Programovatelnost síťových zařízení

Size: px
Start display at page:

Download "Programovatelnost síťových zařízení"

Transcription

1 Praha, hotel Clarion dubna 2013 Programovatelnost síťových zařízení Příklady využití OnePK v komunikačních architekturách T-SDN2 / L2 Pavel Křižanovský Cisco and/or its affiliates. All rights reserved. Cisco Connect 1

2 Agenda Úvod SDN, One, OnePK? Koncept OnePK OnePK API a příklady použití Shrnutí 2013 Cisco and/or its affiliates. All rights reserved. Cisco Connect 2

3 Agenda Úvod SDN, One, OnePK? Koncept OnePK OnePK API a příklady použití Shrnutí 2013 Cisco and/or its affiliates. All rights reserved. Cisco Connect 3

4 SDN je, když...

5 An open solution for VM mobility in the Data-Center A way to reduce the CAPEX of my network and leverage commodity switches A solution to build virtual topologies with optimum multicast forwarding behavior A way to optimize link utilization in my network enhanced, application driven routing A means to get assured quality of experience for my cloud service offerings A platform for developing new control planes An open solution for customized flow forwarding control in and between Data Centers A solution to build a very large scale layer-2 network Develop solutions at software speeds: I don t want to work with my network vendor or go through lengthy standardization. A means to do traffic engineering without MPLS A means to scale my fixed/mobile gateways and optimize their placement A way to distribute policy/intent, e.g. for DDoS prevention, in the network A way to optimize broadcast TV delivery by optimizing cache placement and cache selection A way to configure my entire network as a whole rather than individual devices A way to build my own security/encryption solution A solution to get a global view of the network topology and state A way to scale my firewalls and load balancers 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 5

6 An open solution for VM mobility in the Data-Center A way to reduce the CAPEX of my network and leverage commodity switches A solution to build virtual topologies with optimum multicast forwarding behavior A means to scale my fixed/mobile gateways and optimize their placement A way to distribute policy/intent, e.g. for DDoS prevention, in the network A way to optimize link utilization in my network enhanced, application driven routing A means to get assured quality of experience for my cloud service offerings Enhanced Agility Simplified Operations A platform for developing new control planes A way to optimize broadcast TV delivery by optimizing cache placement and cache selection A way to configure my entire network as a whole rather than individual devices An open solution for customized flow forwarding control in and between Data Centers A solution to build a very large scale layer-2 network Develop solutions at software speeds: I don t want to work with my network vendor or go through lengthy standardization. New Business Opportunities A means to do traffic engineering without MPLS A way to build my own security/encryption solution A solution to get a global view of the network topology and state A way to scale my firewalls and load balancers 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 6

7 Cisco Open Network Environment ONE Preserve What is Working Resilience, Scale, Security Functionality and Rich Features Instrumentation Evolve for New Requirements Operational Simplicity and Automations Programmability and Network-Awareness Upcoming Innovations Open and Integrated Framework Software Defined Network concepts are a component of the Open Network Environment Existing APIs, Agents, Controllers and Infrastructure contribute Network Programming onepk developer.cisco.com, CDN, Training, Certification, Partners, EEM, EASy Open Network Environment (Software) Architectures and Patterns Controllers (ONE/Openflow PoC) (SBC, WLC, +++) CIN, CloudConnect, Sentinels, Agents Open Network Environment Scenarios and Motivations Deployment and Virtualization Nexus 1000v CSR 1000v VSG and vfw/asa, vwaas, vnam, Cisco Openstack Ed Blade Hosting (UCS-E, ), Virtual Containers (AirVision, Cat, ISR, ASR, ) 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 7

8 Anything you can think of Evolving How We Interact With The Network Operating System Traditional Approach New Paradigm CLI Network OS SNMP HTML XML Monitoring Policy App AAA CDP Syslog Netflow Routing Protocols Interface Discovery Routing Data Plane Events C Java... Span Actions App EEM (TCL)

9 Introducing One Platform Kit - onepk Applications That YOU Create onepk Any Cisco Router or Switch Flexible development environment to: Innovate Extend Automate Customize Enhance Modify

10 Who Will be the Network Programmer? Applications That WHO Creates? Network Engineer Developer onepk Network, IOS Skills Scripting Skills Programming Skills Expertise Network-centric use cases Scripts, PoCs, HA networks Application-centric use cases Scalable, HA applications 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 10

11 Agenda Úvod SDN, One, OnePK? Koncept OnePK OnePK API a příklady použití Shrnutí 2013 Cisco and/or its affiliates. All rights reserved. Cisco Connect 11

12 onepk Architecture C, JAVA Program onepk API Presentation onepk API Infrastructure IOS / XE (Catalyst, ISR, ASR1K) NXOS (Nexus Platforms) IOS XR (ASR 9K, CRS) 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 12 12

13 onepk API Libraries Initial Service Sets Element Utilities Discovery Developer Element Capabilities Configuration Management Interface/Ports Events Location Information Syslog Events and Queries AAA Interface Path Trace Network Element Discovery Service Discovery Topology Discovery Debug Capabilities Tracing Interfaces Management Extensions Data Path Packet/Flow Classifiers Copy/Punt/Inject Statistics Policy Interface Policy Interface Feature Policy Forwarding Policy Flow Action Policy Routing Read RIB Routes Add/Delete Application Routes RIB Events (Route up/down) 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 13

14 Blade Where Do onepk Applications Run? Choose the Hosting Model that Suits Your Platform and Your Application App On An External Server Plentiful memory/compute Higher latency and delay Supported on by all platforms App On A Hardware Blade Dedicated memory/compute Low latency and delay Requires modular hardware blade App On the Router Shared memory/compute Very low latency and delay Requires modular software architecture 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 14 14

15 Yes, it is secure App Security Digital Signing Certification Process Code Isolation Strong Typing Code Security Admin Security CLI Control Resource Allocation Access Control (ACL) AAA (PKI) Encryption (TLS) Runtime Security Container Security Isolation Resource Consumption Trusted/Untrusted Containers 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 15 15

16 Agenda Úvod SDN, One, OnePK? Koncept OnePK OnePK API a příklady použití Shrnutí 2013 Cisco and/or its affiliates. All rights reserved. Cisco Connect 16

17 onepk APIs are Grouped in Service Sets Base Service Set Data Path Policy Routing Element Discovery Utility Developer Description Provides packet delivery service to application: Copy, Punt, Inject Provides filtering (ACL), classification (Class-maps, Policy-maps), actions (Marking, Policing, Queuing, Copy, Punt) and applying policies to interfaces on network elements Read RIB routes, add/remove routes, receive RIB notifications Get element properties, CPU/memory statistics, network interfaces, element and interface events L2 topology and local service discovery Syslog events notification, Path tracing capabilities (ingress/egress and interface stats, next-hop info, etc.) Debug capability, CLI extension which allows application to extend/integrate application s CLIs with network element

18 Element Getting Properties and Statistics System Interfaces Discovery CPU, Memory, Platform, Serial #, Versions, Uptime, Routing Location, OIR, CLI Changes Port, Slot, BW, MTU, TX/RX, BPS, PPS, Errors, Other Stats, QoS Config, Link Changes CDP, Security Topology Graph, Edges, Nodes, Topology Changes Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 18

19 Element Setting Properties and Statistics Key Area for Future Enhancements System Interfaces Discovery Location IP address, MTU, Clear Stats, Shut/No Shut Filters Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 19

20 Example: Getting System Properties char *str = NULL; onep_element_connect(elema, user, pwd, NULL, &sh); onep_element_get_property(elema, &property); if (property) { onep_element_to_string(elema, &str); if (str) { fprintf(stderr, "\nelement Info: %s\n", str); free(str); } } 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 20

21 Example: Getting System Properties 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 21

22 Example: Simplified Management Problem: Misconfigurations cause network outages, degrade performance, impact SLAs. Value proposition: Get, set, and detect configuration changes via cross-platform API 1. Network begins with mismatched parameters on either side of link (e.g. MTU) 2 NX3K 1 MTU 1500 MTU Application checks parameters on either side and identifies mismatches (red lines) 3 CRS 3. Application sets parameters to match (lines turn green) 4. Application registers for events related to parameters change. 4 9K MTU 1518 MTU Users logs into console and manually changes parameter. Topology indicates change. 5 1K MTU 1600 MTU 1500 MTU 1500 ISR MTU Cisco and/or its affiliates. All rights reserved. Cisco Connect 22

23 MTU In Action 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 23

24 Policy Getting Policies and Routes Routing QoS Security RIB, Next-Hop, metric, AD, scope (VRF), Changes Configured Classes Configured ACLs Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 25

25 Policy Setting Policies and Routes Routing QoS Security Static routes Service-Policies (Police, Mark, Shape, Queue) ACLs Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 26

26 Getting and Setting Routes Get Routes Set Routes 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 27

27 onepk Example: Custom Routing Data Center Traffic Forwarding Based on a Custom Algorithm 1 Destination ISR Pricing Route A Route B $1 $2 $1 $2 2 App Route A Route B $3 $3 3 Unique Data Forwarding Algorithm Highly Optimized for the Network Operator s Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 28

28 Custom Routing Initial Setup: Default routing using EIGRP 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 29

29 Custom Routing Routing for Dollars: Application driven routes installed in network 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 30

30 Custom Routing Tracing the application installed route using the developer and element services 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 31

31 Getting Packets Data Plane Copy or Punt Packets Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 32

32 Injecting Packets Data Plane Inject New or Modified Packets Application 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 33

33 Punting and Injecting Packets (C) TRY(rc, onep_dpss_register_for_packets( ne1, dpss, targ_left, interesting_class, ONEP_DPSS_ACTION_PUNT, encrypt_callback, (void *)intf_left, &reg_handle), "Register for packets"); Where traffic goes next Defines traffic of interest Action to take on interesting traffic 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 34

34 Example: Custom Encryption Problem: Customers want custom encryption on specific traffic types Value proposition: Punt traffic of interest, encrypt, and re-inject. 1. Policy APIs on ingress router are set to punt telnet and syslog to app 2. App encrypts punted traffic and re-injects into data path. 3. Policy APIs on egress router punt telnet and syslog to app 4. App decrypts punted traffic and re-injects into data path. 5. Traffic that does not match policy passes through unencrypted. telnet http 5 http telnet encrypt http 1 encrypt 2 Unsecure Network 3 encrypt telnet onepk application onepk application Cisco and/or its affiliates. All rights reserved. Cisco Connect 35

35 Custom Encryption in Action What Client Sees What Wireshark Sees 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 36

36 Emergency Response Network pramacom COMMUNICATION & OPTICS Problem: How to deliver secure, trusted, robust, cost-effective broadband connectivity to mobile emergency response units? Solution: Use Network Programming based on Cisco onepk and Cisco IOS Embedded Event Manager to integrate low-cost, high-bandwidth options with accredited legacy radio connectivity: 1. Connect high-bandwidth forward clients via WiFi 4 K a Band 2. Use Cisco IOS EEM for onboard system integration and adaptation WiFi 1 2 EEM Cisco 819 PMR Radio 3 Cisco 29xx 3. Use Cisco onepk to redirect IKE key exchange out-of-band via PMR network 4. Secure IPSec tunnel via cost-effective high bandwidth K a Band 5. Reliable, secure emergency response network saving ~4M operating cost annually

37 What Could You Do With onepk? onepk Sample Applications 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 38

38 Další náměty k nasazení OnePK Backup interface manipulation Dynamically apply policy as needed Firewall Applications / content filtering Load Balancers Packet and flow monitors Traffic capture and injection Quality of experience troubleshooting Web management application with REST interface Management over XMPP 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 39

39 Agenda Úvod SDN, One, OnePK? Koncept OnePK OnePK API a příklady použití Shrnutí 2013 Cisco and/or its affiliates. All rights reserved. Cisco Connect 40

40 Summary: Portfolio of API, Languages and Abstractions Network Programming with onepk and Embedded Network Automation Native Network OS Embedded Automation Advanced Network OS Embedded Scripting Structured API Object Oriented API Higher-Level Abstractions / Interfaces Event-/Expression- MIB, PfR, IPSLA Thresholds, Embedded Event Manager Applets, Tcl, Python, Embedded Event Manager, EASy, onepk C onepk Java onepk Libraries REST, XMPP, Design Patterns, OMNI Controllers, Network Automation Embedded Automations Choice and Flexibility of Implementation 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 41

41 Conclusion: Why onepk? BUILD, AUTOMATE, IMPROVE SPEED & FASTER ADAPTABILITY EXTEND REVENUE & COST SAVINGS SIMPLICITY, INTEGRATION & THE POWER OF CHOICE 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 42

42 Prosíme, ohodnoťte tuto přednášku. T-SDN2 / L Cisco and/or its affiliates. All rights reserved. Cisco Connect 44

43 Děkujeme za pozornost Cisco and/or its affiliates. All rights reserved. Cisco Connect 45

Programmability of Cisco DC Infrastructure

Programmability of Cisco DC Infrastructure Dubrovnik, Croatia, South East Europe 20-22 May, 2013 Programmability of Cisco DC Infrastructure Ulrich Hamm Sascha Merg 2011 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Agenda

More information

Pradeep Kathail Chief Software Architect Network Operating Systems Technology Group, Cisco Systems Inc.

Pradeep Kathail Chief Software Architect Network Operating Systems Technology Group, Cisco Systems Inc. Pradeep Kathail Chief Software Architect Network Operating Systems Technology Group, Cisco Systems Inc. March 4 th, 2014 2012 2010 Cisco and/or its affiliates. All rights reserved. 1 2012 Cisco and/or

More information

onepk Designing Real World Applications

onepk Designing Real World Applications onepk Designing Real World Applications Bruno Klauser Consulting Systems Engineer Jason Pfeifer Technical Marketing Engineer onepk is the cisco software development kit that offers APIs in multiple languages

More information

Network Programming in a Cisco Open Network Environment Start using onepk and EEM

Network Programming in a Cisco Open Network Environment Start using onepk and EEM Praha, Hotel Clarion 10. 11. dubna 2013 Network Programming in a Cisco Open Network Environment Start using onepk and EEM T-SDN4/L3 Bruno Klauser Consulting Engineer BN EMEAR CTO Team bklauser@cisco.com

More information

One Platform Kit: The Power to Innovate

One Platform Kit: The Power to Innovate White Paper One Platform Kit: The Power to Innovate What Could You Do with the Power of the Network? What if you could: Reach into your network and extract the information you need, when you need it? Directly

More information

Implementing OnePK. One Platform Kit (onepk) is a cross platform API and software development kit that enables the user to

Implementing OnePK. One Platform Kit (onepk) is a cross platform API and software development kit that enables the user to One Platform Kit (onepk) is a cross platform API and software development kit that enables the user to develop applications that interact directly with Cisco networking devices, and provides the user with

More information

Cisco Virtual Networking Solution for OpenStack

Cisco Virtual Networking Solution for OpenStack Data Sheet Cisco Virtual Networking Solution for OpenStack Product Overview Extend enterprise-class networking features to OpenStack cloud environments. A reliable virtual network infrastructure that provides

More information

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco PSOACI-4592 Why ACI: An overview and a customer (BBVA) perspective TJ Bijlsma César Martinez Joaquin Crespo Technology Officer DC EMEAR Cisco Lead Architect BBVA Lead Architect BBVA Cisco Spark How Questions?

More information

Network Programming in a Cisco Open Network Environment Strategy and Overview

Network Programming in a Cisco Open Network Environment Strategy and Overview Praha, Hotel Clarion 10. 11. dubna 2013 Network Programming in a Cisco Open Network Environment Strategy and Overview T-SDN1/L1 Bruno Klauser Consulting Engineer BN EMEAR CTO Team bklauser@cisco.com 2011

More information

IWAN APIC-EM Application Cisco Intelligent WAN

IWAN APIC-EM Application Cisco Intelligent WAN IWAN APIC-EM Application Cisco Intelligent WAN René og Per Cisco DK SE s Feb 23 th 2016 AVC MPLS Private Cloud 3G/4G-LTE Virtual Private Cloud Branch WAAS PfR Internet Public Cloud Control, Management,

More information

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016 Network Automation and Branch Agility The Network Helps Enable Digital Business Rajinder Singh Product Sales Specialist June 2016 Agenda WAN Market Drivers Cisco Intelligent WAN (IWAN) Cisco Intelligent

