Documente Academic
Documente Profesional
Documente Cultură
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Enterprise trends – Scale, complexity, and security
AWS
Windows 10
3.64 Devices per person persistent threats 100K Devices per admin
Changing workforce and Agility consumption models
hyper-connected apps
Enterprise IoT
7.5B Things
Infrastructure convergence
Vulnerable endpoints
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
The security challenge
Motivated and targeted adversaries Increased attack surface Increased attack sophistication
• State sponsored • BYOD blurring perimeter • Advanced persistent threats
• Financial and espionage motives • Public cloud services • Encrypted malware
• $1T cybercrime market • Enterprise Internet of Things (IoT) • Zero-day exploits
Scale: Too many alerts Complexity: Securing everything Sophistication: Keeping up against attackers
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Diverse endpoints and applications served across a
multidomain network
Classes of endpoints Classes of applications
Xerox
Office 365
SAP
User devices IT services Non-IT services (On-premises or (Public cloud hosted)
(Laptops, phones, PCs) (Printers, audio, video, displays) (Lighting, alarms, surveillance) private cloud hosted)
• Consistent access across wired and • Service discovery for printing, • Application Visibility and
• Network and power High
wireless Apple TV Control (AVC)
Availability (HA) for emergencies
• Granular Quality of Service (QoS) • Network timing for audio • Seamless experience with
• Traffic monitoring for surveillance
and AVC and video on-premises and cloud
Network requirements
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Need for intent-based networking
Intent
Context
Insights
Mobile Security IoT MultiCloud Security
Powered by intent. Informed by context.
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
SD-Access:
Cisco’s next generation
enterprise architecture
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Software-Defined Access (SD-Access)
Cisco DNA Center™
Identity-based policy
and segmentation
Segmentation Automation Assurance Security policy definition decoupled from VLAN
and IP address
Group 1 Group 2
Group 5 Group 6
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Consistent wired and wireless management
A single network fabric for mobility
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
From network data to business insights
Network telemetry Complex event Correlated Guided
contextual data processing insights remediation
Traceroute 001110101100110
Complex
Clients Baseline
Syslog Netflow 1010110010 correlation
Future ready
• Wi-Fi 6 (IEEE 802.11ax) ready
x86
Open and
x86 multicore CPU UADP 2/3 extensible Cisco IOS XE
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9000 switches at a glance
Enabling a new era of intent-based networking
• Encrypted Traffic Analytics • Constrained Application Protocol • Fabric-enabled wireless • DevOps toolkit
• MACsec link encryption (CoAP) • Embedded Cisco Catalyst 9800 • NETCONF/YANG models
• Trustworthy solutions • Cisco DNA Service for Bonjour Series wireless controller • Streaming telemetry
• Group-based policy • Perpetual PoE • Unified control and policy • Patching and Graceful Insertion
• IEEE 1588 Audio Video • Wired and wireless and Removal (GIR)
• Full Flexible NetFlow
Bridging (AVB) guest access • Application hosting
90W
USB-C Dongle POE Displays Network HVAC VAV’s
60W UPOE+© Touchscreen IP Cameras Powered Light
PCs
30W UPOE
PoE+ E
IEE bt
15W 802
.3
PoE Badge Facial
Readers Recognition
Systems
2018 UPOE Powered Compact Nurse call
CBRS Biometric
2011 Switches systems
Private LTE
Environmental
Door Locks IP Call Tower
Sensor Hubs
2009
2003 IT OT
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9000 portfolio
Cisco Catalyst
Cisco Catalyst 9600 Series
9400 Series Cisco
Cisco Catalyst Catalyst Cisco Catalyst
9300 Series 9000 9500 Series
