SlideShare a Scribd company logo
1 of 25
Download to read offline
Manan Shah / Linus Aranha
April, 2018
Extending Cisco SD-WAN fabric to
the AWS Cloud
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
• Introduction to Cisco SD-WAN
• Key challenges with hybrid cloud deployments
• How to simplify hybrid cloud deployments with Cloud onRamp
• Demo of Cloud onRamp - IaaS for AWS
Agenda
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN
Apps
SD-WAN
Cloud
Use-Cases…
WAN
USERS
DC
IaaS
SaaS
vDC
AnalyticsCloud Delivered
DEVICES
THINGS
Intent- based
NetworkInfrastructure
DNACenter
AnalyticsPolicy Automation
I N T EN T C O N T EX T
S EC U RI T Y
L EA RN I N G
Cloud delivered WAN with
operational simplicity & analytics1
Superior security architecture –
cloud based & on-premises
2
Transport Independent
WAN Fabric
0
5
Application QOE3
End-point flexibility:
• Physical or virtual
• Rich services or lite
• Branch, Agg, Cloud
4
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN – Components
Data Center Campus Branch Home Office
Control Plane
(Containers or VMs)
Data Plane
(Physical or Virtual)
Management Plane
(Multi-tenant or Dedicated)
Orchestration Plane
vManage
vSmart
vBond
vEdge
ISR4k
ASR1k
ENCS
vOrchestrator
vMonitor
API
4GINTERNET MPLS
CONTROL
ANALYTICS
MANAGEMENT
Policy, Security, Routing
On-boarding, life cycle management
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Hybrid-Cloud & SD-WAN
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
New use cases accelerate
adoption
• Hybrid-Cloud adoption
• Container-based applications
• Serverless Compute
• Machine learning / AI
• IoT
IaaS Adoption &
Key Trends
44
IaaS spend in 2018 will grow by 22% CAGR
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Hybrid Cloud Connectivity - Today
Branch
MPLS/Internet
Branch
DC
Internet
IaaS
instance
Inet
IaaS
instance
Inet
IaaS
instance
Inet DC
Public Cloud Provider 1
Region 1
Public Cloud Provider 1
Region 2
Public Cloud Provider 2
Region 1
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Challenges with hybrid Cloud Migrations
Traffic trombones through DC
IaaS is extension of DC
Multi-Transport access
DIA : Protecting branch users
& branch router
Consistency across multi-
cloud deployments
User
experience
Branch to cloud
connectivity
Resiliency
Security
Operational
model
Cloud connectivity
consumable through a single
pane
Transport independent any-
to-any connectivity
End-to-end VPN
segmentation/isolation
Visibility into IaaS application
usage
Consistent policy across
branch, DC and Cloud sites
Cisco Cloud ready WAN
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What is Cloud onRamp ?
Cloud onRamp is Cisco’s SD-WAN capability
to simplify hybrid cloud connectivity, by
extending WAN fabric to public cloud
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp
vManage Cloud onRamp for
IaaS: vManage application that
orchestrates connectivity to IaaS
instances across multiple cloud
and multiple regions. Provides
visibility into cloud instances.
vEdge Cloud Router: A
virtualized version of the vEdge
router. Available on the AWS and
Azure marketplace.
Key Components
SD-WAN
Fabric
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – 3 Simple Steps
1
Discover Applications
2
Provide GW Information
3
Map Applications to
Segments
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS
How it works
Internet
Branch
DC
MPLS
Public Cloud connectivity solution consumable through the vManage platform
vManage
Platform
Public cloud
credentials added to
vManage
vManage invokes
instantiation of vEdge
instances in users
accounts & connects
IaaS instances to vEdge
GW VPN segments
IaaS instances are
discovered from users
account in a region.
User selects instances
to operate on
New instances can
be discovered and
mapped to VPN
segments later
Public Cloud Provider 1 Region 1
IaaS instances
IaaS instances
vEdge GW
User defines vEdge
gateway parameters and
maps IaaS instances to
VPN segments in the
overlay
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS
AWS solution detail
Direct
Connect
VGW
AZ1
AZ2
R
Architectural advantages – Cloud onRamp
• Share transport (Direct connect and
Internet) & vEdge Gateways across multiple
spoke VPCs in a region
• Share one gateway VPC for all host VPCs in
a region.
• Leverage AWS components (IGW, VGW, VPC
router) for redundancy.
• Utilize dynamic routing for fast failover
times.
• Gateway VPC can host firewall for security
compliance.
• End – End security and segmentation
VGW
Standard IPSec
overlay + BGP to
vEdge GW
vEdge GW
vEdge GW
AZ1
AZ2
R
Host VPC
vManage instantiated
and managed
Transit VPC
IGW
AWS Region
VGW
AZ1
AZ2
Host VPC
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Demo
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configuration
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – Discover Applications
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – GW Information
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – Map Applications to Segments
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – Dashboard
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Monitoring &
Troubleshooting
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – Monitoring & Troubleshooting
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – Monitoring & Troubleshooting
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp – Monitoring & Troubleshooting
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS
SD-WAN value proposition
Branch
Internet
Branch
DC
MPLS
IaaS
instances
Public Cloud Provider 1
Region 1
DC
IaaS
instances
vEdge GW
IaaS
instances
Public Cloud Provider 1
Region 2
IaaS
instances
vEdge GW
IaaS
instances
Public Cloud Provider 2
Region 1
IaaS
instances
vEdge GW
1. Direct branch to cloud
connectivity
2. Consistent Policy
management & network
visibility for branch & cloud
3. Resilient & hybrid access
from cloud
4. Application steering
5. Multi-cloud
solution

