We re ready. Are you?

Size: px
Start display at page:

Download "We re ready. Are you?"

Transcription

1 We re ready. Are you?

2 Security Architectures and the Data Center Evolution: Physical, Virtual, and Automated Gustavo Santana Technical Solutions Architect CCIEx3# 8806 (DC, SAN, R&Sw)

3 Agenda Security Threats and Data Center Architectures The Physical Data Center The Virtual Data Center The Automated Data Center

4 Security Threats and Data Center Architecture

5 The Industrialization of Hacking 95% Of Major Corporations suffer attacks 100% Of organizations interact with sites that host malware Source: 2014 Cisco Annual Security Report Viruses Worms Spyware and Rootkits 2005 Today APTs Cyberware Today +

6 Data Center Architecture

7 Data Center Architecture Applications Application Services Security Networking Servers SAN Storage Facilities

8 The Innovation Interval Is Compressing DC Architectures Physical Virtual Automated MAINFRAME MINICOMPUTER CLIENT SERVER DISTRIBUTED COMPUTING WEB SOFTWARE DEFINED X, DISAGGREGATED COMPUTING, SILICON PHOTONICS, APPLICATION CONTAINERS, ETC. SERVER VIRTUALIZATION CONVERGED INFRASTRUCTURE STORAGE VIRTUALIZATION HYPERCONVERGED

9 The Physical Data Center (Before 2006)

10 Edmund Burke

11 Common Attacks Viruses Website Defacing Low sophistication (SQL Injection, Buffer overflow, ) Fame Worms Destructives Network Impact CodeRed, Ninda

12 Security Access Control Lists (ACLs) ip access-list extended myacl permit tcp host host eq telnet interface GigabitEthernet3/1 ip address ip access-group myacl in applies ACL to interface Named ACL can be used to filter IP, TCP, UDP, ICMP traffic and more

13 Promiscuous Isolated Community A Community B Private VLANs

14 Intrusion Detection System (IDS) SOC IDS sig: SQL Inject sig: Conflicker sig: NINDA sig:code RED... SPAN port, Hub, TAP, or VACL

15 Firewall L2 L3 L4 L5-7 MAC src MAC dst IP src IP dst Port src Port dst Farmvile Firewall Tradicional Whitelist Behavior

16 Intrusion Prevention System (IPS) L2 L3 L4 L5-7 Deep Inspection MAC src MAC dst IP src IP dst Port src Port dst Farmvile Firewall Tradicional Blacklist Behavior IPS StandAlone SIO Updates sig: SQL Inject sig: Conflicker sig: NINDA sig:code RED Sig: Apache DoS..

17 North-South Data Center Topology Internet/WAN L3 L2 IDS Firewall/IPS Security ACLs East-West

18 Virtual Contexts Firewall VLAN10 VLAN20 VLAN30 Server Load Balancer VLAN110 VLAN120 VLAN130 App 1 App 2 App 3

19 Network Containers COMMON PHYSICAL INFRASTRUCTURE LOGICAL VIEW PER TENANT, SERVICE OR APPLICATION WAN DC NETWORK

20 The Virtual Data Center ( )

21 E. R. Beadle

22 Common Attacks Spyware and Rootkits Hacking Industry Obfuscation Techniques Botnets, Command-and-Control (CnC)

23 Traffic Distribution (Cisco Global Cloud Index) 17% End Users Internet/WAN Primary DC 7% Secondary DC 76%

24 Virtual Machine Mobility Limited per Rack or POD DC Virtual DC DC POD POD POD POD

25 Host 7 Host 6 Host 5 Host 4 Fabric = Big Non-Blocking Switch Host 1 Host 2 Host 3 Host 1 Host 2 Host 3 Host 4 Host 5 Host 6 Host 7

26 Host 7 Host 6 Host 5 Host 4 Fabric = Big Non-Blocking Switch LC LC LC LC LC FM FM FM LC LC LC LC LC Host 1 Host 2 Host 3

27 Spine-Leaf Topology Spines L3 L2 FabricPath Leaves Border Leaves Edge Internet/WAN Rack Blade Server UCS

28 Physical Firewall L3 L2 Fabric Path Border Leaves vpc Virtual Port Channel High Performance with Advanced Inspection Firewall Clustering

29 Virtual Networking Challenges No visibility Network Perimeter VMs on wrong VLANs NIC NIC Different control policies vswitch VM App OS VM App OS Illicit communication between VMs Host Virtual DMZ?

30 Cisco Nexus 1000V for Multi-Hypervisor NS1000V Virtual Networking Services Virtual ASAv vwaas VSG Supervisor Modules Physical Appliance: Cloud Service Platform Primary Secondary VSM vnam VSG NS1000V VSM vnam VSG NS1000V Virtual Ethernet Module vpath VXLAN ESX Virtual Ethernet Module vpath VXLAN WS2012 Hyper-V Virtual Ethernet Module vpath VXLAN KVM/OpenStack

31 Virtual Networking Security Services Virtual Security Gateway ASAv Traffic between VMs (East-West) External Access to VMs (North-South)

32 Micro-segmentation: Security Profiles per VM Attribute Administrador de Segurança

33 Micro-segmentation: Secure Group Tag N1000V: Assigns SGT based on Port-profile Assignments HR Dev VM VM VM VM Hypervisor Nexus 1000V VEM HR VM VM VM VM Hypervisor Dev Nexus 1000V VEM Server Server Finance Application ASA

34 VLAN Challenges VM VM VM VM VM VM VM VM Virtual Switch Hypervisor Up to 4094 segments Virtual Switch Hypervisor Per Device Provisioning Physical Network

35 VXLAN (Virtual extensible LAN): RFC 7348 VM VM VM VM VM VM VM VM Nexus 1000V Hypervisor VXLAN Up to 16M segments Nexus 1000V Hypervisor VXLAN Physical Network

