HP heads into battle over virtual networking

Q&A

There's more virtualisation than ever before being installed in datacentres. Each host server runs a hypervisor that includes a virtual switch — a piece of software that manages networked data flows to and from the virtual machine under its control.

In addition, switches are no longer just switches. Their functionality has extended considerably over recent years, so, for example, they also act as firewalls, access control lists, perform intrusion-prevention tasks such as deep packet inspection, and balance loads across Ethernet ports.

As a result, the performance, resource implications and management issues of virtual switches are of increasing concern.

An industry standard called the Virtual Ethernet Port Aggregator (VEPA) has been proposed and agreed — although not without some healthy differences of opinion from contributing companies. HP's way of approaching the question is standards-based, HP executive Paul Congdon told ZDNet UK. In other words, Congdon said, it does not tamper with the Ethernet packet format — whereas Cisco's approach does, in order to aid integration with its switches, as part of its recently announced UCS initiative.

Congdon, chief technology officer of HP's ProCurve network hardware division, talked to ZDNet UK about the battle over virtual networking standards at the IEEE 802.1 committee, and other issues of the day.

Q: Network infrastructure has become a lot more complex. How has the cloud changed the switch?
A: It's all about the convergence of compute and storage today, such as blades. It's about that convergence — where does the server end, and the switch begin? We've opened up the switching fabric for applications to sit on top of it.

How do you see the take-up of 10Gb Ethernet developing, and why?
Generally speaking, people are putting off spending on newer architectures and technology, but 10Gb is really considered a mainstream technology now, so we haven't seen people holding off.

There are two reasons for this. First is because of the general move of computing towards the datacentre and, second, we've been successful in establishing 1Gb Ethernet to the desktop. Enterprises weren't so worried about matching bandwidth, as it aggregated at the centre as they are now, due to the extra power on the desktop and 802.11n wireless speeds. They're conscious of that.

From a networking viewpoint, where is virtualisation technology headed?
There are subtle things that are very interesting in the networking space. The key impact is migration, such as [VMware's tool for live migration of virtual machines] VMotion, that creates an environment where servers are mobile now in the datacentre. That puts a strain on the network fabric, so the network must be dynamically reconfigurable to make that happen.

Also, many of the issues we've been working on for years in the client space, such as security — some of those technologies will need to find their way into the datacentre control system. People are now comfortable with the datacentre's physical security, but with VMotion and new capabilities, we need to start looking at how we secure VMotion, which brings 802.1x into focus.

And where does that take the datacentre?
What we've been doing over last couple of decades has been decomposing the mainframe, from mini-computers, distributed environments, to virtualisation environments and so on. But that's created a management burden with lots of different management domains.

So the future is addressing that burden. There's a need to push things back to a larger building block that you provision from, instead of dealing with individual bits of computer storage and network. You need to deal with them in one piece.

The blade server is an example: we collapsed things into a common enclosure. We used to run different networks on backplane in the same enclosure, but now it's all converged onto Ethernet. The same thing will happen with the shared I/O environment in the blade chassis, which then allows you to provision things at a higher level.

Let's get to specifics. HP and Cisco went head to head in the standards body recently over the Virtual Ethernet Port Aggregator (VEPA). What was all that about?
With the advent of virtualisation, we now have an Ethernet switch in every hypervisor. It's been beneficial to VMs because they get connectivity, but the capabilities of switches have continued to grow. For example, we have 16 active projects in [the IEEE] 802.1 [committee] being added to switches.

So we need to ask: how much functionality should I add to a switch when it might be running on a hypervisor? It gets more expensive, and it soaks up CPU cycles and power consumption. You have to ask whether every server needs it. How can we draw a line in the sand and indicate that you no longer have to put every feature of a switch in the host server?

At HP, we can change the packet-forwarding behaviour to reduce the virtual capabilities, and that forces packets to go external from the host, so an external switch can apply those features instead.

Can you give me some examples of the kinds of features you're talking about?
Examples include ACL [access control lists] and firewall features — do you want to have the hypervisor do that, which uses up a lot of CPU cycles? The end user buys a hypervisor to run applications, not a firewall, so it's best to do this in the switch, as silicon's capabilities are going up dramatically.

So how can we augment the hypervisor switch to apply network policy?
The important thing is that ours, unlike Cisco's proprietary approach, is that it uses address tables, and other standard features of Ethernet packets without proprietary extensions.

How does HP's version of VEPA differ from Cisco's?
We had a huge battle in the standards body because their approach was hugely different from everyone else's. But we're now at a base standard that's an HP proposal that Cisco can build on. They have an additional tag that does meet their requirements. It's good how it wound up.

You're vice chair of that committee. How independent can you be?
Well, someone is paying your pay-cheque, so you're always influenced by their views. But in this instance, I wanted to create a natural evolution, to meet customer requirements using a technical approach, not an HP approach.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

11 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

14 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

17 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

22 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

1 day ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

2 days ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

2 days ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint