First Look At Oak Ridge’s “Frontier” Exascaler, Contrasted To Argonne’s “Aurora”

The fiscal year of the federal government in the United States ends on September 30, and whether we all knew it or not, the US Department of Energy had a revised goal of beginning the deployment of at least one exascale-class supercomputing system before fiscal 2021 ended and fiscal 2022 began on October 1.

First Look At Oak Ridge’s “Frontier” Exascaler, Contrasted To Argonne’s “Aurora” was written by Timothy Prickett Morgan at The Next Platform.

Network Break 353: New Juniper Chassis Tops 400G; Akamai Spends Big Money On Microsegmentation

This week's Network Break talks about a new data center chassis from Juniper, why Akamai spent $600 million to buy security company Guardicore, what happened to Zoom's big acquisition of a contact center company, and more tech news.

The post Network Break 353: New Juniper Chassis Tops 400G; Akamai Spends Big Money On Microsegmentation appeared first on Packet Pushers.

AWS Networking – Part IX: AWS VPC Control-Plane – Mapping Servce

 

Introduction


This chapter explains the VPC Control-Plane operation when two EC2 instances within the same subnet initiate TCP session between themself. In our example, EC2 instances are launched in two different physical servers. Both instances have an Elastic Network Interface (ENI) card. The left-hand side EC2’s ENI has MAC/IP addresses cafe:0001:0001/10.10.1.11 and the right-hand side EC2’s ENI has MAC/IP addresses beef:0001:0001/10.10.1.22. Each physical server hosting EC2 instances has a Nitro Card for VPC [NC4VPC]. It is responsible for routing, data packets encapsulation/decapsulation, and Traffic limiting. In addition, Security Groups (SGs) are implemented in hardware on the  Nitro card for VPC. AWS Control-Plane relies on the Mapping Service system decoupled from the network devices. It means that switches are unaware of Overlay Networks having no state information related to VPC’s, Subnets, EC2 Instances, or any other Overlay Network components. From the Control-Plane perspective, physical network switches participate in the Underlay Network routing process by advertising the reachability information of physical hosts, Mapping Service, and so on. From the Data-Plane point of view, they forwards packet based on the outer IP header.

  

Mapping Register

Starting an EC2 instance triggers the Control-Plane process on a host. Figure 2-1 illustrates that Host-1 and Host-2 store information of their local EC2 instances into the Mapping cache. Then they register these instances into Mapping Service. You can consider the registration process as a routing update. We need to inform the Mapping Service about the EC2 instance’s a) MAC/IP addresses bind to ENI, b) Virtual Network Identifier (=VPC), c) the physical host IP, d) and the encapsulation mode (VPC tunnel header). If you are familiar with Locator/Id Separation Protocol LISP, you may notice that its Control-Plane process follows the same principles. The main difference is that switches in LISP-enabled networks have state information related to virtual/bare-metal servers running in a virtual network. 


Figure 2-1: VPC Control-Plane Operation: Mapping Register.

Continue reading

Stuff The Internet Says On Scalability For October 4th, 2021

Hey, HighScalability is here again!

The circulatory system of the internet. @tylermorganwall

Love this Stuff? I need your support on Patreon to keep this stuff going.

Sorry for the long gap in posting, but I’ve been building a new app. I’m looking for testers for my new iOS fitness app: Max reHIT Workout. It guides you through proven ​​reduced-exertion high-intensity interval workouts. If that interests you, please give it a try through TestFlight. I’d appreciate any feedback and suggestions for improvement. Thanks!

Don't miss all that the Internet has to say on Scalability, click below and become eventually consistent with all scalability knowledge (which means this post has many more items to read so please keep on reading)...

Tech Bytes: Global Manufacturer Taps Aruba EdgeConnect For SD-WAN, WAN Optimization

Today on the Tech Bytes podcast we look at a global SD-WAN deployment for manufacturing company IMMI, which makes vehicle safety products, including products for school buses and military vehicles. Our guest is Tom Braden, VP of Enterprise Technology at IMMI, and our sponsor is HPE Aruba.

The post Tech Bytes: Global Manufacturer Taps Aruba EdgeConnect For SD-WAN, WAN Optimization appeared first on Packet Pushers.

What’s new in Ansible Automation Platform 2: automation execution environments

aap 2 gray flying as-1

Red Hat Ansible Automation Platform 2 is now available to customers. This release expands the possibilities of automation across your organization, with a more secure, flexible foundation to build and deploy automation with greater acceleration, orchestration and innovation.

As automation usage/practices/etc. spreads throughout an organization, managing multiple automation environments for different teams and use cases become challenging. This is even more true as automation starts to scale across the IT organization. As automation continues to be part of critical workflows, the following enhancements have been made in Ansible Automation Platform 2:

  • Enables the Ansible Automation Platform administrator with the ability to provide and manage automation execution environments (see below) to differing groups, like networking and cloud teams. Each has specific content needs for their roles  instead of addressing different environments as an individual.

  • Provide the automation developers with a consistent Ansible environment that’s the same as production, so they can stop worrying about the automation environment and dependencies and focus more on the automation content itself.

  • Enable automation teams to define, build and update their automation environments without requiring them to contact the platform administrator for changes to the platform.

