Professional Documents
Culture Documents
BRKDCN-2712
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Main Message
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Session Abstract
The session provides the journey and current state on modern telemetry infrastructure
supporting Day 2 operations.
The Cisco’s Network Insights offering will provide a common tooling for ACI and NX-OS to
efficiently deliver information for Day 2 operations, all built on top of a scale-out micro-
services architecture.
In addition to the infrastructure and architecture that enables Network Insights, model based
software and hardware telemetry will be put in contrast as well as the various telemetry data
consumption models. Where data comes un-throttled from the switches forwarding chip
(ASIC), how we receive this mass of information and talk about the benefits, the trade-offs,
and challenges across ingestion, retention, correlation, and visualization.
The architecture discussion will be complemented with network telemetry concepts, future
directions, and use cases with real-world examples of the concepts, capabilities and key
differentiators.
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Network Visibility Is Hard
Hard to Operationalize
SNMP
Incomplete
Syslog
Unstructured
CLI
Device-Specific
Slow
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Why is support Is my configuration
asking for access to at the supported
my setup three times scale?
If someone else hit for this issue?
this issue and its
fixed, why not notify
that It could impact
me!
How many times do I
need to gather
these, always rolling
over logs to resolve
this case?
Are my network
security patches up
to date?
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Network Telemetry Frees the Data
Storage &
analysis
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Key Telemetry Characteristics
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
“Pushing” More Data Really Does Work Better
Counters CPU load
400 30
Thousands
300 20%
20 14%
200 8%
10 7% 7% 7%
100
0
0
1 2 3
5s 10s 15s 20s Destinations
Interface counters
(In/Out pkts, In/Out Discards, In/Out Errors)
MemAllocated
Telemetry
SNMP
0 5 10 15 20 25
Seconds
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Why This Matters Now
What hasn’t changed What has changed
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Getting the Information out of the Network
• What are the mechanisms for getting information out of the network? – i.e.,
“Telemetry Sources”
• This session: Software and Hardware Streaming Telemetry
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Nexus Software Telemetry
UDP
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Streaming Software Telemetry Platform Support
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
ASIC-Specific Telemetry Outputs
Telemetry Receiver
UDP
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Flow Table (FT)
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Flow Table Events (FTE)
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Streaming Statistics Export (SSX)
Lookup
Pipeline
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Hardware Telemetry Platform Support
9300/9500-EX ✓ X X
9300/9500-FX ✓ ✓ X
9364C X X ✓
9300-FX2 ✓ ✓ ✓
9300-GX ✓ ✓ ✓
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
A Very Basic Analytics Platform Architecture
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Network Insights - Enabling Proactive Action
Sources of
Ingest and Process Derive Insights Recommend Action
Telemetry Data
Config File
PSIRTs Complex
Syslog Tech- Config / Scale / Process
correlation
Support Hardening
Accounting RIB FIB
Metadata
Logs Debug Logs
CLI extraction
Streaming
Telemetry Environmentals
Event Topology Cores Correlate
History Field notices Network SW-Version /
Consistency against
Checkers Database Protocols PSirts
Mac Table
Apps
DCNM APIC
Platform
App Hosting Framework App Hosting Framework
App Store App Store
Data collection and ingestion Data correlation and analysis Data visualization and action
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Download application from the App Store
Common App Store for ACI and NXOS - https://dcappcenter.cisco.com/
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Day 2 Operations Stack
Assurance
• Policy/ Control/Data plane Assurance
Network Assurance Engine (NAE)
• Incident and Problem Management
• Compliance and Audit O
P
Proactive Maintenance S
• Fabric health and maintenance based on
Network
global Insights Advisor (NIA)
Cisco advisories T
• Network security maintenance based on
PSIRTs and known vulnerabilities A
C
Troubleshooting
K
• Fabric Health monitoring
Network Insights Resources (NIR)
• Fabric wide resource monitoring
• Anomaly detection
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Data Center Visibility Use Cases
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Shorten Time to Remediation
for Troubleshooting
Locate Locate Root cause
Problem Problem
lifecycle lifecycle
Network Remediate NIR Remediate
Operations
Network Insights:
Resources
Readings Forecast
Network
Readings Automated with Operations
statistical models
Capacity Capacity
planning planning
Network Adjust NIR Adjust
Operations
Network Insights:
Resources
Detect Notify
Network
Detect Automated with Operations
Anomaly detection
Incident Incident
lifecycle lifecycle
Network Resolve NIR/NIA Resolve
Operations
Network Insights:
Resources and Advisor
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Network Insights Resources
NIR
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Telemetry and Analytics Deployment Models
Cisco Turnkey Custom
Network
Insights
Resources UI
Custom Third
Party
Data Lake
Telemetry Sources
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Complexity of Building a Telemetry Platform
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
How Can NIR Help with Day 2 Operations?
