SlideShare uma empresa Scribd logo
1 de 51
Baixar para ler offline
David Klebanov, Manager, Technical Marketing
Nikolai Pitaev, Engineer, Technical Marketing
Delivering Cisco Next Generation
SD-WAN with Viptela
BRKCRS-2110
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
“What’s in it for me?"
In This Session Out Of Scope
Introduction, design and building
blocks
Detailed explanation how it
technically works “under the hood”
Use cases, operations and security Troubleshooting and debugging
Live Demo during the session Step-by-step migration to SD-WAN
Target audience is technical attendees looking for overview and basic
understanding of the Cisco SD-WAN solution powered by Viptela
BRKCRS-2110 3
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why should I care?
Real life examples
• 80 percent reduction in cost/Mbps for a US insurance provider
• $20 million reduction in OpEx over three years for a retailer
• 5-fold improvement in Office 365 performance for an energy provider
• 4-fold improvement in application latency for a healthcare provider
• M&A integration in 2 weeks for a Fortune 50 healthcare provider
• Securely isolated 100+ business partners for a US manufacturer with
more than 1,000 sites
BRKCRS-2110 4
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Key Message of Our Presentation
Cisco SD-WAN Solution helps you to:
1. Reduce Cost
2. Operate Faster with better Performance and Security
3. Integrate Latest Cloud and Network Technologies
BRKCRS-2110 5
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
• Introduction: Why SD-WAN? Which SD-WAN?
• SD-WAN Architecture and Main Components
• SD-WAN Fabric
• Common Enterprise Deployment Use Cases
• SD-WAN Migration
• Live Demonstration
• Conclusion: Outlook and Summary
Agenda
BRKCRS-2110 6
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco WebEx Teams
Questions?
Use Cisco WebEx Teams (formerly Cisco Spark)
to chat with the speaker after the session
Find this session in the Cisco Events Mobile App
Click “Join the Discussion”
Install WebEx Teams or go directly to the team space
Enter messages/questions in the team space
How
1
2
3
4
cs.co/ciscolivebot#BRKCSR-2110
BRKCRS-2110 7
Introduction
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
The WAN Has Changed
Data
Center
Multi-
Cloud
SaaS
Internet
SAAS
Branch
WAN
Users
Devices
Things
INET
MPLS
Users Internet
MPLS
Branch WAN
Data Center
BRKCRS-2110 9
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Traditional and Legacy Architectures
EXPENSIVE
Hardware-centric
Fixed capacity
DIFFICULT TO SUPPORT
Discrete device-by-device
configurations
Complex management silos
Require slow truck
rolls for changes
INFLEXIBLE
Tightly controlled, client server model
Historical vs predictive management
CONNECTIVITY-CENTRIC
Fragmented, incomplete user experience
Not application-centric
POORLY INTEGRATED
Conflicting policies
and configurations
Inflexible and static
Risk from accidental
interactions and vulnerabilities
Cannot Scale to Address Changing Needs
BRKCRS-2110 10
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco SD-WAN Portfolio
SD-WAN
Powered By
Full stack branch
management for Lean IT
Flexible and sophisticated
with secure segmentation
and advanced routing
Viptela
Powered By
BRKCRS-2110 11
SD-WAN Architecture
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco SD-WAN Architecture Overview
Data Center Campus Branch SOHO
4G/LTE
MPLS
Internet
Control Plane = vSmart
(Containers or VMs)
Data Plane = Edge
(vEdge, Cisco ISR/ASR/ENCS,
Whitebox)
Management = vManage
(Multi-tenant or Dedicated)
Orchestration = vBond
vManage
vSmart
WAN Edge
Orchestrator ZTP/PnP
APIs
Cloud
vAnalytics
BRKCRS-2110 13
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
vBond is SD-WAN Orchestrator
• Orchestrates connectivity between
management, control and data plane
• Serves as the first point of authentication
• Requires public IP Address