More Related Content

What's hot

20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...Amazon Web Services Japan
 
20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...Amazon Web Services Japan
 
Wireless LAN Security, Policy, and Deployment Best Practices
Wireless LAN Security, Policy, and Deployment Best PracticesWireless LAN Security, Policy, and Deployment Best Practices
Wireless LAN Security, Policy, and Deployment Best PracticesCisco Mobility
 
週末趣味のAWS Transit Gatewayでの経路制御
週末趣味のAWS Transit Gatewayでの経路制御週末趣味のAWS Transit Gatewayでの経路制御
週末趣味のAWS Transit Gatewayでの経路制御Namba Kazuo
 
금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략 - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...
금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략  - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략  - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...
금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략 - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...Amazon Web Services Korea
 
SD-WANって何だろう。使い方を知ってみよう(AWS分)
SD-WANって何だろう。使い方を知ってみよう(AWS分)SD-WANって何だろう。使い方を知ってみよう(AWS分)
SD-WANって何だろう。使い方を知ってみよう(AWS分)Yukihiro Kikuchi
 
Identity Access Management 101
Identity Access Management 101Identity Access Management 101
Identity Access Management 101OneLogin
 
AWS Direct Connect フェイルオーバーテストやってみた
AWS Direct Connect フェイルオーバーテストやってみたAWS Direct Connect フェイルオーバーテストやってみた
AWS Direct Connect フェイルオーバーテストやってみたSho Takahashi
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure NetworkingPedro Sousa
 
Cisco ASA Firepower
Cisco ASA FirepowerCisco ASA Firepower
Cisco ASA FirepowerAnwesh Dixit
 
Demystifying Prisma Access
Demystifying Prisma AccessDemystifying Prisma Access
Demystifying Prisma AccessHaris Chughtai
 
aws health organizations notifications
aws health organizations notificationsaws health organizations notifications
aws health organizations notificationskota tomimatsu
 
20190326 AWS Black Belt Online Seminar Amazon CloudWatch
20190326 AWS Black Belt Online Seminar Amazon CloudWatch20190326 AWS Black Belt Online Seminar Amazon CloudWatch
20190326 AWS Black Belt Online Seminar Amazon CloudWatchAmazon Web Services Japan
 
Meraki Solution Overview
Meraki Solution OverviewMeraki Solution Overview
Meraki Solution OverviewClaudiu Sandor
 
20210526 AWS Expert Online マルチアカウント管理の基本
20210526 AWS Expert Online マルチアカウント管理の基本20210526 AWS Expert Online マルチアカウント管理の基本
20210526 AWS Expert Online マルチアカウント管理の基本Amazon Web Services Japan
 
