SlideShare uma empresa Scribd logo
1 de 28
Next-Gen Cisco SD-WAN Architecture
Satit Adirek
Technical Solution Architect
Cisco Systems
User and Application Landscape is Changing
Change in App Content Change in App Delivery Change in App Consumption
Rich, Dynamic, Web-Based Cloud, SaaS, Virtualized Mobile, Diverse devices
Internet Edge Is Moving to the Branch
Applications Are Moving to the Cloud
INTERNET MPLS 4G
DC vDC
IaaS SaaS
mobile
branch
guest
head
office
Architectural Constrain
SOFTWARE DEFINED: True separation of control, data
and management
CLOUD: Cloud hosted and delivered
APPLICATION AWARE: Visibility & SLA business intent
policy enforcement
SCALE AND FLEXIBILITY: True enterprise scale
SECURITY: Ingrained authentication, encryption,
segmentation, access controls & service chaining
OPEN: for automation, orchestration,
best-of-breed integration
Application
Bandwidth
Requirements
Cloud
Consumption
Disjointed
Security
Simplified
Operations
WAN
Flexibility
Time
To Capability
Challenges
Enabling Seamless transition
from traditional WAN to SD WAN
SECURE WAN FABRIC
Broadband 4G/LTEMPLS
ZERO TOUCH ZERO TRUST
1
Traditional Networks
 Control and Data Plane same
devices
 Peer-to-peer control plane
 Routing protocol prorogate
for all (N^2) complexity
 Localize management
 Complex to mnage
 Not scalable
 Impossible to support
multiple transport
4G/LTE
MPLS1Internet
MPLS2
SD-WAN Principals
• Separation Control and Data Plane
• DTLS/TLS is used to establish the
control channel
• Control channel is established only
with central controllers
• No scaling issues are with full mesh
of control plane
• Control channel does not have to
follow the data path
Cisco SD-WAN Architecture
Control Plane
(Containers or VMs)
Data Plane
(Physical or Virtual)
Management Plane
(Multi-tenant or Dedicated)
Orchestration Plane
API
4GINTERNET MPLS
vSmart
ANALYTICSORCHESTRATION
vManager
vManage
vSmart
vEdge
vBond
vBond
Data Center Campus Branch Home Office
Cisco SD-WAN Solution Elements
4G/LTE
MPLSInternet
vEdge Routers
vSmartvManage
Ubiquitous
Data Plane
Secure
Control Plane
Controllers
On-premise/cisco Cloud/
Partner Cloud
vBond
Cisco SD-WAN Solution
Transport Independent Fabric
CellularMPLSBroadband
Delivery Platform
QoS
Application Policies
Security
Per-Segment
Topologies
Segmentation Svc Insertion
Cloud
Path
Application
Visibility
& SLA
Secure
Perimeter
Traffic
Engineering
SurvivabilityRouting
Analytics
Monitoring
Operations
Transport
Hub
Multicast
Cloud
Accel
Zero-Trust Security Principles
DTLS/TLS
Control Tunnel
 Strong authentication
- PKI certificates, 2048bit keys
 Highly encrypted tunnels
- DTLS/TLS AES256
- White-list model
 Ubiquitous Deployment
- Automatic NAT mitigation
Control Elements
X.509 Certificate
Secure Bring-up With Approval
• Per-device control on TPM identity trust
• Single stage (Zero Touch Provisioning) – TPM identity is automatically trusted
• Two stage (One Touch Provisioning) – TPM identity is not automatically
trusted. Requires administrator validation.
• Staging Mode – TPM identity is automatically trusted for control, but not for
data. Requires administrator validation.
End to End Security
TransportsTransportsTransports
Site 1 Site 2
IPSec AES256-GCM
ESPv3 with HMAC SHA-1
vSmart
Controllers
Control Plane
DTLS/TLS
IPSec security
associations
IPSec security
associations
Update Update
 Symmetric encryption IPsec AES256-GCM
ESPv3 with HMAC SHA-1
 Traffic Encryption and Authentication Header
 Tunnel Liveliness Detection (BFD)
 Anti-Replay Protection
 Rekey 12 hours
 Each vEdge advertises its local
IPsec encryption key
Traffic Encrypted
with Key 2
Traffic Encrypted
with Key 1
vEdge
Router
vEdge
Router
Local
Remote Local
Remote
Configuration Simplicity and ZTP
