traffic Engineer – Google Espresso Project by Shaowen Ma
 
Synchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation NetworksSynchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation Networks
 
Open stackdaykorea2016 wedge
Open stackdaykorea2016 wedgeOpen stackdaykorea2016 wedge
Open stackdaykorea2016 wedge
 
UDP Offload Engine (UOE)
UDP Offload Engine (UOE)UDP Offload Engine (UOE)
UDP Offload Engine (UOE)
 
PLNOG 13: Piotr Szolkowski: 100G Ethernet – Case Study
PLNOG 13: Piotr Szolkowski: 100G Ethernet – Case StudyPLNOG 13: Piotr Szolkowski: 100G Ethernet – Case Study
PLNOG 13: Piotr Szolkowski: 100G Ethernet – Case Study
 
Preliminary Test Results: High Performance Optically Pumped Cesium Beam Clock
Preliminary Test Results: High Performance Optically Pumped Cesium Beam ClockPreliminary Test Results: High Performance Optically Pumped Cesium Beam Clock
Preliminary Test Results: High Performance Optically Pumped Cesium Beam Clock
 
ENRZ Advanced Modulation for Low Latency Applications
ENRZ Advanced Modulation for Low Latency ApplicationsENRZ Advanced Modulation for Low Latency Applications
ENRZ Advanced Modulation for Low Latency Applications
 
OIF CEI 56-G-FOE-April2015
OIF CEI 56-G-FOE-April2015OIF CEI 56-G-FOE-April2015
OIF CEI 56-G-FOE-April2015
 
PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland
PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland
PLNOG 6: Dariusz Wichniewicz - AC-X, ATMAN, Telehouse. Poland
 
OIF 2015 FOE Architecture Presentation
OIF 2015 FOE Architecture PresentationOIF 2015 FOE Architecture Presentation
OIF 2015 FOE Architecture Presentation
 
Sspi day out_2014_advantech-mario_jorge
Sspi day out_2014_advantech-mario_jorgeSspi day out_2014_advantech-mario_jorge
Sspi day out_2014_advantech-mario_jorge
 

Similar to LAN, WAN, SAN upgrades: hyperconverged vs traditional vs cloud

100G Networking Berlin.pdf
100G Networking Berlin.pdf100G Networking Berlin.pdf
100G Networking Berlin.pdfJunZhao68
 
PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...
PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...
PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...PROIDEA
 
High performace network of Cloud Native Taiwan User Group
High performace network of Cloud Native Taiwan User GroupHigh performace network of Cloud Native Taiwan User Group
High performace network of Cloud Native Taiwan User GroupHungWei Chiu
 
PLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz Jantas
PLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz JantasPLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz Jantas
PLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz JantasPROIDEA
 
Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...
Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...
Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...ETCenter
 
Deploying flash storage for Ceph without compromising performance
Deploying flash storage for Ceph without compromising performance Deploying flash storage for Ceph without compromising performance
Deploying flash storage for Ceph without compromising performance Ceph Community
 
Bare Metal Club ATX: Networking Discussion
Bare Metal Club ATX: Networking DiscussionBare Metal Club ATX: Networking Discussion
Bare Metal Club ATX: Networking DiscussionCarl Perry
 
Hadoop Networking at Datasift
Hadoop Networking at DatasiftHadoop Networking at Datasift
Hadoop Networking at Datasifthuguk
 
The $1000 Internet Exchange
The $1000 Internet Exchange The $1000 Internet Exchange
The $1000 Internet Exchange Remco van Mook
 
PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters
PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters
PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters PROIDEA
 
HPCS16 - Frederick Lefebvre - Bridging the last mile
HPCS16 - Frederick Lefebvre - Bridging the last mileHPCS16 - Frederick Lefebvre - Bridging the last mile
HPCS16 - Frederick Lefebvre - Bridging the last mileFrédérick Lefebvre
 
Lecture notes - Data Centers________.pptx
Lecture notes - Data Centers________.pptxLecture notes - Data Centers________.pptx
Lecture notes - Data Centers________.pptxSandeepGupta229023
 
DPDK Summit 2015 - Aspera - Charles Shiflett
DPDK Summit 2015 - Aspera - Charles ShiflettDPDK Summit 2015 - Aspera - Charles Shiflett
DPDK Summit 2015 - Aspera - Charles ShiflettJim St. Leger
 
New idc architecture
New idc architectureNew idc architecture
New idc architectureMason Mei
 
Network-aware Data Management for Large Scale Distributed Applications, IBM R...
Network-aware Data Management for Large Scale Distributed Applications, IBM R...Network-aware Data Management for Large Scale Distributed Applications, IBM R...
Network-aware Data Management for Large Scale Distributed Applications, IBM R...balmanme
 
Designing and deploying converged storage area networks final
Designing and deploying converged storage area networks finalDesigning and deploying converged storage area networks final
Designing and deploying converged storage area networks finalBhavin Yadav
 
High-performance 32G Fibre Channel Module on MDS 9700 Directors:
High-performance 32G Fibre Channel Module on MDS 9700 Directors:High-performance 32G Fibre Channel Module on MDS 9700 Directors:
High-performance 32G Fibre Channel Module on MDS 9700 Directors:Tony Antony
 
Building Physical in a Virtual World
Building Physical in a Virtual WorldBuilding Physical in a Virtual World
Building Physical in a Virtual WorldChris Maxwell
 

Similar to LAN, WAN, SAN upgrades: hyperconverged vs traditional vs cloud (20)

100G Networking Berlin.pdf
100G Networking Berlin.pdf100G Networking Berlin.pdf
100G Networking Berlin.pdf
 
PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...
PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...
PLNOG 13: Alexis Dacquay: Handling high-bandwidth-consumption applications in...
 
High performace network of Cloud Native Taiwan User Group
High performace network of Cloud Native Taiwan User GroupHigh performace network of Cloud Native Taiwan User Group
High performace network of Cloud Native Taiwan User Group
 
PLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz Jantas
PLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz JantasPLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz Jantas
PLNOG14: Konwergentność, Wydajność, Szybkość w Data Center - Kazimierz Jantas
 
Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...
Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...
Shoot the Bird: Linear Broadcast Distribution on AWS by Usman Shakeel of Amaz...
 
Deploying flash storage for Ceph without compromising performance
Deploying flash storage for Ceph without compromising performance Deploying flash storage for Ceph without compromising performance
Deploying flash storage for Ceph without compromising performance
 
Bare Metal Club ATX: Networking Discussion
Bare Metal Club ATX: Networking DiscussionBare Metal Club ATX: Networking Discussion
Bare Metal Club ATX: Networking Discussion
 
100 M pps on PC.
100 M pps on PC.100 M pps on PC.
100 M pps on PC.
 
Hadoop Networking at Datasift
Hadoop Networking at DatasiftHadoop Networking at Datasift
Hadoop Networking at Datasift
 
The $1000 Internet Exchange
The $1000 Internet Exchange The $1000 Internet Exchange
The $1000 Internet Exchange
 
PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters
PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters
PLNOG 8: Ivan Pepelnjak - Data Center Fabrics - What Really Matters
 
HPCS16 - Frederick Lefebvre - Bridging the last mile
HPCS16 - Frederick Lefebvre - Bridging the last mileHPCS16 - Frederick Lefebvre - Bridging the last mile
HPCS16 - Frederick Lefebvre - Bridging the last mile
 
Lecture notes - Data Centers________.pptx
Lecture notes - Data Centers________.pptxLecture notes - Data Centers________.pptx
Lecture notes - Data Centers________.pptx
 
IPv6 on the Interop Network
IPv6 on the Interop NetworkIPv6 on the Interop Network
IPv6 on the Interop Network
 
DPDK Summit 2015 - Aspera - Charles Shiflett
DPDK Summit 2015 - Aspera - Charles ShiflettDPDK Summit 2015 - Aspera - Charles Shiflett
DPDK Summit 2015 - Aspera - Charles Shiflett
 
New idc architecture
New idc architectureNew idc architecture
New idc architecture
 
Network-aware Data Management for Large Scale Distributed Applications, IBM R...
Network-aware Data Management for Large Scale Distributed Applications, IBM R...Network-aware Data Management for Large Scale Distributed Applications, IBM R...
Network-aware Data Management for Large Scale Distributed Applications, IBM R...
 
Designing and deploying converged storage area networks final
Designing and deploying converged storage area networks finalDesigning and deploying converged storage area networks final
Designing and deploying converged storage area networks final
 
High-performance 32G Fibre Channel Module on MDS 9700 Directors:
High-performance 32G Fibre Channel Module on MDS 9700 Directors:High-performance 32G Fibre Channel Module on MDS 9700 Directors:
High-performance 32G Fibre Channel Module on MDS 9700 Directors:
 
Building Physical in a Virtual World
Building Physical in a Virtual WorldBuilding Physical in a Virtual World
Building Physical in a Virtual World
 

More from Jisc

Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxJisc
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxJisc
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Jisc
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...Jisc
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptxJisc
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxJisc
 
The Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxJisc
 
Are we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxAre we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxJisc
 
JiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJisc
 
UWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxUWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxJisc
 
An introduction to Cyber Essentials
An introduction to Cyber EssentialsAn introduction to Cyber Essentials
An introduction to Cyber EssentialsJisc
 
MarkChilds.pptx
MarkChilds.pptxMarkChilds.pptx
MarkChilds.pptxJisc
 
RStrachanOct23.pptx
RStrachanOct23.pptxRStrachanOct23.pptx
RStrachanOct23.pptxJisc
 
ISDX2 Oct 2023 .pptx
ISDX2 Oct 2023 .pptxISDX2 Oct 2023 .pptx
ISDX2 Oct 2023 .pptxJisc
 
FerrellWalker.pptx
FerrellWalker.pptxFerrellWalker.pptx
FerrellWalker.pptxJisc
 
ExpertsknightOct23.pptx
ExpertsknightOct23.pptxExpertsknightOct23.pptx
ExpertsknightOct23.pptxJisc
 
BeyondBlended17Oct23.pptx
BeyondBlended17Oct23.pptxBeyondBlended17Oct23.pptx
BeyondBlended17Oct23.pptxJisc
 

More from Jisc (20)

Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptx
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptx
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptx
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptx
 
The Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptx
 
Are we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxAre we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptx
 
JiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptx
 
UWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxUWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptx
 
An introduction to Cyber Essentials
An introduction to Cyber EssentialsAn introduction to Cyber Essentials
An introduction to Cyber Essentials
 
MarkChilds.pptx
MarkChilds.pptxMarkChilds.pptx
MarkChilds.pptx
 
RStrachanOct23.pptx
RStrachanOct23.pptxRStrachanOct23.pptx
RStrachanOct23.pptx
 
ISDX2 Oct 2023 .pptx
ISDX2 Oct 2023 .pptxISDX2 Oct 2023 .pptx
ISDX2 Oct 2023 .pptx
 
FerrellWalker.pptx
FerrellWalker.pptxFerrellWalker.pptx
FerrellWalker.pptx
 
ExpertsknightOct23.pptx
ExpertsknightOct23.pptxExpertsknightOct23.pptx
ExpertsknightOct23.pptx
 
BeyondBlended17Oct23.pptx
BeyondBlended17Oct23.pptxBeyondBlended17Oct23.pptx
BeyondBlended17Oct23.pptx
 

Recently uploaded

Crea il tuo assistente AI con lo Stregatto (open source python framework)
Crea il tuo assistente AI con lo Stregatto (open source python framework)Crea il tuo assistente AI con lo Stregatto (open source python framework)
Crea il tuo assistente AI con lo Stregatto (open source python framework)Commit University
 
Using IESVE for Loads, Sizing and Heat Pump Modeling to Achieve Decarbonization
Using IESVE for Loads, Sizing and Heat Pump Modeling to Achieve DecarbonizationUsing IESVE for Loads, Sizing and Heat Pump Modeling to Achieve Decarbonization
Using IESVE for Loads, Sizing and Heat Pump Modeling to Achieve DecarbonizationIES VE
 
COMPUTER 10: Lesson 7 - File Storage and Online Collaboration
COMPUTER 10: Lesson 7 - File Storage and Online CollaborationCOMPUTER 10: Lesson 7 - File Storage and Online Collaboration
COMPUTER 10: Lesson 7 - File Storage and Online Collaborationbruanjhuli
 
Nanopower In Semiconductor Industry.pdf
Nanopower  In Semiconductor Industry.pdfNanopower  In Semiconductor Industry.pdf
Nanopower In Semiconductor Industry.pdfPedro Manuel
 