Monitor fabric-wide and node-
Resources specific resource utilization
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
First, We Need Data!
Software Telemetry
Hardware Telemetry
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
NIR Architecture NIR
NIR GUI
Data Lake
Anomaly &
Data Lake
Correlation
Connector
Engines
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Operational Intelligence Engine for Network Insights
Dynamic Correlation
Correlate information across Dynamic Correlation
data sources
Proactive Alerts
See problems before end users Proactive Alerts
do and alert
Configs
End-to-end Flow Path
LLDP
Pipelines
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
NIR Integration with External Systems
{ REST }
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Forwarding of Anomalies
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Let’s start the Day
with an Overview
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Select time range
Dashboard -
intended to
quickly drill down
to issues
Anomalies by
Type and Severity
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
My Database
is/was slow!
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Flow Visibility and Flow Anomalies
Flows (5-Tuples) visibility
Shooting in dark using using Cisco ASIC’s
Ping/Traceroute/SPAN hardware telemetry
Without NIR capabilities
Ping/Traceroute may not Correlates and tells you
take same path as Service what caused these
flow in Fabric - anomalies – buffer drops,
troubleshooting is not queue drops, QOS drops,
accurate policy, ACL, policer,
With NIR forwarding drops
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
I need to Capacity
Plan
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Capacity planning
Operational, configuration, hardware, environmental
Stats Collection resource utilization, interface and routing protocol stats,
flow records
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
My switch is not
forwarding any
Traffic to
Destination X
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
BGP statistics
NIR will ingest and correlate BGP data per node which includes -
1) Number of BGP Sessions per switch
2) Total number of Neighbors per switch
3) Per Neighbor information on operational state, address family, connection
attempts, prefixes sent and accepted paths
4) Anomalies and trends for the above data. Anomalies bubbled up in
dashboard for BGP - For example: connection retries and connection
drop counts, sudden increase/decrease in prefixes received/sent
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
BGP Statistics
BGP Protocol data and Anomalies
NIR recommendations
BGP Anomalies in
Dashboard
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
I see CRC errors
on my interface.
Could it be
because of
Interface Optics?
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
DOM Anomaly
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Other use
cases!
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Interface Errors
• Capture Stats, Errors, Drops, Utilization and Rate of all
Stats Collection
Interfaces
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Monitoring vPC
• vPC State and stats, vPC Domain State, Peer State,
Stats Collection Role, Orphan Ports
• Operational state
Correlate If same EPs are not learnt across vPC legs, this is
& Diagnose correlated to vPC inconsistency
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Network Insights Advisor
NIA
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
How Can NIA Help with Day 2 Operations?
Deployment-specific
recommendations & best practices,
Advisories upgrade impact
analysis/Experience*
Network
Alert to known defects, PSIRTs,
Insights Anomalies Flow State Validator
Advisor
System hardening checks, version-
Compliance specific scale limits monitoring (NIR
-> NIA) to generate advisory *
* Roadmap BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
First, We Need Data!
Network Cisco
Provides: Provides:
• Running config of all devices • Best practices updates
• “show tech” from all devices • PSIRTs, FNs, EOS/EOL
(including APIC) • Software release notifications
• Digitized signatures of known
defects
NIA
Network On-prem Data Cloud Data Cisco
User-specified
Every 24h
interval
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
NIA Architecture
EOL/EOS
“show run”
Data Collection
“show tech”
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
How does NIA detect known issues?
Hardening
Check
Tech Storage
Support Data Sources Signature Advisory NIA – GUI
and ‘show
Matching Services
run’
Insights DB
collection
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
NX-OS
Flow State Validator – SW/HW State Validation
for a Flow Check
Input flow info
Software and
hardware
consistency
on each
switch
Once complete,
view details
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Alert me about Field Notices/EOL/EOS/Recommended
Code Notifications
s Affected devices: 3
Leaf 1, Leaf 2, Leaf 3
3 Alert / Inform Anomaly: EOS of current software
Recommend:
Upgrade S/W to NXOS 7.0(3)I7(3)
NIA
Push
Notification Insight DB
Fabric
1
Monitor
4 Implement
p Affected
devices
s S/W 2 Identify Switches
Notify
p p p
Remediate
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
TAC Assist
Helps with log collection directly from the app. These logs can then be attached to an
SR. Optionally upload to Cloud
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Upgrade impact
When a software upgrade advisory is generated, an upgrade impact can be measured
from NIA per switch
Advisory to
Upgrade
Number of Hops
to upgrade
Measure
Upgrade Impact
Non-
Disruptive
disruptive
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
NIA Inbox
Used to send important notifications to end users
• New App Version, new NXOS software, new APIC/DCNM releases
• In future, will be used by Cisco to communicate with customers on best practices,
scripts, FAQs
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
NI Base 2.0.1 $0
ACI 4.2(3), DCNM 11.3(1)
• Infra details
Collect basic info about customer Hardware/Software and send to Cisco
• TAC Assist
Allows user to collect Tech-Support from NI app for specific or set of nodes
• Tech Support to Cloud
Allows user to upload Tech-Support to Cloud. These logs can then be accessed by
TAC searchable using Serial #
• Fast Start
Enables TAC to pull data from customer premise using NI App. No manual intervention
is needed
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
DEMOS on NIR/NIA
Scale, Software,
Hardware Support
Network Insights Resources Scale – NIR 2.1
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Network Insights Resources 2.1
Software and Hardware Support
Nexus
Nexus Nexus
9300 /
Telemetry Type 9300-EX / 9364C /
9500 1st
FX / FX2 9332C
Gen
Software
Yes Yes Yes
Telemetry
ACI Software Version APIC / ACI Release - 4.2(3) / 14.2(3) AND 3.2(8) / 13.2(8)
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Network Insights Advisor 2.0.1
Software, Hardware Support and Scale
Nexus 9300 / 9500 1st Gen and Cloud Scale –
Nexus 3000 (All Models) – NXOS only
ACI and NXOS
Minimum Standalone Software DCNM release 11.3(1) NX-OS release 7.0(3)I7(1) or later
Versions
FSV – 9.3(3) onwards
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Compute
Requirements for
NIR/NIA
Supported fromACI
* In planning
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
ACI/APIC Compute Requirements for NIR 2.1
Software Telemetry
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
ACI/APIC Compute Requirements for NIA 2.0.1
Up to 20 Nodes
21 - 100 Nodes
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
DCNM/NX-OS Compute Requirements for
Network Insights
Hardware Recommendations for Deployments up to 80 Switches and 2000 Flows
Node Deployment CPU Memory Storage Network
Mode
Cisco DCNM OVA/ISO 16 vCPUs 32G 500G HDD 3x NIC
Computes (x3) OVA/ISO 32 vCPUs 64G 500G HDD 3x NIC
Hardware Recommendations for Deployments from 81 to 250 Switches and 10000 Flows
Node Deployment CPU Memory Storage Network
Mode
Cisco DCNM OVA/ISO 16 vCPUs 32G 500G HDD 3x NIC
Computes (x3) ISO/Service 40 vCPUs 256G 2.4TB HDD 3x NIC*
Engine
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Licensing
Network Insights and Assurance: Licensing
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Network Insights and Assurance:
Licensing
NIR/NIA/NAE license is part of Premier Edition License
Premier tier and separate License is not required
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Agenda
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Network Insight Telemetry Applications
Providing Pervasive Network Health Visibility & Enabling Proactive Insights
New Apps
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Main Message
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
BRKDCN-2712 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Thank you