• Templates are attached to provisioned
vEdge routers
• Variables are used for rapid bulk
configuration rollout with unique per-
device settings
• Local configuration changes are not
allowed
- Prevents configuration drift
Configuration Simplicity and ZTP
Zero Touch Bringup
Server
Control and Policy
Elements
Full Registration
and Configuration
vEdge Router
1 2
3 4 5
* Factory default config
Assumption:
 DHCP on Transport Side (WAN)
 DNS to resolve ztp.viptela.com*
 Authentication
 Push the configuration
 Enforce the version
Application Visibility
Secure
SD-WAN
Fabric
Deep Packet Inspection
Over 3000+ application
 App Firewall
 Traffic prioritization
 Transport selection
vEdge Router
App 1
App 2
App 3,000
Application Performances and AAR
Path1: 10ms, 0% loss, 2ms jitter
Path2: 200ms, 3% loss 5ms jitter
Path3: 140ms, 1% loss 3ms jitter
vSmart
Controllers
App Aware Routing Policy
App A path must have
latency <150ms and loss <2%
Path 2
 vEdge Routers continuously perform
path liveliness and quality
measurements Latency, Loss and Jitter,
 Auto Load Balance
Device QoS
(shaping, policing,
queuing, marking)
Internet
MPLS
4G LTE
Optimal Throughput
End to End Segmentation
Use Cases
 Security Zoning
 Compliance
 Guest WiFi
 Multi-Tenancy
 Extranet
Interface
VLAN
Prefix
TransportsTransports
Site 1
Site 2
Data Center
VPN
A
VPN
B
VPN
C
IPSec
20
IP
8
UDP
36
ESP
4
VPN
…
Data
Label
802.1q
802.1q
IF
IF
IF
IF
 Isolated virtual private networks across any
transport
 VPN mapping is based on physical vEdge Router
interface, 802.1Q VLAN tag or a mix of both
Per-Segment Topologies
Full Mesh Hub-and-Spoke Regional Hub
Unified Communications Data Center Applications Regional Internet/Services
Optimal Application Experience
Cloud onRamp for IaaS
Secure
SD-WAN
Fabric
How optimize Public cloud performance (SaaS)
Regional
internet exit
Branch with
local DMZ
Data
Center/DMZ
vFabric
httping probes
SaaS traffic primary
SaaS traffic backup
Score Color
8-10 GREEN
5-8 YELLOW
0-5 RED
Secure Internet Access
Secure
SD-WAN
Fabric
Branch
Campus
Regional
Data Center
Internet
& Cloud
Small Office
Home Office
Cisco
Security
Centralize Management & Monitoring
Centralize Configuration
• Security
• Template Configuration
• Policy
• Routing
• QoS, Marking
• ACL
• Application SLA
• …..
Centralize Monitoring
• Devices
• Application
• Bandwidth usage
• Link Performances
• Alerts
Analytics Dashboard
Visibility
• Application Visibility
• Network Visibility
• Network Co-relation
• Cross-Customer Comparison
Forecast
• Application Usage Forecast
• Bandwidth Usage Forecast
What-If
• Branch Expansions
• Rolling out new applications
• Policy changes
Recommendation
Self Healing Capabilities
Active Software
Available Software
Available Software
Available Software
A
B
C
D
Activate
Rollback
vEdge Router
1
2
3
Failed
Upgrade
vEdge Router
1
Attach Template
vManage
2
Connectivity
Lost
Rollback
3
High Availability and Redundancy
VRRP OSPF/
BGP
OSPF/
BGP
Internet InternetMPLSMPLS
Internet
MPLS
Site
Data
Center
MPLS
Internet
vSmart Controllers
Control
Data
vEdge Portfolio
vEdge capabilities integrated
into all IOS-XE platforms
(ISR, CSR, ENCS, ASR1K)
cloud
Interconnect
(2 Gbps +)
Small Office
Home Office
100 Mbps
Branch
Campus
1 Gbps
Large Campus
Data Center
10 Gbps
Higher Capacity
Aggregation
20 Gbps+
ISR4K
ASR1K
Private Cloud
ENCS
Why Cisco SD-WAN
Trusted by Fortune 500 Enterprises
Cisco SD-WAN: The Most-Deployed Enterprise Grade SD-WAN
Thousands of sites, every major industry, including:
RETAIL HEALTHCARE FINANCIAL SERVICES ENERGY
Most deployed and trusted by
Fortune 500 enterprises
Winning 95% of
competitive POCs
Standards Compliant: …and more
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