Artificial Intelligence & SEO Trends for 2024
Artificial Intelligence & SEO Trends for 2024Artificial Intelligence & SEO Trends for 2024
Artificial Intelligence & SEO Trends for 2024D Cloud Solutions
 
AI Fame Rush Review – Virtual Influencer Creation In Just Minutes
AI Fame Rush Review – Virtual Influencer Creation In Just MinutesAI Fame Rush Review – Virtual Influencer Creation In Just Minutes
AI Fame Rush Review – Virtual Influencer Creation In Just MinutesMd Hossain Ali
 
IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019
IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019
IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019IES VE
 
Comparing Sidecar-less Service Mesh from Cilium and Istio
Comparing Sidecar-less Service Mesh from Cilium and IstioComparing Sidecar-less Service Mesh from Cilium and Istio
Comparing Sidecar-less Service Mesh from Cilium and IstioChristian Posta
 
Meet the new FSP 3000 M-Flex800™
Meet the new FSP 3000 M-Flex800™Meet the new FSP 3000 M-Flex800™
Meet the new FSP 3000 M-Flex800™Adtran
 
UiPath Community: AI for UiPath Automation Developers
UiPath Community: AI for UiPath Automation DevelopersUiPath Community: AI for UiPath Automation Developers
UiPath Community: AI for UiPath Automation DevelopersUiPathCommunity
 
Introduction to Matsuo Laboratory (ENG).pptx
Introduction to Matsuo Laboratory (ENG).pptxIntroduction to Matsuo Laboratory (ENG).pptx
Introduction to Matsuo Laboratory (ENG).pptxMatsuo Lab
 
Building Your Own AI Instance (TBLC AI )
Building Your Own AI Instance (TBLC AI )Building Your Own AI Instance (TBLC AI )
Building Your Own AI Instance (TBLC AI )Brian Pichman
 
UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...
UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...
UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...UbiTrack UK
 
Designing A Time bound resource download URL
Designing A Time bound resource download URLDesigning A Time bound resource download URL
Designing A Time bound resource download URLRuncy Oommen
 
activity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdf
activity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdf
activity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdfJamie (Taka) Wang
 
Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...
Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...
Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...Will Schroeder
 
Linked Data in Production: Moving Beyond Ontologies
Linked Data in Production: Moving Beyond OntologiesLinked Data in Production: Moving Beyond Ontologies
Linked Data in Production: Moving Beyond OntologiesDavid Newbury
 
AI You Can Trust - Ensuring Success with Data Integrity Webinar
AI You Can Trust - Ensuring Success with Data Integrity WebinarAI You Can Trust - Ensuring Success with Data Integrity Webinar
AI You Can Trust - Ensuring Success with Data Integrity WebinarPrecisely
 
UiPath Studio Web workshop series - Day 8
UiPath Studio Web workshop series - Day 8UiPath Studio Web workshop series - Day 8
UiPath Studio Web workshop series - Day 8DianaGray10
 

Recently uploaded (20)

Crea il tuo assistente AI con lo Stregatto (open source python framework)
Crea il tuo assistente AI con lo Stregatto (open source python framework)Crea il tuo assistente AI con lo Stregatto (open source python framework)
Crea il tuo assistente AI con lo Stregatto (open source python framework)
 
Using IESVE for Loads, Sizing and Heat Pump Modeling to Achieve Decarbonization
Using IESVE for Loads, Sizing and Heat Pump Modeling to Achieve DecarbonizationUsing IESVE for Loads, Sizing and Heat Pump Modeling to Achieve Decarbonization
Using IESVE for Loads, Sizing and Heat Pump Modeling to Achieve Decarbonization
 
COMPUTER 10: Lesson 7 - File Storage and Online Collaboration
COMPUTER 10: Lesson 7 - File Storage and Online CollaborationCOMPUTER 10: Lesson 7 - File Storage and Online Collaboration
COMPUTER 10: Lesson 7 - File Storage and Online Collaboration
 
Nanopower In Semiconductor Industry.pdf
Nanopower  In Semiconductor Industry.pdfNanopower  In Semiconductor Industry.pdf
Nanopower In Semiconductor Industry.pdf
 
Artificial Intelligence & SEO Trends for 2024
Artificial Intelligence & SEO Trends for 2024Artificial Intelligence & SEO Trends for 2024
Artificial Intelligence & SEO Trends for 2024
 
