1
1

00:00:00,310  -->  00:00:02,180
<v ->Data center architecture.</v>
2

2

00:00:02,180  -->  00:00:04,500
In this lesson, we're going to discuss the architecture
3

3

00:00:04,500  -->  00:00:05,980
within our data centers.
4

4

00:00:05,980  -->  00:00:07,450
When we're talking about a data center,
5

5

00:00:07,450  -->  00:00:09,380
this is any facility that's composed of network,
6

6

00:00:09,380  -->  00:00:11,240
computers and storage that businesses
7

7

00:00:11,240  -->  00:00:12,870
and other organizations are going to use
8

8

00:00:12,870  -->  00:00:14,860
to organize, process, store,
9

9

00:00:14,860  -->  00:00:16,940
and disseminate large amounts of data.
10

10

00:00:16,940  -->  00:00:19,000
Now that's a pretty generic definition,
11

11

00:00:19,000  -->  00:00:19,963
but this is because a data center
12

12

00:00:19,963  -->  00:00:22,780
is used to describe a lot of different things these days
13

13

00:00:22,780  -->  00:00:25,490
from the very small to the massively large.
14

14

00:00:25,490  -->  00:00:27,340
For example, one of the smaller organizations
15

15

00:00:27,340  -->  00:00:29,160
I worked for had a small data center
16

16

00:00:29,160  -->  00:00:31,690
that was roughly 150 square feet in size.
17

17

00:00:31,690  -->  00:00:34,030
Within it, we had a single rack of networking equipment
18

18

00:00:34,030  -->  00:00:36,650
and about five racks that contained various servers.
19

19

00:00:36,650  -->  00:00:37,540
Now, on the other hand,
20

20

00:00:37,540  -->  00:00:39,220
one of the largest data centers in the world
21

21

00:00:39,220  -->  00:00:41,270
is located in Bluffdale, Utah.
22

22

00:00:41,270  -->  00:00:43,640
This data center is known as the Utah Data Center
23

23

00:00:43,640  -->  00:00:45,140
or its official title,
24

24

00:00:45,140  -->  00:00:47,200
the Intelligence Community Comprehensive National
25

25

00:00:47,200  -->  00:00:48,850
Cybersecurity Initiative Data Center,
26

26

00:00:48,850  -->  00:00:51,770
and it is 1.5 million square feet in size
27

27

00:00:51,770  -->  00:00:53,580
spread across 20 buildings.
28

28

00:00:53,580  -->  00:00:55,740
This data center is massive
29

29

00:00:55,740  -->  00:00:58,740
and it uses around 65 megawatts of electricity
30

30

00:00:58,740  -->  00:01:00,350
just to run it each day.
31

31

00:01:00,350  -->  00:01:02,120
Now this data center costs the US government
32

32

00:01:02,120  -->  00:01:04,730
about $1.5 billion to build
33

33

00:01:04,730  -->  00:01:06,930
and they spend over $40 million each year
34

34

00:01:06,930  -->  00:01:08,670
just on the electricity bills.
35

35

00:01:08,670  -->  00:01:10,730
This is a massive data center.
36

36

00:01:10,730  -->  00:01:13,000
Now, personally, I haven't worked at that data center,
37

37

00:01:13,000  -->  00:01:15,140
but I've worked at some really large data centers.
38

38

00:01:15,140  -->  00:01:17,240
But nothing at that size or scale.
39

39

00:01:17,240  -->  00:01:18,540
Now, Amazon, for example,
40

40

00:01:18,540  -->  00:01:20,300
uses data centers that range in size
41

41

00:01:20,300  -->  00:01:23,740
between 150,000 to 215,000 square feet.
42

42

00:01:23,740  -->  00:01:26,490
And they host about 50,000 to 80,000 servers
43

43

00:01:26,490  -->  00:01:28,160
in each of their data centers.
44

44

00:01:28,160  -->  00:01:29,400
As a network technician,
45

45

00:01:29,400  -->  00:01:30,720
you may very well end up working
46

46

00:01:30,720  -->  00:01:32,340
at one of these data centers one day.
47

47

00:01:32,340  -->  00:01:35,510
So let's explore their architecture just a little bit.
48

48

00:01:35,510  -->  00:01:38,340
In this lesson, we're going to talk about five key areas.
49

49

00:01:38,340  -->  00:01:40,630
The three-tiered hierarchy used by data centers,
50

50

00:01:40,630  -->  00:01:42,710
software-defined networking that allows our data centers
51

