After an overview presentation, we will demonstrate live how HPE's multi-vendor Intelligent Management Center (IMC) software can be used to manage day to day operations for the datacenter. Introduction to HPE IMC focused on management for data center switching. Topics include REST API, virtualization integration and data center fabric management.
3. 3#ATM16
Best of Breed Integrated Management
MULTIVENDOR MANAGEMENT
for
CLOUD-FIRST, MOBILE-FIRST
NETWORKS
AirWave
IMC
ClearPass
4. 4#ATM16
IMC: Complete management for dynamic agile networks
Across entire network
Campus/Branch
• Unified wired and wireless management
• Traffic and application visibility
• Zero touch deployment
• Integrated central management
• Extendable via additional modules
• Supports up to 6000 devices
models
• Maximize network availability
• Gain network visibility
• Fully FCAPS management
Simplified, proactive management that spans the network
Data Center
• Automation and orchestration
• Visualization of virtualized networks
• Consistency across data center
8. 8#ATM16
HPE IMC platform portfolio
IMC Standard
– Full FCAPS
– Includes 50 device license
– Hierarchical model support
– Includes the eAPI license
– Expandable device support
– Modular
IMC Enterprise
– Full FCAPS
– Includes 50 device license
– Hierarchical model support
– Includes NTA and WSM modules, and eAPI
license
– Expandable device support
– Modular
Advanced networks
IMC Basic WLAN
– Fault, config and performance
– Unified wired and wireless management
– Fixed functionality
– Fixed 50 device limit
– Includes a 50 AP license for WSM
IMC Basic
– Fault, config, and performance
– Fixed 50 device limit
– Fixed functionality
Small, simple networks
10. 10#ATM16
Comprehensive management capabilities
Single platform built on top of a modular, service oriented architecture
Confidential – For Training Purposes 10
Fault
Alarms
Syslog
& Trap
Mgr
Configuration
Intelligent
Configuration
Center
Compliance
Center
VLAN &
ACL
Manager
Accounting
Network Assets
Performance
Performance
Mgmt
Virtual
Network
Mgmt
Security
Security Control
Center
FCAPS
IMC
Platform
Add-On
Modules
Remote
Site
Manager
VAN
Connect
Manager
Service
Health
Manager
App
Perform.
Manager
Intelligent
Analysis
Reporter
User
Behavior
Analyzer
Service
Operation
s Mgmt
Network
Traffic
Analyzer
User
Access
Manager
Endpoint
Admission
Defense
Branch
Intelli.
Mgmt
System
TACACS+
Authent
Manager
IPSec
VPN Mgr
MPLS
VPN Mgr
Wireless
Services
Mgr
QoS Mgr
vMon
Extended API
VAN
Resource
Automate
Manager
VAN SDN
Manager
VAN
Fabric
Manager
UC Health
Manager
Business
Service
Performance
CPPM
CPGuest
CPOnboard
CPOnGuard
11. 11#ATM16
Module solution map
One platform for multiple solution requirements
Branch
BIMS
Zero
touch
RSM
Secure
mgmt
DC Monitoring & Performance
VCM
Server
Access
SHM
Service
Monitoring
APM
Application
Monitoring
vMon
Hypervisor
traffic
monitoring
Campus & BYOD
UBA
Usage
Monitor
NTA
Traffic
Monitor
WSM
Wireless
Mgmt
ClearPass
Access &
BYOD
DC Provisioning & Automation
RAM
Network
orchestratio
n
VAN Fabric-M
Fabric
orchestration
MVM
MPLS VPN
Mgmt
IVM
DVPN
config
Across the Network
QoS
QoS config
SOM
Full IT
lifecycle
BSP
Business
Service
Performanc
e
SDN-M
SDN
managemen
t
13. 13#ATM16
Network Changes Causing Instability
“How do control and audit change on my network ?”
– Change accounts for 69% of network downtime and degradation
– Role Based Management
– Controls who can change network configurations
– Audit trail
– Who changed what when
– Lock down network configuration
– Baselining, Configuration Change notification & Role back
– ITIL based management
– Change approval via Service Operations Management (SOM)*
– TACASC+
– Full control with ClearPass
* Additional IMC Module
14. 14#ATM16
Network Visibility and Control
“I’ve got no visibility and control of what my network is being used for?”
– What is the network really being used for and ensuring control
– Network Traffic Analysis (NTA)* shows
– What applications are running & who is using them
– Requires the power of sFlow or NetFlow
– Benefit from selling HPNs sFlow enabled Switches
– QoS Manager (QoSM)* allows
– Network wide configuration and audit of QoS policies
– Control applications Access Control List Manager (ACLM)
– Definition and deployment of ACLs
* Additional IMC Module
15. 15#ATM16
Network Access Management & Guest Access
“How do I control access to my network?”
