SlideShare a Scribd company logo
1 of 57
Download to read offline
Danny Blais & Luis Cruz
Consultants en ingénierie de réseaux
Cisco SD-WAN: Un réseau basé sur
l'intention pour les succursales et le réseau
étendu
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Digital Innovation in the Branch & WAN
of revenue
is generated
in the branch
90%
MORE
THREATS
30%
Of advanced threats will
target branch offices by
2016 (up from 5%)
MORE
USERS
80% Of employee and
customers are served in
branch offices
MORE
DEVICES
73%
Growth in mobile
devices from
2014-2018
MORE
APPS
20-50% Increase in enterprise
bandwidth per year
through 2018
IoT devices
connected to
internet by 2020
30B
Annual increase in
enterprise
bandwidth and video
adoption
50%
Up to
Mobile-connected
devices by 201910B
Of Organizations primarily
use public cloud by 201980%
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
Traditional and Legacy Architectures
cannot scale to address changing needs EXPENSIVE
Hardware-centric
Fixed capacity
DIFFICULTTO SUPPORT
Discrete device-by-device
configurations
Complex management silos
Require slow truck
rolls for changes
INFLEXIBLE
Tightly controlled, client server model
Historical vs predictive management
CONNECTIVITY-CENTRIC
Fragmented, incomplete user experience
Not application-centric
POORLY INTEGRATED
Conflicting policies
and configurations
Inflexible and static
Risk from accidental
interactions and vulnerabilities
Programmable
Hardware Centric
Automated
Predictive
Business Intent
Manual
Closed
Network Intent
Reactive
Software Driven
CLOUD & ON-PREM
Hosted, delivered, managed
AUTOMATION & SCALE
Speed, flexible, zero-touch, policy
driven
SECURITY & COMPLIANCE
Segmentation,
threat mitigation
ASSURANCE & ANALYTICS
Users, applications, devices
Network Transformation
The Era of Digital Transformation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What & Why is SD-WAN
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The WAN Has Changed
Data
Center
Multi-
Cloud
SaaS
Internet
SAAS
Branch
WAN
Users
Devices
Things
INET
MPLS
Users Internet
MPLS
Branch WAN
Data Center
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Software Defined WAN
Hybrid WAN Transport
IPsec Secure
Branch
MPLS (IP-VPN)
Internet
Direct Internet
Access
Private
Cloud
Virtual
Private
Cloud
Public
Cloud
Application
Optimization
Secure
Connectivity
Efficient and
dynamic
load sharing
Agnostic WAN
Transport
Simplified Management, Operation and Orchestration
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8
SD-WAN
Business Case
Cost
• Substitute higher cost links or devices for lower cost
• Lower cost of management, troubleshooting
• Leverage Complete Communications for financial analysis
Agility
• Focus on how automation and policy abstraction empower the
organization to innovate faster while transforming the customer and
workforce experience
Focus
• Provide quantifiable metrics associated with expedited mean time to
detection, mean time to innocence and mean time to repair
Performance
• Quantify frequency and cost associated with outages
• Reduce number of outages affecting user performance
• Improve application performance
Security
• Application relevant topologies
• Segmented virtual WANs and security service chains
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Choosing the right solution
• Layer 3 VPN overlay for hub-and-spoke deployments
• Layer 3 and 7 policy and performance based routing
• Transport independence across a variety of connection types
• Zero touch deployment with support for templated configurations
• Multicast support over WAN
Cisco SD-WANMeraki SD-WAN
Highly flexible and customizableSimple, cross-functional management
• Support for 3 or more uplinks
• Service chaining at L4-L7
• TCP Optimization and WAN acceleration
• Highly flexible segmentation with customizable
topologies on a per-VRF basis
• VNF capabilities for gray and white-box MSP/SP offers
• IPv6 support
• On-premises and private cloud management
• Support for integrating multiple VPC workloads
(OnRamp) and extending WAN segmentation into IaaS
• Highly scalable (10,000+ sites)
• LTE failover
• Virtual platform for AWS / Azure
• Public cloud management
Shared Capabilities
• Single pane of glass management for full stack
branch infrastructure (security, WAN, switching,
wireless, and more)
• Cisco Advanced Malware Protection
• Cisco Snort IPS
• Integrated URL filtering
• Geo-IP based firewalling
• Intuitive GUI-based configuration and monitoring
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10
APPLICATION POLICIES
SERVICES DELIVERY PLATFORM
TRANSPORT INDEPENDENT FABRIC
Broadband CellularMPLS
ZERO TOUCH ZERO TRUST
QoSSecurity Segmentation Svc Insertion SurvivabilityRouting Multicast
Per-Segment
Topologies
Cloud Path
(IaaS)
Application
SLA
Secure
Perimeter
Traffic
Engineering
Transport
Hub
Cloud Accel
(SaaS)
Analytics
Monitoring
Operations
Business Driven WAN Infrastructure
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco’s SD-WAN
Architecture
Supervisor
(Control Plane)
I/O Module
(Data Plane)
Switch Fabric
(Backplane)
SD-WAN Architecture
CLI
(Management Plane)
Supervisor
I/O Module
Switch Fabric
SD-WAN Architecture
Control Plane
Data Plane
Management Plane
Orchestration Plane
Backplane
vBond
CLI
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
Data Plane
Data Plane
Physical/Virtual
Cisco vEdge
• WAN edge router
• Provides secure data plane with
remote vEdge routers
• Establishes secure control plane
with vSmart controllers (OMP)
• Implements data plane and
application aware routing policies
• Exports performance statistics
• Leverages traditional routing
protocols like OSPF and BGP.
• Layer 2 redundancy VRRP
• Support Zero Touch Deployment
• Physical or Virtual form factor
(100Mb, 1Gb, 10Gb)
APIs
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
Control Plane
Control Plane
Cisco vSmart
• Centralized brain of the solution
• Facilitates fabric discovery
• Establishes OMP peering with all
vEdges
• Implements control plane policies,
such as service chaining, traffic
engineering and per VPN topology
• Dramatically reduces complexity of
the entire network
• Distributes connectivity information
between vEdge
• Orchestrates secure data plane
connectivity between vEdges
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
APIs
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
Management Plane
Management Plane
Cisco vManage
• Single pane of glass for Day0,
Day1 and Day2 operations
• Real time alerting
• Centralized provisioning,
monitoring & troubleshooting
• Configuration standardization
• RBAC
• Single or Multitenant
• Programmatic
• REST API
• Syslog
• CLI
• SNMP
• NETCONF
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
APIs
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17
Orchestration Plane
APIs
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
• Orchestrates connectivity
between management, control
and data plane
• First point of authentication
• Requires public IP Address
• Facilitates NAT traversal
• All other components need to
know the vBond IP or DNS
information
• Authorizes all control
connections (white-list model)
• Distributes list of vSmarts to
all vEdges
Orchestration Plane
Cisco vBond
Software Defined Centralized Control
Unified Control Plane provided by OMP (Overlay Management
Protocol)
Control Plane
DTLS/TLS
Legacy
O(n^2) complexity
SD-WAN
O(n) complexity
Control Elements
• Virtual Fabric over any transport
• Virtual or Physical Platforms (vEdge)
• Centralized reachability, security and
application policies
• Secure Channel to SD-WAN Controller
(vSmart, vBond, vManage)
- Single extensible control plane
- Operates over DTLS/TLS authenticated and
secured tunnels
• Dramatically lowers complexity and
increases overall solution scale
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Ingress
vEdge
VPN 3
VPN 1
VPN 2
SD-WAN
IPSec
Tunnel
20
IP
8
UDP
36
ESP
4
VPN
…
Data
Egress
vEdge
Interface
VLAN
• Segment connectivity across fabric w/o
reliance on underlay transport
• vEdge routers maintain per-VPN routing
table
• Labels are used to identify VPN for
destination route lookup
• Interfaces and sub-interfaces (802.1Q tags)
are mapped into VPNs
VPN1
VPN2
Interface
VLAN
VPN1
VPN2
Secure Segmentation
End-to-End Segmentation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