51

00:01:42,710  -->  00:01:43,990
to operate effectively,
52

52

00:01:43,990  -->  00:01:46,600
the spine and leaf architecture that's used by data centers,
53

53

00:01:46,600  -->  00:01:48,490
the traffic flows that are used by our data centers,
54

54

00:01:48,490  -->  00:01:50,800
and the on-premise versus hosted data centers
55

55

00:01:50,800  -->  00:01:52,650
and what the differences between them.
56

56

00:01:52,650  -->  00:01:55,360
So first let's look at the three-tiered hierarchy
57

57

00:01:55,360  -->  00:01:56,680
which consists of the core,
58

58

00:01:56,680  -->  00:01:58,490
the distribution or aggregation layer,
59

59

00:01:58,490  -->  00:02:00,520
and then the access or edge layer.
60

60

00:02:00,520  -->  00:02:02,700
The core layer is going to consist of the biggest
61

61

00:02:02,700  -->  00:02:04,670
and fastest and most expensive routers
62

62

00:02:04,670  -->  00:02:06,400
that you're ever going to end up working with.
63

63

00:02:06,400  -->  00:02:08,410
The core layer is going to be considered the backbone
64

64

00:02:08,410  -->  00:02:09,243
of our network
65

65

00:02:09,243  -->  00:02:11,550
and it's used to merge geographically separated networks
66

66

00:02:11,550  -->  00:02:13,800
into one logical and cohesive unit.
67

67

00:02:13,800  -->  00:02:15,910
In general, you're going to have at least two routers
68

68

00:02:15,910  -->  00:02:18,990
at the core level operating in a redundant configuration.
69

69

00:02:18,990  -->  00:02:20,900
After all, if you only had one core router
70

70

00:02:20,900  -->  00:02:21,760
and it went offline,
71

71

00:02:21,760  -->  00:02:24,420
the entire network would grind to a screeching halt.
72

72

00:02:24,420  -->  00:02:26,070
So we don't want to do that.
73

73

00:02:26,070  -->  00:02:29,100
Next, we have the distribution or aggregation layer.
74

74

00:02:29,100  -->  00:02:31,090
This layer is located under the core layer
75

75

00:02:31,090  -->  00:02:32,900
and it's going to provide boundary definition
76

76

00:02:32,900  -->  00:02:35,520
by implementing access control lists and filters.
77

77

00:02:35,520  -->  00:02:38,170
Now here at the distribution or aggregation layer,
78

78

00:02:38,170  -->  00:02:39,520
we're going to be defining policies
79

79

00:02:39,520  -->  00:02:41,060
for the network at large.
80

80

00:02:41,060  -->  00:02:43,010
Normally, you're going to see layer three switches
81

81

00:02:43,010  -->  00:02:45,260
here being used because this distribution layer
82

82

00:02:45,260  -->  00:02:47,310
is going to ensure packets are being properly routed
83

83

00:02:47,310  -->  00:02:49,130
between different subnets and VLANs
84

84

00:02:49,130  -->  00:02:51,020
within your enterprise network.
85

85

00:02:51,020  -->  00:02:54,030
Finally, we're going to get down to the access or edge layer.
86

86

00:02:54,030  -->  00:02:56,050
This layer is located beneath the distribution
87

87

00:02:56,050  -->  00:02:57,090
or aggregation layer,
88

88

00:02:57,090  -->  00:02:58,430
and it's going to be used to connect
89

89

00:02:58,430  -->  00:03:00,860
to all of your endpoint devices like your computers,
90

90

00:03:00,860  -->  00:03:03,100
your laptops, your servers, your printers,
91

91

00:03:03,100  -->  00:03:05,660
your wireless access points, and everything else.
92

92

00:03:05,660  -->  00:03:07,420
These access or edge devices
93

93

00:03:07,420  -->  00:03:09,170
are going to usually be regular switches,
94

94

00:03:09,170  -->  00:03:10,590
and they're going to be used to ensure packets
95

95

00:03:10,590  -->  00:03:11,990
are being converted to frames
96

96

00:03:11,990  -->  00:03:15,070
and delivered to the correct end point devices when needed.
97

97

00:03:15,070  -->  00:03:16,170
Now you may be wondering
98

98

00:03:16,170  -->  00:03:18,760
why do I need to use this three-tiered hierarchy?
99

99

00:03:18,760  -->  00:03:20,560
Well, by using this type of hierarchy,
100

100

00:03:20,560  -->  00:03:23,260
we can get better performance, management, scalability,
101

