Many enterprises have adopted cloud computing and virtualization technologies to modernize their data centers. Compared to traditional data centers that depend on physical servers and hardware-based networks, enterprise cloud data centers face greater challenges in network security, VM isolation, and data transmission efficiency.
As the software-defined networking and security component of Arcfra Enterprise Cloud Platform (AECP), Arcfra Network Service (ANS) provides agile and effective network services tailored to the cloud environment, with distributed firewall, load balancer, and VPC networking capabilities.
For a quick overview of ANS, please check out this short video What is Arcfra Network Service.
As enterprises migrate their data centers from physical servers to an enterprise cloud platform, they may disappointedly find that their existing network security strategies designed for physical hosts and hardware-based network devices fall short in the virtualization environment.
Therefore, in the cloud era, the centralized cloud management center should provide software-defined virtual cloud network management services with features including:
ANS provides software-defined network and security services for AECP, primarily through three key functions: distributed firewall, load balancer, and VPC networking.
Unlike traditional north-south firewalls, ANS distributed firewall protects network security by focusing on the east-west traffic (i.e., data flows between VMs) in the virtualization environment. It implements a micro-segmented network model adhering to the zero trust principle and extends multiple distributed firewall policies to safeguard individual VMs from cybersecurity threats, thus offering a flexible, fine-grained, and robust security solution for a wide range of services.
#1 Easy to use
#2 High scalability
#3 High availability
#4 Broad compatibility
#1 Securing east-west traffic between services in data centers
Users can configure service labels, security groups, and security policies between different security groups on the management platform. Labels and security groups allow the automatic application of security rules, simplifying ingress and egress traffic control. Newly added VMs only need to be associated with the labels or security groups to automatically inherit application-specific security policies, requiring no need to create new security policies.
#2 Abnormal VM quarantine
Users can use ANS to detect and isolate abnormal VMs in two models.
#3 Dynamic demilitarized zone
Users can isolate and control individual services with flexible demilitarized zones created via micro-segmentation. With no dependence on dedicated hardware and resources, the software-defined demilitarized zones can be created on shared data center resources, meeting the access requirements of virtual demilitarized zones.
ANS LB provides Layer 4 load-balancing services for applications running on VMs, containers, or physical servers. It can improve application performance and reliability by evenly distributing data traffic to multiple real servers based on predefined algorithms according to IP addresses and port information in data packages. Leveraging active-active and active-standby mechanisms, it minimizes service downtime through smooth failover and protects applications with access control and QoS (bandwidth and connection limitations).
#1 Software-defined
#2 Simple operations and maintenance
#3 Flexible adaptation
#4 High availability & efficiency
#1 Balancing data traffic and resources across multiple application instances
ANS LB is mainly responsible for network traffic distribution and ensuring that no single server or application instance is overloaded. This is crucial for applications that handle numerous concurrent requests. By distributing data traffic across multiple servers or instances, ANS LB enhances overall processing capacity and reduces response times. Additionally, it dynamically adjusts traffic distribution based on each instance’s existing load and resource utilization to further optimize performance.
#2 High availability and rapid failover for applications
ANS LB continuously monitors the health of real server and application instances. If an instance fails or experiences performance degradation, the load balancer quickly redirects traffic to other healthy instances, maintaining application availability. This rapid failover capability is critical for mission-critical business applications that need to run 24/7.
#3 Applications’ coexistence and migration across heterogeneous IT infrastructure
Many users are migrating applications from physical servers to virtualization or Kubernetes. In this scenario, ANS LB plays an important role as it enables the coexistence and smooth migration of applications between different environments.
For example, ANS LB can simultaneously distribute data accessing one application to both physical servers and VMs, allowing them to run in parallel. After that, with a gradual adjustment of the weight of traffic distribution, all workloads can be migrated to VMs without service interruption. During this process, LB dynamically adapts traffic allocation based on the performance and health status of each instance, ensuring optimal service quality. This is applicable for both physical server-virtualization/container migration and the migration between different virtualization environments, for instance, migrating applications from vSphere VMs to other virtualization platforms.
Typically, users employ VLANs to isolate VMs within the Layer 2 (L2) virtual network. However, VLAN-based virtual distributed switches are still part of the underlying network (Underlay), which limits their ability to provide application-oriented network isolation, flexibility, and robust support for IT infrastructure high availability.
ANS VPC networking is a virtualized network product that provides secure and isolated network space for VMs in AECP clusters. Building on the GENEVE protocol, an advanced version of VXLAN, VPC networking is fully decoupled from the underlying physical network. It enables secure interconnections inside and outside the virtual network through virtualized network functions (VNFs), allowing users to quickly and flexibly deploy unified enterprise cloud networks across multiple data centers.
#1 Broad compatibility
#2 Rapid network deployment
#3 Business security
#4 Cloud network unified management
#1 Application security guarantee: application-based network isolation
To reduce potential security threats, users need to achieve isolation between different applications or tenants in the cloud while ensuring smooth business access and the solution’s flexibility, agility, and cost-efficiency.
For example, a company has two software development teams, with Team A responsible for developing an online shopping platform and Team B responsible for developing an enterprise resource planning system. In this case, an independent VPC can be created for each development team to deploy the VMs, databases, and other resources needed for their respective projects. The network between these two VPCs is not connected, so Team A members cannot access any resources within Team B’s VPC, and vice versa. In this approach, it forms a business-centric isolation of full-stack resources.
In terms of O&M, VPC significantly simplifies the planning process of VLAN and IP addresses. Traditionally, users need to allocate VLANs and IP address ranges separately for each development team and perform complex configurations. However, with VPCs, each VPC functions as an independent network that can use overlapping IP address ranges and eliminate the need to assign VLANs. Besides, each VPC’s network configuration and management can be handled by its owner, which greatly reduces the complexity of network management and improves O&M efficiency. Additionally, VPC can divide its network into smaller subnets, with each subnet and VM/VM group acting as an independent security zone where users can implement fine-grained security policies.
#2 Improve network flexibility: decoupling from hardware
Leveraging GENEVE-based Overlay network technology, VPC networking can be completely decoupled from the Underlay physical network. All network functions are presented in a virtualized form and managed uniformly through a software-defined approach. This allows users to quickly create various virtual network topologies and services, such as virtual switches, virtual routers, and distributed firewalls, avoiding complex changes to hardware network configuration. As a result, network agility is greatly enhanced, and the time to launch business operations is significantly reduced.
For example, a company uses network devices with different ages and brands across various data centers. These devices can be difficult to be uniformly managed due to significant differences in network architecture and configuration. By using ANS VPC, the company can create virtual private cloud networks with the same logical topology and functionality across multiple AECP clusters, even on different network devices. The configuration and management of the virtualized network are entirely independent of the underlying physical network’s topology and functionality, eliminating compatibility issues.
In this scenario, users can flexibly create and adjust VPC network configurations to meet the frequently changing business needs. In contrast, the modification of traditional physical networks can be more complex and time-consuming.
#3 Efficiently supports cross-site high availability and load balancing
As enterprises expand their business and raise expectations for business continuity, enterprise users often need to deploy applications across multiple geographically dispersed data centers to achieve load balancing, disaster recovery, and wider service coverage. ANS VPC provides a powerful cross-datacenter network virtualization solution, helping businesses seamlessly expand applications to different clusters, racks, server rooms, or data centers while achieving unified management across geographic locations. Users can associate clusters from primary and backup sites through a single VPC network, consolidating resources and simplifying O&M.
The cross-datacenter virtualization network built with ANS VPC can help enterprises with:
Arcfra simplifies enterprise cloud infrastructure with a full-stack, software-defined platform built for the AI era. We deliver computing, storage, networking, security, Kubernetes, and more — all in one streamlined solution. Supporting VMs, containers, and AI workloads, Arcfra offers future-proof infrastructure trusted by enterprises across e-commerce, finance, and manufacturing. Arcfra is recognized by Gartner as a Representative Vendor in full-stack hyperconverged infrastructure. Learn more at www.arcfra.com.