SlideShare a Scribd company logo
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Software Defined Access (SDA)
Transformational Approach to Network Design & Provisioning
Doan Nguyen Lam
Cisco Solution Engineer, Cisco Systems
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
What is Network about?
Today...In the past...
Voice
Video
Data
Mobility
Security
Cloud
IOT
Source: google.de images
Source: google.de images
What really matters !!!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Challenge.
“I want to design and deploy a network.”
Platform choices
Best practices
Manageable
Design options
On time
Future ready
Within budget
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Typical Traditional Campus
Data
Centre
WAN/BRANCH
Access
Points
Core
Switches
Aggregation
Switches
Access
Switches
WLC
ETHERCHANNEL
HSRP SPANNING TREECLI
L2/L3
AVC
VLANS
ACL
802.1x
FNF
Very powerful and feature
rich but:
- Complex to operate
- Difficult to scale
- Difficult to secure
- Inflexible and closed
architecture
- And you manage it all
with CLI…
Internet
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
How we build Traditional Network
Box by Box
Manual | Error Prone
ip domain-name cisco.local
no ip http server
ip http secure-server
ip ssh version 2
ip scp server enable
line vty 0 15
transport input ssh
transport preferred none
Manually
Repetitive Steps
CLI
Skill | Time | Effort
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Key Challenges for Traditional Networks
Difficult to Segment
Ever increasing number of
users and endpoint types
Ever increasing number of
VLANs and IP Subnets
Complex to Manage
Multiple steps,
user credentials, complex
interactions
Multiple touch-points
Slower Issue Resolution
Separate user policies for
wired and wireless networks
Unable to find users
when troubleshooting
Traditional Networks Cannot Keep Up!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco’s Intent-based Networking
Intent Context
Security
Learning
Network Infrastructure
DNA Center
AnalyticsPolicy Automation
Switching Routers Wireless
Powered by Intent.
Informed by Context.
The Network. Intuitive.
7
CISCO CONNECT 2018 . IT’S ALL YOU
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Intent-based Networking Model – Industry Approach
Activation
Physical and Virtual Infrastructure
Translation
Assurance
Orchestrate policies
& configure systems
Capture business intent,
translate to policies, and
check integrity Continuous verification,
insights & visibility, and
corrective actions
Cisco DNA
Intent-based Networking
Industry Initiative
8
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Automated
Network Fabric
Single Fabric for Wired & Wireless
with Workflow-based Automation
Insights
& Telemetry
Analytics and insights into
user and application behavior
Identity-based
Policy & Segmentation
Decoupled security policy definition
from VLAN and IP Address
Software-Defined Access
Networking at the speed of Software!
DNA Center
AnalyticsPolicy Automation
IoT Network Employee Network
SDA-Extension User Mobility
Policy stays with user
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
What is SD-Access?
Campus Fabric + DNA Center (Automation & Assurance)
APIC-EM
1.X
Campus
Fabric
ISE PI
Automation
Policy Assurance
DNA Center
B
C
B
 Campus Fabric
An Overlay network is a logical
topology used to virtually connect
devices
Separated management systems
 SD-Access
GUI approach provides
automation & assurance of all
Fabric configuration,
management and group-based
policy
DNA Center integrates multiple
systems, to orchestrate your
LAN, Wireless LAN and WAN
access
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Software-Defined Access
AssuranceAutomation Policy
Routers Switches Wireless AP WLC
DNA Center
DESIGN PROVISION POLICY ASSURANCE
DNA Center:
Simple Workflows
Solution Components
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
You Need a Network that Drives your Digital Business
With SDA Cisco Rewriting the Networking
Playbook
Hardware Centric Software Driven
Manual (eg CLI) Automated
Silo’ed Security Integrated Security
Network Monitoring Analytics and Insights
Historicaly Digital-Ready Network
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Network Design & Build Work Flow
Assure
Assure
Design
Network Hierarchy
Network Settings
Image Management
Network Profiles
Policy
Virtual Networks
Access Control
Application Priority
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Network Design & Build Work Flow
Assure
Provision Assure
Provision
Device Onboarding
Host Onboarding
Device Inventory
Fabric Administration
Assurance
Network Health Score
Client 360
Device 360
Application 360
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Syslog
Server
SDA Design in DNA Center – Global Setup
AAA
Server
Site1
North
America
South
America
Site2
Africa
EMEAR
AAA
Server
DNS
Server
Syslog
Server
DHCP
Server
• Ability to Define
Global Settings
once and
replicate to all
sites/devices
• Automated
Provisioning
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
L2 Switch
L3 Switch
Trunks
Trunk
BYOD Employee Contractor
One SSID
Production
Servers
AAA
DHCP
AD
WLAN
Developer
Servers
LAN Core
Multiple Steps and
Touch Points
1. Define Groups in AD
2. Define Policies
 VLAN/subnet based
3. Implement VLANs/Subnets
 Create VLANs
 Define DHCP scope
 Create subnets and L3 interfaces
 Routing for new subnets
 Map SSID to Interface/VLAN
4. Implement Policy
 Define ACLs
 Apply ACLs
5. Many different User Interfaces
AAA WLC Devices CLI
….
What if You Need to Add Another Group & Policy?
Network Segmentation Policy Rollout Today
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
How SDA Simplifies Network Segmentation
Access Layer
Enterprise
Backbone
Voice
VLAN
Voice
Data
VLAN
Employee
Aggregation Layer
Supplier
Guest
VLAN
BYOD
BYOD
VLAN
Non-Compliant
Quarantine
VLAN
VLAN
Address
DHCP Scope
Redundancy
Routing
Static ACL
VACL
Security Policy based on Topology
High cost and complex maintenance
Voice
VLAN
Voice
Data
VLAN
Employee Supplier BYODNon-Compliant
Use existing topology and automate
security policy to reduce OpEx
ISE
No VLAN Change
No Topology Change
Central Policy Provisioning
Micro/Macro Segmentation
Employee Tag
Supplier Tag
Non-Compliant Tag
Access Layer
Enterprise
Backbone
DC Firewall / Switch
DC Servers
Policy
TrustSecTraditional Segmentation
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Employees Contractors Production Development
Source Destination
FABRIC NODES
Contract
CISCO
DNA CENTER
CISCO ISE
FABRIC POLICIES
PERMIT
Employees Production
Employees Production
API
POLICY DOWNLOAD
SDA Segmentation Policy Automation
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Network quality is a complex, end-to-end problem
* Both = Join/roam and quality/throughput
APs
Local WLCs
Network services DCOffice site
ISE
DHCP
Mobile clients
CUCM
Client firmware
AP coverage
WAN Uplink usage
WAN QoS, Routing, ...
End-User services
RF Noise/Interf.
Client density
...
Cisco Prime™
Configuration
Addressing
Authentication
Affects Join/Roam
Affects Quality/Throughput
WLC Capacity
Affects Both*
Affects Both*Affects Both*
Affects Both*
Affects Both*
Affects Quality/Throughput
Affects Quality/Throughput Affects Join/Roam
Affects Join/Roam
WAN
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
When users complain about Application Problem
Wireless Network Issue
Increased Latency
WAN Network Issue
Application Problem
Server Problem
User Problem
Network is so
slow I cannot get
any work done
today
I do not see
anything
wrong
End Users
Network
Admin
What the users see What network admins see What can happen
ping – OK
show ip route - OK
traceroute - OK
show interface - OK
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Reverse Path
Lookup
SDA Assurance Path Visualization
Enhanced App Flow Visibility
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Global health - Network and clients
Application and compliance health require DNA advantage.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Global health : Floor-level health score
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Client/Sensor/Device health
360 view
offers
complete
troubleshooti
ng info on a
per client
basis.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Application performance troubleshooting