Cisco Catalyst
9200 Series
switch
platform
Cisco Catalyst Cisco Catalyst Cisco Catalyst Cisco Catalyst Cisco Catalyst Cisco Catalyst
2960-X/XR Series 3650/3850 Series 4500E Series 3850F/4500-X 6840-X/6880-X 6807-XL/6500-E
Standard switches 100G/40G SKUs 25G/10G SKUs Catalyst 9500 Series high performance
(UADP 2.0) switches (UADP 3.0)
Cisco Catalyst
9500 Series high performance switches
Performance and
Security Resiliency
scale
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9600 and 9500 Series
For multidomain campus core
Site 1
Distribution CE
MPLS Site 3
PE
Fabric
PE CE
Site 2
Access
1G/2.5G/5G
CE
VRFs
Customer-managed MPLS backbonee
UADP 2.0
Redundancy
is now Open Cisco IOS XE
table stakes
SD-Access
Industry’s
highest UPOE+©
scale x86 CPU and containers
Trustworthy solutions
New! NBAR2
Model-driven programmability
Catalyst 9400 1G UPOE+ © 90W line card
Patching and GIR
Supervisor Access line cards Core line cards
• Sup-1XL-Y: Adds 25G Uplinks • 24x 10G SFP+
Power supply
• 24x Multigigabit +
• Sup-1XL: Up to 240G per slot • 48x 1G SFP
• 3200W AC Streaming telemetry
24x Cisco UPOE • 3200W DC
• Sup-1: 80G per slot • 48x Cisco UPOE+© • 24x 1G SFP
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public • 2100W AC Densest 90W 1G (260 Ports)
• 48x Cisco UPOE
• 48x PoE+, 48x data
Cisco Catalyst 9400 Series
Innovations and benefits
N+1/N+N Modular power supply
Extending Catalyst
4500E Series leadership
in modular access
Ergonomic handles for
efficient weight distribution
4x throughput
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9400 Series
Unparalleled investment protection
Industry’s leading modular access platform
Upgrade supervisor and unlock increased capabilities on existing line cards
18 years
EOS EOL
14 years
Lower CapEx and OpEx vs. 70%+ of investment protected with Standardized for multiple places in
fixed switches each upgrade the network
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Mission-critical resiliency with Cisco Catalyst 9000
Your business stops if the core is down
Cisco Catalyst
9300 Series 1G with Cisco Catalyst
fixed uplink models 9300 Series 1G Fiber
models
Cisco Catalyst
9300 Series
switch platform
C9300-24S/48S SKUs
C9300L SKUs C9300-24/48
T/P/U/UX/UXM/UN SKUs
Enables support for next-generation wireless access points with minimal cable upgrades
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9300 Series
1G Fiber models - Expanding to FTTD and 1G fiber aggregation applications
24-port – C9300-24S • 24 and 48 port SFP SKUs
• Transition Catalyst 3850 1G SFP
to Catalyst 9300 1G SFP
• Wire-speed, non-blocking
performance
• Seamlessly integrates
with Cisco Catalyst 9300 Series
48-port – C9300-48S copper
• Supports same optics
• Common stacking – StackWise-
480
• Common power stacking –
StackPower
• Common uplink modules
1G fiber aggregation
8x 10G 2x 40G 4x Multigigabit 4x 1G 2x 25G 315W AC 715W AC/DC 1100W AC
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Collapsed access
Cisco Catalyst 9300 Series
Innovations and benefits
Flexible ASIC Optional Bluetooth Powerful CPU complex Wireless scale Most dense and flexible Unmatched PoE
• UADP 2.0 management • Intel x86 CPU • 48x Wave 2 uplink offering • Resiliency – Perpetual/Fast Extends Catalyst 3850 leadership
• USB 2.0 • 4-core 1.8 GHz access points • 8x 10G, • High power – 60W
• 8 GB memory in 1RU Multigigabit, 25G Cisco UPOE 1.5x throughput
• 16 GB flash
4x VRF scale
2x wireless scale
2x to 4x flash, memory
Pluggable storage
2x CPU performance
2x uplink scale
Densest 5G access
Local storage Most flexible stacking Redundant fans Intelligent power Optional power High-efficiency power supplies
• Removable storage • Front* and back stacking management supplies • Power supplies (AC+DC)
(120 GB) • Multiple cabling types – • Cisco StackPower • Power supplies
copper and fiber (AC+DC)
• Best HA – NSF/SSO
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public * Roadmap
