Professional Documents
Culture Documents
10B 90%
Mobile-connected Growth in mobile
devices by 2019
MORE 73% devices from
DEVICES 2014-2018
of revenue
is generated
Up to Annual increase in in the branch Of employee and
MORE 80%
50% enterprise bandwidth
and video adoption USERS
customers are served in
branch offices
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2
Software Defined WAN
Internet
Public
Direct Internet
Cloud
Access
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
SD-WAN
Business Case
• Substitute lower cost links or devices for higher cost
Cost •
•
Lower cost of management, troubleshooting
Leverage Complete Communications for financial analysis
Cisco Digital
Network Architecture
Complements Cisco’s Enterprise Networks architecture strategy
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
Better Together
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7
Now What About IWAN
• Cisco IWAN has over 200,000 sites deployed or in
deployment
• No plans to EOL or EOS – 3+ years of support
• IWAN 2.x & IWAN App support and roadmap will continue
as per prior customer commitments
Direct Cloud Access, Scale Increase, Hardening, MC Placement, APIC behind NAT
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8
Cisco’s New SD-WAN Architecture
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
Common WAN Topologies
Design and Deployment Considerations
Design Challenges with Growing Needs and New Innovation
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10
Common WAN Topologies
Growing Complexity - Scale, Policy, Segmentation
Complexity Grows with Scale and Changing Business Requirements
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11
Business Driven WAN Infrastructure
Analytics
Application Traffic Per-Segment Secure Cloud Path Cloud Accel Transport
SLA Engineering Topologies Perimeter (IaaS) (SaaS) Hub
APPLICATION POLICIES
Monitoring
Routing Security Segmentation QoS Multicast Svc Insertion Survivability
vSmart
vEdge
Orchestration Plane
MANAGEMENT
vBond
API
Management Plane
(Multi-tenant or Dedicated) ANALYTICS
ORCHESTRATION vAnalytics
Control Plane
(Containers or VMs)
CONTROL
INTERNET MPLS 4G
Data Plane
(Physical or Virtual)
Data Center Campus Branch Home Office
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13
Orchestration Plane
Orchestration Plane
vManage
Cisco vBond
APIs
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
Management Plane
Management Plane
vManage
Cisco vManage
APIs
• Single pane of glass for Day0,
3rdParty Day1 and Day2 operations
vAnalytics
Automation
• Real time alerting
vBond • Centralized provisioning
• Configuration standardization
vSmart Controllers • Simplicity of deploying
• Simplicity of change
4G
• Supports
MPLS
• REST API
INET • CLI
vEdge Routers • Syslog
• SNMP
• NETCONF
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
Control Plane
Control Plane
vManage
Cisco vSmart
APIs
• Centralized brain of the solution
3rd Party
vAnalytics • Facilitates fabric discovery
Automation
• Establishes OMP peering with all
vBond vEdges
• Implements control plane policies,
vSmart Controllers such as service chaining, traffic
engineering and per VPN topology
MPLS 4G • Dramatically reduces complexity of
INET the entire network
vEdge Routers • Distributes connectivity information
between vEdge
• Orchestrates secure data plane
Cloud Data Center Campus Branch SOHO
connectivity between vEdges
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
Overlay Management Protocol (OMP)
Unified Control Plane
vSmart
• Runs on top of TCP, extensible control plane
protocol
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
- Inside TLS/DTLS connections
vSmart vSmart • Advertises control plane context
VS
vEdge vEdge
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19
Secure Segmentation
End-to-End Segmentation
VPN 1
Interface VPN1 SD-WAN VPN1 Interface
IPSec VPN 2
VLAN VPN2 Tunnel VPN2 VLAN
VPN 3
Ingress Egress
vEdge vEdge
• Segment connectivity across fabric w/o • Labels are used to identify VPN for
reliance on underlay transport destination route lookup
• vEdge routers maintain per-VPN routing • Interfaces and sub-interfaces (802.1Q tags)
table are mapped into VPNs
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Application Aware Topologies
Arbitrary VPN Topologies
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
Cloud onRamp for SaaS
SaaS Optimization
ISP1 ISP1
SD-WAN SD-WAN
ISP2 Fabric MPLS Fabric
Data Center Data Center
Remote Site Remote Site
FW
VPN1
Regional VPN1
Hub
Data
Center
VPN1 MPLS INET
App 3,000
vEdge Router
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
Policy Driven WAN Infrastructure
Policy Augmented Dynamic Routing
1 vManage GUI – Policy Orchestration
3
vEdge
WAN Execute AAR and Data Policy as received
router Dynamic Routing and Policies Combine to
dictate behavior
Access Layer
Branch/DC
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
A Flexible Model for Applications Over the WAN
Per-Session Loadsharing Per-Session Weighted Application Pinning Application Aware Routing
Active/Active Active/Active Active/Standby SLA Compliant
SLA SLA
Core
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
Critical Applications SLA
Path Quality Detection Routing
vManage
App Aware Routing Policy
§ Enforce SLA compliant path App A path must have:
for applications of interest latency < 150ms
loss < 2%
§ Other applications will follow jitter < 10ms
fabric routing across all vSmart Controllers
paths
Internet
vEdge1 vEdge2
Path 2 MPLS
App A
4G LTE
High Delay
Detected High Jitter
Detected
Business App and Load-Balancing Policy Multimedia and Critical Data Policy
• Protect transactional • Increase WAN bandwidth • Protect voice and • Voice and video preferred
business app from brownouts efficiency by load-sharing traffic video quality path SP1
Latency < 150 ms • Email preferred path ISP
delay < 250ms over all WAN paths, MPLS +
Jitter < 20 ms • Increase utilization
• Preferred path MPLS Internet
• Protect Email applications by load sharing
from WAN congestion
Loss < 5%
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29
Application Optimization
TCP Performance Optimization
Optimized
TCP Connections TCP Connections (Cubic) TCP Connections
SD-WAN
Fabric
Users vEdge vEdge Servers
High Latency Path
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31
Zero Touch Provisioning
Plug-n-Play vEdge Secure Bring-up (Zero Trust)
Administrator Installer
ZTP Identity Trust
Server
vManage
DHCP
TPM
vEdge
Identity
vSmart vBond (X.509)
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32
Template-Based Configurations
Centralized Device Configuration Enforcement
• Templates are attached to provisioned
vEdge routers
• Variables are used for rapid bulk
configuration rollout with unique per-
device settings
• Local configuration changes are not
allowed
- Prevents configuration drift
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33
Single Pane of Glass Operations
vManage GUI
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
vAnalytics Dashboard
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
Cisco SD-WAN Elements
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36
Summary: Solution Elements
Orchestration, Control, Data and Management Planes
Control Plane Data Plane
Orchestration Plane Management Plane Physical/Virtual
Cisco vSmart Cisco vEdge
Cisco vBond Cisco vManage
• Facilitates fabric discovery • WAN edge router
• Single pane of glass for
• Orchestrates control and • Dissimilates control plane
Day0, Day1 and Day2 • Provides secure data plane
management plane information between vEdges
operations with remote vEdge routers
• First point of authentication • Distributes data plane and app-
• Centralized provisioning • Establishes secure control
(white-list model) aware routing policies to the
• Policies and Templates plane with vSmart controllers
• Distributes list of vSmarts/ vEdge routers (OMP)
vManage to all vEdge routers • Troubleshooting and
• Implements control plane • Implements data plane
Monitoring
• Facilitates NAT traversal policies, such as service policies
• Software upgrades chaining, multi-topology and
• Requires public IP Address • Exports performance statistics
[could sit behind 1:1 NAT] • GUI with RBAC multi-hop
• Leverages traditional routing
• Highly resilient • Programmatic interfaces • Dramatically reduces control
protocols like OSPF, BGP and
(REST, NETCONF) plane complexity
VRRP
• NMS interfaces (SNMP, • Highly resilient
• Support Zero Touch
Syslog, IPFIX)
Deployment
• Physical or Virtual form factor
(100Mb, 1Gb, 10Gb)
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37
Cisco vEdge Routers Portfolio
Branch/SOHO/SMB Branch/Campus Campus/Data Center Campus/Data Center NFV, vCPE IaaS & Cloud
(100Mb) (1Gb) (10Gb) (20Gb+) (N x cores) Interconnect
(N x cores)
vEdge Cloud on
vEdge 100 family vEdge 1000 vEdge 2000 vEdge 5000 Greybox or vEdge Cloud
Whitebox
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 38
vEdge Cloud Virtual Routers
Virtualized Branch or Cloud
On-Premise Hosted
vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud
VM Throughput: VM
Physical Server 2x vCPU 500Mb/s
4x vCPU 1Gb/s
8x vCPU 1.5Gb/s
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 39
Controllers
Cloud or On-Premise Delivered
On-Premise Hosted
vBond* vManage vSmart vSmart vBond vManage vSmart vSmart
VM VM
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41
Scalability
Orchestration/Control/Management Plane
Orchestration Plane Management Plane Control Plane
(vBond) (Multi-tenant or Dedicated) (Containers or VMs)
(vManage) (vSmart)
2000 vEdges per vBond 2700 vEdges per vManage 2700 vEdges per vSmart
Redundancy Add 1-2 vBonds Redundancy Add 1-2 vSmarts
Horizontal Scale out Model
Horizontal Scale out Model in cluster mode (same DC) Horizontal Scale out Model
4G/LTE Internet
MPLS
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 44
Viptela Integration Plan
Phase 1 Phase 2 Phase 3
No Integration Platform Integration Management Integration
Deployment Scenarios
DNA Center
vManage vManage
+ SD-WAN
Support current Viptela Viptela SD-WAN on strategic ISR Deliver end-to-end experience
customers platform with full DNA integration
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 46
SD-WAN Evolution
6-12 months Target 12-24 months Planning
Analytics
SDWAN + SDA EN wide Multi-cloud connect
Arch Evolution
Leapfrog With
DNA Center
+ SD-WAN
Voice, App acceleration Platform diversity Appliance security
ZBF, URL filtering, IPS/IDS SAE
Innovate With
Portfolio
Core SDWAN
Analytics One-click
Easy Troubleshooting & Ops Visibility Cloud Networking VDI Acceleration Scale cloud-ops
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 47
SD-WAN Fabric Integration with DNA
USERS Cloud Delivered Analytics
DC
SDA Fabric ACI Fabric
(branch & campus) IoT
SDWAN
Cloud
.…
DC
DEVICES
IaaS
SDWAN Fabric APPs
SaaS
SDA Fabric
(branch & campus)
THINGS
SECURE SCALE OPEN vDC
End-to-end Context
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Thank you.