Ottawa e-NFV Session
Ottawa e-NFV Session Ottawa e-NFV Session
Ottawa e-NFV Session
 
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN Technology
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
Software Defined WAN – SD-WAN
Software Defined WAN – SD-WANSoftware Defined WAN – SD-WAN
Software Defined WAN – SD-WAN
 
Presentation NetScaler SD-WAN - David Gallo
Presentation NetScaler SD-WAN - David GalloPresentation NetScaler SD-WAN - David Gallo
Presentation NetScaler SD-WAN - David Gallo
 
Reducing Cost with DNA Automation
Reducing Cost with DNA AutomationReducing Cost with DNA Automation
Reducing Cost with DNA Automation
 
TechWiseTV Workshop: Cisco ISE 2.1 (Identity Services Engine)
TechWiseTV Workshop: Cisco ISE 2.1 (Identity Services Engine)TechWiseTV Workshop: Cisco ISE 2.1 (Identity Services Engine)
TechWiseTV Workshop: Cisco ISE 2.1 (Identity Services Engine)
 
Secure Your Network for Scale & the Cloud
Secure Your Network for Scale & the CloudSecure Your Network for Scale & the Cloud
Secure Your Network for Scale & the Cloud
 
TechWiseTV Workshop: Cisco Stealthwatch and ISE
TechWiseTV Workshop: Cisco Stealthwatch and ISETechWiseTV Workshop: Cisco Stealthwatch and ISE
TechWiseTV Workshop: Cisco Stealthwatch and ISE
 
Cisco Network Insider: Three Ways to Secure your Network
Cisco Network Insider: Three Ways to Secure your NetworkCisco Network Insider: Three Ways to Secure your Network
Cisco Network Insider: Three Ways to Secure your Network
 
CenturyLink SD-WAN Executive Brief -- Emily Pechal
CenturyLink SD-WAN Executive Brief -- Emily PechalCenturyLink SD-WAN Executive Brief -- Emily Pechal
CenturyLink SD-WAN Executive Brief -- Emily Pechal
 
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
 
CisCon 2018 - Overlay Management Protocol e IPsec
CisCon 2018 - Overlay Management Protocol e IPsecCisCon 2018 - Overlay Management Protocol e IPsec
CisCon 2018 - Overlay Management Protocol e IPsec
 
Meraki powered services bell
Meraki powered services   bellMeraki powered services   bell
Meraki powered services bell
 
Simplify WAN Deployment with the Cisco IWAN Application
Simplify WAN Deployment with the Cisco IWAN ApplicationSimplify WAN Deployment with the Cisco IWAN Application
Simplify WAN Deployment with the Cisco IWAN Application
 
Cisco SDWAN - Components Deployment Workflow
Cisco SDWAN - Components Deployment WorkflowCisco SDWAN - Components Deployment Workflow
Cisco SDWAN - Components Deployment Workflow
 
Moving Beyond the Router to a Thin-branch or Application-driven SD-WAN
Moving Beyond the Router to a Thin-branch or Application-driven SD-WANMoving Beyond the Router to a Thin-branch or Application-driven SD-WAN
Moving Beyond the Router to a Thin-branch or Application-driven SD-WAN
 
Cisco Connect Halifax 2018 Optimizing your client's wi-fi experience
Cisco Connect Halifax 2018   Optimizing your client's wi-fi experienceCisco Connect Halifax 2018   Optimizing your client's wi-fi experience
Cisco Connect Halifax 2018 Optimizing your client's wi-fi experience
 
Cisco Virtual Managed Services Solution
Cisco Virtual Managed Services SolutionCisco Virtual Managed Services Solution
Cisco Virtual Managed Services Solution
 

Semelhante a [Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive

cloudblanket_nms_ds_revb
cloudblanket_nms_ds_revbcloudblanket_nms_ds_revb
cloudblanket_nms_ds_revb
Ori Guez
 
CloudGenix_Customer Presentation
CloudGenix_Customer PresentationCloudGenix_Customer Presentation
CloudGenix_Customer Presentation
Syed Arsalan
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
ozkan01
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
nvirters
 
14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)
Jeff Green
 
Places in the network (featuring policy)
Places in the network (featuring policy)Places in the network (featuring policy)
Places in the network (featuring policy)
Jeff Green
 
Cross selling 5
Cross selling 5Cross selling 5
Cross selling 5
Sen Nathan
 

Semelhante a [Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive (20)

Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
cloudblanket_nms_ds_revb
cloudblanket_nms_ds_revbcloudblanket_nms_ds_revb
cloudblanket_nms_ds_revb
 
CloudGenix_Customer Presentation
CloudGenix_Customer PresentationCloudGenix_Customer Presentation
CloudGenix_Customer Presentation
 
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
[OpenStack Day in Korea 2015] Track 2-3 - 오픈스택 클라우드에 최적화된 네트워크 가상화 '누아지(Nuage)'
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
Digital Transformation Drives WAN Evolution
Digital Transformation Drives WAN EvolutionDigital Transformation Drives WAN Evolution
Digital Transformation Drives WAN Evolution
 
NSX, un salt natural cap a SDN
NSX, un salt natural cap a SDNNSX, un salt natural cap a SDN
NSX, un salt natural cap a SDN
 
Cisco Virtualized Network Services
Cisco Virtualized Network ServicesCisco Virtualized Network Services
Cisco Virtualized Network Services
 
14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
 
Motorola Wing 5.6 specification sheet
Motorola  Wing 5.6 specification sheetMotorola  Wing 5.6 specification sheet
Motorola Wing 5.6 specification sheet
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Building the SD-Branch using uCPE
Building the SD-Branch using uCPEBuilding the SD-Branch using uCPE
Building the SD-Branch using uCPE
 
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
 
ICC icXchange Solution Brochure
ICC icXchange Solution BrochureICC icXchange Solution Brochure
ICC icXchange Solution Brochure
 
VMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use casesVMware NSX for vSphere - Intro and use cases
VMware NSX for vSphere - Intro and use cases
 
Places in the network (featuring policy)
Places in the network (featuring policy)Places in the network (featuring policy)
Places in the network (featuring policy)
 
Cross selling 5
Cross selling 5Cross selling 5
Cross selling 5
 
Endüstriyel Router Çözümleri
Endüstriyel Router ÇözümleriEndüstriyel Router Çözümleri
Endüstriyel Router Çözümleri
 

Mais de Nur Shiqim Chok

[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
Nur Shiqim Chok
 
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
Nur Shiqim Chok
 
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
Nur Shiqim Chok
 
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
Nur Shiqim Chok
 
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
Nur Shiqim Chok
 

Mais de Nur Shiqim Chok (20)

[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss  hyper flex[Cisco Connect 2018 - Vietnam] Long ton dc pss  hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
 
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
 
[Cisco Connect 2018 - Vietnam] Joseph yap journey to the multi cloud
[Cisco Connect 2018 - Vietnam] Joseph yap journey to the multi cloud[Cisco Connect 2018 - Vietnam] Joseph yap journey to the multi cloud
[Cisco Connect 2018 - Vietnam] Joseph yap journey to the multi cloud
 
[Cisco Connect 2018 - Vietnam] Jeff chua hcm print - cisco connect 2018 (hc...
[Cisco Connect 2018 - Vietnam] Jeff chua   hcm print - cisco connect 2018 (hc...[Cisco Connect 2018 - Vietnam] Jeff chua   hcm print - cisco connect 2018 (hc...
[Cisco Connect 2018 - Vietnam] Jeff chua hcm print - cisco connect 2018 (hc...
 
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
 
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
 
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
 
Brink sanders cisco architecture keynote
Brink sanders   cisco architecture keynoteBrink sanders   cisco architecture keynote
Brink sanders cisco architecture keynote
 
[Cisco Connect 2018 - Vietnam] Brian cotaz cyber security strategy
[Cisco Connect 2018 - Vietnam] Brian cotaz   cyber security strategy [Cisco Connect 2018 - Vietnam] Brian cotaz   cyber security strategy
[Cisco Connect 2018 - Vietnam] Brian cotaz cyber security strategy
 
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
 
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
 
[Cisco Connect 2018 - Vietnam] 1. lam doan introducing cisco dna assurance-...
[Cisco Connect 2018 - Vietnam] 1. lam doan   introducing cisco dna assurance-...[Cisco Connect 2018 - Vietnam] 1. lam doan   introducing cisco dna assurance-...
[Cisco Connect 2018 - Vietnam] 1. lam doan introducing cisco dna assurance-...
 
