The shape of networks to come

At last year’s Cisco Live, I sat in a room full of network engineers and architects who were openly hostile to the Cisco marketing person presenting to us. We were talking about control systems, the Internet of Things, and the networking needed to tie modern technologies together.

The presentation was basically “just buy more traditional route/switch gear and you’ll be prepped for this brave new world”, to which the audience almost universally responded “Umm, no.”

I hate being sold to, but something else irked me. I reject the philosophy they were selling all-together – that the current LAN/WAN model will be the path forward.

Popping the stack

Compute is no longer tied to individual, physical datacenters. It has become cloudified – abstracted to the point that we only really talk about the app and automation layers rather than single VMs or even datacenters. Sure, those things exist in the stack, but we don’t really care about them as discrete objects.

Transport (networking), is following the same trend. Switches, routers, firewalls, whathaveyou – are part of the stack, but managing them individually is no longer desirable or sustainable. To adapt to the flux of compute and apps, the network layer has to be handled in software via fullstack policies, rules, and configurations that are independent of individual paths, devices, or locations.

This app needs to be delivered to this user where-ever they are at, across whatever transport is available.

That’s the promise of software defined networking and the death of the LAN as the center of the universe. If we’re defining fullstack access policy and tying it to the identity and rights of each user or resource, the LAN (and WAN, to some extent) is largely dumb plumbing being assembled and re-assembled by software.

Centralized ingress/egress becomes less relevent as well, especially when host-to-host connections are built and policed dynamically. Host and platform-based firewall/IDS/IPS are able to adapt more effectively than centralized, monolithic solutions in this scenario.

VMware’s NSX is a good example of this model (at least in this transitional phase…). Assign an access policy to an app and it flows through the datacenter, across the WAN, and onto the remote device – all at an abstracted network layer that rides on top of the “dumb plumbing” referenced above.

Viptela, Silver Peak, Arista, and others (insert your favorite SDN startup)fit as well – Here are some diverse circuits, here’s the SLA for each application.  You figure it out, software.

Going forward, I no longer care about LAN or WAN – I care about data, software, and identity.

The Everywhere Network

Traditionally, if you want to build a corporate network, you order an expensive circuit from a carrier, put an endpoint like a router or firewall on it, and then build out an enclosed space behind it for trusted devices. If you want two or more locations with trusted devices to communicate with one another, you start looking at technologies like VPNs and MPLS to glue everything together.

If you want resiliency, you order more circuits and create multiple paths for your network traffic. Then you setup dynamic routing protocols and say “Perform! Self-heal! Abracadabra!”

That model, while somewhat flexible, is physical, cumbersome, and geographically pinned. It requires that IT staff wrap ever more complex and onerous controls around the network and attached devices, expanding their attack surface in an attempt to control their attack surface.

It’s a model that will continue to exist for the foreseeable future but will be pushed further and further upstream, into the domain of carriers and service providers, following the same path as compute.

A possible and, in my opinion, likely, future of the access network is one that is omnipresent and largely untrusted – a mobile, shared access WAN that obviates traditional network boundaries and segmentation.

Carriers and OEMs are testing 5G cellular network tech as I write this. It may be that 6G or 7G need to come into play before client access changes wholesale, but the progression seems natural to me; assume that the new, ubiquitous network is unsecure, collapse the security domain (reducing the attack surface) to account for that, and implement tech and controls around data, apps, and identity.

Given that direction, classical network management becomes less of a thing on the customer side and evolves to be more service provider-focused. But just like cloud compute, the corporate default will be to fallback to simpler, base network configs that serve as a underlayer to a virtualized, app-driven topology and to consume transport services rather than building and maintaining them.

This assumes that even the corporate network will be common utility rather than a proprietary diamond. (It also assumes that encryption doesn’t become illegal.) All technologies glide along the slope from rare to commodity – some take longer than others. There is no reason networking won’t follow this arc.

Photo credit: Screenpunk

Oasis

A whisper and the scent of blood woke it. The blood was simple, uncomplicated. The whisper, more complex, spiced with fear, anger, sorrow, acceptance. Both trickled downward into the earth.

“Help me.”

It was spread thin and pieces of it refused to come when called, empty of life or gone wild in isolation. What returned came slowly. Hours passed as it collected enough of itself to remember what it was. The blood it smelt had long since dried, forming brittle roots and rivers that would be broken and scattered by the wind. Only a memory remained of the whisper, but it was an anchor to pull itself from deep dreaming.

It rippled across red stone and scrub as it searched. The air bent and flowed around it – liquid heat dripping upward into the sky that did not burn except what it chose to. It was colorless fire.

The djinn found the woman’s ghost in an arroyo where she wept over her corpse.

The body was wrapped in a rough Navajo blanket that had partially opened, revealing leathery skin and blonde hair burned by harsh bleaching and failed attempts to recapture youth. Her flesh was covered in dark bruises and angry wounds.

Insects scurried away as the djinn approached and the carrion birds circling above sang an ugly song. In the high heat of the day, the ghost shivered from the painful cold that follows the dead. The djinn surrounded her with its warmth.

She wept into the night and through the next day, fully consumed in her grief. It wasn’t until the following sunset that she considered her companion.

“Where do I go now?”

The djinn expressed uncertainty, nothingness and wholeness, a sky bright with stars, an empty void.

The ghost laughed, a dry bark filled with anguish. “No answer even now, huh? Well, I don’t think I could go anywhere anyways. Feels like something’s got its claws in me.”

The djinn did not respond and the ghost stood by it silently until the moon was bright and high above. When she looked towards the djinn again it was a pulsing, black star darker than the night around it.

“I don’t exactly know what you are and I figure I ain’t got no right to ask favors of you regardless, but I’m going to anyway.”

She climbed to the top of the arroyo (the djinn followed) and pointed to lights glowing in the east, then back at the body lying the dried stream bed.

“I want justice. Can you give me that?”

For the first time in five-hundred years, the djinn spoke. Its voice seemed to come from all directions and filled her mind with fire.

“No.”

She began weeping again and collapsed to the ground, holding her knees tight to her chest. She rocked and sobbed, not noticing the fire light building around her. The light had reached is peak and was fading when she discovered that she felt lighter. The bonds holding her to her body had been seared away.

She turned to the shadow beside her. A soft glow pulsed from deep inside it, but soon went dark.

“I am cleansing fire, the mercy of the desert. I give you both.”

And the ghost was gone.

The djinn enveloped her body and burned it to white ash, then turned toward the eastern lights.

A highway that had once been busy with travelers split the town in half, following the path of an older, more powerful road that no humans had ever walked. Its asphalt was being devoured by time and wind.

Signs welcoming visitors to the town lay buried and its name no longer appeared on any maps. It had once been an oasis where travelers and creatures of the desert quenched their thirst, now it was an ugly wound.

The djinn moved among trailer homes and eroding buildings of cinder block and brittle, dry wood, and took notice of the life present. Only a few dozen still lived here – those too old, stubborn, or hopeless to leave. The whole valley stank of their despair and regret.

It entered a home where an old woman slept on a broken-footed couch. The floor was cluttered with liquor bottles and cast-aside romance novels. She snored loudly and exhaled alcohol fumes.

The djinn’s presence filled the room with uncomfortable heat that woke her. Disorientation and confusion gave way to terror as the black shadow surrounded her, but her scream was stopped short as understanding and calm flowed through her. She smiled sadly.

The home began to burn in merciful, silent inferno.

It visited each of the town’s inhabitants in slow succession. None resisted the djinn, several never even woke as they burned away.

By sunrise the entire town was ash and puddles of cooling metal. What remained would be hidden by sand in a few days’ time.

The djinn was diminished now, a thin, weak flame. It had covered whole valleys in waves of fire in younger days, but that power was gone now, drained away over long millennia.

It harnessed the wind to dig a pit underneath the shade of a twisted acacia tree and reached down into the earth to pull up water from the deep aquifer that had fed the wells of the town.

The pit slowly began to fill with cool water.

It looked across the dry expanse for the last time, then the cleansing fire of the desert flickered once and went out.