SlideShare a Scribd company logo
SDN in the Enterprise: APIC Enterprise Module
T-ENM-01-I
Lila Rousseaux, Consulting Systems Engineer, Enterprise Networks, Cisco Systems Canada
Tim Szigeti, Technical Marketing Engineer, Enterprise Architecture Team, Cisco Systems
Housekeeping Notes
Thank you for attending Cisco Connect Toronto 2015, here are a few
housekeeping notes to ensure we all enjoy the session today.
§  Please ensure your cellphones / Laptops are set on silent to ensure
no one is disturbed during the session
§  Ask questions !!
House Keeping Notes
§  What problem are we trying to solve?
§  APIC-EM Architecture
§  APIC-EM Apps a.k.a how can the controller help simplify my
environment?
§  What about Prime?
§  Wrap-Up
AGENDA
What problem are we trying to
solve?
“A platform for
developing new control planes”
“An open solution for VM mobility in
the Data-Center”
“An open solution for customized flow
forwarding control in the Data-Center”
“A means to do traffic engineering without
MPLS”
“A way to scale my firewalls
and loadbalancers”
“A solution to build a very large scale layer-2
network”
“A way to build my own security/encryption solution,
avoiding RSA”
“A way to reduce the
CAPEX of my network
and leverage commodity
switches”
“A way to define virtual networks with specific
topologies for my multi-tenant Data-Center”
“A means to scale my fixed/mobile gateways and
optimize their placement”
“A solution to build virtual topologies with
optimum multicast forwarding behavior”
“A way to optimize link utilization in my network, through
new multi-path algorithms”
“A way to avoid lock-in to a
single networking vendor”
“A way to distribute policy/intent, e.g. for DDoS
prevention, in the network”
“A way to configure my entire network as
a whole rather than individual devices”
“A solution to get a global view of the
network – topology and state”
“With SDN I can develop solutions to my problems far faster –
“at software speeds”. I don’t have to work with my network
vendor or go through length standardization”
SDN – Still Don’t kNow – Stanford Defined Networking
Many things to Many people
Resiliency/Scale has been proven
Distributed Networking has worked
Distributed Networking has worked
?
Distributed Networking adds complexity to manage/comprehend
!
!
!
However
But uses controller
to mask complexity
NETWORK
Admin still makes network behavior decisions
Abstracting Conventional Policy Complexity
Conventional Model
The What
“Security Policy for
Branch A”
The How
“Change ACLs in
the Following
Elements”
The What
“Security Policy for
Branch A”
The How
“Change ACLs in
the Following
Elements”
ACI Constructs
Admin
Driven
Admin Driven
Northbound APIs
APIC EM
Policy Based Model
What is Policy?
WHAT HOW
Policy à way to simplify how we do things via abstraction
Changing Nature of IT Ops with SDN led
Management
Management
(NMS)
NE NE NE NE
Customer developed
provisioning tools, manual CLI
changes, and run book
automation for IT Operations
support
Controller
(APIC-EM)
Management
(Provisioning and Assurance)
Automation
(Workflow / Orchestration)
NE NE NE NE
Customer input on business /
service intent
Traditional Management SDN Led Management
Changing Nature of IT Ops with SDN
led Management
Traditional Management
Feature
Configuration
SDN Led Management
Policy
Automation
Policy Maturity to Cover Enterprise System of Change
Use Cases will Evolve Over Time
policy
traditional
configuration
traditional
policy policy
Controller-based
Automation
Today
traditional
Policy based
Configuration à
•  Dynamic
•  Able to be
automated
•  Managed by
the controller
Policy grows,
static shrinks
Time
APIC-EM Architecture
Cisco APIC Enterprise Module Architecture
Abstracts Network Devices to Mask Complexity
Treat Network as a System
Exposes Network Intelligence
For Business Innovation
Cisco APIC Enterprise Module
Cisco and Third Party Applications
Network Devices
Catalyst, ASR, ISR
Network Info
Database
Policy
Infrastructure
Automation
REST API
Southbound Interface: CLI
Security QoS IWAN Network PnP
Masking Network Complexity, Exposing Network Intelligence
.
Cisco APIC Enterprise Module Architecture
Cisco APIC Enterprise Module
Cisco and Third Party Applications
Network Devices
Catalyst, ASR, ISR
Network Info
Database
Policy
Infrastructure
Automation
REST API
Southbound Interface: CLI
Security QoS IWAN Network PnP
Masking Network Complexity, Exposing Network Intelligence
.
1.  Cisco Visualization Application a.k.a UI
2.  Cisco Applications for specific solutions
IWAN, Network PnP, Collaboration,
Security, etc
3.  DevNet
4.  Customer developed
SDN Innovation: Network Information Base
Provides One Source of Truth
Cisco APIC Enterprise Module
Cisco and Third Party Applications
Network Devices
Catalyst, ASR, ISR
Network Info
Database
Policy
Infrastructure
Automation
REST API
Southbound Interface: CLI
Security QoS IWAN Network PnP
Masking Network Complexity, Exposing Network Intelligence
.
Cisco APIC Enterprise Module Architecture
Cisco APIC Enterprise Module
Cisco and Third Party Applications
Network Devices
Catalyst, ASR, ISR
Network Info
Database
Policy
Infrastructure
Automation
REST API
Southbound Interface: CLI
Security QoS IWAN Network PnP
Masking Network Complexity, Exposing Network Intelligence
.
1.  Network programmer service: used for
programming the network
2.  Services within the controller leverage
network programmer to talk to the network
3.  Depending on the type of platform and
functionality the network programmer
chooses the southbound protocol
4.  Services within the controller unaware of
these protocols
5.  If new protocols are required, we only
need to add the plug-in for that protocol in
the network programmer
APIC-EM Apps a.k.a how can
the controller help simplify my
environment?
First we need to check the APIC-EM User Interface
APIC-EM User Interface App: Device Inventory
Network Information Base - Host Inventory
APIC-EM User Interface App: Discovery
APIC-EM User Interface App: Topology
Use Case: Path Visualization
•  No efficient method to troubleshoot IP voice and video sessions traversing the network
on demand
•  Lack of network visibility creates large OPEX to diagnose and find problem sources
•  Path computation service provides a fast and accurate method for rapidly identifying/
isolating paths causing problems
•  Low risk use case for SDN
Path Trace Visualizer
5-tuple
Path Trace Visualizer
Wireless to Wired
Path Trace Visualizer
ECMP
Policy Analysis
Policy Analysis
Boxes greyed out once
traffic is blocked for easy
visualization
Policy Analysis
CAMPUS
Security Policy App (within User Interface)
