Návrh inteligentní WAN sítě

Size: px
Start display at page:

Download "Návrh inteligentní WAN sítě"

Transcription

1 Návrh inteligentní WAN sítě EN2 Jaromír Pilař, CSE

2 Agenda Úvod a základní pilíře inteligentní WAN sítě Tranport Independent Design Inteligentní výběr cesty Shrnutí Presentation Title:

3 Intelligent WAN: Leveraging the Any Transport Secure WAN Transport and Internet Access Hybrid WAN Transport IPsec Secure Branch (IP-VPN) Private Cloud Virtual Private Cloud Direct Internet Access Secure WAN transport for private and virtual private cloud access Leverage local Internet path for public cloud and Internet access Internet Public Cloud Increased WAN transport capacity and cost effectively Improve application performance (right flows to right places)

4 Intelligent WAN: Leveraging the Any Transport So what is new here? Branch Hybrid WAN Transport IPsec Secure Internet as WAN with High Reliability (IP-VPN) SLAs for Business-Critical Applications Private Cloud Virtual Private Cloud Direct Internet Access Secure WAN transport for private and virtual private cloud access Leverage local Internet path for public cloud and Internet access Internet Centralized Security Policy for Internet Access Public Cloud Increased WAN transport capacity and cost effectively Dramatically Lower WAN Costs Without Compromise Improve application performance (right flows to right places)

5 Intelligent WAN Solution Components AVC Internet Private Cloud 3G/4G-LTE Virtual Private Cloud Branch WAAS PfR Public Cloud Transport Independent Intelligent Path Control Application Optimization Secure Connectivity Consistent operational model Simple provider migrations Scalable and modular design DMVPN IPsec overlay design Application best path based on delay, loss, jitter, path preference Load balancing for full utilization of all bandwidth Improved network availability Performance Routing (PfR) AVC: Application monitoring with Application Visibility and Control Per-tunnel Hierarchical QoS WAAS: Application Acceleration and bandwidth savings WAAS: Intelligent Edge Caching with Akamai Connect Certified strong encryption Comprehensive threat defense with ASA and IOS firewall/ips Cloud Web Security (CWS) for scalable secure direct Internet access

6 Transport Independent Design s využitím DMVPN

7 Cisco Intelligent WAN (IWAN) AVC Private Cloud ISR-AX 3G/4G-LTE ASR1000-AX Virtual Private Cloud Branch WAAS kamai PfRv3 Internet Public Cloud Management & Orchestration Transport Independence Intelligent Path Control Application Optimization Secure Connectivity IPSec WAN Overlay Consistent Operational Model Optimal application routing Efficient use of bandwidth Performance monitoring Optimization and Caching NG Strong Encryption Threat Defense DMVPN Performance Routing AVC, HQoS, WAAS, Akamai Suite-B, CWS, ZBFW

8 IWAN Layered Solution CPE-to-CPE overlay enables separation of transport (underlay) and VPN service (overlay) AVC/QoS PfR path selection policies PfR intelligent routing AVC/QoS Point to multipoint WAN connections with secure tunnel overlay architecture Intelligent policy routing to provide cost optimization and dynamic load balancing Perimeter Security Overlay routing over tunnels Overlay tunnels (DMVPN) Transport routing Internet Routing -VPN Routing Perimeter Security

9 Intelligent WAN Deployment Models Dual Hybrid Dual Internet Internet Public Enterprise Public Branch Branch + Internet Branch Internet Internet Highest SLA guarantees Tightly coupled to SP Expensive More BW for key applications Balanced SLA guarantees Moderately priced Best price/performance Most SP flexibility Enterprise responsible for SLAs Consistent VPN Overlay Enables Security Across Transition

10 Hybrid WAN Designs Traditional and IWAN Active/Standby WAN Paths Primary With Backup TRADITIONAL HYBRID Intelligent WAN HYBRID Active/Active WAN Paths Two IPsec Technologies Data Center Data Center One IPsec Overlay GETVPN/ DMVPN/Internet Two WAN Routing Domains : ebgp or Static Internet: ibgp, EIGRP or OSPF Route Redistribution Route Filtering Loop Prevention ISP A DMVPN Internet ASR 1000 ASR 1000 SP V GETVPN ISP A DMVPN Internet ASR 1000 ASR 1000 SP V DMVPN DMVPN One WAN Routing Domain EIGRP or ibgp ISR Branch ISR Branch

11 IWAN Transport independent Design Overview IWAN Prescriptive Design Transport Independent Design based on DMVPN Branch spoke sites establish an IPsec tunnel to and register with the hub site Data traffic flows over the DMVPN tunnels WAN interface IP address used for the tunnel source address (in a Front VRF) One tunnel per user VRF Over the Top Routing BGP or EIGRP are typically used for scalability IP routing exchanges prefix information for each site Per-tunnel QOS is applied to prevent hub site oversubscription to spoke sites IWAN POP1 MC1 R84 R85 R94 R95 R10 R11 R12 R / /24 DCI WAN Core INET IWAN POP / /24 MC2

12 Using Front Door VRF Keeping the Default Routes in Separate VRFs Customer routing context (Global table) FVRF_SP1 (SP1 routing context) FVRF_SP2 (SP2 routing context) Different default routes possible within global table and towards SP infrastructure Configuration towards SP simplified, allows for simple swap vrf definition FVRF_SP1 address-family ipv4 exit-address-family crypto keyring DMVPN vrf FVRF_SP1 pre-shared-key address key cisco123 Interface Tunnel0 ip address ip nhrp authentication HBfR3lpl ip nhrp map multicast ip nhrp map ip nhrp network-id 1 ip nhrp nhs ip nhrp shortcut tunnel source GigabitEthernet0/0 tunnel mode gre multipoint tunnel vrf FVRF_SP1 tunnel protection ipsec profile dmvpn Interface GigabitEthernet 0/0 description WAN interface to ISP in vrf ip address dhcp ip vrf forwarding FVRF_SP1 Interface GigabitEthernet 0/1 description LAN interface In Global Table

13 Typical IWAN Topology IWAN Domain Group of IWAN sites with common transports and policies 2000 sites per domain, multiple domains for larger scale IWAN POP locations 2+ WAN aggregation locations, also called Transit Sites Each Border Router (BR) is a DMVPN Hub with ibgp or EIGRP routing Summary prefixes with primary and secondary path metrics advertised out to branches Transit routing to other locations with backdoor failover routing between POP locations Dedicated BR per WAN transport IWAN Branch locations Simple consistent configurations 1 or more BRs connected to each transport L2 peering required Peer with each DMVPN Hub, stub routing IWAN POP / /8 BR11 BR12 BR21 BR22 BR31 DC / /16 DMVPN BR / / / /8 WAN Core DC2 DMVPN INET BR51 IWAN POP / /8 BR52

14 Highly Redundant Large Scale Topology DC1 DC2 IWAN POP1 DCI WAN Core IWAN POP2 BR11 BR12 BR13 BR14 R21 R22 R23 R / / /8 Support for multiple BRs per transport Horizontal scaling and redundancy Support for Multiple POPs Different Prefix Common Prefix DMVPN DMVPN INET BR31 BR41 BR51 BR / / / / / /24

15 IWAN Topology with Dual Homed POP Border Routers IWAN POP locations Same design as Typical IWAN Topology with dual homed Border Routers Additional redundancy with fewer BRs Larger BRs required to meet performance targets Not supported in IWAN 2.1 Planned for future release IWAN POP / /8 DC / /16 BR11 BR12 BR21 BR22 DMVPN DCI WAN Core DC2 DMVPN INET IWAN POP / /8 BR31 BR41 BR51 BR / / /24 15

