SlideShare a Scribd company logo
1 of 43
Download to read offline
Cisco Confidential© 2016 Cisco and/or its affiliates. All rights reserved. 1
Principal Systems Engineer
Cisco Canada
November, 2017
Understanding Cisco’ Next
Generation SD-WAN
Technology
Rob Barton
Cisco Confidential© 2016 Cisco and/or its affiliates. All rights reserved. 2
Your Time Is Now
Connect
Cisco
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
The Branch and WAN Are Being Disrupted!
of revenue
is generated
in the branch
90%
MORE
THREATS
30%
Of advanced threats will
target branch offices by
2016 (up from 5%)
MORE
USERS
80% Of employee and
customers are served in
branch offices
MORE
DEVICES
73%
Growth in mobile
devices from
2014-2018
MORE
APPS
20-50% Increase in enterprise
bandwidth per year
through 2018
IoT devices
connected to
internet by 2020
30B
Annual increase in
enterprise bandwidth
and video adoption50%
Up to
Mobile-connected
devices by 201910B
Of Organizations primarily
use public cloud by 201980%
• The traditional WAN / branch market is undergoing a massive disruption
• Customers are asking for SD-WAN solutions with virtualized services
• In 2017 Cisco acquired Viptela, the de-facto market leader and recognized best-of-breed
technology in the SD-WAN space
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
Existing
Data Center
Remote Site
MSP-RT
MPLS
NewWAN
Internet
ISP-RT
New
The WAN Market Disruption and Migration
Services
Delivery
• Segment traffic
• Deploy application aware
topologies
• Optimize routing, security, QoS,
multicast, services insertion and
survivability
Transport
Independence
• Leverage overlay through
existing equipment at data center
for transport agnostic redesign
• Replace remote site equipment
or leverage overlay
Application
Policies
• Select test application as
candidate for intelligent traffic
engineering
• Test blackout and brownout
failover scenarios
Existing
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
APPLICATION POLICIES
SERVICES DELIVERY PLATFORM
TRANSPORT INDEPENDENT FABRIC
Broadband CellularMPLS
ZERO TOUCH ZERO TRUST
QoSSecurity Segmentation Svc Insertion SurvivabilityRouting Multicast
Per-Segment
Topologies
Cloud Path
(IaaS)
Application
SLA
Secure
Perimeter
Traffic
Engineering
Transport
Hub
Cloud Accel
(SaaS)
Analytics
Monitoring
Operations
Business Driven WAN Infrastructure
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6
Cloud-first
management
with flexible
deployment options
Accelerate key
SD-WAN use cases;
Cloud-edge and
Segmentation
Sophisticated, but
still simple to deploy
and operate
Complements Cisco’s Enterprise Networks architecture strategy
Why Did Cisco Buy Viptela?
Cisco Digital
Network Architecture
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7
Better Together
Leading Routing &
SD-WAN Platforms
Goal: Building next generation SD-WAN solutions
Together, helping businesses and IT to innovate faster, securing and delivering
better customer outcomes, while reducing costs and lowering risk
Cloud-managed &
Feature-rich SD-WAN
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8
• Secure Elastic Connectivity
• Cloud First
• Application Quality of
Experience
• Agile Operations
Reinventing the WAN - 4 Technical Pillars
Security
Applications
Services
Connectivity Operations
Flexible
Connectivity
Agile
Operations
Application
Services
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
Centralized Device
Auth-DB
Authenticated/Encrypted
Control Plane
Automatic Key Rollover
Scalable Data-Plane
Encryption
Embedded Security Secure On-Boarding
Reinventing the WAN
Security
Security Applications
Services
Connectivity OperationsConnectivity Operations
Application
Services
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10
MPLS
LTE
INTERNET
Hybrid WAN
Segmentation/VPNs
Dynamic Per-VPN
Topologies
MPLS
LTE
INTERNET
Provider/Transport
Agnostic
Security Applications
Services
Connectivity OperationsConnectivity Operations
Application
Services
Reinventing the WAN
Connectivity
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11
Deep Packet Inspection Central Orchestration
Application-Aware
Routing
Transport SLA Monitoring
MPLS
LTE
INTERNET
Cloud Services
Integration
SEN Overlay
Application Layer
AnalyticsSecurity Applications
Services
Connectivity OperationsConnectivity Operations
Application
Services
Reinventing the WAN
Application Services
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12
Centralized Operations
Distributed Execution
Zero Touch ProvisioningTemplate-based
Configurations
Programmatic APIs
Open Object Model
NetConf Ad-Hoc
Adds/Moves/Changes
Centralized
Policy Orchestration
Security Applications
Services
Connectivity OperationsConnectivity Operations
Application
Services
Reinventing the WAN
Operations
Cisco Confidential 13© 2016 Cisco and/or its affiliates. All rights reserved.
Cisco SD-WAN Architecture
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
vEdge Router
Cloud Data
Center
Campus
Branch
Small Office
Home
Office
vManage
vControl
The Viptela branch
office router
Cloud or on
premises network
management
Policy and Service
Control Plane
Viptela Solution – Key Components
vBond
On-Boarding and
Orchestration
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
vBond: ZTD and Orchestration Plane
APIs
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
• Used for device on-boarding
(ZTD)
• Orchestrates connectivity
between management, control
and data plane
• First point of authentication
• All other components need to
know the vBond IP or DNS
information
• Authorizes all control
connections (white-list model)
• Distributes list of vSmarts to all
vEdges
Orchestration Plane