Advanced Security Best Practices Masterclass
Advanced Security Best Practices MasterclassAdvanced Security Best Practices Masterclass
Advanced Security Best Practices MasterclassAmazon Web Services
 

What's hot (20)

20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
 
20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190130 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
 
Wireless LAN Security, Policy, and Deployment Best Practices
Wireless LAN Security, Policy, and Deployment Best PracticesWireless LAN Security, Policy, and Deployment Best Practices
Wireless LAN Security, Policy, and Deployment Best Practices
 
週末趣味のAWS Transit Gatewayでの経路制御
週末趣味のAWS Transit Gatewayでの経路制御週末趣味のAWS Transit Gatewayでの経路制御
週末趣味のAWS Transit Gatewayでの経路制御
 
금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략 - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...
금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략  - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략  - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...
금융 서비스 패러다임의 전환 가속화 시대, 신한금융투자의 Cloud First 전략 - 신중훈 AWS 솔루션즈 아키텍트 / 최성봉 클라우...
 
SD-WANって何だろう。使い方を知ってみよう(AWS分)
SD-WANって何だろう。使い方を知ってみよう(AWS分)SD-WANって何だろう。使い方を知ってみよう(AWS分)
SD-WANって何だろう。使い方を知ってみよう(AWS分)
 
Identity Access Management 101
Identity Access Management 101Identity Access Management 101
Identity Access Management 101
 
ISE-802.1X-MAB
ISE-802.1X-MABISE-802.1X-MAB
ISE-802.1X-MAB
 
AWS Direct Connect フェイルオーバーテストやってみた
AWS Direct Connect フェイルオーバーテストやってみたAWS Direct Connect フェイルオーバーテストやってみた
AWS Direct Connect フェイルオーバーテストやってみた
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure Networking
 
AWS IAM Introduction
AWS IAM IntroductionAWS IAM Introduction
AWS IAM Introduction
 
Cisco ASA Firepower
Cisco ASA FirepowerCisco ASA Firepower
Cisco ASA Firepower
 
Demystifying Prisma Access
Demystifying Prisma AccessDemystifying Prisma Access
Demystifying Prisma Access
 
AWS PrivateLink Fundamentals
AWS PrivateLink FundamentalsAWS PrivateLink Fundamentals
AWS PrivateLink Fundamentals
 
aws health organizations notifications
aws health organizations notificationsaws health organizations notifications
aws health organizations notifications
 
20190326 AWS Black Belt Online Seminar Amazon CloudWatch
20190326 AWS Black Belt Online Seminar Amazon CloudWatch20190326 AWS Black Belt Online Seminar Amazon CloudWatch
20190326 AWS Black Belt Online Seminar Amazon CloudWatch
 
Meraki Solution Overview
Meraki Solution OverviewMeraki Solution Overview
Meraki Solution Overview
 
Clear pass policy manager advanced_ashwath murthy
Clear pass policy manager advanced_ashwath murthyClear pass policy manager advanced_ashwath murthy
Clear pass policy manager advanced_ashwath murthy
 
20210526 AWS Expert Online マルチアカウント管理の基本
20210526 AWS Expert Online マルチアカウント管理の基本20210526 AWS Expert Online マルチアカウント管理の基本
20210526 AWS Expert Online マルチアカウント管理の基本
 
Advanced Security Best Practices Masterclass
Advanced Security Best Practices MasterclassAdvanced Security Best Practices Masterclass
Advanced Security Best Practices Masterclass
 

Similar to DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud

TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...Amazon Web Services
 
Cisco Connect Ottawa 2018 multi cloud
Cisco Connect Ottawa 2018 multi cloudCisco Connect Ottawa 2018 multi cloud
Cisco Connect Ottawa 2018 multi cloudCisco Canada
 
DEM16 Cisco ACI Anywhere – AWS Extensions
DEM16 Cisco ACI Anywhere – AWS ExtensionsDEM16 Cisco ACI Anywhere – AWS Extensions
DEM16 Cisco ACI Anywhere – AWS ExtensionsAmazon Web Services
 
