Cnaas in Noreway gn4.3 Workshop Oct 2019-Uninett-3222
Cnaas in Noreway gn4.3 Workshop Oct 2019-Uninett-3222
Cnaas in Noreway gn4.3 Workshop Oct 2019-Uninett-3222
3
Why such a service?
ICT departments are overloaded with tasks
Improve security
• Improvements for ICT for research and education etc Life on campus
4
New digitalization
strategy from the
Ministry of Education
2017 - 2021
5
The CNaaS service package
Included Will / can offer
Operations of wired and wireless network Firewall management
DHCP service DNS firewall
NAT 44 service
IDS
Radius (for eduroam)
VPN (eduVPN)
6
Number of customers
7
CEO Uninett as of Jan 1 2019
Total MY for CNaaS in 2020 will be 2.7 (service will have a deficit first years)
8
Joint Swedish and Norwegian high level CNaaS NMS architecture
Customer A
NAV
(monitor)
SNMP read
NAV
1st line config
Campus
(KIND in Norway Customer network
NI in Sweden) and Asset
Database
Netconf
CNaaS-NMS oxidized
(2nd and 3rd line
Uninett config) (tracking
changes)
SUNET Nornir/NAPALM
9
Formal relation
10
Lessons learned so far
Close interaction with customer is key
• Technical staff at customer need to work WITH us
• SLA/mutual expectations – both Uninett and customer
• Clear demarcation line – who is responsible for what
• Day to day low level changes must be done by the customer
CNaaS reference architecture can influence/change campus design for all campuses
Automation is a continuous improvement process.
• Focus on the most repetitive processes first
• 100% automation too expensive (?)
11
Extra material follows…
From help-with-self-help to help-with-everything
13
CNaaS high level objectives
No vendor lock-in
High availability ( => fully redundant design)
Flexible traffic engineering ( routing in underlay beats SPT any day – also easier to debug)
14
Overlay/underlay architecture with EVPN and VXLAN
15
How can we make security management scalable?
??? ???
16
Why must wired and wifi be well integrated?
User experience •User expect same functionality and same level of security
•Multicast, Bonjour, mDNS (BUM)
Wired and wifi must • Lab microscope on wire where wireless iPad is used as monitor
• Apple-TV/Chromecast/Miracast on cable and users on wifi
play well together • Hearing aid devices on wired and user on wifi
• Screen sharing equipment for visually impaired in lecture hall – user on wifi
Simpler overall •Fault monitoring the same for wired and wireless
network topology
Thanks for your attention
www.uninett.no