Per User Per Application Access Policy Enforcement
SiSiSiSi
APIC-EM
Controller
Block
Bit-Torrent
BRANCH
Authentication
ISE
Block
Bit-Torrent
AD/Radius
Server§  Admin configures business policy to block
application traffic on a per user/
user_group basis.
§  Controller uses identity information to
install user specific access policy at the
edge.
User moves to a branch site. Policy moves with it
APIC-EM Policy App
APIC-EM Policy
Under the hood
Branch
SourceFire
Defence Center
SDN Controller
ISR
Sensor
X
Sensor
1.  BYOD Malware/Javascript
Attack
2.  SF Sensor detects threat
3.  SF DC notifies Controller
4.  Remediation API event
5.  Policy installed on Access
switch port by Controller.
6.  Block or quarantine end-point
WAN
ISR
Internet
HQ
Malware Attack
Defense Center
Alert!!!!
Controller
Notification
Remediation Policy
Enforcement
Host Quarantined
How to use Policy Programming for Network
Threat Defense - Policy Programming outside the UI
How to use Policy Programming for Network
Threat Defense - Policy Programming outside the UI
Branch
SourceFire
Defence Center
SDN Controller
ISR
Sensor
X
Sensor
WAN
ISR
Internet
HQ
Controller
Notification
Host Quarantined
Defense Center
/api/v0/policy POST!
{"actions": ["DENY"],
"policyOwner":"admin”,
"policyName": "deny_all”,
"networkUser":
{"userIdentifiers”:
["10.10.20.7"]}}!
SDN QoS Direction
EasyQoS App
No more Box-by-Box configuration
Config.
Cisco Validated
Design- Based Templates
Control
Transactio
nalData
RealtimeBestEffort
Cisco Validated
Design {CVD}
Cisco
APIC -
Enterprise
Module
Easy QoS App
Cisco Validated Design (CVD) classification and marking
Easy QoS
Easy customization of policies
APIC-EM with CUCM Integration—Step 1a
EM
The administrator enters strategic business Intent to APIC-EM
APIC-EM deploys:
a)  static (ingress) ACL-based classification & DSCP-marking policies
(on access edge interfaces only)
with null ACL entries for VOICE and VIDEO
ip access-list extended VOICE
ip access-list extended VIDEO
ip access-list extended BULK-DATA
permit tcp any any eq ftp
permit tcp any any eq ftp-data
…
class-map match-all VOICE
match access-group name VOICE
class-map match-all VIDEO
match access-group name VIDEO
class-map match-all BULK-DATA
match access-group name BULK-DATA
…
policy-map APIC-EM-INGRESS-MARKING
class VOICE
set dscp ef
class VIDEO
set dscp af41
class BULK-DATA
set dscp af11 …
APIC-EM with CUCM Integration—Part 1b
EM
Once the administrator has entered strategic business Intent to APIC-EM
APIC-EM deploys:
a)  static (ingress) ACL-based classification & DSCP marking policies
b)  static (ingress and egress) DSCP-based queuing policies on all switches
class-map match-all VOICE-PQ1
match dscp ef
class-map match-all VIDEO-PQ2
match dscp af41
class-map match-any BULK-DATA-QUEUE
match dscp af11 af12 af13
…
policy-map APIC-EM-2P6Q3T
class VOICE-PQ1
priority level 1
class VIDEO-PQ2
priority level 2
class BULK-DATA-QUEUE
bandwidth remaining percent 5
queue-buffers ratio 10
queue-limit dscp values af13 percent 80
queue-limit dscp values af12 percent 90
queue-limit dscp values af11 percent 100 …
APIC-EM with CUCM Integration—Part 2
EM
CUCM signals APIC-EM of a proceeding call
APIC-EM deploys a dynamic ACL update for voice and/or video
to all ports on the switch (or switch module)
ip access-list extended VOICE
match udp host 10.1.1.1 eq 18578 host 10.2.2.2 eq 17333
ip access-list extended VIDEO
match udp host 10.1.1.1 eq 31199 host 10.2.2.2 eq 24141
ip access-list extended VOICE
match udp host 10.2.2.2 eq 17333 host 10.1.1.1 eq 18578
ip access-list extended VIDEO
match udp host 10.2.2.2 eq 24141 host 10.1.1.1 eq 31199
APIC-EM with CUCM Integration—Part 3
EM
CUCM signals APIC-EM of a terminating call
APIC-EM removes the dynamic ACL update for voice and/or video
ip access-list extended VOICE
no match udp host 10.1.1.1 eq 18578 host 10.2.2.2 eq 17333
ip access-list extended VIDEO
no match udp host 10.1.1.1 eq 31199 host 10.2.2.2 eq 24141
ip access-list extended VOICE
no match udp host 10.2.2.2 eq 17333 host 10.1.1.1 eq 18578
ip access-list extended VIDEO
no match udp host 10.2.2.2 eq 24141 host 10.1.1.1 eq 31199
Intelligent WAN
Intelligent WAN
WAN Transport
Branch
MPLS
$$$
Low Cost Circuit,
Internet, 4G
$
Private
Cloud Virtual
Private
Cloud
Direct
Internet
Access
Internet
backhaul
Cisco
Cloud
Web Security
Public
Cloud
ü  Secure WAN transport across MPLS
and/or Internet for private cloud / DC
access
Increase WAN Capacity Improve App Performance Scale Security at the Branch
ü  Leverage Low Cost path for public cloud
and Internet access
Cisco
APIC -
Enterprise
Module
APIC-EM IWAN App
Dashboard
© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential –Use under NDA – DO NOT DISTRIBUTE
wolfgang@cisco.com
wolfgang@cisco.com
APIC EM Apps will innovate on design simplicity and intuitiveness
APIC-EM IWAN App
Site provisioning
APIC-EM IWAN App
Site provisioning
APIC-EM IWAN App
Site provisioning
IWAN App – Site provisioning
IWAN App – Site provisioning
IWAN App – Site provisioning
APIC-EM IWAN App
Application Policy
•  Applications detected in the network when enabling AVC
•  Classify applications in different categories
•  Organize application in categories to create business
policies based on these categories
APIC-EM IWAN App
Application Policy
APIC-EM IWAN App
Application Policy
APIC-EM IWAN App
Application Policy
•  Business logic à we tell the controller what
applications are relevant for the business
•  The controller is going to perform background tasks
based on this business logic
APIC-EM IWAN App
Application Policy
•  Define primary path for group of applications
•  The controller will create a PfR policy based on
those paths.
APIC-EM IWAN App
Application Policy
Network Plug & Play
(a.k.a. Zero Touch Deployment)
Network Plug-n-Play – for Zero Touch Deployment
Unskilled
Installer
GUI Based
Consistent for devices &
PIN(Campus/Branch)
Secure
Zero-touch
RMA
Greenfield
& Brownfield
Central Staging Facility
Site-1
•  Install OS
•  Install base
config
Network
Admin
Installer
Site-3
Today’s Process
Site-2 Site(s)
Network PnP
Pre Provision
Projects/Sites
Network Admin
1
Install & Power-on
devices
2
Installer
Monitor device
installation
3
Network Admin
Reseller/
Partner
Ships
equipment Cisco
APIC -
Enterprise
Module
PnP Server
Use Case: Device Deployment in Campus
DHCP Server
Pre Provision Projects/
Sites
•  Policies
•  Match Rules
•  Configs/Image
•  IP Addressing
Network Admin
Day 0
Cisco
APIC -
Enterprise
Module
Pre-provision DHCP
Server
•  IP address
•  option 43
PnP Server
Use Case: Device Deployment in Campus
DHCP Server
Switch running
PnP Agent
Device	
  receives	
  PnP	
  server	
  