AI Fame Rush Review – Virtual Influencer Creation In Just Minutes
AI Fame Rush Review – Virtual Influencer Creation In Just MinutesAI Fame Rush Review – Virtual Influencer Creation In Just Minutes
AI Fame Rush Review – Virtual Influencer Creation In Just Minutes
 
IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019
IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019
IESVE Software for Florida Code Compliance Using ASHRAE 90.1-2019
 
Comparing Sidecar-less Service Mesh from Cilium and Istio
Comparing Sidecar-less Service Mesh from Cilium and IstioComparing Sidecar-less Service Mesh from Cilium and Istio
Comparing Sidecar-less Service Mesh from Cilium and Istio
 
Meet the new FSP 3000 M-Flex800™
Meet the new FSP 3000 M-Flex800™Meet the new FSP 3000 M-Flex800™
Meet the new FSP 3000 M-Flex800™
 
UiPath Community: AI for UiPath Automation Developers
UiPath Community: AI for UiPath Automation DevelopersUiPath Community: AI for UiPath Automation Developers
UiPath Community: AI for UiPath Automation Developers
 
Introduction to Matsuo Laboratory (ENG).pptx
Introduction to Matsuo Laboratory (ENG).pptxIntroduction to Matsuo Laboratory (ENG).pptx
Introduction to Matsuo Laboratory (ENG).pptx
 
Building Your Own AI Instance (TBLC AI )
Building Your Own AI Instance (TBLC AI )Building Your Own AI Instance (TBLC AI )
Building Your Own AI Instance (TBLC AI )
 
UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...
UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...
UWB Technology for Enhanced Indoor and Outdoor Positioning in Physiological M...
 
Designing A Time bound resource download URL
Designing A Time bound resource download URLDesigning A Time bound resource download URL
Designing A Time bound resource download URL
 
activity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdf
activity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdf
activity_diagram_combine_v4_20190827.pdfactivity_diagram_combine_v4_20190827.pdf
 
Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...
Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...
Apres-Cyber - The Data Dilemma: Bridging Offensive Operations and Machine Lea...
 
Linked Data in Production: Moving Beyond Ontologies
Linked Data in Production: Moving Beyond OntologiesLinked Data in Production: Moving Beyond Ontologies
Linked Data in Production: Moving Beyond Ontologies
 
AI You Can Trust - Ensuring Success with Data Integrity Webinar
AI You Can Trust - Ensuring Success with Data Integrity WebinarAI You Can Trust - Ensuring Success with Data Integrity Webinar
AI You Can Trust - Ensuring Success with Data Integrity Webinar
 
20230104 - machine vision
20230104 - machine vision20230104 - machine vision
20230104 - machine vision
 
UiPath Studio Web workshop series - Day 8
UiPath Studio Web workshop series - Day 8UiPath Studio Web workshop series - Day 8
UiPath Studio Web workshop series - Day 8
 