101

00:03:23,260  -->  00:03:25,000
and redundancy from our networks.
102

102

00:03:25,000  -->  00:03:26,330
It also is going to give us a better way
103

103

00:03:26,330  -->  00:03:27,540
to troubleshoot our network
104

104

00:03:27,540  -->  00:03:29,570
because normally if we find an issue,
105

105

00:03:29,570  -->  00:03:31,980
we're going to find it and isolate it down to a single access
106

106

00:03:31,980  -->  00:03:33,490
or edge layer device.
107

107

00:03:33,490  -->  00:03:35,430
Now, we can work on fixing that
108

108

00:03:35,430  -->  00:03:37,330
while the rest of the network keeps continuing to operate
109

109

00:03:37,330  -->  00:03:38,600
with no issues at all
110

110

00:03:38,600  -->  00:03:40,750
and then we can get our network all the way back up
111

111

00:03:40,750  -->  00:03:42,500
and running 100%.
112

112

00:03:42,500  -->  00:03:44,390
Normally inside your data center,
113

113

00:03:44,390  -->  00:03:46,200
you're going to find your core layer devices
114

114

00:03:46,200  -->  00:03:48,820
as well as your distribution or aggregation layer devices
115

115

00:03:48,820  -->  00:03:50,920
for the local network in that building.
116

116

00:03:50,920  -->  00:03:53,400
If you have remote branch offices or other locations,
117

117

00:03:53,400  -->  00:03:55,350
each one of those is going to have its own distribution
118

118

00:03:55,350  -->  00:03:57,380
or aggregation layer switch inside
119

119

00:03:57,380  -->  00:03:59,180
its main distribution frame too.
120

120

00:03:59,180  -->  00:04:00,150
In both cases,
121

121

00:04:00,150  -->  00:04:01,440
your network will then branch out
122

122

00:04:01,440  -->  00:04:03,140
to the intermediate distribution frames
123

123

00:04:03,140  -->  00:04:05,930
where you're going to find your access or edge layer devices.
124

124

00:04:05,930  -->  00:04:08,160
Now, when we talk about this three-tiered model,
125

125

00:04:08,160  -->  00:04:09,660
this is a traditional network
126

126

00:04:09,660  -->  00:04:11,830
you're going to find in most enterprises.
127

127

00:04:11,830  -->  00:04:15,360
Next, let's move into software-defined networking or SDN.
128

128

00:04:15,360  -->  00:04:16,480
Software-defined networking
129

129

00:04:16,480  -->  00:04:18,960
is a network architecture approach that enables the network
130

130

00:04:18,960  -->  00:04:21,130
to intelligently and centrally be controlled
131

131

00:04:21,130  -->  00:04:23,740
or programmed using software applications.
132

132

00:04:23,740  -->  00:04:25,020
This helps operators manage
133

133

00:04:25,020  -->  00:04:27,650
the entire network consistently and holistically,
134

134

00:04:27,650  -->  00:04:30,210
regardless of the underlying network technology.
135

135

00:04:30,210  -->  00:04:32,420
Essentially, we're going to take our physical networks
136

136

00:04:32,420  -->  00:04:34,190
and we can completely virtualize them
137

137

00:04:34,190  -->  00:04:35,790
or create a layer of abstraction
138

138

00:04:35,790  -->  00:04:38,280
between the physical devices and the logical architecture
139

139

00:04:38,280  -->  00:04:39,750
that they're going to represent.
140

140

00:04:39,750  -->  00:04:41,390
Now with software-defined networking,
141

141

00:04:41,390  -->  00:04:44,350
we can create complex networks very quickly and easily,
142

142

00:04:44,350  -->  00:04:47,480
leveraging increased network size and expanding their scope
143

143

00:04:47,480  -->  00:04:49,750
as well as their ability to rapidly change.
144

144

00:04:49,750  -->  00:04:51,190
In fact, one of the great things
145

145

00:04:51,190  -->  00:04:52,570
about software-defined networks
146

146

00:04:52,570  -->  00:04:54,050
is that they can be changed automatically
147

147

00:04:54,050  -->  00:04:57,360
by the network itself using automation and orchestration.
148

148

00:04:57,360  -->  00:04:58,310
On the other hand,
149

149

00:04:58,310  -->  00:05:00,580
all of this rapid change does make it harder for us
150

150

00:05:00,580  -->  00:05:02,190
as humans to keep up with it
151

151

00:05:02,190  -->  00:05:04,300
and fully understand the data flows on our network
152