• All other components need to know the
vBond IP or FQDN
• Authorizes all control connections
(white-list model)
BRKCRS-2110 14
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
vManage is NMS for SD-WAN
• Single-tenant or Multitenant
• Single pane of glass for Day 0, Day 1 and
Day 2 operations
• Enables centralized provisioning and
simplifies changes
• Supports REST API, CLI, Syslog, SNMP,
NETCONF
• Provides real time alerting
• Role Based Access Control
BRKCRS-2110 15
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
vSmart is Centralized Control Plane
• Implements control plane policies, such
as service chaining, traffic engineering
and per-VPN topology
• Reduces complexity of the entire
network
• Establishes peering with all WAN Edges,
distributes connectivity and security
context
BRKCRS-2110 16
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Controllers’ Deployment Models
Enterprise IT
vManage
vSmart vBond
Private
Cloud
Deploy
MSP Ops Team
vManage
vSmart vBond
MSP
Cloud
Deploy
Cisco Cloud Ops
vManage
vSmart vBond
Cisco
Cloud
Deploy
BRKCRS-2110 17
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Controller Scale
vManage:
• Validated Scale: 2,000 Devices per-single instance
• Max Production Deployment: 6 vManage instances in a cluster
vSmart:
• Validated Scale: 5,400 Connections per-single vSmart
• Max Production Deployment: 20 vSmarts
vBond:
• Validated Scale: 1,500 Connections per-single vBond
• Max Production Deployment: 6 vBonds
BRKCRS-2110 18
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
WAN Edge is your SD-WAN Data Plane
• Provides secure data plane with remote
WAN Edge routers
• Establishes secure control plane with
vSmart controllers
• Implements data plane and application
aware routing policies
• Exports performance statistics
• Physical or Virtual form factor
BRKCRS-2110 19
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco SD-WAN Platform Options
vEdge 2000
10 Gbps
Modular
vEdge 1000
1 Gbps
Fixed
vEdge 100
100 Mbps
4G LTE & WiFi
Pureplay SD-WAN
20+ Gbps, Modular
vEdge 5000
Virtualization
ENCS 5100 ENCS 5400
ISR 1000 ISR 4000 ASR 1000
High-
performance
with redundancy
Modular
Integrated
services
SD-WAN with Services
Next-gen
Performance
Flexibility
Public and Private Clouds
BRKCRS-2110 20
SD-WAN Fabric
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Unified Control Plane
• Overlay Management Protocol (OMP)
• TCP based extensible control plane protocol
• Runs between WAN Edge routers and vSmart
controllers and between the vSmart controllers
- Inside authenticated TLS/DTLS connections
• Advertises control plane context and policies
• Dramatically lowers control plane complexity and
raises overall solution scale
vSmart vSmart
vSmart
WAN Edge WAN Edge
Note: WAN Edge routers need not connect to all vSmart Controllers
VS
SD-WAN Traditional
O(n) Control Complexity O(n^2) Control Complexity
BRKCRS-2110 22
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Data Plane Establishment
OMP IPSec Tunnel
WAN Edge
WAN Edge
WAN Edge
WAN Edge
WAN Edge
vSmart
Local Routes
- Local prefixes (OSPF/BGP)
- SD-WAN tunnel endpoints (TLOCs)
Security Context
- IPSec Encryption Keys
Routes and encryption keys
are advertised to vSmarts in
OMP updates
vSmarts advertise routes and
encryption keys to WAN
Edges in OMP updates
SD-WAN fabric
between tunnel
endpoints
INET
MPLS
Transport Locator (TLOC)
IPsec
IPsec
IPsec
Fabric Routing:
<prefix> via
BRKCRS-2110 23
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Data Plane Liveliness and Quality
WAN Edge WAN Edge
WAN Edge
WAN Edge WAN Edge
• Bidirectional Forwarding Detection (BFD)
• Path liveliness and quality measurement
- Up/Down, loss/latency/jitter, IPSec tunnel MTU
• Runs between all WAN Edge routers in the topology
- Inside SD-WAN tunnels
- Across all transports
- Operates in echo mode
- Automatically invoked at SD-WAN tunnel
establishment
- Cannot be disabled