36 Physical VXLAN Gateways VM VM VM VSM Users VM VM VM VSM Nexus 1000V VXLAN vsphere, Hyper-V, KVM Internet/WAN Nexus 1000V VXLAN vsphere, Hyper-V, KVM Nexus 5600, 6K, 7K, 9K ASR1K, ASR9K, ASA Physical Servers

37 Virtual VXLAN Gateways VXLAN VLAN 100 Layer 3 VXLAN ASAv VLAN 200 CSR 1000V Layer 2 VXLAN 5000 VXLAN Gateway CSP or x86 VLAN 500

38 VACS Virtual Application Container Services (VACS) Cloud Orchestrator VACS Administrator Internet/WAN REST API GUI Shared VLAN UCS Director Container CSR 1000V VSG Container CSR 1000V VSG Container CSR 1000V VSG PNSC Nexus 1000V VXLAN 5001 VXLAN 5002 VXLAN VM Manager Web Application Database Web Application Database Web Application Database

39

40

41 Valid Questions How can I have the same security policies for physical and virtual machines? How to provision networking (with security) automatically? How to achieve application-based visibility?

42 The Automated Data Center (After 2013)

43 Henry Ford

44 Attacks Advanced Persistent Threats (APTs) Cyberware 2013-Today Sophisticated code Script kids Multiple techniques Horizontal spread

45 Data Breach Anatomy 1 Research targets (Scan for Vulnerabilities) 2 Application Attack (SQL Injection, Buffer-Overflow) 3 Malware Transfer Perimeter (Inbound) 4 Malware installed, back door established and receives commands from CnC server Attacker 5 Scan DMZ for vulnerable Servers to exploit & retain alternative back door + find Target Server (DB) CnC Server 8 System compromised and data breached. 6 Target server found. Access to database backup, then copy them to staging server Perimeter (Outbound) 7 Target Node Zip data, slice it to multiple files, and send those out to external site over HTTPS Data Center

46 Next Generation Firewall L2 L3 L4 L5-7 Deep Inspection MAC src MAC dst IP src IP dst Port src Port dst AngryBird FW, VPN, IPS & APP, ID, URL CONTEXT-BASED Who is the user? Which is the application? Unified Management

47 Bi-Modal IT Traditional Systems of Record Cloud-Scale Systems of Engagement Getting IT Right SCM ERP/Financial Client/ Server CRM Getting IT Fast Online Content Gaming Mobile IoT ecommerce Efficient Stable Resilient Many Applications Single Application Agile / TTM / BU focused Experimental Rapid Application Evolution Server Single Server Many Servers

48

49 ACI Components APPLICATION CENTRIC INFRASTRUCTURE NEXUS 9000 APPLICATION POLICY INFRASTRUCTURE CONTROLLER ECOSYSTEM s APIC

50 ACI Example Web Application Profile The Application App DB External Users QoS QoS QoS P P P Filter Filter Filter Only VMs Physical P = Connectivity Policy Physical and Virtual

51 ACI Example

52 How to Insert a Firewall and an ADC

53 Application Profile with Service Chain

54 Provisioning an Application Profile Bare Metal Virtual Machine Containers Client Modeling Storage Storage Web Tier App Tier DB Tier Instantiation APIC VM VM VM VM VM VM VM

55 ACI is a Multi-Hypervisor Fabric Network Admin APIC ACI Fabric VLAN VXLAN VLAN NVGRE VLAN VXLAN VLAN VMware Microsoft Red Hat XenServer ESXi Hyper-V KVM VMware Microsoft Red Hat BARE METAL Virtualization Admin

56 Application Virtual Switch (AVS) Managed via APIC Segmentation: VLAN, VXLAN DVS AVS Microsegmentation: Port Group, MAC, IP, Guest OS, VM name, hypervisor, AVS AVS Extended ACI Fabric

57 Why Hybrid Cloud? Control DC/Private Clouds Security Data Sovereignty Economics Speed Scale Public Clouds Fixed workloads Choice to build / rent across providers Workload portability Consistent security Elastic workloads

58 Cisco Intercloud Native Cloud Applications Big Data and Analytics Enterprise Workloads Metacloud Collaboration and Video Enterprise Private Clouds WebEx HCS Meraki Security IaaS PaaS Partner Clouds Cisco Intercloud Services Analytics Microsoft Suite aas DRaaS Public Clouds HANA aas vdesktop aas IOE aas

59 Cisco Intercloud Fabric Architecture VM Manager ICFD App_VM VLAN 701 ICX VLAN 702 Web_VM WebServerA Private Cloud IP packet (ICX-ICS) Ethernet Frame (VM-VM) ICS VSG CSR Public Cloud ICFD = Intercloud Fabric Director ICX = Intercloud extender ICS = Intercloud Switch

60 Creating VM in Public Cloud

61 VM is Created in Cloud Provider

62 Migrating a VM to a Public Cloud

63

64 VM is Migrated

65 Intercloud Fabric Example VM Manager App_VM VLAN 701 VLAN 702 ICFD Web_VM ICX ICS VSG AppServer- 13 CSR WebServerA

66 Thank you

67 Reference Chapter 1: Virtualization definition and Data Center concepts Chapter 2: Ethernet evolution, common network topologies, and ANSI/TIA-942 Chapter 3: VLANs and VRFs Chapter 4: Server load balancing and virtual contexts Chapter 5: VDCs Chapter 6: vpc and FabricPath Chapter 7: FEX Chapter 8: EoMPLS, VPLS, and OTV Chapter 9: Storage concepts, SCSI, and virtualization Chapter 10: Fibre Channel and VSANs Chapter 11: FCIP, IVR, and NPV Chapter 12: DCB and FCoE Chapter 13: Server evolution (x86, virtualization e UCS) Chapter 14: Service Profiles Chapter 15: Nexus 1000V, VXLAN, and VM-FEX Chapter 16: vpath, VSG, ASA 1000V, vwaas, and CSR 1000V Chapter 17: Cloud computing, SDN, and Cisco ONE