152

00:05:04,300  -->  00:05:05,500
at any given time.
153

153

00:05:05,500  -->  00:05:07,460
Now, when it comes to software-defined networking,
154

154

00:05:07,460  -->  00:05:09,620
there are several pieces that we need to consider
155

155

00:05:09,620  -->  00:05:12,010
including the application layer, the control layer,
156

156

00:05:12,010  -->  00:05:14,840
the infrastructure layer, and the management plane.
157

157

00:05:14,840  -->  00:05:16,580
These three layers are going to allow the network
158

158

00:05:16,580  -->  00:05:19,270
to be decoupled from the underlying hardware itself.
159

159

00:05:19,270  -->  00:05:20,800
The application layer is going to focus
160

160

00:05:20,800  -->  00:05:22,540
on the communication resource requests
161

161

00:05:22,540  -->  00:05:25,120
or information about the network as a whole.
162

162

00:05:25,120  -->  00:05:27,230
The control layer is then going to use that information
163

163

00:05:27,230  -->  00:05:29,940
from the applications and decide how to route a data packet
164

164

00:05:29,940  -->  00:05:31,130
on that network.
165

165

00:05:31,130  -->  00:05:32,680
It also makes decisions about how traffic
166

166

00:05:32,680  -->  00:05:33,760
should be prioritized,
167

167

00:05:33,760  -->  00:05:34,830
how it should be secured,
168

168

00:05:34,830  -->  00:05:36,640
and where it should be forwarded to.
169

169

00:05:36,640  -->  00:05:38,250
The infrastructure layer is going to contain
170

170

00:05:38,250  -->  00:05:40,850
the actual networking devices that receive the information
171

171

00:05:40,850  -->  00:05:43,090
from the control layer about where to move the data,
172

172

00:05:43,090  -->  00:05:45,380
and then it's going to perform those movements.
173

173

00:05:45,380  -->  00:05:47,180
Now with software-defined networking,
174

174

00:05:47,180  -->  00:05:49,930
these underlying infrastructure devices can be physical
175

175

00:05:49,930  -->  00:05:52,620
or virtual devices depending on your network configuration
176

176

00:05:52,620  -->  00:05:55,060
or a combination or hybrid of the two.
177

177

00:05:55,060  -->  00:05:57,780
Remember the whole concept with software-defined networking,
178

178

00:05:57,780  -->  00:05:59,390
is probably this layer of abstraction
179

179

00:05:59,390  -->  00:06:01,060
between the real underlying devices
180

180

00:06:01,060  -->  00:06:02,370
and the control and data flow
181

181

00:06:02,370  -->  00:06:04,270
that's going to happen on that network.
182

182

00:06:04,270  -->  00:06:06,410
Software-defined networking is also critical for use
183

183

00:06:06,410  -->  00:06:08,180
in our successful cloud applications
184

184

00:06:08,180  -->  00:06:10,730
because it gives us the scalability and elasticity
185

185

00:06:10,730  -->  00:06:13,720
and agility that we need inside those networks.
186

186

00:06:13,720  -->  00:06:15,810
Now, the fourth part of software-defined networks
187

187

00:06:15,810  -->  00:06:17,260
is our management plane.
188

188

00:06:17,260  -->  00:06:18,700
Now the management plane is going to be used
189

189

00:06:18,700  -->  00:06:21,430
to monitor traffic conditions and the status of the network.
190

190

00:06:21,430  -->  00:06:23,360
Basically, the management plane is going to allow us
191

191

00:06:23,360  -->  00:06:26,470
to oversee the network and gain insight into its operations.
192

192

00:06:26,470  -->  00:06:28,720
This will also allow us to make configuration changes,
193

193

00:06:28,720  -->  00:06:30,320
to set things up the way we want,
194

194

00:06:30,320  -->  00:06:33,170
and make sure they're working the way we need them to.
195

195

00:06:33,170  -->  00:06:34,470
So for the exam,
196

196

00:06:34,470  -->  00:06:36,590
I want you to remember that software-defined networking
197

197

00:06:36,590  -->  00:06:39,680
or SDN is broken down into four parts.
198

198

00:06:39,680  -->  00:06:41,700
The application layer, the control layer,
199

199

00:06:41,700  -->  00:06:44,550
the infrastructure layer, and the management plane.
200

200

00:06:44,550  -->  00:06:47,570
Next, let's discuss the spine and leaf architecture.
201

