BRKENT-2105-Deploy and Manage SD-Branch
BRKENT-2105-Deploy and Manage SD-Branch
Ramesh Kalimuthu
Technical Marketing Engineer
BRKENT-2105
#CiscoLive
Agenda
• Need for virtualization and automation
• Key Use-cases
• SD-Branch Architecture and components
overview
• SD-Branch Design, Provision and Manage
• Conclusion
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
What Software Defined Branch Can Do For You
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Virtualization Offers Flexibility, Simplicity, Savings
VNFs
LB Hypervisor
Server
Router Firewall Wan Opt Load Balancer
Why Virtualization?
• Flexibility • Service Agility
• Less Devices, More VNFs • Efficient Resource Utilization
• Quick Rollout Time • OpEx Savings
Cisco’s Virtualization is available for both Traditional Routing as well as SD-WAN routing
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Cisco Software Defined Branch - Summary
Controller lead, modular architecture that allows for use of
SD-Branch is an
best-of-breed network function service chain in Enterprise
architectural choice Branch.
• SDWAN migrations
Can be used to • Security / Compliance
address a number • Hardware consolidation and Branch Virtualization
of use-cases • Local file, Print and DDI (DHCP, DNS, IPAM) services
• SP hosted multitenant routing service
Built on
Catalyst 8200 uCPE, Enterprise Network Compute System(ENCS 5000)
Cloud Services Platform(CSP5000)
UCSE(in ISR4K, Catalyst 8K) with NFVIS
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco’s virtualization portfolio
Network services on any platform, anywhere - branch or data center
Colocation
Freedom of choice
Small/Lean Enterprise Hardware platforms for any
Branch Branch Data Center location in the network
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Platform and
Use-cases
Orchestration
Network Functions
Catalyst 8200 Series Edge uCPE ENCS 5400 Series CSP 5200 & 5400 Series
8 cores 6 to 12 cores 16 to 56 cores
System Status
• Status LED LTE WAN PIM Slot Physical Security
Network Modules • Kensington lock
• FAN LED USB Storage • CAT 4/6/18 PIM • NIM slot
• Power LED • USB 3.0
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Flexible and Converged SD-Branch Solution
SD-WAN Migrations WAN diversity: LTE, DSL,
T1/E1
Hardware consolidation and Best-of-breed Cisco & 3rd
Branch Virtualization Catalyst 8000V Party VNFs
Cisco
Security/Compliance Umbrella Port Segmentation
Virtual Switch / SRIOV
Local file, Print and DDI Hypervisor / Cloud
(DHCP, DNS, IPAM) services Deployment Automation
SD-WAN
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
SD-WAN (IPSec) Throughput Performance with
QoS, DPI and Netflow/cFlow on SD-Branch Platforms
2000 1731 1792
Large Packets
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Monitor WAN Edge Connectivity with
ThousandEyes Agent
SaaS
Monitoring Catalyst
Agent 8000V
Internet
NFVIS
IaaS
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
SD-Branch High Availability Design Connections
ENCS
ENCS MPLS ENCS
Broadband
ENCS
uCPE-Right WAN
Pt-to-Pt
Untrust
WLC WLC
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
SD-Branch High Availability design
MPLS Broadband
AN
ISP1
AN
W
W
uCPE-Left uCPE-Right
WLC WLC
NFVIS NFVIS
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
NFVIS
Network Function Virtualization
Infrastructure Software
Orchestration
Network Functions
Programmable API for service Purpose-built OVS DPDK & SR-IOV to accelerate
orchestration: REST, Netconf API & GUI network traffic
for
interface
Device-local GUI as well as Networking PnP ZTD, Native support for BGP
integration with vManage and MSX
Lifecycle management, Upgrades,
Snapshots, Role Based Access Control
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
NFVIS Architecture
Not Just KVM, Power in software
PnP vManage Console Portal
Server NSO SSH
Hardware
libvirt Open vSwitch Qemu Collectd Syslogd Snmpd
Management
* Roadmap
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
VNF Services
Orchestration
NFVIS
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Orchestration
Network Functions
Catalyst 8000V
ISRv ISRv ISRv on ENCS
Virtual Router Unified
IOS XE XE SD- Unified
WAN
Catalyst 8000V
Unified
// 3rd
vEdge Cloud vEdge Cloud vEdge Cloud Party
Viptela OS Viptela OS Viptela OS
Network Consistency
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Open ecosystem for 3rd party VNFs
Customers can call Cisco support for certified 3rd party VNFs
Certified
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Orchestrator
Orchestration
Network Functions
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
SD-Branch User Experience
Select Network Provision SD-Branch
Connect Branch
Design Use Full Service
uCPE Device
In vManage Branch
vManage
Control and Policy
Elements
NFVIS
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
SD-Branch
Design,
Provision and
Manage
vManage SD-Branch automation workflow
Plan Deploy Monitor and Manage
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Network Design Procedure in vManage
Attach/Detach
Network Design Add Branch Add Services Device to/from
Branch
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
vManage SD-Branch Workflow
1 2 3 4 5 6
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
uCPE Onboarding steps
2 3 4
1 WAN Transport
NFVIS
Internet
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
uCPE Onboarding steps (contd.)
devicehelper.cisco.com
wan-br wan2-br
wan-net wan2-net
DHCP VPN0
mgmt-br
DTLS vEdge
PNP Management Port
NFVIS NFVIS
ASAv
lnt-mgmt-net lan-net
lan-br
SRIOV-1 SRIOV-2 SRIOV-3 … SRIOV-23 SRIOV-24
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Video
SD-Branch Design, Provision, Manage
Demo Video
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
vManage SD-Branch
FY
I
Planning Step Actions
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
vManage SD-Branch
FY
I
Design, Provision, Manage Actions
Step 4 Step 5 Step 6
Network Design and Provision Device Manage and Monitor Day N Changes
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
FY
Validated Use-cases
I
Single Service
Router Single WAN
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
FY
Validated Use-cases
I
Multiple Services
Router + Firewall
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
FY
I
Visual Topology View
vNIC sequence
and
connection clarity
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
FY
Network Design Customization
I
Add
Network(s)
Add
Service(s)
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
FY
I
Addon CLI Template
NFVIS configuration generated via ND and add-on CLI template is Create
merged and device configuration is generated.
Addon CLI
•
•
Add-on CLI must be used in conjunction with Network design
It is recommended to be used only for configurations not natively
Template
supported in ND
• Supported add-on CLI configs for following features –
• track-state
• speed
• duplex
• native vlan
• Global vlan
• QOS
• ACL
• SNMP
• STP enable/disable under switch GE interface
• Banner
Preview of Merged
• MOTD
• Static routes
Config after
• Default gateway Device Attach
• PNIC tracking for WAN interfaces
• Bootup_time
• TACACS
• AAA auth-order
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
vManage SD-Branch features
Supported features
VNF Packaging Tool Cisco and Thirdparty
Network Design(ND) Single/Dual Device
ND Global Settings AAA, NTP, Syslog
ND Device Configuration WAN, LAN, Mgmt
ND Device->Services Configuration Router
Router+Firewall
Router+Firewall+WAAS
AND
Other service/network customization
Addon CLI Template
Visual Topology representation
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
SD-Branch Key takeaways
• Cisco offers complete solution across all four components
• Hardware, Network Hypervisor, VNF, Orchestrator
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Why Cisco SD-Branch?
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Continue your education
Walk-in labs
Related sessions
#CiscoLive BRKENT-2105 © 2021 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Thank you
#CiscoLive
#CiscoLive