• Uses hello (up/down) interval, poll (app-aware)
interval and multiplier for detection
- Fully customizable per-WAN Edge, per-transport
BRKCRS-2110 24
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Common Data Plane Communication
Per-Session Load Sharing
Active/Active
INET
MPLS
Default
Per-Session Weighted
Active/Active
INET
MPLS
Device
Configurable
Application Pinning
Active/Standby
INET
MPLS
Policy
Enforced
Application Aware Routing
SLA Compliant
INET
MPLS
SLA SLA
Policy
Enforced
BRKCRS-2110 25
Common Enterprise
Deployment Use Cases
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Common Enterprise Deployment Use Cases
Critical Application SLA
MultiCloud onRamp for SaaS and IaaS
Secure Branch
BRKCRS-2110 27
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Critical Applications SLA
Sender Receiver
1 2
3 4
5 6
7 8
XOR
1 2
3 4
P
XOR
1 2
3
4
P
FEC Header
SD- WAN Tunnel
• Protects against packet loss
• Protocol (TCP/UDP) agnostic
• Supports multiple transports
• Can be invoked dynamically
Forward Error
Correction (FEC)
1 2
3 4
SD- WAN Tunnel
SD- WAN Tunnel
Sender Receiver
1
1
2
2
3
3
4
4
D
D
D
D
1 2
3 4
• Protects against packet loss
• Protocol (TCP/UDP) agnostic
• Operates over multiple transports
Packet
Duplication
Application Aware
Routing
BRKCRS-2110 28
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Secure Branch - Segmentation
 Security Zoning
 Compliance
 Guest Wi-Fi
 Multi-Tenancy
 Extranet
Full-Mesh Hub-and-Spoke Partial Mesh Point-to-Point
Per-VPN Topology
WAN Edge
VPN 3
VPN 1
VPN 2
SD-WAN
IPSec
Tunnel
WAN
Edge
BRKCRS-2110 29
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Secure Branch – SD-WAN Security
Cloud
Applications
AMP in 2019
Direct Cloud Access
Guest
Employee
Use Case:
Guest Services
Use Case:
Industry Compliance
Use case:
Cloud and DIA
Data Center
Applications
SD-WAN
vManage
DNS/web
layer security
Firewall IPS
Firewall IPS Firewall URL
Filtering
BRKCRS-2110 30
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Traditional Cloud Applications Access
Remote Site
Users
Wide Area
Network
Data Center
BRKCRS-2110 31
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Traditional Cloud Applications Access
Remote Site
Users
Wide Area
Network
• Data Center backhaul
• Increased application latency
• Unpredictable user experience
Data Center
BRKCRS-2110 31
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
MultiCloud onRamp for SaaS
Quality Probing
Remote Site
ISP2
ISP1
Loss/
Latency
!
Regional
Hub/CoLo/DC
Remote Site
SD-WAN
Fabric
ISP1
Loss/
Latency
MPLS
ISP2
!
BRKCRS-2110 33
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Traditional IaaS Access
Wide Area
Network
VNET VNET
VNET VNET
VPC VPC
VPC VPC
Remote Site CNF/CoLo
Data Center IPsec
IPsec
IPsec
AWS Direct
Connect
Azure Express
Route
• No Direct to Cloud access
• Limited segmentation and QoS
• Dependent on underlying technology
BRKCRS-2110 34
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
MultiCloud onRamp for IaaS
Remote Site
SD-WAN
Fabric
Branch
Campus
Cloud
Data Center
Compute
VPC/VNET
Compute
VPC/VNET
Using Marketplace (DIY)
Remote Site
SD-WAN
Fabric
Branch
Campus
Cloud
Data Center
Compute
VPCs/VNETs
Gateway
VPC/VNET
Fully Automated
BRKCRS-2110 35
SD-WAN Migration
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Migration Sequence
Controllers Datacenters Branches
vManage
vSmart vBond Branch Campus
Data Center
A
SOHO
Data Center
B
BRKCRS-2110 37
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Data Center Migration
CE
Data Center Core
Perimeter
Firewall
MPLS INET
To/From
Non-SDWAN
WAN
Edge
Traditional Site
SD-WAN Site
Data Center
BRKCRS-2110 38
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Branch Migration with IOS-XE SDWAN
MPLS INET
Router
L2 HSRP
OSPF/BGP
Router
Traditional
MPLS INET
L2 VRRP
OSPF/BGP
WAN Edge
SD-WAN
L3 Switch L3 Switch
WAN Edge
BRKCRS-2110 39
Live Demo
