SlideShare a Scribd company logo
Q&A
© 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 1 of 4
TechWiseTV Workshop: Cisco SD-WAN Security
May 8, 2019
Q. Can SD-WAN eliminate the requirement of network access control (NAC)?
A. If by NAC you mean user authentication, it is a multiphased story. Today it is based on 802.1X identity. In the
future you w ill be able to use scalable group tags (SGTs) for a more meaningful approach.
Q. How do you manage and control quality of service (QoS) (voice/video) over the internet part of SD-
WAN?
A. Many options are available: device QoS, routing based on SLA (app-aw are routing), link remediation like Fast
EtherChannel (FEC)/duplication, and also things like TCP optimization, fragmentation avoidance, and so on. Stay
tuned for more in the future.
Q. The central management software – are you referring to NMS?
A. It is Cisco® vManage, w hich manages all elements of SD-WAN and integrated security features.
Q. I assume it integrates with Cisco Prime® Infrastructure as well?
A. vManage is the single tool for everything SD-WAN.
Q. What type of zone-based firewall (ZBFW) is in use, and will he be going into more detail about how
branch routers drop packets from IPs that have not registered with the SD-WAN head end?
A. Stay tuned for much more detail from Kural.
Q. Does this or will it in the future be part of the Cisco Meraki® devices?
A. Meraki leverages some of the same security back-end repositories. Cisco has tw o different SD-WAN offerings,
each w ith integrated security.
Q. For internet-destined traffic, how does the SD-WAN security architecture stack up against a Cisco
Firepower® Threat Defense or ASA/Firepower device? What are the differences?
A. Good question! Cisco Firepow er Threat Defense/ASA are dedicated NGFWs, and they have some additional
capabilities. At the same time, both Cisco Firepow er Threat Defense/ASA and SD-WAN security have the same
back-end engines, such as Cisco Talos®. A feature-by-feature comparison is not appropriate.
Q. Are Viptela and Cisco SD-WAN one and the same now?
A. Cisco has tw o leading SD-WAN security solution options, one pow ered by Viptela and one pow ered by Meraki.
Q. Wait, I thought that the firewall used by SD-WAN was the Viptela zone-based firewall and not the Cisco
zone-based firewall. With that said, does that Garner Magic Quadrant reference still apply?
A. Cisco Secure SD-WAN includes Cisco Layer 3/Layer 4 app firew all/cloud-defined firew all. Yes, the Gartner
Magic Quadrant still applies. [[Please move the legal block below to the bottom of the last page. All you need here
© 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 2 of 4
is the copyright footer]]
Q. Does SD-WAN replace MPLS?
A. It can. SD-WAN is transport independent; it can run on top of any transport. Multiprotocol Label Sw itching
(MPLS) can still be used as the underlay for the SD-WAN overlay, alongside the internet and 4G/5G. SD-WAN is
transport agnostic, and it doesn’t replace MPLS. Instead, it encourages the customer to leverage the internet as
their second transport and run one single overlay over MPLS/Internet.
Q. What about control plane security? It’s all kind of hidden if you’re using vManage in the cloud. Support
for SAML, MFA, whitelisting of IP access, etc. seems to be a problem.
A. The control plane is the same w hether the solution is on-premises or cloud hosted. It has a zero-trust approach.
If you need more details, please reach out to your Cisco account team. The control plane communication betw een
vManage, vBond, vSmart, and the edge routers is secured using a Datagram Transport Layer Security (DTLS)
tunnel, w hich uses Advanced Encryption Standard (AES)-256 ciphers for encryption, and authentication is taken
care of w ith digital certificates.
Q. Our network has four main sites and four remote sites. Do you have different hardware router sizes for
main sites with higher bandwidth and lower-end routers for remote sites with lower bandwidth, at a lower
cost?
A. Absolutely! You can choose from any Cisco 1000 or 4000 Series ISR for branches. For higher scale at the
main sites, you may w ant to consider an ASR 1000-X or 1000-HX platform.
Q. What is the current device scalability for configuration pushes and device management? I’m coming
from a major enterprise with thousands of branches, close to 100 campus locations, and upwards of 100
data centers and co-locations.
A. The architecture easily scales to 10,000+ node systems, Viptela currently has the largest production SD-WAN
implementations, w ith customers running over 6000 nodes. Viptela also has the largest SD-WAN market share
among Global 2000 customers. We have production deployments at close to 10,000 sites. I am talking production
deployed today, not future planning. You are covered for deployments of any size.
Q. Is DNS Security via DNSSEC?
A. DNS Security means Cisco Umbrella®.
Q. What is the timeline to get full security in ASR and vEdge?
A. Some of the security features require containers, w hich are not there on all platforms. Full security is offered
on the Cisco 1000 and 4000 Series ISRs. vEdge and the ASR 1000 Series w illhave a subset of security features.
That said, some of the missing features can be augmented by Cisco Umbrella cloud security, w hich now also
supports Secure Internet Gatew ay (SIG), not just DNS-based security.
Q. Does SD-WAN support routing like Open Shortest Path First (OSPF) and Border Gateway Protocol
(BGP)?
A. Yes to both, plus Enhanced Interior Gatew ay Routing Protocol (EIGRP) on Cisco routing platforms.
Q. What kind of intrusion protection system (IPS) is native in the vEdge SD-WAN deployment?
A. We use Cisco Snort® IPS today, backed by Cisco Talos threat intelligence.
© 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 3 of 4
Q. We plan on using the ASR 1000 Series for 1 gig to 4 gig encryption. You are not planning to support
Umbrella there and want us to distribute that out somehow?
A. Cisco Umbrella monitoring is built into the Secure SD-WAN solution today. If you w ant to create a cloud
