Professional Documents
Culture Documents
Users Applications
Users
WAN
Mobile Users
Applications Moved to Not One Cloud, But Many
DC/Private Cloud
Mobile Users
IaaS
Resulting a Highly Complex and Dynamic Network
Campus
X2-5
DC/Private Cloud
Branches X100+
Internet connectivity
becomes
business critical SaaS
Mobile
Users
X1000s
IaaS
DC/Private Cloud
Branches X100+
GreaterSecurity
risk exposure
Cloud Edge
Inconsistent
Networking
user experience
SaaS
Increasing
Cloud
complexity
Mobile
Users
X1000s
IaaS
Cisco
Umbrella
Branch | Colo
Users
Internet
Branch/Campus Gateway
Colocation
Data Center
One way
Users
Gateway
Data Center
Branch/Campus
Colocation
4. Security Everywhere
Cloud
Security
Firewall/IPS UTM Pro: Efficient traffic flows for experience
Con: Difficult to maintain policy
How can IT maintain choice and control connecting a cloud first world?
Combining Best-of-Breed in Security & SD-WAN
Enterprise Firewall
Classification of +1400 layer 7 apps
Security URL-Filtering
Web reputation score using 82+ web
categories
New New
ISR 1111X-8P ISR 4461
Compact fixed branch platform with rich Highest performing and scalable modular
services, integrated Wi-Fi and LTE branch platform with storage and compute
Available now, starting price: $1595 list USD Available now, starting at $24K list USD
Meraki MX ENCS 5000 Public Cloud vEdge ISR 1000 ISR 4000 ASR 1000
PLUS:
Partners
Dev Center
Ecosystem exchange
Opportunity for Managed Service Providers
Security SD-WAN
$6B in 2016 $225M in 2015
$10.8B in 2022 $8B in 2021
9.7% CAGR 69% CAGR
Now let’s take a closer
look at security
Kureli Sankar
Internet
• Zone Policies
Inspect policy allows
only return traffic to Outside Zone
• Application Visibility and Granular be allowed and drops
control any new connections
URL Filtering
• 82+ Web Categories with dynamic
updates
White/Black lists of
custom URLs
• Block based on Web Reputation score
DNS/web-
Ent FW App URL
Platforms/Features Ent FW IPS/IDS layer
Awareness Filtering
Monitoring *
Viptela - (100, 1000, 2000 and 5000) DPI using Qosmos
Y N/A N/A Y
**
Cisco - CSR
Y Y Y Y Y
Cisco – ENCS (ISRv)
Y Y Y Y Y
Cisco – ISR4K (4451, 4431, 4351, 4331,
Y Y Y Y Y
4321, 4221-X)
Cisco – ISR1K (1111X-8P)
Y Y Y Y Y
Cisco - ASR1K 1001-HX, 1002-HX, 1001-X,
Y Y N/A N/A Y
1002-X)
** Stateful Firewall and DPI using Qosmos are separate on the vEdge
* Need Umbrella Subscription for enforcement
© 2018 Cisco and/or its affiliates. All rights reserved.
Protecting Workers Wherever They Are…
Unified
Access Data Center/
Security Private Cloud
SD-WAN and
Firewall/IPS/URL Filtering
Branch/Campus
Cisco
Internet/SaaS
Umbrella
IaaS
Home/Mobile
Secure Internet GW
Combined Security and SD-WAN Licensing
Centralized Management Secure Connectivity Policy Based Automation Analytics and Assurance
• Advanced network and • Network optimization analytics
• On-prem or cloud managed • Unlimited segmentation application visibility • Application trending and
• Zero touch deployment • WAN optimization forecasting
• Branch virtualization with
• SD-WAN and advanced • Application aware policies
Cisco VNF orchestration
WAN topologies using path control,
• Day 0 and Day 2 provisioning • Limited segmentation bandwidth optimization
• Cloud connectivity • Cloud OnRamp
• Lifecycle management
• Forwarding error correction
• Secure VPN overlay • Contextual insights with
• Enterprise firewall* assurance
• IPS/IDS with Talos signatures* • Encrypted traffic analytics
• URL filtering* DNA Premier
• Umbrella (DNS Layer*
Monitoring) DNA Advantage
• Basic application visibility
DNA Essentials
*For Security enforcement with Umbrella, customers must purchase a separate license
But what about service
creation and delivery in a
service provider’s
environment …
One-time
OSS / BSS
Integration
UI / API
MSX Platform
MSX Platform
UI / API
Multi-tenant
services deployed
and managed from
a simple,
customizable UI.
MSX Can Rapidly On-board Many SD-WAN devices
vManage
vSmart
vBond
• MSX creates SD-WAN control plane VMs for each tenant vManage
• MSX provides single sign on and RBAC for each tenant vSmart
• MSX provides SD-WAN OSS/BSS interface for each tenant vBond
Cisco
Umbrella
Branch | Colo
One user interface for SD-WAN and network security simplifies management
Combining Best-of-Breed in Security and SD-WAN
MSX installs SD-WAN & Security
templates for 100s of tenants and sites Enterprise Firewall
MSX Dashboard Classification of +1400 layer 7 apps
URL-Filtering
Web reputation score using 82+ web
categories
Minutes multi-tenant
MSX simplifies instead of weeks and months
SD-WAN + Security from the Cloud
MSX Simplifies Service Creation & Delivery