Cisco vBond
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
vEdge: The Data Plane
Data Plane
Physical/Virtual
Cisco vEdge
• WAN edge routers
• Provides secure data plane with
remote vEdge routers
• Establishes secure control plane
with vSmart controllers (OMP)
• Implements data plane and
application aware routing policies
• Exports performance statistics
• Leverages traditional routing
protocols like OSPF, BGP and
VRRP
• Support Zero Touch Deployment
• Physical or Virtual form factor
(100Mb, 1Gb, 10Gb)
APIs
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17
vSmart: The Control Plane
Control Plane
Cisco vSmart
• Centralized brain of the solution
• Facilitates fabric discovery
• Establishes OMP peering with all
vEdges
• Implements control plane policies,
such as service chaining, traffic
engineering and per VPN topology
• Dramatically reduces complexity of
the entire network
• Distributes connectivity information
between vEdge
• Orchestrates secure data plane
connectivity between vEdges
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
APIs
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18
Overlay Management Protocol (OMP)
Unified Control Plane
• Runs on top of TCP, extensible control plane
protocol
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
- Inside TLS/DTLS connections
• Advertises control plane contextvSmart vSmart
vSmart
vEdge vEdge
VS
Note: vEdge routers need no control connections amongst them
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19
vManage: The Management Plane
Management Plane
Cisco vManage
• Single pane of glass for Day0,
Day1 and Day2 operations
• Real time alerting
• Centralized provisioning
• Configuration standardization
• Simplicity of deploying
• Simplicity of change
• Supports
• REST API
• CLI
• NETCONF / YANG
• SNMP
• Syslog
vSmart Controllers
vAnalytics
3rd Party
Automation
vManage
Data Center Campus Branch SOHOCloud
vBond
vEdge Routers
4GMPLS
INET
APIs
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Single Pane Of Glass Operations
Operations Simplicity and Visibility
Rich Analytics
Cisco Confidential 21© 2016 Cisco and/or its affiliates. All rights reserved.
SD-WAN Fabric and Capabilities
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
TMP
Chip
Root Chain
Embedded Device Identity
Controller Trust
Zero-Touch Provisioning of the vEdge Router
Identity and Trust
Identity
Cert
vEdge
Dynamic Device Identity
Root Chain
Controller Trust
Identity
Cert
vEdge Cloud
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23
Zero Trust Model
Certificate-Based Trust
• Bi-directional certificate-based trust between all
elements
- Public or Enterprise PKI
• White-list of valid vEdges and controllers
- Certificate serial number as unique identification
Signed
vEdge List
Administrator
Defined
Controllers
vEdge
vBond
vManage
vSmart
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 24
Zero Touch Provisioning vEdge Walk-through
Control and Policy
Elements
Full Registration and
Configuration
vEdge
5
* Factory default configured
Assumption:
 DHCP on Transport Side (WAN)
 DNS to resolve ZTP server name*
3
4
Zero Touch Provisioning
Server
1
2
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
Template-Based Configurations
Centralized Device Configuration Enforcement
• Templates are attached to provisioned
vEdge routers
• Variables are used for rapid bulk
configuration rollout with unique per-
device settings
• Local configuration changes are not
allowed
- Prevents configuration drift
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
OMP Update:
 Reachability – IP Subnets, TLOCs
 Security – Encryption Keys
 Policy – Data/App-route Policies
BGP, OSPF,
Connected,
Static
BFD
IPSec Tunnel
OMP
DTLS/TLS Tunnel
Transport1
Transport2VPN1
A
VPN2
B
VPN1
C
VPN2
D
BGP, OSPF,
Connected,
Static
vSmart
OMP
Update
OMP
Update
vEdge vEdge
Subnets Subnets
TLOCs TLOCs
Policies
Fabric Operation
Fabric Walk-Through
OMP
Update
OMP
Update
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
Ingress
vEdge
VPN 3
VPN 1
VPN 2
SD-WAN
IPSec
Tunnel
20
IP
8
UDP
36
ESP
4
VPN
…
Data
Egress
vEdge
Interface
VLAN
• Segment connectivity across fabric w/o
reliance on underlay transport
• vEdge routers maintain per-VPN routing
table
• Labels are used to identify VPN for
destination route lookup
• Interfaces and sub-interfaces (802.1Q tags)
are mapped into VPNs
VPN1
VPN2
Interface
VLAN
VPN1
VPN2
Secure Segmentation
End-to-End Segmentation
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28
Application-Centric Network Capabilities
Per-Session Loadsharing
Active/Active
Per-Session Weighted
Active/Active
Application Pinning
Active/Standby
Application Aware Routing
SLA Compliant
SLASLA
Core
Hierarchical Multihop Fabric Single-hop Fabric
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29
 Enforce SLA compliant path
for applications of interest
 Other applications will follow
fabric routing across all
paths
Control Plane
Path1: 10ms, 0% loss, 5ms latency
Path2: 200ms, 3% loss, 10ms latency
Path3: 140ms, 1% loss, 10ms latency
vManage
App Aware Routing Policy
App A path must have:
latency < 150ms
loss < 2%
jitter < 10ms
vEdge1 vEdge2
Internet
MPLS
4G LTE
vSmart Controllers
App A
IPSec Tunnel
Critical Applications SLA
Application Aware Routing
Path 2
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30
Deep Packet Inspection Engine
Primary Use Cases:
- Application Visibility
- Application Firewall
- Traffic Prioritization
- Transport Selection
- Analytics
vEdge Router
App 1
App 2
App 3,000
Cloud Data
Center
Data
Center
Campus
Branch
Small Office
Home Office
MPLS INET
3G/4G
Embedded Application Recognition
Deep Packet Inspection
