The implementation of the UniNet's research DMZ
Kittipat Jutawongcharoen, Vara Varavithya, Kriangsak Lekdee, Arthit Chaichit, Tawee Sribuddee · 2016
The research and education network is the crucial driving infrastructure that fosters advances in networking. Because of best efforts nature of the Internet, services offered to researches sometimes cannot meet high throughput requirements. The network path is also swamped with network and security devices which create bottlenecks. Many efforts have been proposed to ease this problem, for example, the use of dedicated links, L2-VPN, and QoS mechanisms. Recently, the DMZ concept was proposed as the network pattern to provide high performance networks for researchers. We adopted that concept and implement six research DMZ nodes in the UniNet. Basic network components for research DMZ are defined. A set SDN switches and controllers were installed at the DMZs to control resource accesses. The SDN switch is based on the NetFPGA and the RYU controller orchestrates operations of these switches using OpenFlow. The bandwidth performance between these DMZ nodes is shown. The throughput of 700-900 Mbps between end points of participated institutes was demonstrated, compared to roughly 90 Mbps under campus environment.