specific	
  metadata	
  info	
  
configured	
  in	
  DHCP	
  op7on	
  43	
  
Device	
  validates	
  server’s	
  loca7on	
  and	
  
establishes	
  a	
  communica7on	
  with	
  the	
  server	
  
Installer
Remote Installer
•  Mount and cable
devices
•  Power-on
Day 1
Network Admin remotely
monitors status of install
while in progress.
Day 1
Cisco
APIC -
Enterprise
Module
APIC-EM ZTD App – Configure Site, Device, Config
•  Campus
Workflow
•  Serial #
and PID-
based
device
matching
•  Operational
config and
IOS image
for each
device
Network Admin
Day 0
The End stage
Network Admin remotely
monitors status of install while
in progress.
Day 1
APIC-EM Apps a.k.a how can the controller help
simplify my environment?
•  Path Visualization
•  Path Visualization + Integration with Cisco Prime
Collaboration Manager
•  ACL Trace
•  ACL Analysis
•  Security Policy Programming (Per User/Group)
•  Policy Programming for Network Threat Defense
•  Easy QoS via User Interface
•  Dynamic Policy for video soft clients
•  IWAN App
•  Network Plug and Play Server
Applications
Released in
phases
Just a few
examples,
there’s much
more
What about Prime?
Changing Nature of IT Ops with SDN
led Management
Traditional Management
Feature
Configuration
SDN Led Management
Policy
Automation
System of record vs. system of change
Prime Infrastructure APIC - EM
System of Record System of Change
•  Policy definition
•  Historical reporting on
events & performance
•  Configuration archive
•  Troubleshooting workflows
•  Capacity Trending
•  Predictive Analytics
•  Policy enforcement
•  Discovery (for change)
•  Topology (for change)
•  PnP
•  Network state monitoring
•  Device abstraction
•  Network Control
Cisco Prime and APIC-EM
Control
Layer
Device
Layer
Operational Automation
Policy and Service Definition
Automated Assurance Provisioning
Visualization, Trending and
Analytics
Network Intelligence
Device Layer Abstraction
Network Control
Policy Enforcement & Network
Change
Management
&
Orchestration
Layer
Cisco Devices
Enterprise Networks, Data Center
Cisco APIC
Common ACI Architecture
APIC for datacenter APIC Enterprise Module
CLI, OpenFlow, OnePK API
REST API (ONE DevKit)
Catalog /
Provisioning
Fault /
Events
User / Data
Management
Performanc
e Monitoring
Reporting /
Analytics
Cisco IAC
UCSD
APIC-EM
App (IWAN)
PRIME INFRASTRUCTURE
& NAM
Wrap-Up
Summary
§  Changing Nature of IT Ops with SDN led Management
§  APIC-EM and Apps are a System of Change that will drive real time changes in the
network
§  Prime Infrastructure role will evolve into end-to-end assurance as System of Record,
while also catering to feature configuration for custom environments
§  The network administrator can now focus on Policy and Business Intent
(WHAT)
§  Controllers job to translate into network semantics/implementation (HOW)
§  API to expose the networks capabilities
§  APIC EM abstracts the underlying complexity of the network infrastructure
Give us your feedback and you could win a Plantronics
headset. Complete the session survey on your Cisco
Connect Toronto Mobile app at the end of your session
for a chance to win
Winners will be announced and posted at the
Information desk and on Twitter at the end of the day
(You must be present to win!)
Complete your session evaluation – May 14th
Thank You …

More Related Content

What's hot

DEVNET-1126 APIC-EM API
DEVNET-1126	APIC-EM APIDEVNET-1126	APIC-EM API
DEVNET-1126 APIC-EM API
Cisco DevNet
 
Ottawa e-NFV Session
Ottawa e-NFV Session Ottawa e-NFV Session
Ottawa e-NFV Session
Cisco Canada
 
API Deep Dive: APIC EM Rest API
API Deep Dive: APIC EM Rest API API Deep Dive: APIC EM Rest API
API Deep Dive: APIC EM Rest API
Cisco DevNet
 
SDN in the Enterprise
SDN in the EnterpriseSDN in the Enterprise
SDN in the Enterprise
Cisco Canada
 
DNA: an overview
DNA: an overviewDNA: an overview
DNA: an overview
Cisco DevNet
 
Cisco DNA
Cisco DNACisco DNA
Cisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud PlatformCisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud Platform
Shashi Kiran
 
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network IntuitiveCisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Canada
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Cisco Canada
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscaler
Zscaler
 
UCS Update: Efficiently Managing your server environment for traditional ente...
UCS Update: Efficiently Managing your server environment for traditional ente...UCS Update: Efficiently Managing your server environment for traditional ente...
UCS Update: Efficiently Managing your server environment for traditional ente...
Cisco Canada
 
Digital Transformation - Cisco's Journey
Digital Transformation - Cisco's JourneyDigital Transformation - Cisco's Journey
Digital Transformation - Cisco's Journey
Cisco Canada
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Cisco Russia
 
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
Cisco Connect Ottawa 2018  Cisco digital buildings and the 4th utility   w co...Cisco Connect Ottawa 2018  Cisco digital buildings and the 4th utility   w co...
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
Cisco Canada
 
Agile Network Agile Management
Agile Network Agile ManagementAgile Network Agile Management
Agile Network Agile Management
Huawei Enterprise Hong Kong
 
Simplifying the secure data center
Simplifying the secure data centerSimplifying the secure data center
Simplifying the secure data center
Cisco Canada
 
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Halifax 2018   Cisco dna - deeper diveCisco Connect Halifax 2018   Cisco dna - deeper dive
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Canada
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
Cisco Canada
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
Robb Boyd
 
Cisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attackCisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Canada
 

What's hot (20)

DEVNET-1126 APIC-EM API
DEVNET-1126	APIC-EM APIDEVNET-1126	APIC-EM API
DEVNET-1126 APIC-EM API
 
Ottawa e-NFV Session
Ottawa e-NFV Session Ottawa e-NFV Session
Ottawa e-NFV Session
 
API Deep Dive: APIC EM Rest API
API Deep Dive: APIC EM Rest API API Deep Dive: APIC EM Rest API
API Deep Dive: APIC EM Rest API
 
SDN in the Enterprise
SDN in the EnterpriseSDN in the Enterprise
SDN in the Enterprise
 
DNA: an overview
DNA: an overviewDNA: an overview
DNA: an overview
 
Cisco DNA
Cisco DNACisco DNA
Cisco DNA
 
Cisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud PlatformCisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud Platform
 
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network IntuitiveCisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Digital Network Architecture - Introducing the Network Intuitive
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscaler
 
UCS Update: Efficiently Managing your server environment for traditional ente...
UCS Update: Efficiently Managing your server environment for traditional ente...UCS Update: Efficiently Managing your server environment for traditional ente...
UCS Update: Efficiently Managing your server environment for traditional ente...
 
Digital Transformation - Cisco's Journey
Digital Transformation - Cisco's JourneyDigital Transformation - Cisco's Journey
Digital Transformation - Cisco's Journey
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
Cisco Connect Ottawa 2018  Cisco digital buildings and the 4th utility   w co...Cisco Connect Ottawa 2018  Cisco digital buildings and the 4th utility   w co...
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
 
Agile Network Agile Management
Agile Network Agile ManagementAgile Network Agile Management
Agile Network Agile Management
 
Simplifying the secure data center
Simplifying the secure data centerSimplifying the secure data center
Simplifying the secure data center
 
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Halifax 2018   Cisco dna - deeper diveCisco Connect Halifax 2018   Cisco dna - deeper dive
Cisco Connect Halifax 2018 Cisco dna - deeper dive
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
 
Cisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attackCisco Connect Toronto 2017 - Anatomy-of-attack
Cisco Connect Toronto 2017 - Anatomy-of-attack
 

Viewers also liked

Think Global, Work Digital. Cisco Industry 4.0
Think Global, Work Digital. Cisco Industry 4.0Think Global, Work Digital. Cisco Industry 4.0
Think Global, Work Digital. Cisco Industry 4.0
Matteo Masi
 
Cisco open network environment
Cisco open network environmentCisco open network environment
Cisco open network environment
deepers
 
Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres
Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres
Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres
Martin Lipka
 
TechWiseTV Workshop: Cisco Stealthwatch and ISE
TechWiseTV Workshop: Cisco Stealthwatch and ISETechWiseTV Workshop: Cisco Stealthwatch and ISE
TechWiseTV Workshop: Cisco Stealthwatch and ISE
Robb Boyd
 
Manufacturing the future: Industry 4.0
Manufacturing the future: Industry 4.0Manufacturing the future: Industry 4.0
Manufacturing the future: Industry 4.0
Martina F. Ferracane
 
Simplify WAN Deployment with the Cisco IWAN Application
Simplify WAN Deployment with the Cisco IWAN ApplicationSimplify WAN Deployment with the Cisco IWAN Application
Simplify WAN Deployment with the Cisco IWAN Application
Cisco Enterprise Networks
 
Building The Right Network
Building The Right NetworkBuilding The Right Network
Building The Right Network
Cisco Canada
 
API イントロダクション APIC-EM, Prime Infrastructure & CMX
API イントロダクション APIC-EM, Prime Infrastructure & CMXAPI イントロダクション APIC-EM, Prime Infrastructure & CMX
API イントロダクション APIC-EM, Prime Infrastructure & CMX
npsg
 
SDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergiesSDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergies
Hector.Avalos
 
Cisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation BranchCisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Canada
 
Cisco, Sourcefire and Lancope - Better Together
Cisco, Sourcefire and Lancope - Better TogetherCisco, Sourcefire and Lancope - Better Together
Cisco, Sourcefire and Lancope - Better Together
Lancope, Inc.
 
Preparing Your Network for 802.11ac Wave 2
Preparing Your Network for 802.11ac Wave 2Preparing Your Network for 802.11ac Wave 2
Preparing Your Network for 802.11ac Wave 2
Cisco Enterprise Networks
 
TechWiseTV Workshop: Cisco ONE
TechWiseTV Workshop: Cisco ONETechWiseTV Workshop: Cisco ONE
TechWiseTV Workshop: Cisco ONE
Robb Boyd
 
Case Study (Presentation): How Cisco Spark is used at ZOOM International
Case Study (Presentation): How Cisco Spark is used at ZOOM InternationalCase Study (Presentation): How Cisco Spark is used at ZOOM International
Case Study (Presentation): How Cisco Spark is used at ZOOM International
ZOOM International
 
A sdn based application aware and network provisioning
A sdn based application aware and network provisioningA sdn based application aware and network provisioning
A sdn based application aware and network provisioning
Stanley Wang
 
Unlock Digital Banking with SAP Bank Analyzer & S4
Unlock Digital Banking with SAP Bank Analyzer & S4Unlock Digital Banking with SAP Bank Analyzer & S4
Unlock Digital Banking with SAP Bank Analyzer & S4
Guillermo Salazar
 
Building a Security Architecture
Building a Security ArchitectureBuilding a Security Architecture
Building a Security Architecture
Cisco Canada
 

Viewers also liked (17)

Think Global, Work Digital. Cisco Industry 4.0
Think Global, Work Digital. Cisco Industry 4.0Think Global, Work Digital. Cisco Industry 4.0
Think Global, Work Digital. Cisco Industry 4.0
 
Cisco open network environment
Cisco open network environmentCisco open network environment
Cisco open network environment
 
Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres
Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres
Top 5 favourite features of Cisco ACI in Pulsant Cloud Data Centres
 
TechWiseTV Workshop: Cisco Stealthwatch and ISE
TechWiseTV Workshop: Cisco Stealthwatch and ISETechWiseTV Workshop: Cisco Stealthwatch and ISE
TechWiseTV Workshop: Cisco Stealthwatch and ISE
 
Manufacturing the future: Industry 4.0
Manufacturing the future: Industry 4.0Manufacturing the future: Industry 4.0
Manufacturing the future: Industry 4.0
 
Simplify WAN Deployment with the Cisco IWAN Application
Simplify WAN Deployment with the Cisco IWAN ApplicationSimplify WAN Deployment with the Cisco IWAN Application
Simplify WAN Deployment with the Cisco IWAN Application
 
Building The Right Network
Building The Right NetworkBuilding The Right Network
Building The Right Network
 
API イントロダクション APIC-EM, Prime Infrastructure & CMX
API イントロダクション APIC-EM, Prime Infrastructure & CMXAPI イントロダクション APIC-EM, Prime Infrastructure & CMX
API イントロダクション APIC-EM, Prime Infrastructure & CMX
 
SDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergiesSDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergies
 
Cisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation BranchCisco Intelligent WAN: Enabling the Next-Generation Branch
Cisco Intelligent WAN: Enabling the Next-Generation Branch
 
Cisco, Sourcefire and Lancope - Better Together
Cisco, Sourcefire and Lancope - Better TogetherCisco, Sourcefire and Lancope - Better Together
Cisco, Sourcefire and Lancope - Better Together
 
Preparing Your Network for 802.11ac Wave 2
Preparing Your Network for 802.11ac Wave 2Preparing Your Network for 802.11ac Wave 2
Preparing Your Network for 802.11ac Wave 2
 
TechWiseTV Workshop: Cisco ONE
TechWiseTV Workshop: Cisco ONETechWiseTV Workshop: Cisco ONE
TechWiseTV Workshop: Cisco ONE
 
Case Study (Presentation): How Cisco Spark is used at ZOOM International
Case Study (Presentation): How Cisco Spark is used at ZOOM InternationalCase Study (Presentation): How Cisco Spark is used at ZOOM International
Case Study (Presentation): How Cisco Spark is used at ZOOM International
 
A sdn based application aware and network provisioning
A sdn based application aware and network provisioningA sdn based application aware and network provisioning
A sdn based application aware and network provisioning
 
Unlock Digital Banking with SAP Bank Analyzer & S4
Unlock Digital Banking with SAP Bank Analyzer & S4Unlock Digital Banking with SAP Bank Analyzer & S4
Unlock Digital Banking with SAP Bank Analyzer & S4
 
Building a Security Architecture
Building a Security ArchitectureBuilding a Security Architecture
Building a Security Architecture
 

Similar to SDN in the Enterprise: APIC Enterprise Module

Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
NetworkCollaborators
 
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
Nur Shiqim Chok
 
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
Nur Shiqim Chok
 
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
NetworkCollaborators
 
The History and Evolution of SDN
The History and Evolution of SDNThe History and Evolution of SDN
The History and Evolution of SDN
Napier University
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined Access
NetworkCollaborators
 
Cisco APIC-EM – реализация концепции SDN в корпоративных сетях
Cisco APIC-EM – реализация концепции SDN в корпоративных сетяхCisco APIC-EM – реализация концепции SDN в корпоративных сетях
Cisco APIC-EM – реализация концепции SDN в корпоративных сетях
Cisco Russia
 
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network IntuitiveCisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Canada
 
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Cisco Russia
 
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
NetworkCollaborators
 
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
Nur Shiqim Chok
 
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
NetworkCollaborators
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
NetworkCollaborators
 
Extending Cisco Technologies Thru Solar Winds Network Management
Extending Cisco Technologies Thru Solar Winds Network ManagementExtending Cisco Technologies Thru Solar Winds Network Management
Extending Cisco Technologies Thru Solar Winds Network Management
jkstephens
 
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
NetworkCollaborators
 
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
SDNRG ITB
 
Application Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centreApplication Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centre
Cisco Canada
 
Microservices and containers networking: Contiv, an industry leading open sou...
Microservices and containers networking: Contiv, an industry leading open sou...Microservices and containers networking: Contiv, an industry leading open sou...
Microservices and containers networking: Contiv, an industry leading open sou...
Codemotion
 
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Aruba, a Hewlett Packard Enterprise company
 
Embracing SDN in the Next Gen Network
Embracing SDN in the Next Gen NetworkEmbracing SDN in the Next Gen Network
Embracing SDN in the Next Gen Network
NetCraftsmen
 

Similar to SDN in the Enterprise: APIC Enterprise Module (20)

Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
 
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...[Cisco Connect 2018 - Vietnam] 2. lam doan   software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
 
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...[Cisco Connect 2018 - Vietnam] Lam doan   software-defined access-a transform...
[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transform...
 
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
Cisco Connect 2018 Vietnam - Software-defined access-a transformational appro...
 
The History and Evolution of SDN
The History and Evolution of SDNThe History and Evolution of SDN
The History and Evolution of SDN
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined Access
 
Cisco APIC-EM – реализация концепции SDN в корпоративных сетях
Cisco APIC-EM – реализация концепции SDN в корпоративных сетяхCisco APIC-EM – реализация концепции SDN в корпоративных сетях
Cisco APIC-EM – реализация концепции SDN в корпоративных сетях
 
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network IntuitiveCisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
 
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
 
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
 
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
 
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 
Extending Cisco Technologies Thru Solar Winds Network Management
Extending Cisco Technologies Thru Solar Winds Network ManagementExtending Cisco Technologies Thru Solar Winds Network Management
Extending Cisco Technologies Thru Solar Winds Network Management
 
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
Cisco Connect 2018 Thailand - Enabling the next gen data center transformatio...
 
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
Cisco SDN/NVF Innovations (SDN NVF Day ITB 2016)
 
Application Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centreApplication Centric Infrastructure (ACI), the policy driven data centre
Application Centric Infrastructure (ACI), the policy driven data centre
 
Microservices and containers networking: Contiv, an industry leading open sou...
Microservices and containers networking: Contiv, an industry leading open sou...Microservices and containers networking: Contiv, an industry leading open sou...
Microservices and containers networking: Contiv, an industry leading open sou...
 
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
 
Embracing SDN in the Next Gen Network
Embracing SDN in the Next Gen NetworkEmbracing SDN in the Next Gen Network
Embracing SDN in the Next Gen Network
 

More from Cisco Canada

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
Cisco Canada
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
Cisco Canada
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco Canada
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
Cisco Canada
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco Canada
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco Canada
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Canada
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco Canada
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
Cisco Canada
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
Cisco Canada
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco Canada
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco Canada
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Canada
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Canada
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Canada
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet Overview
Cisco Canada
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
Cisco Canada
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
Cisco Canada
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Canada
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
Cisco Canada
 

More from Cisco Canada (20)

Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
 
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
 
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
 
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
 
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
 
Cisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybridesCisco connect montreal 2018 collaboration les services webex hybrides
Cisco connect montreal 2018 collaboration les services webex hybrides
 
Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
 
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
 
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
 
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet Overview
 
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
 
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
 
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 

Recently uploaded

Nordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptxNordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptx
MichaelKnudsen27
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
DianaGray10
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
DianaGray10
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
DanBrown980551
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
Brandon Minnick, MBA
 
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
saastr
 
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their MainframeDigital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Precisely
 
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge GraphGraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
Neo4j
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Tosin Akinosho
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
Antonios Katsarakis
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Pitangent Analytics & Technology Solutions Pvt. Ltd
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
Chart Kalyan
 
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
Edge AI and Vision Alliance
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
Safe Software
 
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
Fwdays
 
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and BioinformaticiansBiomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Neo4j
 

Recently uploaded (20)

Nordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptxNordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptx
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
 
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
 
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their MainframeDigital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
 
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge GraphGraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
 
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
 
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
 
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and BioinformaticiansBiomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
 

SDN in the Enterprise: APIC Enterprise Module

  • 1. SDN in the Enterprise: APIC Enterprise Module T-ENM-01-I Lila Rousseaux, Consulting Systems Engineer, Enterprise Networks, Cisco Systems Canada Tim Szigeti, Technical Marketing Engineer, Enterprise Architecture Team, Cisco Systems
  • 3. Thank you for attending Cisco Connect Toronto 2015, here are a few housekeeping notes to ensure we all enjoy the session today. §  Please ensure your cellphones / Laptops are set on silent to ensure no one is disturbed during the session §  Ask questions !! House Keeping Notes
  • 4. §  What problem are we trying to solve? §  APIC-EM Architecture §  APIC-EM Apps a.k.a how can the controller help simplify my environment? §  What about Prime? §  Wrap-Up AGENDA
  • 5. What problem are we trying to solve?
  • 6. “A platform for developing new control planes” “An open solution for VM mobility in the Data-Center” “An open solution for customized flow forwarding control in the Data-Center” “A means to do traffic engineering without MPLS” “A way to scale my firewalls and loadbalancers” “A solution to build a very large scale layer-2 network” “A way to build my own security/encryption solution, avoiding RSA” “A way to reduce the CAPEX of my network and leverage commodity switches” “A way to define virtual networks with specific topologies for my multi-tenant Data-Center” “A means to scale my fixed/mobile gateways and optimize their placement” “A solution to build virtual topologies with optimum multicast forwarding behavior” “A way to optimize link utilization in my network, through new multi-path algorithms” “A way to avoid lock-in to a single networking vendor” “A way to distribute policy/intent, e.g. for DDoS prevention, in the network” “A way to configure my entire network as a whole rather than individual devices” “A solution to get a global view of the network – topology and state” “With SDN I can develop solutions to my problems far faster – “at software speeds”. I don’t have to work with my network vendor or go through length standardization” SDN – Still Don’t kNow – Stanford Defined Networking Many things to Many people
  • 7. Resiliency/Scale has been proven Distributed Networking has worked
  • 8. Distributed Networking has worked ? Distributed Networking adds complexity to manage/comprehend ! ! ! However
  • 9. But uses controller to mask complexity NETWORK Admin still makes network behavior decisions
  • 10. Abstracting Conventional Policy Complexity Conventional Model The What “Security Policy for Branch A” The How “Change ACLs in the Following Elements” The What “Security Policy for Branch A” The How “Change ACLs in the Following Elements” ACI Constructs Admin Driven Admin Driven Northbound APIs APIC EM Policy Based Model
  • 11. What is Policy? WHAT HOW Policy à way to simplify how we do things via abstraction
  • 12. Changing Nature of IT Ops with SDN led Management Management (NMS) NE NE NE NE Customer developed provisioning tools, manual CLI changes, and run book automation for IT Operations support Controller (APIC-EM) Management (Provisioning and Assurance) Automation (Workflow / Orchestration) NE NE NE NE Customer input on business / service intent Traditional Management SDN Led Management
  • 13. Changing Nature of IT Ops with SDN led Management Traditional Management Feature Configuration SDN Led Management Policy Automation
  • 14. Policy Maturity to Cover Enterprise System of Change Use Cases will Evolve Over Time policy traditional configuration traditional policy policy Controller-based Automation Today traditional Policy based Configuration à •  Dynamic •  Able to be automated •  Managed by the controller Policy grows, static shrinks Time
  • 16. Cisco APIC Enterprise Module Architecture Abstracts Network Devices to Mask Complexity Treat Network as a System Exposes Network Intelligence For Business Innovation Cisco APIC Enterprise Module Cisco and Third Party Applications Network Devices Catalyst, ASR, ISR Network Info Database Policy Infrastructure Automation REST API Southbound Interface: CLI Security QoS IWAN Network PnP Masking Network Complexity, Exposing Network Intelligence .
  • 17. Cisco APIC Enterprise Module Architecture Cisco APIC Enterprise Module Cisco and Third Party Applications Network Devices Catalyst, ASR, ISR Network Info Database Policy Infrastructure Automation REST API Southbound Interface: CLI Security QoS IWAN Network PnP Masking Network Complexity, Exposing Network Intelligence . 1.  Cisco Visualization Application a.k.a UI 2.  Cisco Applications for specific solutions IWAN, Network PnP, Collaboration, Security, etc 3.  DevNet 4.  Customer developed
  • 18. SDN Innovation: Network Information Base Provides One Source of Truth Cisco APIC Enterprise Module Cisco and Third Party Applications Network Devices Catalyst, ASR, ISR Network Info Database Policy Infrastructure Automation REST API Southbound Interface: CLI Security QoS IWAN Network PnP Masking Network Complexity, Exposing Network Intelligence .
  • 19. Cisco APIC Enterprise Module Architecture Cisco APIC Enterprise Module Cisco and Third Party Applications Network Devices Catalyst, ASR, ISR Network Info Database Policy Infrastructure Automation REST API Southbound Interface: CLI Security QoS IWAN Network PnP Masking Network Complexity, Exposing Network Intelligence . 1.  Network programmer service: used for programming the network 2.  Services within the controller leverage network programmer to talk to the network 3.  Depending on the type of platform and functionality the network programmer chooses the southbound protocol 4.  Services within the controller unaware of these protocols 5.  If new protocols are required, we only need to add the plug-in for that protocol in the network programmer
  • 20. APIC-EM Apps a.k.a how can the controller help simplify my environment?
  • 21. First we need to check the APIC-EM User Interface
  • 22. APIC-EM User Interface App: Device Inventory
  • 23. Network Information Base - Host Inventory
  • 24. APIC-EM User Interface App: Discovery
  • 25. APIC-EM User Interface App: Topology
  • 26. Use Case: Path Visualization •  No efficient method to troubleshoot IP voice and video sessions traversing the network on demand •  Lack of network visibility creates large OPEX to diagnose and find problem sources •  Path computation service provides a fast and accurate method for rapidly identifying/ isolating paths causing problems •  Low risk use case for SDN
  • 32. Boxes greyed out once traffic is blocked for easy visualization Policy Analysis
  • 33. CAMPUS Security Policy App (within User Interface) Per User Per Application Access Policy Enforcement SiSiSiSi APIC-EM Controller Block Bit-Torrent BRANCH Authentication ISE Block Bit-Torrent AD/Radius Server§  Admin configures business policy to block application traffic on a per user/ user_group basis. §  Controller uses identity information to install user specific access policy at the edge. User moves to a branch site. Policy moves with it
  • 36. Branch SourceFire Defence Center SDN Controller ISR Sensor X Sensor 1.  BYOD Malware/Javascript Attack 2.  SF Sensor detects threat 3.  SF DC notifies Controller 4.  Remediation API event 5.  Policy installed on Access switch port by Controller. 6.  Block or quarantine end-point WAN ISR Internet HQ Malware Attack Defense Center Alert!!!! Controller Notification Remediation Policy Enforcement Host Quarantined How to use Policy Programming for Network Threat Defense - Policy Programming outside the UI
  • 37. How to use Policy Programming for Network Threat Defense - Policy Programming outside the UI Branch SourceFire Defence Center SDN Controller ISR Sensor X Sensor WAN ISR Internet HQ Controller Notification Host Quarantined Defense Center /api/v0/policy POST! {"actions": ["DENY"], "policyOwner":"admin”, "policyName": "deny_all”, "networkUser": {"userIdentifiers”: ["10.10.20.7"]}}!
  • 39. EasyQoS App No more Box-by-Box configuration Config. Cisco Validated Design- Based Templates Control Transactio nalData RealtimeBestEffort Cisco Validated Design {CVD} Cisco APIC - Enterprise Module
  • 40. Easy QoS App Cisco Validated Design (CVD) classification and marking
