VMware NSX enters SDWAN
Transcript
[Music] hey how's it going - Steve towns are from the CTO of Arthur comm we're one site in Palo Alto at the VMware campus lovely campus not just because they have Pete's coffee most fanciest coffee that I've had so far for a CTO dose today first interview of the day of many VMware interviews I'm with the CTO of the NSB you hope I said I write the not report the network security business unit Peter Michaels yes Peter introduce yourself how long you been with VMware I
think I'm being worth for now over a year it's been a great ride minutes it's an interesting transition from the start up well before that I was a founder of plumb grid there was an SDN company that we were focusing more on the open cycle system and kind of the cloud native cloud system and before that it was for many years at Cisco I was an engineer at Cisco so a lot of networking fat chops right before we started recording we're talking about IO visor and
the cool stuff that plumb grid is going don't go in the VMware folks at some point will let me talk to you about the isle visor work and and all of that super geeky stuff that our our reference the blog post that I did a couple of years ago on IO visor and plum grid really cool technology I'm looking to see how that's applicable to the enterprise but speaking of startups and applicability to enterprise VMware made a huge splash splash at least in my opinion acquiring
is it velop out the the acquisition closed what about three months ago something like that yeah we're recording in in February so late November mid November or something like that for those who didn't know what what what it valid cloud do pre and now within VMware yeah maybe the first question is about why what are we interested in the s21 space even and what trigger that that move so the first thing is that as vmware - well-known we start from a data centric centric position in
a way that we provide infrastructure for infrastructure to essentially power a lot of applications for enterprise and as we go into the journey of software defined at the center automating everything providing an infrastructure that automatically expands we enter into a networking space with the nsx product line and what do seven is at nsx was having a great traction at the center while providing micro segmentation automation disaster recovery apps for one but the question is what are the customers that consume the applications that you have in
the epicenter right and you have kind of two types of customers the ones that they create an application to be consumed by users that exist in the internet and those user would essentially connect directly from the Internet to your data center or to your cloud but most of our customers were having a different type of situation which is essentially the fact that you had branches remote offices you had retailers you have financial institutions and what they were coming to us saying look it's great to have
micro segmentation it's great to have security automation in the data center but at the end of the day what happens is that we still have to do a lot of configuration steps to reach what our customers are and understand the identity of them so what they were centrally living in the remote Ephesian in order to shred the VPN tunnels the security policy is the whole connectivity in order that when the requests were directed at the center and we could enforce the policies and automation that we
had it was too complex right so essentially the customers were asking are saying not how do you extend this concept of security by default one zero trusted micro segmentation to where my employees my users of my data center application and this is what trigger has to pay attention to the sd1 space and to look deep into it and to Louis eventually the move with the Velo cloud so that's great over your well VMware is dressed and I think we're going to maybe deep into a specific
use case but before then just to recap the what Velo cloud and other st wind solutions provided pre-acquisition by VMware was this ability to have a win in a box at the hint so the huge benefits of SDN was the ability to take commodity circuits combine that and this is just one use case combining those circuits and find best path so a lot of companies were actually displacing or augmenting their MPLS networks with this so they could take their MPLS connection bringing an internet connection and
then intelligent leaves the SD win solution would decide where is the best path to send applications specific traffic back in the old days we we say you know what all voice goes over MPLS period because MPLS offers consistent class of service versus the Internet what we've discovered that thanks not necessarily always the case sometimes the internet path is the better path and these Sdn solutions would do this for dynamically based on network statistics such as jitter and and and other factors and including latency is that
pretty accurate to describe what Vella plow offers today yes anyone brings many value propositions as you are pointing out like the first one is the aspect of saying there's multiple access technologies and having kind of design direction in the edge allows you to pick the best option for your business for your quality of experience and so on the other aspect is the notion of you have many sites and if you have to manage them individually that's painful from an Operations point right and as the one
gives you this kind of over management experience well now you can see and create consistent configurations experience across many sites and the third is what we were discussing is like the aspect of with this automation and this centralized experience now you can tied to the data center so I would say when when we look at the problem of SD one we were not necessarily looking at the aspect of saying do we have to pick in between internet technologies or MPLS why things like that but rather
is how do we focus from an enterprise point of view into an end-to-end experience so let's talk about that I look at that is pretty much the abstraction of the control VMware did a great job early on with NSX I wanted NSX like right away when someone said you know what there's a hypervisor for networking immediately I kind of get the content you know I can pause we were wine and it's a DVR for the network I can take my control plane and do the same
thing that could do with my virtual servers and my virtual infrastructure I can do that with the networking and VMware acquired nasarah and I saw the nasarah solution I'm like you know what I want that yesterday where is it you know Martine could say to even took me out for a burrito and berated me over a burrito about you know one of my blog posts he was right but you know it was all the same now we're taking that same concept Veera is taking that same
concept and bring it out to the edge why should we get excited just excited about data center abstraction network extraction why should we be excited about that and abstract talk to me practically about a use case that a customer take their intersects constructs and extend that out to the edge yes maybe the first is you were saying that working is a copy that has been done for many many years and with many successful companies in the space I would say what's different about VMware that is
fueling kind of this growth into the nsx product line and intrumental virtualization so if you think like many years ago we were focusing on kind of the end-to-end principle that you have endpoints with IP addresses and networking was about how do I connect end to end and the network had a mission by itself first for our few years and with the acquisition of Nicaea and the introduction of NSX and William were brought to the industry was why do we do networking is it about networking for
the sake of networking or is it because we have to provide a service to applications right and as such we took kind of this reference point right NSX and VMware is about creating networking useful to applications now you start saying okay where are the applications running today they are running from bare metal servers to be realized environments moving to containers moving to service functions so the the commitment that VMware had from a networking point of view is I'm going to provide an environment that fulfills whatever
the application makes and the obligation is essentially connectivity security and elasticity which in the old world were like routers firewalls load balancers in the new wall becomes kind of this uber neighborhood position solution that enables applications to appear and disappear as they will reopen it now as you take this concept of following the application and say well how these extensions they weren't right because as we were mentioning sd1 has a very very specific value proposition about do I pick MPLS or Internet or some specific access
technologies and there is a component of that but if that was the sole component then it would be kind of networking for the sake of networking again and there's a very plenty of networking companies that focus on that so we were going more to the operational aspect that you were mentioning right you go one level up and you say what is this mover control plane and for whom and what's the reference point to simplify the life of our customers right and you go like that and
again it's like monochrome applications where the users were at the sides were varmints how do I connect everything how do I secure everything with with a unified reference points and release control point that that simplifies the operations on the lives of of IT and customers and I think one of the real world therefore the word is placed in a word for a large very large or in the organization and one of the challenges we had was we're trying to figure out what we call business traffic
and R&D traffic over the way yes and this is the pain point everyone I think who transfers a large amount of data over the wind can comprehend SD Wynn can help with this but the problem is still the orchestration of that traffic I would love to be able to just say I have over lanes and I can turn the knob for Rd traffic and certain points that they increase the amount of bandwidth available to certain Rd traffic isolate that traffic on a win and get it
into the endpoints I'd like to say from a rural setting you know what this time of day use this protected path for business traffic such as voice and then or diss protected amount of bandwidth operationally what we discovered was no matter how much bandwidth we purchased how many circuits we purchased from the data center all the way where the applications ran all the way to the edge where the computation was done that was an immensely challenging problem in my mind the combination of FD when VMware
NSX solved that helps to solve that problem definitely when you start thinking in terms of application recognition and traffic we always talked over the years about SLA and Q as in data center but in the other sense we have plenty of bandwidth you can always upgrade to an X technology when you go into the one then the problem is very real I mean it's work SLA spot application policies in terms of what bandwidth reservation or latencies past the you Pig it becomes very relevant so completely
with you I mean one of the things that we are aiming is mission of understanding and recognizing the applications that we understand in the data center carrying that experience and knowledge into who's using those type of applications and being able to tie escalation path and path discovery into this end-to-end experience and as you were saying it's not anymore about I have a one problem or a central problem is like oh this specific time this application is very dear and very important to me can I do
something in terms of rerouting innovations from service label or can I grantee certain elements in the one that are going to grantee the experience of the end-users so let's in a conversation on ecosystem you're from farm grid and a bunch of networking background before you've worked in the OpenStack community you understand the value of the overall community and this is something that VMware can even with the acquisition VMware can't do it on on your own you need application folks to get onboard network vendors tell calls
etc there's no movement where's where's the biggest challenge and getting this into hand vision yes we've been trying to basically were quite small on the but is something that as we go into the sd1 space we have to do even better I mean even Willow had a lot of partner relations that we are carrying forward into BM were in the space of security in the springs of visibility and now as we bring this ecosystem together you are correct in VMware cannot do everything we were kind
of provides the base but now you can build on top like providing the connectivity aspect and some obviously engines and so on and now the question is who has the ability to understand identity who has the ability to do the packet inspection at a level that you can have ideas IPS who has the ability to create advanced machine learning analytics and capabilities so we are trying to develop as we create this kind of foundational technology that expands across all the elements of the enterprises who builds
value on top of us what kind of a core system partners do we bring and this is a place where now we are we are they getting definitely much more energy and you'll see this from this from an nsv you you have the app defense product line doing partnerships with security staff that integrity companies specialize in the space but when you take it into Data Center voluntary sd1 you'll see that we'll keep doing more and more about how delivering third party vertical mental functions or party
partners that up men in terms of operations in terms of network capabilities the offering that we have so Peter I really appreciate you spending the time to talk to the city advisor about what VMware is doing in the web space I'll be that same antagonist see I said the word right this time and pushing VMware say where where's the food I've know it's hard work but these are problems that a lot of enterprises have to solve today and I'm happy to see that VMware just like
NSX wouldn't Sarah is pushing the envelope and extending this concept of the Software Defined I don't know we can call software-defined data center anymore it's like the software-defined enterprise so really appreciate the time do you do social media or anything like that at all are you but don't take you under discussion any time it's I'm looking for advanced you're talking about IO visor we got to get our friend you know what Roger on Twitter out I'll put this put her hand away impression him to have
that aisle visor conversation it's really geeky stuff really fun stuff a while about what a lot of industry players are using that technology to do quietly amazing things with things like SLD PDK which I've talked about and wrote about awful lot until then tune in to the rest of these videos we're talking to the cloud services bu a little bit later on today as well as the the other clouds being has to cloud behooves down go figure until then follow me on the web at CTO
visor on Twitter the CTO visor comm talk the next CTO adults