Application Health shows you top apps
with performance issues.
From landing, drill down App Health to see which
applications have issues
1 2
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Ready Platforms
ASR-1000-X
ASR-1000-HX
ISR 4430
ISR 4450
WIRELESSROUTINGSWITCHING
AIR-CT5520
AIR-CT8540
Wave 2 APs (1800, 2800,3800)
Wave 1 APs* (1700, 2700,3700)
Catalyst 9400
Catalyst 9300
Catalyst 9500
Catalyst 4500E Catalyst 6K Nexus 7700
Catalyst 3850 and 3650
AIR-CT3504
CSR 1000V
*with Caveats
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9000 Platform
World’s Most Advanced Enterprise Switches
Catalyst 9300
Fixed Access
Catalyst 9400
Modular Access
Catalyst 9500
Fixed Core
Programmable Mobile Ready
Cloud Ready
Design
Integrated Security
IoT Ready
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Catalyst 9K Family
Catalyst 9300
Catalyst 9400
Catalyst 9500
Stackable Access Modular Access Fixed Aggregation
Built on Cisco’s Innovative UADP ASIC & Open IOS-XE
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
4000+
Customers
Wins
Gaining Momentum with the Catalyst 9000!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Some Early Recognitions…
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9300
1G Data
mGig UPOE
1G UPOE/POE+
2.5G at the
Price of 1G
40G at the
Price of 10G
New Generation of Fixed Access
24 Ports
Modular Power SuppliesModular UplinksModular Fans
UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics (ETA)*
256 bit MACSEC*
Trustworthy Systems
StackWise Virtual*
IEEE1588 & AVB*
NBAR2
Perpetual/Fast PoE
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry
48 Ports
8x10G 2x40G 4x mGig 4x1G 350W 715W 1100W
Only
Stackable
Switch with 8X
10G Uplinks
Highest
2.5G/mGig
Density in the
Industry
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9400
New Generation of Modular Access
4-Slot* 7-Slot 10-Slot
Power Supply
3200W AC
3200W DC*
2400W AC*
Core Linecards
24x 10G SFP+*
48x1G SFP*
24x1G SFP*
Access Linecards
24xmGig + 24xUPOE*
48xUPoE
48xPoE+*
48xData
Supervisor
Sup-1: 80G/Slot Access Optimized
Sup-1XL*: 120G/Slot Core
Optimized
Redundancy
is now
Table-stake
Industry’s
Highest PoE
Scale
9Tbps
System
b/w
UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics*
256 bit MACSEC*
Trustworthy
Systems
StackWise Virtual*
IEEE1588 & AVB*
NBAR2
Perpetual PoE*
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry*
*not available at FCS
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9500
Catalyst 9500-40X
Catalyst 9500-24Q
Catalyst 9500-12Q
New Generation of Purpose Built Fixed Core/Aggregation UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics*
256 bit MACSEC*
Trustworthy
Systems
StackWise Virtual
IEEE1588 & AVB*
NBAR2
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry*
40G at the
Price of 10G
8X Buffering
vs.
Competition
Industry’s
First 40G
Enterprise
Switch
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Current three-tier packaging
IP Services
Full Layer 3 and Advanced Networking
IP Base
Traditional Access and Basic Layer 3 features
LAN Base
L2 Features
Simplified two-tier packaging
DNA Essentials
Simplified Network Operations Solution Package
DNA Advantage
Software Defined Access, Assurance and ETA
Solution Package
Network Advantage
Full L3 with flexible Segmentation and Network
Resiliency
Network Essentials
Competitive Parity with Full L2 and Routed Access
Catalyst 9K: Simplified packaging
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Single
SKU
Prime
DNA Advantage
(Includes DNA Essentials)
DNA EssentialsDNA Essentials
Single
SKU
DNA Essentials
Cat 9K w/ Network Advantage
(Full Layer 3 Routing)
Cat 9K w/ Network Essentials
(Layer 2 & Routed Access)
Base Automation & Monitoring SDA & Assurance Capable
Stealthwatch
Single
SKU
ISE Base + ISE Plus
DNA Advantage
(Includes DNA Essentials)
SDA & Assurance Ready
DNA Advantage
Cisco ONE Advantage
Catalyst 9K Switching Software
Must Attach Cisco ONE Advantage or DNA Advantage or DNA Essentials as Subscription with 9K
• Available in 3/5/7 year subscriptions
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

More Related Content

What's hot (20)

PDF
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
Cisco Canada
 
PDF
Cisco Connect Halifax 2018 Cisco dna - network intuitive
Cisco Canada
 
PDF
Cisco Connect Toronto 2018 sixty to zero
Cisco Canada
 
PDF
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
Cisco Canada
 
PDF
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Canada
 
PDF
Cisco Connect 2018 Philippines - introducing cisco dna assurance
NetworkCollaborators
 
PDF
Cisco Connect Vancouver 2017 - Cisco Meraki -Let Simple Work For You
Cisco Canada
 
PDF
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Canada
 
PDF
Cisco connect winnipeg 2018 introducing the network intuitive
Cisco Canada
 
PDF
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
Nur Shiqim Chok
 
PDF
Cisco connect winnipeg 2018 simply powerful networking with meraki
Cisco Canada
 
PDF
Cisco Connect Vancouver 2017 - Optimizing your client's wi fi experience
Cisco Canada
 
PDF
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Canada
 
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Canada
 
PDF
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Canada
 
PDF
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Canada
 
PDF
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco Canada
 
PPTX
Cisco connect winnipeg 2018 simple it leads to simple it management
Cisco Canada
 
PDF
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
Cisco Canada
 
PDF
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco Canada
 
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
Cisco Canada
 
Cisco Connect Halifax 2018 Cisco dna - network intuitive
Cisco Canada
 
Cisco Connect Toronto 2018 sixty to zero
Cisco Canada
 
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
Cisco Canada
 
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Canada
 
Cisco Connect 2018 Philippines - introducing cisco dna assurance
NetworkCollaborators
 
Cisco Connect Vancouver 2017 - Cisco Meraki -Let Simple Work For You
Cisco Canada
 
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco Canada
 
Cisco connect winnipeg 2018 introducing the network intuitive
Cisco Canada
 
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
Nur Shiqim Chok
 
Cisco connect winnipeg 2018 simply powerful networking with meraki
Cisco Canada
 
Cisco Connect Vancouver 2017 - Optimizing your client's wi fi experience
Cisco Canada
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Canada
 
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Canada
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Canada
 
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Canada
 
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco Canada
 
Cisco connect winnipeg 2018 simple it leads to simple it management
Cisco Canada
 
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
Cisco Canada
 
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco Canada
 

Similar to Cisco Connect 2018 Vietnam - Software-defined access-a transformational approach to network design and provisioning (20)

PDF
Cisco Connect 2018 Singapore - Cisco Software Defined Access
NetworkCollaborators
 
PDF
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
NetworkCollaborators
 
PPTX
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
NetworkCollaborators
 
PDF
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
NetworkCollaborators
 
PDF
Brkaci 1090
almaz tt
 
PDF
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
NetworkCollaborators
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PDF
Интуитивная сеть как платформа для надежного бизнеса
Cisco Russia
 
PDF
Cisco Connect 2018 Malaysia - introducing cisco dna assurance-the future of n...
NetworkCollaborators
 
PDF
Cisco Connect Ottawa 2018 data centre security
Cisco Canada
 
PDF
The Changing Data Center Landscape
Cisco Canada
 
PPTX
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 
PPTX
Cisco Connect 2018 Indonesia - Introducing cisco dna assurance
NetworkCollaborators
 
PDF
Application Centric Infrastructure (ACI), the policy driven data centre
Cisco Canada
 
PDF
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
NetworkCollaborators
 
PDF
Why Automate the Network?
Hank Preston
 
PPTX
Assuring Your SD-WAN to Deliver Unparalleled Digital Experiences
ThousandEyes
 
PPTX
Assuring Your SD-WAN to Deliver Unparalleled Digital Experiences
ThousandEyes
 
PPTX
Cisco Connect 2018 Indonesia - Delivering intent for data center networking
NetworkCollaborators
 
PDF
CISCO’s Cloud Journey (Keynote at Cloud Symposium)
Marcus McEwen
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
NetworkCollaborators
 
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
NetworkCollaborators
 
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
NetworkCollaborators
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
NetworkCollaborators
 
Brkaci 1090
almaz tt
 
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
NetworkCollaborators
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
Интуитивная сеть как платформа для надежного бизнеса
Cisco Russia
 
Cisco Connect 2018 Malaysia - introducing cisco dna assurance-the future of n...
NetworkCollaborators
 
Cisco Connect Ottawa 2018 data centre security
Cisco Canada
 
The Changing Data Center Landscape
Cisco Canada
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 
Cisco Connect 2018 Indonesia - Introducing cisco dna assurance
NetworkCollaborators
 
Application Centric Infrastructure (ACI), the policy driven data centre
Cisco Canada
 
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
NetworkCollaborators
 
Why Automate the Network?
Hank Preston
 
Assuring Your SD-WAN to Deliver Unparalleled Digital Experiences
ThousandEyes
 
Assuring Your SD-WAN to Deliver Unparalleled Digital Experiences
ThousandEyes
 
Cisco Connect 2018 Indonesia - Delivering intent for data center networking
NetworkCollaborators
 
CISCO’s Cloud Journey (Keynote at Cloud Symposium)
Marcus McEwen
 
Ad

More from NetworkCollaborators (20)

PDF
Cisco Connect 2018 Singapore - Cybersecurity strategy
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Cisco Incident Response Services
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Do more than keep the lights on
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - jordan koh
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Changing the Security Equation
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - The Network Intuitive
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Cisco CMX
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Easing the Transition
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Cisco SD-WAN
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - En06 jason pernell
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
NetworkCollaborators
 
PDF
Cisco Connect 2018 Singapore - delivering intent for data center networking
NetworkCollaborators
 
PDF
Cisco Connect 2018 Philippines - ben green
NetworkCollaborators
 
PDF
Cisco Connect 2018 Philippines - do more than keeping the lights on
NetworkCollaborators
 
PDF
Cisco Connect 2018 Philippines - jaymen quah
NetworkCollaborators
 
PDF
Cisco Connect 2018 Philippines - The workplace of the future
NetworkCollaborators
 
PDF
Cisco Connect 2018 Philippines - fay ocampo
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Cybersecurity strategy
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Cisco Incident Response Services
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Do more than keep the lights on
NetworkCollaborators
 
Cisco Connect 2018 Singapore - jordan koh
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Changing the Security Equation
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
NetworkCollaborators
 
Cisco Connect 2018 Singapore - The Network Intuitive
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Cisco CMX
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Easing the Transition
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Cisco SD-WAN
NetworkCollaborators
 
Cisco Connect 2018 Singapore - En06 jason pernell
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
NetworkCollaborators
 
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
NetworkCollaborators
 
Cisco Connect 2018 Singapore - delivering intent for data center networking
NetworkCollaborators
 
Cisco Connect 2018 Philippines - ben green
NetworkCollaborators
 
Cisco Connect 2018 Philippines - do more than keeping the lights on
NetworkCollaborators
 
Cisco Connect 2018 Philippines - jaymen quah
NetworkCollaborators
 
Cisco Connect 2018 Philippines - The workplace of the future
NetworkCollaborators
 
Cisco Connect 2018 Philippines - fay ocampo
NetworkCollaborators
 
Ad

Recently uploaded (20)

PPTX
Building a Production-Ready Barts Health Secure Data Environment Tooling, Acc...
Barts Health
 
PPTX
Top Managed Service Providers in Los Angeles
Captain IT
 
PDF
Français Patch Tuesday - Juillet
Ivanti
 
PPTX
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
PPTX
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
PDF
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
PPTX
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
PDF
July Patch Tuesday
Ivanti
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
Ampere Offers Energy-Efficient Future For AI And Cloud
ShapeBlue
 
PDF
Wojciech Ciemski for Top Cyber News MAGAZINE. June 2025
Dr. Ludmila Morozova-Buss
 
PPTX
Darren Mills The Migration Modernization Balancing Act: Navigating Risks and...
AWS Chicago
 
PDF
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PPT
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
PDF
Empowering Cloud Providers with Apache CloudStack and Stackbill
ShapeBlue
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PDF
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
Building a Production-Ready Barts Health Secure Data Environment Tooling, Acc...
Barts Health
 
Top Managed Service Providers in Los Angeles
Captain IT
 
Français Patch Tuesday - Juillet
Ivanti
 
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
July Patch Tuesday
Ivanti
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
Ampere Offers Energy-Efficient Future For AI And Cloud
ShapeBlue
 
Wojciech Ciemski for Top Cyber News MAGAZINE. June 2025
Dr. Ludmila Morozova-Buss
 
Darren Mills The Migration Modernization Balancing Act: Navigating Risks and...
AWS Chicago
 
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
Empowering Cloud Providers with Apache CloudStack and Stackbill
ShapeBlue
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 

Cisco Connect 2018 Vietnam - Software-defined access-a transformational approach to network design and provisioning

  • 1. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco Software Defined Access (SDA) Transformational Approach to Network Design & Provisioning Doan Nguyen Lam Cisco Solution Engineer, Cisco Systems
  • 2. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public What is Network about? Today...In the past... Voice Video Data Mobility Security Cloud IOT Source: google.de images Source: google.de images What really matters !!!
  • 3. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Challenge. “I want to design and deploy a network.” Platform choices Best practices Manageable Design options On time Future ready Within budget
  • 4. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Typical Traditional Campus Data Centre WAN/BRANCH Access Points Core Switches Aggregation Switches Access Switches WLC ETHERCHANNEL HSRP SPANNING TREECLI L2/L3 AVC VLANS ACL 802.1x FNF Very powerful and feature rich but: - Complex to operate - Difficult to scale - Difficult to secure - Inflexible and closed architecture - And you manage it all with CLI… Internet
  • 5. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU How we build Traditional Network Box by Box Manual | Error Prone ip domain-name cisco.local no ip http server ip http secure-server ip ssh version 2 ip scp server enable line vty 0 15 transport input ssh transport preferred none Manually Repetitive Steps CLI Skill | Time | Effort
  • 6. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Key Challenges for Traditional Networks Difficult to Segment Ever increasing number of users and endpoint types Ever increasing number of VLANs and IP Subnets Complex to Manage Multiple steps, user credentials, complex interactions Multiple touch-points Slower Issue Resolution Separate user policies for wired and wireless networks Unable to find users when troubleshooting Traditional Networks Cannot Keep Up!
  • 7. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco’s Intent-based Networking Intent Context Security Learning Network Infrastructure DNA Center AnalyticsPolicy Automation Switching Routers Wireless Powered by Intent. Informed by Context. The Network. Intuitive. 7 CISCO CONNECT 2018 . IT’S ALL YOU
  • 8. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Intent-based Networking Model – Industry Approach Activation Physical and Virtual Infrastructure Translation Assurance Orchestrate policies & configure systems Capture business intent, translate to policies, and check integrity Continuous verification, insights & visibility, and corrective actions Cisco DNA Intent-based Networking Industry Initiative 8
  • 9. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Automated Network Fabric Single Fabric for Wired & Wireless with Workflow-based Automation Insights & Telemetry Analytics and insights into user and application behavior Identity-based Policy & Segmentation Decoupled security policy definition from VLAN and IP Address Software-Defined Access Networking at the speed of Software! DNA Center AnalyticsPolicy Automation IoT Network Employee Network SDA-Extension User Mobility Policy stays with user
  • 10. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU What is SD-Access? Campus Fabric + DNA Center (Automation & Assurance) APIC-EM 1.X Campus Fabric ISE PI Automation Policy Assurance DNA Center B C B  Campus Fabric An Overlay network is a logical topology used to virtually connect devices Separated management systems  SD-Access GUI approach provides automation & assurance of all Fabric configuration, management and group-based policy DNA Center integrates multiple systems, to orchestrate your LAN, Wireless LAN and WAN access
