Professional Documents
Culture Documents
Enterprise Networking and SD-Wan With Cisco and AWS
Enterprise Networking and SD-Wan With Cisco and AWS
SPONSORED BY CISCO
En t e r p r ise Ne t w o r k in g a n d
SD-WAN w it h Cisco a n d AWS
Nikolai Pit aev Sim arbir Singh
Te chnica l Ma rke t ing Engine e r Te ch n ica l Ma rke t in g En g in e e r
SD-WAN a nd Cloud Virt u a liza t io n a n d SD-WAN
Cisco Cisco
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Ag e n d a
Centralized firewall insp ection arch itecture with SD-WAN
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Wh a t is SD-WAN n o w ?
Yesterday Today
• Sep aration of control
• IaaS: cloud is just another
an d d ata p lanes
branch/ PoP
• Policy-b ased application
• SaaS with first packet m atch
path selection across
and cloud telem etry
m ultip le WAN connections
• Cloud app detection and
• Service chainin g for
integration into SD-WAN
ad d ition al services
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Wh ich Cisco SD-WAN?
SD-WAN
Powered By Powered By
Vipt ela
4
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ce n t ra lize d fire w a ll
in sp e ct io n a n d SD-WAN
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Ce n t r a lize d fir e w a ll in sp e ct io n a n d SD-WAN
USE CASE OVERVIEW
Public internet
FTDv = Se cure Fire wa ll Thre a t De fe nse Virtua l (a ka FTDv / NGFWv) Ge ne ve = Ge ne ric Ne twork Virtua liza tion Enca p sula tion
GWLB = AWS Ga te wa y Loa d Ba la nce r TGW = AWS Tra nsit Ga te wa y AZ = Ava ila b ility Zone (AWS da ta ce nte r) © 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ho st VPC co n n e ct ivit y o p t io n s
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Pa ck e t flo w : Sim p lifie d
AWS us-west Host VPC1 Host VPC2 From Host VPC to SD-WAN
App1 App2 Host VPC ➔ AWS TGW ➔ GWLB ➔ FTDv ➔ TGW ➔ SD-WAN
Shared services VPC
Returning traffic
SD-WAN ➔ AWS TGW ➔ GWLB ➔ FTDv ➔ TGW ➔ Host VPC
AZ1
FTDv-1
… AWS TGW
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Pa ck e t flo w : De t a ils fo r sh a r e d se r vice s VPC
Shared services VPC Shared services VPC
GWLB
GWLB AZ1
endpoint 7
AZ1
endpoint 2 FTDv-1
FTDv-1
FTDv-2
FTDv-2
3 6
GWLB 5 GWLB
4 cross-zone load
cross-zone load
balancing,
balancing,
GENEVE
GENEVE
Step 2: TGW routes to GWLB endpoint – shared services route table Step 5: Firewall decapsulates GENEVE, inspects the
10.102.0.0/ 16 local packet, re-encaps and sends it back to GWLB
0.0.0.0/0 vpce-XYZ FW-Endpoint -Service-AZ1 10.102.3.91
Step 6: GWLB rem oves GENEVE header and forwards
Step 3: GWLB endpoint routes traffic to GWLB using AWS PrivateLink packet to the appropriate GWLB endpoint
Step 4: GWLB routes traffic to a firewall using GENEVE
Target Group: FW-Target -Group-Geneve wit h 4 firewalls: Step 7: GWLB endpoint sends packet to TGW
10.102.3.174 MC-FTD-IFT-1 6081 us-west -AZ1
10.102.13.67 MC-FTD-IFT-2 6081 us-west -AZ1
…
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Co n n e ct in g SD-WAN
AWS us-west Host VPC1 Host VPC2 VPN or connect at t achm ent for SD-WAN VPC
App1 App2
Shared services VPC BGP bet ween AWS TGW and SD-WAN rout ers
AZ1
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco SD-WAN a n d
AWS Clo u d WAN
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Cisco Mu lt iclo u d So lu t io n s fo r AWS
US-We st-1
Ho st VPC Ho st VPC
AWS
TGW
VPN At t ach men t (IPSec) o r
Connect At t achment (GRE)
SD-WAN TVPC
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco SD-WAN a n d AWS Clo u d WAN
USE CASE OVERVIEW
Use case Ap p s in
an y region
• Sit e-t o-Cloud VPC
Benefits
Cisco SD-WAN Fabric
• Easily st it ch SD-WAN & cloud Cisco
across m any region s vMan age
• End-t o-End Segm ent at ion
• Secure, Scalable and On -
Los An geles Lon d on
Dem and Bandwidt h SD-WAN Bran ch SD-WAN Bran ch
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ar ch it e ct u r e
Core Ne t work Policy (CNP):
• Re gion s Region 1 Region 2 Region 3
• Ed ge s VPC VPC VPC VPC VPC VPC
• Se gm e n t s
• Dyn am ic rout in g
• At t ach m e nt s
• Sh arin g (rout e le akin g) CNP AWS Core Network
• Se rvice In se rtion (FW)
CNE-1 CNE-2
CNE-3
TVPC
Cisco CGW
vManage
Test
Pro d
CNE – Co re Net wo rk Ed g e CNP – Co re Net wo rk Po licy TVPC – Tran sit VPC CGW – Clo ud Gat eway © 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco SD-WAN o r ch e st r a t io n fo r Clo u d WAN
USE CISCO VMANAGE TO DEPLOY AND MANAGE AWS CLOUD WAN
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Wo r k flo w – Cisco vMa n a g e
CLOUD ONRAMP FOR MULTICLOUD
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ma p p in g SD-WAN a n d clo u d in fr a st r u ct u r e
ONE CLICK IN THE INTENT MANAGEMENT TABLE
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Clo u d Ma p a s a
b rid g e b e t w e e n a p p s
a n d SD-WAN n e t w o rk
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Cr e a t in g a b r id g e b e t w e e n clo u d a p p s a n d
SD-WAN via AWS Clo u d Ma p
AWS Clo u d Ma p
Ap p
Use case summary DevOp s
“t raffic-p ro file=vid eo ”
Net Op s
Det ails: d eveloper.cisco.com/ d ocs/ cloud -n ative-sdwan/ #!cn -wan -ad aptor
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco Me ra k i a n d AWS
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
A p la t fo r m a p p r o a ch t o SD-WAN
{ HTTPS } { API }
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cr e a t e t h e fo u n d a t io n fo r
high -quality experience in three clicks
Simple Th e ab ilit y t o con figure sit e -t o-sit e, Laye r 3 IPse c VPN t un n e ls in just three clicks in t h e Cisco Me raki d ash b oard
ove r an y WAN lin k
Automatic VPN con figurat ion ge n e rat ed an d d e ploye d aut om at ically from t h e cloud – cre at e a m e sh or h ub -an d -spoke
t op ology wit h on ly a fe w clicks
Resilient Aut om at ically ad just s t o ch an ge s in ord e r t o m ain t ain se cure con n ect ivit y d uring an ISP or d at ace n t e r out age ,
h ard ware failure, or IP ad d re ss up d at e
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ext e n d se cu r it y d e e p in t o t h e clo u d
MULTI - REGION CONNECTIVITY
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco Me ra k i vMX a n d
AWS Tra n sit Ga t e w a y
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Ext e n d in g SD-WAN t o
AWS Tr a n sit Ga t e w a y
• Ext end your branch SD-WAN deploym ent s t o
applicat ions host ed on AWS
• Highly available archit ect ure for deeper
connect ivit y t o cloud resources via AWS
Transit Gat eway (TGW) using AWS lam bda
• Single-but t on aut om at ed deploym ent via
AWS Quick St art
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco Me ra k i vMX a n d
AWS Clo u d WAN
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Mu lt i-Re g io n AWS Cloud
d e p lo ym e n t Region Region
u se ca se
SD-WAN VPC SD-WAN VPC
Cisco
Meraki
vMX
Wo rklo ad VPCs
SD-WAN
Tunnels
Bran ch sit es
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Sim p lifie d m u lt i-Re g io n d e p lo ym e n t
AWS Cloud
Region
SD-WAN VPC
SD-WAN Cisco
t u n n els Meraki
vMX
Bran ch sit es
Region
SD-WAN Seg m en t
SD-WAN VPC
Workload
SD-WAN Wo rklo ad Seg ment VPC
t u n n els Cisco
Meraki
Bran ch sit es
vMX • Sim p lified m ult i-Region
con n e ct ivit y
E E E
Workload
VPC • Man age d Tran sit Gat e way
• Se gm e n t at ion an d
Region
in t e n t -based p olicie s
SD-WAN VPC
Cisco
• Re gion al h ub s as VPC
SD-WAN
t u n n els
Meraki
vMX
at t ach
Bran ch sit es
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco Me r a k i vMX w it h AWS Clo u d WAN
TOPOLOGY FOR THE DEMO
AWS Cloud
CW Po licy
AWS Core Net work
Reg io n A Reg io n B
VPC At t ach m en t
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cisco SD-WAN o r ch e st r a t io n fo r Clo u d WAN
USE CISCO MERAKI TO DEPLOY AND MANAGE AWS CLOUD WAN
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Wo r k flo w – Cisco Me r a k i
CLOUD ONRAMP FOR MULTICLOUD
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Se cu rin g t h e VPC
w it h SASE
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.
Se cu r in g t h e VPC w it h SASE
USE CASE OVERVIEW
SASE Su bn et SD-WAN Su b n et
(Int ern et Gat eway) (Bran ch Co n n ect ivit y)
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ne xt st e p s
Ch eck out t h e
Risk-free evaluat ion Ch eck out our web sit e & b log Cisco Meraki vMX Quick st art s
Dem o an d m ore in form at ion at our b oot h © 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you!
Nikolai Pit aev Sim arbir Singh
np it a e v@cisco .com sim a rb si@cisco .co m
lin ke din.com / in/ npit a e v/ lin ke d in .co m / in / sim a rb ir-sin g h -8 55 0 7 72 4 /
© 2021, Am
Amazon
a zon We
Webb Se
Services,
rvice s, Inc.
Inc.ororitsitsaaffiliates.
ffilia te s. All
All rights
rights re
reserved.
se rve d.