68

69

70 What is MACSec? MACSec provides secure communication on Ethernet connections Guest User ENCRYPT DECRYPT 802.1X PaXrZRnOanUQ r75ptkp10eao zhip0cae34dx LRHdyhWz8k Authenticated User Supplicant With MACSec 802.1AE/Cisco SAP

71 Use Case: MACSec for Secure DCIs Single Access dark Fiber Connectivity Datacenter 1 Datacenter 2 Nexus 7000 Nexus 7000 Dual Access with dark Fiber Connectivity Datacenter 1 Datacenter 2 Nexus 7000 Nexus 7000 Nexus 7000s as Bulk Encrypters for Self managed MPLS DCI Cores Datacenter 1 Datacenter 2 Nexus 7000 Nexus 7000 MPLS Core V P C V P C Nexus 7000 Nexus 7000 Nexus 7000 Nexus 7000

72 Use Case: MACSec for Securing OTV DCIs OTV IP or Multicast-enabled Transport OTV S1 Receiver (for Gs1) S2 West East Receiver (for Gs2) OTV South

Cisco Virtual Networking Solution Nexus 1000v and Virtual Services. Abhishek Mande Engineer

Cisco Virtual Networking Solution Nexus 1000v and Virtual Services. Abhishek Mande Engineer Cisco Virtual Networking Solution Nexus 1000v and Virtual Services Abhishek Mande Engineer mailme@cisco.com Agenda Application requirements in virtualized DC The Anatomy of Nexus 1000V Virtual Services

More information

Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers

Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers Speaker: Mun Hossain Director of Product Management - Security Business Group Cisco Twitter: @CiscoDCSecurity 2 Any

More information

Data Center and Cloud Automation

Data Center and Cloud Automation Data Center and Cloud Automation Tanja Hess Systems Engineer September, 2014 AGENDA Challenges and Opportunities Manual vs. Automated IT Operations What problem are we trying to solve and how do we solve

More information

Segmentation. Threat Defense. Visibility

Segmentation. Threat Defense. Visibility Segmentation Threat Defense Visibility Establish boundaries: network, compute, virtual Enforce policy by functions, devices, organizations, compliance Control and prevent unauthorized access to networks,

More information

Virtual Tech Update Intercloud Fabric. Michael Petersen Systems Engineer, Cisco Denmark

Virtual Tech Update Intercloud Fabric. Michael Petersen Systems Engineer, Cisco Denmark Virtual Tech Update Intercloud Fabric Michael Petersen Systems Engineer, Cisco Denmark michaep2@cisco.com Agenda Introduction Intercloud and Intercloud Fabric Intercloud Fabric - New Features Intercloud

More information

"Charting the Course... Designing Cisco Data Center Infrastructure (DCID) Course Summary

Charting the Course... Designing Cisco Data Center Infrastructure (DCID) Course Summary Course Summary Description v6.0 is a five-day instructor-led course that focuses on data center design based on Cisco solutions. The course includes theoretical content, as well as design oriented case

More information

Cisco Unified Data Center Strategy

Cisco Unified Data Center Strategy Cisco Unified Data Center Strategy How can IT enable new business? Holger Müller Technical Solutions Architect, Cisco September 2014 My business is rapidly changing and I need the IT and new technologies

More information

Hybrid Cloud Solutions

Hybrid Cloud Solutions Hybrid Cloud Solutions with Cisco and Microsoft Innovation Rob Tappenden, Technical Solution Architect rtappend@cisco.com March 2016 Today s industry and business challenges Industry Evolution & Data Centres

More information

Evolution with End-to-End Data Center Virtualization

Evolution with End-to-End Data Center Virtualization Evolution with End-to-End Data Center Virtualization Yves Louis DC Virtualisation Technical Solution Architect Agenda Data Center Virtualization Overview Front-End Data Center Virtualization Core Layer

More information

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002

Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002 Cisco Cloud Architecture with Microsoft Cloud Platform Peter Lackey Technical Solutions Architect PSOSPG-1002 Agenda Joint Cisco and Microsoft Integration Efforts Introduction to CCA-MCP What is a Pattern?

More information

Service Oriented Virtual DC Design

Service Oriented Virtual DC Design Dubrovnik, Croatia, South East Europe 20-22 May, 2013 Service Oriented Virtual DC Design Višnja Milovanović Consulting Systems Engineer Data Center & Virtualization 2011 2012 Cisco and/or its affiliates.

More information

MAKE THE MOST OUT OF HYBRID CLOUD THE CISCO INTERCLOUD FABRIC

MAKE THE MOST OUT OF HYBRID CLOUD THE CISCO INTERCLOUD FABRIC MAKE THE MOST OUT OF HYBRID CLOUD THE CISCO INTERCLOUD FABRIC Luís Coelho lcoelho@cisco.com ConsulAng Systems Engineer SP DC/Cloud SP Architectures Emerging Markets Cisco NaAve Cloud ApplicaAons Big Data

More information

Cisco Application Centric Infrastructure Roadshow. Wednesday, 2. April 14

Cisco Application Centric Infrastructure Roadshow. Wednesday, 2. April 14 Cisco Application Centric Infrastructure Roadshow Wednesday, 2. April 14 Cisco ACI Roadshow - Agenda Business and IT trends Cisco Open Network Environment (ONE) Lunch Cisco Application Centric Infrastructure