– Controlling Network Access with ClearPass Policy Mgr
– Who and what has access & to what
– Advanced policy based access control
– Guest Access & BYOD users ClearPass Guest and OnBoard
– iPads, tablets, iPhones
– Self Registrations and on boarding
– Increasing need for Compliance and Security
– Network Access Control & MDM ClearPass OnGuard
– Ensure device conform to policy
– Integration with MDM for mobile smart devices
– Integration with 3rd party systems ClearPass Exchange
16. 16#ATM16
Integrated Wired and Wireless Management
“How do I manage and control access to my Wired and Wireless network ?”
– IMC, WSM, AirWave and ClearPass integrate Wired, Wireless and User Management
– Seamless Wired and Wireless Access Control with ClearPass
– Management of HPE Aruba Wireless infrastructure with AirWave and WSM
– Manage 3rd Party & legacy wireless – including Cisco
– WIPS and Spectrum Analysis
– Visibility and control of Applications with AppRF*
– Client Health*
*AirWave only
17. 17#ATM16
Enabling Cloud and Virtualisation
“Configuring the network is the bottleneck when I deploy an new Applications”
– Accelerating Application Deployment in a Virtual world
– VAN Connection Manager (VCM*) enables Virtual Application Networking
– Reduces provisioning time from weeks to minute
– VAN Resource Automation Manager (RAM*) end to end service deployment
– Eliminates Manual Configuration
– “Death of the CLI”
– Leverages template policy based approach
* Additional IMC Module
Jump VAN details
18. 18#ATM16
App Profile 3
BW
ACL
QoS
VAN Connection Manager
Simplifying and accelerating application deployment
App
Deployed
1 3
… ready!
Virtualizin
g
2
Chose
application
profile from
IMC in
vCenter.
VM
Create
application
profile with
network policies.
Deploy in
vCenter. IMC
provisions the
connection.
IMC
App Profile 2
BW
ACL
QoS
vCenter
IMC Plugin
App Profile
1
BW
ACL
QoS
App Profile 1
BW
ACL
QoS
App Profile 1
BW, ACL,
QoS
19. 19#ATM16
VAN Resource Automation Manager
Simplifying and accelerating application and services deployment
Virtualized
network path
per app
1 42
Inventory
Devices and
pool
resources.
Create a zone
from physical
topology.
Simulate the
model and
deploy.
Zone 1
Zone
2
Zone
1
3
Create a
service model.
Service Model
BW
ACL
QoS
Service Model
Zone 1
20. 20#ATM16
Resource Automation Manager
Creating agile networks tuned for applications
Applicatio
n
Applicatio
n
Applicatio
nApplication 1
Old way
• Best effort
• Over subscription
• Manual, CLI
provisioning
Application 1
Resource Automation
• Virtualized service path
• Thin provisioning
• Tuned network per app
21. 21#ATM16
Managing Data Center and Virtualised World
“How do I manage my physical and virtual network environments?”
– Managing the technologies deployed in the Data Center
– IMC Platform and Virtual Resource Manager
– Visibility, monitoring and management of virtualized environment
– Data Centre topology to a quickly identify issue location
– MDC – multi tenant device virtualization
– OneView integration – auto provisions ToR
– VXLAN management
– VAN Fabric Manager (VFM*) manages advanced DC technologies
– DCI / EVI –Layer 2 DC connectivity deployment and monitoring
– Visibility onto VM Migration
* Additional IMC Module
22. 22#ATM16
Managing a mixed vendor environment
“I’m locked into Cisco how can I manage my network if I add a second vendor?”
– Extensive 3rd party support
– Comprehensive support for Cisco
– Single Management solution for mixed HP / Cisco network
– Supports Gartner’s “Dual Vendor” strategy
– Includes IMC Platform, WSM*, QoSM*
– Also AirWave and ClearPass
– Extensive 3rd party support
– User / partner extensible
7000+
devices supported
1500+
from Cisco
220
manufacturers
IMC Functionality HPN Cisco
Discovery & Topology
Monitoring / Perfomance Mgmt
Events / Traps
Device Manager
Configuration Backup /Restore
Baselining / Change Notifications
Bulk Configuration
Bulk SW Upgrades
VLAN Management
ACL Management
Network Traffic Analysis
* Additional IMC Module
23. 23#ATM16
Business Service and Application monitoring
“Are my business critical services applications running OK & meeting agreed SLA?”
– Definition and Monitoring of Service Level Agreement and Application Performance
– Service Level management monitoring with Service Health Manager (SHM)*
– Define and monitor advanced SLA models
– Prove your meeting agreed SLAs
– Application Performance Management (APM)*
– Monitoring of Applications and Servers
– UC Health Manager (UCHM)*
– Monitoring of MS Lync
– Business Service Performance (BSP)*
– Models Business Services
– Comines data from SHM + APM + NTA + VRM……
– Dashboard view critical business services
* Additional IMC Module
24. 24#ATM16
– Managing a mix of traditional network and Software Defined Network
– SDN Manager (SDNM*) multi layer visibility onto Software-defined Networks
• Deploy, monitor and manage OpenFlow switches
• Visualize traffic flow and performance monitoring
• Graphical OpenFlow troubleshooting
– Unified management of single and teamed controllers
– SDN Application deployment and monitoring
Managing the transition to SDN
“How I manage my network as a transition from a traditional to SDN Network?”