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31
• Embedded Deep Packet Inspection
engine
• Application and flow level visibility
for the fabric and individual vEdge
routers
• Centralized statistics and
performance
• Export flow level data (IPFIX) to
external collector
Application and Performance Visibility
Deep Packet Inspection
Cisco Confidential 32© 2016 Cisco and/or its affiliates. All rights reserved.
SD-WAN Solution Components
Overview
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33
Cisco vEdge Routers Portfolio Positioning
Branch/SOHO/SMB
(100Mb)
Branch/Campus
(1Gb)
Campus/Data Center
(10Gb)
NFV, vCPE
(N x cores)
IaaS & Cloud
Interconnect
(N x cores)
Campus/Data Center
(20Gb+)
vEdge 100 family vEdge 1000 vEdge 2000 vEdge 5000
vEdge Cloud on
Greybox or
Whitebox
vEdge Cloud
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
Data Center Campus Branch Home Office
4G/LTE
MPLS
Internet
Control Plane
(Containers or VMs)
(vSmart)
Management Plane
(Multi-tenant or Dedicated)
(vManage)
Orchestration Plane
(vBond)
2000 vEdges per vBond
Redundancy Add 1-2 vBonds
Horizontal Scale out Model
Horizontal Scale Out Model
2700 vEdges per vManage
Horizontal Scale out Model
in cluster mode (same DC)
2700 vEdges per vSmart
Redundancy Add 1-2 vSmarts
Horizontal Scale out Model
Scalability Considerations
Orchestration/Control/Management Plane
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
vEdge100 vEdge1000 vEdge2000
IPSec Tunnels : 250 IPSec Tunnels : 1500 IPSec Tunnels : 6000
Max aggregated throughput:
vEdge-100 – 100MB AES-256 full duplex
vEdge-1000 - 1GB AES-256 full duplex
vEdge-2000 – 10GB AES-256 full duplex
Max number of concurrent VPNs: 64
[vpn 0 and vpn 512 included]
Overlay tunnels are static based on policy
Not dynamically generated on-demand.
Scalability Considerations
Data Plane and IPsec
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36
Perpetual cost of
Cisco
SD-WAN CPE
hardware
Subscription cost of
Cisco SD-WAN
software (Includes
SD-WAN controller +
CPE software)
Operational cost of
Cisco SD-WAN
solution
1.Subscription license (1YR, 3YR and 5YR) for Cisco SD-WAN software charged per CPE.
This cost is dependent on two factors:
• Service bandwidth
• Features
2.Perpetual cost of Cisco SD-WAN CPE element.
SD-WAN Pricing Model
Subscription and Perpetual Elements
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37
Plus Pro
Hub
Spoke Spoke Spoke
MPLS Internet Local
breakout
Hub
Spoke Spoke Spoke
MPLS Internet
Spoke Spoke
Local
breakout
Dynamic Routing
Dynamic
Routing
Hub
Spoke Spoke Spoke
MPLS Internet
Spoke Spoke
Dynamic Routing
Dynamic
Routing
SaaS onRamp
SD WAN
controllers
AnalyticsSD WAN
controllers
SD WAN
controllers
AAR
AAR AAR
E2E
Segmentation
E2E
Segmentation
• Routing: Static
• Topology: Hub-n-spoke only
• Internet/Cloud: NAT, Split tunnel
• Policy: Local ACL only, Data policy
• QoS
• SLA: Application aware routing (5 tuple
only)
• Visibility : DPI for visibility only
• Routing: Dynamic routing (OSPF/BGP)
• Topology: Mesh topology
• Internet/Cloud: Cloud onRamp for IaaS
• Policy: Control policy
• Segmentation: 5 VPNs (1+4)
• SLA: Application aware routing (DPI)
• Multicast
• Segmentation: Unlimited
• Internet/Cloud: Cloud onRamp for
SaaS
• Analytics: vAnalytics platform
Enterprise
License Tier Features
License Tiers
Cisco Confidential 38© 2016 Cisco and/or its affiliates. All rights reserved.
Roadmap
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage
Cisco SD-WAN Day 1 Deployment Scenarios
ISR
TI / E! / DSL
DeploymentScenarios
vEdge
ISR Providing Services
vManage
vEdge
Ethernet
ISR
WaaS
UC
Thin Branch
vManage
vEdge
Ethernet
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Roadmap
Phase 2
Platform Integration
Phase 1
No Integration
Phase 3
Management Integration
Platform:
• As-is
Management:
• vManage
Platform:
• vEdge capabilities integrated into all IOS-XE
platforms (ISR, CSR, ENCS, ASR1K)
Management:
• vManage for SD-WAN capabilities on IOS-XE
Management:
• Cloud hosted DNA Center integrates vManage
capabilities
• Full DNA Center capabilities (Assurance,
Integrated workflows for SD-Access and
SD-WAN)
Support current Viptela
customers
Viptela SD-WAN on strategic ISR
platforms
Deliver end-to-end experience
with full DNA integration
DeploymentScenariosBenefitsDetails
vEdge ISR4K + vEdge SW
DNA Center
+ SD-WAN
ISR4K + vEdge SW
vManage
vEdge
vManage
vEdge
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41
Positioning Cisco’s SD-WAN Solutions
1. Do you have a requirement to support end-
to-end secure segmentation over the
WAN?
2. Do you intend to deploy dynamic per VPN
topologies?
3. Do you have different WAN transports with
a need to support a single data plane?
4. Do you intend to deploy a network with
intelligent path selection for IaaS or SaaS?
1. Do you have existing Meraki
infrastructure?
2. Do you have a requirement to manage a
full branch network (switches, firewalls)
through a single management interface?
3. Do you have a lean IT staff with minimal
experience in secure WAN environments?
4. Does your staff desire simple management
and automation for deploying branch
security?
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
• Cisco is the market and technology leader in SD-WAN, combining
the flexibility of Viptela, Meraki, and ISR IOS-XE
• Cisco’s SD-WAN solution (Viptela) is both a cloud and on-prem
(hardware) based solution, offering unmatched capabilities
• Cisco will merge the Viptela and IOS-XE capabilities into a
common ISR 4K-based platform and DNA Center, but the
complimentary Viptela core products are here to stay in
foreseeable future
Key Takeaways
Thank you.

