SlideShare une entreprise Scribd logo
1  sur  47
Télécharger pour lire hors ligne
Cisco Confidential© 2015 Cisco and/or its affiliates. All rights reserved. 1
Cisco Intelligent Branch – Enabling
the Next Generation Branch
Tammy Getschel
Systems Engineer
May 19, 2016
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2
Housekeeping notes
Thank you for attending Cisco Connect Toronto 2016, here are a few housekeeping notes
to ensure we all enjoy the session today.
• Please ensure your cellphones / laptops are set on silent to ensure no one is disturbed
during the session
• [Please add any special notes for your session/labs]
© 2013 Cisco and/or its affiliates. All rights reserved. 3
Pressures on the WAN
Emerging Branch Demands
The Application Landscape Is Changing
Applications are Moving to the DC and Cloud
Internet Edge Is Moving to the Branch
Cloud
SaaS, Google Docs, Office365 Guest WiFi, BYOD, App Updates
Cloud Mobility Apps
Video, VDI, Backup
Branch Data Centers
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
Internet as an Extension of Enterprise WAN
Commodity Transports Viable Now
Dramatic Bandwidth, Price Performance Benefits
Higher Network Availability
Improved Performance Over Internet
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
Intelligent WAN: Leveraging the Internet
Secure WAN Transport and Internet Access
Optimized
Secure Transport
Branch
Direct Cloud
Access
Private
Cloud
Virtual
Private
Cloud
Public
Cloud
1. IWAN Secure transport for private
and virtual private cloud access
2. Leverage local Internet path for
public cloud and Internet access
 Increase WAN transport capacity and
app performance cost effectively!
 Improve application performance
(right flows to right places)
MPLS (IP-VPN)
Internet
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6
Intelligent WAN (IWAN) Architecture
MPLS
Unified
Branch
3G/4G-LTE
Internet
Private
Cloud
Virtual
Private
Cloud
Public
Cloud
Application
Optimization
Enhanced Application
Visibility and Performance
Secure
Connectivity
Comprehensive
Threat Defense
Intelligent
Path Control
Application
Aware Routing
Transport
Independent
Simplified
Hybrid WAN
Management Automation
6
Cisco Confidential 7© 2015 Cisco and/or its affiliates. All rights reserved.
Transport-Independence
Virtualizing the Enterprise WAN
7
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
IWAN Transport Independence
Consistent deployment models simplify operations
Internet MPLS
Branch
DMVPN DMVPN
IWAN HYBRID
Data Center
ISR
ASR 1000 ASR 1000
ISP A SP B
4G/LTE
Branch
DMVPN
IWAN HYBRID/LTE
Data Center
ISP C SP B
ASR 1000
MPLS
Branch
MPLS
DMVPN
IWAN Dual MPLS
Data Center
ISR
ASR 1000 ASR 1000
SP A SP B
DMVPN
MPLS
DMVPN
ISR
ASR 1000
IWAN Transport Independent Design
with Dynamic Multipoint VPN (DMVPN)
• Proven IPsec VPN technology
Widely deployed, Large scale
Standards based IPsec and Routing
Adv QOS: hierarchical, per tunnel and adaptive
• Flexible & Resilient
Over any transport: MPLS, Carrier Ethernet, Internet, 3G/4G,..
Hub-n-Spoke with Dynamic full mesh Topology
Multiple encryption, key management, routing options
Multiple redundancy options: platform, hub, transports
• Secure
Industry Certified IPsec and Firewall
NG Strong Encryption: AES-GCM-256 (Suite B)
IKE Version 2
IEEE 802.1AR Secure unique device identifier
• Simplified IWAN Deployments
Prescriptive validated IWAN designs
Automated provisioning – Prime, IWAN-App, Glue
Branch
Internet MPLS
DMVPN
Purple
DMVPN
Green
IWAN HYBRID
Data Center
ISP A SP B
Cisco Confidential 11© 2015 Cisco and/or its affiliates. All rights reserved.
Intelligent Path Control
Improving Application Delivery and WAN Efficiency
1
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12
Getting the Most Out of Your WAN Investment
Benefits of Intelligent Path Control
Data Center
Branch
ASR 1000
ASR 1000
ISR
MPLS
Internet
Enabling
Hybrid WANs
Efficient Distribution of
Traffic Based Upon Load
or Path Preference
Application Best Path
Based on Quality
Protection From
Carrier Black Holes
and Brownouts
Lower
WAN Costs
Full Utilization
of WAN Bandwidth
Improved
Application
Performance
Higher Application
Availability
12
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13
Intelligent Path Control with PfR
Voice and Video Use-Case
Branch
MPLS
Internet
Virtual Private
Cloud
Private Cloud
• PfR monitors network performance and routes applications
based on policy
• PfR load balances traffic based upon link utilization levels
to efficiently utilize all available WAN bandwidth
Other traffic is load
balanced to maximize
bandwidth Voice/Video will be rerouted if the
current path degrades below policy
thresholds
Voice/Video take the best
delay, jitter, and/or loss path
13
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
What is Performance Routing (PfR)?
MPLS Internet
Branch
BR BR
Data Center
MC
“Performance Routing (PfR) provides additional
intelligence to classic routing to track and verify the
quality of a path over a Wide Area Networking (WAN)
to determine the best path for application traffic....”
MC+BR
14
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
SP1 (MPLS) ISP (FTTH)
• Protect voice and
video quality
Latency < 150 ms
Jitter < 20 ms
• Protect Email applications
from WAN congestion
Loss < 5%
• Voice and video preferred
path SP1
• Email preferred path ISP
• Increase utilization
by load sharing
Multimedia and Critical Data Policy
Business App
Best-Effort Traffic
High Delay
Detected
SP1 (MPLS) ISP (DSL)
Voice and Video
High Jitter
Detected
Email
Best-Effort Traffic
Protecting Critical Applications While Increasing Bandwidth Utilization
• Protect transactional
business app from brownouts
delay < 250ms
• Preferred path SP1 (MPLS)
• Increase WAN bandwidth
efficiency by load-sharing
traffic over all WAN paths,
MPLS + Internet
Business App and Load-Balancing Policy
15
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
Load Balancing
