SlideShare a Scribd company logo
1 of 27
Download to read offline
Liad Ofek
Director, Product management
Cloud and Virtualization
Networking Business Unit
July 2018
Cisco Hybrid cloud :
Cloud Connect
It’s a Hybrid cloud world
Source: IDC CloudView, April, 2017, n=8,293 worldwide respondents, weighted by country, company size and industry
Evaluating or using
public cloud
85%
Taken steps towards a hybrid
cloud strategy
87%
Among cloud users
Hybrid cloud Complexity Challenges
“I need to…”
FRAGMENTED
COMPLEX
NO DATA CONTROL
“…securely extend
private networks to
public clouds”
“…define and
execute my cloud
first strategy”
“…protect my cloud
applications, endpoints,
and data”
“…migrate to cloud
and manage the full
application lifecycle”
Cloud Adoption Journey-Key Activities
& Pain Points
FRAGMENTED
COMPLEX
NO DATA CONTROL
SaaS
SaaS
SaaS
SaaS
SaaS
SaaS
SaaS
Other
Public
Clouds
IaaS
AWS
PaaS
SaaS
PrivatePrivate
Cisco Cloud Portfolio
Hybrid Cloud
Portfolio
Cloud
Connect
Cloud
Protect
Cloud
Advisory
Cloud
Consume
Cisco Cloud Portfolio — Objectives
Hybrid Cloud
Portfolio
Cloud
Connect
Cloud
Protect
Cloud
Advisory
Cloud
Consume
Design, plan, accelerate,
and de-risk your
cloud migrations
Deploy, monitor and
optimize applications in
cloud environments
Securely extend your private
networks into public clouds and
ensure the application
experience
Protect cloud identities, direct-to-
cloud connectivity, data, and
applications including SaaS
Cisco Hybrid Cloud Portfolio — Products Mix
Cloud
Consume
Cloud
Protect
Cloud
Connect
Cloud
Advisory
Multicloud
Portfolio
Advisory Services
• Cloud Migration
• Cloud Connect
• Cloud Protect
• Cloud Consume
(Delivered by AS/Cisco Partners)
• AppDynamics
• CloudCenter
• Container Platform
Cloud
Consume
Cloud
Advisory
• CSR 1000v
• vEdge with Umbrella*
• Umbrella
• AMP for Endpoints
• Meraki Systems
Manager
• Cloudlock
• Tetration Cloud
• Stealthwatch Cloud
Cloud
Connect
Cloud
Protect
* Umbrella license is not included
Cisco Cloud Portfolio — Implementation
▪ Faster implementation
and time to value
▪ Lower risk
▪ Lower cost
Design and
Deployment GuidesHybrid Cloud
Portfolio
Cloud
Connect
Cloud
Protect
Cloud
Advisory
Cloud
Consume
• Best practices
• Integrated design
• Detailed implementation
steps
Cloud Connectivity Challenges
On-Prem Datacenters
Remote Branches
Public Cloud
• Complexity & Dependency – Need a
simple and scalable way to securely
extend the private network across
cloud environments
• Inconsistent security policies between
private & public- Need to apply
consistent security policies
• Performance and ambiguity for best
path to reach the cloud – Need
enhance application experience
Applications
Users
Cloud
Connect
AWS
Enterprise DC
ASR1K
Branch
ISR4K
Cloud Connect – CSR 1000V
Securely extend the private
network to the cloud from
the Branch and DC with CSR1000v
Extend routing to multi-VPC
environment with CSR100v in Transit
VPC
Maintain application experience
with QoS and AVC
CSR1000v
CSR1000v
CSR1000v
VPC
VPC
VPC
VPC
VPC
Enterprise DC
ASR1K
Branch
Cloud Connect w/vEdge Cloud
vEdge Cloud
vEdgevEdge
Internet
Direct Cloud connectivity from a Branch
with vEdge to vEdge Cloud
Extend routing to multi-VPC environment
with vEdgeTransit VPC
Extend Cisco SD-WAN fabric to the cloud
VPC
VPC
VPC
VPC
VPC
Branch Enterprise DC
ASR1K
Cloud Connect - vEdge and Umbrella
vEdge Cloud
vEdgevEdge
Protecting your branch office users directly to
your multi-cloud environment leveraging
direct internet access(DIA), using vEdge and
secure internet gateway (Umbrella)
VPC
VPC
VPC
VPC
VPC
InternetUmbrella
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Extend private network to
cloud leveraging existing
investments
Consistent security policies
across private and public
cloud footprint
Enhance and secure app
experiences with visibility
and path
selection/optimization
Centralized orchestration
across the entire network
including cloud
Cisco Cloud Connect
Benefits
CSR Cloud High Availability
• No virtual IP as with HSRP, since AWS
doesn’t allow multicast
• BFD over GRE tunnel is enabled between
two CSRs to detect failure
• AWS Route Tables for app subnets are re-
pointed to surviving CSR
• Failure detection is automatic
• CSR itself calls AWS API to adjust AWS
Route Table routes
• Sub-second failover
VPC
CSR Subnet
App Subnet
A
App Subnet
B
Before HA Failover
After HA Failover
AWS REST API
http://www.cisco.com/c/en/us/td/docs/routers/csr1000/software/aws/b_csraws/b_csraws_chapter_0100.html
BFD
14
Public Cloud Transit Routing Challenge
• No transit routing capability
A-B Peering
B-C Peering
Transit Routing NOT supported
A-to-C-thru-B
Full mesh
Private DC
…
Backhaul2
See next slide
VPC-A
VPC-C
VPC-B
15
AWS
Transit VPC Design
• Dedicated VPC: Simplifies routing by not
combining with other shared services.
• CSR1000v Virtual Network Appliances:
Provide dynamic routing and VPN network
tunnels
• Redundancy: Dynamic routing combined
with multi-AZ deployment creates a robust
network infrastructure.
• VGW: VPC virtual gateways provide highly
available connections to transit VPC virtual
network appliances.
BA C
…...
Direct Connect
Or Internet
Private DC
Transit VPC
Spoke VPC
Other
Provider
Networks
CSR1 CSR2
AZ1 AZ2
Across regions, accounts/subscriptions
ASR
VPCVPCVPC
VPC
Scale Out
Private DC
Transit VPC
DX/ER
Internet
ASR
VPC
CSR1 CSR2 CSR3 CSR4
…...
• Add another pair of CSRs to scale
out
• Remote end (VGW) has multiple
tunnels and do L3 ECMP (Equal Cost
Multiple Path)
• Elasticity as you go: monitor CSR
real-time throughput and spin up
new CSRs on demand.
Traffic Segregation
• Traffic segregation is built-in natively
• Each Spoke VPC is represented as a
different VRF in CSR
• Routing is controlled through RT
(Route Target)
• Different VPCs can communicate by
export/import same RT
• Follow same mechanism to create
customized VRF like on-premise VRF
CSR1
MP-BGP
On-Premise VRF
CSR2
VPC-A VPC-B VPC-C
Private DC
VPC-C VRFVPC-B VRFVPC-A VRF
Data Center
Transit VPC
AZ1 AZ2
App 1
(VPC1)
App 2
(VPC2) App 3 (VPC3) Internet
Employee
Developer
Guest
Non-Compliant
✓ X ✓ ✓
X X ✓ ✓
X ✓ ✓ ✓
VPC1
Extend Trust Sec into AWS Transit VPC
Simplifying Segmentation and Control
Direct Connect
Dynamic Route Peering
Employee Tag
Developer Tag
Guest Tag
Non-Compliant Tag
X X ✓ ✓
ISE
Identity & Access Control
Policy Enforcement
App 1
VPC2
App 2
VPC3
App 3
Control Access to spoke VPC’s
based on SGT Tags and Policy
Enforcement within the Transit VPC
Hub CSRv’s
• Control Traffic between VPC’s
• Simplify Security Configurations
• Scale Security Group Control
• Single Control Point
dev pro test
ASR1K
CSR1 CSR2
Prioritize Your Traffic with QoS Policy
• AWS Infrastructure doesn’t acknowledge QoS value, however you can use it over Tunnel
• Based on transport type (Direct Connect, VPC Peering, Public IP), shape different traffic to ensure
app experience when link get over-subscribed
Cisco
ISR/ASR
Corporate DC
Co-Lo
Direct Connect
QoS
IPSEC Tunnel
Integrated Security Features on CSR
ACL VRF
Zone Based
Firewall
IPSEC
Trust Sec
Encrypted
Traffic
Analytics (ETA)Transit Hub
VPC
Integrated Security
• Low TCO by enabling security services
• Built-in high availability with routing
• Single device to manage routing and security
CSR1 CSR2
21
Cloud Security with Cisco Umbrella
Regional
Data Center
Remote Site
ISP1
SD-WAN
Fabric
DNS Queries
Data Center
DIA
• vEdge router intercepts client DNS queries
- Deep Packet Inspection
• DNS queries are forwarded to Cisco Umbrella
DNS servers based on the data or application
aware routing policies centrally defined on
vManage
- Target DNS servers list is defined under the
service side VPN
- Policy can pin DNS query for specific application
(DPI based) to specific DNS server from the list
• Cisco Umbrella enforces security policy compliance
based on DNS resolution
Two deployment models
VPC
Application VPC Gateway
• CSR deployed in application VPC
• Provide IPSEC gateway for entire VPC
• Need high availability
Transit Hub Router
• CSR deployed in dedicated Transit Hub, not in
application VPC
• High speed traffic routing for spoke VPC
• High availability is built-in natively
Transit Hub
AZ1 AZ2
Application VPC
VPC
23
Viptela Confidential24
Cloud onRamp for IaaS
How it works
Internet
Branch
DC
MPLS
Public Cloud (AWS) connectivity solution consumable through the vManage platform
vManage
Platform
Public cloud credentials
added to vManage
vManage invokes
instantiation of vEdge
instances in users
accounts & connects
IaaS instances to vEdge
GW VPN segments
IaaS instances are
discovered from users
account in a region.
User selects instances
to operate on
New instances can
be discovered and
mapped to VPN
segments later
Public Cloud Provider 1 Region 1
IaaS instances
IaaS instances
vEdge GW
User defines vEdge
gateway parameters and
maps IaaS instances to VPN
segments in the overlay
vManage Cloud onRamp for IaaS app: A vManage
application that orchestrates connectivity to IaaS
instances across multiple cloud and multiple regions.
Provides visibility into cloud instances.
vEdge Cloud Router: A virtualized
version of the vEdge router. Available
on the AWS and Azure marketplace.
Viptela Confidential25
Cloud onRamp for SaaS
Regional
internet exit
Branch with
local DMZ
Data
Center/DMZ
vFabric
httping probes
SaaS traffic primary
SaaS traffic backup
Cloud onRamp for SaaS Gateways: vEdge routers monitoring
service availability to SaaS apps.
vManage Cloud onRamp for SaaS app: A vManage application
provides visibility into SaaS performance and availability from the
branch.
• User designates Cloud onRamp gateways which can be remote
DMZs or local CPE (DIA case)
• SLA metrics are computed by using httping based probes to the
SaaS endpoint through the Cloud onRamp gateway
• Per application SLA metrics include loss and latency
• Application aware routing to SaaS end-point from gateway routers
• Path experiencing better SLA for the application is chosen
How it works
Viptela Quality of Experience (vQoE) score: Provides visibility into
application QoE based on realtime probes. vQoE information influences
routing decisions on vEdge routers
Viptela Confidential26
Why Cloud Connect ?
• Proven methodology – Transforming to deliver business outcomes based on
adoption of capabilities via cloud technologies
• Ease of management- Easy management and administration due to
consistency of the solutions between on prem and public cloud
• Integrated Security - Most comprehensive security and networking features
and services that leverage existing infrastructure
• Seamless transition to cloud environments by extending enterprise grade
networking & security from on-prem to cloud
• Best-in-class SD WAN with security - Viptela with Umbrella
• Best Network flow monitoring and threat analytics
Q: Where can I find the CSR on AWS?
A: In the AWS marketplace!
1. Search for “Cisco”
2. Pick a flavor
27

