SlideShare une entreprise Scribd logo
1  sur  39
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Software Defined Access (SDA)
TransformationalApproach to Network Design & Provisioning
Hendra Sugraha
Enterprise Network Systems Engineer, Cisco Systems
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
What is network about?
Today...In the past...
Voice
Video
Data
Mobility
Security
Cloud
IOT
Source: google.de images
Source: google.de images
What really matters !!!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Challenge.
“I want to design and deploy a network.”
Platform choices
Best practices
Manageable
Design options
On time
Future ready
Within budget
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Typical Traditional Campus
Data
Centre
WAN/BRANCH
Access
Points
Core
Switches
Aggregation
Switches
Access
Switches
WLC
ETHERCHANNEL
HSRP SPANNING TREECLI
L2/L3
AVC
VLANS
ACL
802.1x
FNF
Very powerful and feature
rich but:
- Complex to operate
- Difficult to scale
- Difficult to secure
- Inflexible and closed
architecture
- And you manage it all
with CLI…
Internet
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Traditional Network Design & Build Work Flow
spanning-tree mode rapid-pvst
spanning-tree portfast bpduguard default
udld enable
errdisable recovery cause all
vtp mode transparent
load-interval 30
Spanning Tree Protection across the LAN
access-list 55 permit 10.4.48.0 0.0.0.255
line vty 0 15
access-class 55 in
!
snmp-server community [SNMP RO] RO 55
snmp-server community [SNMP RW] RW 55
SNMPv2c access
ntp server 10.4.48.17
ntp update-calendar
!
clock timezone PST -8
clock summer-time PDT recurring
!
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
Global LAN Switch Configuration
vlan 10
name Data
vlan 20
name Voice
vlan 30
name Management
Uplink Interfaces
Mgmt VLAN 30
Data VLAN 10
Voice VLAN 20
Client Facing Interfaces
Access Layer Virtual LANs
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
How we build Traditional Network
Box by Box
Manual | Error Prone
ip domain-name cisco.local
no ip http server
ip http secure-server
ip ssh version 2
ip scp server enable
line vty 0 15
transport input ssh
transport preferred none
Manually
Repetitive Steps
CLI
Skill | Time | Effort
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Key Challenges for Traditional Networks
Difficult to Segment
Ever increasing number of
users and endpoint types
Ever increasing number of
VLANs and IP Subnets
Complex to Manage
Multiple steps,
user credentials, complex
interactions
Multiple touch-points
Slower Issue Resolution
Separate user policies for
wired and wireless networks
Unable to find users
when troubleshooting
Traditional Networks Cannot Keep Up!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco’s Intent-based Networking
Intent Context
Security
Learning
Network Infrastructure
DNA Center
AnalyticsPolicy Automation
Switching Routers Wireless
Powered by Intent.
Informed by Context.
The Network. Intuitive.
8
CISCO CONNECT 2018 . IT’S ALL YOU
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Intent-based Networking Model – Industry Approach
Activation
Physical and Virtual Infrastructure
Translation
Assurance
Orchestrate policies
& configure systems
Capture business intent,
translate to policies, and
check integrity Continuous verification,
insights & visibility, and
corrective actions
Cisco DNA
Intent-based Networking
Industry Initiative
9
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Campus
Fabric
Software Defined Access
Policy, Automation and Assurance for an
Intent-based Network Infrastructure
Intent-based
Network Infrastructure
DNA Center
AnalyticsPolicy Automation
I N T E N T C O N T E X T
S E C U R I T Y
L E A R N I N G
WAN
Branch
Wireless
Control
Fabric
Control
Wired + Wireless – Mobility – Segmentation – Scale
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Automated
Network Fabric
Single Fabric for Wired & Wireless
with Workflow-based Automation
Insights
& Telemetry
Analytics and insights into
user and application behavior
Identity-based
Policy & Segmentation
Decoupled security policy definition
from VLAN and IP Address
Software-Defined Access
Networking at the speed of Software!
DNA Center
AnalyticsPolicy Automation
IoT Network Employee Network
SDA-Extension User Mobility
Policy stays with
user
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
What is SD-Access?
Campus Fabric + DNA Center (Automation & Assurance)
APIC-EM
1.X
Campus
Fabric
ISE PI
Automation
Policy Assurance
DNA Center
B
C
B
 Campus Fabric
An Overlay network is a logical
topology used to virtually connect
devices
Separated management
systems
 SD-Access
GUI approach provides
automation & assurance of all
Fabric configuration,
management and group-based
policy
DNA Center integrates multiple
systems, to orchestrate your
LAN, Wireless LAN and WAN
access
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SD-Access
Fabric Roles & Terminology
Automation
Policy Assurance
Identity
Services
Intermediate
Nodes (Underlay)
Fabric Border
Nodes
Fabric Edge
Nodes
DNA
Center
Analytics
Engine
Control-Plane
Nodes
Fabric Wireless
Controller
Campus
Fabric
B
C
B  Control-Plane Nodes – Map System that
manages Endpoint to Device relationships
 Fabric Edge Nodes – A Fabric device
(e.g. Access or Distribution) that connects
Wired Endpoints to the SDA Fabric
 Identity Services – NAC & ID Systems
(e.g. ISE) for dynamic Endpoint to Group
mapping and Policy definition
 Fabric Border Nodes – A Fabric device
(e.g. Core) that connects External L3
network(s) to the SDA Fabric
 DNA Center – Enterprise SDN Controller
provides GUI management and abstraction
via Apps that share context
 Analytics Engine – Data Collectors
(e.g. NDP) analyze Endpoint to App flows
and monitor fabric status
 Fabric Wireless Controller – A Fabric device
(WLC) that connects APs and Wireless
Endpoints to the SDA Fabric
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Software-Defined Access
AssuranceAutomation Policy
Routers Switches Wireless AP WLC
DNA Center
DESIGN PROVISION POLICY ASSURANCE
DNA Center:
Simple Workflows
Solution Components
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
You Need a Network that Drives your Digital Business
With SDA Cisco Rewriting the Networking Playbook
Hardware Centric Software Driven
Manual (eg CLI) Automated
Silo’ed Security Integrated Security
Network Monitoring Analytics and Insights
Historicaly Digital-Ready Network
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Network Design & Build Work Flow
Assure
Assure
Design
Network Hierarchy
Network Settings
Image Management
Network Profiles
Policy
Virtual Networks
Access Control
Application Priority
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Network Design & Build Work Flow
Assure
Provision Assure
Provision
Device Onboarding
Host Onboarding
Device Inventory
Fabric Administration
Assurance
Network Health Score
Client 360
Device 360
Application 360
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Syslog
Server
SDA Design in DNA Center – Global Setup
AAA
Server
Site1
North
America
South
America
Site2
Africa
EMEAR
AAA
Server
DNS
Server
Syslog
Server
DHCP
Server
• Ability to Define
Global Settings
once and
replicate to all
sites/devices
• Automated
Provisioning
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
L2 Switch
L3 Switch
Trunks
Trunk
BYOD Employee Contractor
One SSID
Production
Servers
AAA
DHCP
AD
WLAN
Developer
Servers
LAN Core
Multiple Steps and
Touch Points
1. Define Groups in AD
2. Define Policies