Maximizing Link Utilization to Increase Available Bandwidth
• Traffic distributed across all paths to efficiently use all WAN bandwidth
• Load Balancing based upon link utilization levels
• External links can have different bandwidth capacities
MPLS = 1.5Mbps
Internet = 15Mbps
ISR
WAN
Internet
MPLS
ASR 1000
ASR 1000
Data Center
50% T1 = 750kbps
50% 15Mbps = 7.5Mbps
16
Cisco Confidential 17© 2015 Cisco and/or its affiliates. All rights reserved.
Application Optimization
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18
Branch
Proliferation
of Devices
Users/
Machines
Private
Cloud
Make Your IWAN Application Aware
Application Visibility and Control (AVC)
DC/Headquarters
Public
Cloud
Cisco AVC
Application Performance
Visibility
• Application inspection with
existing routers
• Rich data collection using
NetFlow v9/IPFIX
• Easy to integrate into many
reporting tools
Smart Capacity
Planning
• Better use of costly bandwidth
• Per-branch and per-application
level reporting
Business Objective
Enforcement
• Service Level monitoring per
application
• Better Analytics to adjust
network policies to maintain
compliance
18
AVC
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19
Proliferation
of Devices
Users/
Machines
Private
Cloud
Application Performance Monitoring for IWAN
Track and Report Application Flows and Performance
WAN
Enterprise Edge
AVC
AVC
CSR
NetFlow/IPFIX Records
(Same provisioning, same format)
• Traffic statistics records
• Application Response Time records
• Media monitoring records
(Application, Jitter, Loss, etc)
Cisco Tools
Prime, APIC-EM
Partner Tools
Ecosystem
LiveAction
Glue Networks
Plixer
Living Objects
CompuWare
CA Technologies
Collecting Collecting Collecting
Provisioning
Exporting
NetFlow v9 Export/IPFIX Export
Branch DC/Headquarters
AVC
AVC
19
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Cisco WAAS
Enhancing User Experience and WAN Efficiency
Solution
• Reduce load
Data redundancy elimination
(DRE), compression, and
TCP optimization
• Application optimization
Fewer protocol messages
and metadata caching
Problem
• Application latency
• WAN bandwidth
inefficiencies
Application bandwidth with Cisco® WAAS
Application bandwidth natively
Application latency natively
Application latency with Cisco WAAS 0 0
1
2
3
4
40
80
120
160
Application
Bandwidth
Application
Latency
Bandwidth
(Mbps)
Latency
(Seconds)
Reduction in
bandwidth
Reduction
in latency
20
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
© 2010 Cisco Systems, Inc. All rights reserved.
WAN
Application-Specific Acceleration
 Application and protocol awareness
Eliminate unnecessary chatter
Save WAN bandwidth
Pre-populate edge cache as necessary
Enable disconnected operations
Intelligent protocol acceleration
Read-ahead, prediction, and batching
Safe data and metadata caching
Improves application response time
Provide origin server offload
DRE Hints
Application intelligence signals to DRE & LZ…
whether to compress
whether to cache
Safe Caching
Read-ahead
Prediction
Batching
DRE Hinting
WAN
Optimization
DRE/TFO/LZ
Origin Server
Offloaded
Application Specific Acceleration
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
Email (5MB Attachment) File Services (5MB File)
VDI (Citrix)(5MB Document)
First Optimized with WAAS
Send and Receive Email over native WAN
Second Pass Optimized with WAAS
100 20 30 40 50 60 70 80 90 100 110 120 130 140 150
Time in Seconds
Optimize and Enhance Thousands of Applications
AX Includes Cisco WAAS WAN Optimization
24x
Faster First Optimized with WAAS
File Drag and Drop Over native WAN
Second Pass Optimized with WAAS
100 20 30 40 50 60 70 80 90 100 110 120 130 140 150
Time in Seconds
17x
Faster
First Optimized with WAAS
Sharepoint File Download over Native WAN
Second Pass Optimized with WAAS
Launch Citrix XenDesktop with WAAS
Launch Citrix XenDesktop Over Native Citrix ICA/SSL
Site Navigation with WAAS
20 4 6 8 10 12 14 16 18 20 22 24 26 28 30
Time in Seconds
30x
Faster
20 4 6 8 10 12 14 16 18 20 22 24 26 28 30
Time in Seconds
Site Navigation Over Native Citrix ICA/SSL
3-8x
Faster
Cisco Confidential 25© 2015 Cisco and/or its affiliates. All rights reserved.
IWAN Secure Connectivity
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
Intelligent WAN: Secure Connectivity
Securing the network and users
Secure WAN Transport
Branch
MPLS (IP-VPN)
Internet
Secure
Internet
Access
Private
Cloud
Virtual
Private
Cloud
Public
Cloud
Two areas of concern
1. Protecting the network from outside threats with data privacy over provider networks
2. Protecting user access to Public Cloud and Internet services; malware, privacy,
phishing,…
26
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
Securing IWAN Transports with Front-door VRF
Isolation of external networks
• Virtual Route Forwarding (VRFs) create
multiple logical routers on a single device
Separate control/data planes per VRF
No connectivity between VRFs by default
Provider side VRF (yellow) for external networks,
Global VRF (blue) for internal networks
• Provider VRF minimizes threat exposure
Default routing only in Provider VRF
Provider assigned IP addressing hides internal
network
Provider IP address used as IPSec tunnel
source
Only IPsec allowed between internal Global and
Provider Front Side VRFs
Global
F-VRF
Branch LAN
10.1.1.0/24
10.1.2.0/24
…
Front Side
Provider VRF
Provider Assigned
WAN IP Address
192.168.254.254
VRFs have
independent
routing and
forwarding
planes
IPSec Tunnel
Interface
Global
Enterprise
VRF
• Use ACLs, ZBFW or ASA to block all traffic
except the DMVPN tunnel traffic to routers
• Zone Based Firewall (ZBFW) at the branch if there
are plans for direct Internet access
• Typical ACL for protecting the Internet interface
DSL Cable
Branch
ASR 1000 ASR 1000
ISP A ISP C
Data Center
Protecting the Public facing IWAN Interfaces
interface GigabitEthernet0/0
ip vrf forwarding INET-PUBLIC1
ip access-group ACL-INET-PUBLIC in
!
ip access-list extended ACL-INET-PUBLIC