security policy, you w ill need to use a full Cisco Umbrella suite, w hich has API connectors to your routers. [[Please
delete the legal block above. It goes only on the last page. Copyright line should stay in footer]]
Q. Will vManage apply to Meraki users as well?
A. No, Meraki has its ow n management platform.
Q. What code are you running for vManage and on vEdge?
A. The latest. Version 19.1 on controllers and 16.11.1 on Cisco IOS® XE SD-WAN routers. We are not show ing
vEdge here; that has a subset of this functionality.
Q. What web browsers can be used to view vManage without any quirks?
A. I use Chrome.
Q. How about EIGRP on vEdge?
A. EIGRP is not planned for vEdge. vEdge can do OSPF and BGP.
Q. Is there a way to see statistics for more than seven days?
A. Absolutely! You can choose to go as far back as the data is held in the vManage stats database. It's based on
the database size configured.
Q. Is this the Cisco Firepower Threat Defense firewall or the router zone-based firewall?
A. This is using the DNS Layer cloud-defined app firew all, not the Firepow er Threat Defense NGFW.
Q. Can you load-balance per flow on multiple SD-WAN links? if so, is packet order correction available?
A. Yes, w e do per-flow routing. We do not do reordering on the routers.
Q. We have Cisco Firepower on our edge and in our data center. Do we need SD-WAN Security?
A. You can't compare SD-WAN Security w ith a firew all. The security part of SD-WAN Security is integrated w ithin
the SD-WAN platform and does not exist outside of it.
Q. So Viptela now has an incorporated firewall feature, or is it service chaining to a firewall?
A. What Kural is describing are security features integrated into SD-WAN and managed by vManage. You of
course still have an option of service insertion. You can do both at the same time too.
Q. How does this address zero-day attacks?
A. The Cisco Talos cloud receives something like 20 billion events a day. IPS and AMP are integrated w ith Talos,
so you can enjoy all this threat intelligence.
Q. What products are required to be able to create this ecosystem?
A. It’s all integrated. All you need is Cisco SD-WAN pow ered by Viptela and an appropriate subscription Cisco
DNA license.
Q. Can events still be logged to an external SIEM tool, such as Splunk, Embedded Syslog Manager (ESM),
etc., for further review or event correlation?
A. Yes, they can. We generate syslogs, but they are rate limited to protect the router CPU. We can also export
events in NetFlow v9 format, but you need a receiver that can parse it. Check out Cisco Stealthw atch.
Q. Is SD-WAN managed by vManage – both the ISR/ASR and the VEdge platforms?
A. Yes. You can manage netw orking and security on all those platforms via vManage.
Q. So alerting is handled by other apps versus vManage?
A. Please define alerting. Each device alerts vManage but can also generate messages to an external system.
© 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 4 of 4
Q. So all security platforms that Cisco has – ASA , Cisco’s NGFW, IPS, etc.
A. No. You can manage SD-WAN Security via vManage on ISRs, ASRs, CSRs, and vEdge platforms.
Q. How impactful to production is it normally to get existing devices and network tied into SD-WAN?
(Assuming you already have supported routers, etc.)
A. It is as simple as buying a Cisco DNA license and upgrading existing routers to the Cisco IOS XE SD-WAN
code. Of course, you need to consider communication to nonmigrated sites. This requires planning ahead of time.
Q. Does vManage have an API that can be accessed? Is it read and write?
A. EVERYTHING in vManage can be done using REST APIs! Full read and w rite.
Q. What is a common way for SD-WAN converted sites to communicate with non-SD-WAN converted
sites? Would they route to some head-end device and be routed from there?
A. Yes, this is the recommended approach. Some customers do direct connection at each migrated site. It is
dangerous and can cause routing loops if the administrator is not careful, but it can be done. To minimize latency,
w e advocate establishing several transition hubs w here overlay and underlay are inter-routed.
Q. Can the block page be redirected to a page that provides information vs. just a giving a blank page to
the user?
A. This is part of our future serviceability enhancements. Today it’s session reset for AMP. For URL filtering, you
can present a page.
Q. Does Role-Based Access Control (RBAC) have support for external groups like AD, RADIUS, and
TACACS?
A. Yes. You can use SSO or RADIUS/TACACS. Your Active Directory can be integrated to those.
Q. Is there any technical documentation on SD-WAN QoS in detail?
A. Check sdw an-docs.cisco.comand ciscolive.com.
Q. Wait, we have ZBFW in our ISR and ASRs now .
A. ZBFW w as there in Cisco IOS XE. We have enabled it in SD-WAN managed by vManage. We have also
added Layer 7 intelligence to it.
Q. Is Secure Sockets Layer (SSL) decryption available for traffic inspection?
A. Not today, but stay tuned.
Q. We're running a Cisco iWAN DMVPN overlay right now with fully licensed 4000 Series ISRs at the
branch level. Are there any licensing considerations when moving to Vipte la?
A. Yes! Please talk to your Cisco account team.
Q. Will this be a parity feature with Cisco Meraki?
A. We are not after feature parity, w e are after solving customer problems. Choose the solution that fits your
needs.
Q. Would this solution replace or supplement Firepower?
A. Yes, and it depends. If you are using the SD-WAN solution and have been using additional firew alls for its
security, you can use the current integrated security instead of a firew all.
Q. Can you load-balance a single flow over two separate links?
A. No. This is a very bad practice that some other SD-WAN vendors are promoting. It makes a great demo but
can introduce severe performance issues.
Q. Is the policy configuration as granular?
A. We have not yet found a request that w e have not been able to build a policy for. Trust me, w e have seen
some really crazy ones out there.
Ad