201

00:06:47,570  -->  00:06:49,040
Now, the spine and leaf architecture
202

202

00:06:49,040  -->  00:06:51,070
is an alternative type of network architecture
203

203

00:06:51,070  -->  00:06:53,570
that's used specifically within the data center.
204

204

00:06:53,570  -->  00:06:55,660
Now, when we use our three-tiered hierarchy
205

205

00:06:55,660  -->  00:06:56,493
that we covered earlier,
206

206

00:06:56,493  -->  00:06:57,860
we talked about the fact that we connected
207

207

00:06:57,860  -->  00:07:00,020
the core layer down to the distribution layer
208

208

00:07:00,020  -->  00:07:02,570
and then down to the access layer or edge layer
209

209

00:07:02,570  -->  00:07:04,480
with all of our end point devices.
210

210

00:07:04,480  -->  00:07:06,120
With a spine and leaf architecture,
211

211

00:07:06,120  -->  00:07:08,070
instead we're going to be focused on communication
212

212

00:07:08,070  -->  00:07:10,700
within the data center itself only specifically
213

213

00:07:10,700  -->  00:07:12,920
to the server firm and the portions of it.
214

214

00:07:12,920  -->  00:07:14,640
The spine and leaf architecture consists
215

215

00:07:14,640  -->  00:07:17,810
of two switching layers known as a spine and a leaf.
216

216

00:07:17,810  -->  00:07:18,690
Now the leaf layer
217

217

00:07:18,690  -->  00:07:20,640
is going to consist of all the access switches
218

218

00:07:20,640  -->  00:07:22,770
that aggregate traffic from the different servers
219

219

00:07:22,770  -->  00:07:24,880
and then connect directly into the spine layer
220

220

00:07:24,880  -->  00:07:26,470
or the networks core.
221

221

00:07:26,470  -->  00:07:28,130
This spine contains the switches
222

222

00:07:28,130  -->  00:07:30,010
that will interconnect all the leaf layer switches
223

223

00:07:30,010  -->  00:07:32,010
into a full mesh topology.
224

224

00:07:32,010  -->  00:07:34,420
This leads to increased performance and redundancy
225

225

00:07:34,420  -->  00:07:36,610
for all the servers that are connected to the leaf layer
226

226

00:07:36,610  -->  00:07:38,650
and in turn to the spine layer.
227

227

00:07:38,650  -->  00:07:39,950
Now, as you may be wondering,
228

228

00:07:39,950  -->  00:07:41,910
why did I move from the three-tiered networks
229

229

00:07:41,910  -->  00:07:44,540
to software-defined networks before starting to discuss
230

230

00:07:44,540  -->  00:07:46,160
the spine and leaf architecture?
231

231

00:07:46,160  -->  00:07:48,140
Well, this is because many of our spine
232

232

00:07:48,140  -->  00:07:50,610
and leaf architectures rely on software-defined networks
233

233

00:07:50,610  -->  00:07:51,530
to operate.
234

234

00:07:51,530  -->  00:07:53,270
By using a spine and leaf architecture,
235

235

00:07:53,270  -->  00:07:55,690
we can actually get faster speeds and lower latency
236

236

00:07:55,690  -->  00:07:58,110
than the traditional three-tiered hierarchy as well.
237

237

00:07:58,110  -->  00:07:59,900
By using a spine and leaf architecture,
238

238

00:07:59,900  -->  00:08:01,030
we can actually take shortcuts
239

239

00:08:01,030  -->  00:08:02,520
in getting data from place to place,
240

240

00:08:02,520  -->  00:08:03,800
and this all happens best
241

241

00:08:03,800  -->  00:08:05,500
when we're using software-defined networks
242

242

00:08:05,500  -->  00:08:07,970
in combination with a spine and leaf design.
243

243

00:08:07,970  -->  00:08:10,160
If you're installing a spine and leaf architecture,
244

244

00:08:10,160  -->  00:08:11,673
normally you're going to install two switches
245

245

00:08:11,673  -->  00:08:13,280
into each server rack.
246

246

00:08:13,280  -->  00:08:15,210
This is known as top of rack switching
247

247

00:08:15,210  -->  00:08:16,730
because the switches are physically installed
248

248

00:08:16,730  -->  00:08:18,340
at the very top of the server rack,
249

249

00:08:18,340  -->  00:08:19,990
and each server inside that rack
250

250

00:08:19,990  -->  00:08:21,870
will have a connection to each of the two switches
251

251

00:08:21,870  -->  00:08:23,810
that are residing inside that rack.
252

252

00:08:23,810  -->  00:08:25,390
Now, these switches are essentially going to be
253

253

00:08:25,390  -->  00:08:27,870
the leafs inside our spine and leaf architecture.
254

254

00:08:27,870  -->  00:08:29,530
And they're going to connect back to the spine
255

255

00:08:29,530  -->  00:08:30,740
which is going to serve as the backbone
256

256

00:08:30,740  -->  00:08:32,440
of our data center network.
257

257

00:08:32,440  -->  00:08:34,700
This spine and leaf architecture can also be combined
258

258

00:08:34,700  -->  00:08:36,710
with our standard three-tier hierarchy.
259

259

00:08:36,710  -->  00:08:37,830
Now, when we do this,
260

260

00:08:37,830  -->  00:08:39,590
all the servers in the data center will connect
261

261

00:08:39,590  -->  00:08:40,600
to the leaf layers,
262

262

00:08:40,600  -->  00:08:42,750
and the leaf layers will connect to the spine.
263

263

00:08:42,750  -->  00:08:44,540
But the spine will then connect directly
264

264

00:08:44,540  -->  00:08:46,640
to the core layer of the three-tiered model
265

265

00:08:46,640  -->  00:08:49,130
whereas all the other non-data center devices
266

266

00:08:49,130  -->  00:08:50,630
will connect to the access layer
267

267

00:08:50,630  -->  00:08:52,830
and then up to the distribution or aggregation layers
268

268

00:08:52,830  -->  00:08:55,020
before connecting into the core layer.
269

269

00:08:55,020  -->  00:08:56,980
Next, we need to discuss traffic flows
270

270

00:08:56,980  -->  00:08:58,680
in relation to our data centers.
271

271

00:08:58,680  -->  00:08:59,990
Now there's two main types.
272

272

00:08:59,990  -->  00:09:02,310
We have North-South and East-West.
273

273

00:09:02,310  -->  00:09:03,620
These two terms are used to describe
274

274

00:09:03,620  -->  00:09:06,910
the direction of traffic flow into or out of a data center.
275

275

00:09:06,910  -->  00:09:08,590
Now, when we have North-South traffic,
276

276

00:09:08,590  -->  00:09:10,600
this is going to refer to communication traffic
277

277

00:09:10,600  -->  00:09:12,070
that enters or leaves the data center
278

278

00:09:12,070  -->  00:09:15,090
from a system fiscally residing outside of the data center.
279

279

00:09:15,090  -->  00:09:17,560
So when we talk specifically about North traffic,
280

280

00:09:17,560  -->  00:09:20,100
this is traffic that is exiting your data center.
281

281

00:09:20,100  -->  00:09:21,780
Southbound traffic on the other hand
282

282

00:09:21,780  -->  00:09:24,360
is referring to traffic that is entering your data center.
283

283

00:09:24,360  -->  00:09:26,620
In both cases, this data is exiting
284

284

00:09:26,620  -->  00:09:29,130
or entering the data center going through a firewall
285

285

00:09:29,130  -->  00:09:31,170
or other network infrastructure boundary device
286

286

00:09:31,170  -->  00:09:32,460
such as a router.
287

287

00:09:32,460  -->  00:09:34,980
Conversely, we also have East-West traffic.
288

288

00:09:34,980  -->  00:09:36,960
Now, East-West traffic refers to data flow
289

289

00:09:36,960  -->  00:09:38,380
within a data center.
290

290

00:09:38,380  -->  00:09:41,070
For example, if we're using a spine and leaf architecture,
291

291

00:09:41,070  -->  00:09:43,840
any data flow between various servers in the data center,
292

292

00:09:43,840  -->  00:09:45,550
even if it goes between different leafs
293

293

00:09:45,550  -->  00:09:47,670
would be considered East-West traffic
294

294

00:09:47,670  -->  00:09:50,490
because that data is not leaving our data center.
295

295

00:09:50,490  -->  00:09:53,020
Now due to the increased use of software-defined networking,
296

296

00:09:53,020  -->  00:09:55,810
virtualization, private cloud, and converge networks,
297

297

00:09:55,810  -->  00:09:57,420
more and more traffic that we're using
298

298

00:09:57,420  -->  00:09:59,870
is being classified as East-West traffic,
299

299

00:09:59,870  -->  00:10:02,430
because it's still virtually part of your data center.
300

300

00:10:02,430  -->  00:10:03,540
So in summary,
301

301

00:10:03,540  -->  00:10:05,530
if the data is entering the data center,
302

302

00:10:05,530  -->  00:10:07,400
it's considered Southbound traffic.
303

303

00:10:07,400  -->  00:10:08,790
If it's leaving the data center,
304

304

00:10:08,790  -->  00:10:10,470
it's considered Northbound traffic.
305

305

00:10:10,470  -->  00:10:12,000
If it's moving within the data center,
306

306

00:10:12,000  -->  00:10:13,950
it's considered East-West traffic.
307

307

00:10:13,950  -->  00:10:15,870
Finally, we need to talk about on-premise
308

308

00:10:15,870  -->  00:10:17,640
versus hosted data centers.
309

309

00:10:17,640  -->  00:10:19,140
This discussion is really going to come down
310

310

00:10:19,140  -->  00:10:20,940
to where are you going to store your data?
311

311

00:10:20,940  -->  00:10:23,090
Now, if you're using an on-premise data center,
312

312

00:10:23,090  -->  00:10:25,650
you're using a traditional private data infrastructure
313

313

00:10:25,650  -->  00:10:27,680
where your organization has its own data center
314

314

00:10:27,680  -->  00:10:29,900
that houses all of its servers and networking equipment
315

315

00:10:29,900  -->  00:10:32,490
that it's going to use to be able to support its operations.
316

316

00:10:32,490  -->  00:10:34,920
We call this on-premise because it's usually located
317

317

00:10:34,920  -->  00:10:37,090
in the same building as your main office.
318

318

00:10:37,090  -->  00:10:39,330
Sometimes though, you're going to have multiple offices
319

319

00:10:39,330  -->  00:10:42,940
spread across a large geographic region or across the globe.
320

320

00:10:42,940  -->  00:10:45,290
Normally, one of your offices is going to be considered
321

321

00:10:45,290  -->  00:10:47,820
your headquarters and will host your on-premise data center
322

322

00:10:47,820  -->  00:10:49,310
in this type of organization.
323

323

00:10:49,310  -->  00:10:51,400
And then all the other offices around the globe,
324

324

00:10:51,400  -->  00:10:53,240
they'll be called branch offices.
325

325

00:10:53,240  -->  00:10:54,470
Now these branch offices
326

326

00:10:54,470  -->  00:10:56,200
usually will not host their own servers,
327

327

00:10:56,200  -->  00:10:57,560
but instead they will host them
328

328

00:10:57,560  -->  00:11:00,280
in your on-premise data center at your headquarters.
329

329

00:11:00,280  -->  00:11:01,360
If you have a fast enough connection
330

330

00:11:01,360  -->  00:11:03,330
between each branch office and the headquarters,
331

331

00:11:03,330  -->  00:11:05,660
you can host everything at your main data center.
332

332

00:11:05,660  -->  00:11:07,460
But if you have slower connections,
333

333

00:11:07,460  -->  00:11:09,310
you may need to host some services locally
334

334

00:11:09,310  -->  00:11:11,130
inside the branch office too.
335

335

00:11:11,130  -->  00:11:13,020
For example, when I was an IT director
336

336

00:11:13,020  -->  00:11:15,330
for an organization spread across multiple countries,
337

337

00:11:15,330  -->  00:11:18,160
we had our own on-premise data center at our headquarters
338

338

00:11:18,160  -->  00:11:19,780
where we hosted most of the services
339

339

00:11:19,780  -->  00:11:22,530
including our domain controllers, email, proxy servers,
340

340

00:11:22,530  -->  00:11:23,780
and other services,
341

341

00:11:23,780  -->  00:11:25,910
but we still maintain a local file server
342

342

00:11:25,910  -->  00:11:28,740
in each branch office for them to use for their share drives
343

343

00:11:28,740  -->  00:11:31,030
because otherwise they would be transferring gigabytes
344

344

00:11:31,030  -->  00:11:33,600
and gigabytes of data to and from our data centers
345

345

00:11:33,600  -->  00:11:35,000
over a small connection.
346

346

00:11:35,000  -->  00:11:37,510
And this would really slow down the entire network.
347

347

00:11:37,510  -->  00:11:39,570
Now, this solution for us worked really well
348

348

00:11:39,570  -->  00:11:40,980
because the branch office locations
349

349

00:11:40,980  -->  00:11:43,760
only need to access their own files on their share drive
350

350

00:11:43,760  -->  00:11:45,760
not any files from the main office.
351

351

00:11:45,760  -->  00:11:47,830
Now, if they instead need to have a shared file server
352

352

00:11:47,830  -->  00:11:49,120
with us at the head office,
353

353

00:11:49,120  -->  00:11:50,710
we would have opted for something else
354

354

00:11:50,710  -->  00:11:52,820
like a content engine or a caching engine
355

355

00:11:52,820  -->  00:11:54,400
instead of using a local file server
356

356

00:11:54,400  -->  00:11:55,780
to meet their needs.
357

357

00:11:55,780  -->  00:11:56,990
Now, the other option though,
358

358

00:11:56,990  -->  00:11:59,830
is to host your data using a co-located data center.
359

359

00:11:59,830  -->  00:12:02,030
Now in a co-located data center arrangement,
360

360

00:12:02,030  -->  00:12:03,710
your organization places their servers
361

361

00:12:03,710  -->  00:12:05,910
and networking equipment in the data center environment
362

362

00:12:05,910  -->  00:12:07,550
that's owned by another company.
363

363

00:12:07,550  -->  00:12:10,140
Essentially, you're going to rent space in their data center
364

364

00:12:10,140  -->  00:12:11,840
instead of having to build your own.
365

365

00:12:11,840  -->  00:12:14,690
When I started my very first company back in 1999,
366

366

00:12:14,690  -->  00:12:16,830
I was doing website design, website hosting,
367

367

00:12:16,830  -->  00:12:18,270
and building network architectures
368

368

00:12:18,270  -->  00:12:20,300
for small and medium sized businesses.
369

369

00:12:20,300  -->  00:12:21,460
Because I was just starting out,
370

370

00:12:21,460  -->  00:12:23,660
I couldn't afford the millions of dollars of the cost
371

371

00:12:23,660  -->  00:12:25,150
to make my own data center.
372

372

00:12:25,150  -->  00:12:27,110
So we wanted to host our web servers
373

373

00:12:27,110  -->  00:12:28,820
and we decided to lease two racks
374

374

00:12:28,820  -->  00:12:30,620
in a larger company's data center.
375

375

00:12:30,620  -->  00:12:32,080
For a fixed price each month,
376

376

00:12:32,080  -->  00:12:33,740
I was able to put whatever equipment I wanted
377

377

00:12:33,740  -->  00:12:35,350
that would fit into those two racks
378

378

00:12:35,350  -->  00:12:37,400
and they would provide me with a Cat5 connection
379

379

00:12:37,400  -->  00:12:39,320
with a hundred megabits per second of bandwidth,
380

380

00:12:39,320  -->  00:12:41,570
power, and backup batteries, and generators.
381

381

00:12:41,570  -->  00:12:44,200
Beyond that it was up to me to drive their facility,
382

382

00:12:44,200  -->  00:12:45,720
install and maintain all my own servers
383

383

00:12:45,720  -->  00:12:46,650
and networking equipment
384

384

00:12:46,650  -->  00:12:48,930
and run all the configurations I needed.
385

385

00:12:48,930  -->  00:12:50,400
Now, the last option we have
386

386

00:12:50,400  -->  00:12:52,700
is to move everything into a cloud-based platform
387

387

00:12:52,700  -->  00:12:55,540
like Amazon Web Services or Microsoft Azure.
388

388

00:12:55,540  -->  00:12:57,800
In those cases we can't use co-location
389

389

00:12:57,800  -->  00:12:59,490
because they're not going to allow us put our own servers
390

390

00:12:59,490  -->  00:13:00,800
into their facilities.
391

391

00:13:00,800  -->  00:13:02,750
Instead we would have to migrate all of our data
392

392

00:13:02,750  -->  00:13:04,650
out of our servers and our data centers
393

393

00:13:04,650  -->  00:13:07,290
and put them into their servers and their data centers.
394

394

00:13:07,290  -->  00:13:09,630
All right, as you can see there are lots of different ways
395

395

00:13:09,630  -->  00:13:12,000
to architect your data centers and your networks.
396

396

00:13:12,000  -->  00:13:14,090
Everything from a three-tiered traditional model
397

397

00:13:14,090  -->  00:13:15,860
to a more modern software-defined network
398

398

00:13:15,860  -->  00:13:18,050
that implements spine and leafs to moving completely
399

399

00:13:18,050  -->  00:13:18,910
to the cloud.
400

400

00:13:18,910  -->  00:13:20,560
It really depends on your business case
401

401

00:13:20,560  -->  00:13:22,060
and your organization's needs.