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Demo: Network Design
10 clicks to deploy
simple SD-WAN
network.
One page to see your
entire WAN topology.
Like “Visio canvas” in
vManage.
BRKCRS-2110 41
Conclusion
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Call To Action
SD-WAN on IOS XE Routers:
• Read the White Paper SD-WAN on IOS XE: End-to-End View
• Watch the Migration YouTube Video
Get your hands dirty:
• Complete dCloud SD-WAN Lab “Cisco 4D SD-WAN (Viptela) v2”
BRKCRS-2110 43
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Monday Tuesday Wednesday Thursday Friday
TECCRS-2014
Deep Dive
TECSEC-2355
Security
TECCRS-2191
Deployment / BCP
Your SD-WAN learning map at CLEUR
44
BRKCRS-2110
BRKCRS-2110
The Foundation
BRKCRS-2111
Migration
BRKCRS-2112
Serviceability
BRKRST-2560
Analytics / ML
BRKCRS-2114
Security
BRKRST-2558
SD-WAN as a
Managed Service
BRKRST-2559
On-prem
Deployment
BRKCRS-2113
Cloud onRamp
BRKCRS-2117
Design
Deployment
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Key Message of Our Presentation
Cisco SD-WAN Solution helps you to:
1. Reduce Cost
2. Operate Faster with better Performance and Security
3. Integrate Latest Cloud and Network Technologies
BRKCRS-2110 45
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Proven Solution Across Multiple Verticals
Customer Industry Challenge Solution
Retail
High cost, slow change, limited
flexibility
60-70% cheaper broadband at high bandwidth,
centralized control, full visibility.
Financial
Needed more bandwidth and
guaranteed network uptime for a new
teller application
Dollar cost averaged the bandwidth cost down using a
mix of transport (MPLS, Broadband, LTE). Traffic now
uses the optimal network path to avoid downtime and
slowdowns.
Tech
Slow performance and MPLS outages
provided an expensive and poor user
experience
Monthly savings reduced the cost per Mbps by more
than 80%. Diverse circuits improve the reliability of the
global network, with more than half of Agilent’s sites
doubling WAN redundancy.
Healthcare
With an MPLS contract renewal
approaching, Cigna wanted the
flexibility to change carriers without a
massive technology shift
Gained back control of its control plane and created the
Cigna Service Provider Agnostic Network.
Healthcare Security and high network cost
Satisfied strict security and audit requirements and
provided greater flexibility for partnerships and secure
clinical solutions. Cost reductions with the removal of
remote site voice equipment and expensive PRIs, aging
WAN acceleration equipment and maintenance.
Energy
Scale to support evolving field
operations, and support cloud
migration and application SLAs
Provided 30-60% savings in overall bandwidth costs.
Enabled faster response to acquisitions, divestitures and
policy changes.
For Your
Reference
BRKCRS-2110 46
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco WebEx Teams
Questions?
Use Cisco WebEx Teams (formerly Cisco Spark)
to chat with the speaker after the session
Find this session in the Cisco Events Mobile App
Click “Join the Discussion”
Install WebEx Teams or go directly to the team space
Enter messages/questions in the team space
How
1
2
3
4
BRKCRS-2110 47
cs.co/ciscolivebot#BRKCRS-2110
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Don’t forget: Cisco Live sessions will be available for viewing
on demand after the event at ciscolive.cisco.com
• Please complete your Online Session
Survey after each session
• Complete 4 Session Surveys & the Overall
Conference Survey (available from
Thursday) to receive your Cisco Live T-
shirt
• All surveys can be completed via the Cisco
Events Mobile App or the Communication
Stations
Complete your online
session survey
BRKCRS-2110 48
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Demos in
the Cisco
Showcase
Walk-in
self-paced
labs
Meet the
engineer
1:1
meetings
Related
sessions
Continue Your Education
BRKCRS-2110 49
Thank you
BRKCRS-2110.pdf