 VLAN/subnet based
3. Implement VLANs/Subnets
 Create VLANs
 Define DHCP scope
 Create subnets and L3 interfaces
 Routing for new subnets
 Map SSID to Interface/VLAN
4. Implement Policy
 Define ACLs
 Apply ACLs
5. Many different User Interfaces
AAA WLC Devices CLI
….
What if You Need to Add Another Group & Policy?
Network Segmentation Policy RolloutToday
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
How SDA Simplifies Network Segmentation
Access Layer
Enterprise
Backbone
Voice
VLAN
Voice
Data
VLAN
Employee
Aggregation Layer
Supplier
Guest
VLAN
BYOD
BYOD
VLAN
Non-Compliant
Quarantine
VLAN
VLAN
Address
DHCP Scope
Redundancy
Routing
Static ACL
VACL
Security Policy based on Topology
High cost and complex maintenance
Voice
VLAN
Voice
Data
VLAN
Employee Supplier BYODNon-Compliant
Use existing topology and automate
security policy to reduce OpEx
ISE
No VLAN Change
No Topology Change
Central Policy Provisioning
Micro/Macro Segmentation
Employee Tag
Supplier Tag
Non-Compliant Tag
Access Layer
Enterprise
Backbone
DC Firewall / Switch
DC Servers
Policy
TrustSecTraditional Segmentation
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Employees Contractors Production Development
Source Destination
FABRIC NODES
Contract
CISCO
DNA CENTER
CISCO ISE
FABRIC POLICIES
PERMIT
Employees Production
Employees Production
API
POLICY DOWNLOAD
SDA Segmentation Policy Automation
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Network quality is a complex, end-to-end problem
* Both = Join/roam and quality/throughput
APs
Local WLCs
Network services DCOffice site
ISE
DHCP
Mobile clients
CUCM
Client firmware
AP coverage
WAN Uplink usage
WAN QoS, Routing, ...
End-User services
RF Noise/Interf.
Client density
...
Cisco Prime™
Configuration
Addressing
Authentication
Affects Join/Roam
Affects Quality/Throughput
WLC Capacity
Affects Both*
Affects Both*Affects Both*
Affects Both*
Affects Both*
Affects Quality/Throughput
Affects Quality/Throughput Affects Join/Roam
Affects Join/Roam
WAN
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
When users complain about Application Problem
Wireless Network Issue
Increased Latency
WAN Network Issue
Application Problem
Server Problem
User Problem
Network is so
slow I cannot get
any work done
today
I do not see
anything
wrong
End Users
Network
Admin
What the users see What network admins see What can happen
ping – OK
show ip route - OK
traceroute - OK
show interface - OK
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Reverse Path
Lookup
SDA Assurance Path Visualization
Enhanced App Flow Visibility
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Global health - Network and clients
Application and compliance health require DNA advantage.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Global health : Floor-level health score
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Client/Sensor/Device health
360 view
offers
complete
troubleshooti
ng info on a
per client
basis.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Application performance troubleshooting
Application Health shows you top
apps with performance issues.
From landing, drill down App Health to see
which applications have issues
1 2
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Ready Platforms
ASR-1000-X
ASR-1000-HX
ISR 4430
ISR 4450
WIRELESSROUTINGSWITCHING
AIR-CT5520
AIR-CT8540
Wave 2 APs (1800, 2800,3800)
Wave 1 APs* (1700, 2700,3700)
Catalyst 9400
Catalyst 9300
Catalyst 9500
Catalyst 4500E Catalyst 6K Nexus 7700
Catalyst 3850 and 3650
AIR-CT3504
CSR 1000V
*with Caveats
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9000 Platform
World’s Most Advanced Enterprise Switches
Catalyst 9300
Fixed Access
Catalyst 9400
Modular Access
Catalyst 9500
Fixed Core
Programmable Mobile Ready
Cloud Ready
Design
Integrated Security
IoT Ready
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Catalyst 9K Family
Catalyst 9300
Catalyst 9400
Catalyst 9500
Stackable Access Modular Access Fixed Aggregation
Built on Cisco’s Innovative UADP ASIC & Open IOS-XE
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
4000+
Customers
Wins
Gaining Momentum with the Catalyst 9000!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Some Early Recognitions…
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9300
1G Data
mGig UPOE
1G UPOE/POE+
2.5G at the
Price of 1G
40G at the
Price of 10G
New Generation of Fixed Access
24 Ports
Modular Power SuppliesModular UplinksModular Fans
UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics (ETA)*
256 bit MACSEC*
Trustworthy Systems
StackWise Virtual*
IEEE1588 & AVB*
NBAR2
Perpetual/Fast PoE
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry
48 Ports
8x10G 2x40G 4x mGig 4x1G 350W 715W 1100W
Only
Stackable
Switch with 8X
10G Uplinks
Highest
2.5G/mGig
Density in the
Industry
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9400
New Generation of Modular Access
4-Slot* 7-Slot 10-Slot
Power Supply
3200W AC
3200W DC*
2400W AC*
Core Linecards
24x 10G SFP+*
48x1G SFP*
24x1G SFP*
Access Linecards
24xmGig + 24xUPOE*
48xUPoE
48xPoE+*
48xData
Supervisor
Sup-1: 80G/Slot Access Optimized
Sup-1XL*: 120G/Slot Core
Optimized
Redundancy
is now
Table-stake
Industry’s
Highest PoE
Scale
9Tbps
System
b/w
UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics*
256 bit MACSEC*
Trustworthy
Systems
StackWise Virtual*
IEEE1588 & AVB*
NBAR2
Perpetual PoE*
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry*
*not available at FCS
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9500
Catalyst 9500-40X
Catalyst 9500-24Q
Catalyst 9500-12Q
New Generation of Purpose Built Fixed Core/Aggregation UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics*
256 bit MACSEC*
Trustworthy
Systems
StackWise Virtual
IEEE1588 & AVB*
NBAR2
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry*
40G at the
Price of 10G
8X Buffering
vs.
Competition
Industry’s
First 40G
Enterprise
Switch
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Current three-tier packaging
IP Services
Full Layer 3 and Advanced Networking
IP Base
Traditional Access and Basic Layer 3 features
LAN Base
L2 Features
Simplified two-tier packaging
DNA Essentials
Simplified Network Operations Solution Package
DNA Advantage
Software Defined Access, Assurance and ETA
Solution Package
Network Advantage
Full L3 with flexible Segmentation and Network
Resiliency
Network Essentials
Competitive Parity with Full L2 and Routed Access
Catalyst 9K: Simplified packaging
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Single
SKU
Prime
DNA Advantage
(Includes DNA Essentials)
DNA EssentialsDNA Essentials
Single
SKU
DNA Essentials
Cat 9K w/ Network Advantage
(Full Layer 3 Routing)
Cat 9K w/ Network Essentials
(Layer 2 & Routed Access)
Base Automation & Monitoring SDA & Assurance Capable
Stealthwatch
Single
SKU
ISE Base + ISE Plus
DNA Advantage
(Includes DNA Essentials)
SDA & Assurance Ready
DNA Advantage
Cisco ONE Advantage
Catalyst 9K Switching Software
Must Attach Cisco ONE Advantage or DNA Advantage or DNA Essentials as Subscription
with 9K
• Available in 3/5/7 year subscriptions
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Journey to the Software Defined Access (SDA)
Infrastructure
Readiness
Open and Programmable
Policy Based
Automation
Simplify, scale network deployment
for Cloud, Mobile, IoT
Intent-based
Network
Constantly learning,
adapting, protecting
Analytics
for Assurance
Predictive performance
with machine learning
Secure
Foundation
Rapid threat detection
and mitigation
Software-Driven Innovation