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Data Sheet Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Product Overview Cisco Dynamic Multipoint VPN (DMVPN) is a Cisco IOS Software-based security solution for building

More information

Vendor: Cisco. Exam Code: Exam Name: Developing with Cisco Network Programmability (NPDEV) Version: Demo

Vendor: Cisco. Exam Code: Exam Name: Developing with Cisco Network Programmability (NPDEV) Version: Demo Vendor: Cisco Exam Code: 600-502 Exam Name: Developing with Cisco Network Programmability (NPDEV) Version: Demo Question Set 1 QUESTION 1 A stock brokerage firm requires that all trades are executed quickly

More information

LiveAction IWAN Management

LiveAction IWAN Management LIVEACTION, INC. LiveAction IWAN Management LiveAction, Inc. 3500 WEST BAYSHORE ROAD PALO Copyright ALTO, CA 2016 94303 LiveAction, Inc. All rights reserved. LiveAction, LiveNX, LiveUX, the LiveAction

More information

Cisco Virtual Managed Services

Cisco Virtual Managed Services Data Sheet Cisco Virtual Managed Services SD-WAN Made Simple for Service Providers Cisco Virtual Managed Services (VMS) is a cloud native solution for service providers to automate, innovate and accelerate

More information

Software Defined Networks For Service Providers. A Practical Approach

Software Defined Networks For Service Providers. A Practical Approach BRKSPG-3683 Software Defined Networks For Providers. A Practical Approach Michael O Gorman Chief Architect Office C97-693316-00 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

More information

Cisco Nexus 1000V Switch for Microsoft Hyper-V

Cisco Nexus 1000V Switch for Microsoft Hyper-V Q&A Cisco Nexus 1000V Switch for Microsoft Hyper-V Overview Q. What are Cisco Nexus 1000V Switches? A. Cisco Nexus 1000V Switches provide a comprehensive and extensible architectural platform for virtual

More information

Cisco Extensible Network Controller

Cisco Extensible Network Controller Data Sheet Cisco Extensible Network Controller Product Overview Today s resource intensive applications are making the network traffic grow exponentially putting high demands on the existing network. Companies

More information

Cisco ISR G2 Management Overview

Cisco ISR G2 Management Overview Cisco ISR G2 Management Overview Introduction The new Cisco Integrated Services Routers Generation 2 (ISR G2) Family of routers delivers the borderless network that can transform the branch office and

More information

CertKiller q

CertKiller q CertKiller.500-451.28q Number: 500-451 Passing Score: 800 Time Limit: 120 min File Version: 5.3 500-451 Cisco Unified Access Systems Engineer Exam I just passed today with 89%. My sole focus was the VCE.

More information

Cisco Data Center Network Manager 5.1

Cisco Data Center Network Manager 5.1 Cisco Data Center Network Manager 5.1 Product Overview Modern data centers are becoming increasingly large and complex. New technology architectures such as cloud computing and virtualization are adding

More information

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Product Overview Cisco Dynamic Multipoint VPN (DMVPN) is a Cisco IOS Software-based security solution for building scalable

More information

Cisco 5921 Embedded Services Router

Cisco 5921 Embedded Services Router Data Sheet Cisco 5921 Embedded Services Router The Cisco 5921 Embedded Services Router (ESR) is a Cisco IOS software router. It is designed to operate on small, low-power, Linux-based platforms to extend

More information

Performing Path Traces

Performing Path Traces About Path Trace, page 1 Performing a Path Trace, page 13 Collecting QoS and Interface Statistics in a Path Trace, page 15 About Path Trace With Path Trace, the controller reviews and collects network

More information

Cisco 5921 Embedded Services Router

Cisco 5921 Embedded Services Router Data Sheet Cisco 5921 Embedded Services Router The Cisco 5921 Embedded Services Router (ESR) is a Cisco IOS software router application. It is designed to operate on small, low-power, Linux-based platforms

More information

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC)

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC) Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC) COURSE OVERVIEW: Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent

More information

GRE and DM VPNs. Understanding the GRE Modes Page CHAPTER

GRE and DM VPNs. Understanding the GRE Modes Page CHAPTER CHAPTER 23 You can configure Generic Routing Encapsulation (GRE) and Dynamic Multipoint (DM) VPNs that include GRE mode configurations. You can configure IPsec GRE VPNs for hub-and-spoke, point-to-point,

More information

Intelligent WAN : CVU update

Intelligent WAN : CVU update Intelligent WAN : CVU update Deliver enhanced mobile experience at the branch with Intelligent WAN Soren D. Andreasen (sandreas@cisco.com) Technical Solution Architect CCIE# 3252 Agenda IWAN 2.0/2.1 overview

More information

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC)

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC) Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC) Dedi Shindler - Sr. Manager Product Management Cloud System Management Technology Group Cisco Agenda Trends Influencing

More information

Managing and Securing Computer Networks. Guy Leduc. Chapter 2: Software-Defined Networks (SDN) Chapter 2. Chapter goals:

Managing and Securing Computer Networks. Guy Leduc. Chapter 2: Software-Defined Networks (SDN) Chapter 2. Chapter goals: Managing and Securing Computer Networks Guy Leduc Chapter 2: Software-Defined Networks (SDN) Mainly based on: Computer Networks and Internets, 6 th Edition Douglas E. Comer Pearson Education, 2015 (Chapter

More information

Supported Platforms for Cisco Path Trace, Release x. This document describes the supported platforms for the Cisco Path Trace, Release x.