Mais conteúdo relacionado

Semelhante a BRKCRS-2110.pdf

Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionCisco Canada
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network EvolutionCisco Canada
 
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Canada
 
presentacion comercial de CISCO UCS
presentacion comercial de CISCO UCSpresentacion comercial de CISCO UCS
presentacion comercial de CISCO UCSdnarvarte2
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Cisco Russia
 
Cisco storage networking protect scale-simplify_dec_2016
Cisco storage networking   protect scale-simplify_dec_2016Cisco storage networking   protect scale-simplify_dec_2016
Cisco storage networking protect scale-simplify_dec_2016Tony Antony
 
Security & Virtualization in the Data Center
Security & Virtualization in the Data CenterSecurity & Virtualization in the Data Center
Security & Virtualization in the Data CenterCisco Russia
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaCisco Canada
 
Presentation cloud orchestration
Presentation   cloud orchestrationPresentation   cloud orchestration
Presentation cloud orchestrationxKinAnx
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyCisco Canada
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingCisco Canada
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformationCisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformationNetworkCollaborators
 
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdfBRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdfHarryH11
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Canada
 
#NSD14 - Sécuriser l'infrastructure réseau des datacenters
#NSD14 - Sécuriser l'infrastructure réseau des datacenters#NSD14 - Sécuriser l'infrastructure réseau des datacenters
#NSD14 - Sécuriser l'infrastructure réseau des datacentersNetSecure Day
 
Cisco mds 9000 series software license packages
Cisco mds 9000 series software license packagesCisco mds 9000 series software license packages
Cisco mds 9000 series software license packagesIT Tech
 
Framework for the New IP - Phil O'Reilly
Framework for the New IP - Phil O'ReillyFramework for the New IP - Phil O'Reilly
Framework for the New IP - Phil O'Reillyscoopnewsgroup
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 

Semelhante a BRKCRS-2110.pdf (20)

Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
 
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
 
presentacion comercial de CISCO UCS
presentacion comercial de CISCO UCSpresentacion comercial de CISCO UCS
presentacion comercial de CISCO UCS
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 
Cisco storage networking protect scale-simplify_dec_2016
Cisco storage networking   protect scale-simplify_dec_2016Cisco storage networking   protect scale-simplify_dec_2016
Cisco storage networking protect scale-simplify_dec_2016
 
Security & Virtualization in the Data Center
Security & Virtualization in the Data CenterSecurity & Virtualization in the Data Center
Security & Virtualization in the Data Center
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Presentation cloud orchestration
Presentation   cloud orchestrationPresentation   cloud orchestration
Presentation cloud orchestration
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN Technology
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC Networking
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformationCisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
 
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdfBRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
 
UCS Presentation
UCS PresentationUCS Presentation
UCS Presentation
 
#NSD14 - Sécuriser l'infrastructure réseau des datacenters
#NSD14 - Sécuriser l'infrastructure réseau des datacenters#NSD14 - Sécuriser l'infrastructure réseau des datacenters
#NSD14 - Sécuriser l'infrastructure réseau des datacenters
 
Cisco mds 9000 series software license packages
Cisco mds 9000 series software license packagesCisco mds 9000 series software license packages
Cisco mds 9000 series software license packages
 
Framework for the New IP - Phil O'Reilly
Framework for the New IP - Phil O'ReillyFramework for the New IP - Phil O'Reilly
Framework for the New IP - Phil O'Reilly
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 

Último

Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 

Último (20)

Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 

BRKCRS-2110.pdf

  • 1.
  • 2. David Klebanov, Manager, Technical Marketing Nikolai Pitaev, Engineer, Technical Marketing Delivering Cisco Next Generation SD-WAN with Viptela BRKCRS-2110
  • 3. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public “What’s in it for me?" In This Session Out Of Scope Introduction, design and building blocks Detailed explanation how it technically works “under the hood” Use cases, operations and security Troubleshooting and debugging Live Demo during the session Step-by-step migration to SD-WAN Target audience is technical attendees looking for overview and basic understanding of the Cisco SD-WAN solution powered by Viptela BRKCRS-2110 3
  • 4. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Why should I care? Real life examples • 80 percent reduction in cost/Mbps for a US insurance provider • $20 million reduction in OpEx over three years for a retailer • 5-fold improvement in Office 365 performance for an energy provider • 4-fold improvement in application latency for a healthcare provider • M&A integration in 2 weeks for a Fortune 50 healthcare provider • Securely isolated 100+ business partners for a US manufacturer with more than 1,000 sites BRKCRS-2110 4
  • 5. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Key Message of Our Presentation Cisco SD-WAN Solution helps you to: 1. Reduce Cost 2. Operate Faster with better Performance and Security 3. Integrate Latest Cloud and Network Technologies BRKCRS-2110 5
  • 6. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public • Introduction: Why SD-WAN? Which SD-WAN? • SD-WAN Architecture and Main Components • SD-WAN Fabric • Common Enterprise Deployment Use Cases • SD-WAN Migration • Live Demonstration • Conclusion: Outlook and Summary Agenda BRKCRS-2110 6
  • 7. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Cisco WebEx Teams Questions? Use Cisco WebEx Teams (formerly Cisco Spark) to chat with the speaker after the session Find this session in the Cisco Events Mobile App Click “Join the Discussion” Install WebEx Teams or go directly to the team space Enter messages/questions in the team space How 1 2 3 4 cs.co/ciscolivebot#BRKCSR-2110 BRKCRS-2110 7
  • 9. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public The WAN Has Changed Data Center Multi- Cloud SaaS Internet SAAS Branch WAN Users Devices Things INET MPLS Users Internet MPLS Branch WAN Data Center BRKCRS-2110 9
  • 10. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Traditional and Legacy Architectures EXPENSIVE Hardware-centric Fixed capacity DIFFICULT TO SUPPORT Discrete device-by-device configurations Complex management silos Require slow truck rolls for changes INFLEXIBLE Tightly controlled, client server model Historical vs predictive management CONNECTIVITY-CENTRIC Fragmented, incomplete user experience Not application-centric POORLY INTEGRATED Conflicting policies and configurations Inflexible and static Risk from accidental interactions and vulnerabilities Cannot Scale to Address Changing Needs BRKCRS-2110 10
  • 11. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Cisco SD-WAN Portfolio SD-WAN Powered By Full stack branch management for Lean IT Flexible and sophisticated with secure segmentation and advanced routing Viptela Powered By BRKCRS-2110 11
  • 13. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Cisco SD-WAN Architecture Overview Data Center Campus Branch SOHO 4G/LTE MPLS Internet Control Plane = vSmart (Containers or VMs) Data Plane = Edge (vEdge, Cisco ISR/ASR/ENCS, Whitebox) Management = vManage (Multi-tenant or Dedicated) Orchestration = vBond vManage vSmart WAN Edge Orchestrator ZTP/PnP APIs Cloud vAnalytics BRKCRS-2110 13
  • 14. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public vBond is SD-WAN Orchestrator • Orchestrates connectivity between management, control and data plane • Serves as the first point of authentication • Requires public IP Address • All other components need to know the vBond IP or FQDN • Authorizes all control connections (white-list model) BRKCRS-2110 14
  • 15. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public vManage is NMS for SD-WAN • Single-tenant or Multitenant • Single pane of glass for Day 0, Day 1 and Day 2 operations • Enables centralized provisioning and simplifies changes • Supports REST API, CLI, Syslog, SNMP, NETCONF • Provides real time alerting • Role Based Access Control BRKCRS-2110 15
  • 16. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public vSmart is Centralized Control Plane • Implements control plane policies, such as service chaining, traffic engineering and per-VPN topology • Reduces complexity of the entire network • Establishes peering with all WAN Edges, distributes connectivity and security context BRKCRS-2110 16
  • 17. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Controllers’ Deployment Models Enterprise IT vManage vSmart vBond Private Cloud Deploy MSP Ops Team vManage vSmart vBond MSP Cloud Deploy Cisco Cloud Ops vManage vSmart vBond Cisco Cloud Deploy BRKCRS-2110 17
  • 18. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Controller Scale vManage: • Validated Scale: 2,000 Devices per-single instance • Max Production Deployment: 6 vManage instances in a cluster vSmart: • Validated Scale: 5,400 Connections per-single vSmart • Max Production Deployment: 20 vSmarts vBond: • Validated Scale: 1,500 Connections per-single vBond • Max Production Deployment: 6 vBonds BRKCRS-2110 18
  • 19. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public WAN Edge is your SD-WAN Data Plane • Provides secure data plane with remote WAN Edge routers • Establishes secure control plane with vSmart controllers • Implements data plane and application aware routing policies • Exports performance statistics • Physical or Virtual form factor BRKCRS-2110 19
  • 20. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Cisco SD-WAN Platform Options vEdge 2000 10 Gbps Modular vEdge 1000 1 Gbps Fixed vEdge 100 100 Mbps 4G LTE & WiFi Pureplay SD-WAN 20+ Gbps, Modular vEdge 5000 Virtualization ENCS 5100 ENCS 5400 ISR 1000 ISR 4000 ASR 1000 High- performance with redundancy Modular Integrated services SD-WAN with Services Next-gen Performance Flexibility Public and Private Clouds BRKCRS-2110 20
  • 22. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Unified Control Plane • Overlay Management Protocol (OMP) • TCP based extensible control plane protocol • Runs between WAN Edge routers and vSmart controllers and between the vSmart controllers - Inside authenticated TLS/DTLS connections • Advertises control plane context and policies • Dramatically lowers control plane complexity and raises overall solution scale vSmart vSmart vSmart WAN Edge WAN Edge Note: WAN Edge routers need not connect to all vSmart Controllers VS SD-WAN Traditional O(n) Control Complexity O(n^2) Control Complexity BRKCRS-2110 22
  • 23. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Data Plane Establishment OMP IPSec Tunnel WAN Edge WAN Edge WAN Edge WAN Edge WAN Edge vSmart Local Routes - Local prefixes (OSPF/BGP) - SD-WAN tunnel endpoints (TLOCs) Security Context - IPSec Encryption Keys Routes and encryption keys are advertised to vSmarts in OMP updates vSmarts advertise routes and encryption keys to WAN Edges in OMP updates SD-WAN fabric between tunnel endpoints INET MPLS Transport Locator (TLOC) IPsec IPsec IPsec Fabric Routing: <prefix> via BRKCRS-2110 23
  • 24. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Data Plane Liveliness and Quality WAN Edge WAN Edge WAN Edge WAN Edge WAN Edge • Bidirectional Forwarding Detection (BFD) • Path liveliness and quality measurement - Up/Down, loss/latency/jitter, IPSec tunnel MTU • Runs between all WAN Edge routers in the topology - Inside SD-WAN tunnels - Across all transports - Operates in echo mode - Automatically invoked at SD-WAN tunnel establishment - Cannot be disabled • Uses hello (up/down) interval, poll (app-aware) interval and multiplier for detection - Fully customizable per-WAN Edge, per-transport BRKCRS-2110 24
  • 25. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Common Data Plane Communication Per-Session Load Sharing Active/Active INET MPLS Default Per-Session Weighted Active/Active INET MPLS Device Configurable Application Pinning Active/Standby INET MPLS Policy Enforced Application Aware Routing SLA Compliant INET MPLS SLA SLA Policy Enforced BRKCRS-2110 25
  • 27. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Common Enterprise Deployment Use Cases Critical Application SLA MultiCloud onRamp for SaaS and IaaS Secure Branch BRKCRS-2110 27
  • 28. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Critical Applications SLA Sender Receiver 1 2 3 4 5 6 7 8 XOR 1 2 3 4 P XOR 1 2 3 4 P FEC Header SD- WAN Tunnel • Protects against packet loss • Protocol (TCP/UDP) agnostic • Supports multiple transports • Can be invoked dynamically Forward Error Correction (FEC) 1 2 3 4 SD- WAN Tunnel SD- WAN Tunnel Sender Receiver 1 1 2 2 3 3 4 4 D D D D 1 2 3 4 • Protects against packet loss • Protocol (TCP/UDP) agnostic • Operates over multiple transports Packet Duplication Application Aware Routing BRKCRS-2110 28
  • 29. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Secure Branch - Segmentation  Security Zoning  Compliance  Guest Wi-Fi  Multi-Tenancy  Extranet Full-Mesh Hub-and-Spoke Partial Mesh Point-to-Point Per-VPN Topology WAN Edge VPN 3 VPN 1 VPN 2 SD-WAN IPSec Tunnel WAN Edge BRKCRS-2110 29
  • 30. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Secure Branch – SD-WAN Security Cloud Applications AMP in 2019 Direct Cloud Access Guest Employee Use Case: Guest Services Use Case: Industry Compliance Use case: Cloud and DIA Data Center Applications SD-WAN vManage DNS/web layer security Firewall IPS Firewall IPS Firewall URL Filtering BRKCRS-2110 30
  • 31. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Traditional Cloud Applications Access Remote Site Users Wide Area Network Data Center BRKCRS-2110 31
  • 32. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Traditional Cloud Applications Access Remote Site Users Wide Area Network • Data Center backhaul • Increased application latency • Unpredictable user experience Data Center BRKCRS-2110 31
  • 33. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public MultiCloud onRamp for SaaS Quality Probing Remote Site ISP2 ISP1 Loss/ Latency ! Regional Hub/CoLo/DC Remote Site SD-WAN Fabric ISP1 Loss/ Latency MPLS ISP2 ! BRKCRS-2110 33