16 IWAN Transport Independent Design Best Practices Private peering with Internet providers Use same Internet provider for hub and spoke sites Avoids Internet Exchange bottlenecks between providers Reduces round trip latency Use a separate DMVPN network per provider Increases availability, separate failure domains Enables PfR to optimize traffic between provider Data Center ASR 1000 ASR 1000 Transport settings Use the same MTU size on all WAN paths Bandwidth settings should match offered rate Use a front-side VRF to separate Internet and internal default routes Routing Protocols EIGRP or BGP for networks over 1000 sites ISP A DMVPN Blue Internet ISP C DMVPN Green Internet security Access-lists or Firewalls to block all but DMVPN tunnel traffic Tunnel source IP addresses should not be registered in DNS making the routers difficult for others to find ISR Branch

17 DMVPN Best Practice Configuration Use mode transport on transform-set NHRP needs for NAT support and saves 20 bytes MTU issues ip mtu 1400 ip tcp adjust-mss 1360 crypto ipsec fragmentation after-encryption (global) Routing Protocol EIGRP Timers on tunnel interfaces 20/60 BGP Timers default NHRP ip nhrp holdtime 600 ip nhrp registration no-unique (spokes) ISAKMP / IKEv2 Call Admission Control (CAC) (on spokes and hubs) call admission limit percent (hubs) crypto call admission limit {ike {in-negotiation-sa number sa number}} crypto ikev2 limit {max-in-negotiation-sa limit [incoming outgoing] max-sa limit} Keepalives on spokes (GRE tunnel keepalives are not supported) crypto ikev2 dpd 40 5 on-demand / crypto isakmp keepalive 40 5 First timer is twice routing protocol timer, second timer is confirmation and will run 5 times. Total time 40 + (5 * 5) = 65 seconds is greater than routing protocol hold timer. This keeps dead peer detection from running when routing protocol is functioning correctly Invalid-SPI recovery not useful

18 DMVPN Configuration F-VRF IWAN POP vrf definition IWAN-TRANSPORT-1 address-family ipv4 exit-address-family Front-door VRF definition for Transport MC1 R84 R vrf definition IWAN-TRANSPORT-2 address-family ipv4 exit-address-family Front-door VRF definition for Internet Transport INTERNET R /24

19 DMVPN Configuration IPSec crypto ikev2 keyring DMVPN-KEYRING-1 peer ANY address pre-shared-key c1sco123 crypto ikev2 profile FVRF-IKEv2-IWAN-TRANSPORT-1 match fvrf IWAN-TRANSPORT-1 match identity remote address authentication remote pre-share authentication local pre-share Maximize window size to eliminate keyring local DMVPN-KEYRING-1 future anti-replay issue crypto ipsec security-association replay window-size 512 crypto ipsec transform-set AES256/SHA/TRANSPORT esp-aes 256 esp-sha-hmac mode transport crypto ipsec profile DMVPN-PROFILE-1 set transform-set AES256/SHA/TRANSPORT set ikev2-profile FVRF-IKEv2-IWAN-TRANSPORT-1 crypto ikev2 dpd 40 5 on-demand Required for NAT support Lower overhead Set DPD timers for Branch Configs (65 s 40+5*5 > routing hold timer) MC1 IWAN POP R84 R R /24 INTERNET

20 DMVPN Hub Configuration Interfaces & Routing interface GigabitEthernet0/0/3 description -TRANSPORT vrf forwarding IWAN-TRANSPORT-1 ip address interface Tunnel100 bandwidth ip address no ip redirects ip mtu 1400 ip pim nbma-mode ip pim sparse-mode ip nhrp authentication cisco123 ip nhrp map multicast dynamic ip nhrp map group RS-20MBPS service-policy output RS-20MBPS-POLICY ip nhrp map group... ip nhrp network-id 100 ip nhrp holdtime 600 ip nhrp redirect ip tcp adjust-mss 1360 tunnel source GigabitEthernet0/0/3 tunnel mode gre multipoint tunnel key 101 tunnel vrf IWAN-TRANSPORT-1 tunnel protection ipsec profile DMVPN-PROFILE-1 ip route vrf IWAN-TRANSPORT Put Transport Interface into Front-door VRF Instantiate DMVPN Tunnel Configure interface bandwidth Configure interface MTU Multicast related configuration Add routers automatically QoS gropus DMVPN Network ID: Set DMVPN Phase 3 Map to Physical Interface Tunnel endpoint is in Front-door VRF MC1 Default route for Tunnel endpoints IWAN POP R84 R INTERNET TRANSPORT R84

21 DMVPN Spoke Configuration Interfaces & Routing Interface GigabitEthernet0/1 vrf forwarding IWAN-TRANSPORT-1 Put Transport Interface into Front-door VRF ip address interface Tunnel100 bandwidth ip address no ip redirects ip mtu 1400 ip pim dr-priority 0 Instantiate DMVPN Tunnel Configure interface bandwidth Configure interface MTU Multicast related configuration ip pim nbma-mode ip pim sparse-mode ip nhrp authentication cisco123 ip nhrp group RS-20MBPS ip nhrp network-id 100 ip nhrp holdtime 600 ip nhrp nhs nbma multicast ip nhrp nhs nbma multicast ip nhrp registration no-unique ip nhrp shortcut Assign to QoS group DMVPN Network ID: Multiple DMVPN Hub for Resiliency Set DMVPN Phase 3 Adjust TCP segment size ip tcp adjust-mss 1360 no nhrp route-watch Install shortcuts for path not in RIB if-state nhrp tunnel source GigabitEthernet0/1 NHRP control i/f state R tunnel mode gre multipoint tunnel key 101 tunnel vrf IWAN-TRANSPORT-1 tunnel protection ipsec profile DMVPN-PROFILE-1 Tunnel endpoint is in Front-door VRF /24 ip route vrf IWAN-TRANSPORT Default route for Tunnel endpoints TRANSPORT R10

22 IWAN Routing Protocols Which protocol should I use? IWAN Profiles are based upon BGP and EIGRP for scalability and optimal Intelligent Path Control Scalability: BGP (Path Vector) and EIGRP (Advanced Distance Vector) provide best scale over large hub-and-spoke topologies like DMVPN OSPF (Link State) maintains a lot of network state which cannot be subdivided easily in large DMVPN networks Intelligent Path Control: PfR can be used with any routing protocols by relying on the routing table (RIB). Requires all valid WAN paths be ECMP so that each valid path is in the RIB. For BGP and EIGRP, PfR can look into protocol s topology information to determine both best paths and secondary paths thus, ECMP is not required.

23 IWAN Deployment EIGRP Single EIGRP process for Branch, WAN and POP/hub sites Extend Hello/Hold timers for WAN Adjust tunnel interface delay to ensure WAN path preference ( primary, INET secondary) Hubs Disable Split-Horizon Advertise Site summary, enterprise summary, default route to spokes Summary metrics: A summary-metric is used to reduce computational load on the DMVPN hubs. Ingress filter on tunnels. Spokes EIGRP Stub-Site functionality builds on stub functionality that allows a router to advertise itself as a stub to peers on specified WAN interfaces, but allows for it to exchange routes learned on LAN interface Site1 Delay 1000 Set Tunnel Delay to influence best path EIGRP Stub Site R10 R31 R41 DCI WAN Core INET / / /24 Site2 R20 Delay Delay Delay Delay Delay Delay R11 R12 R21 R22 Delay 1000 Delay Delay 2000 Delay 1000 R51 Delay R52 Delay Delay Delay 25000

24 DMVPN Hub Configuration Routing router eigrp IWAN-EIGRP Use EIGRP named mode address-family ipv4 unicast autonomous-system 400 af-interface default passive-interface Default values for interfaces exit-af-interface LAN interface configuration af-interface Port-channel1 no passive-interface exit-af-interface Tunnel interface configuration af-interface Tunnel10 Summarize WAN address ranges summary-address Adjust timers hello-interval 20 hold-time 60 no passive-interface no split-horizon Disable split horizon exit-af-interface Tag routes topology base distribute-list route-map SET-TAG-DMVPN-1 out Port-channel1 distribute-list route-map SET-TAG-ALL out Tunnel10 distribute-list route-map BLOCK-DC2-DMVPN-1 in Tunnel10 exit-af-topology network Filter routes network eigrp router-id Enable EIGRP for networks exit-address-family MC1 IWAN POP R84 R INTERNET TRANSPORT R84 *) Some parts of configurations not shown (e.g. authentication,...)

