Professional Documents
Culture Documents
Jean-Marc Barozet
Technical Leader
IWAN Solution Group
Agenda
• Business Trends
• PfRv3 Principles
• Monitoring Details – The Life of a Packet
• Path Enforcement – Route Override
• Enterprise Deployment
• IWAN Management
• Key Takeaways
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Business Trends
Hybrid WAN: Leveraging the Internet
Secure WAN Transport and Internet Access
Secure WAN
Transport
Private
MPLS (IP-VPN) Cloud
Virtual
Private
Cloud
Branch
Internet Public
Direct Internet Cloud
Access
IPSec WAN Overlay Optimal application routing Performance monitoring NG Strong Encryption
Consistent Operational Efficient use of bandwidth Optimization and Caching Threat Defense
Model
DMVPN Performance Routing AVC, WAAS, Akamai Suite-B, CWS, ZBFW
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Intelligent Path Control with PfR
Leveraging the Internet
Voice/Video/Critical take
the best delay, jitter, and/or
loss path
MPLS
Private Cloud
Define your Traffic Policy Learn the Traffic Measurement Path Enforcement
Define path optimization Traffic flowing through the Report the measured TC Master Controller directs
policies on the Hub MC Border Routers (BRs) that performance metrics to BR path changes to keep
load balancing, match a policy are learned the Master Controller for traffic within policy
path preference, application Traffic Classes policy compliance Route Enforcement
metrics Unified Performance Unified Performance module in feature path
DSCP Based Policies Monitor Monitor
Application Based Policies
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Intelligent Path Control
IWAN 2.0
PfRv3
PfRv2 • Centralized provisioning
• AVC Infrastructure
PfR/OER • Policy simplification
• VRF Awareness
• App Path Selection
• Internet Edge • Blackout ~ 2s
• Blackout ~6s
• Basic WAN • Brownout ~ 2s
• Brownout ~9s
• Provisioning per site per • Scale 2000 sites
• Scale 500 sites
policy • Hub config only
• 10s of lines of config
• 1000s of lines of config
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Configuration – Improvement and Simplification
PfRv2 PfRv3 MC Configuration on Hub site only
pfr master
policy-rules IWAN-pfr-map
domain <MYNAME>
max-range-utilization percent 30
mc-peer domain 1 eigrp Loopback0
target-discovery
logging
!
vrf <name>
border 10.0.0.30 key-chain PFR-KEYCHAIN
interface GigabitEthernet0/0.32 internal
interface GigabitEthernet0/0.31 internal
interface GigabitEthernet0/0.30 internal
interface Tunnel2 external
master hub
link-group internet
!
interface Tunnel1 external
link-group mpls
learn
traffic-class filter access-list DENY_GLOBAL_LEARN_LIST
source-interface Loopback0
list seq 10 refname LEARN_VOICE_VIDEO
traffic-class access-list VOICE_VIDEO filter BRANCH_PREFIX
count 2000 max 10000
throughput
list seq 20 refname LEARN_CRITICAL
password IWAN
traffic-class access-list CRITICAL filter BRANCH_PREFIX
count 2000 max 10000
throughput
list seq 30 refname LEARN_BEST_EFFORT
traffic-class prefix-list BEST_EFFORT_PREFIX
load-balance
count 2000 max 10000
throughput
periodic 90
probe packets 20
!
class VOICE sequence 10
!
pfr-map IWAN-pfr-map 10
match pfr learn list LEARN_VOICE_VIDEO
set periodic 90
set delay threshold 200
set mode monitor fast
match dscp ef policy voice
set resolve delay priority 1 variance 5
set resolve loss priority 2 variance 5
set resolve jitter priority 3 variance 5
set loss threshold 50000
set jitter threshold 30
path-preference mpls fallback inet
set probe frequency 8
!
set link-group mpls fallback internet
pfr-map IWAN-pfr-map 20
match pfr learn list LEARN_CRITICAL
class VIDEO sequence 20
set periodic 90
set delay threshold 100
set mode monitor fast
set resolve delay priority 1 variance 20
set resolve loss priority 5 variance 10
match dscp af41 policy real-time-video
set probe frequency 8
!
set link-group mpls fallback internet
pfr-map IWAN-pfr-map 30
match pfr learn list LEARN_BEST_EFFORT
set periodic 90
match dscp cs4 policy real-time-video
set mode monitor passive
!
router eigrp IWAN
!
service-family ipv4 autonomous-system 1
path-preference mpls fallback inet
!
sf-interface default
shutdown
exit-sf-interface
!
class APPLICATION sequence 30
sf-interface Loopback0
no shutdown
hello-interval 200
hold-time 600
exit-sf-interface
match dscp af31 policy low-latency-data
!
topology base
exit-sf-topology
neighbor 10.0.0.91 Loopback0 remote 100
exit-service-family
!