  • 34. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Traditional IaaS Access Wide Area Network VNET VNET VNET VNET VPC VPC VPC VPC Remote Site CNF/CoLo Data Center IPsec IPsec IPsec AWS Direct Connect Azure Express Route • No Direct to Cloud access • Limited segmentation and QoS • Dependent on underlying technology BRKCRS-2110 34
  • 35. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public MultiCloud onRamp for IaaS Remote Site SD-WAN Fabric Branch Campus Cloud Data Center Compute VPC/VNET Compute VPC/VNET Using Marketplace (DIY) Remote Site SD-WAN Fabric Branch Campus Cloud Data Center Compute VPCs/VNETs Gateway VPC/VNET Fully Automated BRKCRS-2110 35
  • 37. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Migration Sequence Controllers Datacenters Branches vManage vSmart vBond Branch Campus Data Center A SOHO Data Center B BRKCRS-2110 37
  • 38. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Data Center Migration CE Data Center Core Perimeter Firewall MPLS INET To/From Non-SDWAN WAN Edge Traditional Site SD-WAN Site Data Center BRKCRS-2110 38
  • 39. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Branch Migration with IOS-XE SDWAN MPLS INET Router L2 HSRP OSPF/BGP Router Traditional MPLS INET L2 VRRP OSPF/BGP WAN Edge SD-WAN L3 Switch L3 Switch WAN Edge BRKCRS-2110 39
  • 41. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Demo: Network Design 10 clicks to deploy simple SD-WAN network. One page to see your entire WAN topology. Like “Visio canvas” in vManage. BRKCRS-2110 41
  • 43. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Call To Action SD-WAN on IOS XE Routers: • Read the White Paper SD-WAN on IOS XE: End-to-End View • Watch the Migration YouTube Video Get your hands dirty: • Complete dCloud SD-WAN Lab “Cisco 4D SD-WAN (Viptela) v2” BRKCRS-2110 43
  • 44. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Monday Tuesday Wednesday Thursday Friday TECCRS-2014 Deep Dive TECSEC-2355 Security TECCRS-2191 Deployment / BCP Your SD-WAN learning map at CLEUR 44 BRKCRS-2110 BRKCRS-2110 The Foundation BRKCRS-2111 Migration BRKCRS-2112 Serviceability BRKRST-2560 Analytics / ML BRKCRS-2114 Security BRKRST-2558 SD-WAN as a Managed Service BRKRST-2559 On-prem Deployment BRKCRS-2113 Cloud onRamp BRKCRS-2117 Design Deployment
  • 45. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Key Message of Our Presentation Cisco SD-WAN Solution helps you to: 1. Reduce Cost 2. Operate Faster with better Performance and Security 3. Integrate Latest Cloud and Network Technologies BRKCRS-2110 45
  • 46. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Proven Solution Across Multiple Verticals Customer Industry Challenge Solution Retail High cost, slow change, limited flexibility 60-70% cheaper broadband at high bandwidth, centralized control, full visibility. Financial Needed more bandwidth and guaranteed network uptime for a new teller application Dollar cost averaged the bandwidth cost down using a mix of transport (MPLS, Broadband, LTE). Traffic now uses the optimal network path to avoid downtime and slowdowns. Tech Slow performance and MPLS outages provided an expensive and poor user experience Monthly savings reduced the cost per Mbps by more than 80%. Diverse circuits improve the reliability of the global network, with more than half of Agilent’s sites doubling WAN redundancy. Healthcare With an MPLS contract renewal approaching, Cigna wanted the flexibility to change carriers without a massive technology shift Gained back control of its control plane and created the Cigna Service Provider Agnostic Network. Healthcare Security and high network cost Satisfied strict security and audit requirements and provided greater flexibility for partnerships and secure clinical solutions. Cost reductions with the removal of remote site voice equipment and expensive PRIs, aging WAN acceleration equipment and maintenance. Energy Scale to support evolving field operations, and support cloud migration and application SLAs Provided 30-60% savings in overall bandwidth costs. Enabled faster response to acquisitions, divestitures and policy changes. For Your Reference BRKCRS-2110 46
  • 47. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Cisco WebEx Teams Questions? Use Cisco WebEx Teams (formerly Cisco Spark) to chat with the speaker after the session Find this session in the Cisco Events Mobile App Click “Join the Discussion” Install WebEx Teams or go directly to the team space Enter messages/questions in the team space How 1 2 3 4 BRKCRS-2110 47 cs.co/ciscolivebot#BRKCRS-2110
  • 48. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Don’t forget: Cisco Live sessions will be available for viewing on demand after the event at ciscolive.cisco.com • Please complete your Online Session Survey after each session • Complete 4 Session Surveys & the Overall Conference Survey (available from Thursday) to receive your Cisco Live T- shirt • All surveys can be completed via the Cisco Events Mobile App or the Communication Stations Complete your online session survey BRKCRS-2110 48
  • 49. © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Demos in the Cisco Showcase Walk-in self-paced labs Meet the engineer 1:1 meetings Related sessions Continue Your Education BRKCRS-2110 49