25 DMVPN Spoke Configuration Routing router eigrp IWAN-EIGRP address-family ipv4 unicast autonomous-system 400 af-interface default passive-interface exit-af-interface af-interface Tunnel10 summary-address hello-interval 20 hold-time 60 no passive-interface exit-af-interface... topology base distribute-list route-map DMVPN1-BR-IN in Tunnel10 distribute-list route-map DMVPN2-BR-IN in Tunnel11 distribute-list route-map BLOCK-LEARNED out Tunnel10 distribute-list route-map BLOCK-LEARNED out Tunnel11 exit-af-topology network network network network eigrp router-id eigrp stub connected summary redistributed exit-address-family Use EIGRP named mode Default values for interfaces Tunnel interface configuration Summarize branch address ranges Adjust timers Tag routes Filter routes Enable EIGRP for networks Enable EIGRP stub feature *) Some parts of configurations not shown (e.g. authentication, Tunnel 11...) R /24 TRANSPORT R10

26 IWAN Deployment BGP A single ibgp routing domain is used Appropriate Hello/Hold timers for WAN Hub DMVPN hub routers function as BGP route-reflectors for the spokes. No BGP peering between RR. BGP dynamic peer feature configured on the route-reflectors Site specific prefixes, Enterprise summary prefix and default route advertised to spokes Set local preference for all prefixes Redistribute BGP into local IGP with a defined metric cost to attract traffic from the central sites to the spokes across. Spokes Peer to Hub/Transit BRs in each DMVPN cloud Mutual redistribution OSPF/BGP Set a route tag to identify routes redistributed from BGP Preferred path is due to highest Local Preference Site1 R10 Metric: 1000 Metric: 2000 OSPF R11 R12 R21 R22 DCI WAN Core INET R31 R41 R51 R / / /24 Site2 R20 Metric: 1000 Metric: 2000 OSPF LP LP LP 3000 LP 400 OSPF

27 Deploying with user VRFs vrf definition TEST1 address-family ipv4 exit-address-family vrf definition TEST2 address-family ipv4 exit-address-family interface Tunnel 101 vrf forwarding TEST1 tunnel key 101 tunnel vrf IWAN-TRANSPORT-1 interface Tunnel 102 vrf forwarding TEST2 tunnel key 102 tunnel vrf IWAN-TRANSPORT-1 MC1 TRANSIT SITE R84 R85 INET DMVPN Tunnel per VRF Over the top routing per VRF SAF Peering per VRF R10 R11 R12 R / / / /24 Enterprise Branch Sites

28 Inteligentní výběr cesty s využitím PfRv3

29 Cisco Intelligent WAN (IWAN) AVC Private Cloud ISR-AX 3G/4G-LTE ASR1000-AX Virtual Private Cloud Branch WAAS kamai PfRv3 Internet Public Cloud Management & Orchestration Transport Independence Intelligent Path Control Application Optimization Secure Connectivity IPSec WAN Overlay Consistent Operational Model Optimal application routing Efficient use of bandwidth Performance monitoring Optimization and Caching NG Strong Encryption Threat Defense DMVPN Performance Routing AVC, WAAS, Akamai Suite-B, CWS, ZBFW

30 Intelligent Path Control with PfR Enterprise Use-Case Voice, video and critical applications take the best delay, jitter, and/or loss path Private Cloud Branch Other traffic is load balanced to maximize bandwidth Internet PfR monitors network performance and routes applications based on application performance policies PfR load balances traffic based upon link utilization levels to efficiently utilize all available WAN bandwidth Virtual Private Cloud Voice, video and critical applications will be rerouted if the current path degrades below policy thresholds

31 PfRv3 and Parent Routes Make sure that all Border Routers have a route over each external path to the destination sites PfR will NOT be able to effectively control traffic otherwise. PfRv3 always checks for a parent route before being able to control a Traffic Class. Parent route check is done as follows: Check to see if there is an NHRP shortcut route If not Check in the order of BGP, EIGRP, Static and RIB If at any point, an NHRP short cut route appears, PfRv3 would pick that up and relinquish using the parent route from one of the routing protocols. PfR3 up to 3.15/15.5(2)T supported only one next-hop per multipoint interface. Routing has to be done such that only one next-hop per destination prefix is in the routing table per DMVPN tunnel interface.

32 PfRv3 How it Works ISR ASR1K MC Traffic Classes Learning Active TCs MC Performance Measurements MC TC Path BR BR BR BR BR BR Define your Traffic Policy Learn the Traffic Measurement Path Enforcement Define path optimization policies on the Hub MC load balancing, path preference, application metrics DSCP Based Policies Application Based Policies Traffic flowing through the Border Routers (BRs) that match a policy are learned Traffic Classes Unified Performance Monitor Report the measured TC performance metrics to the Master Controller for policy compliance Unified Performance Monitor Master Controller directs BR path changes to keep traffic within policy Route Enforcement module in feature path

33 PfR Components The Decision Maker: Master Controller (MC) Apply policy, verification, reporting No packet forwarding/ inspection required Standalone of combined with a BR VRF Aware IPv4 only (IPv6 Future) The Forwarding Path: Border Router (BR) Gain network visibility in forwarding path (Learn, measure) Enforce MC s decision (path enforcement) VRF aware IPv4 only (IPv6 Future) MC1 BR1 MC/BR MC/BR BR2 BR

34 IWAN Domain DC1 DCn Collection of sites that share the same set of policies An IWAN domain includes: A mandatory Hub site, Optional Transit sites, As well as Branch sites. Each site has a unique identifier (Site-Id) Derived from the loopback address of the local MC Central and headquarter sites play a significant role in PfR and are called an IWAN Point of Presence (POP). Each of these sites will have a unique identifier called a POP-ID Each site runs PfR and gets its path control configuration and policies from the logical IWAN domain controller through the IWAN Peering Service IWAN Peering POP1 - HUB Site ID = MC1 BR1 BR2 BR3 BR4 MC/BR Site ID Hub PATH1 MC/BR Site ID DCI WAN Core Transit PATH2 MC/BR POP2 - TRANSIT Site ID = Site ID MC2 BR

35 Hub Site Located in an enterprise central site or headquarter location. Can act as a transit site to access servers in the datacenters or for spoke-to-spoke traffic A POP Identifier (POP-ID) 0 is automatically assigned to a Hub site. Only one Hub site exists per IWAN domain. The logical domain controller functionality resides on this site s master controller (MC). The master controller (MC) for this site is known as the Hub master controller (Hub MC, HMC) MCs from all other sites (transit or branch) connect to the Hub MC for PfR configuration and policies. Policies Monitors MC1 Path Id 1 POP1 - HUB Site ID = POP-ID 0 POP2 - TRANSIT Site ID = POP-ID 1 BR1 BR2 BR3 BR4 Path INET Id 2 DMVPN MC2 DMVPN INET MC/BR MC/BR MC/BR BR Branch Branch Branch

36 Policy/Monitor Distribution Policies Monitors DC/MC BR MC/BR BR BRANCH Dual CPE TRANSIT BR INET MC/BR BRANCH Single CPE Domain policies and monitor instances are configured on the Hub MC. Policies are defined per VRF Then distributed to branch sites using the peering infrastructure

