Professional Documents
Culture Documents
Cisco SD-WAN Application BRKRST-2514 PDF
Cisco SD-WAN Application BRKRST-2514 PDF
How
1. Find this session in the Cisco Live Mobile App
2. Click “Join the Discussion”
3. Install Spark or go directly to the space
4. Enter messages/questions in the space
cs.co/ciscolivebot#BRKRST-2514
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Agenda
• Introduction
• SD-WAN Introduction and Architecture
• SD-WAN Application Acceleration
• Next-Gen WAAS Application Optimization
• SD-WAN WAAS Deployment
• Demo
• Conclusion
Introduction
Current WAN Challenges
Insufficient
Bandwidth
Is Your WAN
High Applications
Cost Business Downtime
Ready ?
Limited Fragmented
Scale Security
No Cloud Apps
Readiness
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Why SD-WAN in Enterprise?
50%
of Apps accessed
via Internet
70% 32.4%
Cite management of
Have either 2 or 3 WAN
connectivity at branch
connections/branch
as a challenge
48.6%
Cite poor application
performance and latency as
corporate WAN concern
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
SD-WAN Introduction and Architecture
Cisco SD-WAN Solution Pillars
Cloud-Delivered
Architecture
Comprehensive
Security
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Cisco SD-WAN Secure Extensible Network
vManage
Orchestration Plane vOrchestrator
vSmart
vBond
MANAGEMENT
vEdge
API
Management Plane
(Multi-tenant or Dedicated) ANALYTICS
ORCHESTRATION
Control Plane
(Containers or VMs)
CONTROL
INTERNET MPLS 4G
Data Plane
(Physical or Virtual)
Data Center Campus Branch Home Office
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
SD-WAN Application Acceleration
Application Performance Influencers
Bandwidth
High Latency
User Experience
Brownouts
Lossy Links
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Application Acceleration Techniques
App-Aware
Routing
1001
TCP
Protocol Specific 0001 Optimization
1110
Cloud
Compression
OnRamp
SD-WAN WAAS
Caching
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Application Visibility and Recognition
Cloud
Data Center App 1
App 2
App 3,000
Data Center vEdge Router
MPLS 4G
INET
Small Office
App Firewall
Home Office
Traffic prioritization
Campus
Transport selection
Branch
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Data Plane Liveliness and Quality
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Critical Applications SLA
Internet
MPLS
Remote Site Path 2 Data Center
4G LTE
Path1: 10ms, 0% loss, 5ms jitter
Path2: 200ms, 3% loss, 10ms jitter
Path3: 140ms, 1% loss, 10ms jitter IPSec Tunnel
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
TCP Optimization
Optimized
TCP Connections TCP Connections TCP Connections
SD-WAN
Fabric
Users vEdge vEdge Servers
High Latency Path
• High latency path between users and • Optimized TCP connection uses selective
applications, i.e. geo-distances acknowledgement to prevent unnecessary
retransmissions and large initial TCP
• vEdge routers terminate TCP sessions and
window size to maximize throughput
provide local acknowledgements
- Hosts don’t have to wait for end-to-end TCP • Hosts using older TCP/IP stacks will see the
ACKs and pause TCP transmission most benefit
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Bandwidth Augmentation
• Augment MPLS with vManage
Internet bandwidth
• Create traffic engineering Traffic Engineering Policy
policy to steer application (data policy)
App A -> MPLS TLOC
traffic
App B -> Internet TLOC
- Active/Active if no policy
Remote Site
Internet
A
Data Center
B
MPLS
App A -> MPLS TLOC
App B -> Internet TLOC
SDWAN Tunnel SDWAN Fabric
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Direct Internet Access
• Can use one or more local DIA exits or
Internet backhaul traffic to the regional hub through
the SD-WAN fabric and exit to Internet from
there
- Per-VPN behavior enforcement
INET
• VPN default route for all traffic DIA or data
NAT
policy for selective traffic DIA
Regional • Network Address Translation (NAT) on the
Data Center vEdge router only allows response traffic
NAT
INET
back
SD-WAN - Any unsolicited Internet traffic will be blocked
INET by IP table filters
Fabric
MPLS
Data Center • For performance based routing toward SaaS
Remote Site applications use Cloud onRamp
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Cloud onRamp for SaaS - DIA
Loss/
• Results of quality probing are quantified as
Latency vQoE score (combination of loss and
Regional
Data Center
latency)
!
ISP1 • Local DIA exit with better vQoE score is
chosen to carry the traffic for the selected
SD-WAN
Fabric SaaS application
ISP2 - Initial application flow may choose sub-
Remote Site Data Center optimal path until DPI identification is
complete and cache table is populated
Quality Probing
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Cloud onRamp for SaaS - Gateway
• vEdge routers at the remote site and regional
hub perform quality probing for selected
SaaS applications across their local Internet
exits
- Simulate client connection using HTTP ping
ISP2 • Results of quality probing are quantified as
Loss/ vQoE score (combination of loss and
Latency latency)
Regional
Data Center - HTTP ping for local DIA and App-
! Route+HTTP ping for regional Internet exit
ISP1
• Internet exit with better vQoE score is
SD-WAN chosen to carry the traffic for the selected
Fabric
MPLS SaaS application
Remote Site Data Center - Initial application flow may choose sub-
optimal path until DPI identification is
complete and cache table is populated
Quality Probing
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Quality of Experience Score
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
vEdge Router Device QoS Overview
Data Policy
vManage Classification of application traffic into QoS
forwarding classes (queues)
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Next-Gen WAAS Application
Optimization
Building Blocks of WAAS
AO AO AO
Application Behavior
TCP Flow
Optimization
Latency
Object
DRE LZ
Cache
Bandwidth
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Akamai Caching Technology
2 3 4
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Use Case: Accelerate Live Video
Without
WAN Cisco
vs LAN WAAS withfor
throughput Akamai Connect
Multiple Video Streams
Challenges
• Delivering corporate live video over the 1 2 3 5 7
enterprise network - serving 70K+ end users
across 250 branches globally
WAN/Internet Router
• End-users in South America and Asia suffer
Private/Public LAN Branch
from WAN congestion and video quality issues Cloud Throughput
with frequent re-buffering and slow load times
Benefits
With Cisco WAAS with Akamai Connect
WAN
• Cisco WAAS with Akamai Connect caches live Throughput
and on-demand HTTP video fragments
• Resulted in significant WAN offload while
improving video quality & end-user experiences WAN/Internet
ISR-AX+AC
• Reduced IT tickets related to corporate video Private/Public Branch
webcast quality/performance issues Cloud
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Use Case: Software Download
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Cloud and SaaS
WAAS 6.4 : Dual-Sided and Smart SSL
WAN
Branch DC
Internet
Office365
Optimization
Optimization
Caching only
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Dual-Sided SSL Optimization Solution
Transparent
Secure Channel
Edge WAE Core WAE
SSL Session: client to core WAE SSL Session: core WAE to server
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
AppNav Redirection
AppNav Solution
Optimization AppNav
Distribution
Load
Redirection
Interception
AppNav-XE
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
AppNav Affinity Features
Branch Office_1
Cisco
AppNav
Br3_WAAS
• AppNav’s powerful policy engine
allows for easy separation of branch
WAN
Branch Office_2 Br2_WAAS traffic
Branch1 Traffic
• No knowledge of IP addresses or
Br1_WAAS
Branch2 Traffic
ACLs required
Branch Office_3 Branch3 Traffic
Data Center
Branch Office
• Split traffic into separate application
HTTP Cluster
Cisco clusters
AppNav
WAN • Allows WAAS to easily adapt to
Branch Office SSL Cluster
application traffic increases and
HTTP Traffic changes.
SSL Traffic Other Cluster
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
NG-WAAS
Cisco Application Optimization Form Factors
Next-Gen WAAS
WAAS Appliance
Appliance
Application acceleration
Application acceleration
Scalable platforms for
range of deployments Improved HW and
performance
200 – 150,000 optimized
flows 200 – 6000 optimized
flows
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
What’s new with WAAS?
• On September 30th 2017, End-of-Sale and End-of-Life was announced for the
Cisco WAVE x94, 7541, 7571 and 8541 platforms as well as the AppNav IOM
cards.
• Replacement solutions will be released in phases, starting with branch-side
WAVE replacements by Jan 2018.
• At a high-level the current replacement offerings are as follows:
• For DC-side WAVE (8541/7571/7541), move to BYOH model and run vWAAS
(150K*/50K/12K)
• For branch-side WAVE (694/594/294), move to new WAAS HW platform (ENCS-W)
• For AppNav IOM, move to AppNav-XE which is a software feature available on
CSR/ISR4K/ASR platforms.
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
SD-WAN WAAS Deployment
SD-WAN WAAS Inline
LAN
DC/Remote Office
SD-WAN MPLS
Internet
Fabric
OMP-to-BGP/OSPF vEdge
BGP/OSPF-to-OMP
Local prefixes
(OSPF/BGP)
SD-WAN Traffic
(WAAS, UC, Akamai Connect)
LAN
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
SD-WAN WAAS Offpath
LAN
VPN1
SD-WAN MPLS
Internet
Fabric
vEdge VPN2
SD-WAN Traffic
LAN
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
SD-WAN WAAS Redirection
DATA POLICY ON VSMART CONTROL POLICY ON VSMART
policy data-policy WAAS-REDIRECT policy control-policy WAAS-EXTRANET
WAN From WAN sequence 10
vpn-list VPN-1
sequence 10 match route
match vpn-list VPN1
protocol 6 action accept
VPN 0
action export-to
set next-hop 10.1.2.2 vpn-list VPN2
default-action accept sequence 20
match route
apply-policy site-list Branches vpn-list VPN2
data-policy WAAS-REDIRECT from-tunnel action accept
VPN 2 export-to
vEdge vpn-list VPN1
10.1.2.1 POLICY ON VEDGE default-action accept
10.1.2.2 policy access-list WAAS-REDIRECT
sequence 10 apply-policy site-list Branches
VPN 1
int ge0/1
access-list WAAS-REDIRECT in
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Demo
Cisco Spark
Questions?
Use Cisco Spark to communicate
with the speaker after the session
How
1. Find this session in the Cisco Live Mobile App
2. Click “Join the Discussion”
3. Install Spark or go directly to the space
4. Enter messages/questions in the space
cs.co/ciscolivebot#BRKRST-2514
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
• Please complete your Online Complete Your Online
Session Evaluations after each
session
Session Evaluation
• Complete 4 Session Evaluations
& the Overall Conference
Evaluation (available from
Thursday) to receive your Cisco
Live T-shirt
• All surveys can be completed via
the Cisco Live Mobile App or the
Communication Stations
Don’t forget: Cisco Live sessions will be available
for viewing on-demand after the event at
www.ciscolive.com/global/on-demand-library/.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Continue Your Education
• Demos in the Cisco campus
• Walk-in Self-Paced Labs
• Tech Circle
• Meet the Engineer 1:1 meetings
• Related sessions
BRKRST-2514 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Thank you