Supported Platforms for Cisco Path Trace, Release x. This document describes the supported platforms for the Cisco Path Trace, Release x. Cisco Path Trace Application for APIC-EM Supported Platforms, Release 1.5.0.x First Published: 2017-06-23, Release 1.5.0.x This document describes the supported platforms for the Cisco Path Trace, Release

More information

Borderless Networks. Tom Schepers, Director Systems Engineering

Borderless Networks. Tom Schepers, Director Systems Engineering Borderless Networks Tom Schepers, Director Systems Engineering Agenda Introducing Enterprise Network Architecture Unified Access Cloud Intelligent Network & Unified Services Enterprise Networks in Action

More information

Service Mesh and Microservices Networking

Service Mesh and Microservices Networking Service Mesh and Microservices Networking WHITEPAPER Service mesh and microservice networking As organizations adopt cloud infrastructure, there is a concurrent change in application architectures towards

More information

Cisco Application Centric Infrastructure Roadshow. Wednesday, 2. April 14

Cisco Application Centric Infrastructure Roadshow. Wednesday, 2. April 14 Cisco Application Centric Infrastructure Roadshow Wednesday, 2. April 14 Cisco ACI Roadshow - Agenda Business and IT trends Cisco Open Network Environment (ONE) Lunch Cisco Application Centric Infrastructure

More information

Cisco Exam Questions & Answers

Cisco Exam Questions & Answers Cisco 648-375 Exam Questions & Answers Number: 648-375 Passing Score: 800 Time Limit: 120 min File Version: 22.1 http://www.gratisexam.com/ Cisco 648-375 Exam Questions & Answers Exam Name: Cisco Express

More information

Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies)

Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies) CVP CVP Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies) 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.

More information

IOS Strategy and Evolution

IOS Strategy and Evolution IOS Strategy and Evolution Vittal Krishnamurthy Product Manager, Network Operating Systems Technology Group (NOSTG) About the Speaker 3 About NOSTG (Network Operating System Technology Group) The Central

More information

Virtuální firewall v ukázkách a příkladech

Virtuální firewall v ukázkách a příkladech Praha, hotel Clarion 10. 11. dubna 2013 Virtuální firewall v ukázkách a příkladech T-SEC3 / L2 Tomáš Michaeli Cisco 2013 2011 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Agenda VXLAN

More information

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV.

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV. 2 CHAPTER Cisco's Disaster Recovery as a Service (DRaaS) architecture supports virtual data centers that consist of a collection of geographically-dispersed data center locations. Since data centers are

More information

CCIE Routing & Switching

CCIE Routing & Switching CCIE Routing & Switching Cisco Certified Internetwork Expert Routing and Switching (CCIE Routing and Switching) certifies the skills required of expert-level network engineers to plan, operate and troubleshoot

More information

Power Your Branch with Intelligent WAN

Power Your Branch with Intelligent WAN Power Your Branch with Intelligent WAN Introducing the ISR4400 series Updating the ASR1000 series Enterprise Networking David Roten - Technical Marketing Engineer What s Happening in Your World? MOBILITY,

More information

Configuring Bridge Domain Interfaces

Configuring Bridge Domain Interfaces The Cisco ASR 1000 Series Aggregation Services Routers support the bridge domain interface (BDI) feature for packaging Layer 2 Ethernet segments into Layer 3 IP. Restrictions for Bridge Domain Interfaces,

More information

Pressures on the WAN

Pressures on the WAN IWAN Radek Boch, Systems Engineer, Cisco, rboch@cisco.com CCIE#7095 14.11.2013 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 The Application Landscape Is Changing Applications Are

More information

Transformation through Innovation

Transformation through Innovation INSSPG-2921 Transformation through Innovation Sumeet Arora Senior Vice President/GM, SP Network Systems Service Providers Biggest Challenges Web scale breaks our current cost and design models. l don t

More information

Implementing Cisco Quality of Service 2.5 (QOS)

Implementing Cisco Quality of Service 2.5 (QOS) Implementing Cisco Quality of Service 2.5 (QOS) COURSE OVERVIEW: Implementing Cisco Quality of Service (QOS) v2.5 provides learners with in-depth knowledge of QoS requirements, conceptual models such as

More information

Cisco IOS Software Release 15M&T Q&A

Cisco IOS Software Release 15M&T Q&A Cisco IOS Software Release 15M&T Q&A Last updated: July, 2010 General Q. What is Cisco IOS Software Release 15M&T? A. Developed for wide deployment in the world's most demanding Enterprise, Access, and

More information

Nexus 1000V in Context of SDN. Martin Divis, CSE,

Nexus 1000V in Context of SDN. Martin Divis, CSE, Nexus 1000V in Context of SDN Martin Divis, CSE, mdivis@cisco.com Why Cisco Nexus 1000V Losing the Edge Server Admin Host Host Host Host Server Admin manages virtual switching! vswitch vswitch vswitch

More information

OpenFlow: What s it Good for?

OpenFlow: What s it Good for? OpenFlow: What s it Good for? Apricot 2016 Pete Moyer pmoyer@brocade.com Principal Solutions Architect Agenda SDN & OpenFlow Refresher How we got here SDN/OF Deployment Examples Other practical use cases

More information

Cisco ASR 1000 Series Aggregation Services Routers: QoS Architecture and Solutions

Cisco ASR 1000 Series Aggregation Services Routers: QoS Architecture and Solutions Cisco ASR 1000 Series Aggregation Services Routers: QoS Architecture and Solutions Introduction Much more bandwidth is available now than during the times of 300-bps modems, but the same business principles

More information

Technologies for the future of Network Insight and Automation

Technologies for the future of Network Insight and Automation Technologies for the future of Network Insight and Automation Richard Wade (ricwade@cisco.com) Technical Leader, Asia-Pacific Infrastructure Programmability This Session s Context Service Creation Service

More information

Seven Criteria for a Sound Investment in WAN Optimization

Seven Criteria for a Sound Investment in WAN Optimization Seven Criteria for a Sound Investment in WAN Optimization Introduction WAN optimization technology brings three important business benefits to IT organizations: Reduces branch office infrastructure costs

More information

SDN Security BRKSEC Alok Mittal Security Business Group, Cisco

SDN Security BRKSEC Alok Mittal Security Business Group, Cisco SDN Security Alok Mittal Security Business Group, Cisco Security at the Speed of the Network Automating and Accelerating Security Through SDN Countering threats is complex and difficult. Software Defined

More information

VXLAN Overview: Cisco Nexus 9000 Series Switches

VXLAN Overview: Cisco Nexus 9000 Series Switches White Paper VXLAN Overview: Cisco Nexus 9000 Series Switches What You Will Learn Traditional network segmentation has been provided by VLANs that are standardized under the IEEE 802.1Q group. VLANs provide

More information

Securing VMware NSX MAY 2014

Securing VMware NSX MAY 2014 Securing VMware NSX MAY 2014 Securing VMware NSX Table of Contents Executive Summary... 2 NSX Traffic [Control, Management, and Data]... 3 NSX Manager:... 5 NSX Controllers:... 8 NSX Edge Gateway:... 9

More information

Exam Code: Exam Code: Exam Name: Advanced Borderless Network Architecture Systems Engineer test.

Exam Code: Exam Code: Exam Name: Advanced Borderless Network Architecture Systems Engineer test. Exam Code: 700-303 Number: 700-303 Passing Score: 800 Time Limit: 120 min File Version: 41.2 http://www.gratisexam.com/ Exam Code: 700-303 Exam Name: Advanced Borderless Network Architecture Systems Engineer

More information

Cisco Group Encrypted Transport VPN

Cisco Group Encrypted Transport VPN Cisco Group Encrypted Transport VPN Q. What is Cisco Group Encrypted Transport VPN? A. Cisco Group Encrypted Transport is a next-generation WAN VPN solution that defines a new category of VPN, one that

More information

Cisco Nexus 9500 Series Switches Buffer and Queuing Architecture

Cisco Nexus 9500 Series Switches Buffer and Queuing Architecture White Paper Cisco Nexus 9500 Series Switches Buffer and Queuing Architecture White Paper December 2014 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.

More information

Cisco IOS Embedded Event Manager

Cisco IOS Embedded Event Manager Data Sheet Cisco IOS Embedded Event Manager Last updated: November 2011 Product Overview Cisco IOS Embedded Event Manager (EEM) is a unique subsystem within Cisco IOS Software. EEM is a powerful and flexible

More information

Configuring Cisco Nexus 7000 Series Switches

Configuring Cisco Nexus 7000 Series Switches Configuring Cisco Nexus 7000 Series Switches DCNX7K v3.1; 5 Days, Instructor-led Course Description The Configuring Cisco Nexus 7000 Switches (DCNX7K) v3.0 course is a 5-day ILT training program that is

More information

Cisco Plug and Play Feature Guide Cisco Services. Cisco Plug and Play Feature Guide Cisco and/or its affiliates.

Cisco Plug and Play Feature Guide Cisco Services. Cisco Plug and Play Feature Guide Cisco and/or its affiliates. Cisco Services TABLE OF CONTENTS Configuring Cisco Plug and Play... 14 Contents Introduction... 3 Cisco Plug and Play Components... 3 Plug-n-Play Agent... 3 Key Benefits... 4 Plug and Play Server... 4

More information

Deploy Microsoft SQL Server 2014 on a Cisco Application Centric Infrastructure Policy Framework

Deploy Microsoft SQL Server 2014 on a Cisco Application Centric Infrastructure Policy Framework White Paper Deploy Microsoft SQL Server 2014 on a Cisco Application Centric Infrastructure Policy Framework August 2015 2015 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.

More information

TestOut Routing and Switching Pro - English 6.0.x COURSE OUTLINE. Modified

TestOut Routing and Switching Pro - English 6.0.x COURSE OUTLINE. Modified TestOut Routing and Switching Pro - English 6.0.x COURSE OUTLINE Modified 2017-07-10 TestOut Routing and Switching Pro Outline- English 6.0.x Videos: 133 (15:42:34) Demonstrations: 78 (7:22:19) Simulations:

More information

Cisco Certdumps Questions & Answers - Testing Engine

Cisco Certdumps Questions & Answers - Testing Engine Cisco Certdumps 642-996 Questions & Answers - Testing Engine Number: 642-996 Passing Score: 797 Time Limit: 120 min File Version: 16.8 http://www.gratisexam.com/ Sections 1. A 2. B 3. C 4. Exhibit Case

More information

Vendor: Cisco. Exam Code: Exam Name: Advanced Routing and Switching for Field Engineers - ARSFE. Version: Demo

Vendor: Cisco. Exam Code: Exam Name: Advanced Routing and Switching for Field Engineers - ARSFE. Version: Demo Vendor: Cisco Exam Code: 644-068 Exam Name: Advanced Routing and Switching for Field Engineers - ARSFE Version: Demo QUESTION: 1 Which three of the following are major trends that fuel the demand for routing

More information

Cisco SD-WAN and DNA-C

Cisco SD-WAN and DNA-C Cisco SD-WAN and DNA-C SD-WAN Cisco SD-WAN Intent-based networking for the branch and WAN 4x Improved application experience Better user experience Deploy applications in minutes on any platform with consistent

More information

Cloud Intelligent Network

Cloud Intelligent Network Dubrovnik, Croatia, South East Europe 20-22 May, 2013 Cloud Intelligent Network Mitko Vasilev CIN Lead Central Europe mitko@cisco.com 2011 2012 Cisco and/or its affiliates. All rights reserved. 1 New Application

More information

Configuring sflow. Information About sflow. sflow Agent. This chapter contains the following sections:

Configuring sflow. Information About sflow. sflow Agent. This chapter contains the following sections: This chapter contains the following sections: Information About sflow, page 1 Licensing Requirements, page 2 Prerequisites, page 2 Guidelines and Limitations for sflow, page 2 Default Settings for sflow,

More information

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002 Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002 Agenda Joint Cisco and Microsoft Integration Efforts Introduction to CCA-MCP What is a Pattern?

More information

Intelligent WAN: Leveraging the Internet Secure WAN Transport and Internet Access

Intelligent WAN: Leveraging the Internet Secure WAN Transport and Internet Access Now a part of Cisco We bought Viptela Intelligent WAN: Leveraging the Internet Secure WAN Transport and Internet Access Branch Hybrid WAN Transport IPsec Secure MPLS (IP-VPN) Private Cloud Virtual Private

More information

Secure Extensible Network. Solution and Technology Introduction

Secure Extensible Network. Solution and Technology Introduction Secure Extensible Network Solution and Technology Introduction Agenda Company Overview Current WAN Challenges Viptela Solution Migration Strategy Product Lineup 2 Viptela At A Glance $110M VC funding:

More information

Managing Site-to-Site VPNs: The Basics

Managing Site-to-Site VPNs: The Basics CHAPTER 23 A virtual private network (VPN) consists of multiple remote peers transmitting private data securely to one another over an unsecured network, such as the Internet. Site-to-site VPNs use tunnels

More information

What s New in Release 9.2 Martin Adamčík

What s New in Release 9.2 Martin Adamčík CA SPECTRUM Infrastructure Manager What s New in Release 9.2 Martin Adamčík Agenda New IP Routing Management New Report Management Capabilities Network Configuration Management Enhancements in r9.2 Other

More information

Troubleshooting Tools. Tools for Gathering Information

Troubleshooting Tools. Tools for Gathering Information Internetwork Expert s CCNP Bootcamp Troubleshooting Tools http:// Tools for Gathering Information Before implementing a fix, information must be gathered about a problem to eliminate as many variables

More information

Cisco Wide Area Application Services: Secure, Scalable, and Simple Central Management

Cisco Wide Area Application Services: Secure, Scalable, and Simple Central Management Solution Overview Cisco Wide Area Application Services: Secure, Scalable, and Simple Central Management What You Will Learn Companies are challenged with conflicting requirements to consolidate costly

More information

Securing VMware NSX-T J U N E 2018

Securing VMware NSX-T J U N E 2018 Securing VMware NSX-T J U N E 2018 Securing VMware NSX Table of Contents Executive Summary...2 NSX-T Traffic [Control, Management, and Data]...3 NSX Manager:...7 NSX Controllers:...9 NSX Edge:...10 NSX-T

More information

Cisco Integrated Services Virtual Router

Cisco Integrated Services Virtual Router Data Sheet Cisco Integrated Services Virtual Router The Cisco Integrated Services Virtual Router (ISRv) is a virtual form-factor Cisco IOS XE Software router that delivers comprehensive WAN gateway and

More information

Designing Cisco Data Center Unified Computing

Designing Cisco Data Center Unified Computing Designing Cisco Data Center Unified Computing Number: 642-998 Passing Score: 800 Time Limit: 120 min File Version: 1.1 http://www.gratisexam.com/ Sections 1. Drag and Drop 2. Questions 3. Hot Spot CISCO

More information

Syllabus. Cisco Certified Design Professional. Implementing Cisco IP Routing

Syllabus. Cisco Certified Design Professional. Implementing Cisco IP Routing Syllabus Cisco Certified Design Professional Implementing Cisco IP Routing 1.0 Network Principles 1.1 Identify Cisco Express Forwarding concepts 1.1.a FIB 1.1.b Adjacency table 1.2 Explain general network

More information

Network Virtualization

Network Virtualization Network Virtualization Petr Grygárek 1 Traditional Virtualization Techniques Network Virtualization Implementation of separate logical network environments (Virtual Networks, VNs) for multiple groups on

More information

Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites

Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites The recommended knowledge and skills that a learner must have before attending this course are as follows: Knowledge

More information

CCIE Route & Switch Written (CCIERSW) 1.0

CCIE Route & Switch Written (CCIERSW) 1.0 CCIE Route & Switch Written (CCIERSW) 1.0 COURSE OVERVIEW: CCIE Route and Switch Written (CCIERSW) preparation course is a five-day course that prepares the student for the written exam portion of the

More information

Managing Site-to-Site VPNs

Managing Site-to-Site VPNs CHAPTER 21 A virtual private network (VPN) consists of multiple remote peers transmitting private data securely to one another over an unsecured network, such as the Internet. Site-to-site VPNs use tunnels

More information

CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies)

CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies) CVP CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies) 2018 Cisco and/or its affiliates. All rights reserved. This

More information

Cisco Virtual Office High-Scalability Design

Cisco Virtual Office High-Scalability Design Solution Overview Cisco Virtual Office High-Scalability Design Contents Scope of Document... 2 Introduction... 2 Platforms and Images... 2 Design A... 3 1. Configure the ACE Module... 3 2. Configure the

More information

Whitebox and Autonomous Networks

Whitebox and Autonomous Networks Whitebox and Autonomous Networks Chris Rice SVP AT&T Labs Domain 2.0 Architecture & Design 2017 AT&T Intellectual Property. All rights reserved. AT&T, Globe logo, Mobilizing Your World and DIRECTV are

More information

Implementing and Configuring Cisco SDWAN (ICSDWAN-CT)

Implementing and Configuring Cisco SDWAN (ICSDWAN-CT) Implementing and Configuring Cisco SDWAN (ICSDWAN-CT) COURSE OVERVIEW: This course discusses the Cisco s SDWAN solution using Viptela. In this class, students will configure and manage the Viptela Fabric.

More information

Virtual Security Gateway Overview

Virtual Security Gateway Overview This chapter contains the following sections: Information About the Cisco Virtual Security Gateway, page 1 Cisco Virtual Security Gateway Configuration for the Network, page 10 Feature History for Overview,

More information

Patricia Costa Product Manager, Cisco Systems

Patricia Costa Product Manager, Cisco Systems Patricia Costa patcosta@cisco.com Product Manager, Cisco Systems Dec 6 th, 2011 2010 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 2010 Cisco and/or its affiliates. All rights reserved.

More information

Cisco Nexus 9200 Switch Datasheet

Cisco Nexus 9200 Switch Datasheet Cisco Nexus 9200 Switch Datasheet CONTENT Content... 1 Overview... 2 Appearance... 2 Key Features and Benefits... 3 NX-OS Software... 4 Nexus 9200 Compare models... 6 Specification of nexus 9200 series

More information

Chapter 1: Enterprise Campus Architecture. Course v6 Chapter # , Cisco Systems, Inc. All rights reserved. Cisco Public

Chapter 1: Enterprise Campus Architecture. Course v6 Chapter # , Cisco Systems, Inc. All rights reserved. Cisco Public Chapter 1: Analyzing The Cisco Enterprise Campus Architecture CCNP SWITCH: Implementing IP Switching Course v6 1 Chapter 1 Objectives Describe common campus design options and how design choices affect

More information

Cisco Certified Network Associate ( )

Cisco Certified Network Associate ( ) Cisco Certified Network Associate (200-125) Exam Description: The Cisco Certified Network Associate (CCNA) Routing and Switching composite exam (200-125) is a 90-minute, 50 60 question assessment that

More information

Cisco Nexus 1000V Series Switches

Cisco Nexus 1000V Series Switches Cisco Nexus 1000V Series Switches Product Overview Cisco Nexus 1000V Series Switches are virtual machine access switches that are an intelligent software switch implementation for VMware vsphere environments

More information

BROCADE CLOUD-OPTIMIZED NETWORKING: THE BLUEPRINT FOR THE SOFTWARE-DEFINED NETWORK

BROCADE CLOUD-OPTIMIZED NETWORKING: THE BLUEPRINT FOR THE SOFTWARE-DEFINED NETWORK BROCADE CLOUD-OPTIMIZED NETWORKING: THE BLUEPRINT FOR THE SOFTWARE-DEFINED NETWORK Ken Cheng VP, Service Provider and Application Delivery Products September 12, 2012 Brocade Cloud-Optimized Networking

More information

Building Service-Aware Networks

Building Service-Aware Networks Building Service-Aware Networks The Next-Generation WAN/MAN Muhammad Afaq Khan, CCIE No. 9070 Cisco Press 800 East 96th Street Indianapolis, IN 46240 Building Service-Aware Networks: The Next-Generation

More information

Technology Overview. Overview CHAPTER

Technology Overview. Overview CHAPTER CHAPTER 2 Revised: July 29, 2013, This overview of AVC technology includes the following topics: Overview, page 2-1 AVC Features and Capabilities, page 2-2 AVC Architecture, page 2-4 Interoperability of

More information

Introducing Avaya SDN Fx with FatPipe Networks Next Generation SD-WAN

Introducing Avaya SDN Fx with FatPipe Networks Next Generation SD-WAN Avaya-FatPipe Solution Overview Introducing Avaya SDN Fx with FatPipe Networks Next Generation SD-WAN The Avaya SDN-Fx and FatPipe Networks solution provides a fabric-based SDN architecture for simplicity

More information

LARGE SCALE DYNAMIC MULTIPOINT VPN

LARGE SCALE DYNAMIC MULTIPOINT VPN LARGE SCALE DYNAMIC MULTIPOINT VPN NOVEMBER 2004 1 INTRODUCTION Presentation_ID 2004, Cisco Systems, Inc. All rights reserved. 2 Dynamic Multipoint VPN Facts Dynamic Multipoint VPN (DMVPN) can work with

More information

Drive Greater Value from Your Cisco Deployment with Radware Solutions

Drive Greater Value from Your Cisco Deployment with Radware Solutions Drive Greater Value from Your Cisco Deployment with Radware Solutions Ron Meyran Director, Alliances Marketing Feb 24, 2015 Introducing Radware Radware/Cisco Solution Mapping Solutions Overview & Differentiators

More information

SDWAN: Re-architecting WAN with Software Defined Networking

SDWAN: Re-architecting WAN with Software Defined Networking SDWAN: Re-architecting WAN with Software Defined Networking Introduction SDN (Software Defined Networking) is an emerging focus area in the world of networking. This architectural approach of decoupling

More information