37 Performance Policies - DSCP or App Based domain IWAN vrf default master hub load-balance class MEDIA sequence 10 match application telepresence-media policy real-time-video match application ms-lync policy real-time-video path-preference fallback INET class VOICE sequence 20 match dscp ef policy voice path-preference fallback INET class CRITICAL sequence 30 match dscp af31 policy low-latency-data Policies: DSCP or Application Based Policies (NBAR2) DSCP marking can be used with NBAR2 on the LAN interface (ingress on BR) Default Class is load balanced

38 Built-in Policy Templates Voice Pre-defined Template Threshold Definition priority 1 one-way-delay threshold 150 (msec) priority 2 packet-loss-rate threshold 1 (%) priority 2 byte-loss-rate threshold 1 (%) priority 3 jitter 30 (msec) Real-time-video priority 1 packet-loss-rate threshold 1 (%) priority 1 byte-loss-rate threshold 1 (%) Low-latency-data priority 2 one-way-delay threshold 150 (msec) priority 3 jitter 20 (msec) priority 1 one-way-delay threshold 100 (msec) priority 2 byte-loss-rate threshold 5 (%) priority 2 packet-loss-rate threshold 5 (%) Pre-defined Template Bulk-data Best-effort scavenger Threshold Definition priority 1 one-way-delay threshold 300 (msec) priority 2 byte-loss-rate threshold 5 (%) priority 2 packet-loss-rate threshold 5 (%) priority 1 one-way-delay threshold 500 (msec) priority 2 byte-loss-rate threshold 10 (%) priority 2 packet-loss-rate threshold 10 (%) priority 1 one-way-delay threshold 500 (msec) priority 2 byte-loss-rate threshold 50 (%) priority 2 packet-loss-rate threshold 50 (%)

39 Transit Site Located in an enterprise central site or headquarter location. Can act as a transit site to access servers in the datacenters or for spoke-to-spoke traffic A POP Identifier (POP-ID) is configured for each transit site. This POP-ID has to be unique in the domain. The master controller (MC) for this site is known as a Transit Master Controller (Transit MC, TMC) The local MC peers with the Hub MC to get its policies, monitor, configuration and timers POP1 - HUB Site ID = POP-ID 0 MC1 IWAN Peering BR1 BR2 BR3 BR4 DMVPN POP2 - TRANSIT Site ID = POP-ID 1 MC2 Path Id 1 DMVPN INET MC/BR MC/BR MC/BR BR Branch Branch Branch Path INET Id 2

40 Branch Site These will always be a DMVPN spoke, and are a stub sites where traffic transit is not allowed. The local MC peers with the logical domain controller (aka Hub MC) to get its policies, and monitoring guidelines. POP1 - HUB Site ID = MC1 POP2 - TRANSIT Site ID = MC2 BR1 BR2 BR3 BR4 IWAN Peering DMVPN DMVPN INET MC/BR MC/BR MC/BR BR Branch Branch Branch

41 WAN Interface Discovery Hub and Transit BRs have path names and path identifier manually defined Path name identifies a Transport Path Identifier (Path-id) is unique per site Hub and Transit BRs send Discovery Packet with path names from to all discovered sites Path Discovery from the Hub Border Routers MC1 Path Path-id 1 HUB SITE Site ID = Hub MC MC2 Transit MC BR1 BR1 BR3 BR4 Path INET Path-id 2 DMVPN TRANSIT SITE Site ID = POP-ID 0 POP-ID 1 Path Path-id 1 DMVPN INET Path INET Path-id 2 WAN Path is detected on the branch - Path Name - POP-ID - Path-Id - DSCP MC/BR MC/BR MC/BR BR / / /24

42 WAN Interface Performance Monitors PfR automatically configures 3 Performance Monitors instances (PMI) over every external interface Monitor1 Site Prefix Learning (egress direction) Monitor2 Aggregate Bandwidth per Traffic Class (egress direction) Monitor3 Performance measurements (ingress direction) BR 42

43 Performance Monitoring User Traffic Passive Monitoring MC/BR SITE2 Dual CPE MC SITE1 BR BR BR INET MC/BR SITE3 Single CPE Bandwidth on egress Per Traffic Class (dest-prefix, DSCP, AppName) Performance Monitor Collect Performance Metrics Per Channel - Per DSCP - Per Source and Destination Site - Per Interface

44 Performance Monitoring Smart Probing Smart Probing MC/BR SITE2 Dual CPE MC SITE1 BR BR BR INET MC/BR SITE3 Single CPE Integrated Smart Probes Traffic driven intelligent on/off Site to site and per DSCP Performance Monitor Collect Performance Metrics Per Channel - Per DSCP - Per Source and Destination Site - Per Interface

45 Performance Violation MC/BR SITE2 Dual CPE MC SITE1 BR BR BR INET MC/BR SITE3 Single CPE Threshold Crossing Alert (TCA) Sent to source site loss, delay, jitter, unreachable

46 Performance Violation NetFlow Export MC/BR SITE2 Dual CPE MC SITE1 BR BR BR INET MC/BR SITE3 Single CPE

47 Policy Decision MC/BR SITE2 Dual CPE MC BR User traffic BR SITE1 BR INET MC/BR SITE3 Single CPE Reroute Traffic to a Secondary Path

48 Nasazení PfRv3 v síti

49 PfR Deployment Hub R83 (MC) domain IWAN vrf default master hub source-interface Loopback0 enterprise-prefix prefix-list ENTERPRISE_PREFIX site-prefixes prefix-list DC_PREFIX R83 HUB SITE Site ID = Hub MC POP ID 0 R93 R84 R85 (BRs) domain IWAN vrf default border master source-interface Loopback0 interface Tunnel100 description -- Primary Path -- domain IWAN path path-id 1 domain IWAN vrf default border master source-interface Loopback0 interface Tunnel200 description Secondary Path -- domain IWAN path INET path-id 2 Path Id 1 R84 R85 R94 R95 Path INET Id 2 DMVPN DMVPN INET Hub Site Enterprise Prefix: summary prefix for the entire domain Site Prefix: static definition of prefixes for a site (no automatic learning) - Mandatory R10 R11 R12 R / / / /24

50 Redundant MC Anycast IP What happens when a MC fails? Traffic forwarded based on routing information ie no drop What happens when the Hub MC fails? Branch MCs keep their configuration and policies Continue to optimize traffic A backup MC can be defined on the hub. Using the same IP address as the primary Routing Protocol is used to make sure BRs and branch MC connect to the primary Stateless redundancy Backup MC will re-learn the traffic MC1 Hub MC /32 R / /24 MC2 TRANSIT SITE Backup Hub MC /30 R85 INET R10 R11 R12 R / /24

51 PfR Deployment Transit Site R93 (MC) domain IWAN vrf default master transit 1 source-interface Loopback0 site-prefixes prefix-list DC_PREFIX hub R83 HUB SITE Site ID = TRANSIT SITE Site ID = R93 Transit MC POP ID 1 R94 R95 (BRs) domain IWAN vrf default border master source-interface Loopback0 interface Tunnel100 description -- Primary Path -- domain IWAN path path-id 1 domain IWAN vrf default border master source-interface Loopback0 interface Tunnel200 description Secondary Path -- domain IWAN path INET path-id 2 R84 R85 R94 R95 DMVPN Path Id 1 DMVPN INET Path INET Id 2 Transit Site Site Prefix: static definition of prefixes for a site (no automatic learning) - Mandatory R10 R11 R12 R / / / /24

52 PfR Deployment Single CPE Branch HUB SITE Site ID = TRANSIT SITE Site ID = R10 domain IWAN vrf default master branch source-interface Loopback0 hub border master local source-interface Loopback0 R83 R93 R84 R85 R94 R95 DMVPN DMVPN INET Single CPE Branch Sites Branch MCs connect to the Hub R10 R11 R12 R13 R10 R11 R12 R / / / /24