Cisco Connect Ottawa 2018 multi cloud connect, protect, and consume
Cisco Connect Ottawa 2018 multi cloud   connect, protect, and consumeCisco Connect Ottawa 2018 multi cloud   connect, protect, and consume
Cisco Connect Ottawa 2018 multi cloud connect, protect, and consumeCisco Canada
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Canada
 
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...Amazon Web Services
 
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...NetworkCollaborators
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Cisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WANCisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WANNetworkCollaborators
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityMarketingArrowECS_CZ
 
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...Nur Shiqim Chok
 
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformationCisco Connect 2018 Malaysia - SDNNFV telco data center transformation
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformationNetworkCollaborators
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:Cisco Canada
 
Fostering the Evolution of Network Based Cloud Service Providers.
Fostering the Evolution of Network Based Cloud Service Providers.Fostering the Evolution of Network Based Cloud Service Providers.
Fostering the Evolution of Network Based Cloud Service Providers.Cisco Service Provider
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionCisco Canada
 
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...NetworkCollaborators
 
cisco csr1000v
cisco csr1000vcisco csr1000v
cisco csr1000vMing914298
 

Similar to DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud (20)

TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
 
Cisco Connect Ottawa 2018 multi cloud
Cisco Connect Ottawa 2018 multi cloudCisco Connect Ottawa 2018 multi cloud
Cisco Connect Ottawa 2018 multi cloud
 
DEM16 Cisco ACI Anywhere – AWS Extensions
DEM16 Cisco ACI Anywhere – AWS ExtensionsDEM16 Cisco ACI Anywhere – AWS Extensions
DEM16 Cisco ACI Anywhere – AWS Extensions
 
Cisco Connect Ottawa 2018 multi cloud connect, protect, and consume
Cisco Connect Ottawa 2018 multi cloud   connect, protect, and consumeCisco Connect Ottawa 2018 multi cloud   connect, protect, and consume
Cisco Connect Ottawa 2018 multi cloud connect, protect, and consume
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
 
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
 
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
Cisco Connect 2018 Malaysia - Cisco sd-wan-next generation wan to power your ...
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Cisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WANCisco Connect 2018 Singapore - Cisco SD-WAN
Cisco Connect 2018 Singapore - Cisco SD-WAN
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
Secure Your Network for Scale & the Cloud
Secure Your Network for Scale & the CloudSecure Your Network for Scale & the Cloud
Secure Your Network for Scale & the Cloud
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivity
 
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...[Cisco Connect 2018 - Vietnam] 3. rajinder singh   cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
 
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformationCisco Connect 2018 Malaysia - SDNNFV telco data center transformation
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
 
Fostering the Evolution of Network Based Cloud Service Providers.
Fostering the Evolution of Network Based Cloud Service Providers.Fostering the Evolution of Network Based Cloud Service Providers.
Fostering the Evolution of Network Based Cloud Service Providers.
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
 
cisco csr1000v
cisco csr1000vcisco csr1000v
cisco csr1000v
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