[Cisco Connect 2018 - Vietnam] Vipul shah intel it transformation an imperat...
[Cisco Connect 2018 - Vietnam] Vipul shah  intel it transformation an imperat...[Cisco Connect 2018 - Vietnam] Vipul shah  intel it transformation an imperat...
[Cisco Connect 2018 - Vietnam] Vipul shah intel it transformation an imperat...
 
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
 
[Cisco Connect 2018 - Vietnam] Vib 30 min hcmc cisco connect 2018
[Cisco Connect 2018 - Vietnam] Vib 30 min hcmc cisco connect 2018[Cisco Connect 2018 - Vietnam] Vib 30 min hcmc cisco connect 2018
[Cisco Connect 2018 - Vietnam] Vib 30 min hcmc cisco connect 2018
 
[Cisco Connect 2018 - Vietnam] Yedu s. cisco cmx
[Cisco Connect 2018 - Vietnam] Yedu s.   cisco cmx[Cisco Connect 2018 - Vietnam] Yedu s.   cisco cmx
[Cisco Connect 2018 - Vietnam] Yedu s. cisco cmx
 
[Cisco Connect 2018 - Vietnam] Vib 15 min hn cisco connect 2018
[Cisco Connect 2018 - Vietnam] Vib 15 min hn cisco connect 2018[Cisco Connect 2018 - Vietnam] Vib 15 min hn cisco connect 2018
[Cisco Connect 2018 - Vietnam] Vib 15 min hn cisco connect 2018
 
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
 
[Cisco Connect 2018 - Vietnam] Thuy luong hcm welcome &amp; opening address
[Cisco Connect 2018 - Vietnam] Thuy luong hcm   welcome &amp; opening address[Cisco Connect 2018 - Vietnam] Thuy luong hcm   welcome &amp; opening address
[Cisco Connect 2018 - Vietnam] Thuy luong hcm welcome &amp; opening address
 
[Cisco Connect 2018 - Vietnam] Pauline hampshire vietnam cisco connect with...
[Cisco Connect 2018 - Vietnam] Pauline hampshire   vietnam cisco connect with...[Cisco Connect 2018 - Vietnam] Pauline hampshire   vietnam cisco connect with...
[Cisco Connect 2018 - Vietnam] Pauline hampshire vietnam cisco connect with...
 

Último

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Último (20)

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 

[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive

  • 1.
  • 2. Next-Gen Cisco SD-WAN Architecture Satit Adirek Technical Solution Architect Cisco Systems
  • 3. User and Application Landscape is Changing Change in App Content Change in App Delivery Change in App Consumption Rich, Dynamic, Web-Based Cloud, SaaS, Virtualized Mobile, Diverse devices Internet Edge Is Moving to the Branch Applications Are Moving to the Cloud INTERNET MPLS 4G DC vDC IaaS SaaS mobile branch guest head office
  • 4. Architectural Constrain SOFTWARE DEFINED: True separation of control, data and management CLOUD: Cloud hosted and delivered APPLICATION AWARE: Visibility & SLA business intent policy enforcement SCALE AND FLEXIBILITY: True enterprise scale SECURITY: Ingrained authentication, encryption, segmentation, access controls & service chaining OPEN: for automation, orchestration, best-of-breed integration Application Bandwidth Requirements Cloud Consumption Disjointed Security Simplified Operations WAN Flexibility Time To Capability Challenges Enabling Seamless transition from traditional WAN to SD WAN SECURE WAN FABRIC Broadband 4G/LTEMPLS ZERO TOUCH ZERO TRUST 1
  • 5. Traditional Networks  Control and Data Plane same devices  Peer-to-peer control plane  Routing protocol prorogate for all (N^2) complexity  Localize management  Complex to mnage  Not scalable  Impossible to support multiple transport
  • 6. 4G/LTE MPLS1Internet MPLS2 SD-WAN Principals • Separation Control and Data Plane • DTLS/TLS is used to establish the control channel • Control channel is established only with central controllers • No scaling issues are with full mesh of control plane • Control channel does not have to follow the data path
  • 7. Cisco SD-WAN Architecture Control Plane (Containers or VMs) Data Plane (Physical or Virtual) Management Plane (Multi-tenant or Dedicated) Orchestration Plane API 4GINTERNET MPLS vSmart ANALYTICSORCHESTRATION vManager vManage vSmart vEdge vBond vBond Data Center Campus Branch Home Office
  • 8. Cisco SD-WAN Solution Elements 4G/LTE MPLSInternet vEdge Routers vSmartvManage Ubiquitous Data Plane Secure Control Plane Controllers On-premise/cisco Cloud/ Partner Cloud vBond
  • 9. Cisco SD-WAN Solution Transport Independent Fabric CellularMPLSBroadband Delivery Platform QoS Application Policies Security Per-Segment Topologies Segmentation Svc Insertion Cloud Path Application Visibility & SLA Secure Perimeter Traffic Engineering SurvivabilityRouting Analytics Monitoring Operations Transport Hub Multicast Cloud Accel
  • 10. Zero-Trust Security Principles DTLS/TLS Control Tunnel  Strong authentication - PKI certificates, 2048bit keys  Highly encrypted tunnels - DTLS/TLS AES256 - White-list model  Ubiquitous Deployment - Automatic NAT mitigation Control Elements X.509 Certificate
  • 11. Secure Bring-up With Approval • Per-device control on TPM identity trust • Single stage (Zero Touch Provisioning) – TPM identity is automatically trusted • Two stage (One Touch Provisioning) – TPM identity is not automatically trusted. Requires administrator validation. • Staging Mode – TPM identity is automatically trusted for control, but not for data. Requires administrator validation.
  • 12. End to End Security TransportsTransportsTransports Site 1 Site 2 IPSec AES256-GCM ESPv3 with HMAC SHA-1 vSmart Controllers Control Plane DTLS/TLS IPSec security associations IPSec security associations Update Update  Symmetric encryption IPsec AES256-GCM ESPv3 with HMAC SHA-1  Traffic Encryption and Authentication Header  Tunnel Liveliness Detection (BFD)  Anti-Replay Protection  Rekey 12 hours  Each vEdge advertises its local IPsec encryption key Traffic Encrypted with Key 2 Traffic Encrypted with Key 1 vEdge Router vEdge Router Local Remote Local Remote
  • 13. Configuration Simplicity and ZTP • Templates are attached to provisioned vEdge routers • Variables are used for rapid bulk configuration rollout with unique per- device settings • Local configuration changes are not allowed - Prevents configuration drift
  • 14. Configuration Simplicity and ZTP Zero Touch Bringup Server Control and Policy Elements Full Registration and Configuration vEdge Router 1 2 3 4 5 * Factory default config Assumption:  DHCP on Transport Side (WAN)  DNS to resolve ztp.viptela.com*  Authentication  Push the configuration  Enforce the version
  • 15. Application Visibility Secure SD-WAN Fabric Deep Packet Inspection Over 3000+ application  App Firewall  Traffic prioritization  Transport selection vEdge Router App 1 App 2 App 3,000
  • 16. Application Performances and AAR Path1: 10ms, 0% loss, 2ms jitter Path2: 200ms, 3% loss 5ms jitter Path3: 140ms, 1% loss 3ms jitter vSmart Controllers App Aware Routing Policy App A path must have latency <150ms and loss <2% Path 2  vEdge Routers continuously perform path liveliness and quality measurements Latency, Loss and Jitter,  Auto Load Balance Device QoS (shaping, policing, queuing, marking) Internet MPLS 4G LTE Optimal Throughput
  • 17. End to End Segmentation Use Cases  Security Zoning  Compliance  Guest WiFi  Multi-Tenancy  Extranet Interface VLAN Prefix TransportsTransports Site 1 Site 2 Data Center VPN A VPN B VPN C IPSec 20 IP 8 UDP 36 ESP 4 VPN … Data Label 802.1q 802.1q IF IF IF IF  Isolated virtual private networks across any transport  VPN mapping is based on physical vEdge Router interface, 802.1Q VLAN tag or a mix of both
  • 18. Per-Segment Topologies Full Mesh Hub-and-Spoke Regional Hub Unified Communications Data Center Applications Regional Internet/Services Optimal Application Experience
  • 19. Cloud onRamp for IaaS Secure SD-WAN Fabric
  • 20. How optimize Public cloud performance (SaaS) Regional internet exit Branch with local DMZ Data Center/DMZ vFabric httping probes SaaS traffic primary SaaS traffic backup Score Color 8-10 GREEN 5-8 YELLOW 0-5 RED
  • 21. Secure Internet Access Secure SD-WAN Fabric Branch Campus Regional Data Center Internet & Cloud Small Office Home Office Cisco Security
  • 22. Centralize Management & Monitoring Centralize Configuration • Security • Template Configuration • Policy • Routing • QoS, Marking • ACL • Application SLA • ….. Centralize Monitoring • Devices • Application • Bandwidth usage • Link Performances • Alerts
  • 23. Analytics Dashboard Visibility • Application Visibility • Network Visibility • Network Co-relation • Cross-Customer Comparison Forecast • Application Usage Forecast • Bandwidth Usage Forecast What-If • Branch Expansions • Rolling out new applications • Policy changes Recommendation
  • 24. Self Healing Capabilities Active Software Available Software Available Software Available Software A B C D Activate Rollback vEdge Router 1 2 3 Failed Upgrade vEdge Router 1 Attach Template vManage 2 Connectivity Lost Rollback 3
  • 25. High Availability and Redundancy VRRP OSPF/ BGP OSPF/ BGP Internet InternetMPLSMPLS Internet MPLS Site Data Center MPLS Internet vSmart Controllers Control Data
  • 26. vEdge Portfolio vEdge capabilities integrated into all IOS-XE platforms (ISR, CSR, ENCS, ASR1K) cloud Interconnect (2 Gbps +) Small Office Home Office 100 Mbps Branch Campus 1 Gbps Large Campus Data Center 10 Gbps Higher Capacity Aggregation 20 Gbps+ ISR4K ASR1K Private Cloud ENCS
  • 27. Why Cisco SD-WAN Trusted by Fortune 500 Enterprises Cisco SD-WAN: The Most-Deployed Enterprise Grade SD-WAN Thousands of sites, every major industry, including: RETAIL HEALTHCARE FINANCIAL SERVICES ENERGY Most deployed and trusted by Fortune 500 enterprises Winning 95% of competitive POCs Standards Compliant: …and more

