Documente Academic
Documente Profesional
Documente Cultură
Next Generation
SD-WAN Technology
Colin Boland
SE
February 1, 2018
Cisco
Your Time
Connect Is Now
10B 90%
Mobile-connected Growth in mobile
devices by 2019
MORE 73% devices from
DEVICES 2014-2018
of revenue
is generated
Up to Annual increase in in the branch Of employee and
MORE 80%
50% enterprise bandwidth
and video adoption USERS
customers are served in
branch offices
WAN New
Remote Site
MSP-RT
MPLS
Existing Existing
Data Center
New
Cisco Digital
Network Architecture
Complements Cisco’s Enterprise Networks architecture strategy
Better Together
Analytics
Application Traffic Per-Segment Secure Cloud Path Cloud Accel Transport
SLA Engineering Topologies Perimeter (IaaS) (SaaS) Hub
APPLICATION POLICIES
Monitoring
Routing Security Segmentation QoS Multicast Svc Insertion Survivability
• Secure Connectivity
• Flexible (Cloud First) Connectivity
Application
Security
Applications
Services
• Application Quality of Experience
Services
• Agile Operations
Flexible Agile
Connectivity Operations
Connectivity Operations
Security Applications
Application
Centralized Device
Services Scalable Data-Plane
Encryption
Auth-DB
Connectivity
Connectivity Operations
DPI
Engine
Data Center
INTERNET
Google
MPLS
Security Applications
Application
Services
Dynamic Per-VPN
Segmentation/VPNs
Connectivity
Connectivity Operations Topologies
DPI
Engine
MPLS
Connectivity
Connectivity Operations Cloud Services
Application-Aware Integration
Routing
SEN Overlay
Programmatic APIs
Connectivity
Connectivity Operations
Open Object Model
NetConf Ad-Hoc
Adds/Moves/Changes
vManage
Cisco vBond
APIs
• Used for device on-boarding
3rd Party
vAnalytics (ZTD/ZTD)
Automation
• Orchestrates connectivity
vBond between management, control
and data plane
vSmart Controllers • First point of authentication
• All other components need to
4G know the vBond IP or DNS
MPLS
information
INET
vEdge Routers • Authorizes all control
connections (white-list model)
• Distributes list of vSmarts to all
vEdges
Cloud Data Center Campus Branch SOHO
vManage
Cisco vSmart
APIs
• Centralized brain of the solution
3rd Party
vAnalytics • Establishes OMP peering with all
Automation
vEdges
vBond • Implements control plane policies,
such as service chaining, traffic
vSmart Controllers
engineering and per VPN topology
• Distributes connectivity information
MPLS 4G between vEdge
INET • Orchestrates secure data plane
vEdge Routers connectivity between vEdges
VS
vEdge vEdge
OMP Update:
vSmart § Reachability – IP Subnets, TLOCs
OMP
DTLS/TLS Tunnel
§ Security – Encryption Keys
§ Policy – Data/App-route Policies
IPSec Tunnel
OMP OMP
BFD Update Update
Policies
OMP OMP
Update Update
vEdge vEdge
Transport1
TLOCs TLOCs
Subnets Subnets
© 2016 Cisco and/or its affiliates. All rights reserved. 18
Secure Segmentation
End-to-End Segmentation
VPN 1
Interface VPN1 SD-WAN VPN1 Interface
IPSec VPN 2
VLAN VPN2 VPN2 VLAN
Tunnel VPN 3
Ingress Egress
vEdge vEdge
• Segment connectivity across fabric w/o • Labels are used to identify VPN for
reliance on underlay transport destination route lookup
• vEdge routers maintain per-VPN routing • Interfaces and sub-interfaces (802.1Q tags)
table are mapped into VPNs
© 2016 Cisco and/or its affiliates. All rights reserved. 19
vManage: The Management Plane
Management Plane
vManage
Cisco vManage
APIs
• Single pane of glass for Day0,
3rd Party Day1 and Day2 operations
vAnalytics
Automation
• Real time alerting
vBond • Centralized provisioning
• Configuration standardization
vSmart Controllers • Supports
• REST API
• CLI
MPLS 4G
• NETCONF / YANG
INET • SNMP
vEdge Routers • Syslog
TPM
Chip
Identity
Cert
Identity
Cert
vBond vSmart
vEdge
Re orc
2
d ir
ec
Qu Ser
at l
ic tro
n
3
tt
io
5
ery ver
un o n
he
an tio e
o c ator
m c
vM ra ic
s
ag n
m ial
v
to
e
e
r
1
co nit
om fig d
ZT
Configuration
l
ora
co itia
u
P
In
te
fr n 4
vEdge Assumption:
§ DHCP on Transport Side (WAN)
§ DNS to resolve ZTP server name*
© 2016 Cisco and/or its affiliates. All rights reserved. * Factory default configured 25
Template-Based Configurations
Centralized Device Configuration Enforcement
• Templates are attached to provisioned
vEdge routers
• Variables are used for rapid bulk
configuration rollout with unique per-
device settings
• Local configuration changes are not
allowed
- Prevents configuration drift
SLA SLA
Core
App 3,000
vEdge Router
1 Internet
Path
vEdge1 vEdge2
Path 2 MPLS
App A
4G LTE
Path
3
Path1: 10ms, 0% loss, 5ms latency IPSec Tunnel
Path2: 200ms, 3% loss, 10ms latency
Path3: 140ms, 1% loss, 10ms latency
© 2016 Cisco and/or its affiliates. All rights reserved.
Control Plane 30
SD-WAN Solution Components
Overview
vEdge Cloud on
vEdge 100 family vEdge 1000 vEdge 2000 vEdge 5000 Greybox or vEdge Cloud
Whitebox
2000 vEdges per vBond 2700 vEdges per vManage 2700 vEdges per vSmart
Redundancy Add 1-2 vBonds Redundancy Add 1-2 vSmarts
Horizontal Scale out Model
Horizontal Scale out Model in cluster mode (same DC) Horizontal Scale out Model
4G/LTE Internet
MPLS
Subscription
Perpetual cost of cost of Cisco
Cisco SD-WAN Operational cost
software of Cisco SD-
SD-WAN CPE (Includes SD- WAN solution
hardware WAN controller
+ CPE software)
AAR
AAR AAR