Professional Documents
Culture Documents
Waqas Daar
TECHNICAL CONSULTING ENGINEER
September 17, 2019
• What is SD-WAN?
• Why SD-WAN?
• Benefits of SD-WAN
• SD-WAN Solution Overview
• Orchestration Plane
Agenda • Management Plane
• Control Plane
• Data Plane
• Controller Deployment Architecture
• Control Plane Sessions
• Cisco SD-WAN Fabric Operations
• Cisco SD-WAN Platforms
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What is SD-WAN?
• The software-defined wide area network (SD-WAN) is a technology for configuring
and implementing an enterprise WAN — based on software-defined networking
(SDN) — to effectively route traffic to remote locations such as branch offices,
Internet.
• SD-WAN technology derives significant flexibility and agility benefits from removing
the burden of traffic management from physical devices and transferring it to
software.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What challenges SD-WAN is
addressing ?
• The traditional WAN lacks the agility and efficiency for today’s cloud-driven
networking requirements and bandwidth intensive applications
• Align business policy to the operational performance of applications doing
intelligent forwarding of application traffic across the enterprise WAN ensuring
that pre-defined, per-application performance metrics, or service level
agreements (SLA), are persistently met at the lowest achievable costs.
• Maximize the use of the internet connected link.
• Remove the complexity of the network topology
• Adapt and gain real visibility of my network
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Benefits of SD-WAN
• Increased bandwidth at a lower cost
• Centralized management across branch networks
• Full visibility into the network
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Things to remember…
vEdge – vEdge Router
i.e. an SDWAN router
cEdge – ISR/ASR Router
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Overview
Applying SDN Principles To The Wide Area Network
vManage
OrchestrationPlane vBond
vSmart
MANAGEMENT
vBond
ORCHESTRATION ANALYTICS
Control Plane
(Containers or VMs)
CONTROL
Data Plane
(Physical or Virtual)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Management Plane
vManage
vBond Main
Characteristics
MANAGEMENT
• Single pane of glass for
API Day0, Day1 and Day2
ANALYTICS
operations
ORCHESTRATION
• Centralized provisioning
• Multitenant or single tenant
• Policies and Templates
CONTROL
• Troubleshooting and
Monitoring
Secure DTLS Control Channel
Secure IPSEC Data Channel
INET MPLS 4G • Software upgrades
• GUI with RBAC
• Programmatic interfaces
(REST, NETCONF)
Data Center Campus Branch Home Office • Highly resilient
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane
vSmart Controller
vBond
Main
MANAGEMENT Characteristics
API • Facilitates fabric discovery
ORCHESTRATION ANALYTICS • Disseminates control plane
information between vEdges
• Distributes data plane and app-
aware routing policies to the vEdge
CONTROL routers
• Implements control plane policies
Secure IPSEC Data Channel
INET MPLS 4G
Secure DTLS Control Channel
• Dramatically reduces control
plane complexity
• Highly resilient
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Data Plane
SD-WAN Router Main
Characteristics
vBond
• SD-WAN edge router
MANAGEMENT • Provides secure data plane with
remote Sd-WAN edge routers.
API
• Establishes secure control plane
ORCHESTRATION ANALYTICS with vSmart controllers (OMP)
• Implements data plane and
application aware routing
policies
CONTROL
• Exports performance statistics
• Leverages traditional routing
Secure DTLS Control Channel
Secure IPSEC Data Channel
INET MPLS 4G protocols like OSPF, BGP, EIGRP
and VRRP
• Support Zero Touch
Deployment
Data Center Campus Branch Home Office • Physical or Virtual form factor
(100Mb, 1Gb, 10Gb, 20Gb+)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controller Deployment
NIC0 NIC1 NIC0 NIC1
Control Mgmt
Interface
ESXi, KVM, AWS, MS Azure Interface ESXi, KVM, AWS, MS Azure
Cluster
Interface
(vManage
Only)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN Fabric Terminology
• Overlay Management Protocol (OMP) – Control plane protocol distributing
reachability, security and policies throughout the fabric
• Transport Locator (TLOC) – Transport attachment point and next hop route attribute
• Color – Control plane tag used for IPSec tunnel establishment logic
• System IP – Unique per-device (vEdge and controllers) IPv4 notation identifier. Also
used as Router ID for BGP and OSPF.
• Organization Name – Overlay identifier common to all elements of the fabric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane Sessions
o Secure Channel to SD-WAN Controllers DTLS only
operates over DTLS/TLS authentic ated and • Viptela Primitives
secured tunnels. vManage • Permanent
• Multiple Sessions
o OMP between vEdge routers and vSmart
controllers and between the vSmart controllers vBond
DTLS or TLS
DTLS or TLS
• Viptela Primitives
• Viptela Primitives • OMP
• NETCONF • Permanent
• Permanent • 1 session / vSmart /
• Single Session TLOC
DTLS Only
• Viptela
Primitives
• Temporary
vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Fabric Operations
Policies
OMP vSmart
DTLS/TLS Tunnel
vManage vBond
IPSec Tunnel
BFD
OMP OMP
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Typical SDWAN Deployment Architecture
Private Cloud Site Enterprise Controllers Virtual Private Cloud SaaS
App
Se rvers
SDWAN Servers
VPC VPC
Headend
VPC VPC
Distro
Switch
V V
CE
Routers
MPLS1 I NET
V = Virtual Router
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Platform Options
Virtual (x86) Platforms Public Cloud
Physical Platforms
ISR 1000 vEdge 100 ISR 4000 vEdge 1000 ASR 1000 vEdge 2000 vEdge 5000