More Related Content

What's hot

Cisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloud
Cisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloudCisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloud
Cisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloudCisco Canada
 
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
Cisco Connect Halifax 2018   Putting firepower into the next generation firewallCisco Connect Halifax 2018   Putting firepower into the next generation firewall
Cisco Connect Halifax 2018 Putting firepower into the next generation firewallCisco Canada
 
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
[Cisco Connect 2018 - Vietnam] Rajinder singh   cisco sd-wan-next generation ...[Cisco Connect 2018 - Vietnam] Rajinder singh   cisco sd-wan-next generation ...
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...Nur Shiqim Chok
 
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Halifax 2018   Cisco dna - deeper diveCisco Connect Halifax 2018   Cisco dna - deeper dive
Cisco Connect Halifax 2018 Cisco dna - deeper diveCisco Canada
 
Cisco Connect Halifax 2018 Application agility and programmability with cis...
Cisco Connect Halifax 2018   Application agility and programmability with cis...Cisco Connect Halifax 2018   Application agility and programmability with cis...
Cisco Connect Halifax 2018 Application agility and programmability with cis...Cisco Canada
 
Cisco Connect Halifax 2018 Anatomy of attack
Cisco Connect Halifax 2018   Anatomy of attackCisco Connect Halifax 2018   Anatomy of attack
Cisco Connect Halifax 2018 Anatomy of attackCisco Canada
 
Cisco Connect Halifax 2018 Accelerating the secure digital business through...
Cisco Connect Halifax 2018   Accelerating the secure digital business through...Cisco Connect Halifax 2018   Accelerating the secure digital business through...
Cisco Connect Halifax 2018 Accelerating the secure digital business through...Cisco Canada
 
Putting firepower into the next generation firewall
Putting firepower into the next generation firewallPutting firepower into the next generation firewall
Putting firepower into the next generation firewallCisco Canada
 
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...Cisco Canada
 
Cisco Connect Halifax 2018 cloud and on premises collaboration security exp...
Cisco Connect Halifax 2018   cloud and on premises collaboration security exp...Cisco Connect Halifax 2018   cloud and on premises collaboration security exp...
Cisco Connect Halifax 2018 cloud and on premises collaboration security exp...Cisco Canada
 
Cisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attackCisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attackCisco Canada
 
Leverage the Network
Leverage the NetworkLeverage the Network
Leverage the NetworkCisco Canada
 
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...Cisco Canada
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...Cisco Canada
 
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Connect Vancouver 2017 - How to have magical meeting experiencesCisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Connect Vancouver 2017 - How to have magical meeting experiencesCisco Canada
 
Cisco Connect Toronto 2017 - UCS and Hyperflex update
Cisco Connect Toronto 2017 - UCS and Hyperflex updateCisco Connect Toronto 2017 - UCS and Hyperflex update
Cisco Connect Toronto 2017 - UCS and Hyperflex updateCisco Canada
 
Cisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural Design
Cisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural DesignCisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural Design
Cisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural DesignCisco Canada
 
Cisco Connect Toronto 2018 dc-aci-anywhere
Cisco Connect Toronto 2018   dc-aci-anywhereCisco Connect Toronto 2018   dc-aci-anywhere
Cisco Connect Toronto 2018 dc-aci-anywhereCisco Canada
 
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Canada
 
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 -  Security Through The Eyes of a HackerCisco Connect Toronto 2017 -  Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 - Security Through The Eyes of a HackerCisco Canada
 

What's hot (20)

Cisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloud
Cisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloudCisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloud
Cisco Connect Vancouver 2017 - Compute infrastructure for a hybrid cloud
 
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
Cisco Connect Halifax 2018   Putting firepower into the next generation firewallCisco Connect Halifax 2018   Putting firepower into the next generation firewall
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
 
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
[Cisco Connect 2018 - Vietnam] Rajinder singh   cisco sd-wan-next generation ...[Cisco Connect 2018 - Vietnam] Rajinder singh   cisco sd-wan-next generation ...
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
 
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Halifax 2018   Cisco dna - deeper diveCisco Connect Halifax 2018   Cisco dna - deeper dive
Cisco Connect Halifax 2018 Cisco dna - deeper dive
 
Cisco Connect Halifax 2018 Application agility and programmability with cis...
Cisco Connect Halifax 2018   Application agility and programmability with cis...Cisco Connect Halifax 2018   Application agility and programmability with cis...
Cisco Connect Halifax 2018 Application agility and programmability with cis...
 