More information

Intercloud Fabric. Session ID 18PT. Michael Petersen, CCIE #39836 Systems Engineer, Cisco Danmark

Intercloud Fabric. Session ID 18PT. Michael Petersen, CCIE #39836 Systems Engineer, Cisco Danmark Fabric Session ID 18PT Michael Petersen, CCIE #39836 Systems Engineer, Cisco Danmark Agenda Why Hybrid? What are the Challenges? and Cisco Fabric Solution and Architecture Overview Cisco ONE Summary, Q&A

More information

The Rise of the Intercloud

The Rise of the Intercloud The Rise of the Intercloud How Service Providers Can Leverage the Platform for the Internet of Everything Tom Williams, Director, Cloud Business Development Azhar Sayeed, Sr. Director of Solutions Engineering

More information

Cisco Designing the Cisco Cloud (CLDDES) Download Full version :

Cisco Designing the Cisco Cloud (CLDDES) Download Full version : Cisco 300-465 Designing the Cisco Cloud (CLDDES) Download Full version : http://killexams.com/pass4sure/exam-detail/300-465 out from the VM. F. Operates by allocating disk storage space in a flexible manner

More information

The Next Opportunity in the Data Centre

The Next Opportunity in the Data Centre The Next Opportunity in the Data Centre Application Centric Infrastructure Soni Jiandani Senior Vice President, Cisco THE NETWORK IS THE INFORMATION BROKER FOR ALL APPLICATIONS Applications Are Changing

More information

Cisco SDN 解决方案 ACI 的基本概念

Cisco SDN 解决方案 ACI 的基本概念 Cisco SDN 解决方案 ACI 的基本概念 Presented by: Shangxin Du(@shdu)-Solution Support Engineer, Cisco TAC Aug 26 th, 2015 2013 Cisco and/or its affiliates. All rights reserved. 1 Type Consumption Delivery Big data,

More information

SDN Security BRKSEC Alok Mittal Security Business Group, Cisco

SDN Security BRKSEC Alok Mittal Security Business Group, Cisco SDN Security Alok Mittal Security Business Group, Cisco Security at the Speed of the Network Automating and Accelerating Security Through SDN Countering threats is complex and difficult. Software Defined

More information

Cisco Designing Cisco Data Center Unified Fabric (DCUFD) v5.0. Download Full Version :

Cisco Designing Cisco Data Center Unified Fabric (DCUFD) v5.0. Download Full Version : Cisco 642-996 Designing Cisco Data Center Unified Fabric (DCUFD) v5.0 Download Full Version : https://killexams.com/pass4sure/exam-detail/642-996 Answer: A QUESTION: 156 Which three functions are provided

More information

Data Center Virtualization Setting the Foundation. Ed Bugnion VP/CTO, Cisco Server, Access and Virtualization Technology Group

Data Center Virtualization Setting the Foundation. Ed Bugnion VP/CTO, Cisco Server, Access and Virtualization Technology Group Data Center Virtualization Setting the Foundation Ed Bugnion VP/CTO, Cisco Server, Access and Virtualization Technology Group I Fought the Law, and the Law Won Sonny Curtis and the Crickets Moore s Law

More information

MAKING THE CLOUD A SECURE EXTENSION OF YOUR DATACENTER

MAKING THE CLOUD A SECURE EXTENSION OF YOUR DATACENTER MAKING THE CLOUD A SECURE EXTENSION OF YOUR DATACENTER Bret Hartman Cisco / Security & Government Group Session ID: SPO1-W25 Session Classification: General Interest 1 Mobility Cloud Threat Customer centric

More information

Network Services in Virtualized Data Center

Network Services in Virtualized Data Center Network Services in Virtualized Data Center Tomáš Michaeli Consulting Systems Engineer, DCV Central / Czech republic 21 Mar 2012 2011 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 Almost

More information

Modelos de Negócio na Era das Clouds. André Rodrigues, Cloud Systems Engineer

Modelos de Negócio na Era das Clouds. André Rodrigues, Cloud Systems Engineer Modelos de Negócio na Era das Clouds André Rodrigues, Cloud Systems Engineer Agenda Software and Cloud Changed the World Cisco s Cloud Vision&Strategy 5 Phase Cloud Plan Before Now From idea to production:

More information

Network Virtualization Business Case

Network Virtualization Business Case SESSION ID: GPS2-R01 Network Virtualization Business Case Arup Deb virtual networking & security VMware NSBU adeb@vmware.com I. Data center security today Don t hate the player, hate the game - Ice T,

More information

Data Center 3.0 Technology Evolution. Session ID 20PT

Data Center 3.0 Technology Evolution. Session ID 20PT Data Center 3.0 Technology Evolution Session ID 20PT Session Goal The focus of this seminar is on the latest technologies some of which can already be used in today's deployments and some that will become

More information

Migration from Classic DC Network to Application Centric Infrastructure

Migration from Classic DC Network to Application Centric Infrastructure Migration from Classic DC Network to Application Centric Infrastructure Kannan Ponnuswamy, Solution Architect, Cisco Advanced Services Acronyms IOS vpc VDC AAA VRF STP ISE FTP ToR UCS FEX OTV QoS BGP PIM

More information

APPLICATION CENTRIC INFRASTRUCTURE

APPLICATION CENTRIC INFRASTRUCTURE APPLICATION CENTRIC INFRASTRUCTURE Ulrich Hamm, Technical Solutions Architect, uhamm@cisco.com Jose Moreno, Technical Solutions Architect, josemor@cisco.com May 30, 2014 1 WHAT IS THE PROBLEM? (I) The

More information

2018 Cisco and/or its affiliates. All rights reserved.

2018 Cisco and/or its affiliates. All rights reserved. Beyond Data Center A Journey to self-driving Data Center with Analytics, Intelligent and Assurance Mohamad Imaduddin Systems Engineer Cisco Oct 2018 App is the new Business Developer is the new Customer

