Professional Documents
Culture Documents
Nexus Hybrid Cloud
Nexus Hybrid Cloud
• BRKDCN-2671
• Introduction
• Challenges with Hybrid Cloud networking
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Introduction
What is Hybrid Cloud
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Introduction
• Private Cloud – On-prem Data Center
• Public Cloud – AWS, Azure, GCP
• Hybrid Cloud – Private Cloud + Public Cloud
• Hybrid Multi Cloud - Private Cloud + 2 or more Public Clouds
• Multi Cloud – Public Cloud + Public Cloud
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Hybrid Multicloud Networking – The requirements
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Challenges with
Hybrid Cloud
Networking
Network Admin Challenges
Heterogenous networks
No centralized control
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Network Admin Challenges
NX-OS ACI
Access-list (ACL) Contracts & Filters Security Group Security Rules Firewall Rules
Rules
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
What’s Cisco
Hybrid Cloud
Solution
Building Hybrid Multicloud
NDO 4.1(1)
NDFC 12.1.2e
VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM
Consistent
Secure Single Point of Automated Cloud Only
Network
Communication Orchestration Connectivity (Multi-Cloud)
and Policy
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Hybrid Cloud : Building Blocks
Cisco Cloud
Catalyst 8000v Network Nexus Dashboard
Controller
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Catalyst 8000v
• IOS-XE based Cloud Native Router
• SAAS offering (ISO, BIN, OVA, and QCOW2 formats)
• Available on CCO and Cloud Marketplace (PAYG or BYOL)
• Up to 10 Gbps of Throughput per instance
• VM requirement –
• CPU – 1 to 8 virtual CPUs
• Memory – 4 GB to 16 GB
• Disk space – 8 GB
• Two or more vNICs, up to maximum allowed by hypervisor
https://www.cisco.com/c/en/us/products/collateral/routers/catalyst-8000v-edge-
software/datasheet-c78-744101.html
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Reference slide
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Cisco Cloud Network Controller (CNC)
• Provides the ability to connect and consume public clouds,
accelerating business agility to support hybrid or multicloud
environments.
• Utilizes cloud-native constructs, the solution enables automation that
accelerates infrastructure deployment and governance and simplifies
management to easily connect workloads across multicloud
environments.
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Cisco Cloud Network Controller (CNC)
• Manage multiple regions through a single Cloud Network Controller
instance
• Provide secure interconnect for multi cloud environment and
automate network connectivity across multiple On Premises and
Public Cloud environments
• Enable Consistent Policy, Security and Operations between On-
Premises and Public Cloud environments
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Reference slide
L4-L7 services
• Automate service insertion Open APIs
and service chaining • Enable automation using
(load balancers, firewalls, …) Terraform and Ansible
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Cloud Network Controller
Public cloud policy mappings
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Cisco Cloud Network Controller
C8Kv C8Kv
TGW NLB
Connect TGW
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Powering automation
Cisco Nexus Dashboard Unified agile platform
Simple to automate, simple to consume
Cisco Nexus
Dashboard
Fabric Controller
Orchestrator
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Nexus Dashboard Fabric Controller
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Nexus Dashboard Orchestrator
Multi-site Orchestrator
NDO offers multi-site networking orchestration and policy management, disaster
recovery and high availability, as well as provisioning and health monitoring.
• Centralized deployment of –
• VRFs/Networks in on-prem VXLAN fabric
• VPCs/VNets in Cloud sites
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Hybrid Cloud : Under the Hood
Underlay (BGP/IPsec)
Overlay (Vxlan Multi-site)
BGP EVPN (Control-Plane)
NDFC
ASN: 65091 Cloud Network
ASN: 65084 ASN: 65080 Controller
Border
Gateway
Underlay
OverlayInternet/DC/ER
TGW
Spine On-prem
IPsec Router
us-west-1 Infra VPC
Leaf1 Leaf2
172.16.10.0/24 External fabric
VXLAN fabric
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Use-Cases
Stretched VRF
Schema: Stretched-VRF
Template: Template:
Stretched-VRF On-Prem
Spine
stretched-vrf
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Use-Cases
VRF Route Leaking
Schema: Route-leaking
Spine
Route Leaking
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Supported
Topologies
Supported Topologies VXLAN Multi-site
C8Kv C8Kv
Internet/DC/ER
C8Kv
Cisco
NDFC BGW
Spine
Leaf
On-Prem Site1
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Supported Topologies VXLAN Multi-site
C8Kv C8Kv
Internet/DC/ER
Cisco
NDFC BGW BGW BGW
C8Kv C8Kv
Internet/DC/ER
C8Kv
Cisco
NDFC BGW BGW BGW
Leaf Leaf
NLB
NDFC
Border
Gateway ASN: 65091 Cloud Network
Spine Controller
On-prem
IPsec Router
TGW
Leaf1 Leaf2
172.16.10.0/24 External fabric
us-west-1 Infra VPC
VXLAN fabric
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Topology
Step 1 : Build Underlay
NLB
NDFC
Border
Gateway Internet/DC/ER ASN: 65091 Cloud Network
Spine Controller
On-prem
IPsec Router
TGW
Leaf1 Leaf2
172.16.10.0/24 External fabric
us-west-1 Infra VPC
VXLAN fabric
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Topology
Step 2 : Build Underlay
eBGP
ASN: 65092 Cloud Network
OSPF Controller
NLB
NDFC
Border
Gateway Internet/DC/ER ASN: 65091 Cloud Network
Spine Controller
On-prem
IPsec Router
TGW
Leaf1 Leaf2
172.16.10.0/24 External fabric
us-west-1 Infra VPC
VXLAN fabric
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Topology
Step 2 : Build Overlay
eBGP
ASN: 65092 Cloud Network
OSPF Controller
BGP EVPN
NLB
NDFC
Border
Gateway Internet/DC/ER ASN: 65091 Cloud Network
Spine Controller
On-prem
IPsec Router
TGW
Leaf1 Leaf2
172.16.10.0/24 External fabric
us-west-1 Infra VPC
VXLAN fabric
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Topology
Step 3 : Deploy VRFs and Networks
NLB
East US
East US Infra VNet
NDFC
Border
Gateway Internet/DC/ER ASN: 65091 Cloud Network
Spine Controller
On-prem
IPsec Router VPC
TGW
Attachment
10.2.1.0/24
Leaf1 Leaf2
172.16.10.0/24
172.16.10.0/24 External fabric us-west-1
us-west-1 Infra VPC
VXLAN fabric
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
DEMO VIDEOS Demo Video
Further References
© 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Thank you