More Related Content

What's hot (20)

Data Centre Portfolio Update
Data Centre Portfolio UpdateData Centre Portfolio Update
Data Centre Portfolio Update
Cisco Canada
 
Cisco Catalyst 9000 Switching Family
Cisco Catalyst 9000 Switching FamilyCisco Catalyst 9000 Switching Family
Cisco Catalyst 9000 Switching Family
Mobeen Khan
 
TCO Case Study - Cisco and Huawei L2 Switches
TCO Case Study - Cisco and Huawei L2 SwitchesTCO Case Study - Cisco and Huawei L2 Switches
TCO Case Study - Cisco and Huawei L2 Switches
IT Brand Pulse
 
Sudharsan rangasamy resume
Sudharsan rangasamy resumeSudharsan rangasamy resume
Sudharsan rangasamy resume
Sudharsan Rangasamy
 
What you can do with cisco avb
What you can do with cisco avbWhat you can do with cisco avb
What you can do with cisco avb
IT Tech
 
CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...
CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...
CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...
AreaNetworking.it
 
Cisco avb switches
Cisco avb switchesCisco avb switches
Cisco avb switches
IT Tech
 
CCTV - DVR vs NVR - what’s the difference
CCTV - DVR vs NVR - what’s the differenceCCTV - DVR vs NVR - what’s the difference
CCTV - DVR vs NVR - what’s the difference
Gary Crilly, RCDD/OSP
 
Innovations in the Enterprise Routing & Switching Space
Innovations in the Enterprise Routing & Switching SpaceInnovations in the Enterprise Routing & Switching Space
Innovations in the Enterprise Routing & Switching Space
Cisco Canada
 
Simplifying Cloud Adoption with Cisco
Simplifying Cloud Adoption with CiscoSimplifying Cloud Adoption with Cisco
Simplifying Cloud Adoption with Cisco
Cisco Canada
 
The latest isr 4000 model comparison
The latest isr 4000 model comparisonThe latest isr 4000 model comparison
The latest isr 4000 model comparison
IT Tech
 
Cisco one advanced security
Cisco one advanced securityCisco one advanced security
Cisco one advanced security
IT Tech
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Canada
 
Presentation cisco plus tech datacenter virtualisering
Presentation   cisco plus tech datacenter virtualiseringPresentation   cisco plus tech datacenter virtualisering
Presentation cisco plus tech datacenter virtualisering
xKinAnx
 
Cisco A9K-MOD80-TR
Cisco A9K-MOD80-TRCisco A9K-MOD80-TR
Cisco A9K-MOD80-TR
savomir
 
Cisco ucs s3260 the new storage building blocks
Cisco ucs s3260 the new storage building blocksCisco ucs s3260 the new storage building blocks
Cisco ucs s3260 the new storage building blocks
IT Tech
 
Ciscomigration20100602 12769954370856-phpapp02
Ciscomigration20100602 12769954370856-phpapp02Ciscomigration20100602 12769954370856-phpapp02
Ciscomigration20100602 12769954370856-phpapp02
Veerapong Khumpilee
 
Cisco Product Migration options
Cisco Product Migration optionsCisco Product Migration options
Cisco Product Migration options
DCom82
 
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
Robb Boyd
 
TechWiseTV Workshop: Programmable ASICs
TechWiseTV Workshop: Programmable ASICsTechWiseTV Workshop: Programmable ASICs
TechWiseTV Workshop: Programmable ASICs
Robb Boyd
 
Data Centre Portfolio Update
Data Centre Portfolio UpdateData Centre Portfolio Update
Data Centre Portfolio Update
Cisco Canada
 
Cisco Catalyst 9000 Switching Family
Cisco Catalyst 9000 Switching FamilyCisco Catalyst 9000 Switching Family
Cisco Catalyst 9000 Switching Family
Mobeen Khan
 
TCO Case Study - Cisco and Huawei L2 Switches
TCO Case Study - Cisco and Huawei L2 SwitchesTCO Case Study - Cisco and Huawei L2 Switches
TCO Case Study - Cisco and Huawei L2 Switches
IT Brand Pulse
 
What you can do with cisco avb
What you can do with cisco avbWhat you can do with cisco avb
What you can do with cisco avb
IT Tech
 
CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...
CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...
CisCon 2017 - I problemi di scalabilità delle tradizionali reti IP nei modern...
AreaNetworking.it
 
Cisco avb switches
Cisco avb switchesCisco avb switches
Cisco avb switches
IT Tech
 
CCTV - DVR vs NVR - what’s the difference
CCTV - DVR vs NVR - what’s the differenceCCTV - DVR vs NVR - what’s the difference
CCTV - DVR vs NVR - what’s the difference
Gary Crilly, RCDD/OSP
 
Innovations in the Enterprise Routing & Switching Space
Innovations in the Enterprise Routing & Switching SpaceInnovations in the Enterprise Routing & Switching Space
Innovations in the Enterprise Routing & Switching Space
Cisco Canada
 
Simplifying Cloud Adoption with Cisco
Simplifying Cloud Adoption with CiscoSimplifying Cloud Adoption with Cisco
Simplifying Cloud Adoption with Cisco
Cisco Canada
 
The latest isr 4000 model comparison
The latest isr 4000 model comparisonThe latest isr 4000 model comparison
The latest isr 4000 model comparison
IT Tech
 
Cisco one advanced security
Cisco one advanced securityCisco one advanced security
Cisco one advanced security
IT Tech
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Canada
 
Presentation cisco plus tech datacenter virtualisering
Presentation   cisco plus tech datacenter virtualiseringPresentation   cisco plus tech datacenter virtualisering
Presentation cisco plus tech datacenter virtualisering
xKinAnx
 
Cisco A9K-MOD80-TR
Cisco A9K-MOD80-TRCisco A9K-MOD80-TR
Cisco A9K-MOD80-TR
savomir
 
Cisco ucs s3260 the new storage building blocks
Cisco ucs s3260 the new storage building blocksCisco ucs s3260 the new storage building blocks
Cisco ucs s3260 the new storage building blocks
IT Tech
 
Ciscomigration20100602 12769954370856-phpapp02
Ciscomigration20100602 12769954370856-phpapp02Ciscomigration20100602 12769954370856-phpapp02
Ciscomigration20100602 12769954370856-phpapp02
Veerapong Khumpilee
 
Cisco Product Migration options
Cisco Product Migration optionsCisco Product Migration options
Cisco Product Migration options
DCom82
 
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
Robb Boyd
 
TechWiseTV Workshop: Programmable ASICs
TechWiseTV Workshop: Programmable ASICsTechWiseTV Workshop: Programmable ASICs
TechWiseTV Workshop: Programmable ASICs
Robb Boyd
 

Similar to TechWiseTV Workshop 314 - Q&A Cisco SD-WAN Security (20)

Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...
Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...
Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...
IT Tech
 
TechWiseTV Workshop: Q&A OpenDNS and AnyConnect
TechWiseTV Workshop: Q&A OpenDNS and AnyConnect TechWiseTV Workshop: Q&A OpenDNS and AnyConnect
TechWiseTV Workshop: Q&A OpenDNS and AnyConnect
Robb Boyd
 
Q&A from our Cisco One Workshop
Q&A from our Cisco One WorkshopQ&A from our Cisco One Workshop
Q&A from our Cisco One Workshop
Robb Boyd
 
MX Deep Dive PPT
MX Deep Dive PPTMX Deep Dive PPT
MX Deep Dive PPT
omar awad
 
Sdwan webinar
Sdwan webinarSdwan webinar
Sdwan webinar
pmohapat
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Canada
 
Q&A for TechWiseTV Workshop: HyperFlex
Q&A for TechWiseTV Workshop: HyperFlexQ&A for TechWiseTV Workshop: HyperFlex
Q&A for TechWiseTV Workshop: HyperFlex
Robb Boyd
 
Ip san-best-practices-en
Ip san-best-practices-enIp san-best-practices-en
Ip san-best-practices-en
Oscar Gil Merino
 
How to Secure Multi-Cloud through SD-WAN
How to Secure Multi-Cloud through SD-WANHow to Secure Multi-Cloud through SD-WAN
How to Secure Multi-Cloud through SD-WAN
Digital Carbon
 
Cisco SD-Wan introduction and caracteristics.pdf
Cisco SD-Wan introduction and caracteristics.pdfCisco SD-Wan introduction and caracteristics.pdf
Cisco SD-Wan introduction and caracteristics.pdf
ssuser8cfe271
 
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdfISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
SebastianMolinaFerna
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
Cisco Canada
 
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
NetworkCollaborators
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
Cisco Canada
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined Access
NetworkCollaborators
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
NetworkCollaborators
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 
Simplifying the secure data center
Simplifying the secure data centerSimplifying the secure data center
Simplifying the secure data center
Cisco Canada
 
Abdullah 2015 RESUM
Abdullah 2015 RESUMAbdullah 2015 RESUM
Abdullah 2015 RESUM
Shaik Abdullah
 
Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...
Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...
Cisco adaptive security appliance (asa) firewalls lifeline of today’s data ce...
IT Tech
 
TechWiseTV Workshop: Q&A OpenDNS and AnyConnect
TechWiseTV Workshop: Q&A OpenDNS and AnyConnect TechWiseTV Workshop: Q&A OpenDNS and AnyConnect
TechWiseTV Workshop: Q&A OpenDNS and AnyConnect
Robb Boyd
 
Q&A from our Cisco One Workshop
Q&A from our Cisco One WorkshopQ&A from our Cisco One Workshop
Q&A from our Cisco One Workshop
Robb Boyd
 
MX Deep Dive PPT
MX Deep Dive PPTMX Deep Dive PPT
MX Deep Dive PPT
omar awad
 
Sdwan webinar
Sdwan webinarSdwan webinar
Sdwan webinar
pmohapat
 
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WANCisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Connect Toronto 2017 - Understanding Cisco Next Generation SD-WAN
Cisco Canada
 
Q&A for TechWiseTV Workshop: HyperFlex
Q&A for TechWiseTV Workshop: HyperFlexQ&A for TechWiseTV Workshop: HyperFlex
Q&A for TechWiseTV Workshop: HyperFlex
Robb Boyd
 
How to Secure Multi-Cloud through SD-WAN
How to Secure Multi-Cloud through SD-WANHow to Secure Multi-Cloud through SD-WAN
How to Secure Multi-Cloud through SD-WAN
Digital Carbon
 
Cisco SD-Wan introduction and caracteristics.pdf
Cisco SD-Wan introduction and caracteristics.pdfCisco SD-Wan introduction and caracteristics.pdf
Cisco SD-Wan introduction and caracteristics.pdf
ssuser8cfe271
 
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdfISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
ISR1100_and_ISR1100X_Series_Workshop_Session_III.pdf
SebastianMolinaFerna
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
Cisco Canada
 
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
NetworkCollaborators
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
Cisco Canada
 
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined AccessCisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Singapore - Cisco Software Defined Access
NetworkCollaborators
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...Cisco Connect 2018 Indonesia -  software-defined access-a transformational ap...
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
NetworkCollaborators
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 
Simplifying the secure data center
Simplifying the secure data centerSimplifying the secure data center
Simplifying the secure data center
Cisco Canada
 
Ad

More from Robb Boyd (20)

Enterprise-Grade Trust: Collaboration Without Compromise
Enterprise-Grade Trust: Collaboration Without CompromiseEnterprise-Grade Trust: Collaboration Without Compromise
Enterprise-Grade Trust: Collaboration Without Compromise
Robb Boyd
 
TechWiseTV Workshop: Application Hosting on Catalyst 9000 Series Switches
TechWiseTV Workshop: Application Hosting on Catalyst 9000 Series SwitchesTechWiseTV Workshop: Application Hosting on Catalyst 9000 Series Switches
TechWiseTV Workshop: Application Hosting on Catalyst 9000 Series Switches
Robb Boyd
 
The Enhanced Cisco Container Platform
The Enhanced Cisco Container PlatformThe Enhanced Cisco Container Platform
The Enhanced Cisco Container Platform
Robb Boyd
 
TechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlex
TechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlexTechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlex
TechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlex
Robb Boyd
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
Robb Boyd
 
TechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless Controller
TechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless ControllerTechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless Controller
TechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless Controller
Robb Boyd
 
Protect Kubernetes Environments with Cisco Stealthwatch Cloud
Protect Kubernetes Environments with Cisco Stealthwatch CloudProtect Kubernetes Environments with Cisco Stealthwatch Cloud
Protect Kubernetes Environments with Cisco Stealthwatch Cloud
Robb Boyd
 
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIsIncredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Robb Boyd
 
Infrastructure Solutions for Deploying AI/ML/DL Workloads at Scale
Infrastructure Solutions for Deploying AI/ML/DL Workloads at ScaleInfrastructure Solutions for Deploying AI/ML/DL Workloads at Scale
Infrastructure Solutions for Deploying AI/ML/DL Workloads at Scale
Robb Boyd
 
TechWiseTV Workshop Q&A: Cisco UCS C4200
TechWiseTV Workshop Q&A: Cisco UCS C4200TechWiseTV Workshop Q&A: Cisco UCS C4200
TechWiseTV Workshop Q&A: Cisco UCS C4200
Robb Boyd
 
TechWiseTV Workshop: Cisco UCS C4200
TechWiseTV Workshop: Cisco UCS C4200TechWiseTV Workshop: Cisco UCS C4200
TechWiseTV Workshop: Cisco UCS C4200
Robb Boyd
 
TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000
Robb Boyd
 
TechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google Cloud
Robb Boyd
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
Robb Boyd
 
TechWiseTV Workshop: Extending Intent-Based Networking to IoT
TechWiseTV Workshop: Extending Intent-Based Networking to IoTTechWiseTV Workshop: Extending Intent-Based Networking to IoT
TechWiseTV Workshop: Extending Intent-Based Networking to IoT
Robb Boyd
 
TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...
TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...
TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...
Robb Boyd
 
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
Robb Boyd
 
Software Subscription for Enterprise Routing
Software Subscription for Enterprise RoutingSoftware Subscription for Enterprise Routing
Software Subscription for Enterprise Routing
Robb Boyd
 
TechWiseTV Workshop: Q&A HyperFlex 3.0
TechWiseTV Workshop: Q&A HyperFlex 3.0TechWiseTV Workshop: Q&A HyperFlex 3.0
TechWiseTV Workshop: Q&A HyperFlex 3.0
Robb Boyd
 
TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture
TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture
TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture
Robb Boyd
 
Enterprise-Grade Trust: Collaboration Without Compromise
Enterprise-Grade Trust: Collaboration Without CompromiseEnterprise-Grade Trust: Collaboration Without Compromise
Enterprise-Grade Trust: Collaboration Without Compromise
Robb Boyd
 
TechWiseTV Workshop: Application Hosting on Catalyst 9000 Series Switches
TechWiseTV Workshop: Application Hosting on Catalyst 9000 Series SwitchesTechWiseTV Workshop: Application Hosting on Catalyst 9000 Series Switches
TechWiseTV Workshop: Application Hosting on Catalyst 9000 Series Switches
Robb Boyd
 
The Enhanced Cisco Container Platform
The Enhanced Cisco Container PlatformThe Enhanced Cisco Container Platform
The Enhanced Cisco Container Platform
Robb Boyd
 
TechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlex
TechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlexTechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlex
TechWiseTV Workshop: Improving Performance and Agility with Cisco HyperFlex
Robb Boyd
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
Robb Boyd
 
TechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless Controller
TechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless ControllerTechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless Controller
TechWiseTV Workshop: Cisco Catalyst 9800 Series Wireless Controller
Robb Boyd
 
Protect Kubernetes Environments with Cisco Stealthwatch Cloud
Protect Kubernetes Environments with Cisco Stealthwatch CloudProtect Kubernetes Environments with Cisco Stealthwatch Cloud
Protect Kubernetes Environments with Cisco Stealthwatch Cloud
Robb Boyd
 
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIsIncredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Robb Boyd
 
Infrastructure Solutions for Deploying AI/ML/DL Workloads at Scale
Infrastructure Solutions for Deploying AI/ML/DL Workloads at ScaleInfrastructure Solutions for Deploying AI/ML/DL Workloads at Scale
Infrastructure Solutions for Deploying AI/ML/DL Workloads at Scale
Robb Boyd
 
TechWiseTV Workshop Q&A: Cisco UCS C4200
TechWiseTV Workshop Q&A: Cisco UCS C4200TechWiseTV Workshop Q&A: Cisco UCS C4200
TechWiseTV Workshop Q&A: Cisco UCS C4200
Robb Boyd
 
TechWiseTV Workshop: Cisco UCS C4200
TechWiseTV Workshop: Cisco UCS C4200TechWiseTV Workshop: Cisco UCS C4200
TechWiseTV Workshop: Cisco UCS C4200
Robb Boyd
 
TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000
Robb Boyd
 
TechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Q&A Cisco Hybrid Cloud Platform for Google Cloud
Robb Boyd
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
Robb Boyd
 
TechWiseTV Workshop: Extending Intent-Based Networking to IoT
TechWiseTV Workshop: Extending Intent-Based Networking to IoTTechWiseTV Workshop: Extending Intent-Based Networking to IoT
TechWiseTV Workshop: Extending Intent-Based Networking to IoT
Robb Boyd
 
TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...
TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...
TechWiseTV Workshop: Cisco Catalyst 9500 Series High-Performance Switch Archi...
Robb Boyd
 
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google CloudTechWiseTV Workshop:  Cisco Hybrid Cloud Platform for Google Cloud
TechWiseTV Workshop: Cisco Hybrid Cloud Platform for Google Cloud
Robb Boyd
 
Software Subscription for Enterprise Routing
Software Subscription for Enterprise RoutingSoftware Subscription for Enterprise Routing
Software Subscription for Enterprise Routing
Robb Boyd
 
TechWiseTV Workshop: Q&A HyperFlex 3.0
TechWiseTV Workshop: Q&A HyperFlex 3.0TechWiseTV Workshop: Q&A HyperFlex 3.0
TechWiseTV Workshop: Q&A HyperFlex 3.0
Robb Boyd
 
TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture
TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture
TechWiseTV Workshop: Cisco Aironet 4800 Access Point with Intelligent Capture
Robb Boyd
 
Ad

Recently uploaded (20)

IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...
IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...
IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...
organizerofv
 
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In FranceManifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
chb3
 
Special Meetup Edition - TDX Bengaluru Meetup #52.pptx
Special Meetup Edition - TDX Bengaluru Meetup #52.pptxSpecial Meetup Edition - TDX Bengaluru Meetup #52.pptx
Special Meetup Edition - TDX Bengaluru Meetup #52.pptx
shyamraj55
 
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
BookNet Canada
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...
Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...
Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...
Noah Loul
 
Electronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploitElectronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploit
niftliyevhuseyn
 
TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...
TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...
TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...
TrustArc
 
How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?
Daniel Lehner
 
Cybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure ADCybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure AD
VICTOR MAESTRE RAMIREZ
 
Andrew Marnell: Transforming Business Strategy Through Data-Driven Insights
Andrew Marnell: Transforming Business Strategy Through Data-Driven InsightsAndrew Marnell: Transforming Business Strategy Through Data-Driven Insights
Andrew Marnell: Transforming Business Strategy Through Data-Driven Insights
Andrew Marnell
 
HCL Nomad Web – Best Practices and Managing Multiuser Environments
HCL Nomad Web – Best Practices and Managing Multiuser EnvironmentsHCL Nomad Web – Best Practices and Managing Multiuser Environments
HCL Nomad Web – Best Practices and Managing Multiuser Environments
panagenda
 
Drupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy ConsumptionDrupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy Consumption
Exove
 
Heap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and DeletionHeap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and Deletion
Jaydeep Kale
 
2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx
Samuele Fogagnolo
 
Quantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur MorganQuantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded DevelopersLinux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Toradex
 
Linux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdfLinux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdf
RHCSA Guru
 
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdfComplete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Software Company
 
Procurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptxProcurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptx
Jon Hansen
 
IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...
IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...
IEDM 2024 Tutorial2_Advances in CMOS Technologies and Future Directions for C...
organizerofv
 
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In FranceManifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
chb3
 
Special Meetup Edition - TDX Bengaluru Meetup #52.pptx
Special Meetup Edition - TDX Bengaluru Meetup #52.pptxSpecial Meetup Edition - TDX Bengaluru Meetup #52.pptx
Special Meetup Edition - TDX Bengaluru Meetup #52.pptx
shyamraj55
 
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
#StandardsGoals for 2025: Standards & certification roundup - Tech Forum 2025
BookNet Canada
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...
Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...
Noah Loul Shares 5 Steps to Implement AI Agents for Maximum Business Efficien...
Noah Loul
 
Electronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploitElectronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploit
niftliyevhuseyn
 
TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...
TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...
TrustArc Webinar: Consumer Expectations vs Corporate Realities on Data Broker...
TrustArc
 
How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?
Daniel Lehner
 
Cybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure ADCybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure AD
VICTOR MAESTRE RAMIREZ
 
Andrew Marnell: Transforming Business Strategy Through Data-Driven Insights
Andrew Marnell: Transforming Business Strategy Through Data-Driven InsightsAndrew Marnell: Transforming Business Strategy Through Data-Driven Insights
Andrew Marnell: Transforming Business Strategy Through Data-Driven Insights
Andrew Marnell
 
HCL Nomad Web – Best Practices and Managing Multiuser Environments
HCL Nomad Web – Best Practices and Managing Multiuser EnvironmentsHCL Nomad Web – Best Practices and Managing Multiuser Environments
HCL Nomad Web – Best Practices and Managing Multiuser Environments
panagenda
 
Drupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy ConsumptionDrupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy Consumption
Exove
 
Heap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and DeletionHeap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and Deletion
Jaydeep Kale
 
2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx2025-05-Q4-2024-Investor-Presentation.pptx
2025-05-Q4-2024-Investor-Presentation.pptx
Samuele Fogagnolo
 
Quantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur MorganQuantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded DevelopersLinux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Toradex
 
Linux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdfLinux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdf
RHCSA Guru
 
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdfComplete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Software Company
 
Procurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptxProcurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptx
Jon Hansen
 

TechWiseTV Workshop 314 - Q&A Cisco SD-WAN Security

  • 1. Q&A © 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 1 of 4 TechWiseTV Workshop: Cisco SD-WAN Security May 8, 2019 Q. Can SD-WAN eliminate the requirement of network access control (NAC)? A. If by NAC you mean user authentication, it is a multiphased story. Today it is based on 802.1X identity. In the future you w ill be able to use scalable group tags (SGTs) for a more meaningful approach. Q. How do you manage and control quality of service (QoS) (voice/video) over the internet part of SD- WAN? A. Many options are available: device QoS, routing based on SLA (app-aw are routing), link remediation like Fast EtherChannel (FEC)/duplication, and also things like TCP optimization, fragmentation avoidance, and so on. Stay tuned for more in the future. Q. The central management software – are you referring to NMS? A. It is Cisco® vManage, w hich manages all elements of SD-WAN and integrated security features. Q. I assume it integrates with Cisco Prime® Infrastructure as well? A. vManage is the single tool for everything SD-WAN. Q. What type of zone-based firewall (ZBFW) is in use, and will he be going into more detail about how branch routers drop packets from IPs that have not registered with the SD-WAN head end? A. Stay tuned for much more detail from Kural. Q. Does this or will it in the future be part of the Cisco Meraki® devices? A. Meraki leverages some of the same security back-end repositories. Cisco has tw o different SD-WAN offerings, each w ith integrated security. Q. For internet-destined traffic, how does the SD-WAN security architecture stack up against a Cisco Firepower® Threat Defense or ASA/Firepower device? What are the differences? A. Good question! Cisco Firepow er Threat Defense/ASA are dedicated NGFWs, and they have some additional capabilities. At the same time, both Cisco Firepow er Threat Defense/ASA and SD-WAN security have the same back-end engines, such as Cisco Talos®. A feature-by-feature comparison is not appropriate. Q. Are Viptela and Cisco SD-WAN one and the same now? A. Cisco has tw o leading SD-WAN security solution options, one pow ered by Viptela and one pow ered by Meraki. Q. Wait, I thought that the firewall used by SD-WAN was the Viptela zone-based firewall and not the Cisco zone-based firewall. With that said, does that Garner Magic Quadrant reference still apply? A. Cisco Secure SD-WAN includes Cisco Layer 3/Layer 4 app firew all/cloud-defined firew all. Yes, the Gartner Magic Quadrant still applies. [[Please move the legal block below to the bottom of the last page. All you need here
  • 2. © 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 2 of 4 is the copyright footer]] Q. Does SD-WAN replace MPLS? A. It can. SD-WAN is transport independent; it can run on top of any transport. Multiprotocol Label Sw itching (MPLS) can still be used as the underlay for the SD-WAN overlay, alongside the internet and 4G/5G. SD-WAN is transport agnostic, and it doesn’t replace MPLS. Instead, it encourages the customer to leverage the internet as their second transport and run one single overlay over MPLS/Internet. Q. What about control plane security? It’s all kind of hidden if you’re using vManage in the cloud. Support for SAML, MFA, whitelisting of IP access, etc. seems to be a problem. A. The control plane is the same w hether the solution is on-premises or cloud hosted. It has a zero-trust approach. If you need more details, please reach out to your Cisco account team. The control plane communication betw een vManage, vBond, vSmart, and the edge routers is secured using a Datagram Transport Layer Security (DTLS) tunnel, w hich uses Advanced Encryption Standard (AES)-256 ciphers for encryption, and authentication is taken care of w ith digital certificates. Q. Our network has four main sites and four remote sites. Do you have different hardware router sizes for main sites with higher bandwidth and lower-end routers for remote sites with lower bandwidth, at a lower cost? A. Absolutely! You can choose from any Cisco 1000 or 4000 Series ISR for branches. For higher scale at the main sites, you may w ant to consider an ASR 1000-X or 1000-HX platform. Q. What is the current device scalability for configuration pushes and device management? I’m coming from a major enterprise with thousands of branches, close to 100 campus locations, and upwards of 100 data centers and co-locations. A. The architecture easily scales to 10,000+ node systems, Viptela currently has the largest production SD-WAN implementations, w ith customers running over 6000 nodes. Viptela also has the largest SD-WAN market share among Global 2000 customers. We have production deployments at close to 10,000 sites. I am talking production deployed today, not future planning. You are covered for deployments of any size. Q. Is DNS Security via DNSSEC? A. DNS Security means Cisco Umbrella®. Q. What is the timeline to get full security in ASR and vEdge? A. Some of the security features require containers, w hich are not there on all platforms. Full security is offered on the Cisco 1000 and 4000 Series ISRs. vEdge and the ASR 1000 Series w illhave a subset of security features. That said, some of the missing features can be augmented by Cisco Umbrella cloud security, w hich now also supports Secure Internet Gatew ay (SIG), not just DNS-based security. Q. Does SD-WAN support routing like Open Shortest Path First (OSPF) and Border Gateway Protocol (BGP)? A. Yes to both, plus Enhanced Interior Gatew ay Routing Protocol (EIGRP) on Cisco routing platforms. Q. What kind of intrusion protection system (IPS) is native in the vEdge SD-WAN deployment? A. We use Cisco Snort® IPS today, backed by Cisco Talos threat intelligence.
  • 3. © 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 3 of 4 Q. We plan on using the ASR 1000 Series for 1 gig to 4 gig encryption. You are not planning to support Umbrella there and want us to distribute that out somehow? A. Cisco Umbrella monitoring is built into the Secure SD-WAN solution today. If you w ant to create a cloud security policy, you w ill need to use a full Cisco Umbrella suite, w hich has API connectors to your routers. [[Please delete the legal block above. It goes only on the last page. Copyright line should stay in footer]] Q. Will vManage apply to Meraki users as well? A. No, Meraki has its ow n management platform. Q. What code are you running for vManage and on vEdge? A. The latest. Version 19.1 on controllers and 16.11.1 on Cisco IOS® XE SD-WAN routers. We are not show ing vEdge here; that has a subset of this functionality. Q. What web browsers can be used to view vManage without any quirks? A. I use Chrome. Q. How about EIGRP on vEdge? A. EIGRP is not planned for vEdge. vEdge can do OSPF and BGP. Q. Is there a way to see statistics for more than seven days? A. Absolutely! You can choose to go as far back as the data is held in the vManage stats database. It's based on the database size configured. Q. Is this the Cisco Firepower Threat Defense firewall or the router zone-based firewall? A. This is using the DNS Layer cloud-defined app firew all, not the Firepow er Threat Defense NGFW. Q. Can you load-balance per flow on multiple SD-WAN links? if so, is packet order correction available? A. Yes, w e do per-flow routing. We do not do reordering on the routers. Q. We have Cisco Firepower on our edge and in our data center. Do we need SD-WAN Security? A. You can't compare SD-WAN Security w ith a firew all. The security part of SD-WAN Security is integrated w ithin the SD-WAN platform and does not exist outside of it. Q. So Viptela now has an incorporated firewall feature, or is it service chaining to a firewall? A. What Kural is describing are security features integrated into SD-WAN and managed by vManage. You of course still have an option of service insertion. You can do both at the same time too. Q. How does this address zero-day attacks? A. The Cisco Talos cloud receives something like 20 billion events a day. IPS and AMP are integrated w ith Talos, so you can enjoy all this threat intelligence. Q. What products are required to be able to create this ecosystem? A. It’s all integrated. All you need is Cisco SD-WAN pow ered by Viptela and an appropriate subscription Cisco DNA license. Q. Can events still be logged to an external SIEM tool, such as Splunk, Embedded Syslog Manager (ESM), etc., for further review or event correlation? A. Yes, they can. We generate syslogs, but they are rate limited to protect the router CPU. We can also export events in NetFlow v9 format, but you need a receiver that can parse it. Check out Cisco Stealthw atch. Q. Is SD-WAN managed by vManage – both the ISR/ASR and the VEdge platforms? A. Yes. You can manage netw orking and security on all those platforms via vManage. Q. So alerting is handled by other apps versus vManage? A. Please define alerting. Each device alerts vManage but can also generate messages to an external system.
  • 4. © 2019 Cisco and/or its affiliates. All rights reserv ed. This document is Cisco Public. Page 4 of 4 Q. So all security platforms that Cisco has – ASA , Cisco’s NGFW, IPS, etc. A. No. You can manage SD-WAN Security via vManage on ISRs, ASRs, CSRs, and vEdge platforms. Q. How impactful to production is it normally to get existing devices and network tied into SD-WAN? (Assuming you already have supported routers, etc.) A. It is as simple as buying a Cisco DNA license and upgrading existing routers to the Cisco IOS XE SD-WAN code. Of course, you need to consider communication to nonmigrated sites. This requires planning ahead of time. Q. Does vManage have an API that can be accessed? Is it read and write? A. EVERYTHING in vManage can be done using REST APIs! Full read and w rite. Q. What is a common way for SD-WAN converted sites to communicate with non-SD-WAN converted sites? Would they route to some head-end device and be routed from there? A. Yes, this is the recommended approach. Some customers do direct connection at each migrated site. It is dangerous and can cause routing loops if the administrator is not careful, but it can be done. To minimize latency, w e advocate establishing several transition hubs w here overlay and underlay are inter-routed. Q. Can the block page be redirected to a page that provides information vs. just a giving a blank page to the user? A. This is part of our future serviceability enhancements. Today it’s session reset for AMP. For URL filtering, you can present a page. Q. Does Role-Based Access Control (RBAC) have support for external groups like AD, RADIUS, and TACACS? A. Yes. You can use SSO or RADIUS/TACACS. Your Active Directory can be integrated to those. Q. Is there any technical documentation on SD-WAN QoS in detail? A. Check sdw an-docs.cisco.comand ciscolive.com. Q. Wait, we have ZBFW in our ISR and ASRs now . A. ZBFW w as there in Cisco IOS XE. We have enabled it in SD-WAN managed by vManage. We have also added Layer 7 intelligence to it. Q. Is Secure Sockets Layer (SSL) decryption available for traffic inspection? A. Not today, but stay tuned. Q. We're running a Cisco iWAN DMVPN overlay right now with fully licensed 4000 Series ISRs at the branch level. Are there any licensing considerations when moving to Vipte la? A. Yes! Please talk to your Cisco account team. Q. Will this be a parity feature with Cisco Meraki? A. We are not after feature parity, w e are after solving customer problems. Choose the solution that fits your needs. Q. Would this solution replace or supplement Firepower? A. Yes, and it depends. If you are using the SD-WAN solution and have been using additional firew alls for its security, you can use the current integrated security instead of a firew all. Q. Can you load-balance a single flow over two separate links? A. No. This is a very bad practice that some other SD-WAN vendors are promoting. It makes a great demo but can introduce severe performance issues. Q. Is the policy configuration as granular? A. We have not yet found a request that w e have not been able to build a policy for. Trust me, w e have seen some really crazy ones out there.