F5 Solutions For Service Providers: Bart Salaets Solution Architect
F5 Solutions For Service Providers: Bart Salaets Solution Architect
F5 Solutions For Service Providers: Bart Salaets Solution Architect
F5 Solutions for
Service Providers
Bart Salaets
Solution Architect
Complex network architectures
Value-added services (VAS)
VAS layer
Static port 80 steering
WITH F5
VAS layer
Dynamic & intelligent steering
VIPRION
PGW/ Internet
BNG
Multi-service
router
L2 switching Full Proxy
MPLS L2 PE IP ROUTING (TCP opt,
TCP OPTIM
HHE) Policy
Enforcement
MPLS L2 PE DPI/PCEF
7,000,000 8M L7 RPS
4M L4 CPS
320G L7/L4
TPUT
6,000,000
VIPRION 2200
5,000,000
4M L7 RPS
2M L4 CPS
160G L7/L4 TPUT
4,000,000
BIG-IP 11050
BIG-IP 10200v 2.5M L7 RPS
BIG-IP 7200v 2M L7 RPS 1M L4 CPS
3,000,000
BIG-IP 5200v 1.6M L7 RPS 1M L4 CPS 40/42G L7/L4 TPUT
775K L4 CPS 40/80G L7/L4 TPUT
1.5M L7 RPS
BIG-IP 4200v 20/40G L7/L4 TPUT
2,000,000 700K L4 CPS
850k L7 RPS 15/30G L7/L4 TPUT
BIG-IP 2200s 300K L4 CPS
BIG-IP Virtual Edition
425K L7 RPS 10G L7/L4 TPUT
1,000,000 Up to 325K L7 RPS 150K L4 CPS
Up to 100K L4 CPS 5G L7/L4 TPUT
10G L7/L4 TPUT
0
BIG-IP Virtual EditionBIG-IP 2000 Series BIG-IP 4000 Series BIG-IP 5000 Series BIG-IP 7000 SeriesBIG-IP 10000 SeriesBIG-IP 11000 Series VIPRION 2200 VIPRION 2400 VIPRION 4480 VIPRION 4800
Service Provider
Diameter Gx
PCRF
Radius
RTR Internet
PGW/
BNG VIPRION
LB LB
PEM
POOL 1 POOL 2
HTTP ICAP
HTTP STEER TO STEER TO HTTP
ASSIGN FLOW
User VIDEO OPT PARENTAL
TO SERVICE CHAIN
POOL CTRL POOL
Internet
PCRF
PGW/GGSN VIPRION
PGW/GGSN VIPRION
DPI inspection for OTT Identification & Monetization
OTT MONETIZATION & FLEXIBLE CHARGING
PGW/GGSN VIPRION
SPECIALIZED
SERVICE
(MNO BRAND)
RTR Internet
PGW/
GGSN
3. Access Denied 2. Integrated Webroot
URL Filtering / Blacklist
Online Charging (Gy) URL Filtering & Parental Control OTT Identification & Monetization
• Government lists
• Flexible rating group • Per-subscriber OTT
definitions based on • Per-subscriber parental application detection
applications and/or URI control opt-in/opt-out
• Per-OTT bandwidth, marking
service
• Redirect or block upon quota and charging rules
expiration • For HTTP & HTTPS
Header Enrichment & WAP offload Content Injection / Toolbars Lightweight BRAS/BNG
Local DNS • Manage existing traffic to DNS server infrastructure with BIG-IP
• Enhance the subscriber experience by making intelligent DNS and GSLB decisions
• Enable high availability and performance for subscribers by managing UE/MME PDP sessions
Infrastructure
• Intelligent GSLB with ENUM support for IMS / EPC interoperability and NAT64 delivery
“Cybercrime is a
15%
37%
40% 31% 10%
30% 5%
20%
17%
9% 10%
persistent threat in 0%
DNS is now the second most business is immune.” Of the customers that mitigate DDoS
targeted protocol after HTTP. attacks, many choose a technique
Network Solutions that inhibits the ability of DNS to do
DNS DoS techniques range from:
its job
• Flooding requests to a given host
• DNS is based on UDP
• Reflection attacks against DNS
infrastructure • DNS DDoS often uses spoofed sources
• Reflect / Amplification attacks • Using an ACL block legitimate clients
• DNS Cache Poisoning attempts • DNS attacks use massive volumes of
source addresses, breaking many
firewalls.
F5 PARADIGM SHIFT
F5 DNS DELIVERY
REIMAGINED
• Strong DoS/DDoS protection
DNS Firewall
Internet
Master DNS
Infrastructure
DNS DDoS Protection
Protocol Validation
• Consolidation
Authoritative DNS
Caching Resolver • Protects “Back-End” servers
Transparent Caching
BIG-IP
High Performance DNSSEC
DNSSEC Validation
Intelligent GSLB
Answer
Answe Answer
Answe
Admin
r r
DNS
DNS
DNS
DNS OS Auth
Query
Query Query
Query Roles
• Need to decrease DNS latency and offload • Scale DNS transparent caches as demand
DNS resolvers increases. Offloads existing DNS
• Implement transparent DNS caches close infrastructure
to the subscriber • Provides a simple upgrade path to a full
• Deliver DNS scale without impacting caching resolver
service - Eliminate the need for centralized DNS
F5 DNS Services in Mobile Core F5 DNS Services in Mobile Core
DNS Resolver
Infrastructure
1200000
1000000
RPS
800000
600000
400000
200000
0
2000S Infoblox 2200S Infoblox 4000S Infoblox 7000S Infoblox 7200V Infoblox
Trinzic Trinzic Trinzic Trinzic Trinzic
1420 2210 2220 4010 4030 Platforms are grouped by like pricing
Prevent malware and sites hosting malicious content from ever communicating with a client.
Internet activity starts with a DNS request. Inhibit the threat at the earliest opportunity.
Live updates
RPZ live feed
BIG-IP GTM
REPUTATION
RESOLVER
VALIDATION
CACHE
PROTOCOL
LISTENER
IPV4/V6
IRULES
DATABASE
SPECIAL
HANDLING
iControl iQuery
QUERY: WWW.DOMAIN.COM
DNS iRules (Request / Response)
RPZ
RESOLVER
INGRESS DNS PATH
URL Filtering
CACHE
iRule
DNS Request Path
Suspend
Classify the traffic:
Threshold Determine the SLA for RPS and allowed response size.
Take an action:
QUERY RATE Is the client above the score threshold?
SCORING
- Drop the request
RESPONSE
SIZE SCORING
- Suspend DNS service for a period.
Client E
Client C
Client D
Client F
Client A
Client B
Маршрутизатор F5 BIG-IP
(пакетная обработка) (обработка на базе сессий)
L2 VPN Балансировка
Traffic steering
L3 VPN NAT44
Безопасность L4-L7
NAT64
Управление SSL и IPsec VPN
абонентами DS-Lite Масштабирование и
безопасность DNS
IP QoS
Ускорение WEB
IP пиринг
32 © F5 Networks, Inc.
RTR Internet
PGW/GG VIPRION
SN
Частное адресное Публичное адресное
NAT4(6)4
пространство пространство IPv4 / IPv6
Ответ:
Ответ:
6
21x
Millions
8M
2
600k
400k 350k
0
• Top video sites such as YouTube, Netflix, Hulu, and BBC iPlayer
have all embraced ABR video technology
• Video is encoded at different bit rates, client dynamically chooses
or changes appropriate bit rate based on network conditions
Avg HTTP
response
size 16 kB (3
round trips)
PGW/ RTR
GGSN
TCP
EXPRESS
Cell-optimized TCP stack WAN-optimized TCP stack
Mobile Origin
Client Server
• Delay-based algorithms
• Vegas
• Bandwidth-estimating algorithms
• Westwood, Westwood+
Business Business
center center
Shopping Shopping
Mall Mall
Residential Residential
Area Area
Optimized (sec)
As-is (sec)
Case 3 – Regular website 1 Case 4 – Regular website 2 Improvement (%)
Business
Business
center
center
Shopping Shopping
Mall
Mall
Residential
Residential
Area
Area
100% 20%
80%
15%
60%
10%
40%
20% 5% 38% 33% 20% 28%
196% 95% 22% 14%
0% 0%
Poor coverage Good coverage Poor coverage Good coverage