LAN, WAN, SAN upgrades: hyperconverged vs traditional vs cloud

  • 1. LAN, WAN, SAN upgrades. Hyperconverged vs traditional vs cloud etc Experiences of two merged colleges in Wales Simon Palmer, Head of IT development, Coleg Sir Gar
  • 2. • communities - like networkshop • Member of the TTP thettp.org • ITSYSMAN (FE IT Systems Managers, Wales) • And conf: https://gregynogconference.wordpress.com/ • Linux, OSS, ethernet, IoT, wifi, IDM/AM, SAML, 802.1x etc • Follow UKNOF, UKNOT and lots of jiscmail lists. About me 2 Interest in:
  • 3. Coleg Sir Gar and Coleg Ceredigion 3 •1,000 staff •10,000 learners including •14 -16 GCSE school links •16-19 FE •19+ HE •Work Based Learning and apprenticeships
  • 4. Coleg Sir Gar and Coleg Ceredigion 4 •5 Coleg Sir Gar campuses •“Coleg = college”, “Sir” = like “shire”, “Gar” is “sea” •2 Coleg Ceredigion campuses •Aberystwyth and Cardigan (Welsh west coast towns) •Coleg Sir Gar merged with UWTSD •Coleg Ceredigion merged with UWTSD •Coleg Sir Gar merged with Coleg Ceredigion
  • 5. Coleg Sir Gar 5 •Development team: •Me •Sysadmin & php, linux •2 x web developers (php, .net, java, sql, linux) •Graphics/CSS/websites/content •Support team: •7 tech’s - recruiting now - on www.fejobs.com
  • 6. Things we support 6 •7 Campuses •2200 Windows 10 (LTSB) •300 Macs OSX •1000 Chromebooks •300 Windows 10 Laptops •200 iPads •270 Wifi Access points (around 2.5k concurrent) (Aruba instant) •91 “stacks” of switches (ExtremeNetworks x440 10G) •ExtremeNetworks X670/x690 core, dual home switches and 20 VMWare/XEN hosts •200 VMs (80% Linux, 20% Windows)
  • 7. Things we support 7 •Mobile Device Management MDM Mobile Iron (previously Airwatch) •Windows management with Zenworks •OSX management with Jamf •Finance, Personnel, Student Records platforms •email, file/print, licensing, mobile phones, Moodle, Google G Suite, Office 365, all software etc. •Building Management BMS, Solar panel monitoring etc
  • 8. Requirements 8 •Improve bandwidth for teaching & learning •Google Drive Stream, and Onedrive/Sharepoint (vs USB!) •Reduce single points of failure (No SAN at remote sites) •Simplify - reduce maintenance time, OOH maintenance. •Replace old kit with supported, secure, faster etc. •Improve backup and restore time. •Consolidate our HA and DR strategy to try and reduce cost, and improve RPO/RTO etc •Allow for future SIP (VoIP) trunks
  • 9. Security Certifications 9 •ISO 27001 •Cyber Essentials Plus recently •Improved change management (local Gitlab) •Pen testing end user devices only (not servers/network) •2 weeks to patch!
  • 10. Project 1: Compute and SAN •2 x HP C7000 Blade enclosures (4 active, 4 backup blades) •256G, Vsphere 6.5, AMD 2x16 core •Flex 10, Brocade 8GB Fibre Channel (FC) •10 servers on 4 other sites (6-10 years old) •2 x servers per site, running Xen hypervisor (not vmware) •DR computing environment (4 x DL385s) •2 x HP 3Par FC SANs 40TB •2 x 9 year old FC Hitachi HDS 2300 SANs 18TB •WAN… •Almost everything really!! 10 Replace EOL kit:
  • 11. Compute/SAN Project Options: •Move all compute/storage to AWS/Azure/GCP •Replace like for like •Hyperconverged!? •Simplify? •Openstack, Ovirt, Red Hat, etc. 11
  • 12. Disaster Recovery vs/& Business Continuity •DC1 and DC2 at site 1 •DC1: 3Par Fibre Channel, HP C7000’s, 10G Flex10, 4 x BL465 G8, 256G •DC2: 3Par Fibre Channel, HP C7000’s, 10G Flex10, 4 x BL465 G8, 256G •DC3 at site 2 •Dell Compellent, 4 x HP DL385 servers, 10G ethernet •Veeam replication and backup •2 x 10G Infortrend 10G iSCSI SAN for Veeam and rsync backups 12
  • 13. Project 2: WAN 13 •10 years ago, 100M fibre (OpenReach ethernet) circuit ring •5 years ago, move to PSBA MPLS 100M/1000M circuits (reduced cost) •Now, consider 10G WAN, MPLS is too expensive, back to fibre! •Except fibre links to Aberystwyth or Cardigan too far
  • 14. PSBA (Public Sector Network in Wales) 14 •PSBA = “Public Sector Broadband Aggregation” •Awarded to BT in 2017? (Used to be run by Logicalis) •Health, Councils, FE, HE, Police, etc •All Cisco based •Local backhauls have been traditionally 1G, recently 10G •CSG was DDoS’d in 2014 14-17Gbps broke lots of West Wales •(We caught Daniel Kelley, due sentencing soon…)