More Related Content

What's hot

클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017
클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017
클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017Amazon Web Services Korea
 
Preparing_for_PCA_Workbook.pptx
Preparing_for_PCA_Workbook.pptxPreparing_for_PCA_Workbook.pptx
Preparing_for_PCA_Workbook.pptxmambrino
 
Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...
Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...
Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...Amazon Web Services
 
KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...
KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...
KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...Amazon Web Services Korea
 
Defining Your Cloud Strategy
Defining Your Cloud StrategyDefining Your Cloud Strategy
Defining Your Cloud StrategyInternap
 
Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트
Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트
Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트Amazon Web Services Korea
 
AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019
AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019
AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019Amazon Web Services Korea
 
AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...
AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...
AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...Amazon Web Services Korea
 
Microsoft Azure a cloud computing platform
Microsoft Azure a cloud computing platformMicrosoft Azure a cloud computing platform
Microsoft Azure a cloud computing platformAayush Mohanka
 
AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...
AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...
AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...Amazon Web Services Korea
 
Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...
Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...
Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...Amazon Web Services Korea
 
What is Cloud Computing with Amazon Web Services?
What is Cloud Computing with Amazon Web Services?What is Cloud Computing with Amazon Web Services?
What is Cloud Computing with Amazon Web Services?Amazon Web Services
 
Cloud eHealth in Medical Imaging & Radiology
Cloud eHealth in Medical Imaging & RadiologyCloud eHealth in Medical Imaging & Radiology
Cloud eHealth in Medical Imaging & RadiologyCarestream
 
Amazon Relational Database Service (Amazon RDS)
Amazon Relational Database Service (Amazon RDS)Amazon Relational Database Service (Amazon RDS)
Amazon Relational Database Service (Amazon RDS)Amazon Web Services
 
Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices Amazon Web Services
 
Making a cloud first strategy a practical reality
Making a cloud first strategy a practical realityMaking a cloud first strategy a practical reality
Making a cloud first strategy a practical realityAmazon Web Services
 

What's hot (20)

클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017
클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017
클라우드 보안 이슈 및 원격 관제 기반 대응 방안 - AWS Summit Seoul 2017
 
Preparing_for_PCA_Workbook.pptx
Preparing_for_PCA_Workbook.pptxPreparing_for_PCA_Workbook.pptx
Preparing_for_PCA_Workbook.pptx
 
Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...
Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...
Decouple and Scale Applications Using Amazon SQS and Amazon SNS - July 2017 A...
 
KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...
KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...
KB국민카드 - 클라우드 기반 분석 플랫폼 혁신 여정 - 발표자: 박창용 과장, 데이터전략본부, AI혁신부, KB카드│강병억, Soluti...
 
Defining Your Cloud Strategy
Defining Your Cloud StrategyDefining Your Cloud Strategy
Defining Your Cloud Strategy
 
Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트
Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트
Amazon VPC와 ELB/Direct Connect/VPN 알아보기 - 김세준, AWS 솔루션즈 아키텍트
 
AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019
AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019
AWS를 위한 도커, 컨테이너 (이미지) 환경 보안 방안 - 양희선 부장, TrendMicro :: AWS Summit Seoul 2019
 
AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...
AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...
AWS Direct Connect 를 통한 하이브리드 클라우드 아키텍쳐 설계 - 김용우 솔루션즈 아키텍트, AWS :: AWS Summit...
 
Microsoft Azure a cloud computing platform
Microsoft Azure a cloud computing platformMicrosoft Azure a cloud computing platform
Microsoft Azure a cloud computing platform
 
AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...
AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...
AWS의 다양한 Compute 서비스(EC2, Lambda, ECS, Batch, Elastic Beanstalk)의 특징 이해하기 - 김...
 
Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...
Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...
Cloud Migration 과 Modernization 을 위한 30가지 아이디어-박기흥, AWS Migrations Specialist...
 
What is Cloud Computing with Amazon Web Services?
What is Cloud Computing with Amazon Web Services?What is Cloud Computing with Amazon Web Services?
What is Cloud Computing with Amazon Web Services?
 
Cloud eHealth in Medical Imaging & Radiology
Cloud eHealth in Medical Imaging & RadiologyCloud eHealth in Medical Imaging & Radiology
Cloud eHealth in Medical Imaging & Radiology
 
Migrating to the Cloud
Migrating to the CloudMigrating to the Cloud
Migrating to the Cloud
 
Aws
AwsAws
Aws
 
Amazon Relational Database Service (Amazon RDS)
Amazon Relational Database Service (Amazon RDS)Amazon Relational Database Service (Amazon RDS)
Amazon Relational Database Service (Amazon RDS)
 
Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices
 
Making a cloud first strategy a practical reality
Making a cloud first strategy a practical realityMaking a cloud first strategy a practical reality
Making a cloud first strategy a practical reality
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Aws overview
Aws overviewAws overview
Aws overview
 

Similar to Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain User Experience

DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...Amazon Web Services
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWSAmazon Web Services
 
2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf
2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf
2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdfShahedHasib1
 
DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS CloudDEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS CloudAmazon Web Services
 
Secure SDN
Secure SDNSecure SDN
Secure SDNAPNIC
 
20151019 v mworld2015-recap-02
20151019 v mworld2015-recap-0220151019 v mworld2015-recap-02
20151019 v mworld2015-recap-02Kevin Groat
 
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...Amazon Web Services
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載Amazon Web Services
 
打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載Amazon Web Services
 
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...Amazon Web Services
 
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...Amazon Web Services
 
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptxNSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptxAvi Networks
 
Getting Started with VMware Cloud on AWS
Getting Started with VMware Cloud on AWSGetting Started with VMware Cloud on AWS
Getting Started with VMware Cloud on AWS2nd Watch
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure IntegrationAmazon Web Services
 
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013Amazon Web Services
 
Self service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsxSelf service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsxsolarisyougood
 
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - SegmentationVMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - SegmentationVMworld
 
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...Amazon Web Services
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure IntegrationAmazon Web Services
 

Similar to Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain User Experience (20)

DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
 
2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf
2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf
2017DellEMCForum-ConsistentCloudOperations-VMwareCloudonAWS-FV.pdf
 
DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS CloudDEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud
 
Secure SDN
Secure SDNSecure SDN
Secure SDN
 
20151019 v mworld2015-recap-02
20151019 v mworld2015-recap-0220151019 v mworld2015-recap-02
20151019 v mworld2015-recap-02
 
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載
 
打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載
 
VMWare on AWS
VMWare on AWSVMWare on AWS
VMWare on AWS
 
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
 
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
 
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptxNSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
 
Getting Started with VMware Cloud on AWS
Getting Started with VMware Cloud on AWSGetting Started with VMware Cloud on AWS
Getting Started with VMware Cloud on AWS
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
Selecting the Best VPC Network Architecture (CPN208) | AWS re:Invent 2013
 
Self service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsxSelf service it with v realizeautomation and nsx
Self service it with v realizeautomation and nsx
 
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - SegmentationVMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
VMworld 2013: NSX PCI Reference Architecture Workshop Session 1 - Segmentation
 
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain User Experience

  • 1. Liad Ofek Director, Product management Cloud and Virtualization Networking Business Unit July 2018 Cisco Hybrid cloud : Cloud Connect
  • 2. It’s a Hybrid cloud world Source: IDC CloudView, April, 2017, n=8,293 worldwide respondents, weighted by country, company size and industry Evaluating or using public cloud 85% Taken steps towards a hybrid cloud strategy 87% Among cloud users
  • 3. Hybrid cloud Complexity Challenges “I need to…” FRAGMENTED COMPLEX NO DATA CONTROL “…securely extend private networks to public clouds” “…define and execute my cloud first strategy” “…protect my cloud applications, endpoints, and data” “…migrate to cloud and manage the full application lifecycle”
  • 4. Cloud Adoption Journey-Key Activities & Pain Points FRAGMENTED COMPLEX NO DATA CONTROL SaaS SaaS SaaS SaaS SaaS SaaS SaaS Other Public Clouds IaaS AWS PaaS SaaS PrivatePrivate
  • 5. Cisco Cloud Portfolio Hybrid Cloud Portfolio Cloud Connect Cloud Protect Cloud Advisory Cloud Consume
  • 6. Cisco Cloud Portfolio — Objectives Hybrid Cloud Portfolio Cloud Connect Cloud Protect Cloud Advisory Cloud Consume Design, plan, accelerate, and de-risk your cloud migrations Deploy, monitor and optimize applications in cloud environments Securely extend your private networks into public clouds and ensure the application experience Protect cloud identities, direct-to- cloud connectivity, data, and applications including SaaS
  • 7. Cisco Hybrid Cloud Portfolio — Products Mix Cloud Consume Cloud Protect Cloud Connect Cloud Advisory Multicloud Portfolio Advisory Services • Cloud Migration • Cloud Connect • Cloud Protect • Cloud Consume (Delivered by AS/Cisco Partners) • AppDynamics • CloudCenter • Container Platform Cloud Consume Cloud Advisory • CSR 1000v • vEdge with Umbrella* • Umbrella • AMP for Endpoints • Meraki Systems Manager • Cloudlock • Tetration Cloud • Stealthwatch Cloud Cloud Connect Cloud Protect * Umbrella license is not included
  • 8. Cisco Cloud Portfolio — Implementation ▪ Faster implementation and time to value ▪ Lower risk ▪ Lower cost Design and Deployment GuidesHybrid Cloud Portfolio Cloud Connect Cloud Protect Cloud Advisory Cloud Consume • Best practices • Integrated design • Detailed implementation steps
  • 9. Cloud Connectivity Challenges On-Prem Datacenters Remote Branches Public Cloud • Complexity & Dependency – Need a simple and scalable way to securely extend the private network across cloud environments • Inconsistent security policies between private & public- Need to apply consistent security policies • Performance and ambiguity for best path to reach the cloud – Need enhance application experience Applications Users Cloud Connect AWS
  • 10. Enterprise DC ASR1K Branch ISR4K Cloud Connect – CSR 1000V Securely extend the private network to the cloud from the Branch and DC with CSR1000v Extend routing to multi-VPC environment with CSR100v in Transit VPC Maintain application experience with QoS and AVC CSR1000v CSR1000v CSR1000v VPC VPC VPC VPC VPC
  • 11. Enterprise DC ASR1K Branch Cloud Connect w/vEdge Cloud vEdge Cloud vEdgevEdge Internet Direct Cloud connectivity from a Branch with vEdge to vEdge Cloud Extend routing to multi-VPC environment with vEdgeTransit VPC Extend Cisco SD-WAN fabric to the cloud VPC VPC VPC VPC VPC
  • 12. Branch Enterprise DC ASR1K Cloud Connect - vEdge and Umbrella vEdge Cloud vEdgevEdge Protecting your branch office users directly to your multi-cloud environment leveraging direct internet access(DIA), using vEdge and secure internet gateway (Umbrella) VPC VPC VPC VPC VPC InternetUmbrella