  • 42. APIC-EM with CUCM Integration—Step 1a EM The administrator enters strategic business Intent to APIC-EM APIC-EM deploys: a)  static (ingress) ACL-based classification & DSCP-marking policies (on access edge interfaces only) with null ACL entries for VOICE and VIDEO ip access-list extended VOICE ip access-list extended VIDEO ip access-list extended BULK-DATA permit tcp any any eq ftp permit tcp any any eq ftp-data … class-map match-all VOICE match access-group name VOICE class-map match-all VIDEO match access-group name VIDEO class-map match-all BULK-DATA match access-group name BULK-DATA … policy-map APIC-EM-INGRESS-MARKING class VOICE set dscp ef class VIDEO set dscp af41 class BULK-DATA set dscp af11 …
  • 43. APIC-EM with CUCM Integration—Part 1b EM Once the administrator has entered strategic business Intent to APIC-EM APIC-EM deploys: a)  static (ingress) ACL-based classification & DSCP marking policies b)  static (ingress and egress) DSCP-based queuing policies on all switches class-map match-all VOICE-PQ1 match dscp ef class-map match-all VIDEO-PQ2 match dscp af41 class-map match-any BULK-DATA-QUEUE match dscp af11 af12 af13 … policy-map APIC-EM-2P6Q3T class VOICE-PQ1 priority level 1 class VIDEO-PQ2 priority level 2 class BULK-DATA-QUEUE bandwidth remaining percent 5 queue-buffers ratio 10 queue-limit dscp values af13 percent 80 queue-limit dscp values af12 percent 90 queue-limit dscp values af11 percent 100 …
  • 44. APIC-EM with CUCM Integration—Part 2 EM CUCM signals APIC-EM of a proceeding call APIC-EM deploys a dynamic ACL update for voice and/or video to all ports on the switch (or switch module) ip access-list extended VOICE match udp host 10.1.1.1 eq 18578 host 10.2.2.2 eq 17333 ip access-list extended VIDEO match udp host 10.1.1.1 eq 31199 host 10.2.2.2 eq 24141 ip access-list extended VOICE match udp host 10.2.2.2 eq 17333 host 10.1.1.1 eq 18578 ip access-list extended VIDEO match udp host 10.2.2.2 eq 24141 host 10.1.1.1 eq 31199
  • 45. APIC-EM with CUCM Integration—Part 3 EM CUCM signals APIC-EM of a terminating call APIC-EM removes the dynamic ACL update for voice and/or video ip access-list extended VOICE no match udp host 10.1.1.1 eq 18578 host 10.2.2.2 eq 17333 ip access-list extended VIDEO no match udp host 10.1.1.1 eq 31199 host 10.2.2.2 eq 24141 ip access-list extended VOICE no match udp host 10.2.2.2 eq 17333 host 10.1.1.1 eq 18578 ip access-list extended VIDEO no match udp host 10.2.2.2 eq 24141 host 10.1.1.1 eq 31199
  • 47. Intelligent WAN WAN Transport Branch MPLS $$$ Low Cost Circuit, Internet, 4G $ Private Cloud Virtual Private Cloud Direct Internet Access Internet backhaul Cisco Cloud Web Security Public Cloud ü  Secure WAN transport across MPLS and/or Internet for private cloud / DC access Increase WAN Capacity Improve App Performance Scale Security at the Branch ü  Leverage Low Cost path for public cloud and Internet access Cisco APIC - Enterprise Module
  • 49. © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential –Use under NDA – DO NOT DISTRIBUTE wolfgang@cisco.com wolfgang@cisco.com APIC EM Apps will innovate on design simplicity and intuitiveness
  • 50. APIC-EM IWAN App Site provisioning
  • 51. APIC-EM IWAN App Site provisioning
  • 52. APIC-EM IWAN App Site provisioning
  • 53. IWAN App – Site provisioning
  • 54. IWAN App – Site provisioning
  • 55. IWAN App – Site provisioning
  • 56. APIC-EM IWAN App Application Policy •  Applications detected in the network when enabling AVC •  Classify applications in different categories •  Organize application in categories to create business policies based on these categories
  • 59. APIC-EM IWAN App Application Policy •  Business logic à we tell the controller what applications are relevant for the business •  The controller is going to perform background tasks based on this business logic
  • 60. APIC-EM IWAN App Application Policy •  Define primary path for group of applications •  The controller will create a PfR policy based on those paths.
  • 62. Network Plug & Play (a.k.a. Zero Touch Deployment)
  • 63. Network Plug-n-Play – for Zero Touch Deployment Unskilled Installer GUI Based Consistent for devices & PIN(Campus/Branch) Secure Zero-touch RMA Greenfield & Brownfield Central Staging Facility Site-1 •  Install OS •  Install base config Network Admin Installer Site-3 Today’s Process Site-2 Site(s) Network PnP Pre Provision Projects/Sites Network Admin 1 Install & Power-on devices 2 Installer Monitor device installation 3 Network Admin Reseller/ Partner Ships equipment Cisco APIC - Enterprise Module
  • 64. PnP Server Use Case: Device Deployment in Campus DHCP Server Pre Provision Projects/ Sites •  Policies •  Match Rules •  Configs/Image •  IP Addressing Network Admin Day 0 Cisco APIC - Enterprise Module Pre-provision DHCP Server •  IP address •  option 43
  • 65. PnP Server Use Case: Device Deployment in Campus DHCP Server Switch running PnP Agent Device  receives  PnP  server   specific  metadata  info   configured  in  DHCP  op7on  43   Device  validates  server’s  loca7on  and   establishes  a  communica7on  with  the  server   Installer Remote Installer •  Mount and cable devices •  Power-on Day 1 Network Admin remotely monitors status of install while in progress. Day 1 Cisco APIC - Enterprise Module
  • 66. APIC-EM ZTD App – Configure Site, Device, Config •  Campus Workflow •  Serial # and PID- based device matching •  Operational config and IOS image for each device Network Admin Day 0
  • 67. The End stage Network Admin remotely monitors status of install while in progress. Day 1
  • 68. APIC-EM Apps a.k.a how can the controller help simplify my environment? •  Path Visualization •  Path Visualization + Integration with Cisco Prime Collaboration Manager •  ACL Trace •  ACL Analysis •  Security Policy Programming (Per User/Group) •  Policy Programming for Network Threat Defense •  Easy QoS via User Interface •  Dynamic Policy for video soft clients •  IWAN App •  Network Plug and Play Server Applications Released in phases Just a few examples, there’s much more
  • 70. Changing Nature of IT Ops with SDN led Management Traditional Management Feature Configuration SDN Led Management Policy Automation
  • 71. System of record vs. system of change Prime Infrastructure APIC - EM System of Record System of Change •  Policy definition •  Historical reporting on events & performance •  Configuration archive •  Troubleshooting workflows •  Capacity Trending •  Predictive Analytics •  Policy enforcement •  Discovery (for change) •  Topology (for change) •  PnP •  Network state monitoring •  Device abstraction •  Network Control
  • 72. Cisco Prime and APIC-EM Control Layer Device Layer Operational Automation Policy and Service Definition Automated Assurance Provisioning Visualization, Trending and Analytics Network Intelligence Device Layer Abstraction Network Control Policy Enforcement & Network Change Management & Orchestration Layer Cisco Devices Enterprise Networks, Data Center Cisco APIC Common ACI Architecture APIC for datacenter APIC Enterprise Module CLI, OpenFlow, OnePK API REST API (ONE DevKit) Catalog / Provisioning Fault / Events User / Data Management Performanc e Monitoring Reporting / Analytics Cisco IAC UCSD APIC-EM App (IWAN) PRIME INFRASTRUCTURE & NAM
  • 74. Summary §  Changing Nature of IT Ops with SDN led Management §  APIC-EM and Apps are a System of Change that will drive real time changes in the network §  Prime Infrastructure role will evolve into end-to-end assurance as System of Record, while also catering to feature configuration for custom environments §  The network administrator can now focus on Policy and Business Intent (WHAT) §  Controllers job to translate into network semantics/implementation (HOW) §  API to expose the networks capabilities §  APIC EM abstracts the underlying complexity of the network infrastructure
  • 75. Give us your feedback and you could win a Plantronics headset. Complete the session survey on your Cisco Connect Toronto Mobile app at the end of your session for a chance to win Winners will be announced and posted at the Information desk and on Twitter at the end of the day (You must be present to win!) Complete your session evaluation – May 14th