Professional Documents
Culture Documents
Local Knowledge
Local Knowledge
Local Knowledge
Local knowledge.
Cisco Connect Dubrovnik
Croatia • 28.03.2019
Cisco SD-WAN
Delivering Cisco Next Generation SD-WAN with Viptela
Vedran Franjić
System Engineer Sales
28.03.2019
• Introduction
• SD-WAN architecture
SD-WAN fabric
Agenda
•
• Deployment options
• Use Cases
• Licensing
Introduction
The WAN Has Changed
MPLS
Branch WAN
Users Data Center Internet
Data
Center
MPLS
Multi-
Cloud
Users
INET SAAS
SaaS
Branch
Devices WAN
Things Internet
Traditional and Legacy Architectures
Cannot Scale to Address Changing Needs
EXPENSIVE
CONNECTIVITY-CENTRIC INFLEXIBLE
Incomplete user experience Static network
Not application-centric
SD-WAN
Architecture
Cisco SD-WAN Architecture Overview
Orchestration = vBond Orchestrator PnP
vManage
Management = vManage APIs
(Multi-tenant or Dedicated)
vAnalytics vSmart
WAN Edge
Control Plane = vSmart
(Containers or VMs)
4G/LTE Internet
MPLS
vManage vAnalytics
SD-WAN Traditional
Local Routes
- Local prefixes (OSPF/BGP)
MPLS INET - SD-WAN tunnel endpoints (TLOCs)
WAN Edge Security Context
WAN Edge
- IPSec Encryption Keys
Fabric Routing:
<prefix> via
WAN Edge WAN Edge
Per-Session Load Sharing Per-Session Weighted Application Pinning Application Aware Routing
Active/Active Active/Active Active/Standby SLA Compliant
SLA SLA
Learn O365
1 IP Networks
SD-AVC SD-AVC
Cloud onRamp
for SaaS Controller
vManage First-packet
vManage
4 steer O365
First-packet
3 Distribute O365
match O365 2 IP Networks
Branch
Application
Rule SD-AVC
Pack Update Sensor Data
• SD-AVC Controller:
• Application Signatures updates
NBAR2 NBAR2 • Connectors to external service (O365)
Agent Agent
• Custom-app definition
cEdge cEdge
Deployment
options
Controllers’ Deployment Models
Cisco Cloud Ops MSP Ops Team Enterprise IT
VM VM
vSmart:
• Validated Scale: 5,400 Connections per-single vSmart
• Max Production Deployment: 20 vSmarts
vBond:
• Validated Scale: 1,500 Connections per-single vBond
• Max Production Deployment: 6 vBonds
SD-WAN Transition Strategy
Site B Site B Site B
Non- Non-
SDWAN SDWAN SDWAN SDWAN SDWAN SDWAN
Control
MPLS
Data
Center
Data MPLS
INET
Site
INET
Cisco SD-WAN Platform Options
SD-WAN with Services Pureplay SD-WAN
ISR 1000 ISR 4000 ASR 1000 vEdge 100 vEdge 1000 vEdge 2000
SD-WAN Security
Regional Deployment
Critical Applications SLA
Application Aware
Routing
5 6 1 2
D D
7 8 3 4 Sender 4 3 2 1 Receiver
Sender Receiver
Gateway
VPC/VNET
Cloud Cloud
Data Center Data Center
SD-WAN SD-WAN
Fabric Fabric
Campus
Remote Site Campus
Remote Site
Branch Branch
MultiCloud onRamp for SaaS
ISP2
Loss/ Loss/
Latency Latency
Regional
! ! Hub/CoLo/DC
ISP1
ISP1
SD-WAN
MPLS Fabric
ISP2
Remote Site
Remote Site
Quality Probing
Secure Branch - Firewall
Unified
Access Data Center/
Security Private Cloud
SD-WAN and
APP Firewall/IPS/URL Filtering
Branch/Campus
Cisco
Internet/SaaS
Umbrella
IaaS
Home/Mobile
Secure Internet GW
Secure Segmentation
§ Security Zoning
VPN 1
SD-WAN § Compliance
IPSec VPN 2
Tunnel VPN 3 § Guest Wi-Fi
WAN Edge WAN
Edge § Multi-Tenancy
§ Extranet
Per-VPN Topology
DNS/web
Firewall Firewall
vManage Firewall layer security IPS IPS URL
Filtering
Employee Guest
ZTP– New cEdge Appliance
Control and Policy
PnP Server
Elements
2 3
5
1 Full Registration and
Configuration
4
Assumption:
• DHCP on Transport Side (WAN)
• DNS to resolve devicehelper.cisco.com*
cEdge
* Factory default config
Regional deployment
Public Public Public
Internet Internet Internet
Choose on premises or
4
cloud managed
Cisco DNA Essentials
Determine platform for
5
future scale
Delivering Cisco Next Generation SD-WAN with Viptela