!
ip prefix-list BEST_EFFORT_PREFIX seq 10 permit 0.0.0.0/0
!
ip prefix-list BEST_EFFORT_PREFIX seq 5 deny 10.0.0.0/16
ip prefix-list BEST_EFFORT_PREFIX seq 10 permit 0.0.0.0/0
DCI
IWAN POP1 WAN Core IWAN POP2
• A collection of sites sharing the
same set of policies MC1
Transit Transit
MC2
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
PfRv3 Components
MC/BR
BRANCH
MPLS Dual CPE
MC BR BR
BR
Transit BRANCH
INET
MC/BR Single CPE
The Decision Maker: Master Controller (MC) The Forwarding Path: Border Router (BR)
Apply policy, verification, reporting Gain network visibility in forwarding path
No packet forwarding/ inspection required (Learn, measure)
Standalone of combined with a BR Enforce MC’s decision (path enforcement)
VRF Aware VRF aware
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
PfRv3 Sites BRANCH SITE
Site11 – Site ID = 10.2.11.11
TRANSIT SITE
Hub – Site ID = 10.8.3.3
MC/BR
BRANCH
MPLS Dual CPE
MC BR BR
TRANSIT
BR
INET BRANCH
MC/BR Single CPE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Transit Site – Hub Master Controller
MC/BR
BRANCH
MPLS Dual CPE
DC/MC BR BR
BR
TRANSIT BRANCH
INET
MC/BR Single CPE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Branch Site
MC/BR
BRANCH
MPLS Dual CPE
DC/MC BR BR
BR
TRANSIT BRANCH
INET
MC/BR Single CPE
domain IWAN
vrf default
• Service Exchange master branch
source-interface Loopback0
• Policies and Monitor configurations hub 10.8.3.3
• Site Prefixes border
source-interface Loopback0
master local
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Policy/Monitor Distribution
MC/BR
BRANCH
Policies MPLS Dual CPE
Monitors
DC/MC BR BR
BR
TRANSIT BRANCH
INET
MC/BR Single CPE
• Domain policies and monitor instances are configured on the Hub MC.
• Policies are defined per VRF
• Then distributed to branch sites using the peering infrastructure
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Policy/Monitor Distribution
Policies
MC/BR
Monitors
BRANCH
MPLS Dual CPE
DC/MC BR BR
BR
TRANSIT BRANCH
INET Policies
MC/BR Single CPE
Monitors
• Domain policies and monitor instances are configured on the Hub MC.
• Policies are defined per VRF
• Then distributed to branch sites using the peering infrastructure
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Performance Policies - DSCP or App Based
• Policies:
domain IWAN
– DSCP or Application Based Policies
vrf default
(NBAR2)
master hub
– DSCP marking can be used with
load-balance
NBAR2 on the LAN interface
class MEDIA sequence 10 (ingress on BR)
match application telepresence-media policy real-time-video
match application ms-lync policy real-time-video
• Default Class is load balanced
path-preference MPLS fallback INET
class VOICE sequence 20
match dscp ef policy voice
path-preference MPLS fallback INET
class CRITICAL sequence 30
match dscp af31 policy low-latency-data
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Built-in Policy Templates
Pre-defined Threshold Definition
Template
Voice priority 1 one-way-delay threshold 150 (msec)
priority 2 packet-loss-rate threshold 1 (%)
priority 2 byte-loss-rate threshold 1 (%)
priority 3 jitter 30 (msec)
Real-time-video priority 1 packet-loss-rate threshold 1 (%)
priority 1 byte-loss-rate threshold 1 (%)
priority 2 one-way-delay threshold 150 (msec) Pre-defined Threshold Definition
priority 3 jitter 20 (msec) Template
Low-latency-data priority 1 one-way-delay threshold 100 (msec) Bulk-data priority 1 one-way-delay threshold 300 (msec)
priority 2 byte-loss-rate threshold 5 (%) priority 2 byte-loss-rate threshold 5 (%)
priority 2 packet-loss-rate threshold 5 (%) priority 2 packet-loss-rate threshold 5 (%)
Best-effort priority 1 one-way-delay threshold 500 (msec)
priority 2 byte-loss-rate threshold 10 (%)
priority 2 packet-loss-rate threshold 10 (%)
scavenger priority 1 one-way-delay threshold 500 (msec)
priority 2 byte-loss-rate threshold 50 (%)
priority 2 packet-loss-rate threshold 50 (%)
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Discovery – WAN Interface
Branch BRs discover Path Names
and External Interfaces
Define the Path Names on the
Hub Border Routers
MC/BR
BRANCH
MPLS Dual CPE
MC BR
BR
Hub
Master MC
BR
TRANSIT HUB BRANCH
INET MC/BR Single CPE
Passive Monitoring
MC/BR SITE2
Dual CPE
MPLS
MC BR BR
SITE1
BR SITE3
Single CPE
INET
MC/BR
Performance Monitor
Bandwidth on egress • Collect Performance Metrics
Per Traffic Class • Per Channel
(dest-prefix, DSCP, AppName) - Per DSCP
- Per Source and Destination Site
- Per Interface
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Performance Monitoring
Smart Probing
MC/BR SITE2
Dual CPE
MPLS
MC BR BR
SITE1
BR SITE3
Single CPE
INET
MC/BR
MC/BR
SITE2
MPLS Dual CPE
MC BR BR
SITE1
BR
SITE3
INET
MC/BR Single CPE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Performance Violation – NetFlow Export
MC/BR
SITE2
MPLS Dual CPE
MC BR BR
SITE1
BR
SITE3
INET
MC/BR Single CPE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Policy Decision
MC/BR
SITE2
MPLS Dual CPE
MC BR BR
SITE1
BR
SITE3
INET
MC/BR Single CPE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Policy Decision
MC/BR
SITE2
MPLS Dual CPE
MC BR BR
SITE1
BR
SITE3
INET
MC/BR Single CPE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Key Points and … Limitations
• Key Points
– DSCP or Application (NBAR2) based policies
– Control traffic in the global Routing Table and per VRF
– Passive Monitoring based on user traffic
– Leverage smart probing when needed
– Cooperation between pair of sites
– Exports of PfR information with NetFlow v9 to collectors
• Limitation:
– No IPv6 support yet (Roadmap) – But infrastructure is IPv6 ready
– NBAR2 with Asymmetric Routing is not yet supported
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Monitoring Details – The Life of a Packet
PfRv3 Monitoring
Based on Performance Monitor
• PfRv3 defines multiple Performance
Monitor Instances (PMI)
• Applied on all External interfaces
Monitor1 – Site Prefix Learning
(egress direction)
MC
Monitor2 – Aggregate Bandwidth per
Traffic Class (egress direction)
Exports to MC
1 1
2 2
Site
BR BR
3 3
Monitor3 – Performance
measurements (ingress direction)
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Performance Monitor
Multiple Monitors with Unique Key Fields
Performance
Monitor 1
Traffic Performance
BR Monitor 2
Non-Key Fields
Key Fields Packet 1 Non-Key Fields Key Fields Packet 1
Packets
ipv4 destination prefix 10.1.10.0 Packets Source Prefix 10.8.0.0
Bytes
ipv4 destination mask /24 Bytes Source Mask /16
Destination Site ID 10.2.10.10 Input VRF VRF1 Timestamps
Timestamps
Application Name Skype
DSCP AF41
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Source Site – Egress Traffic
Collecting Traffic Class IWAN POP
Hub MC
10.8.3.3/32
MC1 Dst-Site- App DSCP Dst-Site- State BW BR Exit MC1
Pfx Id
10.1.10.0 APP1 AF41 ? UK 24 BR1 Tu10
BR1 BR2
Source Destination DSCP App 2
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Monitor2 Details
PMI: [Egress-Aggregate] - #2
Aggregate Bandwidth Per TC
Trigger NBAR: no/yes
Traffic Flow
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
What is a Traffic Class?
IWAN POP
Dst-Site-Pfx App DSCP Dst-Site-id State BR Exit
Hub MC
10.1.10.0 APP1 AF41 ? UK ? ? 10.8.3.3/32
MC1
10.1.10.0 N/A EF ? UK ? ?
10.1.10.0 N/A AF31 ? UK ? ?
BR1 BR2
10.1.10.0 N/A 0 ? UK ? ?
10.1.11.0 N/A EF ? UK ? ?
10.1.11.0 N/A AF31 ? UK ? ?
10.1.11.0 N/A 0 ? UK ? ?
10.1.12.0 N/A 0 ? UK ? ? MPLS INET
…
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
We need the Destination Site ID – Why??
MC1
BR
MPLS ?
Dst-Site-Pfx App DSC Dst-Site-id State BR Exit
P
10.1.10.0 APP1 AF41 ? UK ? ?
BR
SITE
INET
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Site Prefix Exchange – Dynamic
Based on User Traffic IWAN POP
Hub MC
10.8.3.3/32
• Source Prefix and Mask collected from MC1
Site 10
10.1.10.0/24 Site 10 Site 10
Source Destination DSCP App
1 10.1.10.0/24 10.1.10.0/24
10.1.10.200 10.8.1.200 AF41 XYZ
R10 R11 R12 R13
10.1.12.0/24
R10 Site-Pfx Mask 10.1.10.0/24 10.1.11.0/24
MC 10.1.13.0/24
10.1.10.0 /24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Site Prefix Exchange – Dynamic
Based on User Traffic IWAN POP
Hub MC
10.8.3.3/32
Site Prefix List MC1
Hub 10.8.0.0/16
R10 10.1.10.0/24
BR1 BR2
R11 10.1.11.0/24
R12 10.1.12.0/24
R12 10.1.13.0/24
MPLS INET
• Every MC in the domain owns a Site Prefix
database
• Gives the mapping between site and prefixes
R10 R11 R12 R13
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Monitor1 Details
Site Prefix Learning
PMI: [Egress-prefix-learn] - #2
Non-Key Fields
• counter bytes long
• counter packet long
MC • timestamp absolute monitoring-interval start
Exports to MC
Monitor-interval
30 sec default
1
Site10
10.1.10.0/24 BR BR
Traffic Flow
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Site Prefixes – Static Configuration
TRANSIT SITE
• This allows configuring site-prefix manually instead of
learning. Hub MC
10.8.3.3/32
MC1
• This configuration should be used at the site if the
site is used for transit. BR1 BR2
– For example, Site A reaches Site B via Hub-Site, where
Hub-Site is transit site. The configuration is used to
prevent learning of Site A prefix as Hub-Site prefix when it
is transiting from Hub.
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Source Site – Egress Traffic
Traffic Class Controlled IWAN POP
Hub MC
10.8.3.3/32
Site Prefix List MC1
Hub 10.8.0.0/16
R10 10.1.10.0/24
MC1 BR1 BR2
R11 10.1.11.0/24
R12 10.1.12.0/24 Source Destination DSCP App 2
MPLS INET
Dst-Site-Pfx App DSCP Dst- State BW BR Exit
MC1 Site-id
10.1.10.0 APP1 AF41 R10 CN 24 BR1 Tu100
• Now the MC has the destination site R10 R11 R12 R13
information 10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
• Traffic Class is controlled
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Source Site – Traffic Class Database
IWAN POP
Hub MC
10.8.3.3/32
Dst-Site-Pfx Dst-Site-id App DSCP State BR Exit MC1
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Destination Site – Ingress Traffic
Channel Performance IWAN POP
Hub MC
• Traffic flow captured on the destination MC1
10.8.3.3/32
site
• Performance Monitor collects BR1 BR2
Performance Metrics
• Per Channel
• Default Monitor interval is 30 sec MPLS INET
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
What is a Channel?
Between Sites
• A Channel is a unique combination of:
– Interface
– Peer-Site id
– DSCP
• Created
– Based on real traffic observed on the BRs
– Added every time there is a new DSCP or a new interface or a new site
added to the prefix database.
– Smart Probe is received
• On all exits (Present Channel, Backup Channel)
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Monitor3 Details
PMI [Ingress-per-DSCP] - #3
Ingress Performance Monitor
Key Fields
• Performance is measured ingress direction: • pfr site source id ipv4
• pfr site destination id ipv4
– Actual Traffic • ip dscp
• Interface input
– Smart Probes if no traffic • policy performance-monitor classification hierarchy
Monitor-interval
• Using monitor #3 Non-Key Fields
• transport packets lost rate
30 sec default
3
SITE BR1 R10
Traffic Flow
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Channel Details
IWAN POP
Hub MC
10.8.3.3/32
MC1
BR1 BR2
Present Channel 3
Backup Channel 4
• Site 10
• Site 10
• DSCP AF41
• DSCP AF41
• DMVPN1
• DMVPN2
MPLS INET
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Channel Details
IWAN POP
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Smart Probing
Help for Measurement Over Channels
INET
MC MC
3
Site10 Site11
BR MPLS BR
10.1.10.0/24 3 10.1.11.0/24
Traffic Flow
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Channel Unreachable
• PfRv3 considers a channel reachable as long as the Exports to MC
BR
site receives a PACKET on that channel
1
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Unreachable
Channel State Examples
R84#sh domain IWAN border channels R84#sh domain IWAN border channels
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Smart Probing – Zero SLA Support
INET
MC MC
3
Site10 Site11
BR MPLS BR
10.1.10.0/24 3 10.1.11.0/24
Traffic Flow
• No SLA on the secondary path, but still probing all channels (DSCPs)
– 10 DSCP => 10 Smart Probes over the secondary path
• Waste of bandwidth, especially for metered interfaces (4G/LTE)
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Zero-SLA
Principles
• Zero-sla added on the WAN interface path configuration option.
• PfR will only probe the default channel (DSCP 0).
– It will mute all other smart-probes besides the default channel.
– The default channel runs as DSCP 0, TCA and ODE are DSCP CS6.
– Extrapolate metrics on this to all other DSCPs on this channel
• Site Capability Exchange:
– Site-capability exchange: allow for backwards compatibility and coexistence with legacy
sites until they are upgraded.
– The site-capability is fully extensible so that additional domain configuration features can
be added, not just PfRv3 capabilities.
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Zero SLA Configuration
R83#sh domain IWAN master site-capability
interface Tunnel200 Device Capability IWAN POP
description --- INET ---
domain IWAN path INET zero-sla -----------------------------------------------------------
| Capability | Major | Minor |
! -----------------------------------------------------------
| Domain | 2 | 0 |
-----------------------------------------------------------
| Zero-SLA | 1 | 0 |
-----------------------------------------------------------
Site id :10.2.10.10 BR2
[SNIP
R83#
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Zero SLA Configuration
R83#sh domain IWAN master site-capability
interface Tunnel200 Device Capability IWAN POP
description --- INET ---
domain IWAN path INET zero-sla -----------------------------------------------------------
| Capability | Major | Minor |
! -----------------------------------------------------------
| Domain | 2 | 0 |
-----------------------------------------------------------
| Zero-SLA | 1 | 0 |
-----------------------------------------------------------
Site id :10.2.10.10 BR2
Borders:
----------------------------------------------------------- Tunnel 200
| Capability | Major | Minor |
IP address: 10.8.4.4
-----------------------------------------------------------
Version: 2
| Domain | 2 | 0 |
Connection status: CONNECTED (Last Updated 1d00h ago )
-----------------------------------------------------------
Interfaces configured:
| Zero-SLA | 1 | 0 | INET
Name: Tunnel100 | type: external | Service Provider: MPLS | Status: UP | Zero-SLA: NO
-----------------------------------------------------------
Number of default Channels: 0
Site id :10.2.12.12
DMVPN-2
Tunnel if: Tunnel0
[SNIP
IP address: 10.8.5.5
Version: 2
R83#
Connection status: CONNECTED (Last Updated 00:04:59 ago )
Interfaces configured:
Name: Tunnel200 | type: external | Service Provider: INET | Status: UP | Zero-SLA: YES
Number of default Channels: 0
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Path Enforcement – Route Override
Performance Violation
Enterprise HQ
• Performance notification exported ONLY Hub MC
when there is a violation on a specific MC1
10.8.3.3/32
channel
– Generated from ingress monitor attached on BR1 BR2
BRs to the source site MC
– Based on Monitor interval (30 sec default, R10
configurable) TCA Delay
– Via all available external interfaces. DSCP AF41
MPLS INET
Path MPLS
3
Channel Dst-Site-id DSCP Path BW Delay Jitter Loss
R10 R10 R11 R12 R13
5 Hub AF41 Tu1 24 250 2 1
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Performance Violation – Detected on Dst Site
Enterprise HQ
Hub MC
10.8.3.3/32
Dst-Site-Pfx Dst-Site-id App DSCP State BR Exit MC1
3
R10 R10 R11 R12 R13
TCA Delay
10.1.12.0/24
DSCP EF 10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
Path MPLS
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Policy Decision – Reroute TC
Enterprise HQ
• MC computes a new path for each Hub MC
10.8.3.3/32
impacted TC MC1
MPLS INET
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Reroute TC – Path Enforcement
Enterprise HQ
• Dataplane forwarding Hub MC
10.8.3.3/32
MC1
• Activated on all but external interfaces
• Lookup per packet - output-if/next hop BR1 BR2
retrieved
– Packet Forwarded
– If no entry – Uses FIB entry MPLS INET
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Enterprise Deployment
Intelligent WAN Deployment Models
Dual MPLS Hybrid Dual Internet
Internet
Public Enterprise Public
MPLS MPLS
MPLS + Internet
Internet
Branch Branch Branch
Two WAN
Routing Domains
DMVPN GETVPN DMVPN DMVPN
MPLS: eBGP or Static One WAN
Internet MPLS Internet MPLS
Internet: iBGP, EIGRP Routing Domain
or OSPF
iBGP, EIGRP, or OSPF
Route Redistribution
Route Filtering Loop
Prevention
ISR-G2
Branch ISR-G2 Branch
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
IWAN Layers
Intelligent Path
AVC PfR QoS Selection
Overlay routing
Overlay Routing Protocol (BGP, EIGRP) over tunnels
ZBFW
MPLS Routing Internet Routing CWS
Infrastructure Routing
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
IWAN Deployment – DMVPN
DCI
IWAN POP1 WAN Core IWAN POP2
• IWAN Prescriptive Design – Transport
Independent Design based on DMVPN MC1 MC2
http://docwiki.cisco.com/wiki/PfR3:Solutions:IWAN
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Best Practice: VRF-Aware DMVPN
Keeping the Default Routes in Separate VRFs with Front Door VRF
• Enable FVRF DMVPN on the Spokes
default
EIGRP
• Allow the ISP learned Default Route in the default VRF: INET-PUBLIC
VRF INET-PUBLIC and use for tunnel INSIDE
Internet Edge
establishment Block
default
• Global VRF contains Default Route learned
via tunnel. User data traffic follows Tunnel to VPN-DMZ
default
INSIDE interface on firewall OUTSIDE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
DMVPN Configuration – F-VRF
IWAN POP
MC1
R84 R85
vrf definition IWAN-TRANSPORT-1 10.0.100.84 10.0.200.85
!
Front-door VRF definition for
address-family ipv4
MPLS Transport
exit-address-family
!
MPLS INTERNET
10.0.100.10 10.0.200.10
R10
10.1.10.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
DMVPN Configuration – IPSec
! IWAN POP
! <removed IKEv2 proposal, will use smart default)
!
! MC1
crypto ikev2 keyring DMVPN-KEYRING-1
peer ANY
address 0.0.0.0 0.0.0.0
pre-shared-key c1sco123 R84 R85
! 10.0.100.84 10.0.200.85
!
crypto ikev2 profile FVRF-IKEv2-IWAN-TRANSPORT-1
match fvrf IWAN-TRANSPORT-1
match identity remote address 0.0.0.0
authentication remote pre-share Maximise window size to
authentication local pre-share eliminate future anti-replay issue MPLS INTERNET
keyring local DMVPN-KEYRING-1
!
crypto ipsec security-association replay window-size 512
!
crypto ipsec transform-set AES256/SHA/TRANSPORT esp-aes 256 esp-sha-hmac 10.0.100.10 10.0.200.10
mode transport
!
crypto ipsec profile DMVPN-PROFILE-1
R10
set transform-set AES256/SHA/TRANSPORT
set ikev2-profile FVRF-IKEv2-IWAN-TRANSPORT-1
10.1.10.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
DMVPN Hub Configuration – Interfaces & Routing
MPLS TRANSPORT – R84
IWAN POP
interface GigabitEthernet0/0/3
description MPLS-TRANSPORT Put Transport Interface into
MC1
vrf forwarding IWAN-TRANSPORT-1 MPLS Front-door VRF
ip address 172.16.84.4 255.255.255.0
!
interface Tunnel100 R84 R85
Instantiate DMVPN Tunnel
bandwidth 1000 10.0.100.84 10.0.200.85
ip address 10.0.100.84 255.255.255.0
no ip redirects
ip mtu 1400
ip pim nbma-mode
ip pim sparse-mode
ip nhrp authentication cisco123 MPLS INTERNET
ip nhrp map multicast dynamic
ip nhrp network-id 100
DMVPN Network ID: MPLS
ip nhrp holdtime 600
ip nhrp redirect Set DMVPN Ph3
ip tcp adjust-mss 1360
tunnel source GigabitEthernet0/0/3 Map to Physical Interface
tunnel mode gre multipoint
tunnel key 101
tunnel vrf IWAN-TRANSPORT-1
tunnel protection ipsec profile DMVPN-PROFILE-1 Tunnel endpoint is in Front-door VRF
!
ip route vrf IWAN-TRANSPORT-1 0.0.0.0 0.0.0.0 172.16.84.8
Default route for Tunnel endpoints
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
DMVPN Spoke Configuration – Interfaces & Routing
!
Interface GigabitEthernet0/1 Put Transport Interface into
vrf forwarding IWAN-TRANSPORT-1
MPLS Front-door VRF
ip address 10.0.100.10 255.255.255.0
!
interface Tunnel100
Instantiate DMVPN Tunnel
ip address 10.0.100.10 255.255.255.0
no ip redirects
ip mtu 1400
ip pim dr-priority 0
ip pim sparse-mode
ip nhrp authentication cisco123 DMVPN Network ID: MPLS
ip nhrp network-id 100
ip nhrp holdtime 600
ip nhrp nhs 10.0.100.84 nbma 172.16.84.4 multicast Multiple DMVPN Hub for
ip nhrp nhs 10.0.100.94 nbma 172.16.94.4 multicast Resiliency
ip nhrp registration no-unique
ip nhrp shortcut
ip tcp adjust-mss 1360 Set DMVPN Ph3 10.0.100.10 10.0.200.10
if-state nhrp
tunnel source GigabitEthernet0/1
tunnel mode gre multipoint R10
tunnel key 101 Tunnel endpoint is in Front-
tunnel vrf IWAN-TRANSPORT-1 door VRF 10.1.10.0/24
tunnel protection ipsec profile DMVPN-PROFILE-1
!
ip route vrf IWAN-TRANSPORT-1 0.0.0.0 0.0.0.0 172.16.101.8
Default route for Tunnel endpoints
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
IWAN Routing Protocols
Which protocol should I use?
• IWAN Profiles are based upon BGP and EIGRP for scalability and optimal Intelligent
Path Control
• Scalability:
– BGP (Path Vector) and EIGRP (Advanced Distance Vector) provide best scale over
large hub-and-spoke topologies like DMVPN
– OSPF (Link State) maintains a lot of network state which cannot be subdivided easily in
large DMVPN networks
• Intelligent Path Control:
– PfR can be used with any routing protocols by relying on the routing table (RIB).
• Requires all valid WAN paths be ECMP so that each valid path is in the RIB.
– For BGP and EIGRP, PfR can look into protocol’s topology information to determine both
best paths and secondary paths thus, ECMP is not required.
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
EIGRP IWAN Design Overview 10.9.0.0/16
IWAN POP2
Principles
IWAN POP1 10.8.0.0/16
• Single EIGRP process for Branch, WAN and MC1
Hub MC
10.8.3.3/32
POP/hub sites
• Extend Hello/Hold timers for WAN R84 R85
Delay TAG Delay TAG
• Adjust tunnel interface “delay” to ensure WAN 1000 DMVPN-1 2000 DMVPN-2
path preference
• MPLS primary, INET secondary Set Interface
Delay to
influence best MPLS INET
• Hubs path DMVPN-1 DMVPN-2
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24
• Spokes 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
IWAN Deployment – BGP 10.9.0.0/16
IWAN POP2
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
PfRv3 and Parent Routes
• Make sure that all Border Routers have a route over each external path to the
destination sites
– PfR will NOT be able to effectively control traffic otherwise.
• PfRv3 always checks for a parent route before being able to control a Traffic
Class. Parent route check is done as follows:
– Check to see if there is an NHRP shortcut route
– If not – Check in the order of BGP, EIGRP, Static and RIB
– If at any point, an NHRP short cut route appears, PfRv3 would pick that up and
relinquish using the parent route from one of the routing protocols.
• PfR3 currently supports only one next-hop per multipoint interface. Routing has
to be done such that only one next-hop per destination prefix is in the routing
table per DMVPN tunnel interface.
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Transit Site – Hub MC TRANSIT SITE
10.1.12.0/24
• MC1 – Hub MC 10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
• BR1 – Hub BR, DMVPN Hub for MPLS
• BR2 – Hub BR, DMVPN Hub for INET
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Single CPE Branch Sites
TRANSIT SITE
Hub MC
MC1 10.8.3.3/32
domain IWAN
vrf default R84 R85
master branch
source-interface Loopback0
hub 10.8.3.3
R10 border
R11 master local
source-interface Loopback0 MPLS INET
• Stub Site
• Combination of MC and BR on the same CPE R10 R11 R12 R13
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Dual CPE Branch Sites
TRANSIT SITE
Hub MC
domain IWAN MC1 10.8.3.3/32
vrf default
master branch
source-interface Loopback0 R84 R85
hub 10.8.3.3
R12 border
master local
source-interface Loopback0
MPLS INET
domain IWAN
vrf default
R13 border
master 10.2.12.12
source-interface Loopback0
R10 R11 R12 R13
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24
• Stub Site 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Enterprise Domain
Policy – DSCP or App Based
domain IWAN
vrf default
• When load balancing is enabled,
master hub
PfRv3 adds a “default class for
load-balance
match all DSCP (lowest priority
class VOICE sequence 10
compared to all the other classes)”
and we influence this traffic.
match dscp ef policy voice
path-preference MPLS fallback INET • When load balancing is disabled,
class VIDEO sequence 20 PfRv3 deletes this “default class”
match dscp af41 policy voice and as a part of that frees up the
path-preference MPLS fallback INET TCs that was learnt as a part of LB –
class CRITICAL sequence 30 they follow the routing table
match dscp af31 policy low-latency-data
MC1
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Policy – Monitor Intervals
MC1
• Advanced commands
– Carefully choose monitor interval for critical applications
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Deploying with user VRFs
TRANSIT SITE
vrf definition TEST1
!
address-family ipv4 MC1
exit-address-family 1 2 1 2
!
vrf definition TEST2 R84 R85
! interface Tunnel 101
address-family ipv4 vrf forwarding TEST1
exit-address-family tunnel key 101
! tunnel vrf IWAN-TRANSPORT-1
!
interface Tunnel 102 MPLS INET
vrf forwarding TEST2
tunnel key 102
tunnel vrf IWAN-TRANSPORT-1
domain IWAN
vrf TEST1 MPLS INET
master hub
source-interface Loopback1
!
vrf TEST2
master hub
R10 R11 R12 R13
source-interface Loopback2
10.1.12.0/24
10.1.10.0/24 10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Deploying with VRF – Hub BR
TRANSIT SITE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Dual POPs – Different Prefixes
DCI
IWAN POP1 WAN Core IWAN POP2
• Requirements:
MC1 MC2
– Separate datacenters/POPs 10.8.0.0/16 10.9.0.0/16
– Separate prefix advertised from each datacenters
to spokes R84 R85 R94 R95
• POP2 Hub MC EIGRP/BGP
10.8.0.0/16
EIGRP/BGP
10.8.0.0/16
EIGRP/BGP
10.9.0.0/16
EIGRP/BGP
10.9.0.0/16
– Configured as Branch
MPLS INET
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Horizontal Scaling Architecture
TRANSIT SITE
PfRv3 Multiple DMVPN Next Hop Limitation
Hub MC
MC1 10.8.3.3/32
• Limitations:
– PfRv3 manages traffic between Tunnel Interfaces, not
multiple tunnels within a single Tunnel Interface
BR1 BR2 BR3 BR4
– Spokes have multiple next hops on the same DMVPN
tunnel Interface Next Hop 1 Next Hop 2
– Channel definition:
• local site id + remote site id + DSCP + color(SP)
• No differentiation for multiple channels within a color(SP) MPLS INET
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Multiple POPs – Common Prefixes DC1
DCI
TRANSIT SITE1 WAN Core TRANSIT SITE2
• Requirements:
MC1 MC2
– 2 (or more) Transit Sites advertise the very same 10.8.0.0/16 10.8.0.0/16
set of prefixes 10.9.0.0/16 10.9.0.0/16
– Datacenter may not be collocated with the BR1 BR2 BR3 BR4
Transit Sites
– DCs/DMZs are reachable across the WAN Core
for each Transit Site
– Branches can access any DC or DMZ across DMVPN DMVPN
MPLS INET
either POP(hub). And, DC/DMZs can reach any
branch across multiple Transit Sites (hubs).
– Multiple BRs per DMVPN per site may be
required for crypto and bandwidth horizontal
scaling
R10 R11 R12 R13
• Targeted for Spring XE 3.15 / 15.5(2)T releases 10.1.10.0/24
10.1.12.0/24
10.1.11.0/24 10.1.13.0/24
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Monitoring Operations
R83#sh domain one master traffic-classes summary
[SNIP]
Traffic
Total Traffic Class
Classes: 12 –Site:
Site11
6 -Internet:
Critical 0TC Id Controlled Path Information - Channels
R83#
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Check Traffic Classes Details
R83#sh domain one master traffic-classes
Class-Sequence in use: 10
Class Name: VOICE using policy User-defined Policies and
priority 2 packet-loss-rate threshold 5.0 percent
priority 1 one-way-delay threshold 150 msec
reason for last
priority 2 byte-loss-rate threshold 5.0 percent change
BW Updated: 00:00:14 ago
Reason for Route Change: Delay
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Check Channel after TCA
On Demand Export
(ODE)
MC1#sh domain IWAN master channels | beg 107
Channel Id: 107 Dst Site-Id: 10.2.11.11 Link Name: MPLS DSCP: ef [46] TCs: 1
Channel Created: 00:15:03 ago
Provisional State: Initiated and open Threshold Crossing
Operational state: Available Alert (TCA)
Interface Id: 11
Estimated Channel Egress Bandwidth: 0 Kbps
Immitigable Events Summary:
Total Performance Count: 0, Total BW Count: 0
ODE Stats Bucket Number: 1 [SNIP]
Last Updated : 00:05:45 ago
Packet Count : 2 TCA Statistics:
Byte Count : 116 Received:1 ; Processed:1 ; Unreach_rcvd:0
One Way Delay : 254 msec* Latest TCA Bucket
Loss Rate Pkts: 0.66 % Last Updated : 00:05:45 ago
Loss Rate Byte: 0.0 % One Way Delay : 266 msec
Jitter Mean : 38000 usec Loss Rate Pkts: NA
Unreachable : FALSE Loss Rate Byte: NA
Jitter Mean : NA
Unreachability: FALSE
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
PfRv3 Management
PfRv3 Exporter Configuration
IWAN POP
Hub MC
MC1 10.8.3.3/32
domain IWAN
vrf default
BR1 BR2
master hub
collector 10.151.1.95 port 2055
MC1
MPLS INET
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
PfRv3 NetFlow Export
List of Templates
• Exports from MC
– TCA record
– Route Change record
– Immitigable Event Summary
• Bandwidth
– Exports from BRs
– Egress Measurement Template
– Ingress Measurement Template
• All records available at:
– http://docwiki.cisco.com/wiki/PfRv3:Reporting
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Cisco IWAN Management
On-Prem Management Specialized Management Cloud-Based Management
Prime
Infrastructure
2.2
End-to-End Assurance of Application Application Aware Network Automates Deployment
Experience Performance Management and Lifecycle Management
• Single-pane view of IWAN • Integrates with Cisco AVC and PfR • Eliminates manual building of WANs
• IWAN deployment workflows • Monitor and analyze application traffic • Automated SD-WAN orchestration
• Plug and Play • End-to-end flow visualization • Centralized hybrid WAN management
• DMVPN, QoS, AVC deployment and • Flow & App-based Troubleshooting • Quick config updates and IOS upgrades
monitoring • Fix and Verify in Realtime • Leverages onePK and REST APIs
• PfR v3 in Q1 2015
• License includes IWAN App and APIC-
EM controller!
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
LiveAction 4.1
1. Alert Workflow
1. PfR path change
visualization
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
PfRv3 TCA Alerts on DC1
Drill down to site pairs
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
2. PfRv3 Dashboard
All Alerts
Alerts / performance
by Site
Alerts / performance
by Application Group
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Alerts / performance
by Service Provider
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
IWAN Automation and Orchestration Evolution
Capacity Planning, Troubleshooting,
Prime
Change control
Intelligent Application
Security
Path Control Experience
Cisco Prime
Evolution
REST APIs
APIC-EM Services (Partial)
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Key Takeaways
Performance Routing – IOS and IOS-XE Releases
PfR/OER version 1 PfR version 2 PfR version 3
IOS 12.3(8)T, XE 2.6.1 IOS 15.2(3)T, IOS-XE 3.6 IOS 15.4(3)M, IOS-XE 3.13
Per Device provisioning Per Device provisioning PfR Domain
Passive monitoring with Traditional Target Discovery (TD) One touch provisioning
NetFlow (TNF) Automatic provisioning of jitter probes Auto Discovery of sites
Active monitoring with IP SLA Passive monitoring with Traditional NBAR2 support
Manual provisioning jitter probes NetFlow (TNF) Passive Monitoring (performance
1000’s lines of configuration (pfr-map Active monitoring with IP SLA monitor)
per site) 10’s lines of configuration Smart Probing
VRF Awareness
IPv4/IPv6 (Future)
<10 lines of configuration and
centralized
Blackout 6 seconds Blackout 6 seconds Blackout ~ 2 sec
Brownout 9 seconds Brownout 9 seconds Brownout ~ 2 sec
Limited scalability due to provisioning Scale 500 sites Scale 2000 sites
(~ tens of sites)
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Performance Routing – Platform Support
Cisco CSR-1000
MC
Cisco ASR-1000 BR*
* BR support coming
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public
Key Takeaways
• IWAN Intelligent Path Control pillar is based upon Performance
Routing (PfR)
– Maximizes WAN bandwidth utilization
– Protects applications from performance degradation
– Enables the Internet as a viable WAN transport
– Provides multisite coordination to simplify network wide provisioning.
– Application-based policy driven framework and is tightly integrated with
existing AVC components.
– Smart and Scalable multi-sites solution to enforce application SLAs while
optimizing network resources utilization.
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
More Information
• Cisco.com IWAN/PfR Page:
– http://www.cisco.com/go/iwan
– http://www.cisco.com/go/pfr
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Call to Action
• Visit the World of Solutions for
– Cisco Campus
– Walk in Labs
– Technical Solution Clinics
• Meet the Engineer
• Lunch time Table Topics
• DevNet zone related labs and sessions
• Recommended Reading: for reading material and further resources for this
session, please visit www.pearson-books.com/CLMilan2015
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Complete Your Online Session Evaluation
• Please complete your online session
evaluations after each session.
Complete 4 session evaluations
& the Overall Conference Evaluation
(available from Thursday)
to receive your Cisco Live T-shirt.
BRKRST-2362 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public 106