Contenu connexe

Tendances

Tendances (20)

Cisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WANCisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WAN
 
Cisco Connect 2018 Singapore - Cisco Incident Response Services
Cisco Connect 2018 Singapore - Cisco Incident Response ServicesCisco Connect 2018 Singapore - Cisco Incident Response Services
Cisco Connect 2018 Singapore - Cisco Incident Response Services
 
Cisco Connect 2018 Singapore - The Network Intuitive
Cisco Connect 2018 Singapore - The Network IntuitiveCisco Connect 2018 Singapore - The Network Intuitive
Cisco Connect 2018 Singapore - The Network Intuitive
 
Cisco Connect 2018 Singapore - Do more than keep the lights on
Cisco Connect 2018 Singapore - Do more than keep the lights onCisco Connect 2018 Singapore - Do more than keep the lights on
Cisco Connect 2018 Singapore - Do more than keep the lights on
 
Cisco Connect 2018 Singapore - delivering intent for data center networking
Cisco Connect 2018 Singapore -   delivering intent for data center networkingCisco Connect 2018 Singapore -   delivering intent for data center networking
Cisco Connect 2018 Singapore - delivering intent for data center networking
 
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud WorldCisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
 
Cisco Connect 2018 Singapore - En06 jason pernell
Cisco Connect 2018 Singapore - En06 jason pernellCisco Connect 2018 Singapore - En06 jason pernell
Cisco Connect 2018 Singapore - En06 jason pernell
 
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructureCisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined Access
 
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
 
Cisco Connect 2018 Singapore - Cisco CMX
Cisco Connect 2018 Singapore - Cisco CMXCisco Connect 2018 Singapore - Cisco CMX
Cisco Connect 2018 Singapore - Cisco CMX
 
TechWiseTV Workshop: Encrypted Traffic Analytics
TechWiseTV Workshop: Encrypted Traffic Analytics TechWiseTV Workshop: Encrypted Traffic Analytics
TechWiseTV Workshop: Encrypted Traffic Analytics
 
Интуитивная сеть как платформа для надежного бизнеса
Интуитивная сеть как платформа для надежного бизнесаИнтуитивная сеть как платформа для надежного бизнеса
Интуитивная сеть как платформа для надежного бизнеса
 
