Re: [sami] A new draft on state migration use cases is submitted.

卓志强(研七 福州) <zhuozq@ruijie.com.cn> Tue, 11 October 2011 06:06 UTC

Return-Path: <zhuozq@ruijie.com.cn>
X-Original-To: sami@ietfa.amsl.com
Delivered-To: sami@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E4B321F8D53 for <sami@ietfa.amsl.com>; Mon, 10 Oct 2011 23:06:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.991
X-Spam-Level: **
X-Spam-Status: No, score=2.991 tagged_above=-999 required=5 tests=[AWL=3.739, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, MIME_8BIT_HEADER=0.3, RDNS_NONE=0.1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lyq-2USwa70B for <sami@ietfa.amsl.com>; Mon, 10 Oct 2011 23:06:39 -0700 (PDT)
Received: from fzex.ruijie.com.cn (unknown [120.35.11.201]) by ietfa.amsl.com (Postfix) with ESMTP id EABE921F8D46 for <sami@ietf.org>; Mon, 10 Oct 2011 23:06:38 -0700 (PDT)
Received: from FZEX.ruijie.com.cn ([::1]) by fzex.ruijie.com.cn ([::1]) with mapi; Tue, 11 Oct 2011 14:06:37 +0800
From: "卓志强(研七 福州)" <zhuozq@ruijie.com.cn>
To: Linda Dunbar <linda.dunbar@huawei.com>, "刘茗(研六 福州)" <lium@ruijie.com.cn>, "Yingjie Gu(yingjie)" <guyingjie@huawei.com>, 'Juergen Schoenwaelder' <j.schoenwaelder@jacobs-university.de>
Thread-Topic: [sami] A new draft on state migration use cases is submitted.
Thread-Index: AQHMgdu7ms9tl0Rqcky/axuIq0CnsZVziHEAgAAnLwCAAJ2LAIAA2ayAgABqeICAAR49wA==
Date: Tue, 11 Oct 2011 06:06:34 +0000
Message-ID: <169529F73649BF469B4F61792955CD5C125E230D@fzex.ruijie.com.cn>
References: <CAB+71L3btz_h8Lkm9jW-WHUeS4=K-Jq-r9mmX94=NdHiepkJ-Q@mail.gmail.com> <2CE4AB2F9CD06543A3F2B0FE76661E12125C8295@fzex.ruijie.com.cn> <20111009160138.GB99820@elstar.local> <000601cc86eb$829967f0$87cc37d0$@com> <2CE4AB2F9CD06543A3F2B0FE76661E12125C85F9@fzex.ruijie.com.cn> <4A95BA014132FF49AE685FAB4B9F17F61209F3D1@dfweml506-mbx>
In-Reply-To: <4A95BA014132FF49AE685FAB4B9F17F61209F3D1@dfweml506-mbx>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Cc: 'A tao' <yangjingtao@gmail.com>, "sami@ietf.org" <sami@ietf.org>
Subject: Re: [sami] A new draft on state migration use cases is submitted.
X-BeenThere: sami@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: State Migration <sami.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sami>, <mailto:sami-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sami>
List-Post: <mailto:sami@ietf.org>
List-Help: <mailto:sami-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sami>, <mailto:sami-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Oct 2011 06:06:40 -0000

I have the following documents to get some reference data,
http://people.netfilter.org/kadlec/nftest.pdf

The "filtering rules" is like ACLs. As the numbers increase, the performance of different software have declined.


-----Original Message-----
From: sami-bounces@ietf.org [mailto:sami-bounces@ietf.org] On Behalf Of Linda Dunbar
Sent: Tuesday, October 11, 2011 4:46 AM
To: 刘茗(研六 福州); Yingjie Gu(yingjie); 'Juergen Schoenwaelder'
Cc: 'A tao'; sami@ietf.org
Subject: Re: [sami] A new draft on state migration use cases is submitted.

Tao, 

That is an interesting description. Can you elaborate a little bit on pros and cons of hypervisor CPU taken by the security vs. the extra processing on switches? 

Linda 

> -----Original Message-----
> From: sami-bounces@ietf.org [mailto:sami-bounces@ietf.org] On Behalf Of
> 刘茗(研六 福州)
> Sent: Monday, October 10, 2011 9:25 AM
> To: Yingjie Gu(yingjie); 'Juergen Schoenwaelder'
> Cc: 'A tao'; sami@ietf.org
> Subject: Re: [sami] A new draft on state migration use cases is
> submitted.
> 
> Dear  Yingjie,
> 
> Yes, you got my point. Our customers deploy the virtualization in order
> to improve the utility of hardware resources, especially the CPU . But
> the security policy executed by the hypervisor will consume the CPU
> resource without money back. So if the switches can migrate the
> security policy across the physical machine, it will make more money
> back.
> 
> Oh, I forgot introducing myself. My name is Ming Liu. I'm  a product
> manager from a network product vendor in China mainland and in charge
> of solutions and products for Data Center. And our customers include
> government, universities, ICP and so on .
> 
> -----Original Message-----
> From: Yingjie Gu(yingjie) [mailto:guyingjie@huawei.com]
> Sent: Monday, October 10, 2011 9:25 AM
> To: 'Juergen Schoenwaelder'; 刘茗(研六 福州)
> Cc: 'A tao'; sami@ietf.org
> Subject: Re: [sami] A new draft on state migration use cases is
> submitted.
> 
> Ming, you'd better introduce yourself :)
> 
> My understanding of these words is that, instead of deploying ACLs on
> Hypervisor and try to migrate ACLs between Hypervisors, the customer
> would like the ACLs be deployed on switches and migrate ACLs between
> switches.
> 
> Is this what you mean, Ming?
> 
> 
> Best Regards
> Gu Yingjie
> 
> -----邮件原件-----
> 发件人: sami-bounces@ietf.org [mailto:sami-bounces@ietf.org] 代表
> Juergen Schoenwaelder
> 发送时间: 2011年10月10日 乐乐0:02
> 收件人: 刘茗(研六 福州)
> 抄送: A tao; sami@ietf.org
> 主题: Re: [sami] A new draft on state migration use cases is submitted.
> 
> On Sun, Oct 09, 2011 at 01:41:24PM +0000, 刘茗(研六 福州) wrote:
> > One of our customers, the leader of online shopping provider in china,
> have the same requirement.  They run VMs on the power x86 machine with
> KVM hypervisor. For some security reasons, they applied the ACLs
> through the Linux’s IPtable running on the Hypervisor. But when the VM
> floating , the IPtable profile can not be migrated to the other machine.
> So they hope the switch can replace the IPTable  and can migrates the
> ACL profiles for the VM when floating .
> 
> The switches really have nothing to do with ACLs sitting in the
> hypervisor. Making the switches responsible for migrating the ACLs
> seems broken to me.
> 
> /js
> 
> --
> Juergen Schoenwaelder           Jacobs University Bremen gGmbH
> Phone: +49 421 200 3587         Campus Ring 1, 28759 Bremen, Germany
> Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>
> _______________________________________________
> sami mailing list
> sami@ietf.org
> https://www.ietf.org/mailman/listinfo/sami
> 
> _______________________________________________
> sami mailing list
> sami@ietf.org
> https://www.ietf.org/mailman/listinfo/sami
_______________________________________________
sami mailing list
sami@ietf.org
https://www.ietf.org/mailman/listinfo/sami