  • 11. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Software-Defined Access AssuranceAutomation Policy Routers Switches Wireless AP WLC DNA Center DESIGN PROVISION POLICY ASSURANCE DNA Center: Simple Workflows Solution Components
  • 12. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU You Need a Network that Drives your Digital Business With SDA Cisco Rewriting the Networking Playbook Hardware Centric Software Driven Manual (eg CLI) Automated Silo’ed Security Integrated Security Network Monitoring Analytics and Insights Historicaly Digital-Ready Network
  • 13. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Network Design & Build Work Flow Assure Assure Design Network Hierarchy Network Settings Image Management Network Profiles Policy Virtual Networks Access Control Application Priority
  • 14. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Network Design & Build Work Flow Assure Provision Assure Provision Device Onboarding Host Onboarding Device Inventory Fabric Administration Assurance Network Health Score Client 360 Device 360 Application 360
  • 15. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Syslog Server SDA Design in DNA Center – Global Setup AAA Server Site1 North America South America Site2 Africa EMEAR AAA Server DNS Server Syslog Server DHCP Server • Ability to Define Global Settings once and replicate to all sites/devices • Automated Provisioning
  • 16. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public L2 Switch L3 Switch Trunks Trunk BYOD Employee Contractor One SSID Production Servers AAA DHCP AD WLAN Developer Servers LAN Core Multiple Steps and Touch Points 1. Define Groups in AD 2. Define Policies  VLAN/subnet based 3. Implement VLANs/Subnets  Create VLANs  Define DHCP scope  Create subnets and L3 interfaces  Routing for new subnets  Map SSID to Interface/VLAN 4. Implement Policy  Define ACLs  Apply ACLs 5. Many different User Interfaces AAA WLC Devices CLI …. What if You Need to Add Another Group & Policy? Network Segmentation Policy Rollout Today
  • 17. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU How SDA Simplifies Network Segmentation Access Layer Enterprise Backbone Voice VLAN Voice Data VLAN Employee Aggregation Layer Supplier Guest VLAN BYOD BYOD VLAN Non-Compliant Quarantine VLAN VLAN Address DHCP Scope Redundancy Routing Static ACL VACL Security Policy based on Topology High cost and complex maintenance Voice VLAN Voice Data VLAN Employee Supplier BYODNon-Compliant Use existing topology and automate security policy to reduce OpEx ISE No VLAN Change No Topology Change Central Policy Provisioning Micro/Macro Segmentation Employee Tag Supplier Tag Non-Compliant Tag Access Layer Enterprise Backbone DC Firewall / Switch DC Servers Policy TrustSecTraditional Segmentation
  • 18. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Employees Contractors Production Development Source Destination FABRIC NODES Contract CISCO DNA CENTER CISCO ISE FABRIC POLICIES PERMIT Employees Production Employees Production API POLICY DOWNLOAD SDA Segmentation Policy Automation
  • 19. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Network quality is a complex, end-to-end problem * Both = Join/roam and quality/throughput APs Local WLCs Network services DCOffice site ISE DHCP Mobile clients CUCM Client firmware AP coverage WAN Uplink usage WAN QoS, Routing, ... End-User services RF Noise/Interf. Client density ... Cisco Prime™ Configuration Addressing Authentication Affects Join/Roam Affects Quality/Throughput WLC Capacity Affects Both* Affects Both*Affects Both* Affects Both* Affects Both* Affects Quality/Throughput Affects Quality/Throughput Affects Join/Roam Affects Join/Roam WAN
  • 20. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU When users complain about Application Problem Wireless Network Issue Increased Latency WAN Network Issue Application Problem Server Problem User Problem Network is so slow I cannot get any work done today I do not see anything wrong End Users Network Admin What the users see What network admins see What can happen ping – OK show ip route - OK traceroute - OK show interface - OK
  • 21. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Reverse Path Lookup SDA Assurance Path Visualization Enhanced App Flow Visibility
  • 22. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Global health - Network and clients Application and compliance health require DNA advantage.
  • 23. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Global health : Floor-level health score