Cisco Connect Ottawa 2018 data centre security
Cisco Connect Ottawa 2018 data centre securityCisco Connect Ottawa 2018 data centre security
Cisco Connect Ottawa 2018 data centre security
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Laser Pioneer Secures Network End-to-End to Protect Assets
Laser Pioneer Secures Network End-to-End to Protect AssetsLaser Pioneer Secures Network End-to-End to Protect Assets
Laser Pioneer Secures Network End-to-End to Protect Assets
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Mfg workshop security
Mfg workshop   securityMfg workshop   security
Mfg workshop security
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 
TFI2014 Session II - Requirements for SDN - Jeff Doyle
TFI2014 Session II - Requirements for SDN - Jeff DoyleTFI2014 Session II - Requirements for SDN - Jeff Doyle
TFI2014 Session II - Requirements for SDN - Jeff Doyle
 

Similaire à Cisco Connect 2018 Indonesia - software-defined access-a transformational approach to network design and provisioning

Similaire à Cisco Connect 2018 Indonesia - software-defined access-a transformational approach to network design and provisioning (20)

Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
 
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
 
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
 
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
 
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Brkaci 1090
Brkaci 1090Brkaci 1090
Brkaci 1090
 
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIsIncredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
 
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Halifax 2018   Cisco dna - deeper diveCisco Connect Halifax 2018   Cisco dna - deeper dive
Cisco Connect Halifax 2018 Cisco dna - deeper dive
 
Cisco connect winnipeg 2018 simply powerful networking with meraki
Cisco connect winnipeg 2018   simply powerful networking with merakiCisco connect winnipeg 2018   simply powerful networking with meraki
Cisco connect winnipeg 2018 simply powerful networking with meraki
 
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WANCisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
 
Cisco Connect Toronto 2017 - Cisco meraki let simple work for you
Cisco Connect Toronto 2017 - Cisco meraki   let simple work for youCisco Connect Toronto 2017 - Cisco meraki   let simple work for you
Cisco Connect Toronto 2017 - Cisco meraki let simple work for you
 
Application Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centreApplication Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centre
 
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
 
Cisco Digital Network Architecture Deeper Dive From The Gates To The Gui
Cisco Digital Network Architecture Deeper Dive From The Gates To The GuiCisco Digital Network Architecture Deeper Dive From The Gates To The Gui
Cisco Digital Network Architecture Deeper Dive From The Gates To The Gui
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
 
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
 
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network IntuitiveCisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
 

Plus de NetworkCollaborators

Plus de NetworkCollaborators (14)

Cisco Connect 2018 Singapore - jordan koh
Cisco Connect 2018 Singapore -  jordan kohCisco Connect 2018 Singapore -  jordan koh
Cisco Connect 2018 Singapore - jordan koh
 
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
Cisco Connect 2018 Singapore -  Data center transformation a customer perspec...Cisco Connect 2018 Singapore -  Data center transformation a customer perspec...
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
 
Cisco Connect 2018 Philippines - ben green
Cisco Connect 2018 Philippines -  ben greenCisco Connect 2018 Philippines -  ben green
Cisco Connect 2018 Philippines - ben green
 
Cisco Connect 2018 Philippines - do more than keeping the lights on
Cisco Connect 2018 Philippines - do more than keeping the lights onCisco Connect 2018 Philippines - do more than keeping the lights on
Cisco Connect 2018 Philippines - do more than keeping the lights on
 
Cisco Connect 2018 Philippines - jaymen quah
Cisco Connect 2018 Philippines - jaymen quahCisco Connect 2018 Philippines - jaymen quah
Cisco Connect 2018 Philippines - jaymen quah
 
Cisco Connect 2018 Philippines - The workplace of the future
Cisco Connect 2018 Philippines - The workplace of the futureCisco Connect 2018 Philippines - The workplace of the future
Cisco Connect 2018 Philippines - The workplace of the future
 
Cisco Connect 2018 Philippines - fay ocampo
Cisco Connect 2018 Philippines - fay ocampoCisco Connect 2018 Philippines - fay ocampo
Cisco Connect 2018 Philippines - fay ocampo
 
Cisco Connect 2018 Philippines - delivering a secure, intelligent platform fo...
Cisco Connect 2018 Philippines - delivering a secure, intelligent platform fo...Cisco Connect 2018 Philippines - delivering a secure, intelligent platform fo...
Cisco Connect 2018 Philippines - delivering a secure, intelligent platform fo...
 
Cisco Connect 2018 Philippines - security keynote
Cisco Connect 2018 Philippines -   security keynoteCisco Connect 2018 Philippines -   security keynote
Cisco Connect 2018 Philippines - security keynote
 
Cisco Connect 2018 Philippines - Microsoft azure stack
Cisco Connect 2018 Philippines - Microsoft azure stackCisco Connect 2018 Philippines - Microsoft azure stack
Cisco Connect 2018 Philippines - Microsoft azure stack
 
Cisco Connect 2018 Philippines - cybersecurity strategy
Cisco Connect 2018 Philippines - cybersecurity strategyCisco Connect 2018 Philippines - cybersecurity strategy
Cisco Connect 2018 Philippines - cybersecurity strategy
 
Cisco Connect 2018 Philippines - next-generation customer care and the connec...
Cisco Connect 2018 Philippines - next-generation customer care and the connec...Cisco Connect 2018 Philippines - next-generation customer care and the connec...
Cisco Connect 2018 Philippines - next-generation customer care and the connec...
 
Cisco Connect 2018 Philippines - introducing cisco dna assurance
Cisco Connect 2018 Philippines - introducing cisco dna assuranceCisco Connect 2018 Philippines - introducing cisco dna assurance
Cisco Connect 2018 Philippines - introducing cisco dna assurance
 
Cisco Connect 2018 Philippines - Trends transforming it network data into bus...
Cisco Connect 2018 Philippines - Trends transforming it network data into bus...Cisco Connect 2018 Philippines - Trends transforming it network data into bus...
Cisco Connect 2018 Philippines - Trends transforming it network data into bus...
 