  • 13. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public Extend private network to cloud leveraging existing investments Consistent security policies across private and public cloud footprint Enhance and secure app experiences with visibility and path selection/optimization Centralized orchestration across the entire network including cloud Cisco Cloud Connect Benefits
  • 14. CSR Cloud High Availability • No virtual IP as with HSRP, since AWS doesn’t allow multicast • BFD over GRE tunnel is enabled between two CSRs to detect failure • AWS Route Tables for app subnets are re- pointed to surviving CSR • Failure detection is automatic • CSR itself calls AWS API to adjust AWS Route Table routes • Sub-second failover VPC CSR Subnet App Subnet A App Subnet B Before HA Failover After HA Failover AWS REST API http://www.cisco.com/c/en/us/td/docs/routers/csr1000/software/aws/b_csraws/b_csraws_chapter_0100.html BFD 14
  • 15. Public Cloud Transit Routing Challenge • No transit routing capability A-B Peering B-C Peering Transit Routing NOT supported A-to-C-thru-B Full mesh Private DC … Backhaul2 See next slide VPC-A VPC-C VPC-B 15 AWS
  • 16. Transit VPC Design • Dedicated VPC: Simplifies routing by not combining with other shared services. • CSR1000v Virtual Network Appliances: Provide dynamic routing and VPN network tunnels • Redundancy: Dynamic routing combined with multi-AZ deployment creates a robust network infrastructure. • VGW: VPC virtual gateways provide highly available connections to transit VPC virtual network appliances. BA C …... Direct Connect Or Internet Private DC Transit VPC Spoke VPC Other Provider Networks CSR1 CSR2 AZ1 AZ2 Across regions, accounts/subscriptions ASR VPCVPCVPC VPC
  • 17. Scale Out Private DC Transit VPC DX/ER Internet ASR VPC CSR1 CSR2 CSR3 CSR4 …... • Add another pair of CSRs to scale out • Remote end (VGW) has multiple tunnels and do L3 ECMP (Equal Cost Multiple Path) • Elasticity as you go: monitor CSR real-time throughput and spin up new CSRs on demand.
  • 18. Traffic Segregation • Traffic segregation is built-in natively • Each Spoke VPC is represented as a different VRF in CSR • Routing is controlled through RT (Route Target) • Different VPCs can communicate by export/import same RT • Follow same mechanism to create customized VRF like on-premise VRF CSR1 MP-BGP On-Premise VRF CSR2 VPC-A VPC-B VPC-C Private DC VPC-C VRFVPC-B VRFVPC-A VRF
  • 19. Data Center Transit VPC AZ1 AZ2 App 1 (VPC1) App 2 (VPC2) App 3 (VPC3) Internet Employee Developer Guest Non-Compliant ✓ X ✓ ✓ X X ✓ ✓ X ✓ ✓ ✓ VPC1 Extend Trust Sec into AWS Transit VPC Simplifying Segmentation and Control Direct Connect Dynamic Route Peering Employee Tag Developer Tag Guest Tag Non-Compliant Tag X X ✓ ✓ ISE Identity & Access Control Policy Enforcement App 1 VPC2 App 2 VPC3 App 3 Control Access to spoke VPC’s based on SGT Tags and Policy Enforcement within the Transit VPC Hub CSRv’s • Control Traffic between VPC’s • Simplify Security Configurations • Scale Security Group Control • Single Control Point dev pro test ASR1K CSR1 CSR2
  • 20. Prioritize Your Traffic with QoS Policy • AWS Infrastructure doesn’t acknowledge QoS value, however you can use it over Tunnel • Based on transport type (Direct Connect, VPC Peering, Public IP), shape different traffic to ensure app experience when link get over-subscribed Cisco ISR/ASR Corporate DC Co-Lo Direct Connect QoS IPSEC Tunnel
  • 21. Integrated Security Features on CSR ACL VRF Zone Based Firewall IPSEC Trust Sec Encrypted Traffic Analytics (ETA)Transit Hub VPC Integrated Security • Low TCO by enabling security services • Built-in high availability with routing • Single device to manage routing and security CSR1 CSR2 21