Infrastructure
Controller
Applications
* Additional IMC Module
25. 25#ATM16
Multi Site Management
“I’ve lots of remote sites which I need to deploy and manage”
– Simplify the deployment and management of multi site networks
– Branch Intelligent Management System (BIMS)*
– Zero touch deployment of CPE & remote site devices
– Dynamic IP and NAT
– Remote Site Manager (RSM)*
– Light weight IMC agent that can be hosted on remote sites
– Information sent back to Central manager via secure tunnel
– Provides a Multi Tenant Management solution
– Resolves issues of overlapping IP ranges
* Additional IMC Module
26. 26#ATM16
Integration with OSS via North Bound API
“I need to integrate the mgmt system with my higher level mgmt. systems”
– IMCs extended API (eAPI) provides rich access to all IMC functionality via API
– RestFull / SOAP API
– Comprehensive documentation, examples and tools
29. 29#ATM16
Join Aruba’s Titans of Tomorrow
force in the fight against network
mayhem. Find out what your
IT superpower is.
Share your results with friends
and receive a free superpower
t-shirt.
www.arubatitans.com
IMC is built on a platform/module architecture. The platform provides the base network management services, and is the minimum needed for an IMC product installation.
There are four platforms available as shown. The rightmost two are the basic platforms that are targeted at small, simple networks. These configurations provide basic functionality, and cannot be expanded beyond their initial capabilities.
On the left are the two expandable platforms, Standard and Enterprise. Both use the same software codebase meaning that the management services for both are identical. Both support all of the available optional modules. Where they differ is in the scalability of the number of network devices that can be managed, and in modules that are initially included.
The Standard platform is the IMC workhorse. Starting with support for 50 network devices, additional licenses allows expansion to support up to 15,000 devices.
The Enterprise platform includes support for full hierarchical scaling of the solution. When combined with additional standard platform installations, the number of network devices supported rises to more than 100,000. The Enterprise platform also includes Network Traffic Analyser and Wireless Services Manager modules.
Looking specifically at the IMC platform functionality, all of the following basic network management services are included:
Discovery
Find the network devices and visualize the network topology
Monitor
Monitor the network for performance and QoS, fault detection, and capacity planning
Manage
Configuration management, backup and recovery of software upgrades, etc., keep the networking up and running, and continuously verify that the network is enabled the way it was configured
Troubleshoot
Provide the tools to get to root cause, and to minimize time to fix
Report
Provide reports for auditing, documenting, planning and troubleshooting the network
These platform functions provide the basis for an optimized network that will support the mission critical functionality that most networks now contain.
While the IMC platforms provide the functionality most customers need to meet their management requirements, IMC Modules can extend IMC’s capabilities to meet the requirements of even the most demanding customer.
The IMC module portfolio provides a broad set of features across the FCAPS model to provision, monitor, and manage network elements. These twenty-one modules can be installed as needed on top of the IMC platform and its services. This modular architecture allows deeper functionality providing a tailored solution that delivers scalability for growth as management needs change. Further information on any of these modules can be found on the HPE Networking web site.
With Aruba wireless now part of Hewlett Packard Enterprise, the Aruba AirWave product is the recommended wireless services solution and replaces the IMC Wireless Services Manager module. Similarly, ClearPass replaces the User Access Manager, Endpoint Admission Defense and the TACACS+ Authentication Manager Modules as the recommended sources for these services.
It should be noted that there may be some customers that can benefit from the Wireless Services Manager module, which can coexist in the network environment with AirWave, and provide additional customer value, particularly for environments that are in transition from a legacy HP Wireless solution to an Aruba Wireless solution. Many of these customers would already have Wireless Services Manager to manage their current environment.
Module solution map
VAN Resource Automation Manager
Contest Overview
- Aruba is running a marketing campaign where we ask “What is your IT superpower?”
- Go to arubatitans.com to take a quick quiz to discover your superpower.
- Share your results with friends and encourage others to play the game
- Once you share, go to the Social and Community Hub, Gracia Commons, 3rd fl to pick up your free superpower shirt.
FAQ
1. What do I have to do to get a shirt?
Share your IT superpower results with friends and encourage them to play the game. Then come to the Social & Community Hub, 3rd Floor Gracia Commons to pick up your shirt. We just need your name and badge for verification.
2. Where do I get my shirt?
Come to the #ATM16 Social & Community hub located at Gracia Commons on the 3rd Floor
3. Do I have to be at the event to get the shirt?
Yes. You have to be at #ATM16 to get a shirt.
4. Can I get my colleague a shirt? He/she is in a session right now.
Unfortunately not. We encourage your colleague to participate so that they can win a shirt for themselves.
5. Can I bring a shirt home for my colleague?
Unfortunately not. You have to be at #ATM16 to get a shirt.
6. You don’t have a shirt in my size, can you ship the right size to me later?
Unfortunately not. Please select the best size from our inventory on site.