  • 15. Project 3: Janet connection upgrade 15 •PSBA CPE equipment EOL from Cisco •1G primary, 1G backup •PSBA said 4G over 10G bearer (backhauls being 10G) •Web filtering (iBoss) •Firewall (PfSense) •Want to move to BGP (OSPF currently and HSRP) •Thinking about using quagga on PfSense vs Extreme Networks BGP •HRSP means both connections flap when attacked. •HSRP has a single point of failure in our design (our link)
  • 16. Why so much bandwidth?! 16 •Cloud! Google Drive Stream, Onedrive, Sharepoint. •(We’ve been holding back) •Updates! (Out of hours patching - 20Gbps at HQ) •Adobe patching! •Accidental patching, mismanaged/no QOS. •Locally: Imaging, software distribution, patching etc •(Our record for imaging is 1000 Windows 10 devices/day). •Even some Android/IOS updates are now 1GB+ •Wifi usage is 1/3 of total traffic, pictures, video uploads. And
  • 17. So, decisions: 17 •Weighed up costs: •No need for servers at remote site IF “resilient” 10G/20G •10G MPLS too expensive (because of NTE costs), so move back to openreach 10G P2P •So we will build a “ring” around Carmarthenshire •AWS/Azure/GCP pricing worked out quite expensive… (scary) •Some SAN/HCI vendor pricing was even more scary! •£120K - £500+K
  • 18. Telecoms 18 •All VOIP, except PRI/ISDN30 inbound links •DDoS in 2013-2014 reduced our confidence in cloud SIP •We found the attacker’s home IP by matching netflow, HTTP and full logging of DNS queries around attack times, included using the eDNS “Client Subnet” and PowerDNS.
  • 19. Pricing openreach circuits 19 •Really transparent pricing (£5.5k install, £5.5k annual) •Portal gives a good shopping cart idea of what’s available •Resilience, Optical Spectrum Access (OSA) etc •More cost effective than we expected
  • 20. Connecting dual 10G circuits at each site 20 •Extreme X670’s (48 SFP+) at all sites, 10G stacks (SM&MM) •Improve with X690’s at HQ and DR, (re-use X670’s at CC) •Gives us 4 x QSFP28’s (breakouts to 16 x 25Gbps) per switch •Or 4 x 100G ports/switch •2 switches at each site
  • 21. Where to put a cluster quorum? 21 •Reduce “split brain” risk as much as possible •Does network team talk to storage team? •Quorum on cloud? •Quorum on 3rd site? •Quorum at DR site? •Quorum at HQ seems to make sense •HQ has 50+% of people •HQ has business critical services locally •Still some SPOF areas, ducts, BT exchange etc.
  • 23. 23 SW1 SW2 SW1 SW2 SW1 SW2 HQ DC1 DR DC2 SW1 SW2 SW1 SW2 Quorum?
  • 24. 24 SW1 SW2 SW1 SW2 SW1 SW2 HQ DC1 DR DC2 SW1 SW2 SW1 SW2 Quorum?
  • 25. UDP QOS by udp/physical port 25 •WOL •PXE •TFTP •DHCP •VOIP •Priority all UDP from VM host!
  • 26. MPLS vs circuits vs fibre 26 •MPLS - •expensive Network Termination Equipment (NTE) (£20K+) •MPLS + •Cloud type architecture •Cheaper for long distance links than fibre
  • 27. Access Control List management 27
  • 28. Switch management (ssh) •Cluster ssh csshX •Parallel ssh pssh •For loop in bash •Others 28
  • 29. •Whole config backups •Change management requirements •Subscribe to change notifications Switch management (git) 29
  • 30. Bandwidth/problem monitoring •Cacti & php weathermap •Nagios (Want to move to Icinga2) •Graylog 30
  • 31. How to get quotes for BT circuits 31
  • 32. Janet network connection upgrade 32 •2 sites with internet breakout •Web filtering (iBoss) •Firewall (PfSense) •Want to move to BGP (OSPF currently) •Thinking about using quagga on PfSense vs Extreme Networks BGP
  • 33. VXLAN 33 •Switches support it •Resilience/DR for ESXi hosts in 2 Ceredigion sites •(Spread L2 VLAN over MPLS L3 links)
  • 34. Compatible Optics 34 •We’re using throughout - saved LOTS of money •<£150/10G LX SFP+ •10G DAC’s ~£30 each
  • 35. DAC and QSFP28 breakout cables 35 •100G to 4 x 25G •Flex 10 is active/passive in C7000 •4 x 10G DAC cables per active/backup Flex10 card
  • 36. iSCSI and data network over 100G ? 36 •Segment by VLAN in host vs external to host?
  • 37. New build problem 37 •Network design spec given to contractor •CCTV install bypassed, Cat5e, no patch panel even!