DEM14 Extending the Cisco SD-WAN Fabric to the AWS Cloud

  • 1. Manan Shah / Linus Aranha April, 2018 Extending Cisco SD-WAN fabric to the AWS Cloud
  • 2. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Introduction to Cisco SD-WAN • Key challenges with hybrid cloud deployments • How to simplify hybrid cloud deployments with Cloud onRamp • Demo of Cloud onRamp - IaaS for AWS Agenda
  • 3. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN Apps SD-WAN Cloud Use-Cases… WAN USERS DC IaaS SaaS vDC AnalyticsCloud Delivered DEVICES THINGS Intent- based NetworkInfrastructure DNACenter AnalyticsPolicy Automation I N T EN T C O N T EX T S EC U RI T Y L EA RN I N G Cloud delivered WAN with operational simplicity & analytics1 Superior security architecture – cloud based & on-premises 2 Transport Independent WAN Fabric 0 5 Application QOE3 End-point flexibility: • Physical or virtual • Rich services or lite • Branch, Agg, Cloud 4
  • 4. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco SD-WAN – Components Data Center Campus Branch Home Office Control Plane (Containers or VMs) Data Plane (Physical or Virtual) Management Plane (Multi-tenant or Dedicated) Orchestration Plane vManage vSmart vBond vEdge ISR4k ASR1k ENCS vOrchestrator vMonitor API 4GINTERNET MPLS CONTROL ANALYTICS MANAGEMENT Policy, Security, Routing On-boarding, life cycle management
  • 5. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Hybrid-Cloud & SD-WAN
  • 6. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential New use cases accelerate adoption • Hybrid-Cloud adoption • Container-based applications • Serverless Compute • Machine learning / AI • IoT IaaS Adoption & Key Trends 44 IaaS spend in 2018 will grow by 22% CAGR
  • 7. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Hybrid Cloud Connectivity - Today Branch MPLS/Internet Branch DC Internet IaaS instance Inet IaaS instance Inet IaaS instance Inet DC Public Cloud Provider 1 Region 1 Public Cloud Provider 1 Region 2 Public Cloud Provider 2 Region 1
  • 8. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Challenges with hybrid Cloud Migrations Traffic trombones through DC IaaS is extension of DC Multi-Transport access DIA : Protecting branch users & branch router Consistency across multi- cloud deployments User experience Branch to cloud connectivity Resiliency Security Operational model Cloud connectivity consumable through a single pane Transport independent any- to-any connectivity End-to-end VPN segmentation/isolation Visibility into IaaS application usage Consistent policy across branch, DC and Cloud sites Cisco Cloud ready WAN
  • 9. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential What is Cloud onRamp ? Cloud onRamp is Cisco’s SD-WAN capability to simplify hybrid cloud connectivity, by extending WAN fabric to public cloud
  • 10. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp vManage Cloud onRamp for IaaS: vManage application that orchestrates connectivity to IaaS instances across multiple cloud and multiple regions. Provides visibility into cloud instances. vEdge Cloud Router: A virtualized version of the vEdge router. Available on the AWS and Azure marketplace. Key Components SD-WAN Fabric
  • 11. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – 3 Simple Steps 1 Discover Applications 2 Provide GW Information 3 Map Applications to Segments
  • 12. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp for IaaS How it works Internet Branch DC MPLS Public Cloud connectivity solution consumable through the vManage platform vManage Platform Public cloud credentials added to vManage vManage invokes instantiation of vEdge instances in users accounts & connects IaaS instances to vEdge GW VPN segments IaaS instances are discovered from users account in a region. User selects instances to operate on New instances can be discovered and mapped to VPN segments later Public Cloud Provider 1 Region 1 IaaS instances IaaS instances vEdge GW User defines vEdge gateway parameters and maps IaaS instances to VPN segments in the overlay
  • 13. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp for IaaS AWS solution detail Direct Connect VGW AZ1 AZ2 R Architectural advantages – Cloud onRamp • Share transport (Direct connect and Internet) & vEdge Gateways across multiple spoke VPCs in a region • Share one gateway VPC for all host VPCs in a region. • Leverage AWS components (IGW, VGW, VPC router) for redundancy. • Utilize dynamic routing for fast failover times. • Gateway VPC can host firewall for security compliance. • End – End security and segmentation VGW Standard IPSec overlay + BGP to vEdge GW vEdge GW vEdge GW AZ1 AZ2 R Host VPC vManage instantiated and managed Transit VPC IGW AWS Region VGW AZ1 AZ2 Host VPC
  • 14. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Demo
  • 15.
  • 16. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Configuration
  • 17. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – Discover Applications
  • 18. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – GW Information
  • 19. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – Map Applications to Segments
  • 20. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – Dashboard
  • 21. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Monitoring & Troubleshooting
  • 22. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – Monitoring & Troubleshooting
  • 23. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – Monitoring & Troubleshooting
  • 24. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp – Monitoring & Troubleshooting
  • 25. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cloud onRamp for IaaS SD-WAN value proposition Branch Internet Branch DC MPLS IaaS instances Public Cloud Provider 1 Region 1 DC IaaS instances vEdge GW IaaS instances Public Cloud Provider 1 Region 2 IaaS instances vEdge GW IaaS instances Public Cloud Provider 2 Region 1 IaaS instances vEdge GW 1. Direct branch to cloud connectivity 2. Consistent Policy management & network visibility for branch & cloud 3. Resilient & hybrid access from cloud 4. Application steering 5. Multi-cloud solution