More information

CCIE Data Center Written Exam ( ) version 1.0

CCIE Data Center Written Exam ( ) version 1.0 CCIE Data Center Written Exam (350-080) version 1.0 Exam Description: The Cisco CCIE Data Center Written Exam (350-080) version 1.0 is a 2-hour test with 80 110 questions that will validate that a data

More information

Designing Cisco Data Center Unified Computing

Designing Cisco Data Center Unified Computing Designing Cisco Data Center Unified Computing Number: 642-998 Passing Score: 800 Time Limit: 120 min File Version: 1.1 http://www.gratisexam.com/ Sections 1. Drag and Drop 2. Questions 3. Hot Spot CISCO

More information

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC)

Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC) Deploying Cloud Network Services Prime Network Services Controller (formerly VNMC) Dedi Shindler - Sr. Manager Product Management Cloud System Management Technology Group Cisco Agenda Trends Influencing

More information

Building Private Cloud Infrastructure

Building Private Cloud Infrastructure Building Private Cloud Infrastructure Matthias Wessendorf Consulting Systems Engineer 20.11.2014 Cloud == FOG?? 3 The Path to Data Center Transformation Application- Based Silos Zones of Virtualization

More information

Virtual Security Gateway Overview

Virtual Security Gateway Overview This chapter contains the following sections: Information About the Cisco Virtual Security Gateway, page 1 Cisco Virtual Security Gateway Configuration for the Network, page 10 Feature History for Overview,

More information

Nexus 1000V in Context of SDN. Martin Divis, CSE,

Nexus 1000V in Context of SDN. Martin Divis, CSE, Nexus 1000V in Context of SDN Martin Divis, CSE, mdivis@cisco.com Why Cisco Nexus 1000V Losing the Edge Server Admin Host Host Host Host Server Admin manages virtual switching! vswitch vswitch vswitch

More information

Cisco Nexus 1000V InterCloud

Cisco Nexus 1000V InterCloud Deployment Guide Cisco Nexus 1000V InterCloud Deployment Guide (Draft) June 2013 2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 49 Contents

More information

Cisco Nexus 1000V Switch for Microsoft Hyper-V

Cisco Nexus 1000V Switch for Microsoft Hyper-V Q&A Cisco Nexus 1000V Switch for Microsoft Hyper-V Overview Q. What are Cisco Nexus 1000V Switches? A. Cisco Nexus 1000V Switches provide a comprehensive and extensible architectural platform for virtual

More information

Cisco Nexus 1000V InterCloud based Hybrid Cloud Architectures and Approaches

Cisco Nexus 1000V InterCloud based Hybrid Cloud Architectures and Approaches Cisco Nexus 1000V InterCloud based Hybrid Cloud Architectures and Approaches Kapil Bakshi Solutions Architect Session Details - Session Title: Cisco Nexus 1000V InterCloud-based Hybrid Cloud Architectures

More information

Title DC Automation: It s a MARVEL!

Title DC Automation: It s a MARVEL! Title DC Automation: It s a MARVEL! Name Nikos D. Anagnostatos Position Network Consultant, Network Solutions Division Classification ISO 27001: Public Data Center Evolution 2 Space Hellas - All Rights

More information

Nuage Networks Product Architecture. White Paper

Nuage Networks Product Architecture. White Paper Nuage Networks Product Architecture White Paper Table of Contents Abstract... 3 Networking from the Application s Perspective... 4 Design Principles... 4 Architecture... 4 Integrating Bare Metal Resources...

More information

DEFINING SECURITY FOR TODAY S CLOUD ENVIRONMENTS. Security Without Compromise

DEFINING SECURITY FOR TODAY S CLOUD ENVIRONMENTS. Security Without Compromise DEFINING SECURITY FOR TODAY S CLOUD ENVIRONMENTS Security Without Compromise CONTENTS INTRODUCTION 1 SECTION 1: STRETCHING BEYOND STATIC SECURITY 2 SECTION 2: NEW DEFENSES FOR CLOUD ENVIRONMENTS 5 SECTION

More information

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview STRATEGIC WHITE PAPER Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview Abstract Cloud architectures rely on Software-Defined Networking

More information

Cisco Enterprise Cloud Suite Overview Cisco and/or its affiliates. All rights reserved.

Cisco Enterprise Cloud Suite Overview Cisco and/or its affiliates. All rights reserved. Cisco Enterprise Cloud Suite Overview 2015 Cisco and/or its affiliates. All rights reserved. 1 CECS Components End User Service Catalog SERVICE PORTAL Orchestration and Management UCS Director Application

More information

ACI Terminology. This chapter contains the following sections: ACI Terminology, on page 1. Cisco ACI Term. (Approximation)

ACI Terminology. This chapter contains the following sections: ACI Terminology, on page 1. Cisco ACI Term. (Approximation) This chapter contains the following sections:, on page 1 Alias API Inspector App Center Alias A changeable name for a given object. While the name of an object, once created, cannot be changed, the Alias

More information

Cisco HyperFlex Systems

Cisco HyperFlex Systems White Paper Cisco HyperFlex Systems Install and Manage Cisco HyperFlex Systems in a Cisco ACI Environment Original Update: January 2017 Updated: March 2018 Note: This document contains material and data

More information

Policy Driven Data Centre with ACI

Policy Driven Data Centre with ACI Policy Driven Data Centre with ACI Chris Gascoigne Technical Solutions Architect #clmel Agenda Introduction What is policy Network policy Application policy Conclusion Introduction Traditional Data Centre

More information

Q&As DCID Designing Cisco Data Center Infrastructure

Q&As DCID Designing Cisco Data Center Infrastructure CertBus.com 300-160 Q&As DCID Designing Cisco Data Center Infrastructure Pass Cisco 300-160 Exam with 100% Guarantee Free Download Real Questions & Answers PDF and VCE file from: 100% Passing Guarantee

More information

Running RHV integrated with Cisco ACI. JuanLage Principal Engineer - Cisco May 2018

Running RHV integrated with Cisco ACI. JuanLage Principal Engineer - Cisco May 2018 Running RHV integrated with Cisco ACI JuanLage Principal Engineer - Cisco May 2018 Agenda Why we need SDN on the Data Center What problem are we solving? Introduction to Cisco Application Centric Infrastructure

More information

Data Center Security. Fuat KILIÇ Consulting Systems

Data Center Security. Fuat KILIÇ Consulting Systems Data Center Security Fuat KILIÇ Consulting Systems Engineer @Security Data Center Evolution WHERE ARE YOU NOW? WHERE DO YOU WANT TO BE? Traditional Data Center Virtualized Data Center (VDC) Virtualized

More information

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV.

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV. 2 CHAPTER Cisco's Disaster Recovery as a Service (DRaaS) architecture supports virtual data centers that consist of a collection of geographically-dispersed data center locations. Since data centers are

More information

Cisco Application Centric Infrastructure (ACI) Simulator

Cisco Application Centric Infrastructure (ACI) Simulator Data Sheet Cisco Application Centric Infrastructure (ACI) Simulator Cisco Application Centric Infrastructure Overview Cisco Application Centric Infrastructure (ACI) is an innovative architecture that radically

More information

Data Centar trends and evolution

Data Centar trends and evolution Data Centar trends and evolution Martina Herceg Jungic DC Lead SEE 75% of Businesses To be Digital in 5 years 1 How Companies View Digitization 81% 80% 81% 80% Mobile Technologies Mobile for Technologies

More information

Powering Applications in Mid-Market Cisco Data Center

Powering Applications in Mid-Market Cisco Data Center Powering Applications in Mid-Market Cisco Data Center Joy ABOIM UCS Business Development Manager EMEAR EBG Data Center and Commercial xx xx@cisco.com February, 2016 The Innovation Interval Is Compressing

More information

Virtuální firewall v ukázkách a příkladech

Virtuální firewall v ukázkách a příkladech Praha, hotel Clarion 10. 11. dubna 2013 Virtuální firewall v ukázkách a příkladech T-SEC3 / L2 Tomáš Michaeli Cisco 2013 2011 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Agenda VXLAN

More information

1V0-642.exam.30q.

1V0-642.exam.30q. 1V0-642.exam.30q Number: 1V0-642 Passing Score: 800 Time Limit: 120 min 1V0-642 VMware Certified Associate 6 Network Visualization Fundamentals Exam Exam A QUESTION 1 Which is NOT a benefit of virtualized

More information

Integrating Cisco UCS with Cisco ACI

Integrating Cisco UCS with Cisco ACI Integrating Cisco UCS with Cisco ACI Marian Klas, mklas@cisco.com Systems Engineer Data Center February 2015 Agenda: Connecting workloads to ACI Bare Metal Hypervisors UCS & APIC Integration and Orchestration

More information

Cisco ACI Terminology ACI Terminology 2

Cisco ACI Terminology ACI Terminology 2 inology ACI Terminology 2 Revised: May 24, 2018, ACI Terminology Cisco ACI Term Alias API Inspector App Center Application Policy Infrastructure Controller (APIC) Application Profile Atomic Counters Alias

More information

5 days lecture course and hands-on lab $3,295 USD 33 Digital Version

5 days lecture course and hands-on lab $3,295 USD 33 Digital Version Course: Duration: Fees: Cisco Learning Credits: Kit: DCAC9K v1.1 Cisco Data Center Application Centric Infrastructure 5 days lecture course and hands-on lab $3,295 USD 33 Digital Version Course Details

More information

Vendor: Cisco. Exam Code: Exam Name: Designing Cisco Data Center Unified Fabric (DCUFD) Version: Demo

Vendor: Cisco. Exam Code: Exam Name: Designing Cisco Data Center Unified Fabric (DCUFD) Version: Demo Vendor: Cisco Exam Code: 642-996 Exam Name: Designing Cisco Data Center Unified Fabric (DCUFD) Version: Demo DEMO QUESTION 1 Which three Cisco technologies or solutions are used during the virtualization

More information

Configuring Cisco Nexus 7000 Series Switches

Configuring Cisco Nexus 7000 Series Switches Configuring Cisco Nexus 7000 Series Switches DCNX7K v3.1; 5 Days, Instructor-led Course Description The Configuring Cisco Nexus 7000 Switches (DCNX7K) v3.0 course is a 5-day ILT training program that is

More information

Cisco Virtual Networking Solution for OpenStack

Cisco Virtual Networking Solution for OpenStack Data Sheet Cisco Virtual Networking Solution for OpenStack Product Overview Extend enterprise-class networking features to OpenStack cloud environments. A reliable virtual network infrastructure that provides

More information

Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack

Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack White Paper Cisco Application Centric Infrastructure and Microsoft SCVMM and Azure Pack Introduction Cisco Application Centric Infrastructure (ACI) is a next-generation data center fabric infrastructure

More information

Borderless Networks. Tom Schepers, Director Systems Engineering

Borderless Networks. Tom Schepers, Director Systems Engineering Borderless Networks Tom Schepers, Director Systems Engineering Agenda Introducing Enterprise Network Architecture Unified Access Cloud Intelligent Network & Unified Services Enterprise Networks in Action

More information

Cisco Cloud Strategy. Uwe Müller. Leader PreSales Cloud & Datacenter Germany

Cisco Cloud Strategy. Uwe Müller. Leader PreSales Cloud & Datacenter Germany Cisco Cloud Strategy Uwe Müller Leader PreSales Cloud & Datacenter Germany 277X Data created by IoE devices v. end-user 30M New devices connected every week 180B Mobile apps downloaded in 2015 78% Workloads

More information

Cisco Configuring Cisco Nexus 7000 Switches v3.1 (DCNX7K)

Cisco Configuring Cisco Nexus 7000 Switches v3.1 (DCNX7K) Course Overview View Course Dates & Register Today This course is designed for systems and field engineers who configure the Cisco Nexus 7000 Switch. This course covers the key components and procedures

More information

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme

Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitme SAI2803BU The Road to Micro- Segmentation with VMware NSX #VMworld #SAI2803BU Disclaimer This presentation may contain product features that are currently under development. This overview of new technology

More information

Creating Application Containers

Creating Application Containers This chapter contains the following sections: General Application Container Creation Process, page 1 Creating Application Container Policies, page 2 About Application Container Templates, page 5 Creating

More information

Layer 4 to Layer 7 Design

Layer 4 to Layer 7 Design Service Graphs and Layer 4 to Layer 7 Services Integration, page 1 Firewall Service Graphs, page 5 Service Node Failover, page 10 Service Graphs with Multiple Consumers and Providers, page 12 Reusing a

More information

Cisco ACI with Cisco AVS

Cisco ACI with Cisco AVS This chapter includes the following sections: Cisco AVS Overview, page 1 Cisco AVS Installation, page 6 Key Post-Installation Configuration Tasks for the Cisco AVS, page 43 Distributed Firewall, page 62

More information

Cisco VTS. Enabling the Software Defined Data Center. Jim Triestman CSE Datacenter USSP Cisco Virtual Topology System

Cisco VTS. Enabling the Software Defined Data Center. Jim Triestman CSE Datacenter USSP Cisco Virtual Topology System Cisco Virtual Topology System Cisco VTS Enabling the Software Defined Data Center Jim Triestman CSE Datacenter USSP jtriestm@cisco.com VXLAN Fabric: Choice of Automation and Programmability Application

More information

Automate Application Deployment with F5 Local Traffic Manager and Cisco Application Centric Infrastructure

Automate Application Deployment with F5 Local Traffic Manager and Cisco Application Centric Infrastructure Automate Application Deployment with F5 Local Traffic Manager and Cisco Application Centric Infrastructure White Paper 2016 Cisco F5 Networks. All rights reserved. Page 1 Contents What You Will Learn...

More information

Hybrid Clouds: Integrating the Enterprise Data Center and the Public Cloud

Hybrid Clouds: Integrating the Enterprise Data Center and the Public Cloud Hybrid Clouds: Integrating the Enterprise Data Center and the Public Cloud Usha Ramachandran, Technical Marketing Engineer Session Abstract In this session, participants will learn how to create hybrid

More information

Hypervisors networking: best practices for interconnecting with Cisco switches

Hypervisors networking: best practices for interconnecting with Cisco switches Hypervisors networking: best practices for interconnecting with Cisco switches Ramses Smeyers Customer Support Engineer Agenda What is this session about? Networking virtualization concepts Hypervisor

More information

Modernize Your IT with FlexPod. NetApp & Schneider Electric

Modernize Your IT with FlexPod. NetApp & Schneider Electric Modernize Your IT with FlexPod NetApp & Schneider Electric Hyper-distribution of Applications and Data 30M New devices connected every week 277X Data created by IoE devices v. end-user 180B Mobile apps

More information

Application Provisioning

Application Provisioning Overview, page 1 Application Categories, page 1 Application Containers, page 2 Catalogs, page 7 Self-Service Provisioning, page 8 Overview After you have allocated your resources among your user groups,

More information

Application Centric Infrastructure

Application Centric Infrastructure Application Centric Infrastructure Design pro řešení na zelené louce i do stávajícího DC DCA4 Miroslav Brzek, Systems Engineer Agenda Modern DC infrastructure Customer requirements What s Application Centric

More information

Fast IT - Policy Driven Infrastructure for the Intercloud World

Fast IT - Policy Driven Infrastructure for the Intercloud World Fast IT - Policy Driven Infrastructure for the Intercloud World Paul Horrocks Technical Solution Architect Agenda What is Fast IT? What is Policy? How Cisco delivers Fast IT The foundation for Fast IT

More information

Brocade and VMware Strategic Partners. Kyle Creason Brocade Systems Engineer

Brocade and VMware Strategic Partners. Kyle Creason Brocade Systems Engineer Brocade and VMware Strategic Partners Kyle Creason Brocade Systems Engineer Brocade Data Center Network Technologies Strategic focus areas FIBRE CHANNEL FABRICS ETHERNET FABRICS CORE ROUTING SDN NFV CLOUD

More information

Data Center Design for the Midsize Enterprise

Data Center Design for the Midsize Enterprise Data Center Design for the Midsize Enterprise Jerry Hency Technical Marketing Engineer, Data Center Group Data Center Design for the Midsize Enterprise Terminology and Goals for this session Midsize Enterprise/Organization

More information

Securing Containers Using a PNSC and a Cisco VSG

Securing Containers Using a PNSC and a Cisco VSG Securing Containers Using a PNSC and a Cisco VSG This chapter contains the following sections: About Prime Network Service Controllers, page 1 Integrating a VSG into an Application Container, page 4 About

More information

Cisco ACI and Cisco AVS

Cisco ACI and Cisco AVS This chapter includes the following sections: Cisco AVS Overview, page 1 Installing the Cisco AVS, page 5 Key Post-Installation Configuration Tasks for the Cisco AVS, page 14 Distributed Firewall, page

More information

Cloud Service Orchestration and Management with Cisco VMDC

Cloud Service Orchestration and Management with Cisco VMDC Dubai, UAE 20th March 2013 Cloud Service Orchestration and Management with Cisco VMDC Ashley Woodbridge Systems Engineer 2011 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Agenda

More information

Cisco ONE Software Overview. October 2017

Cisco ONE Software Overview. October 2017 Cisco ONE Software Overview October 2017 Agenda Why Cisco ONE Software and the Outcome Offers and Use Case Access (Wireless and Switching) WAN Cloud and Compute DC Networking Smart Accounts Resources Cisco

More information

Extreme Networks How to Build Scalable and Resilient Fabric Networks

Extreme Networks How to Build Scalable and Resilient Fabric Networks Extreme Networks How to Build Scalable and Resilient Fabric Networks Mikael Holmberg Distinguished Systems Engineer Fabrics MLAG IETF TRILL Cisco FabricPath Extreme (Brocade) VCS Juniper QFabric IEEE Fabric

More information

Creating Application Containers

Creating Application Containers This chapter contains the following sections: General Application Container Creation Process, page 1 Creating Application Container Policies, page 3 About Application Container Templates, page 5 Creating

More information

Cloud Technologies Public and Private Cloud Interconnection

Cloud Technologies Public and Private Cloud Interconnection Cloud Technologies Public and Private Cloud Interconnection Danut Agache - Technical Manager, CCIE #14573 Bogdan Nita - Data Center Architectures Consultant AGENDA About Us Cloud Technologies - Public

More information

believe in more SDN for Datacenter A Simple Approach

believe in more SDN for Datacenter A Simple Approach believe in more SDN for Datacenter A Simple Approach 1 Agenda ACI Overview Fabric Policy Constructs Hypervisor Support A migra>on scenario One management umbrella: UCS Director Q&A 2 Applica,on Language

More information

DELL EMC VSCALE FABRIC

DELL EMC VSCALE FABRIC NETWORK DATA SHEET DELL EMC VSCALE FABRIC FIELD-PROVEN BENEFITS Increased utilization and ROI Create shared resource pools (compute, storage, and data protection) that connect to a common, automated network

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

Cisco Cisco Data Center Associate Level Accelerated - v1.0 (DCAA)

Cisco Cisco Data Center Associate Level Accelerated - v1.0 (DCAA) Course Overview DCAA v1.0 is an extended hours bootcamp class designed to convey the knowledge necessary to understand and work with Cisco data center technologies. Covering the architecture, components

More information

Administration and monitoring of the Cisco Data Center with Cisco DCNM

Administration and monitoring of the Cisco Data Center with Cisco DCNM Administration and monitoring of the Cisco Data Center with Cisco DCNM Paul Dunon Consulting SE Network Management Emeric Calabrese Consulting SE Data Center Agenda DCNM Solution overview Best Practices

More information

Next-Generation Data Center Interconnect Powered by the Adaptive Cloud Fabric

Next-Generation Data Center Interconnect Powered by the Adaptive Cloud Fabric Solution Overview Next-Generation Interconnect Powered by the Adaptive Cloud Fabric Increases availability and simplifies the stretching and sharing of resources across distributed data centers Highlights

More information

Cloud Networking From Theory to Practice. Ivan Pepelnjak NIL Data Communications

Cloud Networking From Theory to Practice. Ivan Pepelnjak NIL Data Communications Cloud Networking From Theory to Practice Ivan Pepelnjak (ip@ioshints.info) NIL Data Communications Who is Ivan Pepelnjak... in 30 Seconds Networking engineer since 1985 (DECnet, Netware, X.25, OSI, IP...)

More information

Cloud Networking (VITMMA02) Server Virtualization Data Center Gear

Cloud Networking (VITMMA02) Server Virtualization Data Center Gear Cloud Networking (VITMMA02) Server Virtualization Data Center Gear Markosz Maliosz PhD Department of Telecommunications and Media Informatics Faculty of Electrical Engineering and Informatics Budapest

More information

2018 Cisco and/or its affiliates. All rights reserved. Cisco Public

2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public PSODCN-1030 Intent Based Systems Deliver Automation Dave Malik Cisco Fellow and Chief Architect Advanced Services @dmalik2 2018 Cisco

More information

Cisco CloudCenter Solution with Cisco ACI: Common Use Cases

Cisco CloudCenter Solution with Cisco ACI: Common Use Cases Cisco CloudCenter Solution with Cisco ACI: Common Use Cases Cisco ACI increases network security, automates communication policies based on business-relevant application requirements, and decreases developer

More information

Cisco Application Centric Infrastructure

Cisco Application Centric Infrastructure Data Sheet Cisco Application Centric Infrastructure What s Inside At a glance: Cisco ACI solution Main benefits Cisco ACI building blocks Main features Fabric Management and Automation Network Security

More information

Cisco HyperFlex Systems

Cisco HyperFlex Systems White Paper Cisco HyperFlex Systems Converting to Cisco Nexus 1000V Distributed Switches for Cisco HyperFlex Virtual Machine Guest and VMware vmotion Networks Author: Hui Chen October 2016 2016 Cisco and/or

More information

End To End Data Center Virtualization

End To End Data Center Virtualization Toronto, Canada May 30, 2013 End To End Data Center Virtualization Ronnie Scott DC Technology Solutions Architect ascott@cisco.com Follow us on Twitter at #CiscoConnect_TO 2011 2012 Cisco and/or its affiliates.

More information

Cisco Unified Computing System

Cisco Unified Computing System Cisco Unified Computing System Architected for Workload Diversity and Fast IT Todd Brannon, Director of Product Marketing, Unified Computing tobranno@cisco.com @tobranno Agenda Applications & Architecture

More information