Notas do Editor

  1. Cisco SD-WAN provide Multi transport Network Over disjoin network - Separation of the control plane Application visibility over 3000+ application Limited scale them of thousand  Reduce the WAN cost Direct access to cloud and improve the performances  Simplify the operation
  2. Disjoined Network No application visibility Limited scale  Insufficient BW WAN cost No direct access to cloud app Hybrid  Fragment Security Complex Operations
  3. Component – vEdge Router (Hardware / Software), Control Component (software Support – smaller branch, Large Datacenter, Public and Private cloud Controller can be deployed – Viptela / Private / On Premise Transport Independent Fabric Create Secure data plane connection between the vEdge and controllers Only control information send to the controller vManage for Management and monitoring. Rest full APIS
  4. Transport Independent Fabric Can connect multiple transport to Single router Simplify the deployment using Zero Touch Zero trust All connation are A/A Eliminate WAN side routing Delivery Platform (Routing) Full Router, Full BGP and OSPF (VRF) Segmentation Full QoS and Shaping Multicast Traffic redirection (Svc Insertions) High Availability (AS/AP) Replace the router and simplify the Network Application & Policies DPI and Application Visibility, Application SLA base policy (best path base on the underline network performances) Traffic engineering Segmentation based topology Secure internet gateway SaaS and IaaS path selection and acceleration Operation, Monitoring and Analytics Complete configuration and Management No Configuration in Edge Device 5 min revert, 8 min revert for upgrade
  5. Optimal Throughput – MTU discovery
  6. Largest Deployed in Retail, Healthcare, Financial Services and Energy Most deployed across Fortune-500 Enterprises Thousands of production sites in every major industry Compliant with PCI, HIPAA and other industry standards 1. Sophistication of Use cases for the Enterprise - hybrid wan, business partners, soho, cloud, M&A etc 2. Most deployed and trusted SDWAN solution by Fortune 500