  • 24. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Client/Sensor/Device health 360 view offers complete troubleshooti ng info on a per client basis.
  • 25. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Application performance troubleshooting Application Health shows you top apps with performance issues. From landing, drill down App Health to see which applications have issues 1 2
  • 26. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Ready Platforms ASR-1000-X ASR-1000-HX ISR 4430 ISR 4450 WIRELESSROUTINGSWITCHING AIR-CT5520 AIR-CT8540 Wave 2 APs (1800, 2800,3800) Wave 1 APs* (1700, 2700,3700) Catalyst 9400 Catalyst 9300 Catalyst 9500 Catalyst 4500E Catalyst 6K Nexus 7700 Catalyst 3850 and 3650 AIR-CT3504 CSR 1000V *with Caveats
  • 27. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9000 Platform World’s Most Advanced Enterprise Switches Catalyst 9300 Fixed Access Catalyst 9400 Modular Access Catalyst 9500 Fixed Core Programmable Mobile Ready Cloud Ready Design Integrated Security IoT Ready
  • 28. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Catalyst 9K Family Catalyst 9300 Catalyst 9400 Catalyst 9500 Stackable Access Modular Access Fixed Aggregation Built on Cisco’s Innovative UADP ASIC & Open IOS-XE
  • 29. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU 4000+ Customers Wins Gaining Momentum with the Catalyst 9000!
  • 30. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Some Early Recognitions…
  • 31. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9300 1G Data mGig UPOE 1G UPOE/POE+ 2.5G at the Price of 1G 40G at the Price of 10G New Generation of Fixed Access 24 Ports Modular Power SuppliesModular UplinksModular Fans UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics (ETA)* 256 bit MACSEC* Trustworthy Systems StackWise Virtual* IEEE1588 & AVB* NBAR2 Perpetual/Fast PoE Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry 48 Ports 8x10G 2x40G 4x mGig 4x1G 350W 715W 1100W Only Stackable Switch with 8X 10G Uplinks Highest 2.5G/mGig Density in the Industry
  • 32. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9400 New Generation of Modular Access 4-Slot* 7-Slot 10-Slot Power Supply 3200W AC 3200W DC* 2400W AC* Core Linecards 24x 10G SFP+* 48x1G SFP* 24x1G SFP* Access Linecards 24xmGig + 24xUPOE* 48xUPoE 48xPoE+* 48xData Supervisor Sup-1: 80G/Slot Access Optimized Sup-1XL*: 120G/Slot Core Optimized Redundancy is now Table-stake Industry’s Highest PoE Scale 9Tbps System b/w UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics* 256 bit MACSEC* Trustworthy Systems StackWise Virtual* IEEE1588 & AVB* NBAR2 Perpetual PoE* Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry* *not available at FCS
  • 33. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9500 Catalyst 9500-40X Catalyst 9500-24Q Catalyst 9500-12Q New Generation of Purpose Built Fixed Core/Aggregation UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics* 256 bit MACSEC* Trustworthy Systems StackWise Virtual IEEE1588 & AVB* NBAR2 Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry* 40G at the Price of 10G 8X Buffering vs. Competition Industry’s First 40G Enterprise Switch
  • 34. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Current three-tier packaging IP Services Full Layer 3 and Advanced Networking IP Base Traditional Access and Basic Layer 3 features LAN Base L2 Features Simplified two-tier packaging DNA Essentials Simplified Network Operations Solution Package DNA Advantage Software Defined Access, Assurance and ETA Solution Package Network Advantage Full L3 with flexible Segmentation and Network Resiliency Network Essentials Competitive Parity with Full L2 and Routed Access Catalyst 9K: Simplified packaging
  • 35. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Single SKU Prime DNA Advantage (Includes DNA Essentials) DNA EssentialsDNA Essentials Single SKU DNA Essentials Cat 9K w/ Network Advantage (Full Layer 3 Routing) Cat 9K w/ Network Essentials (Layer 2 & Routed Access) Base Automation & Monitoring SDA & Assurance Capable Stealthwatch Single SKU ISE Base + ISE Plus DNA Advantage (Includes DNA Essentials) SDA & Assurance Ready DNA Advantage Cisco ONE Advantage Catalyst 9K Switching Software Must Attach Cisco ONE Advantage or DNA Advantage or DNA Essentials as Subscription with 9K • Available in 3/5/7 year subscriptions
  • 36. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential