Documente Academic
Documente Profesional
Documente Cultură
BRKNMS-2443
BRKNMS-2443
Cisco Public
Agenda
Introductions
What is Unified Access?
One Network
One Policy
One Management
Prime Infrastructure 2.2
Simplifying Network Deployment
Mobility and Performance Assurance
Simplified Troubleshooting
Simplifying Day-to-Day Management
Conclusion
BRKNMS-2443
Cisco Public
VIDEO
VIRTUALIZATION /
MOVE TO CLOUD
Global Trends
To m o r r o w S t a r t s H e r e
IT Challenges
Connecting
People
BRKNMS-2443
Connecting
Things
Cisco Public
Connecting
Clouds
BRKNMS-2443
Cisco Public
Wired
Security
Networks are
getting too
complex to
manage !
Network Admin
BRKNMS-2443
Cisco Public
1. Not affordable
2. Not Scalable
3. Too many BW
hungry
multimedia
applications
BRKNMS-2443
Cisco Public
Connecting Clouds
Simple
Secure
Lower
TCO
Connecting People
Connecting Things
Cisco Public
One Network
Corporate
Network
Cisco
Access Point
Catalyst 3850 /
Internet
Cisco Firewall
Catalyst 3650
Catalyst
Switch
Con v e r g e d Ac c e s s M ode
Integrated wireless controller
Distributed wired/wireless
data plane (CAPWAP
termination on switch)
BRKNMS-2443
LAN Mgmt
Solution
Access Control
Server
One
Management
Wireless
Control
Assurance
CiscoSystem
Prime Infrastructure
Cisco Public
10
NAC
Profiler
One
Policy
Guest
Server
Cisco
ISE
Wireless Management
Configuration Management
Branch Management
QoS Management
Network Monitoring
Cisco Public
Cisco Prime
LAN
Management
Cisco
Solution
Cisco Prime
Network
Control
Prime
System
Infrastructure
Cisco Prime
Assurance
Manager
BRKNMS-2443
Cisco Public
UCS Server
Management
Assurance
Convergence
BRKNMS-2443
End-to-end application
experience and visibility
Consolidation
Cisco Public
Cisco Advantage
Operational
Productivity
Application
Performance
Converged
Wired+Wireless
Full Lifecycle
Management
Real-time
Troubleshooting
Integrated
Best Practices
Plug-N-Play
BRKNMS-2443
Cisco Public
15
Lifecycle
End-to-End Lifecycle Management
Lifecycle
Rapid device support through Device Packs for new Cisco devices,
routers, switches, controllers, access points, Nexus technology, and
more
Customizable configuration templates based on Cisco validated
designs and guided workflows
Cisco Unified Access management and client tracking
Seamless integration with Cisco Identity Services Engine
(ISE) for simplified troubleshooting
Seamless integration with Cisco Mobility Services Engine
(MSE) for location-based services, rogue detection, etc.
BRKNMS-2443
Cisco Public
See Everything
Routing, switching, wireless LAN
Users, endpoints and policy
AVC, NAM & built-in IOS features
(WLC 7.4 gets AVC)
Corporate &
BYOD Endpoints
Unified Access
Policy System
Branch / WAN
Cisco Public
17
Corporate &
Cloud Apps
Assurance
Application Experience and End User Experience
Assurance
BRKNMS-2443
Cisco Public
UCS Server
Management
BRKNMS-2443
Cisco Public
Operations Manager
Ops Manager
BRKNMS-2443
Distributed
Supports up to 10 Prime Infrastructure instances
Addresses geographic distribution, scalability,
resiliency and visibility
Single pane of glass monitoring with click-through
management
Centralized
Central view of assets, alarms and clients
Single sign-on
Dashlets aggregated from PI instances
Scalable
Consolidated view of network health
Consolidated view of health of each PI instance
Reports scheduling from one interface
Cisco Public
BRKNMS-2443
Cisco Public
22
Cisco Public
23
Mobility Work Center can now be used to form peering between AireOS
Controllers and IOS-XE based Mobility Controllers by just adding GA
Controllers in the right Mobility Domain
BRKNMS-2443
Cisco Public
24
Cisco Public
25
BRKNMS-2443
Cisco Public
26
New
Dashlet in
PI 2.2
Available as Part
of TechPack
Post Prime
Infrastructure 2.2
BRKNMS-2443
Cisco Public
27
WLAN
Four SSID Support
WPA2-Enterprise
WPA2-Personal
Open
Guest-CWA
802.11 AC
Captive Bypass-Portal
Fast SSID-Change
BRKNMS-2443
Security
Application
Experience
Wireless Flexible
Netflow,
Application
Visibility
Per-SSID BW
allocation
Cisco Public
Radius,
TACACS+
802.1X
CWA
AAA-Override
Client Timeout
NAC
DHCP Snooping
ARP Inspection
Clear Password
Encryption
Wireless Best
Practices
Band-Select
RRM
CleanAir
DCA Channel
Radius Timeout
WiFi Direct Policy
CPI Template
Overview
DC
Internet
5760-GA-1
Branch
Branch
ISE
CPI
5760-GA-2
3
IOS-XE
Wireless
Templates
Large Campus
Large Branch
MC
MC
MC/MA
MC/MA
MC/MA
MC/MA
MA
MA
MC/MA
MA
MA
MA
MA
MA
MA
MA
MA
AP
WLC
WLC
AP
AP
Platforms : 5760
IOS-XE Centralized Design :
Single or Multi Sub-Domain
Centralized Wireless
Mobility
WLAN : 4 SSID Support WPA2-Ent/WPA2-Personal/Open/Guest-CWA, 802.11 AC, Captive Bypass-Portal, Fast SSID-Change etc.
Application Experience : Wireless Flexible Netflow, Application Visibility and Per-SSID BW allocation
Security : Radius, TACACS+, 802.1X, CWA, AAA-Override, Client Timeout, NAC, DHCP Snooping, ARP Inspection, Clear Password Encryption etc.
Wireless Best Practices : Band-Select, RRM, CleanAir, DCA Channel, Radius Timeout, WiFi Direct Policy etc
BRKNMS-2443
Cisco Public
Branch
Branch
PI_8021X
MC/MA
MC/MA
MC/MA
101
8021X_WLAN_VLAN
PI_8021X
401
8021X_WLAN_VLAN
PI_8021X
701
8021X_WLAN_VLAN
PI_8021X
102
PI_PSK
PSK_WLAN_VLAN
402
PI_PSK
PSK_WLAN_VLAN
702
PI_PSK
PSK_WLAN_VLAN
OPEN_WLAN_VLAN
PI_OPEN
103
OPEN_WLAN_VLAN
PI_OPEN
403
OPEN_WLAN_VLAN
PI_OPEN
703
8021X_WLAN_VLAN
PI_PSK
CISCO123
PSK_WLAN_VLAN
PI_OPEN
Cisco Public
OPEN_WLAN_VLAN
CA-Mobility-SubDomain-3
CA-Mobility-SubDomain-3
Internet
GUEST_WLAN_VLAN
PI_GUEST_CWA
5760-GA-1
5760-GA-2
10.99.2.242
10.99.2.242
10.99.2.243
10.99.2.243
PI_GUEST_CWA
Branch
Branch
Branch
GUEST_WLAN_VLAN
MC/MA
10.101.1.109
PI_GUEST_CWA
MC/MA
10.101.4.109
PI_GUEST_CWA
MC/MA
10.101.7.109
PI_GUEST_CWA
10.101.1.10910.101.4.10910.101.7.109
Supports Guest Access with Central Web Authentication (CWA) using Cisco ISE
Multiple Guest Anchor support with automatic Mobility and load balancing
Automatic CWA configurations AAA, Pre-Auth ACL, CoA, MAC Filter, Radius Attributes etc.
AireOS (New Mobility) Guest Anchor WLC support with additional WLAN Template and Mobility Work Center
BRKNMS-2443
Cisco Public
CPI
TACACS+
10.100.1.49
10.100.1.82
UDP Port 9991
10.100.1.50
10.100.1.83
UDP Port 2055
10.100.1.49
<KEY>
TACACS+
Branch
Branch
Branch
10.100.1.50
<KEY>
MC/MA
MC/MA
MC/MA
Radius or TACACS+ Server group, Method Lists and association to 802.1X and Guest WLANs on
Authenticator Device (Switch/Guest WLC)
40
30
20
10
BRKNMS-2443
Cisco Public
SPG-1
10.101.3.109
SPG-1
10.101.1.109 ; 10.101.2.109
MA
MA
10.101.1.109 10.101.2.109
MC/MA
10.101.3.109
MA
MC/MA
10.101.4.109 10.101.5.109
MA
10.101.6.109
10.101.4.109
CA-RF
MA Configuration
BRKNMS-2443
Cisco Public
10.101.3.109
Leave Blank
Leave Blank
Leave Blank
Leave Blank
SPG-1
5760-Stack
5760-Stack
MC 10.100.221.1
MC
Controller
10.100.221.1
10.100.222.1
SPG-1
10.101.1.109 ; 10.101.2.109 ; 10.101.3.109
10.100.222.1
CA-RF
MA
MA
10.101.1.109 10.101.2.109
MA
10.101.3.109
MA
MA
10.101.4.109 10.101.5.109
MA
10.101.6.109
3x50/4500E-Sup8E MA Configuration
10.100.221.1
Leave Blank
Leave Blank
BRKNMS-2443
Cisco Public
Leave Blank
Leave Blank
IEEE 802.11AC
Band-select
Clean Air on both Radio interfaces
Radio Resource Management
ClientLink 2.0 on 5Ghz Radio
IP DHCP Snooping
IP ARP Inspection
WiFi Direct Access Policy Deny
PreShared-Key Clear Password Encryption
Wireless Fast SSID Change
Wireless AP Authentication
Wireless Device Classification
Captive By-Pass Portal
Not Integrated
VoWLAN
Rogue AP
http://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/5700/software/release/ios_xe_33/5760_IOS_WLC_Configuration_Best_Practices.pdf
BRKNMS-2443
Cisco Public
Its the quickest way to learn how to deploy converged access using Prime
BRKNMS-2443
Cisco Public
BRKNMS-2443
Cisco Public
39
BRKNMS-2443
Cisco Public
40
Cisco Public
41
BRKNMS-2443
Cisco Public
42
Section Name
Additional Notes
WLAN 1 thru 3
Guest WLAN
Guest Controller/Anchor
(GA)
Security
Application Services
Mobility
Wireless Management
BRKNMS-2443
Cisco Public
43
BRKNMS-2443
Cisco Public
1) Deploy the Plug and Play (meaning make it run on the Plug and Play
Gateway to listen for incoming connections
2) Email an automated generated PIN to the installer (or email the config)
BRKNMS-2443
Cisco Public
DMZ
Internet OR MPLS
APIC
EM
ZTD service
PKI service
BRKNMS-2443
Prime
Infrastructure
Cisco Public
Cisco Public
49
ISR G2
ASR1K
ISR G2
ASR1K
App
BW
Transaction
Time
SAP
3M
150 ms
NFv9/IPFIX
ISR G2
ASR1K
High
Med
Low
Reporting Tools
Application
Recognition
applications using
Layer 3 to 7
information
BRKNMS-2443
Reporting
Tool
Perf. Collection
Management
Tool
& Exporting
Advanced
reporting tool
aggregates and
reports application
performance
Collect application
performance
metrics, and
export to
management tool
Cisco Public
50
Control
Control
application use to
maximize
application
performance
BRKNMS-2443
Cisco Public
51
BRKNMS-2443
Cisco Public
52
Prime Infrastructure
NAM Appliance (23XX)
NBAR2, Voice, ART, SPAN, ERSPAN
Cisco ASR
NBAR2, AVC, Medianet
NGA 3240
Netflow, SPAN, ERSPAN
Netflow, NAM
module
AP 3700
NBAR2
SNMP/CLI
Polling
BRKNMS-2443
SPAN/
ERSPAN
Netflow
Wireless Controllers
NBAR2
WAAS
Cisco Public
PA
MEDIANET
NBAR
NBAR2
Select OR Search
for Device(s)
BRKNMS-2443
Device Work
Center Bottom
Panel is now on its
own page in PI 2.2
BRKNMS-2443
Cisco Public
Network Topology
Network Topology Page
Maps> Network Topology
Main landing page for viewing network
topology
Topology Dashlets
Topology Dashlets available for Overview
level dashboards
Multiple Topology dashlets supported
Any topology map can be viewed in a
dashlet
Device 360 N-Hop contextual topology
view
Cisco Public
BRKNMS-2443
Cisco Public
BRKNMS-2443
Cisco Public
60
BRKNMS-2443
Cisco Public
Device Identity
or Profile from
ISE Integration
AAA Override
Parameters
Applied to
Client
Policy Information
Including Posture
BRKNMS-2443
Cisco Public
or end-point issues
Device 360: Identify and fix device related
problems
Interface 360: Identify application load and
related stats
BRKNMS-2443
Cisco Public
BRKNMS-2443
Cisco Public
64
Summary
BRKNMS-2443
Cisco Public
Cisco Prime
Infrastructure
BRKNMS-2443
Cisco Public
Cisco Public
Cisco Prime
Infrastructure
Learning Resources
Fee-Based and Free Resources Are Available
Instructor-led training (fee)
Three days of training available from learning partner
www.cisco.com/go/primeinfrastructure under Learn More
Cisco Public
Americas
Edition
EMEAR
Edition
Every Tuesday
Every Wednesday
Every Thursday
Every Week*
APJC
Edition
Every Tuesday
Every Thursday
Same Time
11 a.m. Pacific
(San Jose
time)
(90 mins)
Same Time
12 p.m.
Singapore
time
(90 mins)
Every Week*
Same Time
Every Tuesday
Every Thursday
10:30 a.m.
CET
(Paris, Berlin)
(90 mins)
Same Place
bit.ly/PrimeDemo
No registration required
Same Place
bit.ly/PrimeDemo-APJC
No registration required
Same Place
bit.ly/PrimeDemo-EMEAR
No registration required
* Exceptions: No sessions on Belgium or France public holidays and during the Cisco shutdown
BRKNMS-2443
Cisco Public
www.cisco.com/go/prime-demo
Every Week*
Cisco Public
72
Call to Action
Visit the World of Solutions for
Cisco Campus (I can be found at Network Transformation Whisper Suites)
Walk in Labs WISP-2999 Tues thru Thurs at World of Solution
Technical Solution Clinics TECCRS-2001
Recommended Reading: for reading material and further resources for this
session, please visit www.pearson-books.com/CLMilan 2015
BRKNMS-2443
Cisco Public
73
BRKNMS-2443
Cisco Public
74
Wireless
Wired
Datacenter
Topology
IPV6 Device
Management
UCS Server
Assurance
PI Operations
Center
Converged Access
3.6 and 3.7 with
APs
QoS
Configuration &
Monitoring Support
Nexus 9K
Assurance
R/W APIs
Maps Performance
Improvements
IWAN
Configuration
Workflows
Technology
Packs
BRKNMS-2443
Cisco Public