You are on page 1of 5

Software Defined Networks: Issues and Challenges.

Bhargava Sokappadu Avishek Hardin Avinash Mungur


Dept. of Information and Dept. of Information and Dept. of Information and
Communication Technologies Communication Technologies Communication Technologies
University of Mauritius University of Mauritius University of Mauritius
Port-Louis, Mauritius Port-Louis, Mauritius Port-Louis, Mauritius
bhargava.sokappadu2@umail.uom.ac. avishek.hardin4@umail.uom.ac.mu a.mungur@uom.ac.mu
mu
Sheeba Armoogum
Dept. of Information and
Communication Technologies
University of Mauritius
Port-Louis, Mauritius
s.armoogum@uom.ac.mu

Abstract—Contemporary development of the Software a single pane of management. At present, there is limited
Defined Network technology (SDN) brings a number of key information available regarding the migration of an existing
challenges. Current issues such as performance, scalability, legacy tiered network infrastructure towards SDN in terms
security, interoperability are highlighted. In this paper, the of costs, compatibility and issues explaining whether it is
question of whether to adopt and capitalize on the concept of
worthwhile for a firm to migrate towards SDN and the
SDN by enterprises, taking into consideration the cost
implications and whether it’s worth to invest on such state-of- approach to be taken [2].
the-art methodology.
This paper is targeted towards those who are intending
Keywords—Software-Defined Network (SDN), OpenFlow, to migrate an existing tiered network to SDN network and
Network Virtualization, QoS, Security. aims at providing a deep insight on the pros and cons of
moving towards SDN with its associated cost factors,
I. INTRODUCTION feasibility and security aspects. In addition, the challenges
faced in SDN planning and deployment especially in terms
With today’s advanced data center infrastructures,
of multi-vendor interoperability will be addressed. Taking
Software Defined Networking (SDN) is no more a
into consideration of the existing issues like performance,
buzzword and holds the roadmap for networking industries
scalability, synchronized security and interoperability to
towards Software Defined Data Center (SDDC) networks.
The concept of SDN, though technically complex but rather cater for future growth, the roadmap for the phased
simple to understand, consists of a full-fledged network migration and target architecture is proposed for generic
network environment.
solution based on TCP/IP layered approach where all the
necessary switching, routing and firewalling aspects are
This paper is structured as follows: - Section II provides
predefined and controlled from the SDN controller. The
a description of how SDN concepts started and explains
latter is autonomous in the sense that it configures the nodes
such as routers, switches, firewalls and servers without the how SDN has started and evolved. Section III illustrates the
need of manual intervention compared to legacy methods different SDN solutions currently available on the market.
Section IV discusses the advantages and disadvantages of
[1].
SDN solutions with Section V explaining the challenges
Within a short period of time, SDN has rapidly taken
faces in SDN implementation. Section VI provides a brief
over the world of networking urging most firms to move
towards a SDN ready infrastructure. Though many description of the SDN best practices which can be
advantages like Centralized Network Provisioning, Holistic followed. Finally, Section VII concludes the paper.
Enterprise Management, Granular Security, Low Operating II. HISTORY AND EVOLUTION OF SDN
Cost and Hardware savings & reduce Total Cost of
Ownership (TCO), it is a common complaint that, firms The term SDN is quite ambiguous especially due to the
misconception that Software Defined Networking is
claim a massive capital expenditure (CAPEX) whereby a
applicable only to conventional network devices such as
full network inventory refresh needs to be carried out prior routers and switches. But in fact, a network is a whole
to adopting the concept of SDN, and this indeed is an area interconnectivity of routers, switches, security appliances,
of concern to radically leverage on the investment and hosts, servers and much more.
return on investment of such a huge project. On top, most
SDN vendors limit their SDN controller capabilities to As such, the revolution towards a Software-Defined
devices of their own brand which worsens the infrastructure was available since around 10 years ago with
interoperability among several vendor products solutions. the advent of server virtualization platforms such as
VMware, Hyper-V, Citrix inter alia. Following the advent of
The key challenge in SDN relates to the segregation of the next major trend which is Cloud Computing, the concept
of SDN has now spread across several segments which
the control and data planes while maintaining the carrier
include Network Function Virtualization (NFV), Software-
grade service such as Scalability, Reliability, Quality of
Defined Storage, Software-Defined WAN, Software-Defined
Service and Service Management within the framework via Access among many others but all these solutions can be

978-1-7281-1460-6/19/$31.00 ©2019 IEEE


Authorized licensed use limited to: NATIONAL INSTITUTE OF TECHNOLOGY TIRUCHIRAPALLI. Downloaded on November 18,2023 at 18:14:24 UTC from IEEE Xplore. Restrictions apply.
englobed as a Software-Defined Data Center (SDDC) which tiered networks with a major inclusion of spine and leaf
comprises of several software-defined solutions which can nodes and the APIC controller. [7]
be put in place [3].
The main reason behind such a paradigm shift towards VMware is the current global leader in providing
SDDC is mainly due to rising demands in network infrastructure virtualization on traditional and
utilizations over time. As mentioned in the Gartner Report, it hyperconverged virtualized infrastructures [8]. VMware’s
is expected that most data center networking access port solution for software-defined is way different from Cisco’s
speeds will be shifting to 25Gbps during the first quarter of idea. Cisco’s APIC controls the whole network fabric
2020 [4]. including routing, switching and security aspects through
the network including access among different physical and
Gartner’s explanation of the term SDN relates “SDx is a
virtual nodes. VMware NSX solution provides the handling
collective term that encapsulates the growing market
of network traffic throughout a virtualized VMware-based
momentum for improved standards for infrastructure
programmability and data center interoperability driven by infrastructure.
automation inherent to cloud computing” [4]. Present day
software-defined trends are as follows: Given the above Cisco and VMware solutions are geared
usually towards their own appliances, other vendors such as
• Software-Defined Networking (SDN) focuses on Juniper’s Contrail SDN, Alcatel-Lucent Enterprise’s SDN
automating the control plane for automatic data and Dell Network’s SDN have adopted the Open Network
plane traffic management. Foundation solution to move towards an open-source SDN
• Network Function Virtualization (NFV) which aims and NFV control which provides vendor interoperability to
at automating network processes such as NAT, some extent given that these solutions are closely based on
Firewalling, Load Balancing etc. while running in the Open flow protocols [9].
software. [5] [3]
Today’s buzzword is definitely SD-WAN with several
• Software-Defined WAN (SD-WAN) provide high
granular policy-based WAN link load balancing in vendors rushing towards the integration of SD-WAN
tandem with security. solution in their network devices. Software-Defined WAN
deals with the basic concept of providing enhanced WAN
• Software-Defined Access (SD-Access) focuses on connectivity in terms of uptime, route redundancy,
the user policies and controlling their access to compression, load balancing, and security in an automated
different networks. manner. The main target of SD-WAN was to address the
poor branch connectivity for several enterprise networks
III. CURRENT SDN SOLUTIONS towards the Internet and corporate network to the Head
Today, there exist several SDN solutions from multiple office while leveraging on cheaper solutions compared to
vendors with major niche players like Cisco Application- leased lines. This software-defined is either contained within
Centric Infrastructure (ACI) solution, VMware NSX, Cisco the WAN Edge appliance or in another management
SD-WAN, Fortinet SD-WAN and emerging solutions based platform for the whole infrastructure. Based on the recent
on the Open Flow opted by vendors such as Juniper Gartner’s report, some main vendors for SD-WAN solutions
Networks, Dell Networks and Alcatel Lucent Networking. are Cisco, Silver Peak, VMware and Fortinet [10].
Huawei itself plays a major role in Data Centre Networking IV. PROS AND CONS OF SDN
by being a direct challenger to the market leaders [6].
However, each of the SDN solution is closely based to a It has been a long debate whether the SDN solution
particular type of development and a single solution might should be adopted and if yes, leveraging the advantages vis-
not fit the different market needs. Below provides an à-vis the disadvantages in the SDN implementation. This
overview of the aforementioned solutions before performing section demonstrates the primary advantages and
a critical analysis among these. disadvantages of moving towards SDN.
A. Advantages
Cisco ACI was announced in end 2013 and under
For several years, the traditional network methods were
implementation since around 2014 whereby the platform of
using routers, switches, security devices and these
operation of the network is controlled by the SDN controller
necessitated initial configurations and change in
known as APIC (Application Policy Infrastructure
configurations as and when required. This was indeed a
Controller). Cisco’s concept of SDN is based on having a
cumbersome activity because of the manual intervention
network fabric over a spine-leaf architecture (ACI fabric)
required for every configuration on every node through
which primarily signifies the underlay and such a network is
which the traffic flows (the control plane had to be
then predominantly controlled the APIC provides all the
configured manually). However, with SDN, this issue is
automation, decision-making, management, policies for the
refrained by automatic network configuration and any
control plane. In such a topology, the data plane is still
changes need can be either automated to take any actions
contained within the network fabric itself in such a way that
following an event or an intervention on the controller only
the APIC instructs the flow of traffic among the Spine-Leaf
– the configuration on all the other prevalent nodes are then
fabric and is therefore responsible for decision-making
controlled through the controller itself which indeed
among the network fabric architecture. Cisco’s ACI solution
provides rapid deployment, troubleshooting and
involves significant changes with respect to traditional
maintenance with the minimal human intervention possible

Authorized licensed use limited to: NATIONAL INSTITUTE OF TECHNOLOGY TIRUCHIRAPALLI. Downloaded on November 18,2023 at 18:14:24 UTC from IEEE Xplore. Restrictions apply.
that today accounts for 95% of network management solutions might still prevail. Under such circumstances,
changes [12]. Cisco ACI fabric is a good option for data center networks
to cater for infrastructures for a Cisco-based infrastructure.
In line with the above, another much awaited However, if the same network includes part of a campus
functionality was the single management platform for network, the Cisco SD-Access solution such as Cisco DNA
application, monitoring and troubleshooting for all the Center is highly recommended as well. The SDN controller
devices in the network. Previous management solutions such for the data center infrastructure to control the ACI fabric is
as Network Monitoring platforms were not as powerful and the Cisco APIC whilst the SDN controller for campus
granular as provided by SDN controllers such as the Cisco network traffic is the Cisco DNA center solution. The
APIC even provide application, fault, event and advantage with a Cisco Software Defined Data Center
performance management on all the nodes [8]. architecture is that the Cisco ACI solution can cater for the
east-west and northbound traffic offering firewalling
As an example, SDN solutions such as Cisco ACI and features with the integration of the Cisco Firepower with the
the VMware NSX provide management of virtualized Cisco ACI fabric whereby the Cisco APIC controller would
networks, their integration with the physical network nodes be responsible for the whole management while integrating
and their respective configurations. This provides a unique security [14].
and single network fabric which was not possible earlier
with the hypervisor infrastructure having its own However, if the user has a highly virtualized data center
configuration and the physical nodes a separate one which environment, considering the fact that VMware holds the
made configuration management tough. largest market share [15], this opens up several solutions
which are best fit for VMware infrastructures. A good
B. Disadvantages
option would be to move towards VMware NSX solution
The main disadvantage of moving towards an SDN which is optimal of course given it is from VMware itself.
solution is undoubtedly the huge investment involved in the However, VMware NSX is capable of controlling only
implementation of such a project. SDN-capable equipment server traffic among virtual machines or hypervisor hosts
is tremendously costly compared to a conventional network while offering limited resources in terms of traditional
offering almost no backward compatibility with tiered routing, switching and security among other network
networks. This means that implementing and deploying an appliances which do not form part of the virtualized
SDN solution involve full infrastructure refresh rather than a environment such as routers and switches. This can be
phased hardware inventory refresh and is definitely a big remediated by deploying Cisco ACI fabric in tandem with
discouragement for enterprises willing to move towards VMware NSX. In this solution, the Cisco ACI acts as the
SDN. underlay network and NSX works atop the fabric as an
overlay network but this still involves to some extent two
Furthermore, current SDN solutions offer very limited if separate control/ management planes and the price of two
no multi-vendor solution compatibility which points back to separate infrastructures.
the drawback of high initial cost since the whole network
would need to be harmonized to a single vendor network to B. Security for the solution
optimize the SDN solution at most. Relative to conventional Security is a primordial aspect not to be missed when
hierarchical networks, multi-vendor compatibility is not an sizing any network solution. SDN security solutions consist
issue in terms of operation of a solution, even though this of Edge Firewalling, Intra-zone firewalling, user access
comes into play when dealing with unified network control amongst others. Again, several vendors come into
management or synchronized security. play with the main players being Cisco, Fortinet when it
comes to SDN [16]. Cisco ACI solution integrates security
V. CHALLENGES AND ISSUES features in all the Software Defined Solutions namely Cisco
A missing highlight in today’s current publications on ACI which is compatible with Firepower firewalling
SDN implementations is the lack of an implementation plan solutions, Cisco SD-Access and Cisco SD-WAN as well as
suited for each different enterprise network or data center offering an embedded security control mechanism within
topology. No significant information is available in the the SDN controller at the fabric layer itself.
approach to be adopted towards moving to SDN nor the
phased-migration approach. Usually enterprise / data center Fortinet, however covers a niche market since its
networks are multi-vendor based as a single vendor does not presence in the SDN market focuses on the security aspect
cater the whole integrity of the solution or due to price and its integration within an SDN solution while it however
constraints several vendor equipment were used. provides security interoperability with both major SDN
solutions: Cisco ACI and VMware NSX. This also means
A. Choosing the SDN solution
that to some extent two control planes are involved- one for
The first challenge that such an enterprise would face is the network fabric and one for the firewalling side. The
to choose an SDN solution which is best suited to adapt to same approach is brought by CheckPoint Technologies, Palo
the current environment which in turn means choosing the Alto Networks and others to offer security for both ACI and
vendor (Cisco currently occupies a market share of almost NSX network fabrics. [17]
53.4% in switching solutions which is why we have focused
on a Cisco-based switched and routed network [13].) In this
case, it is believed that the trend to continue with Cisco

Authorized licensed use limited to: NATIONAL INSTITUTE OF TECHNOLOGY TIRUCHIRAPALLI. Downloaded on November 18,2023 at 18:14:24 UTC from IEEE Xplore. Restrictions apply.
C. Inter-operability infrastructure rather than the campus topology or vice versa.
As highlighted throughout this paper, SDN vendor Similarly, it is a recommendation to choose a vendor that
interoperability is one of the significant drawback of moving makes up most of the expected network infrastructure to
towards any SDN solution. Currently, there exist limited cater and offer maximum operability for the single vendor
compatible solutions which can easily integrate seamlessly solution. The major pint of concern is definitely a trade-off
with minimal overhead among multiple vendor networks. between budgetary constraints and technological
Even though security is provided by several firewalling advancement which means that the solution should be well
vendors, it still does not provide a single management calculated in terms of CAPEX, OPEX, TCO and ROI over
platform for the whole network unless a single- vendor full- 5-7 years at least compared to a conventional solution via
fledged solution is opted for. Several vendors have joined phased upgrade. Similarly, it is recommended for new
the Open Networking Foundation (ONF) with a view to networks to consider opting the SDN solution itself as it
provide a consortium to move towards an open SDN represents a lower TCO over years [18]. The
solution such as Dell and Juniper as partners and Cisco as recommendation for an existing data center infrastructure
innovator, however interoperability among different vendor with a conventional network would be to perform a phased
solutions is an issue due to limited resources or use cases of migration by initially moving towards a hardware refresh
a multi-vendor deployment. As at date, the only vendor which are SDN capable but can also support conventional
integration can be done by major modifications of each of protocols. Once the switching and routing has been
the available APIs for a vendor to allow integration but refreshed over a few years, the SDN controllers can
again not to the maximum extent to provide a synchronized thereafter be included to automate the processes. This
architecture. To summarize, among the several SDN approach is currently already brought by Cisco ACI with
vendors, there exist very limited inter-operability feature as Nexus Spine-Leaf switches and even Cisco SD-Access with
at date. SD-access ready switches and routers [8] [12].

D. Budget constraints
On the other hand, there are SDN solutions such as the
Several theories prevail regarding the budgetary
SD-WAN which are already available and offer the service
constraints of an SDN implementation project. Gartner
at almost the same cost of a hardware refresh while offering
research claims that moving towards SDN will provide
several advantages such as compression, high uptime,
savings of 30 – 70% in terms of CAPEX and over 30% in
intelligent bandwidth management and security amongst
terms of OPEX. [18] At the same time, a report by Garland
others.
Technology claims that major expenses in an SDN solution
are in Ensuring network security, Dynamic provisioning and VII. CONCLUSION
Automation and the lack of expertise in the SDN domain
In this paper, key issues and challenges related to SDN
[19]. The main issue comes to the fact that an SDN solution
have been highlighted, particularly from vendors and
requires a full hardware refresh at one go and phase
industries perspective. Most SDN vendors adopts
migration is not possible as such where a phased migration
proprietary standards rather than open standards though still
would definitely reduce the huge one-time investment. In
on the streamline, which at some extents confines the SDN
addition, currently there is no vendor solution which can
controller functionalities, resulting interoperability issues
cater for a full network infrastructure entirely maintained by
between competitors, limiting users to a single vendor
a single controller and fabric which in turn means that more
solution. This in turns causes an adverse effect to firm
than one SDN solution would need to be adopted implying
decision-makers who intend to migrate, whether for “Go” or
the costs for at least two solutions. Another significant
“No-Go” decision toward SDN solutions. Subsequently, this
player in the SDN’s price is the sizing of the solution in
involves full infrastructure replacement as legacy networks
itself and the approach vendors bring. For example, addition
are not SDN compatible and also does not provide backward
of the SDN controllers means additional hardware cost by
compatibility with tiered networks. At present, there exist
default and being a strategic part of the infrastructure
very limited solutions to an open SDN architecture while
undeniably means that they should be redundant and always
those offering the highly-featured solutions are vendor-
available as a means of processing and redundancy an in
specific. It is a trade-off to be done for companies whether
turn, this means an additional overhead in the budget to
to migrate towards an SDN solution gradually or perform a
cater for several controllers together with their licenses [8]
full network refresh. At the same time, it is recommended
VI. RECOMMENDATIONS AND BEST PRACTICES that new Data Center Infrastructure opts a full SDN solution
to minimize the TCO as compared to a traditional tiered
Currently even though there exist several vendors
network. Consequently, for firms opting for a single vendor
proposing SDN solutions, there is still no single solution
solution it is worth capitalizing on a proprietary based SDN,
that can cater for the whole network demands of an
alternatively, it is better for firms with multi-vendor
enterprise or data center. As such, a compromise needs to
solutions worth waiting for the open standard SDN solutions
be done while opting for an SDN solution in terms of which
prior investing.
part of the network infrastructure would need software-
defined automation while other parts could be considered at REFERENCES
a later stage. For example, if a topology consists of both [1] G. A. A. Santana, “VMware NSX Network Virtualization
data center and campus network topology, it is vital to Fundamentals,” vmware Press, Palo Alto , 2017.
consider about current equipment scalability, lifetime and [2] M. Marden, “IDC Business Value Brief : Cisco ACI,” International
capacity to understand whether to automate the data center Data Corporation, Framingham, 2014.

Authorized licensed use limited to: NATIONAL INSTITUTE OF TECHNOLOGY TIRUCHIRAPALLI. Downloaded on November 18,2023 at 18:14:24 UTC from IEEE Xplore. Restrictions apply.
[3] Fortinet, “The Fortinet SDN Security Framework,” Fortinet Inc., Results Bode Well for Year Ahead, International Data Corporation,
Sunnyvale, 2016. 2018.
[4] A. Lerner, “Data Center Networking Magic Quadrant 2018,” Gartner [14] Cisco, “Cisco Firepower Threat Defense Quick Start Guide for APIC
Inc, 2018. Integration, 1.0.2,” 6 December 2017. [Online]. Available:
[5] Gartner, “Gartner Identifies the Top 10 Strategic Technology Trends https://www.cisco.com/c/en/us/td/docs/security/firepower/APIC/quick
for 2014,” Gartner Inc., Orlando, 2013. -start/guide/ftd-apic-qsg-102/ftd-apic-qsg-102_chapter_00.html.
[Accessed 10 November 2018].
[6] SDXCentral, “What is NFV – Network Functions Virtualization –
Definition?,” 15 November 2018. [Online]. Available: [15] Infotech Reseach Group Inc, “Vendor Landscape: Server
https://www.sdxcentral.com/nfv/definitions/whats-network-functions- Virtualization,” 2013. [Online]. Available:
virtualization-nfv/. https://www.citrix.com/content/dam/citrix/en_us/documents/products-
solutions/vendor-landscape-server-virtualization.pdf. [Accessed 10
[7] G. Danilo Ciscato, “Magic Quadrant for Data Center Networking,” November 2018].
Gartner, Orlando, 2017.
[16] J. D. R. K. Adam Hils, “Magic Quadrant for Enterprise Network
[8] Cisco, “Cisco Application Policy Infrastructure Controller Data
Firewalls,” 4 October 2018. [Online]. Available:
Sheet,” Cisco Inc, San Francisco, 2018.
https://www.gartner.com/doc/reprints?id=1-
[9] Globe Newswire, “VMware Named a Leader in 2018 Magic Quadrant 5J7ZPYL&ct=181008&st=sb&elqTrackId=23f70889e9664194997cb
for Hyperconverged Infrastructure,” Globe Newswire, Palo Alto, 4534889f383&elq=b691379800be48c89c2d0dbf1882846c&elqaid=1
2018. 2239&elqat=1&elqCampaignId=. [Accessed 2018 November 15].
[10] Open Networking Foundation, “Open Networking Foundation Stragic [17] Palto Alto Networks, “VM-Series 8.0 Deployment Guide,” Palto Alto
Plan,” ONF, Menlo Park, 2018. Networks Inc., Palo Alto, 2018.
[11] C. C. A. L. M. T. Joe Skorupa, “Gartner 2018 Magic Quadrant for [18] KEMP, “The Economics of SDN,” 2018. [Online]. Available:
WAN Edge Infrastructure,” Gartner, Orlando, 2018. https://kempsdn.com/sdn-for-adc/the-economics-of-network-sdn/.
[12] Cisco, “Cisco Software-Defined Access - Introducing an entirely new [Accessed 15 November 2018].
era in networking,” Cisco, San Francisco, 2018. [19] C. Bihary, “Unveiling The True Cost Of Software-Defined
[13] P. J. M. S. Rohit Mehra, IDC's Worldwide Quarterly Ethernet Switch Networking,” 2 November 2015. [Online]. Available:
and Router Trackers Show Marked Improvement for Q1 2018; https://www.garlandtechnology.com/blog/unveiling-the-true-cost-of-
software-defined-networking. [Accessed 15 November 2018].

Authorized licensed use limited to: NATIONAL INSTITUTE OF TECHNOLOGY TIRUCHIRAPALLI. Downloaded on November 18,2023 at 18:14:24 UTC from IEEE Xplore. Restrictions apply.

You might also like