Cisco Connect Halifax 2018 Anatomy of attack
Cisco Connect Halifax 2018   Anatomy of attackCisco Connect Halifax 2018   Anatomy of attack
Cisco Connect Halifax 2018 Anatomy of attack
 
Cisco Connect Halifax 2018 Accelerating the secure digital business through...
Cisco Connect Halifax 2018   Accelerating the secure digital business through...Cisco Connect Halifax 2018   Accelerating the secure digital business through...
Cisco Connect Halifax 2018 Accelerating the secure digital business through...
 
Putting firepower into the next generation firewall
Putting firepower into the next generation firewallPutting firepower into the next generation firewall
Putting firepower into the next generation firewall
 
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
 
Cisco Connect Halifax 2018 cloud and on premises collaboration security exp...
Cisco Connect Halifax 2018   cloud and on premises collaboration security exp...Cisco Connect Halifax 2018   cloud and on premises collaboration security exp...
Cisco Connect Halifax 2018 cloud and on premises collaboration security exp...
 
Cisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attackCisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attack
 
Leverage the Network
Leverage the NetworkLeverage the Network
Leverage the Network
 
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Connect Vancouver 2017 - How to have magical meeting experiencesCisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
 
Cisco Connect Toronto 2017 - UCS and Hyperflex update
Cisco Connect Toronto 2017 - UCS and Hyperflex updateCisco Connect Toronto 2017 - UCS and Hyperflex update
Cisco Connect Toronto 2017 - UCS and Hyperflex update
 
Cisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural Design
Cisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural DesignCisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural Design
Cisco Connect Vancouver 2017 - Cisco Spark Hybrid Services Architectural Design
 
Cisco Connect Toronto 2018 dc-aci-anywhere
Cisco Connect Toronto 2018   dc-aci-anywhereCisco Connect Toronto 2018   dc-aci-anywhere
Cisco Connect Toronto 2018 dc-aci-anywhere
 
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUICisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
Cisco Digital Network Architecture – Deeper Dive, “From the Gates to the GUI
 
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 -  Security Through The Eyes of a HackerCisco Connect Toronto 2017 -  Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
 

Similar to Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN

Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaCisco Canada
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyCisco Canada
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionCisco Canada
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco Canada
 
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)Cisco Canada
 
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...Cisco Canada
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Canada
 
NFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch servicesNFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch servicesCisco Canada
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANRobb Boyd
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
 Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation Network Innovations Driving Business Transformation
 Network Innovations Driving Business TransformationCisco Service Provider
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:Cisco Canada
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessNetworkCollaborators
 
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Canada
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...NetworkCollaborators
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...NetworkCollaborators
 
Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit
Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit
Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit kimw001
 
Mạng chuyển mạch thế hệ mới
Mạng chuyển mạch thế hệ mớiMạng chuyển mạch thế hệ mới
Mạng chuyển mạch thế hệ mớiSunmedia Corporation
 

Similar to Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN (20)

Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN Technology
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
SP Virtual Managed Services (VMS) for Intelligent WAN (IWAN)
 
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
 
NFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch servicesNFV orchestration for cloud and virtual branch services
NFV orchestration for cloud and virtual branch services
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
BRKCRS-2110.pdf
BRKCRS-2110.pdfBRKCRS-2110.pdf
BRKCRS-2110.pdf
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
 Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined Access
 
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 
Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit
Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit
Cisco - OpenStack Summit 2016/Red Hat NFV Mini Summit
 
Mạng chuyển mạch thế hệ mới
Mạng chuyển mạch thế hệ mớiMạng chuyển mạch thế hệ mới
Mạng chuyển mạch thế hệ mới
 

More from Cisco Canada

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco Canada
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic frCisco Canada
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco Canada
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dcCisco Canada
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla nsCisco Canada
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco Canada
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Canada
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco Canada
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Cisco Canada
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v finalCisco Canada
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco Canada
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...Cisco Canada
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kineticCisco Canada
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...Cisco Canada
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet OverviewCisco Canada
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assuranceCisco Canada
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicingCisco Canada
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco merakiCisco Canada
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zeroCisco Canada
 
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1Cisco Canada
 

More from Cisco Canada (20)

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet Overview
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1Cisco Connect Toronto 2018   model-driven programmability for cisco ios xr-v1
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
 

Recently uploaded

The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 

Recently uploaded (20)

The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 

Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN

  • 1. Cisco Confidential© 2016 Cisco and/or its affiliates. All rights reserved. 1 Principal Systems Engineer Cisco Canada November, 2017 Understanding Cisco’ Next Generation SD-WAN Technology Rob Barton
  • 2. Cisco Confidential© 2016 Cisco and/or its affiliates. All rights reserved. 2 Your Time Is Now Connect Cisco
  • 3. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3 The Branch and WAN Are Being Disrupted! of revenue is generated in the branch 90% MORE THREATS 30% Of advanced threats will target branch offices by 2016 (up from 5%) MORE USERS 80% Of employee and customers are served in branch offices MORE DEVICES 73% Growth in mobile devices from 2014-2018 MORE APPS 20-50% Increase in enterprise bandwidth per year through 2018 IoT devices connected to internet by 2020 30B Annual increase in enterprise bandwidth and video adoption50% Up to Mobile-connected devices by 201910B Of Organizations primarily use public cloud by 201980% • The traditional WAN / branch market is undergoing a massive disruption • Customers are asking for SD-WAN solutions with virtualized services • In 2017 Cisco acquired Viptela, the de-facto market leader and recognized best-of-breed technology in the SD-WAN space
  • 4. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4 Existing Data Center Remote Site MSP-RT MPLS NewWAN Internet ISP-RT New The WAN Market Disruption and Migration Services Delivery • Segment traffic • Deploy application aware topologies • Optimize routing, security, QoS, multicast, services insertion and survivability Transport Independence • Leverage overlay through existing equipment at data center for transport agnostic redesign • Replace remote site equipment or leverage overlay Application Policies • Select test application as candidate for intelligent traffic engineering • Test blackout and brownout failover scenarios Existing
  • 5. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5 APPLICATION POLICIES SERVICES DELIVERY PLATFORM TRANSPORT INDEPENDENT FABRIC Broadband CellularMPLS ZERO TOUCH ZERO TRUST QoSSecurity Segmentation Svc Insertion SurvivabilityRouting Multicast Per-Segment Topologies Cloud Path (IaaS) Application SLA Secure Perimeter Traffic Engineering Transport Hub Cloud Accel (SaaS) Analytics Monitoring Operations Business Driven WAN Infrastructure
  • 6. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 Cloud-first management with flexible deployment options Accelerate key SD-WAN use cases; Cloud-edge and Segmentation Sophisticated, but still simple to deploy and operate Complements Cisco’s Enterprise Networks architecture strategy Why Did Cisco Buy Viptela? Cisco Digital Network Architecture
  • 7. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7 Better Together Leading Routing & SD-WAN Platforms Goal: Building next generation SD-WAN solutions Together, helping businesses and IT to innovate faster, securing and delivering better customer outcomes, while reducing costs and lowering risk Cloud-managed & Feature-rich SD-WAN
  • 8. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 • Secure Elastic Connectivity • Cloud First • Application Quality of Experience • Agile Operations Reinventing the WAN - 4 Technical Pillars Security Applications Services Connectivity Operations Flexible Connectivity Agile Operations Application Services
  • 9. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 Centralized Device Auth-DB Authenticated/Encrypted Control Plane Automatic Key Rollover Scalable Data-Plane Encryption Embedded Security Secure On-Boarding Reinventing the WAN Security Security Applications Services Connectivity OperationsConnectivity Operations Application Services
  • 10. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10 MPLS LTE INTERNET Hybrid WAN Segmentation/VPNs Dynamic Per-VPN Topologies MPLS LTE INTERNET Provider/Transport Agnostic Security Applications Services Connectivity OperationsConnectivity Operations Application Services Reinventing the WAN Connectivity
  • 11. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11 Deep Packet Inspection Central Orchestration Application-Aware Routing Transport SLA Monitoring MPLS LTE INTERNET Cloud Services Integration SEN Overlay Application Layer AnalyticsSecurity Applications Services Connectivity OperationsConnectivity Operations Application Services Reinventing the WAN Application Services
  • 12. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12 Centralized Operations Distributed Execution Zero Touch ProvisioningTemplate-based Configurations Programmatic APIs Open Object Model NetConf Ad-Hoc Adds/Moves/Changes Centralized Policy Orchestration Security Applications Services Connectivity OperationsConnectivity Operations Application Services Reinventing the WAN Operations
  • 13. Cisco Confidential 13© 2016 Cisco and/or its affiliates. All rights reserved. Cisco SD-WAN Architecture
  • 14. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14 vEdge Router Cloud Data Center Campus Branch Small Office Home Office vManage vControl The Viptela branch office router Cloud or on premises network management Policy and Service Control Plane Viptela Solution – Key Components vBond On-Boarding and Orchestration
  • 15. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15 vBond: ZTD and Orchestration Plane APIs vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET • Used for device on-boarding (ZTD) • Orchestrates connectivity between management, control and data plane • First point of authentication • All other components need to know the vBond IP or DNS information • Authorizes all control connections (white-list model) • Distributes list of vSmarts to all vEdges Orchestration Plane Cisco vBond
  • 16. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16 vEdge: The Data Plane Data Plane Physical/Virtual Cisco vEdge • WAN edge routers • Provides secure data plane with remote vEdge routers • Establishes secure control plane with vSmart controllers (OMP) • Implements data plane and application aware routing policies • Exports performance statistics • Leverages traditional routing protocols like OSPF, BGP and VRRP • Support Zero Touch Deployment • Physical or Virtual form factor (100Mb, 1Gb, 10Gb) APIs vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET
  • 17. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17 vSmart: The Control Plane Control Plane Cisco vSmart • Centralized brain of the solution • Facilitates fabric discovery • Establishes OMP peering with all vEdges • Implements control plane policies, such as service chaining, traffic engineering and per VPN topology • Dramatically reduces complexity of the entire network • Distributes connectivity information between vEdge • Orchestrates secure data plane connectivity between vEdges vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET APIs
  • 18. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18 Overlay Management Protocol (OMP) Unified Control Plane • Runs on top of TCP, extensible control plane protocol • Runs between vEdge routers and vSmart controllers and between the vSmart controllers - Inside TLS/DTLS connections • Advertises control plane contextvSmart vSmart vSmart vEdge vEdge VS Note: vEdge routers need no control connections amongst them
  • 19. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19 vManage: The Management Plane Management Plane Cisco vManage • Single pane of glass for Day0, Day1 and Day2 operations • Real time alerting • Centralized provisioning • Configuration standardization • Simplicity of deploying • Simplicity of change • Supports • REST API • CLI • NETCONF / YANG • SNMP • Syslog vSmart Controllers vAnalytics 3rd Party Automation vManage Data Center Campus Branch SOHOCloud vBond vEdge Routers 4GMPLS INET APIs
  • 20. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 Single Pane Of Glass Operations Operations Simplicity and Visibility Rich Analytics
  • 21. Cisco Confidential 21© 2016 Cisco and/or its affiliates. All rights reserved. SD-WAN Fabric and Capabilities
  • 22. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22 TMP Chip Root Chain Embedded Device Identity Controller Trust Zero-Touch Provisioning of the vEdge Router Identity and Trust Identity Cert vEdge Dynamic Device Identity Root Chain Controller Trust Identity Cert vEdge Cloud
  • 23. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23 Zero Trust Model Certificate-Based Trust • Bi-directional certificate-based trust between all elements - Public or Enterprise PKI • White-list of valid vEdges and controllers - Certificate serial number as unique identification Signed vEdge List Administrator Defined Controllers vEdge vBond vManage vSmart
  • 24. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 24 Zero Touch Provisioning vEdge Walk-through Control and Policy Elements Full Registration and Configuration vEdge 5 * Factory default configured Assumption:  DHCP on Transport Side (WAN)  DNS to resolve ZTP server name* 3 4 Zero Touch Provisioning Server 1 2
  • 25. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25 Template-Based Configurations Centralized Device Configuration Enforcement • Templates are attached to provisioned vEdge routers • Variables are used for rapid bulk configuration rollout with unique per- device settings • Local configuration changes are not allowed - Prevents configuration drift
  • 26. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26 OMP Update:  Reachability – IP Subnets, TLOCs  Security – Encryption Keys  Policy – Data/App-route Policies BGP, OSPF, Connected, Static BFD IPSec Tunnel OMP DTLS/TLS Tunnel Transport1 Transport2VPN1 A VPN2 B VPN1 C VPN2 D BGP, OSPF, Connected, Static vSmart OMP Update OMP Update vEdge vEdge Subnets Subnets TLOCs TLOCs Policies Fabric Operation Fabric Walk-Through OMP Update OMP Update
  • 27. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27 Ingress vEdge VPN 3 VPN 1 VPN 2 SD-WAN IPSec Tunnel 20 IP 8 UDP 36 ESP 4 VPN … Data Egress vEdge Interface VLAN • Segment connectivity across fabric w/o reliance on underlay transport • vEdge routers maintain per-VPN routing table • Labels are used to identify VPN for destination route lookup • Interfaces and sub-interfaces (802.1Q tags) are mapped into VPNs VPN1 VPN2 Interface VLAN VPN1 VPN2 Secure Segmentation End-to-End Segmentation
  • 28. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28 Application-Centric Network Capabilities Per-Session Loadsharing Active/Active Per-Session Weighted Active/Active Application Pinning Active/Standby Application Aware Routing SLA Compliant SLASLA Core Hierarchical Multihop Fabric Single-hop Fabric
  • 29. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29  Enforce SLA compliant path for applications of interest  Other applications will follow fabric routing across all paths Control Plane Path1: 10ms, 0% loss, 5ms latency Path2: 200ms, 3% loss, 10ms latency Path3: 140ms, 1% loss, 10ms latency vManage App Aware Routing Policy App A path must have: latency < 150ms loss < 2% jitter < 10ms vEdge1 vEdge2 Internet MPLS 4G LTE vSmart Controllers App A IPSec Tunnel Critical Applications SLA Application Aware Routing Path 2
  • 30. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30 Deep Packet Inspection Engine Primary Use Cases: - Application Visibility - Application Firewall - Traffic Prioritization - Transport Selection - Analytics vEdge Router App 1 App 2 App 3,000 Cloud Data Center Data Center Campus Branch Small Office Home Office MPLS INET 3G/4G Embedded Application Recognition Deep Packet Inspection
  • 31. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31 • Embedded Deep Packet Inspection engine • Application and flow level visibility for the fabric and individual vEdge routers • Centralized statistics and performance • Export flow level data (IPFIX) to external collector Application and Performance Visibility Deep Packet Inspection
  • 32. Cisco Confidential 32© 2016 Cisco and/or its affiliates. All rights reserved. SD-WAN Solution Components Overview
  • 33. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33 Cisco vEdge Routers Portfolio Positioning Branch/SOHO/SMB (100Mb) Branch/Campus (1Gb) Campus/Data Center (10Gb) NFV, vCPE (N x cores) IaaS & Cloud Interconnect (N x cores) Campus/Data Center (20Gb+) vEdge 100 family vEdge 1000 vEdge 2000 vEdge 5000 vEdge Cloud on Greybox or Whitebox vEdge Cloud
  • 34. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34 Data Center Campus Branch Home Office 4G/LTE MPLS Internet Control Plane (Containers or VMs) (vSmart) Management Plane (Multi-tenant or Dedicated) (vManage) Orchestration Plane (vBond) 2000 vEdges per vBond Redundancy Add 1-2 vBonds Horizontal Scale out Model Horizontal Scale Out Model 2700 vEdges per vManage Horizontal Scale out Model in cluster mode (same DC) 2700 vEdges per vSmart Redundancy Add 1-2 vSmarts Horizontal Scale out Model Scalability Considerations Orchestration/Control/Management Plane
  • 35. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35 vEdge100 vEdge1000 vEdge2000 IPSec Tunnels : 250 IPSec Tunnels : 1500 IPSec Tunnels : 6000 Max aggregated throughput: vEdge-100 – 100MB AES-256 full duplex vEdge-1000 - 1GB AES-256 full duplex vEdge-2000 – 10GB AES-256 full duplex Max number of concurrent VPNs: 64 [vpn 0 and vpn 512 included] Overlay tunnels are static based on policy Not dynamically generated on-demand. Scalability Considerations Data Plane and IPsec
  • 36. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 36 Perpetual cost of Cisco SD-WAN CPE hardware Subscription cost of Cisco SD-WAN software (Includes SD-WAN controller + CPE software) Operational cost of Cisco SD-WAN solution 1.Subscription license (1YR, 3YR and 5YR) for Cisco SD-WAN software charged per CPE. This cost is dependent on two factors: • Service bandwidth • Features 2.Perpetual cost of Cisco SD-WAN CPE element. SD-WAN Pricing Model Subscription and Perpetual Elements
  • 37. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 37 Plus Pro Hub Spoke Spoke Spoke MPLS Internet Local breakout Hub Spoke Spoke Spoke MPLS Internet Spoke Spoke Local breakout Dynamic Routing Dynamic Routing Hub Spoke Spoke Spoke MPLS Internet Spoke Spoke Dynamic Routing Dynamic Routing SaaS onRamp SD WAN controllers AnalyticsSD WAN controllers SD WAN controllers AAR AAR AAR E2E Segmentation E2E Segmentation • Routing: Static • Topology: Hub-n-spoke only • Internet/Cloud: NAT, Split tunnel • Policy: Local ACL only, Data policy • QoS • SLA: Application aware routing (5 tuple only) • Visibility : DPI for visibility only • Routing: Dynamic routing (OSPF/BGP) • Topology: Mesh topology • Internet/Cloud: Cloud onRamp for IaaS • Policy: Control policy • Segmentation: 5 VPNs (1+4) • SLA: Application aware routing (DPI) • Multicast • Segmentation: Unlimited • Internet/Cloud: Cloud onRamp for SaaS • Analytics: vAnalytics platform Enterprise License Tier Features License Tiers
  • 38. Cisco Confidential 38© 2016 Cisco and/or its affiliates. All rights reserved. Roadmap
  • 39. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential vManage Cisco SD-WAN Day 1 Deployment Scenarios ISR TI / E! / DSL DeploymentScenarios vEdge ISR Providing Services vManage vEdge Ethernet ISR WaaS UC Thin Branch vManage vEdge Ethernet
  • 40. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Roadmap Phase 2 Platform Integration Phase 1 No Integration Phase 3 Management Integration Platform: • As-is Management: • vManage Platform: • vEdge capabilities integrated into all IOS-XE platforms (ISR, CSR, ENCS, ASR1K) Management: • vManage for SD-WAN capabilities on IOS-XE Management: • Cloud hosted DNA Center integrates vManage capabilities • Full DNA Center capabilities (Assurance, Integrated workflows for SD-Access and SD-WAN) Support current Viptela customers Viptela SD-WAN on strategic ISR platforms Deliver end-to-end experience with full DNA integration DeploymentScenariosBenefitsDetails vEdge ISR4K + vEdge SW DNA Center + SD-WAN ISR4K + vEdge SW vManage vEdge vManage vEdge
  • 41. © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41 Positioning Cisco’s SD-WAN Solutions 1. Do you have a requirement to support end- to-end secure segmentation over the WAN? 2. Do you intend to deploy dynamic per VPN topologies? 3. Do you have different WAN transports with a need to support a single data plane? 4. Do you intend to deploy a network with intelligent path selection for IaaS or SaaS? 1. Do you have existing Meraki infrastructure? 2. Do you have a requirement to manage a full branch network (switches, firewalls) through a single management interface? 3. Do you have a lean IT staff with minimal experience in secure WAN environments? 4. Does your staff desire simple management and automation for deploying branch security?
  • 42. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Cisco is the market and technology leader in SD-WAN, combining the flexibility of Viptela, Meraki, and ISR IOS-XE • Cisco’s SD-WAN solution (Viptela) is both a cloud and on-prem (hardware) based solution, offering unmatched capabilities • Cisco will merge the Viptela and IOS-XE capabilities into a common ISR 4K-based platform and DNA Center, but the complimentary Viptela core products are here to stay in foreseeable future Key Takeaways