End-to-End Segmentation with Multi-Topology
A
B
C
A
B
C
vEdge Router vEdge Router
vSmart
Route
Tables
Single Tunnel
(per transport)
 Security Zoning
 Compliance
 Guest Wi-Fi
 Multi-Tenancy
 Extranet
Full-Mesh Hub-and-Spoke Partial Mesh Point-to-Point
Per-VPN Topology
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
Application Quality Probing
Regional
Hub
Remote Site
ISP2
ISP1
SD-WAN
Fabric
Loss/
Latency
!
Data Center
Cloud onRamp for SaaS
Data Center
Regional
Hub
Remote Site
SD-WAN
FabricMPLS
ISP1
Loss/
Latency
!
ISP2
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23
Cloud Security with Cisco Umbrella
Regional
Data Center
Remote Site
ISP1
SD-WAN
Fabric
DNS Queries
Data Center
DIA
• Best suited for cloud SaaS
applications
• Interoperates with Cloud onRamp
for SaaS
• Cisco Umbrella enforces security
policy compliance based on DNS
resolution
• Augments native fabric security
• Can co-exist with on-premise L4-
L7 security modes
- VPN segmentation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
Regional Secure Perimeter
Single Service Insertion
• vEdge router with connected L4-L7
service makes advertisement
- Service route OMP address family
- Service VPN label
• Service is advertised in specific VPN
• Service can be L3 routed or L2 bridged
• Service can be singly or dually connected
(Firewall trust zones) to the advertising
vEdge
• Control or data policies are used to insert
the service node into the matching traffic
forwarding path
- Match on 6-tuple or DPI signature
- Applied on ingress/egress vEdge* For data policy only. Control policy enforced on vSmart.
Data
Center
Remote
Office
Regional
Hub
L4-L7 Service
Advertisement
Policy
Advertisement*vSmart
VPN1
VPN1
VPN1
Traffic Path
Control Plane
FW
4GMPLS
INET
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
Regional Secure Perimeter
Multiple Services Chaining
Data
Center
Remote
Office
• vEdge routers with connected L4-L7 service
make advertisement
- Service route OMP address family
- Services VPN labels
• Services are advertised in specific VPN
• Services can be L3 routed or L2 bridged
• Services can be singly or dually connected
to the advertising vEdges
• Control or data policies are used to insert
the service nodes into the matching traffic
forwarding path
- Match on 6-tuple or DPI signature
- Applied on ingress/egress/service vEdge
Regional
Hub
vSmart
* For data policy only. Control policy enforced on vSmart.
VPN1
VPN1
VPN1
Policy
Advertisement*
Service
Advertisement
FW IDS
Traffic Path
Control Plane
4GMPLS
INET
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
Deep Packet Inspection Engine
Primary Use Cases:
- Application Visibility
- Application Firewall
- Traffic Prioritization
- Transport Selection
- Analytics
vEdge Router
App 1
App 2
App 3,000
Cloud Data
Center
Data
Center
Campus
Branch
Small Office
Home Office
MPLS INET
3G/4G
Embedded Application Recognition
Deep Packet Inspection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
28BRKRST-2092
App-Aware Routing Policies
• SLA-Driven Routing / Performance Routing
Broadband
4G/LTE
MPLS
#
DPI POLICY SLA
lte
mpls
public-internet
VPN 1
VPN 2
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29
 Enforce SLA compliant path
for applications of interest
 Other applications will follow
fabric routing across all
paths
Control Plane
Path1: 10ms latency, 0% loss, 5ms jitter
Path2: 200ms latency, 3% loss, 10ms jitter
Path3: 140ms latency , 1% loss, 10ms jitter
vManage
App Aware Routing Policy
App A path must have:
latency < 150ms
loss < 2%
jitter < 10ms
vEdge1 vEdge2
MPLS
Internet
4G LTE
vSmart Controllers
App A
IPSec Tunnel
Critical Applications SLA
Path Quality Detection Routing
Path 2
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30
• High latency path between users and
servers, i.e. geo-distances
• vEdge routers terminate TCP sessions and
provide local acknowledgements to prevent
TCP windowing from reacting
• Selective acknowledgements prevents
unnecessary retransmit of the successfully
received segments
• Hosts using old TCP/IP stacks will see the
most benefit
Users Servers
High Latency Path
vEdgevEdge
TCP Connections TCP Connections
Optimized
TCP Connections (Cubic)
SD-WAN
Fabric
Application Optimization
TCP Performance Optimization
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
INET
MPLS
Site
Data
Center
Network/Headend Redundancy
MPLS
INET
vSmart Controllers
Control
Data
Control Redundancy
INET INETMPLSMPLS
Transport Redundancy
High Availability and Redundancy Overview
VRRP OSPF/
BGP
OSPF/
BGP
Site Redundancy
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN
Operation and Management
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
Zero Touch Provisioning – vEdge Appliance
Control and Policy
Elements
* Factory default config
Assumption:
• DHCP on Transport Side (WAN)
• DNS to resolve ztp.viptela.com*
 Delivered as-a-Service
Zero Touch Provisioning
Server
1
2
Full Registration and
Configuration
5
3
4
vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
Simplified Management
REST NETCONF Syslog Flow ExportSNMP CLI Linux Shell
Power Tools
Single Pane Of Glass Operations RichAnalytics
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36
Single Pane of Glass Operations
vManage GUI
• Intuitive GUI driven operations
- Management, monitoring and
troubleshooting
• Cloud Delivered
- Private, hosted or managed
• Single or Multi-tenant
• Role-based Access Control
• Clustered for scale and high
availability
• REST APIs based
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37
• Embedded Deep Packet Inspection
engine
• Application and flow level visibility
for the fabric and individual vEdge
routers
• Centralized statistics and
performance
• Export flow level data (IPFIX) to
external collector
Application and Performance Visibility
Deep Packet Inspection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 39
• vManage measures performance for
popular SaaS applications
(Loss/Latency)
• Quality of experience score is assigned
- Range is from 1 to 10
• Indicates optimal Internet exit point toward
the SaaS applications of interest
SaaS Application Performance
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 40
Centralized Device Configuration Enforcement
• Centralized Feature Templates
• Enforces configuration compliance
• Self-recover on misconfiguration
• Feature Configuration with
Variables
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41
Policy Driven WAN Infrastructure
Policy Augmented Dynamic Routing
vEdge
WAN
router
Access Layer
Branch/DC
vSmart controller – Policy
Enforcement/Advertisement
Control Policy:
Routing and Services
vManage GUI – Policy Orchestration1
2
3
Data Policy:
Extensive Policy-based
Routing and Services
App-Route Policy:
App-Aware SLA-based
Routing
Combine and Apply per Site
Execute Control Policy
Advertise AAR/Data Policies to Sites
Execute AAR and Data Policy as received
Dynamic Routing and Policies Combine to
dictate behavior
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 45
vAnalytics Dashboard
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 46
1. Bandwidth Usage:
1. Identification of top sources / top destinations / top application (family)
2. Drill-down into information on a per-Site basis
3. Identification of top sources
2. Application Performance:
1. Application to tunnel-binding and performance information
3. Anomaly Detection:
1. Baseline of Application usage. Anomaly detection based on overall application usage / by Family /
by Site
The Power of Analytics
Application Centric (Based on DPI/cflowd)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 47
1. Site Availability (SD-WAN value prop)
1. List of Sites with down-time comparing to TLOCs with their down-time
2. Network Availability
1. List of sites by down-time
2. Comparison of Site down-time vs TLOC down-time (SD-WAN value prop)
3. Down site count on a time basis with the ability to drill-down into Sites and downtimes
3. Site Usage Analysis
1. Bandwidth consumed by Site (Top Sites)
2. Drill-down to show historical bandwidth consumption by time
4. Carrier Performance
1. App-Route stats based on a per-carrier basis
2. Ability to drill-down on a specific carrier and visibility into various remote carrier connectivity
The Power of Analytics
Network Centric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 48
vAnalytics – BW Consumption by Applications
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 49
vAnalytics – Network Health by Carriers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Portfolio &
Scale
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 51
Summary: Solution Elements
Orchestration, Control, Data and Management Planes
Control Plane
Cisco vSmart
• Facilitates fabric discovery
• Dissimilates control plane
information between vEdges
• Distributes data plane and app-
aware routing policies to the
vEdge routers
• Implements control plane
policies, such as service
chaining, multi-topology and
multi-hop
• Dramatically reduces control
plane complexity
• Highly resilient
Data Plane
Physical/Virtual
Cisco vEdge
• WAN edge router
• Provides secure data plane
with remote vEdge routers
• Establishes secure control
plane with vSmart controllers
(OMP)
• Implements data plane
policies
• Exports performance statistics
• Leverages traditional routing
protocols like OSPF, BGP and
VRRP
• Support Zero Touch
Deployment
• Physical or Virtual form factor
(100Mb, 1Gb, 10Gb)
Management Plane
Cisco vManage
• Single pane of glass for
Day0, Day1 and Day2
operations
• Centralized provisioning
• Policies and Templates
• Troubleshootingand
Monitoring
• Software upgrades
• GUI with RBAC
• Programmatic interfaces
(REST, NETCONF)
• NMS interfaces (SNMP,
Syslog, IPFIX)
Orchestration Plane
Cisco vBond
• Orchestrates control and
management plane
• First point of authentication
(white-list model)
• Distributes list of vSmarts/
vManage to all vEdge routers
• Facilitates NAT traversal
• Requires public IP Address
[could sit behind 1:1 NAT]
• Highly resilient
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Platform Options
ISR 1000 ISR 4000 ASR 1000
High-
performance
HW & SW
redundancy
Modular
Integrated
service
containers
Next-gen
Performance
flexibility
Branch Services
Public Cloud
vEdge 2000
10 Gbps
Modular
vEdge 1000
Up to 1 Gbps
Fixed
vEdge 100
100 Mbps
4G LTE & WiFi
SD-WAN
Virtualization
ENCS 5100
20 Gbps, Modular
vEdge 5000
ENCS 5400
vEdge Cloud
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
58
Controller Deployment Models
vManage
vSmart vBond
Cloud-Delivered
Cisco
Cloud
Deployed by Cisco Deployed by Customer or SP
On-Premise
Recommended Control and
Management Elements
Private
Cloud
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 62
Data Center Campus Branch Home Office
4G/LTE
MPLS
Internet
Control Plane
(Containers or VMs)
(vSmart – up to 20)
Management Plane
(Multi-tenant or Dedicated)
(vManage – up to 6)
Orchestration Plane
(vBond - up to 6)
1500 vEdges per vBond
Redundancy Add 1-2 vBonds
Horizontal Scale out Model
Horizontal Scale Out Model
2000 vEdges per vManage
Horizontal Scale out Model
in cluster mode (same DC)
2700 vEdges per vSmart
Redundancy Add 1-2 vSmarts
Horizontal Scale out Model
Scalability
Orchestration/Control/Management Plane
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Viptela Integration Plan
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Integration Roadmap
Phase 2
Platform Integration
Phase 1
No Integration
Phase 3
Management Integration
Platform:
• As-is
Management:
• vManage
Platform:
• vEdge capabilities integrated into all IOS-XE
platforms (ISR, CSR, ENCS, ASR1K)
Management:
• vManage for SD-WAN capabilities on IOS-XE
Management:
• Cloud hosted DNA Center integrates vManage
capabilities
• Full DNA Center capabilities (Assurance,
Integrated workflows for SD-Access and
SD-WAN)
Support current Viptela
customers
Viptela SD-WAN on strategic ISR
platform
Deliver end-to-end experience
with full DNA integration
DeploymentScenariosBenefitsDetails
vEdge ISR4K + vEdge SW
DNA Center
+ SD-WAN
ISR4K + vEdge SW
vManage
vEdge
vManage
vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Clarification On SDWAN Terminology
Viptela H/W With All Software Capabilities As-Is
vEdge
Traditional IOSXE With IWAN capabilities, for ISR4K, ASR, CSR & ISRv
ISR
SDWAN Enabled IOSXE for ISR4K, ASR, CSR & ISRv
"SDWAN Enabled
ISR" Only Features Highlighted In The Next Slide Are Included In The SD-WAN Image
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Software
SD WAN Features
 ZTP, App Route Policy, HQoS,
Segmentation, NAT DIA, BFD PMTU
 Cloud onRamp–IaaS
IOS Features:
 NBAR2, Umbrella (DNS redirect)
 Zone Based Firewall
Deployments:
 TLOC Extension
Routing Protocols
 BGP, OSPF
Other Features
 VRRP, DHCP server,
 DNS, RADIUS, Syslog, NTP
Monitoring & Troubleshooting
 System & Interface stats
 vManage with DPI, Analytics
July 2018 (16.9.1) Nov 2018 Jan 2019 Post Jan 2019
Hardware
SD WAN Features
 Cloud onRamp-SaaS
 TCP Optimizations
 IPv6 support (Transport)
 Service chaining
 AppQoE – phase1 (FEC, TCP Opt)
 Security – phase 2 (AMP etc)
 CLI templates for XE-SDWAN
IOS Features
 Multicast (Auto-RP, Static-RP)
 EIGRP
 NBAR2 Custom App
Platforms
 ISR43xx, ISR4221, ASR1001-X, ASR1002-
X, ASR 1001-HX, ASR 1002–HX, ISRv
(ENCS) 5412, C1111-8P LTEEA/LA,
C1117-4PLTEEA/LA, C1111-8P
New Interfaces
 Ethernet, 4G LTE, T1/E1, xDSL
Services
 AppNav Functionality
 UC –SRST, PSTN GW, SIP GW
SDA segmentation use case
Platforms:
 ASR1006-X, ASR1009-X
New Interfaces
 Port Channel, UCSE, NIM-1T/2T/4T
In PlanningCapabilitiesin“SD-WANIntegratedIOSXE”
Integration Roadmap
IOS Features:
 SD-AVC
 Ipv6 service side support
Routing protocols:
 BGP for IPv6
 Multiple BGP community tags
Security:
 Segmentation scale to 300
VRFs
 On-Prem: IPS/IDS, URL
Filtering
 Umbrella auto-registration
 Cloud: Local domain bypass
for umbrella
Monitoring & Troubleshooting
 Multitenancy scale 500
tenants
 Template Imp, Network
design builder
Platforms
CSR, C1111-4PLTEEA, C1111-
4PLTELA, C1116-4PLTEEA C1117-
4PMLTEEA
C1111-4P, C1116-4P, C1117-4P,
C1117-4PM, C1111X-8P
Wireless SKU -C1111-
8PLTEEAW, C1111-8PW
Not a commitment, roadmap is subject to change
Platforms
 ISR-4451,
ISR-4431
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 67
APPs
SDWAN
Cloud IoT
.…
SDWAN Fabric
USERS
DC
IaaS
SaaS
vDC
Analytics
SECURE SCALE OPEN
Cloud Delivered
DEVICES
THINGS
SDA Fabric
(branch & campus)
SDA Fabric
(branch & campus)
DC
ACI Fabric
• User / DeviceIdentity, network-wide
• Policyabstraction at User / Group and
Application levels
• Policyat Fabric Edge. Over-the-top.
• Increased Simplicity. Seamless Mobility.
End-to-end Context
SD-WAN Fabric Integration with DNA
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
100+ Global Enterprise Customers Across Verticals
ManufacturingMANUFACTURING
TechnologyTECHNOLOGYRetail RETAIL Other IndustriesOTHER INDUSTRIES
FinServ FINSERV Healthcare / PharmaHEALTHCARE / PHARMA
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Customer Industry Challenge Solution
Retail
High cost, slow change, limited
flexibility
60-70% cheaper broadband at high bandwidth,
centralized control, full visibility.
Financial
Needed more bandwidth and
guaranteed network uptime for a new
teller application
Dollar cost averaged the bandwidth cost down using a mix
of transport (MPLS, Broadband, LTE). Traffic now uses the
optimal network path to avoid downtime and slowdowns.
Tech
Slow performance and MPLS outages
provided an expensive and poor user
experience
Monthly savings reduced the cost per Mbps by more than
80%. Diverse circuits improve the reliability of the global
network, with more than half of Agilent’s sites doubling
WAN redundancy.
Healthcare
With an MPLS contract renewal
approaching, Cigna wanted the
flexibility to change carriers without a
massive technology shift
Gained back control of its control plane and created the
Cigna Service Provider Agnostic Network.
Healthcare Security and high network cost
Satisfied strict security and audit requirements and
provided greater flexibility for partnerships and secure
clinical solutions. Cost reductions with the removal of
remote site voice equipment and expensive PRIs, aging
WAN acceleration equipment and maintenance.
Energy
Scale to support evolving field
operations, and support cloud migration
and application SLAs
Provided 30-60% savings in overall bandwidth costs.
Enabled faster response to acquisitions, divestitures and
policy changes.
Proven Solution Across Multiple Verticals
For Your
Reference
Cisco connect montreal 2018 sd wan - delivering intent-based networking to the branch and wan