permit udp any any eq non500-isakmp
permit udp any any eq isakmp
permit esp any any
permit udp any any eq bootpc
permit icmp any any echo
permit icmp any any echo-reply
permit icmp any any ttl-exceeded
permit icmp any any port-unreachable
permit udp any any gt 1023 ttl eq 1
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31
Intelligent WAN—Direct Cloud Access
Branch
MPLS (IP-VPN)
Internet
Direct Internet
Access
Private
Cloud
Virtual
Private
Cloud
Public
Cloud
• Leverage Local Internet path for Public Cloud and Internet access
• Improve application performance (right flows to right places)
Solutions
On Premise – Zone Based Firewall
Cloud Based – Cloud Web Security
CWS
ISR-AX
ZBFW
31
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32
Secure Internet Access with Cisco
Cloud Web Security (CWS)
Secure Public
Cloud and Internet
Access
ISR Connector to
CWS Firewall towers
Web Filtering,
Access Policy,
Malware Detect
WAN1
(IP-VPN)
CWS
Private
Cloud
Public
Cloud
Branch
WAN2
(Internet)
IWAN IPsec VPN
for Private Cloud
TrafficIOS Firewall to
protect Internet
Edge
Internet
32
Cisco Confidential 33© 2015 Cisco and/or its affiliates. All rights reserved.
Orchestration and Automation
3
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
Cisco IWAN Management Portfolio
Covering a broad range of preferences and requirements
• Customer wants advanced
provisioning, life cycle
management, and
customized policies
• System-wide network
consistency assurance
• Lean IT OR IT Network team
Cisco
Prime
Infrastructure
• Customer needs
customizable IWAN with
end-to-end monitoring
• One Assurance across Cisco
portfolio from Branch to
Datacenter
• IT Network team
Enterprise Network
Mgmt and Monitoring
Ecosystem Partners
IWAN App
• Customer wants
considerable automation
and operational simplicity
• Requirements consistent
with prescriptive IWAN
Validated Design
• Lean IT organization
Prescriptive
Policy Automation
• Customer looking for
advanced monitoring and
visualization
• QoS/ PfR/ AVC configuration,
Real-time analytics and
network troubleshooting
• IT Network team
Application Aware
Performance Mgmt
Advanced
Orchestration
3
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
Provisioning & Life
Cycle Management
Visualization & Health
IWAN Management Solution Positioning
CustomizablePrescriptive
AdvancedFoundation
Prime
Prime
IWAN AppOn Prem
Cloud
Infrastructure ASR 1000
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36
APIC-EM IWAN App
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37
APIC-EM IWAN App
Site provisioning
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 38
APIC-EM IWAN App
Site provisioning
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 39
APIC-EM IWAN App
Site provisioning
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 40
IWAN App – Site provisioning
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41
IWAN App – Site provisioning
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 42
IWAN App – Site provisioning
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 43
APIC-EM IWAN App
Define Application Policy
• Business Intent  network admin informs the controller
what applications are relevant for the business
• The controller is going to perform background tasks based
on this business logic
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 44
APIC-EM IWAN App
Define Application Policy
• Define primary path for group of applications
• The controller will create a PfR policy based on
those paths.
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 45
IWAN App
Define Application Policy
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 46
Prime Infrastructure for IWAN
• IWAN workflow wizard with PnP
• Template-based IWAN configs
• PfRv3 Domain, MC and BR
• AVC One-Click provision
• QoS Provisioning
• Single or Dual Router Branch
• CVD-based, Customizable
• AVC Readiness Assessment
• AVC, QoS, PfR Visibility
• Leverages APIC EM services
46
Cisco Confidential 47© 2015 Cisco and/or its affiliates. All rights reserved.
Cisco IWAN Product Portfolio
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 48
Start with Cisco AX Routers
IWAN Capabilities Embedded in the Router
ISR-AX
Simplify
Application
Delivery
One Network
UNIFIED SERVICES ASR1000-AX
ISR-4000AX
Transport
Independent
Secure
Routing
Optimization
Control
Visibility
Cisco AX Routers 800 | 1900 | 2900 | 3900 | 4000 | ASR 1000
Cisco Confidential 49© 2015 Cisco and/or its affiliates. All rights reserved.
Why Cisco IWAN?
4
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 50
Internet
Intelligent WAN Summary
Branch-1 Branch-513
DCI
WAN Core
MC MC
20M Dn
2M Up
512M FD
BR BR
ATBT
MPLS
Island
ADSL
BR
ISR-AX
vWAAS
ISR-AX
vWAAS
1.5M FD
256M FD
CWS
BR
ASR-AX ASR-AX
WAAS WAAS
AVC
AVC AVC
ShowMe$$
DC-WestDC-East
Internet Internet
Transport Independent Design
• Highly available Hybrid WAN
Intelligent Path Control
• Performance Routing (PfR) to protect applications and
load balance traffic to maximize expensive WAN bandwidth
Application Optimization
• Application Visibility and Control (AVC) to monitor performance
• WAAS + Akamai to reduce bandwidth consumption while improving
application experience
Secure Connectivity
• Secure the network from outside threats
• Cloud Web Security (CWS) for improved Cloud performance while
freeing up WAN bandwidth, without compromising security
IWAN Management
• Cisco and Ecosystem Partner tools
APIC-EM IWAN-APP, Prime, LiveAction, GlueWare, and more
5
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 51
Branch
MPLS (IP-VPN)
Internet
Private
Cloud
Virtual
Private
Cloud
Public
Cloud
Cisco Intelligent WAN (IWAN)
Secure WAN Transport
Direct Internet
Access
Mixed Transport WAN with High Reliability
SLAs for Business-Critical Applications
Centralized Security Policy for Internet Access
Dramatically Lower WAN Costs Without Compromise
51
Cisco Intelligent Branch - Enabling the Next Generation Branch

Contenu connexe

Tendances

Tendances (20)

Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM...
Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM...Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM...
Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM...
 
Emerging Threats - The State of Cyber Security
Emerging Threats - The State of Cyber SecurityEmerging Threats - The State of Cyber Security
Emerging Threats - The State of Cyber Security
 
Cisco Connect Toronto 2017 - Accelerating Incident Response in Organizations...
Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations...Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations...
Cisco Connect Toronto 2017 - Accelerating Incident Response in Organizations...
 
Leverage the Network
Leverage the NetworkLeverage the Network
Leverage the Network
 
Putting firepower into the next generation firewall
Putting firepower into the next generation firewallPutting firepower into the next generation firewall
Putting firepower into the next generation firewall
 
Security and Virtualization in the Data Center
Security and Virtualization in the Data CenterSecurity and Virtualization in the Data Center
Security and Virtualization in the Data Center
 
Cisco ONE Enterprise Cloud (UCSD) Hands-on Lab
Cisco ONE Enterprise Cloud (UCSD) Hands-on LabCisco ONE Enterprise Cloud (UCSD) Hands-on Lab
Cisco ONE Enterprise Cloud (UCSD) Hands-on Lab
 
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WANCisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
 
Hosted Security as a Service - Solution Architecture Design
Hosted Security as a Service - Solution Architecture DesignHosted Security as a Service - Solution Architecture Design
Hosted Security as a Service - Solution Architecture Design
 
Meraki powered services bell
Meraki powered services   bellMeraki powered services   bell
Meraki powered services bell
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
 
Application Engineered Routing: Allowing Applications to Program the Network
Application Engineered Routing: Allowing Applications to Program the NetworkApplication Engineered Routing: Allowing Applications to Program the Network
Application Engineered Routing: Allowing Applications to Program the Network
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
 
ACI Hands-on Lab
ACI Hands-on LabACI Hands-on Lab
ACI Hands-on Lab
 
Cisco Connect Vancouver 2017 - Gain insight and programmability with Cisco DC...
Cisco Connect Vancouver 2017 - Gain insight and programmability with Cisco DC...Cisco Connect Vancouver 2017 - Gain insight and programmability with Cisco DC...
Cisco Connect Vancouver 2017 - Gain insight and programmability with Cisco DC...
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
 
Cisco connect winnipeg 2018 understanding cisco's next generation sdwan sol...
Cisco connect winnipeg 2018   understanding cisco's next generation sdwan sol...Cisco connect winnipeg 2018   understanding cisco's next generation sdwan sol...
Cisco connect winnipeg 2018 understanding cisco's next generation sdwan sol...
 
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
 
Cisco Spark Hybrid Services Architectural Design
Cisco Spark Hybrid Services Architectural DesignCisco Spark Hybrid Services Architectural Design
Cisco Spark Hybrid Services Architectural Design
 
Cisco Connect Toronto 2017 - Your time is now
Cisco Connect Toronto 2017 - Your time is nowCisco Connect Toronto 2017 - Your time is now
Cisco Connect Toronto 2017 - Your time is now
 

En vedette

David_A_Locher_resume (1)
David_A_Locher_resume (1)David_A_Locher_resume (1)
David_A_Locher_resume (1)
David Locher
 

En vedette (10)

David_A_Locher_resume (1)
David_A_Locher_resume (1)David_A_Locher_resume (1)
David_A_Locher_resume (1)
 
Neco GCE Timetable 2015
Neco GCE Timetable 2015Neco GCE Timetable 2015
Neco GCE Timetable 2015
 
Apresentação APIMEC - SP
Apresentação APIMEC - SPApresentação APIMEC - SP
Apresentação APIMEC - SP
 
Gerenciamento e registros de uso das TIC - NTE-Regional/MS
Gerenciamento e registros de uso das TIC - NTE-Regional/MSGerenciamento e registros de uso das TIC - NTE-Regional/MS
Gerenciamento e registros de uso das TIC - NTE-Regional/MS
 
Facts about logic
Facts about logicFacts about logic
Facts about logic
 
Apostila módulo 5 - Calc - fonte IFRS
Apostila módulo 5 - Calc - fonte IFRSApostila módulo 5 - Calc - fonte IFRS
Apostila módulo 5 - Calc - fonte IFRS
 
Entrepreneurship
EntrepreneurshipEntrepreneurship
Entrepreneurship
 
Land pollutions
Land pollutionsLand pollutions
Land pollutions
 
GFP Workshop
GFP WorkshopGFP Workshop
GFP Workshop
 
СМЕРТЬ КОНЕЦ СВЕТА АД
СМЕРТЬ КОНЕЦ СВЕТА АДСМЕРТЬ КОНЕЦ СВЕТА АД
СМЕРТЬ КОНЕЦ СВЕТА АД
 

Similaire à Cisco Intelligent Branch - Enabling the Next Generation Branch

Cisco Intelligent WAN (IWAN) Solution
Cisco Intelligent WAN (IWAN) SolutionCisco Intelligent WAN (IWAN) Solution
Cisco Intelligent WAN (IWAN) Solution
Cisco Russia
 
Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01
Boris Rojas
 

Similaire à Cisco Intelligent Branch - Enabling the Next Generation Branch (20)

Cisco Intelligent WAN (IWAN) Solution
Cisco Intelligent WAN (IWAN) SolutionCisco Intelligent WAN (IWAN) Solution
Cisco Intelligent WAN (IWAN) Solution
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
Cisco IWAN – Intelligent Connectivity for Today’s Reality
Cisco IWAN – Intelligent Connectivity for Today’s RealityCisco IWAN – Intelligent Connectivity for Today’s Reality
Cisco IWAN – Intelligent Connectivity for Today’s Reality
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN Technology
 
Secure Connectivity on Every Network Layer
Secure Connectivity on Every Network LayerSecure Connectivity on Every Network Layer
Secure Connectivity on Every Network Layer
 
Cisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation BranchCisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation Branch
 
iWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience SolutioniWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience Solution
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
 
Software-Defined WAN 101
Software-Defined WAN 101Software-Defined WAN 101
Software-Defined WAN 101
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01
 
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
 
Maximizing SD-WAN Architecture with Service Chaining - VeloCloud
Maximizing SD-WAN Architecture with Service Chaining - VeloCloudMaximizing SD-WAN Architecture with Service Chaining - VeloCloud
Maximizing SD-WAN Architecture with Service Chaining - VeloCloud
 
What SD-WAN Means for Enterprise
What SD-WAN Means for EnterpriseWhat SD-WAN Means for Enterprise
What SD-WAN Means for Enterprise
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Cisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WANCisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WAN
 
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
 

Plus de Cisco Canada

Plus de Cisco Canada (20)

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet Overview
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 

Dernier

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Dernier (20)

Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 

Cisco Intelligent Branch - Enabling the Next Generation Branch

  • 1. Cisco Confidential© 2015 Cisco and/or its affiliates. All rights reserved. 1 Cisco Intelligent Branch – Enabling the Next Generation Branch Tammy Getschel Systems Engineer May 19, 2016
  • 2. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 Housekeeping notes Thank you for attending Cisco Connect Toronto 2016, here are a few housekeeping notes to ensure we all enjoy the session today. • Please ensure your cellphones / laptops are set on silent to ensure no one is disturbed during the session • [Please add any special notes for your session/labs]
  • 3. © 2013 Cisco and/or its affiliates. All rights reserved. 3 Pressures on the WAN Emerging Branch Demands The Application Landscape Is Changing Applications are Moving to the DC and Cloud Internet Edge Is Moving to the Branch Cloud SaaS, Google Docs, Office365 Guest WiFi, BYOD, App Updates Cloud Mobility Apps Video, VDI, Backup Branch Data Centers
  • 4. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4 Internet as an Extension of Enterprise WAN Commodity Transports Viable Now Dramatic Bandwidth, Price Performance Benefits Higher Network Availability Improved Performance Over Internet 4
  • 5. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5 Intelligent WAN: Leveraging the Internet Secure WAN Transport and Internet Access Optimized Secure Transport Branch Direct Cloud Access Private Cloud Virtual Private Cloud Public Cloud 1. IWAN Secure transport for private and virtual private cloud access 2. Leverage local Internet path for public cloud and Internet access  Increase WAN transport capacity and app performance cost effectively!  Improve application performance (right flows to right places) MPLS (IP-VPN) Internet
  • 6. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 Intelligent WAN (IWAN) Architecture MPLS Unified Branch 3G/4G-LTE Internet Private Cloud Virtual Private Cloud Public Cloud Application Optimization Enhanced Application Visibility and Performance Secure Connectivity Comprehensive Threat Defense Intelligent Path Control Application Aware Routing Transport Independent Simplified Hybrid WAN Management Automation 6
  • 7. Cisco Confidential 7© 2015 Cisco and/or its affiliates. All rights reserved. Transport-Independence Virtualizing the Enterprise WAN 7
  • 8. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 IWAN Transport Independence Consistent deployment models simplify operations Internet MPLS Branch DMVPN DMVPN IWAN HYBRID Data Center ISR ASR 1000 ASR 1000 ISP A SP B 4G/LTE Branch DMVPN IWAN HYBRID/LTE Data Center ISP C SP B ASR 1000 MPLS Branch MPLS DMVPN IWAN Dual MPLS Data Center ISR ASR 1000 ASR 1000 SP A SP B DMVPN MPLS DMVPN ISR ASR 1000
  • 9. IWAN Transport Independent Design with Dynamic Multipoint VPN (DMVPN) • Proven IPsec VPN technology Widely deployed, Large scale Standards based IPsec and Routing Adv QOS: hierarchical, per tunnel and adaptive • Flexible & Resilient Over any transport: MPLS, Carrier Ethernet, Internet, 3G/4G,.. Hub-n-Spoke with Dynamic full mesh Topology Multiple encryption, key management, routing options Multiple redundancy options: platform, hub, transports • Secure Industry Certified IPsec and Firewall NG Strong Encryption: AES-GCM-256 (Suite B) IKE Version 2 IEEE 802.1AR Secure unique device identifier • Simplified IWAN Deployments Prescriptive validated IWAN designs Automated provisioning – Prime, IWAN-App, Glue Branch Internet MPLS DMVPN Purple DMVPN Green IWAN HYBRID Data Center ISP A SP B
  • 10. Cisco Confidential 11© 2015 Cisco and/or its affiliates. All rights reserved. Intelligent Path Control Improving Application Delivery and WAN Efficiency 1
  • 11. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12 Getting the Most Out of Your WAN Investment Benefits of Intelligent Path Control Data Center Branch ASR 1000 ASR 1000 ISR MPLS Internet Enabling Hybrid WANs Efficient Distribution of Traffic Based Upon Load or Path Preference Application Best Path Based on Quality Protection From Carrier Black Holes and Brownouts Lower WAN Costs Full Utilization of WAN Bandwidth Improved Application Performance Higher Application Availability 12
  • 12. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13 Intelligent Path Control with PfR Voice and Video Use-Case Branch MPLS Internet Virtual Private Cloud Private Cloud • PfR monitors network performance and routes applications based on policy • PfR load balances traffic based upon link utilization levels to efficiently utilize all available WAN bandwidth Other traffic is load balanced to maximize bandwidth Voice/Video will be rerouted if the current path degrades below policy thresholds Voice/Video take the best delay, jitter, and/or loss path 13
  • 13. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14 What is Performance Routing (PfR)? MPLS Internet Branch BR BR Data Center MC “Performance Routing (PfR) provides additional intelligence to classic routing to track and verify the quality of a path over a Wide Area Networking (WAN) to determine the best path for application traffic....” MC+BR 14
  • 14. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15 SP1 (MPLS) ISP (FTTH) • Protect voice and video quality Latency < 150 ms Jitter < 20 ms • Protect Email applications from WAN congestion Loss < 5% • Voice and video preferred path SP1 • Email preferred path ISP • Increase utilization by load sharing Multimedia and Critical Data Policy Business App Best-Effort Traffic High Delay Detected SP1 (MPLS) ISP (DSL) Voice and Video High Jitter Detected Email Best-Effort Traffic Protecting Critical Applications While Increasing Bandwidth Utilization • Protect transactional business app from brownouts delay < 250ms • Preferred path SP1 (MPLS) • Increase WAN bandwidth efficiency by load-sharing traffic over all WAN paths, MPLS + Internet Business App and Load-Balancing Policy 15
  • 15. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16 Load Balancing Maximizing Link Utilization to Increase Available Bandwidth • Traffic distributed across all paths to efficiently use all WAN bandwidth • Load Balancing based upon link utilization levels • External links can have different bandwidth capacities MPLS = 1.5Mbps Internet = 15Mbps ISR WAN Internet MPLS ASR 1000 ASR 1000 Data Center 50% T1 = 750kbps 50% 15Mbps = 7.5Mbps 16
  • 16. Cisco Confidential 17© 2015 Cisco and/or its affiliates. All rights reserved. Application Optimization
  • 17. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18 Branch Proliferation of Devices Users/ Machines Private Cloud Make Your IWAN Application Aware Application Visibility and Control (AVC) DC/Headquarters Public Cloud Cisco AVC Application Performance Visibility • Application inspection with existing routers • Rich data collection using NetFlow v9/IPFIX • Easy to integrate into many reporting tools Smart Capacity Planning • Better use of costly bandwidth • Per-branch and per-application level reporting Business Objective Enforcement • Service Level monitoring per application • Better Analytics to adjust network policies to maintain compliance 18 AVC
  • 18. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19 Proliferation of Devices Users/ Machines Private Cloud Application Performance Monitoring for IWAN Track and Report Application Flows and Performance WAN Enterprise Edge AVC AVC CSR NetFlow/IPFIX Records (Same provisioning, same format) • Traffic statistics records • Application Response Time records • Media monitoring records (Application, Jitter, Loss, etc) Cisco Tools Prime, APIC-EM Partner Tools Ecosystem LiveAction Glue Networks Plixer Living Objects CompuWare CA Technologies Collecting Collecting Collecting Provisioning Exporting NetFlow v9 Export/IPFIX Export Branch DC/Headquarters AVC AVC 19
  • 19. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 Cisco WAAS Enhancing User Experience and WAN Efficiency Solution • Reduce load Data redundancy elimination (DRE), compression, and TCP optimization • Application optimization Fewer protocol messages and metadata caching Problem • Application latency • WAN bandwidth inefficiencies Application bandwidth with Cisco® WAAS Application bandwidth natively Application latency natively Application latency with Cisco WAAS 0 0 1 2 3 4 40 80 120 160 Application Bandwidth Application Latency Bandwidth (Mbps) Latency (Seconds) Reduction in bandwidth Reduction in latency 20
  • 20. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21 © 2010 Cisco Systems, Inc. All rights reserved. WAN Application-Specific Acceleration  Application and protocol awareness Eliminate unnecessary chatter Save WAN bandwidth Pre-populate edge cache as necessary Enable disconnected operations Intelligent protocol acceleration Read-ahead, prediction, and batching Safe data and metadata caching Improves application response time Provide origin server offload DRE Hints Application intelligence signals to DRE & LZ… whether to compress whether to cache Safe Caching Read-ahead Prediction Batching DRE Hinting WAN Optimization DRE/TFO/LZ Origin Server Offloaded Application Specific Acceleration
  • 21. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22 Email (5MB Attachment) File Services (5MB File) VDI (Citrix)(5MB Document) First Optimized with WAAS Send and Receive Email over native WAN Second Pass Optimized with WAAS 100 20 30 40 50 60 70 80 90 100 110 120 130 140 150 Time in Seconds Optimize and Enhance Thousands of Applications AX Includes Cisco WAAS WAN Optimization 24x Faster First Optimized with WAAS File Drag and Drop Over native WAN Second Pass Optimized with WAAS 100 20 30 40 50 60 70 80 90 100 110 120 130 140 150 Time in Seconds 17x Faster First Optimized with WAAS Sharepoint File Download over Native WAN Second Pass Optimized with WAAS Launch Citrix XenDesktop with WAAS Launch Citrix XenDesktop Over Native Citrix ICA/SSL Site Navigation with WAAS 20 4 6 8 10 12 14 16 18 20 22 24 26 28 30 Time in Seconds 30x Faster 20 4 6 8 10 12 14 16 18 20 22 24 26 28 30 Time in Seconds Site Navigation Over Native Citrix ICA/SSL 3-8x Faster
  • 22. Cisco Confidential 25© 2015 Cisco and/or its affiliates. All rights reserved. IWAN Secure Connectivity
  • 23. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26 Intelligent WAN: Secure Connectivity Securing the network and users Secure WAN Transport Branch MPLS (IP-VPN) Internet Secure Internet Access Private Cloud Virtual Private Cloud Public Cloud Two areas of concern 1. Protecting the network from outside threats with data privacy over provider networks 2. Protecting user access to Public Cloud and Internet services; malware, privacy, phishing,… 26
  • 24. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27 Securing IWAN Transports with Front-door VRF Isolation of external networks • Virtual Route Forwarding (VRFs) create multiple logical routers on a single device Separate control/data planes per VRF No connectivity between VRFs by default Provider side VRF (yellow) for external networks, Global VRF (blue) for internal networks • Provider VRF minimizes threat exposure Default routing only in Provider VRF Provider assigned IP addressing hides internal network Provider IP address used as IPSec tunnel source Only IPsec allowed between internal Global and Provider Front Side VRFs Global F-VRF Branch LAN 10.1.1.0/24 10.1.2.0/24 … Front Side Provider VRF Provider Assigned WAN IP Address 192.168.254.254 VRFs have independent routing and forwarding planes IPSec Tunnel Interface Global Enterprise VRF
  • 25. • Use ACLs, ZBFW or ASA to block all traffic except the DMVPN tunnel traffic to routers • Zone Based Firewall (ZBFW) at the branch if there are plans for direct Internet access • Typical ACL for protecting the Internet interface DSL Cable Branch ASR 1000 ASR 1000 ISP A ISP C Data Center Protecting the Public facing IWAN Interfaces interface GigabitEthernet0/0 ip vrf forwarding INET-PUBLIC1 ip access-group ACL-INET-PUBLIC in ! ip access-list extended ACL-INET-PUBLIC permit udp any any eq non500-isakmp permit udp any any eq isakmp permit esp any any permit udp any any eq bootpc permit icmp any any echo permit icmp any any echo-reply permit icmp any any ttl-exceeded permit icmp any any port-unreachable permit udp any any gt 1023 ttl eq 1
  • 26. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31 Intelligent WAN—Direct Cloud Access Branch MPLS (IP-VPN) Internet Direct Internet Access Private Cloud Virtual Private Cloud Public Cloud • Leverage Local Internet path for Public Cloud and Internet access • Improve application performance (right flows to right places) Solutions On Premise – Zone Based Firewall Cloud Based – Cloud Web Security CWS ISR-AX ZBFW 31
  • 27. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32 Secure Internet Access with Cisco Cloud Web Security (CWS) Secure Public Cloud and Internet Access ISR Connector to CWS Firewall towers Web Filtering, Access Policy, Malware Detect WAN1 (IP-VPN) CWS Private Cloud Public Cloud Branch WAN2 (Internet) IWAN IPsec VPN for Private Cloud TrafficIOS Firewall to protect Internet Edge Internet 32
  • 28. Cisco Confidential 33© 2015 Cisco and/or its affiliates. All rights reserved. Orchestration and Automation 3
  • 29. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34 Cisco IWAN Management Portfolio Covering a broad range of preferences and requirements • Customer wants advanced provisioning, life cycle management, and customized policies • System-wide network consistency assurance • Lean IT OR IT Network team Cisco Prime Infrastructure • Customer needs customizable IWAN with end-to-end monitoring • One Assurance across Cisco portfolio from Branch to Datacenter • IT Network team Enterprise Network Mgmt and Monitoring Ecosystem Partners IWAN App • Customer wants considerable automation and operational simplicity • Requirements consistent with prescriptive IWAN Validated Design • Lean IT organization Prescriptive Policy Automation • Customer looking for advanced monitoring and visualization • QoS/ PfR/ AVC configuration, Real-time analytics and network troubleshooting • IT Network team Application Aware Performance Mgmt Advanced Orchestration 3
  • 30. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35 Provisioning & Life Cycle Management Visualization & Health IWAN Management Solution Positioning CustomizablePrescriptive AdvancedFoundation Prime Prime IWAN AppOn Prem Cloud Infrastructure ASR 1000
  • 31. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36 APIC-EM IWAN App
  • 32. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37 APIC-EM IWAN App Site provisioning
  • 33. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 38 APIC-EM IWAN App Site provisioning
  • 34. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 39 APIC-EM IWAN App Site provisioning
  • 35. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 40 IWAN App – Site provisioning 4
  • 36. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41 IWAN App – Site provisioning 4
  • 37. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 42 IWAN App – Site provisioning 4
  • 38. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 43 APIC-EM IWAN App Define Application Policy • Business Intent  network admin informs the controller what applications are relevant for the business • The controller is going to perform background tasks based on this business logic
  • 39. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 44 APIC-EM IWAN App Define Application Policy • Define primary path for group of applications • The controller will create a PfR policy based on those paths.
  • 40. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 45 IWAN App Define Application Policy
  • 41. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 46 Prime Infrastructure for IWAN • IWAN workflow wizard with PnP • Template-based IWAN configs • PfRv3 Domain, MC and BR • AVC One-Click provision • QoS Provisioning • Single or Dual Router Branch • CVD-based, Customizable • AVC Readiness Assessment • AVC, QoS, PfR Visibility • Leverages APIC EM services 46
  • 42. Cisco Confidential 47© 2015 Cisco and/or its affiliates. All rights reserved. Cisco IWAN Product Portfolio 4
  • 43. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 48 Start with Cisco AX Routers IWAN Capabilities Embedded in the Router ISR-AX Simplify Application Delivery One Network UNIFIED SERVICES ASR1000-AX ISR-4000AX Transport Independent Secure Routing Optimization Control Visibility Cisco AX Routers 800 | 1900 | 2900 | 3900 | 4000 | ASR 1000
  • 44. Cisco Confidential 49© 2015 Cisco and/or its affiliates. All rights reserved. Why Cisco IWAN? 4
  • 45. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 50 Internet Intelligent WAN Summary Branch-1 Branch-513 DCI WAN Core MC MC 20M Dn 2M Up 512M FD BR BR ATBT MPLS Island ADSL BR ISR-AX vWAAS ISR-AX vWAAS 1.5M FD 256M FD CWS BR ASR-AX ASR-AX WAAS WAAS AVC AVC AVC ShowMe$$ DC-WestDC-East Internet Internet Transport Independent Design • Highly available Hybrid WAN Intelligent Path Control • Performance Routing (PfR) to protect applications and load balance traffic to maximize expensive WAN bandwidth Application Optimization • Application Visibility and Control (AVC) to monitor performance • WAAS + Akamai to reduce bandwidth consumption while improving application experience Secure Connectivity • Secure the network from outside threats • Cloud Web Security (CWS) for improved Cloud performance while freeing up WAN bandwidth, without compromising security IWAN Management • Cisco and Ecosystem Partner tools APIC-EM IWAN-APP, Prime, LiveAction, GlueWare, and more 5
  • 46. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 51 Branch MPLS (IP-VPN) Internet Private Cloud Virtual Private Cloud Public Cloud Cisco Intelligent WAN (IWAN) Secure WAN Transport Direct Internet Access Mixed Transport WAN with High Reliability SLAs for Business-Critical Applications Centralized Security Policy for Internet Access Dramatically Lower WAN Costs Without Compromise 51