Cisco Catalyst 9200 Series
Next generation of entry-level access switches for intent-based networking
Available
Fixed Uplinks Modular Uplinks Now Cisco Catalyst 9200 Series highlights
Recommended for small
scale SDA deployments
48 ports Full POE+/Data, 1G/10G Uplink
UADP 2.0 mini
Security 48 ports Full POE+, 12xmGig, 10G Uplink 48 ports Full POE+/Data Cisco IOS XE Software
48 ports Full POE+, 8xmGig, 25G Uplink
Limited-scale SD-Access
24 ports Full POE+/Data, 1G/10G Uplink 24 ports Full POE+/Data
MACsec-128 link encryption
Cold patching
Silver Platinum Platinum
Rated Rated Rated
Application
experience 125W 600W 1000W Full Flexible NetFlow
streaming telemetry
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst Access Switching
Secure, resilient campus Business-critical branch Simple branch
SD-Access SD-Access
Extended Nodes
SD-Access SD-Access
Choose Cisco Catalyst 9400 Series or Choose Cisco Catalyst 9300 Series Consider Cisco 9200 Series
Catalyst 9300 Series modular uplink models (C9300) fixed uplink models (C9300L) • Extend automation and policy
• Designed for security, mobility, IoT, and cloud • Full security with visibility • Simple to manage
• High availability, ETA, Application Hosting • High availability, ETA, Application Hosting • 2-box solution for SD-Access
• Catalyst 9800 Embedded WLC Support • Catalyst 9800 Embedded WLC Support • Limited VRFs
• Multi-tier SD-Access Fabric deployments • Single box solution with Fabric-in-a-box
• Highest density copper and fiber applications
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9k feature differentiation
Intent based networks for everyone
Features 9200L 9200 9300L 9300 Features 9200L 9200 9300L 9300
Platform 24P/48P x 1G √ √ √ √ Software Full L3/L2 √ √ √ √
Full Netflow √ √ √ √
√
√
mGig (12xmGig + √* √*
(12xmGig + Patching √ (cold) √ (cold) √ √
36x2.5G,
36x1G)
48x5G) √ √ √ √
MACSec
(128-bit) (128-bit) (256-bit) (256-bit)
PoE+ √ (Full) √ (Full) √ (Full) √ (Full) NSF/SSO × × √ √
√* ETA × × √ √
UPoE × × √
(mGig only)
SD Bonjour × × √ √
FRU PS and Fans √ √ √ √
ERSPAN × × √ √
FRU Uplinks × √ × √
AVB, PTP 1588 × × √ √
1G/10G uplinks √ √ √ √
SD-Access User VNs √(1) √(4) √(64) √(256)
40G uplinks × × √* √
Fabric Wireless × √ √ √
25G uplinks √ √* × √
√
Stacking 80G 160G 320G 480G 9800 Embedded Wireless × × √ (200APs)
(50APs)
Stackpower × × × √
Fabric in a Box × × √ √
Programmability Netconf/Restconf APIs √ √ √ √
Extended Node × × √ √
ZTP, PnP Agent √ √ √ √
Assurance Fabric, Network, Client √ √ √ √
Streaming Telemetry √ √ √ √
Application × × √ √
Guestshell/Python Scripting × √ √ √
√(Full √ (Full
AVC × ×
NBAR) NBAR)
Application Hosting × × √ (limited) √
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
* On roadmap
Enterprise speed transitions
100G (2km) = $4495
40G (2km) = $5995
25G Drive up to 300/400m over standard dual Cisco offers flexible 40G and 25G
or strand OM3/OM4 fiber options
40G
5 5 1
Gbps Future-ready for maximum • 4K Video, CAD/CAM, Imaging,
Gbps Gbps
bandwidth over Cat5e/Cat6 cable CFD driving need for Wi-Fi 6 /
802.11ax
• USB 3.0 interfaces now
standard on PC’s driving up to 5
Gbps data rates
• Workstations standardize on 5
Gbps NICs
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
25G for unsurpassed investment protection
on Cisco Catalyst switches - access to core
Future-ready with dual rate
• 10G, 25G Cisco Short Reach (CSR) for multimode fiber
• 10G, 25G Long Reach (LR) for single-mode fiber
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Expanded Multigigabit offerings for access
Cisco Catalyst
Cisco Catalyst 9300 Series Cisco Catalyst 9300 Series
9400 Series
C9300-48UN
C9300-48UXM
C9400-LC-48UX C9300-24UX C9300-NM-4M
Game-changing Innovation that supports 2.5G, 5G and 10G on existing cabling infrastructure
Ethernet portfolio is 802.3bz compliant, with support for 802.3af/at/bt PoE standards
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Simplified operations and serviceability with
Cisco Catalyst 9000
Lower TCO with better ergonomics
Ease of serviceability with blue beacons on
Inventory management efficiency with built-in RFID
each component
Ergonomic design with industry-standard icons Wireless console access with Bluetooth
Icons
Mobile Laptop
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9000 switches – proven platforms
Proven hardware
• Based on Catalyst 3850 launched Jan 2013 University of Vienna
• Next generation UADP ASIC architecture “The Catalyst 9000 switches with the power of open Cisco IOS XE simplifies operations dramatically and helps
• IT to create a secure and connected learning environment for our 10,000 employees and almost 100,000
Common PS, fans, uplinks, cables
students.“
— University of Vienna
Proven software
• Open Cisco IOS XE – Launched Nov 2015
CHC
• Common across Switching, Routing, WLS
• Added Resiliency – Patching, GIR, ISSU “The Catalyst 9000 provide us performance we need, and the security features that are critical for our
healthcare records. The new network, powered by Cisco® Digital Network Architecture, gives us granular
Largest and most successful EFT program insight into who’re the users, the devices they use, and the applications they access—all with the ability to learn
and adapt to changes and needs in the network.”
• 40+ Early Field Trial (EFT) Customers — Michel Fontaine, CHC Hospital
over the span of 4 mo. before the FCS
• Most exhaustive testing Cinnober
In production before FCS “The new solution with Catalyst 9000 switches has, among other things, x86 processors capacity to carry
multiple future applications that increase the reliability, security and flexibility of the network. Mainly, there is
Live since April 2017 in Cisco Building 23 in San Jose an increased division of the networks and control of communication in them for safety reasons. Then access
control is added by the users.”
Customer adoption — Peter Ekström, Ops Team Lead, Cinnober Financial
Tens of thousands of customers for Cisco Catalyst 9000
platform to date and counting NASA
The Catalyst 9000 has exceeded NASA’s mission critical requirements for security and segmentation... and at
“Catalyst 9000 continues to be the fastest Winner: 2018 twice the performance
— Eric Latta, Solutions Architect, NASA
ramping product in the company's history” pioneer award
Los Angeles World Airports
— Chuck Robbins, CEO Cisco Systems Winner:
“Los Angeles World Airports (LAWA) is expecting increased traffic in the next several years at LAX. The new
Overall product of the Catalyst 9500 with 100G interface will help LAWA to meet our capacity requirements while providing
https://miercom.com/cisco-catalyst-9000-pv/ year: 2017 and 2018 increased visibility and capabilities that were not previously possible.“
— Nathan Look, Deputy CIO, Los Angeles World Airports
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Speed transition with Cisco Catalyst 9000
End-to-end leadership with Cisco Catalyst access portfolio
Core/aggregation switches
Access points Access switches Wireless controllers
Multi- 25G
1G 1G 10 G
gigabit /40G
40 G
40G/
100G
Built from the ground up for intent-based networking Automation Security Analytics
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9000 campus core/aggregation portfolio
driving all campus needs
Cisco Catalyst Cisco Catalyst Cisco Catalyst Cisco Catalyst
9300 Series1G Fiber 9400 Series 9500 Series 9600 Series
UADP UADP
2.0 3.0
High availability: Cisco StackWise/ StackWise Virtual, ISSU, NSF, and SSO
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
* Roadmap for Catalyst 9600 Series
Cisco Catalyst 9000 access portfolio
Intent-based networks for everyone
Encrypted Traffic Analytics, Catalyst 9800 embedded wireless controller,
Full Automaton/Assurance,
Cisco DNA
Advantage
Advanced Assurance*
Software-Defined Access*
High Availability
NW
Cisco
Essential
DNA
NW
Open
Stacking, Dual FRU PS,
Built with Cisco UADP.
Cisco IOS
Platform
XE
FRU Fan/UL
Cisco Catalyst 9200 Series Cisco Catalyst 9300 Series Cisco Catalyst 9400 Series
Advanced automation Assurance and analytics Element management Basic automation Basic assurance Element management
• SD-Access • Global insights, trends • Patch lifecycle management • Plug-and Play (PnP) • Health dashboards – • Software image management
• Application policy • Compliance, custom reports application network, client, application • Discovery, inventory, topology
• Encrypted Traffic Analytics* • Switch 360 and Wired Client 360 • LAN automation • Basic switch and wired
• Cisco DNA Service for Bonjour* • SD-Access and switch insights
Telemetry and visibility client health monitoring Telemetry
• Embedded Event Manager
• • • ERSPAN
Third-party app hosting Application health, Application 360, • Full Flexible NetFlow
performance • AVC (NBAR2)
(loss, latency, jitter) • Wireshark
Enhanced security Full routing functionality High availability and Essential switch capabilities DevOps integration Telemetry
controls • BGP, HSRP, OSPF, ISIS,GLBP resiliency Layer 2, routed access (RIP, EIGRP Stub, • NETCONF, RESTCONF, and visibility
• MACsec-256* • NSF, GIR, StackWise/StackWise OSPF [1000 routes], gRPC • Model-driven Telemetry
Virtual+, ISSU/eFSU, Patching PBR, PIM Stub Multicast • YANG data model • Sampled NetFlow
(CLI) [1000 routes] • Guest Shell (on-box Python) • SPAN, RSPAN
IoT and mobility Flexible network Optimize bandwidth PVLAN, VRRP, PBR, Cisco Discovery • PnP Agent, zero-touch
• CoAP*, AVB*, PTP* segmentation utilization with multicast Protocol, QoS, FHS, 802.1X, MACsec- provisioning
128, CoPP, SXP, IP SLA Responder
• VRF, VXLAN, LISP, SGT, MPLS* • MSDP, mVPN, AutoRP,
SSO)
PIM-BIDIR
• Cisco Catalyst 9000 switching hardware includes the Perpetual Network Stack – • It is mandatory to attach a Cisco DNA license when ordering Cisco Catalyst 9000
Network Essentials or Network Advantage. switches. Cisco DNA license includes switch and Cisco DNA Center features.
• Cisco Catalyst 9600 Series offers only the Cisco DNA Advantage license.
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public * Not available on Cisco Catalyst 9200 Series switches
+Cisco Catalyst 9400, 9500, and 9600 Series switches
Seamless backbone speed migration with
Cisco Catalyst 9000
25G 40G 100G
• 10/25G dual-rate optics • SR/CSR/LR/ER/ZR/ • SR/LR/ER module
Drive for lower TCO BiDi modules • 40G/100G
• 10/25G-CSR • 1G/10G dual-rate dual-rate optics
speed (4x distance) with QSA Adaptor • 4x10G, 4x25G
• 10/25G-LR-S
migration (up to 10 km on SMF) • 4x10G breakouts* with breakouts*
Flexible
deployment
100M to 100G Fiber infrastructure Diverse
investment protection deployment
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
*Roadmap for Catalyst 9600 Series
Cisco Catalyst 9000 switching
Built to see you through the next decade
Ethernet Alliance
IEEE
PoE+
UPOE+ / UPOE
Passthrough Single Pair PoE
2 (for replacing RSxx for BMS)
single-pair
Cisco compact switch PoE
USB-C powering
IEEE 802.3bt compliant platforms 3 (laptop/phone charging data)
Catalyst 9400 and 9300 Series*
USB-C
Power +
Data
C97-738949-03 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public