  • 22. Cloud Security with Cisco Umbrella Regional Data Center Remote Site ISP1 SD-WAN Fabric DNS Queries Data Center DIA • vEdge router intercepts client DNS queries - Deep Packet Inspection • DNS queries are forwarded to Cisco Umbrella DNS servers based on the data or application aware routing policies centrally defined on vManage - Target DNS servers list is defined under the service side VPN - Policy can pin DNS query for specific application (DPI based) to specific DNS server from the list • Cisco Umbrella enforces security policy compliance based on DNS resolution
  • 23. Two deployment models VPC Application VPC Gateway • CSR deployed in application VPC • Provide IPSEC gateway for entire VPC • Need high availability Transit Hub Router • CSR deployed in dedicated Transit Hub, not in application VPC • High speed traffic routing for spoke VPC • High availability is built-in natively Transit Hub AZ1 AZ2 Application VPC VPC 23
  • 24. Viptela Confidential24 Cloud onRamp for IaaS How it works Internet Branch DC MPLS Public Cloud (AWS) connectivity solution consumable through the vManage platform vManage Platform Public cloud credentials added to vManage vManage invokes instantiation of vEdge instances in users accounts & connects IaaS instances to vEdge GW VPN segments IaaS instances are discovered from users account in a region. User selects instances to operate on New instances can be discovered and mapped to VPN segments later Public Cloud Provider 1 Region 1 IaaS instances IaaS instances vEdge GW User defines vEdge gateway parameters and maps IaaS instances to VPN segments in the overlay vManage Cloud onRamp for IaaS app: A vManage application that orchestrates connectivity to IaaS instances across multiple cloud and multiple regions. Provides visibility into cloud instances. vEdge Cloud Router: A virtualized version of the vEdge router. Available on the AWS and Azure marketplace.
  • 25. Viptela Confidential25 Cloud onRamp for SaaS Regional internet exit Branch with local DMZ Data Center/DMZ vFabric httping probes SaaS traffic primary SaaS traffic backup Cloud onRamp for SaaS Gateways: vEdge routers monitoring service availability to SaaS apps. vManage Cloud onRamp for SaaS app: A vManage application provides visibility into SaaS performance and availability from the branch. • User designates Cloud onRamp gateways which can be remote DMZs or local CPE (DIA case) • SLA metrics are computed by using httping based probes to the SaaS endpoint through the Cloud onRamp gateway • Per application SLA metrics include loss and latency • Application aware routing to SaaS end-point from gateway routers • Path experiencing better SLA for the application is chosen How it works Viptela Quality of Experience (vQoE) score: Provides visibility into application QoE based on realtime probes. vQoE information influences routing decisions on vEdge routers
  • 26. Viptela Confidential26 Why Cloud Connect ? • Proven methodology – Transforming to deliver business outcomes based on adoption of capabilities via cloud technologies • Ease of management- Easy management and administration due to consistency of the solutions between on prem and public cloud • Integrated Security - Most comprehensive security and networking features and services that leverage existing infrastructure • Seamless transition to cloud environments by extending enterprise grade networking & security from on-prem to cloud • Best-in-class SD WAN with security - Viptela with Umbrella • Best Network flow monitoring and threat analytics
  • 27. Q: Where can I find the CSR on AWS? A: In the AWS marketplace! 1. Search for “Cisco” 2. Pick a flavor 27