WWW.GTRI.COM
Cisco ACI: A New Approach
to Software Defined
Networking
Michael Edwards – Principal Architect GTRI
Gabriel Guillen – TME INSBU Cisco
© 2016 Global Technology Resources, Inc.
All rights reserved.
© 2016 Global Technology Resources, Inc. All Rights Reserved.
2
Agenda
• Cisco ACI Policy Model Review
• ACI Design Models
• ACI Demonstration
Management options
• CLI
• Cut/paste
• Limited automation
• Disparate management platforms
Traditional Networking
© 2016 Global Technology Resources, Inc. All Rights Reserved.
3
Limitations:
• Box by box approach
• Lack of consistent configuration (no
network wide policies)
• Leftover/unknown configuration
• Open “any to any” connectivity
• Lack of traffic visibility
• Separate virtual and physical networks
• Separate L4-7 device management
ACI Networking
© 2016 Global Technology Resources, Inc. All Rights Reserved.
4
Management Options:
• GUI (basic/advanced)
• CLI
• XML/JSON
• Scripting
• Open API
• Automation
Benefits:
• Distributed centralized management
• Full traffic visibility
• Self documenting
• Integrated virtual and physical network
• Integrated L4-7 device management
• Policy defined network
WWW.GTRI.COM
ACI Policy Model
© 2016 Global Technology Resources, Inc.
All rights reserved.
© 2016 Global Technology Resources, Inc. All Rights Reserved.
6
Tenants
© 2016 Global Technology Resources, Inc. All Rights Reserved.
7
VRFs
© 2016 Global Technology Resources, Inc. All Rights Reserved.
8
Bridge Domains
WWW.GTRI.COM
EndPoint Communications
© 2016 Global Technology Resources, Inc.
All rights reserved.
© 2016 Global Technology Resources, Inc. All Rights Reserved.
10
End Point Groups
HTTPS
Service
HTTPS
Service
HTTPS
Service
HTTPS
Service
EPG - Web
EPGs are a grouping of end-points representing application or
application components independent of other network constructs.
POLICY MODEL
HTTPS
Service
HTTPS
Service
HTTPS
Service
HTTPS
Service
© 2016 Global Technology Resources, Inc. All Rights Reserved.
11
Contracts
Application Network Profile
C ContractContracts define what
an EPG exposes to other
app tiers and how
Contracts are reusable for
multiple EPGs and EPGs
can inherit multiple
contracts
The use of contracts separates ‘what’ a policy is from ‘where’ it exists, extending its use.
C
C
EPG NFS
EPG MGMT
EPG DBEPG AppEPG WebC CC
© 2016 Global Technology Resources, Inc. All Rights Reserved.
12
Application Network Profiles
Inbound/
Outbound Policies
Application Network Profile
Application Network profiles are a group of EPGs and the
policies that define the communication between them.
POLICY MODEL
=
Inbound/
Outbound Policies
WWW.GTRI.COM
ACI Design Examples
© 2016 Global Technology Resources, Inc.
All rights reserved.
How?
• 1 BD and 1 EPG per Current Infrastructure VLAN
• Few customers deploy BD in legacy mode (VLAN)
• Tight integration with Orchestration platforms
Who is deploying?
• Customers needing to slowly introduce ACI
• Underlay management for NFV use cases – service
provider
Benefits:
• Network automation and operations
• Workload mobility – any app, anywhere
• Network capacity and bandwidth
• Increased scalability and availability
Network Centric Layer 2 ACI Fabric
© 2016 Global Technology Resources, Inc. All Rights Reserved.
14
How?
• 1 BD and 1 EPG mapping of Current Infrastructure VLAN
• Fabric as default gateway with or without policy
enforcement
Who is deploying?
• Customers requiring secure multi-tenancy
• No re-IP of application workloads
• Network infrastructure refresh, and adopt ACI Fabric
as a single DC switching system
Benefits:
• Network automation and operations
• Workload mobility – any app, anywhere
• Network capacity and bandwidth
• Pervasive gateway, directed ARP and other ACI
innovations
• Increased scalability and availability
Network Centric Layer 3 ACI Fabric
© 2016 Global Technology Resources, Inc. All Rights Reserved.
15
© 2016 Global Technology Resources, Inc. All Rights Reserved.
16
ACI Hybrid Approach
© 2016 Global Technology Resources, Inc. All Rights Reserved.
17
GTRI SDN Solutions
• Virtualization and Advanced Networking Professional Services (PS) practice has
expertise with SDN vendor solutions.
• GTRI has top-tier partner status with the most relevant long-term vendors in the IT
virtualization market.
• SDN readiness assessment service to assess your infrastructure, your applications,
and the benefits to your business gained from using SDN.
• SDN test bed where we can learn and teach SDN solutions and help validate
solutions prior to deployment.
• GTRI is performing SDN deployments and we will freely share the latest vendor and
industry information with you.
© 2016 Global Technology Resources, Inc. All Rights Reserved.
18
FREE SDN Technology Review
• We are offering a FREE 3-hour (~1/2 day) SDN technology
review for your company
• Bring your networking, security, DevOps and other technology
teams together
• Review SDN capabilities within your existing networked
infrastructure
• Discuss SDN architecture and design options
• Review network automation and network programmability potential
WWW.GTRI.COM
© 2016 Global Technology Resources, Inc.
All rights reserved.
877.603.1984
To schedule a SDN Technology
review, contact us at:

Cisco ACI: A New Approach to Software Defined Networking

  • 1.
    WWW.GTRI.COM Cisco ACI: ANew Approach to Software Defined Networking Michael Edwards – Principal Architect GTRI Gabriel Guillen – TME INSBU Cisco © 2016 Global Technology Resources, Inc. All rights reserved.
  • 2.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 2 Agenda • Cisco ACI Policy Model Review • ACI Design Models • ACI Demonstration
  • 3.
    Management options • CLI •Cut/paste • Limited automation • Disparate management platforms Traditional Networking © 2016 Global Technology Resources, Inc. All Rights Reserved. 3 Limitations: • Box by box approach • Lack of consistent configuration (no network wide policies) • Leftover/unknown configuration • Open “any to any” connectivity • Lack of traffic visibility • Separate virtual and physical networks • Separate L4-7 device management
  • 4.
    ACI Networking © 2016Global Technology Resources, Inc. All Rights Reserved. 4 Management Options: • GUI (basic/advanced) • CLI • XML/JSON • Scripting • Open API • Automation Benefits: • Distributed centralized management • Full traffic visibility • Self documenting • Integrated virtual and physical network • Integrated L4-7 device management • Policy defined network
  • 5.
    WWW.GTRI.COM ACI Policy Model ©2016 Global Technology Resources, Inc. All rights reserved.
  • 6.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 6 Tenants
  • 7.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 7 VRFs
  • 8.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 8 Bridge Domains
  • 9.
    WWW.GTRI.COM EndPoint Communications © 2016Global Technology Resources, Inc. All rights reserved.
  • 10.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 10 End Point Groups HTTPS Service HTTPS Service HTTPS Service HTTPS Service EPG - Web EPGs are a grouping of end-points representing application or application components independent of other network constructs. POLICY MODEL HTTPS Service HTTPS Service HTTPS Service HTTPS Service
  • 11.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 11 Contracts Application Network Profile C ContractContracts define what an EPG exposes to other app tiers and how Contracts are reusable for multiple EPGs and EPGs can inherit multiple contracts The use of contracts separates ‘what’ a policy is from ‘where’ it exists, extending its use. C C EPG NFS EPG MGMT EPG DBEPG AppEPG WebC CC
  • 12.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 12 Application Network Profiles Inbound/ Outbound Policies Application Network Profile Application Network profiles are a group of EPGs and the policies that define the communication between them. POLICY MODEL = Inbound/ Outbound Policies
  • 13.
    WWW.GTRI.COM ACI Design Examples ©2016 Global Technology Resources, Inc. All rights reserved.
  • 14.
    How? • 1 BDand 1 EPG per Current Infrastructure VLAN • Few customers deploy BD in legacy mode (VLAN) • Tight integration with Orchestration platforms Who is deploying? • Customers needing to slowly introduce ACI • Underlay management for NFV use cases – service provider Benefits: • Network automation and operations • Workload mobility – any app, anywhere • Network capacity and bandwidth • Increased scalability and availability Network Centric Layer 2 ACI Fabric © 2016 Global Technology Resources, Inc. All Rights Reserved. 14
  • 15.
    How? • 1 BDand 1 EPG mapping of Current Infrastructure VLAN • Fabric as default gateway with or without policy enforcement Who is deploying? • Customers requiring secure multi-tenancy • No re-IP of application workloads • Network infrastructure refresh, and adopt ACI Fabric as a single DC switching system Benefits: • Network automation and operations • Workload mobility – any app, anywhere • Network capacity and bandwidth • Pervasive gateway, directed ARP and other ACI innovations • Increased scalability and availability Network Centric Layer 3 ACI Fabric © 2016 Global Technology Resources, Inc. All Rights Reserved. 15
  • 16.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 16 ACI Hybrid Approach
  • 17.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 17 GTRI SDN Solutions • Virtualization and Advanced Networking Professional Services (PS) practice has expertise with SDN vendor solutions. • GTRI has top-tier partner status with the most relevant long-term vendors in the IT virtualization market. • SDN readiness assessment service to assess your infrastructure, your applications, and the benefits to your business gained from using SDN. • SDN test bed where we can learn and teach SDN solutions and help validate solutions prior to deployment. • GTRI is performing SDN deployments and we will freely share the latest vendor and industry information with you.
  • 18.
    © 2016 GlobalTechnology Resources, Inc. All Rights Reserved. 18 FREE SDN Technology Review • We are offering a FREE 3-hour (~1/2 day) SDN technology review for your company • Bring your networking, security, DevOps and other technology teams together • Review SDN capabilities within your existing networked infrastructure • Discuss SDN architecture and design options • Review network automation and network programmability potential
  • 19.
    WWW.GTRI.COM © 2016 GlobalTechnology Resources, Inc. All rights reserved. 877.603.1984 To schedule a SDN Technology review, contact us at: