Meraki v4

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 111

Meraki

Avit Session
August Martens – Meraki TSS

© 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Today’s Agenda

Intro to Meraki Meraki Catalyst + Dashboard


Meraki Dashboard Portfolio Meraki Demo
Meraki at a glance Connecting passionate people
to their mission by simplifying
2006 FOUNDED CLOUD
NETWORKING
the digital workplace.

2012 ACQUIRED BY CISCO

2017 IT PORTFOLIO
EXPANSION TO IOT

TODAY 16+ YEARS DESIGNING


SCALABLE & SECURE
CLOUD ARCHITECTURE
Trusted to simplify
experiences everywhere
4M+ 12M+ 190+
Customer Meraki devices Countries
networks online in network

640K+ 6B+ 191M+ 250M+


Customers External API Daily end-user Daily splash
monthly calls devices pages served

99.99% 100K+ Active devices for 5+ customers, each

Cloud SLA

285K+ Access points deployed for a single customer


The Meraki platform:
A foundation for IT and IoT 3x
larger than
competitors

CUSTOM BUILT
developer.cisco.com/meraki
API
Built-in solutions Tailored solutions TECH PARTNERS
MERAKI DASHBOARD meraki.com/marketplace

Wireless Switching Mobile Device Security and Cellular Smart Sensors


Management SD-WAN Gateways Cameras

ACCESS SECURITY AND IOT


Out of Band Cloud Management
Intuitive
● Simple browser-based dashboard
● Cloud-hosted centralized management platform
User Traffic Management Data
Scalable
● Unlimited throughput, no bottlenecks
● Add devices or sites in minutes

Reliable
● Highly available cloud with multiple data centers WAN / Internet
● Network functions even if connection to cloud is interrupted
● 99.99% uptime SLA

Secure
Security Appliances
● No user traffic passes through Meraki cloud
● Can fully support a HIPAA- / PCI-compliant network (level 1
certified)
● Third party security audits, daily penetration testing Security Cameras Switches
● Automatic firmware and security updates (user-scheduled)

Systems
Access Points
Manager
The engine behind the single dashboard

• Meraki runs a sophisticated CI/CD - velocity


hybrid cloud (best of private
and public infrastructure)
Container
• Our scale allows us to orchestration
scalability
learn and evolve faster
for customers’ benefit, which
Meraki Hybrid cloud:
simplifies IT platform reliability and
agility
Easiest solution to deploy, manage, and maintain
Preconfigure networks before
equipment is powered on or
connected for rapid, plug-and-play
zero-touch deployment.

Scale quickly without limits or


bottlenecks — no need to purchase
wireless LAN controllers.

Manage your networks from


anywhere you have internet
connectivity using our intuitive, web-
based dashboard.

Oversee all Meraki and client devices


— wired and wireless — from one
place for centralized, end-to-end
visibility and control.
Accelerate your business with Meraki

91% 60% 3.3x


license renewal of customers increase from initial
rate from Meraki repurchase in the purchase value in
customers first 2 years the first 2 years
Management
at scale
• Streamlined landing experience
• Improved performance: faster load times

• Handling 12+ million devices and 4+


million networks
One Dashboard.
Policy, Assurance, Automation

• Automate Policies
• Configuration Templates
• 18.000 API request/hour

• AI based Assurance
Policy

Consistent Policy across all sites


M
SRC | DST Employee IoT IoT Server
Employee
IoT
IoT Server

Policy & Groups are configured in dashboard and pushed to


Adaptive Policy nodes like any other Meraki configuration
change
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy

Multi-Domain Consistency with ISE

Cisco Tag-Based Security Domain


Policy Sync SGT Trust

Meraki Adaptive Policy Domain

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Assurance

Meraki Health: Using data to simplify assurance and


optimization across the network Performance analytics

Auth.
101100101010010001010100110101100
RSSI DNS
001001010010101001000101010011011
101101001011010101101011101001100
Latency SNR
Data010100101101101011010000101010101
Rate DHCP
101101100100100010101001101010110
Channel Web app health
010001010100110110110101010010101
utilization
101101001011010101101011101010100
101101101011010000101010101101101
100100100010100110010100101101110
SD-WAN110100001010101011011011001001000
101101100100100010101001101010110
Performance
010001010100110110110101010010101
101101001011010101101011101010100
101101101011010000101010101101101
Pinpoint network issues
100100100010100110010100101101110
Application
110100001010101011011011001001000
Performance
Assurance

Machine Learning based Assurance

• Auto-baselined, Root Cause Analysis


• Machine learning powered Anomaly detection
• Industry leading one month historical information
• Automated reporting & Comparison
Automation

Ecosystem integrations. Rich API tool kit.

{APIs and more}

Captive portal
Dashboard API Webhook API Scanning API MQTT wireless MV Sense API
API

● Programmability ● Event stream ● Asset tracking ● Real-time ● Guest Wi-Fi ● Real-time (4


● Automation ● Automation ● Location location ● Secure Hz) data
● Monitoring trigger analytics services Onboarding stream
● Reporting ● Wayfinding ● Wayfinding* ● Historical time-
● Data insights series via REST
● Snapshot API ● Current
snapshot
Automation

Lifecycle Visibility and Control


Review, schedule, and update firmware from a single location

ü Change log

ü Schedule visibility

ü Firmware security status

ü Release notes

ü End of support tracking


Simple, All Inclusive Licensing

1:1 ratio of licensing and hardware


1, 3, 5, 7, and 10 year durations available
Centralized management with network-wide visibility and
remote troubleshooting tools
Over-the-web firmware and security updates

License Hardware 24/7 enterprise support and warranty


All features included as standard, no per-feature
licensing
Made for MSP Licensing Features & Capabilities

Move licenses 90 day license Individual


Partial Licensing
between activation device
renewals APIs
organizations window shutdowns
Knowledge Check

Co- Termination PDL Subscription


How Many Expiration dates? 1 1 or Many 1 or Many

When do Licenses begin to burn? Order Generated When Activated or 90 days When Activated or 90 days

Where is Licensing enforced? Org-wide Per-Device Network-wide

What if a licenses expire and exceeds grace Period? Org Shutdown Device Shutdown Subscription Shutdown

SKUs? Complex Complex Simplify

Payments? Upfront Upfront Customer decides

Ease for Grow adaptability? No Yes Yes

Ease for Management? Yes No Yes

© 2 0 2 3 C isco and/or its affiliate s. All rights re se rve d. C isco C onfide ntial
Dashboard Global Overview Timing: GA
Announcement
Posted: 1 March 2023

Global Overview creates an efficient


workflow to help you manage more
organizations in less time
• Quickly add new organizations
• See what needs attention across all organizations
from a single screen
• Keep organizations optimized with less effort by
viewing intuitive metrics such as the current
status of each device
• Easily monitor the status of licenses for each
organization
• Gain faster resolutions by using filters to quickly
find what you need within the dashboard
• Need further analysis on a topic? Easily export
data for reports
Meraki Switching

Meraki Wireless

Meraki Portfolio
A Quick Overview Meraki SD-WAN with MX
MS
Switching
MS Access and Aggregation Switches
Product Highlights:
• Multigigabit stackable access switches in 8, 24, and
48 port configurations with (U)PoE on all ports
• Aggregation switches in 16 and 32 port
• Configurations with 40 Gigabit QSFP+
• Per-port configurations for granular control
• Lifetime warranty on all switches

Feature Highlights:
• Rich visibility and troubleshooting
• Easy QoS for voice and video
• Virtual & physical stacking options
• Multigigabit-capable options
Configuration
Virtual stacking: configuration of switchports
in bulk, independently from physical
connectivity

QoS for humans: network-wide quality of


service configuration and deployment

Spanning-tree: network-wide rapid-STP


configuration
Full Stack Topology Visualization
Layer 2, Layer 3, and multicast topology visualization

L2 / L3 and Multicast Topology Visibility

Identify alerting devices across platforms

Validate connectivity and visualize the network


Troubleshooting
Remote Packet Capture: full Wireshark capable
packet captures from dashboard

Live tools – Ping | MTR: validate connectivity to


resources on a per-device basis

Live tools – Cable test: ensure pair status and


length of a cable run

Live tools – L2/L3: per-switch MAC, L3 tables, and


OSPF Peering
A foundation
End-to-end for IThealth
network and IoT
3x
larger than
10%
competitors
75% SNA < 15dB 65% latency > 200ms 100% 100%

Custom
Developed
100%
Built-in solutions Tailored solutions
apps.meraki.io
API
End (buy or build apps) Cloud
Point Services

Meraki Dashboard Tech Partner


80%
(single pane of glass)

Wireless Switching SD-WAN Gateway Mobile Device Environmental Sensors Cameras


and Security Management

SD-Access SD-WAN, SASE IOT

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28
MR
Wireless
More than 18 billion devices in use, 4.4
billion shipping in 2022

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d. C isco C onfide ntial
What is Wi-Fi 6E?

11b 11n 11ax


Wi-Fi 1 (2.4 GHz) Wi-Fi 4 (2.4, 5 GHz) Wi-Fi 6 (2.4, 5 GHz)
• High efficiency
• 4x capacity
• IoT scale

1999 2003/2004 2009 2013 2019 2021

11ax
Wi-Fi 6E (6 GHz)
11a, g 11ac • Additional 6-GHz spectrum, 59
new channels augmenting Wi-
Wi-Fi 2/3 (2.4, 5 GHz) Wi-Fi 5 (5 GHz) Fi 6
• In 6 GHz, ONLY 11ax, no
support for legacy

C97-745041-00 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31
6 GHz is the biggest Wi-Fi spectrum
expansion ever
Band Channels Bandwidth

3 20 MHz
2.4 GHz 60 MHz of spectrum and
1 40 MHz 3x 20-MHz channels

25 20 MHz

12 40 MHz 500 MHz of spectrum and


5 GHz 25x 20-MHz channels
6 80 MHz

2 160 MHz

59 20 MHz 1200 MHz of


spectrum and
29 40 MHz 59x 20-MHz
6 GHz channels in US
14 80 MHz
500 MHz of
7 160 MHz spectrum in EU

C97-745041-00 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32
Image TBC

Faster Speeds
Lower Latency
Better User Experience

C97-3018295-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33
MWC 22 – One of the first production
Wi-Fi 6E networks
Congested spectrum in 2.4 and 5 GHz

Speed test in 2.4 and 5 GHz: Speed test in 6 GHz:


126 Mbps UP VS. 1016 Mbps UP
186 Mbps DW 1311 Mbps DW

C97-3018295-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34
One Product – Two Management Modes

Cisco DNA Management Mode Meraki Management Mode


C9800 & DNAC Stack MR Dashboard Stack

C97-2479435-00 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35
Wi-Fi 6E access points
Ideal for small to medium-sized deployments Best-in-class; flexibility Mission-critical; performance

cloud- cloud- cloud- cloud-


managed managed managed managed

CW9162I-MR CW9164I-MR CW9166I-MR MR57


• 2x2 + 2x2 + 2x2 • 2x2 + 4x4 + 4x4 • 4x4 + 4x4 + 4x4 (XOR 5/6) • 4x4 + 4x4 + 4x4 (XOR 5/6)
• 2.5 Gbps mGig • 2.5 Gbps mGig • Dual 5 Gbps mGig • Dual 5 Gbps mGig, power pool,
active failover *
• Power options: PoE, DC • Power options: PoE, DC • Flex radio – dual 5 GHz
• PoE redundancy
• IoT-ready + Bluetooth® 5.x • IoT-ready + Bluetooth® 5.x • Power options: PoE, DC • Flex radio - dual 5 GHz
• USB 4.5 W • USB 4.5 W • IoT-ready + Bluetooth® 5.x • IoT-ready + Bluetooth® 5.x
• General purpose • High performance • USB 4.5W • USB 9W
• Medium density • High density • Ultra-high performance • Ultra-high performance
• 3.9 Gbps aggregate t. • 7.5 Gbps aggregate t. • High density • High density
• 7.8 Gbps aggregate t.
• 7.8 Gbps aggregate t.
*Available in Future

Full radio capability (6 GHz @ LPI) on single 30W PoE+

Same bracket; industrial


Dedicated scanning radio Air Marshal for WIDS/WIPS USB
design
Wi-Fi 6 & Wi-FI 6E Co-Existence
Wi-Fi 6 Wi-Fi 6E Wi-Fi 6
MR57 C9136(I)

MR56 C9130(I &E)

C9166(I)

MR46(E) C9120(I &E)

C9164(I)

C9115(I &E)
MR44

C9162(I)

C9105W
MR36 C9105
MR36H

© 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Powerful Wi-Fi 6 for small spaces
Ideal for small to medium-sized deployments

Cost reduced; entry-level Wi-Fi 6

MR-28 NEW MR-78 NEW


• 2x2:2 • 2x2:2
• 1.5 Gbps Aggregate • 1.5 Gbps Aggregated BW
BW • Power options: 802.3 af PoE,
• Power options: PoE, DC
DC • IoT-ready + Bluetooth® 5.x
• IoT-ready + • Ruggedized
Bluetooth® 5.x
• Medium density
• Medium density

3-radio = 2.4 GHz and 5 GHz client-serving radios, Bluetooth® Low Energy radio

OFDMA (DL/UL) MU-MIMO (DL/UL) Target wake time Bluetooth® 5.0


Flexible (XOR) radio – maximum flexibility
To optimize radio capacity when the client mix is mainly 5-GHz clients, the
Catalyst 9166 allows switching the 6-GHz radio to operate as a second 5-GHz
radio
Fewer 6-GHz clients – optimize network Optimize for both 5-GHz and
for 5 GHz 6-GHz clients

C97-3018295-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 39
AP power optimizations
New AP Power Distribution allows admins control over how APs operate when
provided less than full power (30W/PoE+), enabling maximum utility of the AP.

Scenario 1 Scenario 2 Scenario 3


Mainly 5 GHz clients
Mix of 5 and 6GHz clients Balanced
(Or 6 GHz not allowed)

2x2 4x4 Off Off 4x4 2x2 2x2 2x2 2x2

Available fall 2022

C97-3018295-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Numbers are examples, and will depend per AP platform 40
AP power optimizations
New AP power save mode allows administrators to schedule periods of time
where APs should, for example, turn off radios to save power, thus reducing
power consumption

Day Night

C97-3018295-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 41
New

Wireless
Experience
Dashboard
• Intelligence
• Discoverability
• Expandable, More KPIs
coming

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d. C isco C onfide ntial
Contextual Client Roaming Analytics Beta in Q2 2023

• Tiering of Roaming Events –


Bad, Suboptmial, Good Roaming

• Contextual Roaming Events -


Ping-Pong Client, Sticky Clients

• Historical Timeline up to a month

• Visualize Session Time and


Roaming Experiences

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d. C isco C onfide ntial
Home network experience on shared network: WPN

JANE KABIR SAM

Each receives a home Wi-Fi experience while securely segmented and


connected to the same access point
© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 44
Footfall monitoring, movement
tracking, and shopper analytics
Monitor store congestion, footfall, and
frequently trafficked areas over time to
improve product placement, operations,
and customer experience.

Measure in-store footfall analytics for


visual entrances and exits or specific
departments using the built-in ML engine.

Cloud-managed Smart security


wireless access points cameras
Enabling smart buildings with Cisco Spaces
Environmental monitoring

Catalyst® 9166 and 9136 Series


both have environmental sensors
(Total Volatile Organic
Compounds [TVOC]) that tie in
with Cisco DNA Spaces, enabling
live monitoring of temperature
and air quality in the Smart
Workplaces app

C97-3018295-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 46
Cisco Spaces

• How long are people waiting in your


store?

• Create a live dashboard on your website


to show occupancy in real time!

• Gives a monthly-report of how people are


behaving at locations – helpful for LOB
use cases and business users.

• Can choose to view report by:


• Location Name
• Tags created
• Month
• Historical View

© 2020 Cisco and/or its affiliates. All rights reserved.


Location Analytics
• Gives a detailed and granular view
of analytics at each location level.

• Helpful for IT use cases and


business use cases.

• Presents analytics about:


• Visitor numbers
• Number of visits
• Average dwell times
• Dwell time breakdowns

• Raw data is LOCATION UPDATES:


Probe or Data RSSI based

• Vertical dependent metrics

• Can create personalized


dashboard per location, date range
and SSID filters

© 2020 Cisco and/or its affiliates. All rights reserved.


Unlock the physical space blind spot

how people and things


See behave on-site

on insights through
Act digitization toolkits

platform capabilities to
Extend drive business outcomes

Cisco® wireless delivers


connectivity + business insights

Digitizing physical spaces: People and things


C97-742513-00 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Partner Confidential
Density Rules and Triggers
Right Now supports Density Rule Triggers for both Wi-Fi and MV data.
Density Triggers requires ACT license
Three types of density rules triggers:

Count Based Density Based Occupancy Based

“Set real time trigger “Set real time trigger “Set real time trigger
warning when number of warning when number of warning when number of
people in SJC24 exceeds people in SJC24 exceeds people in SJC24 exceeds
100.” 20 per square foot” 40% of occupancy limit”

© 2020 Cisco and/or its affiliates. All rights reserved.


Captive Portals Onboard and acquire visitors and deliver
targeted engagements at zero click

Where to show Use Cases


Brand, Location, Geography,
etc. • Seamlessly onboard and acquire visitors at your properties.

When to show • Map to CRM/ loyalty systems and expand loyalty programs
Weekdays/ Weekends, Days
of week, 5 PM, etc. • Promote enterprise services (app downloads, partners);
location specific information (localized offers, notifications,
etc.) and drive monetization through sponsorships
Who to show
Location, behavior • Access to onboarding and acquisition reports
(entry, exit, dwell), or persona
• Provide relevant information to your visitors to promote
safety and compliance of your properties
What to show
Relevant messaging specific
Value
to that day/time/ location
Customer Acquisition Loyalty

Onboarding Engagement

© 2020 Cisco and/or its affiliates. All rights reserved.


High Level Data Flow Architecture
DNA Spaces
Dashboard Apps
Partner App IoT Device
Behavior
Center Space Optimization Analytics People
Marketplace
Real time Lighting
monitoring Experience Sensor*

Safety, Outcomes Operational


Contact Tracing Compliance Efficiency PoE
Sensors

Meeting Room Finder Environmental


Sensors
(wired+ wireless)
Firehose API Dynamic Gateway
Wayfinding Dashboard+Apps

DNA Spaces Cloud


Asset
Tags
Asset Management
Spaces Connector Or
And other Directly
enterprise Occupancy
systems
Contact Tracing PIR
Sensors
And more
Catalyst & Meraki Catalyst Wristband
Tags
Access Points Switches And more
Card

Cisco Network
© 2020 Cisco and/or its affiliates. All rights reserved.
WebEx DNA Center MV Tags

Endpoints Network Management Cameras


Hardware
MV & MT
Smart Cameras / Sensors
Meraki use-cases that advance
sustainability Electronic Shelf Label integration
• Reduce waste
• Reduce required paper and ink for
Energy savings traditional labels
schedule
• Switch off WiFi and Smart cameras
other PoE powered • Reduce travel
devices out of requirements
business hours • Occupancy / usage-
• Turn off WiFi based lighting
radios to save
energy
Air Quality
Temperature/Humidity • Promote Health
Sensors and Safety
• Prevent IT equipment failure • Improve HVAC
• Improve HVAC efficiency, reduce efficiency
energy costs and emissions Water leak sensor
• Prevent spoiled goods (food, • Prevent water waste
medical substances, etc.) • Avoid spoiled goods
• Fridge/freezer/cold chain • Prevent water damage to
monitoring Door open/close sensor building and infrastructure
• Improve HVAC efficiency, reduce
waste
MT 40
Smart Power Controller

Monitor

Manage

Control
Monitors
● Voltage

● Current

● Frequency

● Real Power

● Apparent Power

● Power Factor

● Energy Usage
MT Sensors
Introducing : Alert Cards

Available Q3FY23

● Newest alerts shown first

● Dynamically updated
● Take action quickly
Meraki MV smart cameras
Cloud-managed physical security designed
to give you more

Scalable Secure Agile access Smart

• On-camera storage and • Hardware security • Local and remote viewing • Motion analytics
processes • Video encryption • Browser-based dashboard • Detects people, vehicles,
• Cloud management • Automatic updates • Mobile app and PWA sirens, and alarms
• No NVR, VMS, or plug-ins • Secure user accounts • Audio analytics
SCALABLE

Streamlined architecture

EVERYTHING IN THE BOX ACCESS ANYWHERE SMART PROCESSING


Eliminates the NVR, VMS, and View locally or remotely Video is analyzed on-camera
extra analytics in real time
AGILE ACCESS

Access on any device, anywhere


Easy access to react and respond
wherever you are

Meraki mobile app for teams on the go

Meraki Vision portal puts safety front-


and-center to resolve incidents faster

Meraki Display transforms compatible


TVs to public viewing stations for easy
monitoring
React and respond

• Quickly find footage of events

• Share live link access to first responders


in emergencies

• Easily export video from one or multiple


cameras to download or share
MV SENSE

Built-in Smart
Camera analytics
Use people and vehicle detection, office occupancy,
and audio analytics for a variety of use cases.

• Customer behavior patterns


• Staffing needs or queue wait times
• Conference and meeting room
occupancy
• Long-term facilities planning
• Alarm system or access control
integration
Endless Opportunities and Use Cases

Empty parking lot spot detection Blocked emergency exits Coffee cup detection and dwell time

5 4 3
1

Logistics efficiencies and safety Food and


Office beverage portion control
entry Office entry security
security

Cogniac © 2022 Cogniac. All Rights Reserved. 65


Calculations and Charts – MV Camera

• Meraki sends detections via a


continuous MQTT stream

• DNA Spaces generates entry /


exit events per site in real time
based on people crossing
across Trip Wire.

• Each “oid” of type “person” in


the MQTT stream is counted
as an individual

While internally the entry / exit events are


generated in real time, it can take about 2-3
minutes for the dashboard value to be
updated
© 2020 Cisco and/or its affiliates. All rights reserved.
MV camera indoor portfolio
FLEXIBLE, LOW-COST EASY INSTALLATION 360° FISHEYE GENERAL PURPOSE

MV2 MV12 series MV32 MV22 series


Wide FoV Wide or narrow FoV 360° fisheye Varifocal lens
1080P video 1080P video 8.4MP sensor Wide to narrow FoV
256GB storage Up to 4MP video
No on-camera storage 128-256GB storage
256-512GB storage
MV camera outdoor portfolio
LONG-RANGE, HIGH- PANORAMIC AREA
MORE DETAIL, HIGH RESOLUTION
GENERAL PURPOSE DETAIL CAPTURE
LONGER STORAGE AND FLEXIBLE STORAGE
AND MORE STORAGE AND MORE STORAGE

NEW NEW

MV72 MV72X MV52 MV63 series MV93 series


36-112º FoV 36-112º FoV 12-37º FoV Fixed lens (102º FoV) 360° fisheye
1080P video 4MP video 4K video Up to 4K video Up to 12.4MP sensor
256GB storage 512GB storage 1TB storage 256GB-1TB storage 256GB-1TB storage
Licensing

ENTERPRISE MV SENSE CLOUD ARCHIVE


Everything you need to scale Leverage analytics Increase storage

• Centralized cloud management • Custom CV • Dual recording on-camera and


in the cloud
• Seamless firmware and security • API access to machine learning
updates • 24/7 backup off-site or longer-
• Object detection for people and
duration video storage
• New software features and vehicles, audio, and occupancy
functionality analytics • 7-, 30-, 90-, 180-, and 365-day
options
• 24/7 phone and email support • Custom CV for bespoke use cases
• Ten free licenses included for
every organization
MX
Security & SD-WAN
Why SD-WAN
WHY SD-WAN

WAN & Bandwidth


Transitions • Increasing bandwidth demands
o Continued cloud migration of applications and resources
o Increasing use of video & VoIP

• Private legacy WAN links are coming under


M P L S
increasing strain
Branch HQ / DC
• Other WAN technologies are maturing to
become viable for enterprise consideration
o Broadband
Traffic yesterday o Fiber
Traffic today
o Cellular
WHY SD-WAN: Reducing reliance on MPLS

Cost-Effective & MPLS-like


Enterprise WAN Options
AUGMENTED MPLS

M P L S • Supplement an existing MPLS network with


broadband for increased bandwidth
B R O A D B A N D

Branch • Offload traffic from MPLS to broadband with policy


based routing dynamic path selection

BROADBAND-BROADBAND

B R O A D B A N D • Dual high speed broadband connections


B R O A D B A N D • Load balance business critical traffic based on policy
Branch or link performance
WHY SD-WAN: Beyond Conversion of MPLS

Quality of Experience

• Business traffic continues transition to be more cloud-centric

• Acceleration of resources and workloads moving to SaaS & IaaS


hosted in multiple cloud environments

• Branches and remote users are increasingly accessing SaaS & IaaS
directly over the Internet

• Visibility through advanced analytics is becoming essential to


deliver high quality user experience
• End-to-end: from the user to the application server
• WAN including the Internet
ABOUT MERAKI

A Platform Approach to SD-WAN

OUT-OF-THE-BOX DIGITAL BUSINESS


MANAGEMENT & ANALYTICS POWERED BY MERAKI

{ HTTPS } { API }
USE CASE

Fiber 1
Fiber 2

Superfast branch
with extra resiliency
MX

USB
cellular failover

1. Superfast branch 1 Superfast


Primary: Up to two gigabit fiber uplinks
Failover: One gigabit fiber uplink or USB cellular
Agile options
2. Extra resiliency
OPTION 1 2 Extra resiliency
Primary: Two active gigabit uplinks – 1x fiber + 1x cellular
Failover: Two uplinks – gigabit cellular + USB cellular
Gigabit
OPTION 2
Fiber 1 cellular 1
Primary: One active gigabit fiber uplink MG
Failover: Three uplinks – 2x gigabit cellular + USB cellular
Gigabit
cellular failover

MX

USB
cellular failover
Unique end-to-end platform visibility

Client Wi-Fi Switch Security & SD-WAN WAN

Applications
Benchmark ISP performance
ThousandEyes Internet Insights

• Get ‘Internet Insights’ from ThousandEyes


integrated into the Meraki dashboard

• See global ISP outages overview on a map

• Benchmark your ISP performance against


providers globally

• Independently validate findings from web


app health and WAN health

Map view of global ISP outages powered by ThousandEyes Internet Insights


Data Generation and Outcome
Cloud Agent

End-to-end network SaaS


Enterprise Agent visibility

Big data
analysis

Endpoint Agent

Different vantage points of data


create a complete picture
WAN health

• At-a-glance health of all MX uplinks across all


sites

• Quickly identify downed uplinks, including


cellular, across all sites

• Easily monitor signal strength for cellular


uplinks across all locations

• Quickly isolate sites with underperforming


uplinks to make the case for switching ISP or
adding cellular as failover

• Discover which sites are most reliant on


Monitor the health of all MX uplinks including cellular across all sites
cellular as failover
Pinpoint app performance issues at-a-glance

An IT admin can immediately


Where’s the issue
tell which point in the
! and so who should
network is failing and causing
be contacted?
degradation

Within 2 clicks, an IT admin


What’s the exact can understand the exact
! reason and where’s reason and drill down to
the evidence? generate specific evidence
for the poor performance

Suggested root cause of performance issues


Don’t worry Smart Thresholds SMART
THRESHOLDS

about setting
thresholds
• No need to set any threshold
• Thresholds autonomously adjust
through sophisticated machine
learning models
• Based on past behavioral patterns of
the specific network
• Takes into account previous
performance, workloads etc.
One Unified Platform
Industry Leading SD-WAN
Meets Industry Leading Security

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
MX Security Features & Capabilities

Malware Content Logging &


AMP IDS / IPS Firewall
Analysis Filtering Analytics

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Intrusion Detection and Prevention (IDS/IPS)
Prevention or Detection

Connectivity: contains rules from


current and past two years and
CVSS score of 10

Balanced: contains rules from


current and past two years and
CVSS score of 9 or greater

Security: contains rules from


current and past three years and
CVSS score of 8 or greater

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
MX Network Objects
Consolidate firewall rules using logical groups and aliases

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Seamless Extension to Public Cloud Environments

• Delivered by a virtual MX appliance (vMX)

• vMX is designed to extend the simplicity of site-to-site Auto VPN to


public cloud environments

• Supported in all major public clouds: Amazon Web Services (AWS),


Microsoft Azure, Google Cloud Platform (GCP)*, Alibaba Cloud

• Extend the Meraki SD-WAN fabric to public cloud environments for


optimized access to business-critical resources

• Securely connect branch sites with a physical MX appliance to


resources in public cloud environments in three clicks with Auto VPN

• Supports client VPN for remote users

* Targeted Q2 2021

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controlled Path Selection for SaaS Applications

• Local Internet breakout for SaaS


applications to use direct Internet
access instead of VPN tunnels
• Seamless one-click setup for top
applications
• Choose a proffered public Internet path
• Load balance between available public Internet
links
• Apply a global preference

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Dynamic Auto VPN path selection
1. Define acceptable performance thresholds

3. Choose preferred uplink and when fail


over should occur
2. Select from built-in Layer-7
categories and applications

© 2021 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco+ Secure
Connect
More and more blind spots

Hybrid work is the norm Transition to multicloud and SaaS

Remote users Web

Personal and
mobile devices Public SaaS apps

IoT devices Private apps

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d.


Recommended SASE Architecture by Gartner
The components

SD-WAN SWG CASB FWaaS ZTNA

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d.


Recommended SASE Architecture by Gartner
Categorized

SWG FWaaS
SD-WAN ZTNA
CASB

WAN Modernization Outbound Cloud Security Inbound Application Access

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d.


Recommended SASE Architecture by Gartner

SWG FWaaS

SD-WAN CASB ZTNA

optional add-on

© 2 0 2 2 C isco and/or its affiliate s. All rights re se rve d.


First connect, then protect

Internet / SaaS
Viptela
SDWAN
DNS security CD L3/4/7 Secure web Cloud-access IPsec
firewall gateway security broker
(CASB) VPC/VNETs
Secure
w/Private Apps
Branch/HQ/DC Cloud Traffic
Acquisition

Meraki Secure Connect Identity Device posture


Browser
SDWAN Dashboard and health
internet traffic AnyConnect
private traffic
Global Interconnect Users

Interconnect Everything Security Everywhere

© 2 0 2 3 C isco and/or its affiliate s. All rights re se rve d.


C97-2964708-00 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 96
Part of the Meraki eco-system

© 2 0 2 3 C isco and/or its affiliate s. All rights re se rve d.


A Model For Every Location
SMALL BRANCH VIRTUAL CELLULAR

VPN THROUGHPUT

Small 200 Mbps


MX67/68 MX67C/68CW MX75 MG21/21E
Up to 50 users Up to 50 users Up to 250 users Medium 500 Mbps
300 Mbps DL
600 Mbps FW throughput 600 Mbps FW throughput 1 Gbps FW throughput Failover connectivity
Wi-Fi & PoE Wi-Fi & PoE WAN PoE Large 1 Gbps
CAT 6 LTE modem

MEDIUM TO LARGE BRANCH CAMPUS OR CONCENTRATOR

MX85 MX95 MX105 MX250 MX450 MG41/41E


Up to 250 users Up to 500 users Up to 750 users Up to 2,000 users Up to 10,000 users 1.2 Gbps DL
1 Gbps FW throughput 2 Gbps FW throughput 3 Gbps FW throughput 4 Gbps FW 6 Gbps FW Critical failover or
throughput throughput primary connectivity
1:1 Ratio of MXs to Licenses
Choose the license that matches your needs

SD-WAN Plus Adv Security Enterprise


Reliant on SaaS and Site-to-site traffic with Basic site-to-site
FEATURE HI GHLI GHTS internet-based resources internet access VPN traffic only

3-click secure SD-WAN connectivity ● ● ●


L7 stateful firewall ● ● ●
Advanced Malware Protection (AMP) ● ● ✕

Intrusion detection & prevention ● ● ✕

Content filtering ● ● ✕

Internet Outages from ThousandEyes ● ✕ ✕

Smart L7 local internet breakout ● ✕ ✕

Performance-based internet routing ● ✕ ✕

ML-powered SD-WAN analytics ● ✕ ✕


MG51 & MG51E Cellular
Gateways
● 5G always-on connected experiences anywhere
● Primary connectivity
● Category 20
● 2 Gbps / 300 Mbps (down/up)
● Dual SIM
● IP67-rated: mountable anywhere indoor or outdoor
● Cellular is not just a backup option anymore, it can
connect your entire branch
SM
Enterprise Mobility Management
FEATURE

Multi OS Support
iOS 10+
including Apple iPad, iPhone

macOS 10.10+
including Macbook, iMac, Mac mini, Mac Pro, and more

tvOS 10+

Android Enterprise 7.0+


including phones, tablets, and more

Chrome OS (G Suite for Enterprise)

Windows 10, 11 (build 1703+)


including Surface, tablets, desktops, laptops,
and more

Windows Server 2016+

Simple Licensing: same license for any device type


FEATURE

Real-time inventory
and visibility
• Single-cloud platform for all endpoint devices,
no matter what OS

• Device location via Wi-Fi/ GPS/ IP Address

• Device hardware inventory details: serial #,


model, CPU, memory, storage,
Export
• Software posturing: OS version, antivirus as .csv file
for easy
check, firewall inventory
• Flex Table: include additional columns for
additional device information, and export to keep
CSV files of device inventory and information
associated to them
FEATURE

Unique bridge connecting networking


and cloud security
Zero Trust Network Access Deploy & Configure Cisco Security

Sentry Wi-Fi &


Trusted endpoint
Trusted Access

AUTOMATE
Sentry VPN SIMPLIFY Device posture
SECURE

Sentry Policies Deploy & secure


FEATURE

Sentry: seamless network


integration
• Sentry Wi-Fi Security — MR
EAP-TLS WLAN authentication made easy
+ Simple Setup
• Sentry Enrollment – MR
+ Unified Console
Self-onboarding for end users
+ Dynamic Policy
• Sentry VPN Security — MX
Auto provision mobile client VPN

• Sentry Policies — Meraki Group Policies


Network policy enforcement based on posture
Accelerating the transition to a
cloud-managed networking experience

#1 #1
in cloud
managed in
networks networking
Meraki Catalyst

© 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 106
Your IT operating model, your way
Flexibility, choice, and simplicity

On-Premises Cloud
Management Management
Do-it-Yourself
Cloud Cloud first IT Transformation
Operational Flexibility Monitoring Operational Simplicity

Cisco Physical Appliance


DNA
Center Virtual Appliance

High-Touch Low-Touch

© 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 107
Cloud Monitoring for Catalyst

Unified view of Cisco M


network infrastructure

Device health and


troubleshooting

Network client and


traffic information

© 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 108
Supported Platforms and Software
Firmware
IOS-XE 17.3+

Models
Catalyst
9200/L
9300/L/X Licensing
9500 DNA Advantage
DNA Essentials*

* DNA Essentials will not provide application or usage data

© 2022 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 109
Tiered/Hybrid Campus
Single Pane across Catalyst and Meraki

Meraki
Experience Catalyst
Experience

d
Clou ed
d
Clou d o n itor
M
an age Core
M ss
Acce
Centralized Monitoring
Catalyst Troubleshooting

MR M
9500

9200/9300

Port Cycle Ping


Tests
MAC Table
Firmware Upgrades*

* Roadmap
Distributed Branch
Catalyst Campus with Meraki Branches
M
Meraki Catalyst Meraki
Experience Experience Experience
M Cloud
Monitored
M
Campus

Cloud Cloud
Managed Managed
Branch Branch

* Roadmap
Thank
Thank you!
you!

You might also like