More Related Content

What's hot

Cisco Connect Halifax 2018 Simple IT
Cisco Connect Halifax 2018   Simple ITCisco Connect Halifax 2018   Simple IT
Cisco Connect Halifax 2018 Simple ITCisco Canada
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla nsCisco Canada
 
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Canada
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network IntuitiveCisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network IntuitiveCisco Canada
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaCisco Canada
 
Cisco Connect Toronto 2018 dc-aci-anywhere
Cisco Connect Toronto 2018   dc-aci-anywhereCisco Connect Toronto 2018   dc-aci-anywhere
Cisco Connect Toronto 2018 dc-aci-anywhereCisco Canada
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityRobb Boyd
 
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
Cisco Connect Ottawa 2018 dna automation   the evolution to intent-based netw...Cisco Connect Ottawa 2018 dna automation   the evolution to intent-based netw...
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...Cisco Canada
 
Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...
Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...
Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...Cisco Canada
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zeroCisco Canada
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingCisco Canada
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dcCisco Canada
 
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
Cisco connect winnipeg 2018   putting firepower into the next generation fire...Cisco connect winnipeg 2018   putting firepower into the next generation fire...
Cisco connect winnipeg 2018 putting firepower into the next generation fire...Cisco Canada
 
TechWiseTV Workshop: Cisco DNA Center Assurance
TechWiseTV Workshop: Cisco DNA Center AssuranceTechWiseTV Workshop: Cisco DNA Center Assurance
TechWiseTV Workshop: Cisco DNA Center AssuranceRobb Boyd
 
Cisco Connect Halifax 2018 Compute infrastructure for a hybrid cloud ucs an...
Cisco Connect Halifax 2018   Compute infrastructure for a hybrid cloud ucs an...Cisco Connect Halifax 2018   Compute infrastructure for a hybrid cloud ucs an...
Cisco Connect Halifax 2018 Compute infrastructure for a hybrid cloud ucs an...Cisco Canada
 
TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 Robb Boyd
 
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WANCisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WANCisco Canada
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco Canada
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco Canada
 

What's hot (20)

Cisco Connect Halifax 2018 Simple IT
Cisco Connect Halifax 2018   Simple ITCisco Connect Halifax 2018   Simple IT
Cisco Connect Halifax 2018 Simple IT
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
 
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network IntuitiveCisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network Intuitive
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Cisco Connect Toronto 2018 dc-aci-anywhere
Cisco Connect Toronto 2018   dc-aci-anywhereCisco Connect Toronto 2018   dc-aci-anywhere
Cisco Connect Toronto 2018 dc-aci-anywhere
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
 
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
Cisco Connect Ottawa 2018 dna automation   the evolution to intent-based netw...Cisco Connect Ottawa 2018 dna automation   the evolution to intent-based netw...
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
 
Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...
Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...
Architecture of NFV Platform for Orchestrating Cloud-based & vBranch Managed ...
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC Networking
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
 
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
Cisco connect winnipeg 2018   putting firepower into the next generation fire...Cisco connect winnipeg 2018   putting firepower into the next generation fire...
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
 
TechWiseTV Workshop: Cisco DNA Center Assurance
TechWiseTV Workshop: Cisco DNA Center AssuranceTechWiseTV Workshop: Cisco DNA Center Assurance
TechWiseTV Workshop: Cisco DNA Center Assurance
 
Cisco Connect Halifax 2018 Compute infrastructure for a hybrid cloud ucs an...
Cisco Connect Halifax 2018   Compute infrastructure for a hybrid cloud ucs an...Cisco Connect Halifax 2018   Compute infrastructure for a hybrid cloud ucs an...
Cisco Connect Halifax 2018 Compute infrastructure for a hybrid cloud ucs an...
 
TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000
 
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WANCisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
 

Similar to Cisco connect montreal 2018 sd wan - delivering intent-based networking to the branch and wan

Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionCisco Canada
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyCisco Canada
 
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...Cisco Canada
 
 Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation Network Innovations Driving Business Transformation
 Network Innovations Driving Business TransformationCisco Service Provider
 
Cisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnhaCisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnhaldangelo0772
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network EvolutionCisco Canada
 
iWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience SolutioniWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience Solutionxband
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:Cisco Canada
 
Cisco’s Cloud Ready Infrastructure
Cisco’s Cloud Ready InfrastructureCisco’s Cloud Ready Infrastructure
Cisco’s Cloud Ready InfrastructureCisco Canada
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Canada
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrailnvirters
 
NFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch servicesNFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch servicesCisco Canada
 
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformationCisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformationNetworkCollaborators
 
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_diveNur Shiqim Chok
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014ozkan01
 
Cisco IWAN – Intelligent Connectivity for Today’s Reality
Cisco IWAN – Intelligent Connectivity for Today’s RealityCisco IWAN – Intelligent Connectivity for Today’s Reality
Cisco IWAN – Intelligent Connectivity for Today’s RealityCisco Canada
 
Cisco Connect 2018 Indonesia - next-gen cisco sd-wan architecture
Cisco Connect 2018 Indonesia -  next-gen cisco sd-wan architectureCisco Connect 2018 Indonesia -  next-gen cisco sd-wan architecture
Cisco Connect 2018 Indonesia - next-gen cisco sd-wan architectureNetworkCollaborators
 

Similar to Cisco connect montreal 2018 sd wan - delivering intent-based networking to the branch and wan (20)

Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN Technology
 
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
 
 Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation
 
Cisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnhaCisco at v mworld 2015 theater presentation brfarnha
Cisco at v mworld 2015 theater presentation brfarnha
 
The Data Center Network Evolution
The Data Center Network EvolutionThe Data Center Network Evolution
The Data Center Network Evolution
 
BRKCRS-2110.pdf
BRKCRS-2110.pdfBRKCRS-2110.pdf
BRKCRS-2110.pdf
 
iWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience SolutioniWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience Solution
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
 
Cisco’s Cloud Ready Infrastructure
Cisco’s Cloud Ready InfrastructureCisco’s Cloud Ready Infrastructure
Cisco’s Cloud Ready Infrastructure
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
NFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch servicesNFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch services
 
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformationCisco Connect 2018 Malaysia - Innovation towards SP transformation
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
 
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
 
2500 controller
2500 controller2500 controller
2500 controller
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
Banv meetup 04162014
Banv meetup 04162014Banv meetup 04162014
Banv meetup 04162014
 
Cisco IWAN – Intelligent Connectivity for Today’s Reality
Cisco IWAN – Intelligent Connectivity for Today’s RealityCisco IWAN – Intelligent Connectivity for Today’s Reality
Cisco IWAN – Intelligent Connectivity for Today’s Reality
 
Cisco Connect 2018 Indonesia - next-gen cisco sd-wan architecture
Cisco Connect 2018 Indonesia -  next-gen cisco sd-wan architectureCisco Connect 2018 Indonesia -  next-gen cisco sd-wan architecture
Cisco Connect 2018 Indonesia - next-gen cisco sd-wan architecture
 

More from Cisco Canada

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco Canada
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic frCisco Canada
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco Canada
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Canada
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco Canada
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Cisco Canada
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v finalCisco Canada
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kineticCisco Canada
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicingCisco Canada
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco merakiCisco Canada
 
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1Cisco Canada
 
Cisco Connect Toronto 2018 consuming public and private clouds
Cisco Connect Toronto 2018   consuming public and private cloudsCisco Connect Toronto 2018   consuming public and private clouds
Cisco Connect Toronto 2018 consuming public and private cloudsCisco Canada
 
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...Cisco Canada
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kineticCisco Canada
 
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocence
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocenceCisco Connect Ottawa 2018 dna assurance shortest path to network innocence
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocenceCisco Canada
 
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
Cisco Connect Ottawa 2018   data center - protecting your data with Cisco hyp...Cisco Connect Ottawa 2018   data center - protecting your data with Cisco hyp...
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...Cisco Canada
 
Cisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco MerakiCisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco MerakiCisco Canada
 
Cisco Connect Ottawa 2018 consuming public and private clouds
Cisco Connect Ottawa 2018 consuming public and private cloudsCisco Connect Ottawa 2018 consuming public and private clouds
Cisco Connect Ottawa 2018 consuming public and private cloudsCisco Canada
 

More from Cisco Canada (18)

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
 
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
 
Cisco Connect Toronto 2018 consuming public and private clouds
Cisco Connect Toronto 2018   consuming public and private cloudsCisco Connect Toronto 2018   consuming public and private clouds
Cisco Connect Toronto 2018 consuming public and private clouds
 
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocence
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocenceCisco Connect Ottawa 2018 dna assurance shortest path to network innocence
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocence
 
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
Cisco Connect Ottawa 2018   data center - protecting your data with Cisco hyp...Cisco Connect Ottawa 2018   data center - protecting your data with Cisco hyp...
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
 
Cisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco MerakiCisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
Cisco Connect Ottawa 2018 the intelligent network with Cisco Meraki
 
Cisco Connect Ottawa 2018 consuming public and private clouds
Cisco Connect Ottawa 2018 consuming public and private cloudsCisco Connect Ottawa 2018 consuming public and private clouds
Cisco Connect Ottawa 2018 consuming public and private clouds
 

Recently uploaded

Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 

Recently uploaded (20)

Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 

Cisco connect montreal 2018 sd wan - delivering intent-based networking to the branch and wan

  • 1. Danny Blais & Luis Cruz Consultants en ingénierie de réseaux Cisco SD-WAN: Un réseau basé sur l'intention pour les succursales et le réseau étendu
  • 2. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Digital Innovation in the Branch & WAN of revenue is generated in the branch 90% MORE THREATS 30% Of advanced threats will target branch offices by 2016 (up from 5%) MORE USERS 80% Of employee and customers are served in branch offices MORE DEVICES 73% Growth in mobile devices from 2014-2018 MORE APPS 20-50% Increase in enterprise bandwidth per year through 2018 IoT devices connected to internet by 2020 30B Annual increase in enterprise bandwidth and video adoption 50% Up to Mobile-connected devices by 201910B Of Organizations primarily use public cloud by 201980%
  • 3. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3 Traditional and Legacy Architectures cannot scale to address changing needs EXPENSIVE Hardware-centric Fixed capacity DIFFICULTTO SUPPORT Discrete device-by-device configurations Complex management silos Require slow truck rolls for changes INFLEXIBLE Tightly controlled, client server model Historical vs predictive management CONNECTIVITY-CENTRIC Fragmented, incomplete user experience Not application-centric POORLY INTEGRATED Conflicting policies and configurations Inflexible and static Risk from accidental interactions and vulnerabilities
  • 4. Programmable Hardware Centric Automated Predictive Business Intent Manual Closed Network Intent Reactive Software Driven CLOUD & ON-PREM Hosted, delivered, managed AUTOMATION & SCALE Speed, flexible, zero-touch, policy driven SECURITY & COMPLIANCE Segmentation, threat mitigation ASSURANCE & ANALYTICS Users, applications, devices Network Transformation The Era of Digital Transformation
  • 5. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential What & Why is SD-WAN
  • 6. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential The WAN Has Changed Data Center Multi- Cloud SaaS Internet SAAS Branch WAN Users Devices Things INET MPLS Users Internet MPLS Branch WAN Data Center
  • 7. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Software Defined WAN Hybrid WAN Transport IPsec Secure Branch MPLS (IP-VPN) Internet Direct Internet Access Private Cloud Virtual Private Cloud Public Cloud Application Optimization Secure Connectivity Efficient and dynamic load sharing Agnostic WAN Transport Simplified Management, Operation and Orchestration
  • 8. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 SD-WAN Business Case Cost • Substitute higher cost links or devices for lower cost • Lower cost of management, troubleshooting • Leverage Complete Communications for financial analysis Agility • Focus on how automation and policy abstraction empower the organization to innovate faster while transforming the customer and workforce experience Focus • Provide quantifiable metrics associated with expedited mean time to detection, mean time to innocence and mean time to repair Performance • Quantify frequency and cost associated with outages • Reduce number of outages affecting user performance • Improve application performance Security • Application relevant topologies • Segmented virtual WANs and security service chains
  • 9. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Choosing the right solution • Layer 3 VPN overlay for hub-and-spoke deployments • Layer 3 and 7 policy and performance based routing • Transport independence across a variety of connection types • Zero touch deployment with support for templated configurations • Multicast support over WAN Cisco SD-WANMeraki SD-WAN Highly flexible and customizableSimple, cross-functional management • Support for 3 or more uplinks • Service chaining at L4-L7 • TCP Optimization and WAN acceleration • Highly flexible segmentation with customizable topologies on a per-VRF basis • VNF capabilities for gray and white-box MSP/SP offers • IPv6 support • On-premises and private cloud management • Support for integrating multiple VPC workloads (OnRamp) and extending WAN segmentation into IaaS • Highly scalable (10,000+ sites) • LTE failover • Virtual platform for AWS / Azure • Public cloud management Shared Capabilities • Single pane of glass management for full stack branch infrastructure (security, WAN, switching, wireless, and more) • Cisco Advanced Malware Protection • Cisco Snort IPS • Integrated URL filtering • Geo-IP based firewalling • Intuitive GUI-based configuration and monitoring
  • 10. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10 APPLICATION POLICIES SERVICES DELIVERY PLATFORM TRANSPORT INDEPENDENT FABRIC Broadband CellularMPLS ZERO TOUCH ZERO TRUST QoSSecurity Segmentation Svc Insertion SurvivabilityRouting Multicast Per-Segment Topologies Cloud Path (IaaS) Application SLA Secure Perimeter Traffic Engineering Transport Hub Cloud Accel (SaaS) Analytics Monitoring Operations Business Driven WAN Infrastructure
  • 11. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco’s SD-WAN Architecture
  • 12. Supervisor (Control Plane) I/O Module (Data Plane) Switch Fabric (Backplane) SD-WAN Architecture CLI (Management Plane)
  • 13. Supervisor I/O Module Switch Fabric SD-WAN Architecture Control Plane Data Plane Management Plane Orchestration Plane Backplane vBond CLI
  • 14. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14 Data Plane Data Plane Physical/Virtual Cisco vEdge • WAN edge router • Provides secure data plane with remote vEdge routers • Establishes secure control plane with vSmart controllers (OMP) • Implements data plane and application aware routing policies • Exports performance statistics • Leverages traditional routing protocols like OSPF and BGP. • Layer 2 redundancy VRRP • Support Zero Touch Deployment • Physical or Virtual form factor (100Mb, 1Gb, 10Gb) APIs vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET
  • 15. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15 Control Plane Control Plane Cisco vSmart • Centralized brain of the solution • Facilitates fabric discovery • Establishes OMP peering with all vEdges • Implements control plane policies, such as service chaining, traffic engineering and per VPN topology • Dramatically reduces complexity of the entire network • Distributes connectivity information between vEdge • Orchestrates secure data plane connectivity between vEdges vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET APIs
  • 16. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16 Management Plane Management Plane Cisco vManage • Single pane of glass for Day0, Day1 and Day2 operations • Real time alerting • Centralized provisioning, monitoring & troubleshooting • Configuration standardization • RBAC • Single or Multitenant • Programmatic • REST API • Syslog • CLI • SNMP • NETCONF vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET APIs
  • 17. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17 Orchestration Plane APIs vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET • Orchestrates connectivity between management, control and data plane • First point of authentication • Requires public IP Address • Facilitates NAT traversal • All other components need to know the vBond IP or DNS information • Authorizes all control connections (white-list model) • Distributes list of vSmarts to all vEdges Orchestration Plane Cisco vBond
  • 18. Software Defined Centralized Control Unified Control Plane provided by OMP (Overlay Management Protocol) Control Plane DTLS/TLS Legacy O(n^2) complexity SD-WAN O(n) complexity Control Elements • Virtual Fabric over any transport • Virtual or Physical Platforms (vEdge) • Centralized reachability, security and application policies • Secure Channel to SD-WAN Controller (vSmart, vBond, vManage) - Single extensible control plane - Operates over DTLS/TLS authenticated and secured tunnels • Dramatically lowers complexity and increases overall solution scale
  • 19. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN Solution
  • 20. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 Ingress vEdge VPN 3 VPN 1 VPN 2 SD-WAN IPSec Tunnel 20 IP 8 UDP 36 ESP 4 VPN … Data Egress vEdge Interface VLAN • Segment connectivity across fabric w/o reliance on underlay transport • vEdge routers maintain per-VPN routing table • Labels are used to identify VPN for destination route lookup • Interfaces and sub-interfaces (802.1Q tags) are mapped into VPNs VPN1 VPN2 Interface VLAN VPN1 VPN2 Secure Segmentation End-to-End Segmentation
  • 21. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21 End-to-End Segmentation with Multi-Topology A B C A B C vEdge Router vEdge Router vSmart Route Tables Single Tunnel (per transport)  Security Zoning  Compliance  Guest Wi-Fi  Multi-Tenancy  Extranet Full-Mesh Hub-and-Spoke Partial Mesh Point-to-Point Per-VPN Topology
  • 22. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22 Application Quality Probing Regional Hub Remote Site ISP2 ISP1 SD-WAN Fabric Loss/ Latency ! Data Center Cloud onRamp for SaaS Data Center Regional Hub Remote Site SD-WAN FabricMPLS ISP1 Loss/ Latency ! ISP2
  • 23. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23 Cloud Security with Cisco Umbrella Regional Data Center Remote Site ISP1 SD-WAN Fabric DNS Queries Data Center DIA • Best suited for cloud SaaS applications • Interoperates with Cloud onRamp for SaaS • Cisco Umbrella enforces security policy compliance based on DNS resolution • Augments native fabric security • Can co-exist with on-premise L4- L7 security modes - VPN segmentation
  • 24. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25 Regional Secure Perimeter Single Service Insertion • vEdge router with connected L4-L7 service makes advertisement - Service route OMP address family - Service VPN label • Service is advertised in specific VPN • Service can be L3 routed or L2 bridged • Service can be singly or dually connected (Firewall trust zones) to the advertising vEdge • Control or data policies are used to insert the service node into the matching traffic forwarding path - Match on 6-tuple or DPI signature - Applied on ingress/egress vEdge* For data policy only. Control policy enforced on vSmart. Data Center Remote Office Regional Hub L4-L7 Service Advertisement Policy Advertisement*vSmart VPN1 VPN1 VPN1 Traffic Path Control Plane FW 4GMPLS INET
  • 25. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26 Regional Secure Perimeter Multiple Services Chaining Data Center Remote Office • vEdge routers with connected L4-L7 service make advertisement - Service route OMP address family - Services VPN labels • Services are advertised in specific VPN • Services can be L3 routed or L2 bridged • Services can be singly or dually connected to the advertising vEdges • Control or data policies are used to insert the service nodes into the matching traffic forwarding path - Match on 6-tuple or DPI signature - Applied on ingress/egress/service vEdge Regional Hub vSmart * For data policy only. Control policy enforced on vSmart. VPN1 VPN1 VPN1 Policy Advertisement* Service Advertisement FW IDS Traffic Path Control Plane 4GMPLS INET
  • 26. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27 Deep Packet Inspection Engine Primary Use Cases: - Application Visibility - Application Firewall - Traffic Prioritization - Transport Selection - Analytics vEdge Router App 1 App 2 App 3,000 Cloud Data Center Data Center Campus Branch Small Office Home Office MPLS INET 3G/4G Embedded Application Recognition Deep Packet Inspection
  • 27. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28BRKRST-2092 App-Aware Routing Policies • SLA-Driven Routing / Performance Routing Broadband 4G/LTE MPLS # DPI POLICY SLA lte mpls public-internet VPN 1 VPN 2
  • 28. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29  Enforce SLA compliant path for applications of interest  Other applications will follow fabric routing across all paths Control Plane Path1: 10ms latency, 0% loss, 5ms jitter Path2: 200ms latency, 3% loss, 10ms jitter Path3: 140ms latency , 1% loss, 10ms jitter vManage App Aware Routing Policy App A path must have: latency < 150ms loss < 2% jitter < 10ms vEdge1 vEdge2 MPLS Internet 4G LTE vSmart Controllers App A IPSec Tunnel Critical Applications SLA Path Quality Detection Routing Path 2
  • 29. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30 • High latency path between users and servers, i.e. geo-distances • vEdge routers terminate TCP sessions and provide local acknowledgements to prevent TCP windowing from reacting • Selective acknowledgements prevents unnecessary retransmit of the successfully received segments • Hosts using old TCP/IP stacks will see the most benefit Users Servers High Latency Path vEdgevEdge TCP Connections TCP Connections Optimized TCP Connections (Cubic) SD-WAN Fabric Application Optimization TCP Performance Optimization
  • 30. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential INET MPLS Site Data Center Network/Headend Redundancy MPLS INET vSmart Controllers Control Data Control Redundancy INET INETMPLSMPLS Transport Redundancy High Availability and Redundancy Overview VRRP OSPF/ BGP OSPF/ BGP Site Redundancy
  • 31. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN Operation and Management
  • 32. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34 Zero Touch Provisioning – vEdge Appliance Control and Policy Elements * Factory default config Assumption: • DHCP on Transport Side (WAN) • DNS to resolve ztp.viptela.com*  Delivered as-a-Service Zero Touch Provisioning Server 1 2 Full Registration and Configuration 5 3 4 vEdge
  • 33. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35 Simplified Management REST NETCONF Syslog Flow ExportSNMP CLI Linux Shell Power Tools Single Pane Of Glass Operations RichAnalytics
  • 34. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36 Single Pane of Glass Operations vManage GUI • Intuitive GUI driven operations - Management, monitoring and troubleshooting • Cloud Delivered - Private, hosted or managed • Single or Multi-tenant • Role-based Access Control • Clustered for scale and high availability • REST APIs based
  • 35. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37 • Embedded Deep Packet Inspection engine • Application and flow level visibility for the fabric and individual vEdge routers • Centralized statistics and performance • Export flow level data (IPFIX) to external collector Application and Performance Visibility Deep Packet Inspection
  • 36. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 39 • vManage measures performance for popular SaaS applications (Loss/Latency) • Quality of experience score is assigned - Range is from 1 to 10 • Indicates optimal Internet exit point toward the SaaS applications of interest SaaS Application Performance
  • 37. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 40 Centralized Device Configuration Enforcement • Centralized Feature Templates • Enforces configuration compliance • Self-recover on misconfiguration • Feature Configuration with Variables
  • 38. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41 Policy Driven WAN Infrastructure Policy Augmented Dynamic Routing vEdge WAN router Access Layer Branch/DC vSmart controller – Policy Enforcement/Advertisement Control Policy: Routing and Services vManage GUI – Policy Orchestration1 2 3 Data Policy: Extensive Policy-based Routing and Services App-Route Policy: App-Aware SLA-based Routing Combine and Apply per Site Execute Control Policy Advertise AAR/Data Policies to Sites Execute AAR and Data Policy as received Dynamic Routing and Policies Combine to dictate behavior
  • 39. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential vAnalytics
  • 40. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 45 vAnalytics Dashboard
  • 41. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 46 1. Bandwidth Usage: 1. Identification of top sources / top destinations / top application (family) 2. Drill-down into information on a per-Site basis 3. Identification of top sources 2. Application Performance: 1. Application to tunnel-binding and performance information 3. Anomaly Detection: 1. Baseline of Application usage. Anomaly detection based on overall application usage / by Family / by Site The Power of Analytics Application Centric (Based on DPI/cflowd)
  • 42. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 47 1. Site Availability (SD-WAN value prop) 1. List of Sites with down-time comparing to TLOCs with their down-time 2. Network Availability 1. List of sites by down-time 2. Comparison of Site down-time vs TLOC down-time (SD-WAN value prop) 3. Down site count on a time basis with the ability to drill-down into Sites and downtimes 3. Site Usage Analysis 1. Bandwidth consumed by Site (Top Sites) 2. Drill-down to show historical bandwidth consumption by time 4. Carrier Performance 1. App-Route stats based on a per-carrier basis 2. Ability to drill-down on a specific carrier and visibility into various remote carrier connectivity The Power of Analytics Network Centric
  • 43. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 48 vAnalytics – BW Consumption by Applications
  • 44. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 49 vAnalytics – Network Health by Carriers
  • 45. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN Portfolio & Scale
  • 46. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 51 Summary: Solution Elements Orchestration, Control, Data and Management Planes Control Plane Cisco vSmart • Facilitates fabric discovery • Dissimilates control plane information between vEdges • Distributes data plane and app- aware routing policies to the vEdge routers • Implements control plane policies, such as service chaining, multi-topology and multi-hop • Dramatically reduces control plane complexity • Highly resilient Data Plane Physical/Virtual Cisco vEdge • WAN edge router • Provides secure data plane with remote vEdge routers • Establishes secure control plane with vSmart controllers (OMP) • Implements data plane policies • Exports performance statistics • Leverages traditional routing protocols like OSPF, BGP and VRRP • Support Zero Touch Deployment • Physical or Virtual form factor (100Mb, 1Gb, 10Gb) Management Plane Cisco vManage • Single pane of glass for Day0, Day1 and Day2 operations • Centralized provisioning • Policies and Templates • Troubleshootingand Monitoring • Software upgrades • GUI with RBAC • Programmatic interfaces (REST, NETCONF) • NMS interfaces (SNMP, Syslog, IPFIX) Orchestration Plane Cisco vBond • Orchestrates control and management plane • First point of authentication (white-list model) • Distributes list of vSmarts/ vManage to all vEdge routers • Facilitates NAT traversal • Requires public IP Address [could sit behind 1:1 NAT] • Highly resilient
  • 47. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN Platform Options ISR 1000 ISR 4000 ASR 1000 High- performance HW & SW redundancy Modular Integrated service containers Next-gen Performance flexibility Branch Services Public Cloud vEdge 2000 10 Gbps Modular vEdge 1000 Up to 1 Gbps Fixed vEdge 100 100 Mbps 4G LTE & WiFi SD-WAN Virtualization ENCS 5100 20 Gbps, Modular vEdge 5000 ENCS 5400 vEdge Cloud
  • 48. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 58 Controller Deployment Models vManage vSmart vBond Cloud-Delivered Cisco Cloud Deployed by Cisco Deployed by Customer or SP On-Premise Recommended Control and Management Elements Private Cloud
  • 49. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 62 Data Center Campus Branch Home Office 4G/LTE MPLS Internet Control Plane (Containers or VMs) (vSmart – up to 20) Management Plane (Multi-tenant or Dedicated) (vManage – up to 6) Orchestration Plane (vBond - up to 6) 1500 vEdges per vBond Redundancy Add 1-2 vBonds Horizontal Scale out Model Horizontal Scale Out Model 2000 vEdges per vManage Horizontal Scale out Model in cluster mode (same DC) 2700 vEdges per vSmart Redundancy Add 1-2 vSmarts Horizontal Scale out Model Scalability Orchestration/Control/Management Plane
  • 50. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Viptela Integration Plan
  • 51. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN Integration Roadmap Phase 2 Platform Integration Phase 1 No Integration Phase 3 Management Integration Platform: • As-is Management: • vManage Platform: • vEdge capabilities integrated into all IOS-XE platforms (ISR, CSR, ENCS, ASR1K) Management: • vManage for SD-WAN capabilities on IOS-XE Management: • Cloud hosted DNA Center integrates vManage capabilities • Full DNA Center capabilities (Assurance, Integrated workflows for SD-Access and SD-WAN) Support current Viptela customers Viptela SD-WAN on strategic ISR platform Deliver end-to-end experience with full DNA integration DeploymentScenariosBenefitsDetails vEdge ISR4K + vEdge SW DNA Center + SD-WAN ISR4K + vEdge SW vManage vEdge vManage vEdge
  • 52. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Clarification On SDWAN Terminology Viptela H/W With All Software Capabilities As-Is vEdge Traditional IOSXE With IWAN capabilities, for ISR4K, ASR, CSR & ISRv ISR SDWAN Enabled IOSXE for ISR4K, ASR, CSR & ISRv "SDWAN Enabled ISR" Only Features Highlighted In The Next Slide Are Included In The SD-WAN Image
  • 53. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Software SD WAN Features  ZTP, App Route Policy, HQoS, Segmentation, NAT DIA, BFD PMTU  Cloud onRamp–IaaS IOS Features:  NBAR2, Umbrella (DNS redirect)  Zone Based Firewall Deployments:  TLOC Extension Routing Protocols  BGP, OSPF Other Features  VRRP, DHCP server,  DNS, RADIUS, Syslog, NTP Monitoring & Troubleshooting  System & Interface stats  vManage with DPI, Analytics July 2018 (16.9.1) Nov 2018 Jan 2019 Post Jan 2019 Hardware SD WAN Features  Cloud onRamp-SaaS  TCP Optimizations  IPv6 support (Transport)  Service chaining  AppQoE – phase1 (FEC, TCP Opt)  Security – phase 2 (AMP etc)  CLI templates for XE-SDWAN IOS Features  Multicast (Auto-RP, Static-RP)  EIGRP  NBAR2 Custom App Platforms  ISR43xx, ISR4221, ASR1001-X, ASR1002- X, ASR 1001-HX, ASR 1002–HX, ISRv (ENCS) 5412, C1111-8P LTEEA/LA, C1117-4PLTEEA/LA, C1111-8P New Interfaces  Ethernet, 4G LTE, T1/E1, xDSL Services  AppNav Functionality  UC –SRST, PSTN GW, SIP GW SDA segmentation use case Platforms:  ASR1006-X, ASR1009-X New Interfaces  Port Channel, UCSE, NIM-1T/2T/4T In PlanningCapabilitiesin“SD-WANIntegratedIOSXE” Integration Roadmap IOS Features:  SD-AVC  Ipv6 service side support Routing protocols:  BGP for IPv6  Multiple BGP community tags Security:  Segmentation scale to 300 VRFs  On-Prem: IPS/IDS, URL Filtering  Umbrella auto-registration  Cloud: Local domain bypass for umbrella Monitoring & Troubleshooting  Multitenancy scale 500 tenants  Template Imp, Network design builder Platforms CSR, C1111-4PLTEEA, C1111- 4PLTELA, C1116-4PLTEEA C1117- 4PMLTEEA C1111-4P, C1116-4P, C1117-4P, C1117-4PM, C1111X-8P Wireless SKU -C1111- 8PLTEEAW, C1111-8PW Not a commitment, roadmap is subject to change Platforms  ISR-4451, ISR-4431
  • 54. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 67 APPs SDWAN Cloud IoT .… SDWAN Fabric USERS DC IaaS SaaS vDC Analytics SECURE SCALE OPEN Cloud Delivered DEVICES THINGS SDA Fabric (branch & campus) SDA Fabric (branch & campus) DC ACI Fabric • User / DeviceIdentity, network-wide • Policyabstraction at User / Group and Application levels • Policyat Fabric Edge. Over-the-top. • Increased Simplicity. Seamless Mobility. End-to-end Context SD-WAN Fabric Integration with DNA
  • 55. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 100+ Global Enterprise Customers Across Verticals ManufacturingMANUFACTURING TechnologyTECHNOLOGYRetail RETAIL Other IndustriesOTHER INDUSTRIES FinServ FINSERV Healthcare / PharmaHEALTHCARE / PHARMA
  • 56. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Customer Industry Challenge Solution Retail High cost, slow change, limited flexibility 60-70% cheaper broadband at high bandwidth, centralized control, full visibility. Financial Needed more bandwidth and guaranteed network uptime for a new teller application Dollar cost averaged the bandwidth cost down using a mix of transport (MPLS, Broadband, LTE). Traffic now uses the optimal network path to avoid downtime and slowdowns. Tech Slow performance and MPLS outages provided an expensive and poor user experience Monthly savings reduced the cost per Mbps by more than 80%. Diverse circuits improve the reliability of the global network, with more than half of Agilent’s sites doubling WAN redundancy. Healthcare With an MPLS contract renewal approaching, Cigna wanted the flexibility to change carriers without a massive technology shift Gained back control of its control plane and created the Cigna Service Provider Agnostic Network. Healthcare Security and high network cost Satisfied strict security and audit requirements and provided greater flexibility for partnerships and secure clinical solutions. Cost reductions with the removal of remote site voice equipment and expensive PRIs, aging WAN acceleration equipment and maintenance. Energy Scale to support evolving field operations, and support cloud migration and application SLAs Provided 30-60% savings in overall bandwidth costs. Enabled faster response to acquisitions, divestitures and policy changes. Proven Solution Across Multiple Verticals For Your Reference