  • Build and distribute automation execution environments via private automation hub, Continue reading

Announcing Access Temporary Authentication

Announcing Access Temporary Authentication

Zero Trust rules by default block attempts to reach a resource. To obtain access, users need to prove they should be allowed to connect using signals like their identity, their device health, and other factors.

However, some workflows need a second opinion. Starting today, you can add new policies in Cloudflare Access that grant temporary access to specific users based on approvals for a set of predefined administrators. You can decide that some applications need second-party approval in addition to other Zero Trust signals. We’re excited to give your team another layer of Zero Trust control for any application — whether it’s a popular SaaS tool or you host it yourself.

Why temporary authentication?

Configuring appropriate user access is a challenge. Most companies start granting employee-specific application access based on username or email. This requires manual provisioning and deprovisioning when an employee joins or leaves.

When this becomes unwieldy, security teams generally use identity provider groups to set access levels by employee role. Which allows better provisioning and deprovisioning, but again starts to get clunky when application access requirements do not conform around roles. If a specific support rep needs access, then they need to be added to an existing Continue reading

6 data center trends to watch

Data-center owners and operators face increasing complexity and operational challenges as they look to improve IT resiliency, build out capacity at the edge, and retain skilled staff in a tight labor market.Meanwhile, use of the public cloud for mission-critical workloads is up, according to Uptime Institute, even as many enterprises seek greater transparency into cloud providers’ operations. Read more: Data-center recruitment needs to change to avoid staff shortagesTo read this article in full, please click here

Data-center network overhaul nets big savings for healthcare system

Modernizing a data-center network is no easy task under any conditions, but when a healthcare system that includes hospitals and emergency care depends on that network, the pressure is only more intense.That’s the challenge that Tom Hull, CIO of Kaleida Health, the largest healthcare system in western New York, has undertaken in the past year-and-a-half with the goal of building a secure, software-defined data-center environment capable of moving the provider into the future.To read this article in full, please click here

Data-center network overhaul nets big savings for healthcare system

Modernizing a data-center network is no easy task under any conditions, but when a healthcare system that includes hospitals and emergency care depends on that network, the pressure is only more intense.That’s the challenge that Tom Hull, CIO of Kaleida Health, the largest healthcare system in western New York, has undertaken in the past year-and-a-half with the goal of building a secure, software-defined data-center environment capable of moving the provider into the future.To read this article in full, please click here

6 data center trends to watch

Data-center owners and operators face increasing complexity and operational challenges as they look to improve IT resiliency, build out capacity at the edge, and retain skilled staff in a tight labor market.Meanwhile, use of the public cloud for mission-critical workloads is up, according to Uptime Institute, even as many enterprises seek greater transparency into cloud providers’ operations. Read more: Data-center recruitment needs to change to avoid staff shortagesTo read this article in full, please click here

Data center network modernization brings Kaleida Health big savings, security and automation

Modernizing a data-center network is no easy task under any conditions, but when a healthcare system that includes hospitals and emergency care depends on that network, the pressure is only more intense.But that’s the challenge Tom Hull, CIO of Kaleida Health, the largest healthcare system in western New York, has undertaken in the past year-and-a-half with the goal of building a secure, software-defined data-center environment capable of moving the provider into the future.To read this article in full, please click here

Feedback: Mastering Cloud Networking

Most of the public cloud training seems focused on developers. No surprise there, they are the usual beachhead public cloud services need to get into large organizations. Unfortunately, once the production applications start getting deployed into public cloud infrastructure, someone has to take over operations, and that’s where the fun starts.

For whatever reason, there aren’t that many resources helping the infrastructure operations teams understand how to deal with this weird new world, at least according to the feedback Jawed left on Azure Networking webinar:

Feedback: Mastering Cloud Networking

Most of the public cloud training seems focused on developers. No surprise there, they are the usual beachhead public cloud services need to get into large organizations. Unfortunately, once the production applications start getting deployed into public cloud infrastructure, someone has to take over operations, and that’s where the fun starts.

For whatever reason, there aren’t that many resources helping the infrastructure operations teams understand how to deal with this weird new world, at least according to the feedback Jawed left on Azure Networking webinar:

The secret to Cloudflare’s pace of Innovation

The secret to Cloudflare’s pace of Innovation
The secret to Cloudflare’s pace of Innovation

We are 11! And we also may be a little bleary-eyed and giddy from a week of shipping.

The secret to Cloudflare’s pace of Innovation

Our Birthday Weeks are one of my favorite Cloudflare traditions — where we release innovations that help to build a better Internet. Just this week we tackled email security, expanded our network into office buildings, and entered into the Web3 world.

The secret to Cloudflare’s pace of Innovation

But these weeks also precipitate the most common questions I’m asked from my product and engineering peers across the industry: how do we do it? How do we get so much stuff out so quickly? That we are able to innovate — and innovate so quickly — is no happy accident. In fact, this capability has been very deliberately built into the DNA of Cloudflare. I want to touch on three of the reasons unique to us: one relates to our people, one relates to our technology, and one relates to our customers.

Cultivating curiosity

The seeds of innovative ideas start with our team. One of the core things we look for when hiring in every role at Cloudflare — be it engineering and product or sales or account — is curiosity. We seek people who approach a situation Continue reading