Dernier

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 

Dernier (20)

Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 

Cisco Connect 2018 Indonesia - software-defined access-a transformational approach to network design and provisioning

  • 1. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco Software Defined Access (SDA) TransformationalApproach to Network Design & Provisioning Hendra Sugraha Enterprise Network Systems Engineer, Cisco Systems
  • 2. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public What is network about? Today...In the past... Voice Video Data Mobility Security Cloud IOT Source: google.de images Source: google.de images What really matters !!!
  • 3. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Challenge. “I want to design and deploy a network.” Platform choices Best practices Manageable Design options On time Future ready Within budget
  • 4. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Typical Traditional Campus Data Centre WAN/BRANCH Access Points Core Switches Aggregation Switches Access Switches WLC ETHERCHANNEL HSRP SPANNING TREECLI L2/L3 AVC VLANS ACL 802.1x FNF Very powerful and feature rich but: - Complex to operate - Difficult to scale - Difficult to secure - Inflexible and closed architecture - And you manage it all with CLI… Internet
  • 5. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Traditional Network Design & Build Work Flow spanning-tree mode rapid-pvst spanning-tree portfast bpduguard default udld enable errdisable recovery cause all vtp mode transparent load-interval 30 Spanning Tree Protection across the LAN access-list 55 permit 10.4.48.0 0.0.0.255 line vty 0 15 access-class 55 in ! snmp-server community [SNMP RO] RO 55 snmp-server community [SNMP RW] RW 55 SNMPv2c access ntp server 10.4.48.17 ntp update-calendar ! clock timezone PST -8 clock summer-time PDT recurring ! service timestamps debug datetime msec localtime service timestamps log datetime msec localtime Global LAN Switch Configuration vlan 10 name Data vlan 20 name Voice vlan 30 name Management Uplink Interfaces Mgmt VLAN 30 Data VLAN 10 Voice VLAN 20 Client Facing Interfaces Access Layer Virtual LANs
  • 6. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU How we build Traditional Network Box by Box Manual | Error Prone ip domain-name cisco.local no ip http server ip http secure-server ip ssh version 2 ip scp server enable line vty 0 15 transport input ssh transport preferred none Manually Repetitive Steps CLI Skill | Time | Effort
  • 7. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Key Challenges for Traditional Networks Difficult to Segment Ever increasing number of users and endpoint types Ever increasing number of VLANs and IP Subnets Complex to Manage Multiple steps, user credentials, complex interactions Multiple touch-points Slower Issue Resolution Separate user policies for wired and wireless networks Unable to find users when troubleshooting Traditional Networks Cannot Keep Up!
  • 8. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco’s Intent-based Networking Intent Context Security Learning Network Infrastructure DNA Center AnalyticsPolicy Automation Switching Routers Wireless Powered by Intent. Informed by Context. The Network. Intuitive. 8 CISCO CONNECT 2018 . IT’S ALL YOU
  • 9. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Intent-based Networking Model – Industry Approach Activation Physical and Virtual Infrastructure Translation Assurance Orchestrate policies & configure systems Capture business intent, translate to policies, and check integrity Continuous verification, insights & visibility, and corrective actions Cisco DNA Intent-based Networking Industry Initiative 9
  • 10. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Campus Fabric Software Defined Access Policy, Automation and Assurance for an Intent-based Network Infrastructure Intent-based Network Infrastructure DNA Center AnalyticsPolicy Automation I N T E N T C O N T E X T S E C U R I T Y L E A R N I N G WAN Branch Wireless Control Fabric Control Wired + Wireless – Mobility – Segmentation – Scale
  • 11. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Automated Network Fabric Single Fabric for Wired & Wireless with Workflow-based Automation Insights & Telemetry Analytics and insights into user and application behavior Identity-based Policy & Segmentation Decoupled security policy definition from VLAN and IP Address Software-Defined Access Networking at the speed of Software! DNA Center AnalyticsPolicy Automation IoT Network Employee Network SDA-Extension User Mobility Policy stays with user
  • 12. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU What is SD-Access? Campus Fabric + DNA Center (Automation & Assurance) APIC-EM 1.X Campus Fabric ISE PI Automation Policy Assurance DNA Center B C B  Campus Fabric An Overlay network is a logical topology used to virtually connect devices Separated management systems  SD-Access GUI approach provides automation & assurance of all Fabric configuration, management and group-based policy DNA Center integrates multiple systems, to orchestrate your LAN, Wireless LAN and WAN access
  • 13. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SD-Access Fabric Roles & Terminology Automation Policy Assurance Identity Services Intermediate Nodes (Underlay) Fabric Border Nodes Fabric Edge Nodes DNA Center Analytics Engine Control-Plane Nodes Fabric Wireless Controller Campus Fabric B C B  Control-Plane Nodes – Map System that manages Endpoint to Device relationships  Fabric Edge Nodes – A Fabric device (e.g. Access or Distribution) that connects Wired Endpoints to the SDA Fabric  Identity Services – NAC & ID Systems (e.g. ISE) for dynamic Endpoint to Group mapping and Policy definition  Fabric Border Nodes – A Fabric device (e.g. Core) that connects External L3 network(s) to the SDA Fabric  DNA Center – Enterprise SDN Controller provides GUI management and abstraction via Apps that share context  Analytics Engine – Data Collectors (e.g. NDP) analyze Endpoint to App flows and monitor fabric status  Fabric Wireless Controller – A Fabric device (WLC) that connects APs and Wireless Endpoints to the SDA Fabric
  • 14. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Software-Defined Access AssuranceAutomation Policy Routers Switches Wireless AP WLC DNA Center DESIGN PROVISION POLICY ASSURANCE DNA Center: Simple Workflows Solution Components
  • 15. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU You Need a Network that Drives your Digital Business With SDA Cisco Rewriting the Networking Playbook Hardware Centric Software Driven Manual (eg CLI) Automated Silo’ed Security Integrated Security Network Monitoring Analytics and Insights Historicaly Digital-Ready Network
  • 16. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Network Design & Build Work Flow Assure Assure Design Network Hierarchy Network Settings Image Management Network Profiles Policy Virtual Networks Access Control Application Priority
  • 17. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Network Design & Build Work Flow Assure Provision Assure Provision Device Onboarding Host Onboarding Device Inventory Fabric Administration Assurance Network Health Score Client 360 Device 360 Application 360
  • 18. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Syslog Server SDA Design in DNA Center – Global Setup AAA Server Site1 North America South America Site2 Africa EMEAR AAA Server DNS Server Syslog Server DHCP Server • Ability to Define Global Settings once and replicate to all sites/devices • Automated Provisioning
  • 19. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public L2 Switch L3 Switch Trunks Trunk BYOD Employee Contractor One SSID Production Servers AAA DHCP AD WLAN Developer Servers LAN Core Multiple Steps and Touch Points 1. Define Groups in AD 2. Define Policies  VLAN/subnet based 3. Implement VLANs/Subnets  Create VLANs  Define DHCP scope  Create subnets and L3 interfaces  Routing for new subnets  Map SSID to Interface/VLAN 4. Implement Policy  Define ACLs  Apply ACLs 5. Many different User Interfaces AAA WLC Devices CLI …. What if You Need to Add Another Group & Policy? Network Segmentation Policy RolloutToday
  • 20. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU How SDA Simplifies Network Segmentation Access Layer Enterprise Backbone Voice VLAN Voice Data VLAN Employee Aggregation Layer Supplier Guest VLAN BYOD BYOD VLAN Non-Compliant Quarantine VLAN VLAN Address DHCP Scope Redundancy Routing Static ACL VACL Security Policy based on Topology High cost and complex maintenance Voice VLAN Voice Data VLAN Employee Supplier BYODNon-Compliant Use existing topology and automate security policy to reduce OpEx ISE No VLAN Change No Topology Change Central Policy Provisioning Micro/Macro Segmentation Employee Tag Supplier Tag Non-Compliant Tag Access Layer Enterprise Backbone DC Firewall / Switch DC Servers Policy TrustSecTraditional Segmentation
  • 21. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Employees Contractors Production Development Source Destination FABRIC NODES Contract CISCO DNA CENTER CISCO ISE FABRIC POLICIES PERMIT Employees Production Employees Production API POLICY DOWNLOAD SDA Segmentation Policy Automation
  • 22. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Network quality is a complex, end-to-end problem * Both = Join/roam and quality/throughput APs Local WLCs Network services DCOffice site ISE DHCP Mobile clients CUCM Client firmware AP coverage WAN Uplink usage WAN QoS, Routing, ... End-User services RF Noise/Interf. Client density ... Cisco Prime™ Configuration Addressing Authentication Affects Join/Roam Affects Quality/Throughput WLC Capacity Affects Both* Affects Both*Affects Both* Affects Both* Affects Both* Affects Quality/Throughput Affects Quality/Throughput Affects Join/Roam Affects Join/Roam WAN
  • 23. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU When users complain about Application Problem Wireless Network Issue Increased Latency WAN Network Issue Application Problem Server Problem User Problem Network is so slow I cannot get any work done today I do not see anything wrong End Users Network Admin What the users see What network admins see What can happen ping – OK show ip route - OK traceroute - OK show interface - OK
  • 24. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Reverse Path Lookup SDA Assurance Path Visualization Enhanced App Flow Visibility
  • 25. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Global health - Network and clients Application and compliance health require DNA advantage.
  • 26. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Global health : Floor-level health score
  • 27. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Client/Sensor/Device health 360 view offers complete troubleshooti ng info on a per client basis.
  • 28. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Application performance troubleshooting Application Health shows you top apps with performance issues. From landing, drill down App Health to see which applications have issues 1 2
  • 29. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Ready Platforms ASR-1000-X ASR-1000-HX ISR 4430 ISR 4450 WIRELESSROUTINGSWITCHING AIR-CT5520 AIR-CT8540 Wave 2 APs (1800, 2800,3800) Wave 1 APs* (1700, 2700,3700) Catalyst 9400 Catalyst 9300 Catalyst 9500 Catalyst 4500E Catalyst 6K Nexus 7700 Catalyst 3850 and 3650 AIR-CT3504 CSR 1000V *with Caveats
  • 30. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9000 Platform World’s Most Advanced Enterprise Switches Catalyst 9300 Fixed Access Catalyst 9400 Modular Access Catalyst 9500 Fixed Core Programmable Mobile Ready Cloud Ready Design Integrated Security IoT Ready
  • 31. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Catalyst 9K Family Catalyst 9300 Catalyst 9400 Catalyst 9500 Stackable Access Modular Access Fixed Aggregation Built on Cisco’s Innovative UADP ASIC & Open IOS-XE
  • 32. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU 4000+ Customers Wins Gaining Momentum with the Catalyst 9000!
  • 33. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Some Early Recognitions…
  • 34. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9300 1G Data mGig UPOE 1G UPOE/POE+ 2.5G at the Price of 1G 40G at the Price of 10G New Generation of Fixed Access 24 Ports Modular Power SuppliesModular UplinksModular Fans UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics (ETA)* 256 bit MACSEC* Trustworthy Systems StackWise Virtual* IEEE1588 & AVB* NBAR2 Perpetual/Fast PoE Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry 48 Ports 8x10G 2x40G 4x mGig 4x1G 350W 715W 1100W Only Stackable Switch with 8X 10G Uplinks Highest 2.5G/mGig Density in the Industry
  • 35. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9400 New Generation of Modular Access 4-Slot* 7-Slot 10-Slot Power Supply 3200W AC 3200W DC* 2400W AC* Core Linecards 24x 10G SFP+* 48x1G SFP* 24x1G SFP* Access Linecards 24xmGig + 24xUPOE* 48xUPoE 48xPoE+* 48xData Supervisor Sup-1: 80G/Slot Access Optimized Sup-1XL*: 120G/Slot Core Optimized Redundancy is now Table-stake Industry’s Highest PoE Scale 9Tbps System b/w UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics* 256 bit MACSEC* Trustworthy Systems StackWise Virtual* IEEE1588 & AVB* NBAR2 Perpetual PoE* Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry* *not available at FCS
  • 36. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9500 Catalyst 9500-40X Catalyst 9500-24Q Catalyst 9500-12Q New Generation of Purpose Built Fixed Core/Aggregation UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics* 256 bit MACSEC* Trustworthy Systems StackWise Virtual IEEE1588 & AVB* NBAR2 Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry* 40G at the Price of 10G 8X Buffering vs. Competition Industry’s First 40G Enterprise Switch
  • 37. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Current three-tier packaging IP Services Full Layer 3 and Advanced Networking IP Base Traditional Access and Basic Layer 3 features LAN Base L2 Features Simplified two-tier packaging DNA Essentials Simplified Network Operations Solution Package DNA Advantage Software Defined Access, Assurance and ETA Solution Package Network Advantage Full L3 with flexible Segmentation and Network Resiliency Network Essentials Competitive Parity with Full L2 and Routed Access Catalyst 9K: Simplified packaging
  • 38. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Single SKU Prime DNA Advantage (Includes DNA Essentials) DNA EssentialsDNA Essentials Single SKU DNA Essentials Cat 9K w/ Network Advantage (Full Layer 3 Routing) Cat 9K w/ Network Essentials (Layer 2 & Routed Access) Base Automation & Monitoring SDA & Assurance Capable Stealthwatch Single SKU ISE Base + ISE Plus DNA Advantage (Includes DNA Essentials) SDA & Assurance Ready DNA Advantage Cisco ONE Advantage Catalyst 9K Switching Software Must Attach Cisco ONE Advantage or DNA Advantage or DNA Essentials as Subscription with 9K • Available in 3/5/7 year subscriptions
  • 39. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Journey to the Software Defined Access (SDA) Infrastructure Readiness Open and Programmable Policy Based Automation Simplify, scale network deployment for Cloud, Mobile, IoT Intent-based Network Constantly learning, adapting, protecting Analytics for Assurance Predictive performance with machine learning Secure Foundation Rapid threat detection and mitigation Software-Driven Innovation

Notes de l'éditeur

  1. This is a typical campus network that many of our customers & you will be familiar with. [Build slide up showing different layers, protocols, policy, management, controller etc…] Whilst the network is critical for every business and offers powerful features, enterprise networks are complex and we have tied policy to an IP address - that is why you build with VLAN’s, per switch, you put subnets against ACL’s, you implement Spanning-Tree and then HSRP, VSS, the list goes on… And there we see it. Very powerful and feature rich but: Complex to operate Difficult to scale Difficult to secure Inflexible and closed architecture And you manage it all with CLI…
  2. In Cisco’s view, a complete intent-based network (Figure 1) needs to deliver on 3 essential functions: Translation: The Translation function is about the characterization of intent. It enables network operators to express intent in a declarative and flexible manner, expressing what the expected networking behavior is that will best support the business objectives, rather than how the network elements should be configured to achieve that outcome.The captured intent then needs to be interpreted into policies that can be applied across the network Activation:. The Activation function installs these policies into the physical and virtual network infrastructure using a networkwide automation engine. Assurance: In order to continuously check that the expressed intent is honored by the network at any point in time, the Assurance function maintains a continuous validation-and-verification loop. Context derived from telemetry data is used to check alignment of operation with intent. For many enterprises, the evolution to a fully intent-based network will be a journey, requiring a combination of new technologies and process changes.  The full potential of intent-based networking is recognized when deployed across all network domains, including data center, campus, branch, and WAN.  Cisco’s solutions help customers achieve end-to-end intent-based networking based on Cisco’s open platform and third-party technologies.   Data Center   Cisco Network Assurance Engine (NAE) Provides always-on assurance for data centers. NAE predicts the impact of changes, proactively verifies network behavior, and helps assure policy and compliance. Cisco Application Centric Infrastructure (Cisco ACI) Policy-based automated network fabric, covering the translation and deployment phases of the intent-based network framework. Cisco Tetration platform Dramatically improves data center security by enabling zero-trust operations and real-time visibility. Using behavior-based application insights and machine learning, it provides customers with a whitelist policy model, enabling segmentation through automated policy enforcement.   Enterprise Networks   Cisco Digital Network Architecture (Cisco DNA) Intent-based networking platform for enterprise campus and WAN environments, providing automation and analytics for wired and wireless, software-defined access, and software-defined WAN domains. Cisco’s Identity Services Engine (ISE) provides identify-based policy and rich contextual information.   Cisco Services [this should be the same level as DC and EN above] New Cisco Services help you accelerate network assurance, gain analytical insight, improve productivity, and lower risk by leveraging our unique expertise, best practices, innovative tools, and business and IT insights.   Learn more about intent-based networking https://www.cisco.com/go/intentbasednetworking
  3. There are 2 main components of SD-Access: Campus Fabric + DNA Center. Campus Fabric are all of the features and protocols (control-plane, data-plane, policy-plane) to operate the network infrastructure. DNA Center provides all of the wired & wireless automation & assurance aspects, along with Cisco ISE for security aspects. If you manage the solution via the CLI or API, it is considered Campus Fabric. If you manage the Campus Fabric with DNA Center, it is SD-Access!
  4. Traditional segmentation could be based on topology. Those could be VLANs, Subnets, VRF, and statically configured Access Control List. When you create a VLAN, you can definitely isolates endpoints as long as you configure those VLANs are not communicating. VLAN is easy to setup in the lab. But in a real world, when you are trying to setup additional VLAN to implement security policy, you are not just adding one VLAN. You need same VLAN per floor, per building, and per location. Adding VLAN involves additional adjustments in the topology. You have to make sure that you have enough address space for those VLANs, changes in DHCP pools (and possibly DNS), probably adding VLAN to gateway redundancy like HSRP, and adding segments to the routing. After all of those additional works, you will use VACL or L3 IP ACL statically to enforce traffic. You want to make sure that you have enough TCAM space on the box. And you are going to keep adding ACL again, and again, and again… We’ve been seeing customers trying to understand what those 1000’s lines of ACLs on their routers because IP address does not tell you exactly what’s behind it. Even servers or applications are decommissioned, you are keeping those ACLs because you don’t know exactly what type of security hole you are making. With TrustSec, you can simply leverage your customer’s existing VLAN design. We simply assign SGT or Security Group Tag to the endpoints (not just endpoint but also destination as well) and user such tag information to enforce traffic. ISE automates the whole ACL provisioning process. When a device is connected, then switch will ask ISE what type of policy ISE has for this endpoint. If there is any policy exists, then switch automatically get that policy right away.
  5. All this is changing (mobile, VDI, cloud) is real and coming now. To reduce your costs, you need to look at your WAN BW costs because that’s where the money is being spent! So let’s talk about what we can do to manage that...
  6. What’s great about SDA is that you can get started today. @ C3K – Includes all models of C3650 & 3850 (copper) family, with C3K scale & features (UADP 1.0 or 1.1) @ C9K – Includes all models of C9300 & 9400 (copper) family, with C9K scale & features (UADP 2.0) @ C4K – Includes all models of C4500-E series chassis. C6500-E requires Sup8E or Sup9E uplinks for fabric encap (FGPA on Sup ONLY). Other cards (e.g. WS-X4700) can be used for non-fabric connections (outside). @ C6K – Includes C6880-X and all models of C6840-X-LE family. Includes all models of C6500-E series chassis. C6807-XL / 6500-E requires Sup2T or Sup6T, with C6800 10G or WS-X6900 cards for fabric encap (FGPA on PFC4/DFC4). Other cards (e.g. WS-X6700) can be used for non-fabric connections (outside). @ ASR1K – Only X or HX series. Includes 1001-X or 1002-X. Does not include other/older ASR1000 (non-X) series. @ ISR4K – Only 4400 series. Includes 4431 and 4451. Does not include other/older models of ISR (e.g. G2) series. NOTE: CSRv & ISRv (IOS CSR / ISR Virtual Machine) is also an option, but is not currently listed due to inherent underlay/reachability complexities (between network [RLOC] to remote CP node [e.g. via DC]) @ N7K – Includes all models of N7700 series chassis. Does not include N7000 series. N7700 requires Sup2E, with M3 cards for fabric encap (F3 SOC 2.0). Other cards (e.g. F3) can be used for non-fabric connections (outside).
  7. SLIDE 4: Catalyst 9000 While our intent driven IOS software can be deployed on existing equipment to transform deployed networks, we are also announcing a new lineup of our award willing Catalyst campus switches – the 9000 series. Built from the ground up for the world of cloud, IoT, Mobility and Advanced Persistent Threats these platforms are the most advanced enterprise switches in the world. ----------------------------------------------------------- Key innovations include: Programmable: High-performance, programmable ASICs. Cisco’s own ASIC for maximum performance and feature richness. It’s programmable to adapt to future innovations, a breakthrough in silicon technology. Integrated Security: Rapid threat detection with Encrypted Traffic Analytics. We’ll say more about this later – the ability for the network to find and block the most sophisticated cyber-attacks. IoT Ready: Instantly discover, onboard, and automatically segment IoT traffic. Built for IoT and the huge diversity of devices that will connect to enterprise networks. The ability to automatically configure the network for security – separating IoT devices from other traffic. Mobile Ready: Built-in wired and wireless controller. Cloud Ready: Secure Access to Cloud Apps 3rd Party App Hosting. These platforms are built for extensibility and open computing. They can host third party applications on a built in x86 compute complex. Allowing our customers to run their applications in containers or virtual machines. We can now extend the cloud all the way to the user. Design: With these platforms we’ve taken a user-centered design approach every step of the way – from the software design to the operations to even the hardware design. The physical chassis have been designed and engineered by the famous Italian design firm Pininfarina to make them easy to install and maintain
  8. http://wikicentral.cisco.com/display/PROJECT/Cetus+%28C6807-XL%29
  9. http://wikicentral.cisco.com/display/PROJECT/Cetus+%28C6807-XL%29
  10. How should customers implement our vision for a more intuitive network….Its through a phased approach Infrastructure Readiness – To get to the network intuitive, you need to have the right infrastructure foundation in place – one that is flexbile, available, secure, and scalable. The Cisco infrastructure provides an open and programmable infrastructure which enables the powerful software-driven value around security, automation, and analytics. Secure Foundation - The enterprise has become a loosely coupled collection of networks and clouds, the business actors have changing roles. This is why the cloud-agile network we envision needs to rely on a flexible, powerful policy model, and pervasively deliver security everywhere to support a network as a sensor/enforcer. Policy Based Automation – the concept of a digital business wouldn’t even exist without the universal connectivity we have so successfully delivered on. Our networks are the engines that connect digital business to their customers, and we are looking to automate everywhere we can with our APIC EM controller strategy to simplify and speed up IT. With automation business intent can be translated into network configurations immediately, dynamically. Network services like IWAN can more efficiently use bandwidth or EasyQoS can dynamically update the network for application prioritization. Analytics for Assurance - With DNA Center, Automation, and Analytics and Assurance, only Cisco combines analytics and network automation into a single, closed loop network management solution to power the self-driving network. Actionable insights from DNA Analytics and Assurance are driven by 30years of Cisco domain expertise. This foundation delivers the a more intuitive network, a network that is constantly learning, adapting and protecting. The NETWORK. INTUITIVE.