53 PfR Deployment Dual CPE Branch HUB SITE Site ID = TRANSIT SITE Site ID = R12 domain IWAN vrf default master branch source-interface Loopback0 hub border master local source-interface Loopback0 R83 R93 R84 R85 R94 R95 R13 domain IWAN vrf default border master source-interface Loopback0 DMVPN DMVPN INET Dual CPE Branch Sites Branch MCs connect to the Hub R10 R11 R12 R13 R10 R11 R12 R / / / /24

54 PfR Deployment Hub Policies, Intervals R83 domain one vrf default master hub source-interface Loopback0 site-prefixes prefix-list DC1_PREFIX monitor-interval 4 dscp af31 monitor-interval 4 dscp cs4 monitor-interval 4 dscp af41 monitor-interval 4 dscp ef load-balance enterprise-prefix prefix-list ENTERPRISE_PREFIX class VOICE sequence 10 match dscp ef policy voice path-preference fallback INET class VIDEO sequence 20 match dscp af41 policy custom priority 2 loss threshold 5 priority 1 one-way-delay threshold 150 match dscp cs4 policy custom priority 2 loss threshold 5 priority 1 one-way-delay threshold 150 path-preference fallback INET class CRITICAL sequence 30 match dscp af31 policy low-latency-data path-preference fallback INET Hub Site Policies configured on hub only Monitoring intervals can be adjusted R83 Path Id 1 HUB SITE Site ID = Hub MC POP ID 0 R84 R85 R94 R95 Path INET Id 2 DMVPN R10 R11 R12 R / /24 R93 DMVPN INET / /24

55 Deploying with VRF Hub MC TRANSIT SITE interface Loopback1 vrf forwarding TEST1 interface Loopback2 vrf forwarding TEST2 MC1 GLOBAL: VRF TEST1: VRF TEST2: R84 R85 domain IWAN vrf TEST1 master hub source-interface Loopback1 vrf TEST2 master hub source-interface Loopback / /24 INET R10 R11 R12 R / /24 Enterprise Branch Sites

56 Deploying with VRF Hub MC Policies domain IWAN vrf TEST1 master hub load-balance class VOICE sequence 10 match dscp ef policy voice path-preference fallback INET class VIDEO sequence 20 match dscp af41 policy voice path-preference fallback INET class CRITICAL sequence 30 match dscp af31 policy low-latency-data [Cont d] vrf TEST2 master hub load-balance class VOICE sequence 10 match dscp ef policy voice path-preference fallback INET class CRITICAL sequence 30 match dscp af31 policy low-latency-data

57 Deploying with VRF Hub BR domain IWAN vrf TEST1 border master source-interface Loopback1 vrf TEST2 border master source-interface Loopback2 interface Tunnel101 description -- Primary Path vrf forwarding TEST1 domain IWAN path interface Tunnel102 description -- Primary Path vrf forwarding TEST2 domain IWAN path MC1 GLOBAL: VRF TEST1: VRF TEST2: Tu101 Tu102 R / /24 TRANSIT SITE R85 INET R10 R11 R12 R / /24 Enterprise Branch Sites

58 Deploying with VRF Branch MC/BR TRANSIT SITE R10 domain IWAN vrf TEST1 master branch source-interface Loopback1 hub border master local source-interface Loopback1 vrf TEST2 master branch source-interface Loopback2 hub border master local source-interface Loopback2 MC1 Tu101 Tu102 GLOBAL: VRF TEST1: VRF TEST2: R / /24 R85 INET R10 R11 R12 R / /24 Enterprise Branch Sites

59 Shrnutí

60 Intelligent WAN: An Architectural and Systems Approach IWAN is a Solution Architecture Solves a network problem Use Case Driven Systems Development Approach Prescribed. Tested. Interoperable. Bounded Scope and Complexity Enables Automation and Quality NEW Delivers Business Outcomes Reduce WAN costs. Increase bandwidth Improve and Protect application performance Direct Internet Access Guest Access Offload IT Simplification (Cost reduction)

61 Platform Support Cisco CSR-1000 Cisco ASR-1000 MC BR (1) Cisco ISR G2 family 3900-AX 2900-AX 1900-AX 890 MC BR Cisco ISR MC BR MC BR (1) XE 3.18

62 Cisco IWAN Enterprise Management Portfolio Cisco Ecosystem Partners IWAN App Prime Infrastructure Prescriptive Policy Automation Enterprise Network Mgmt and Monitoring Application Aware Performance Mgmt Advanced Orchestration Customer wants considerable automation and operational simplicity Requirements consistent with prescriptive IWAN Validated Design Customer needs customizable IWAN with end-to-end monitoring One Assurance across Cisco portfolio from Branch to Datacenter Customer looking for advanced monitoring and visualization QoS/ PfR/ AVC configuration, Real-time analytics and network troubleshooting Customer wants advanced provisioning, life cycle management, and customized policies System-wide network consistency assurance Lean IT organization IT Network team IT Network team Lean IT OR IT Network team 62

63

Intelligent WAN 2.0 Traffic Independent Design and Intelligent Path Selection

Intelligent WAN 2.0 Traffic Independent Design and Intelligent Path Selection Intelligent WAN 2.0 Traffic Independent Design and Intelligent Path Selection Tech-WAN Jaromír Pilař Consulting Systems Engineer, CCIE #2910 Cisco Intelligent WAN (IWAN) AVC Private Cloud ISR-AX 3G/4G-LTE

More information

Implementing Next Generation Performance Routing PfRv3

Implementing Next Generation Performance Routing PfRv3 Implementing Next Generation Performance Routing PfRv3 Jean-Marc Barozet Technical Leader IWAN Solution Group Agenda Business Trends PfRv3 Principles Monitoring Details The Life of a Packet Path Enforcement

More information

IWAN Under the Hood - Next Gen Performance Routing and DMVPN. David Prall, Communication Architect CCIE 6508 (R&S/SP/Security)

IWAN Under the Hood - Next Gen Performance Routing and DMVPN. David Prall, Communication Architect CCIE 6508 (R&S/SP/Security) IWAN Under the Hood - Next Gen Performance Routing and DMVPN David Prall, Communication Architect CCIE 6508 (R&S/SP/Security) dprall@cisco.com Agenda Introduction Intelligent Path Control PfRv3 Operations

More information

Intelligent WAN : CVU update

Intelligent WAN : CVU update Intelligent WAN : CVU update Deliver enhanced mobile experience at the branch with Intelligent WAN Soren D. Andreasen (sandreas@cisco.com) Technical Solution Architect CCIE# 3252 Agenda IWAN 2.0/2.1 overview

More information

Intelligent WAN Multiple VRFs Deployment Guide

Intelligent WAN Multiple VRFs Deployment Guide Cisco Validated design Intelligent WAN Multiple VRFs Deployment Guide September 2017 Table of Contents Table of Contents Deploying the Cisco Intelligent WAN... 1 Deploying the Cisco IWAN Multiple VRFs...

More information

Cisco Intelligent WAN

Cisco Intelligent WAN Cisco Intelligent WAN Ľuboš Lontoš Systems Engineer SP/R&S ALEF NULA a.s. Agenda Cisco iwan Architecture Overview Tranport Independent Design Intelligent Path Control- PfRv3 Product PorMolio Tradi4onal

More information

Intelligent WAN Multiple Data Center Deployment Guide

Intelligent WAN Multiple Data Center Deployment Guide Cisco Validated design Intelligent WAN Multiple Data Center Deployment Guide September 2017 Table of Contents Table of Contents Deploying the Cisco Intelligent WAN... 1 Deployment Details...1 Deploying

More information

PfRv3 Zero SLA Support

PfRv3 Zero SLA Support The Performance Routing v3 (PfRv3) Zero SLA Support feature enables users to reduce probing frequency on various ISP links, such as 3G, 4G, and LTE When the Zero SLA (0-SLA) feature is configured on an

More information

ARCHIVED DOCUMENT. - The topics in the document are now covered by more recent content.

ARCHIVED DOCUMENT. - The topics in the document are now covered by more recent content. ARCHIVED DOCUMENT This document is archived and should only be used as a historical reference and should not be used for new deployments for one of the following reasons: - The topics in the document are

More information

Intelligent WAN Deployment Guide

Intelligent WAN Deployment Guide Cisco Validated design Intelligent WAN Deployment Guide September 2017 Table of Contents Table of Contents Deploying the Cisco Intelligent WAN... 1 Deployment Details...1 Configuring DMVPN Hub Router...2

More information

Performance Routing Version 3 Configuration Guide

Performance Routing Version 3 Configuration Guide First Published: 2014-07-22 Last Modified: 2016-04-20 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

IWAN APIC-EM Application Cisco Intelligent WAN

IWAN APIC-EM Application Cisco Intelligent WAN IWAN APIC-EM Application Cisco Intelligent WAN René og Per Cisco DK SE s Feb 23 th 2016 AVC MPLS Private Cloud 3G/4G-LTE Virtual Private Cloud Branch WAAS PfR Internet Public Cloud Control, Management,

More information

IWAN Intelligent WAN, Next Generation Branch Architecture. Lars Thoren Technical Marketing Engineer, ENG

IWAN Intelligent WAN, Next Generation Branch Architecture. Lars Thoren Technical Marketing Engineer, ENG IWAN Intelligent WAN, Next Generation Branch Architecture Lars Thoren Technical Marketing Engineer, ENG Mobile Device Network Traffic Average Number of Apps per Device* Average App Size** OS Update File

More information

Pressures on the WAN

Pressures on the WAN IWAN Radek Boch, Systems Engineer, Cisco, rboch@cisco.com CCIE#7095 14.11.2013 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 The Application Landscape Is Changing Applications Are

More information

Intelligent WAN Design Summary

Intelligent WAN Design Summary Cisco Validated design Intelligent WAN Design Summary September 2017 Table of Contents Table of Contents WAN Strategy... 1 IWAN Introduction... 4 Business Use Cases for IWAN...4 Business Use Cases for

More information

Advanced Concepts of DMVPN (Dynamic Multipoint VPN)

Advanced Concepts of DMVPN (Dynamic Multipoint VPN) Advanced Concepts of DMVPN (Dynamic Multipoint VPN) Mike Sullenberger Distinguished Engineer Agenda DMVPN Design Overview DMVPN General IWAN Specific NHRP Details NHRP Overview NHRP Registrations/Resolutions/Redirects

More information

PfRv3 Inter-DC Optimization

PfRv3 Inter-DC Optimization The PfRv3-Inter-DC-Optimization feature provides support by routing traffic from a hub site to another for specific traffic types such as data, voice, video, etc. Feature Information for PfRv3-Inter-DC-Optimization,

More information

DMVPN for R&S CCIE Candidates Johnny Bass CCIE #6458

DMVPN for R&S CCIE Candidates Johnny Bass CCIE #6458 DMVPN for R&S CCIE Candidates Johnny Bass CCIE #6458 BRKCCIE-3003 @CCIE6458 2015 Cisco and/or its affiliates. All rights reserved. Cisco Public About the Presenter Johnny Bass Networking industry since

More information

GRE and DM VPNs. Understanding the GRE Modes Page CHAPTER

GRE and DM VPNs. Understanding the GRE Modes Page CHAPTER CHAPTER 23 You can configure Generic Routing Encapsulation (GRE) and Dynamic Multipoint (DM) VPNs that include GRE mode configurations. You can configure IPsec GRE VPNs for hub-and-spoke, point-to-point,

More information

REFERENCE NETWORK ARCHITECTURE

REFERENCE NETWORK ARCHITECTURE REFERENCE NETWORK ARCHITECTURE CISCO VALIDATED DESIGN Intelligent WAN Technology Design Guide February 2016 REFERENCE NETWORK ARCHITECTURE Table of Contents Table of Contents Introduction... 1 Technology

More information

Migrating from Dynamic Multipoint VPN Phase 2 to Phase 3: Why and How to Migrate to the Next Phase

Migrating from Dynamic Multipoint VPN Phase 2 to Phase 3: Why and How to Migrate to the Next Phase Migration Guide Migrating from Dynamic Multipoint VPN Phase 2 to Phase 3: Why and How to Migrate to the Next Phase This guide shows how a Dynamic Multipoint VPN (DMVPN) deployment can be migrated to make

More information

Intelligent WAN Remote Site 4G LTE Deployment Guide

Intelligent WAN Remote Site 4G LTE Deployment Guide Cisco Validated design Intelligent WAN Remote Site 4G LTE Deployment Guide September 2017 Table of Contents Table of Contents Deploying the Cisco Intelligent WAN... 1 Deployment Details...1 Deploying Remote

More information

Intelligent WAN High Availability and Scalability Deployment Guide

Intelligent WAN High Availability and Scalability Deployment Guide Cisco Validated design Intelligent WAN High Availability and Scalability Deployment Guide September 2017 Table of Contents Table of Contents Deploying the Cisco Intelligent WAN... 1 Deployment Details...1

More information

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC)

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC) Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC) COURSE OVERVIEW: Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent

More information

Cisco Multicloud Portfolio: Cloud Connect

Cisco Multicloud Portfolio: Cloud Connect Deployment Guide Cisco Multicloud Portfolio: Cloud Connect Private Network to Azure Transit Virtual Network October 2018 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public

More information

Intelligent WAN (IWAN) Design and Deployment

Intelligent WAN (IWAN) Design and Deployment Intelligent WAN (IWAN) Design and Deployment Adam Groudan, Technical Solutions Architect David Prall, Communications Architect BRKCRS-2002 Cisco Spark How Questions? Use Cisco Spark to communicate with

More information

SD-WAN Deployment Guide (CVD)

SD-WAN Deployment Guide (CVD) SD-WAN Deployment Guide (CVD) All Cisco Meraki security appliances are equipped with SD-WAN capabilities that enable administrators to maximize network resiliency and bandwidth efficiency. This guide introduces

More information

Cisco Service Advertisement Framework Deployment Guide

Cisco Service Advertisement Framework Deployment Guide Cisco Service Advertisement Framework Deployment Guide What You Will Learn Cisco Service Advertisement Framework (SAF) is a network-based, scalable, bandwidth-efficient approach to service advertisement

More information

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016 Network Automation and Branch Agility The Network Helps Enable Digital Business Rajinder Singh Product Sales Specialist June 2016 Agenda WAN Market Drivers Cisco Intelligent WAN (IWAN) Cisco Intelligent

More information

FlexVPN HA Dual Hub Configuration Example

FlexVPN HA Dual Hub Configuration Example FlexVPN HA Dual Hub Configuration Example Document ID: 118888 Contributed by Piotr Kupisiewicz, Wen Zhang, and Frederic Detienne, Cisco TAC Engineers. Apr 08, 2015 Contents Introduction Prerequisites Requirements

More information

DMVPN for R&S CCIE Candidates

DMVPN for R&S CCIE Candidates DMVPN for R&S CCIE Candidates Johnny Bass CCIE #6458 BRKCCIE-3003 @CCIE6458 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public About the Presenter Johnny Bass Networking industry since

More information

Scalability Considerations

Scalability Considerations 3 CHAPTER This chapter presents the following steps to selecting Cisco products for a VPN solution: Sizing the headend Choosing Cisco products that can be deployed for headend devices Product sizing and

More information

Chapter H through R. loss (PfR), page 28. load-balance, page 23 local (PfR), page 24 logging (PfR), page 26

Chapter H through R. loss (PfR), page 28. load-balance, page 23 local (PfR), page 24 logging (PfR), page 26 Chapter H through R holddown (PfR), page 3 host-address (PfR), page 5 hub, page 7 inside bgp (PfR), page 8 interface (PfR), page 10 interface tunnel (global configuration), page 12 jitter (PfR), page 13

More information

Cisco Multicloud Portfolio: Cloud Connect

Cisco Multicloud Portfolio: Cloud Connect Design and Deployment Guide Cisco Multicloud Portfolio: Cloud Connect Design and Deployment Guide for Private Data Center to AWS VPC October 2018 2018 Cisco and/or its affiliates. All rights reserved.

More information

COURSE OUTLINE: Course: CCNP Route Duration: 40 Hours

COURSE OUTLINE: Course: CCNP Route Duration: 40 Hours COURSE OUTLINE: Course: CCNP Route 300-101 Duration: 40 Hours CCNP Route Training Day 1: Connecting Remote Locations Principles of Static Routing Configuring an IPv4 Static Route Configuring a Static Default

More information

WAN Edge MPLSoL2 Service

WAN Edge MPLSoL2 Service 4 CHAPTER While Layer 3 VPN services are becoming increasing popular as a primary connection for the WAN, there are a much larger percentage of customers still using Layer 2 services such Frame-Relay (FR).

More information

DYNAMIC MULTIPOINT VPN SPOKE TO SPOKE DIRECT TUNNELING

DYNAMIC MULTIPOINT VPN SPOKE TO SPOKE DIRECT TUNNELING DYNAMIC MULTIPOINT VPN SPOKE TO SPOKE DIRECT TUNNELING NOVEMBER 2004 1 Direct Spoke To Spoke Tunnels Initially, spoke to spoke traffic can only travel via the hub In DMVPN, spokes can send packets directly

More information

Cisco Group Encrypted Transport VPN

Cisco Group Encrypted Transport VPN Cisco Group Encrypted Transport VPN Q. What is Cisco Group Encrypted Transport VPN? A. Cisco Group Encrypted Transport is a next-generation WAN VPN solution that defines a new category of VPN, one that

More information

Virtual Private Networks Advanced Technologies

Virtual Private Networks Advanced Technologies Virtual Private Networks Advanced Technologies Petr Grygárek rek Agenda: Supporting Technologies (GRE, NHRP) Dynamic Multipoint VPNs (DMVPN) Group Encrypted Transport VPNs (GET VPN) Multicast VPNs (mvpn)

More information

DMVPN to Group Encrypted Transport VPN Migration

DMVPN to Group Encrypted Transport VPN Migration DMVPN to Group Encrypted Transport VPN Migration This document provides the steps for Dynamic Multipoint VPN (DMVPN) to Group Encrypted Transport VPN migration. DMVPN to Group Encrypted Transport VPN Migration

More information

Flexible Dynamic Mesh VPN draft-detienne-dmvpn-00

Flexible Dynamic Mesh VPN draft-detienne-dmvpn-00 Flexible Dynamic Mesh VPN draft-detienne-dmvpn-00 Fred Detienne, Cisco Systems Manish Kumar, Cisco Systems Mike Sullenberger, Cisco Systems What is Dynamic Mesh VPN? DMVPN is a solution for building VPNs

More information

Setting Up OER Network Components

Setting Up OER Network Components Setting Up OER Network Components First Published: January 29, 2007 Last Updated: August 21, 2007 This module describes the concepts and tasks to help you set up the network components required for an

More information

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Data Sheet Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Product Overview Cisco Dynamic Multipoint VPN (DMVPN) is a Cisco IOS Software-based security solution for building

More information

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Product Overview Cisco Dynamic Multipoint VPN (DMVPN) is a Cisco IOS Software-based security solution for building scalable

More information

IOS/CCP: Dynamic Multipoint VPN using Cisco Configuration Professional Configuration Example

IOS/CCP: Dynamic Multipoint VPN using Cisco Configuration Professional Configuration Example IOS/CCP: Dynamic Multipoint VPN using Cisco Configuration Professional Configuration Example Document ID: 113265 Contents Introduction Prerequisites Requirements Components Used Conventions Background

More information

Cisco Virtual Office High-Scalability Design

Cisco Virtual Office High-Scalability Design Solution Overview Cisco Virtual Office High-Scalability Design Contents Scope of Document... 2 Introduction... 2 Platforms and Images... 2 Design A... 3 1. Configure the ACE Module... 3 2. Configure the

More information

IWAN Security for Remote Site Direct Internet Access and Guest Wireless

IWAN Security for Remote Site Direct Internet Access and Guest Wireless IWAN Security for Remote Site Direct Internet Access and Guest Wireless Technology Design Guide (ISR4K) March 2015 Table of Contents Preface...1 CVD Navigator...2 Use Cases... 2 Scope... 2 Proficiency...

More information

Virtual Private Networks Advanced Technologies

Virtual Private Networks Advanced Technologies Virtual Private Networks Advanced Technologies Petr Grygárek rek Agenda: Supporting Technologies (GRE, NHRP) Dynamic Multipoint VPNs (DMVPN) Group Encrypted Transport VPNs (GET VPN) Multicast VPNs (mvpn)

More information

A-B I N D E X. backbone networks, fault tolerance, 174

A-B I N D E X. backbone networks, fault tolerance, 174 I N D E X A-B access links fault tolerance, 175 176 multiple IKE identities, 176 182 single IKE identity with MLPPP, 188 189 with single IKE identity, 183 187 active/standby stateful failover model, 213

More information

Intelligent WAN. Technology Design Guide

Intelligent WAN. Technology Design Guide Intelligent WAN Technology Design Guide January 2015 Table of Contents Preface... 1 CVD Navigator... 2 Use Cases...2 Scope...2 Proficiency...2 Introduction... 3 Technology Use Cases...3 Use Case: Secure

More information

Cloud Intelligent Network

Cloud Intelligent Network Dubrovnik, Croatia, South East Europe 20-22 May, 2013 Cloud Intelligent Network Mitko Vasilev CIN Lead Central Europe mitko@cisco.com 2011 2012 Cisco and/or its affiliates. All rights reserved. 1 New Application

More information

Managing Site-to-Site VPNs: The Basics

Managing Site-to-Site VPNs: The Basics CHAPTER 23 A virtual private network (VPN) consists of multiple remote peers transmitting private data securely to one another over an unsecured network, such as the Internet. Site-to-site VPNs use tunnels

More information

Cisco Performance Routing

Cisco Performance Routing Cisco Performance Routing As enterprise organizations grow their businesses, the demand for real-time application performance and a better application experience for users increases. For example, voice

More information

LARGE SCALE DYNAMIC MULTIPOINT VPN

LARGE SCALE DYNAMIC MULTIPOINT VPN LARGE SCALE DYNAMIC MULTIPOINT VPN NOVEMBER 2004 1 INTRODUCTION Presentation_ID 2004, Cisco Systems, Inc. All rights reserved. 2 Dynamic Multipoint VPN Facts Dynamic Multipoint VPN (DMVPN) can work with

More information

Cisco IOS Performance Routing Version 3 Command Reference

Cisco IOS Performance Routing Version 3 Command Reference First Published: 2017-04-07 Last Modified: 2017-04-07 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

CCIE R&S LAB CFG H2/A5 (Jacob s & Jameson s)

CCIE R&S LAB CFG H2/A5 (Jacob s & Jameson s) Contents Section 1 Layer 2 Technologies... 2 1.1 Jameson s Datacenter: Access port... 2 1.2 Jameson s Datacenter: Trunk ports... 4 1.3 Jameson s Datacenter: Link bundling... 5 1.4 Jameson s Branch Offices...

More information

Dynamic Multipoint VPN Configuration Guide

Dynamic Multipoint VPN Configuration Guide First Published: 2011-10-14 Last Modified: 2014-01-10 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

IWAN AVC/QoS Design. Kelly Fleshner, Communications Architect. CCIE # years BRKRST-2043

IWAN AVC/QoS Design. Kelly Fleshner, Communications Architect. CCIE # years BRKRST-2043 IWAN AVC/QoS Design Kelly Fleshner, Communications Architect CCIE #1852 21 years BRKRST-2043 Cisco Spark How Questions? Use Cisco Spark to chat with the speaker after the session 1. Find this session in

More information

PREREQUISITES TARGET AUDIENCE. Length Days: 5

PREREQUISITES TARGET AUDIENCE. Length Days: 5 Cisco Implementing Cisco IP Routing v2.0 (ROUTE) ROUTE v2.0 includes major updates and follows an updated blueprint. However, note that this course does not cover all items listed on the blueprint. Some

More information

Operating and Monitoring the Network

Operating and Monitoring the Network CHAPTER 6 Under the Operate tab, Prime NCS (WAN) provides tools to help you monitor your network on a daily basis, as well as perform other day-to-day or ad hoc operations relating to network device inventory

More information

Migrating Your Existing WAN to Cisco s IWAN

Migrating Your Existing WAN to Cisco s IWAN Migrating Your Existing WAN to Cisco s IWAN BRKCRS-2007 Brad Edgeworth, CCIE#31574, Systems Engineer @BradEdgeworth Mani Ganesan, CCIE#27200, Consulting Systems Engineer @Mani_Cisco Introduction Housekeeping

More information

Actualtests questions. Cisco Enterprise Networks Core and WAN Exam

Actualtests questions. Cisco Enterprise Networks Core and WAN Exam Actualtests.500-452.83 questions Number: 500-452 Passing Score: 800 Time Limit: 120 min File Version: 4.8 Cisco 500-452 Enterprise Networks Core and WAN Exam A questions are all in the dump file and there

More information

Performance Routing (PfR) Master Controller Redundancy Configuration

Performance Routing (PfR) Master Controller Redundancy Configuration Performance Routing (PfR) Master Controller Redundancy Configuration This application note provides an overview on how to configure a Performance Routing (PfR) master controller in a redundant configuration.

More information

Cisco SD-WAN and DNA-C

Cisco SD-WAN and DNA-C Cisco SD-WAN and DNA-C SD-WAN Cisco SD-WAN Intent-based networking for the branch and WAN 4x Improved application experience Better user experience Deploy applications in minutes on any platform with consistent

More information

Optimized Edge Routing Configuration Guide, Cisco IOS Release 15.1MT

Optimized Edge Routing Configuration Guide, Cisco IOS Release 15.1MT Optimized Edge Routing Configuration Guide, Cisco IOS Release 15.1MT Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800

More information

Implementing Cisco IP Routing

Implementing Cisco IP Routing 300-101 Implementing Cisco IP Routing NWExam.com SUCCESS GUIDE TO CISCO CERTIFICATION Exam Summary Syllabus Questions Table of Contents Introduction to 300-101 Exam on Implementing Cisco IP Routing...

More information

Dynamic Multipoint VPN Configuration Guide, Cisco IOS Release 15M&T

Dynamic Multipoint VPN Configuration Guide, Cisco IOS Release 15M&T Dynamic Multipoint VPN Configuration Guide, Cisco IOS Release 15M&T Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800

More information

Performance Routing Version 3 Commands

Performance Routing Version 3 Commands Performance Routing Version 3 Commands advanced, page 3 bandwidth (interface configuration), page 4 border (VRF configuration), page 7 class (master controller configuration), page 8 collector, page 9

More information

CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies)

CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies) CVP CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies) 2018 Cisco and/or its affiliates. All rights reserved. This

More information

CCIE Routing & Switching

CCIE Routing & Switching CCIE Routing & Switching Cisco Certified Internetwork Expert Routing and Switching (CCIE Routing and Switching) certifies the skills required of expert-level network engineers to plan, operate and troubleshoot

More information

Implementing Cisco IP Routing (ROUTE)

Implementing Cisco IP Routing (ROUTE) Implementing Cisco IP Routing (ROUTE) Foundation Learning Guide Foundation learning for the ROUTE 642-902 Exam Diane Teare Cisco Press 800 East 96th Street Indianapolis, IN 46240 Implementing Cisco IP

More information

IPv6 over DMVPN. Finding Feature Information

IPv6 over DMVPN. Finding Feature Information This document describes how to implement the Dynamic Multipoint VPN for IPv6 feature, which allows users to better scale large and small IPsec Virtual Private Networks (VPNs) by combining generic routing

More information

Cisco CCNP ROUTE: Implementing Cisco IP Routing (ROUTE) 2.0. Upcoming Dates. Course Description. Course Outline

Cisco CCNP ROUTE: Implementing Cisco IP Routing (ROUTE) 2.0. Upcoming Dates. Course Description. Course Outline Cisco CCNP ROUTE: Implementing Cisco IP Routing (ROUTE) 2.0 Implementing Cisco IP Routing (ROUTE) v2.0 is an instructor-led five day training course developed to help students prepare for Cisco CCNP certification.

More information

Deploying Performance Routing

Deploying Performance Routing Deploying Performance Routing KRST-2362 Jean-Marc Barozet Technical Leader Application Visibility and Control Network Operating Systems Technology Group Introducing Performance Routing (PfR) Application

More information

This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and

This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and exclusive use by instructors in the CCNP: Building Scalable

More information

Configuring FlexVPN Spoke to Spoke

Configuring FlexVPN Spoke to Spoke Last Published Date: March 28, 2014 The FlexVPN Spoke to Spoke feature enables a FlexVPN client to establish a direct crypto tunnel with another FlexVPN client leveraging virtual tunnel interfaces (VTI),

More information

Sharing IPsec with Tunnel Protection

Sharing IPsec with Tunnel Protection The feature allows sharing an IPsec security association database (SADB) between two or more generic routing encapsulation (GRE) tunnel interfaces when tunnel protection is used. Shared tunnel interfaces

More information

Implementing Cisco IP Routing (ROUTE)

Implementing Cisco IP Routing (ROUTE) Implementing Cisco IP Routing (ROUTE) COURSE OVERVIEW: Implementing Cisco IP Routing (ROUTE) v2.0 is an instructor-led five-day training course developed to help students prepare for Cisco CCNP certification.

More information

Zero To Hero CCIE CCNP

Zero To Hero CCIE CCNP Zero To Hero CCIE CCNP CCIE CCNP CCIE CCNP Week 1 Simple Network Design Understanding the Host-to-Host Communications Model Understanding the TCP/IP Internet Layer Addresses in a Network Introduction to

More information

Cisco Implementing Cisco IP Routing v2.0 (ROUTE)

Cisco Implementing Cisco IP Routing v2.0 (ROUTE) Course Overview ROUTE v2.0, a five-day ILT course, includes major updates and follows an updated blueprint. (However, note that this course does not cover all items listed on the blueprint.) Some older

More information

Shortcut Switching Enhancements for NHRP in DMVPN Networks

Shortcut Switching Enhancements for NHRP in DMVPN Networks Shortcut Switching Enhancements for NHRP in DMVPN Networks Routers in a Dynamic Multipoint VPN (DMVPN) Phase 3 network use Next Hop Resolution Protocol (NHRP) Shortcut Switching to discover shorter paths

More information

Managing Site-to-Site VPNs

Managing Site-to-Site VPNs CHAPTER 21 A virtual private network (VPN) consists of multiple remote peers transmitting private data securely to one another over an unsecured network, such as the Internet. Site-to-site VPNs use tunnels

More information

Intelligent WAN. Rupesh Chakkingal Cisco Product Management (Market Strategy) Enterprise Products and Solution

Intelligent WAN. Rupesh Chakkingal Cisco Product Management (Market Strategy) Enterprise Products and Solution Intelligent WAN Rupesh Chakkingal Cisco Product Management (Market Strategy) Enterprise Products and Solution Customer IT Challenges What they are telling us LOWER OPEX MOBILITY EXPLOSION APPLICATION PROLIFERATION

More information

Managing Site-to-Site VPNs: The Basics

Managing Site-to-Site VPNs: The Basics CHAPTER 21 A virtual private network (VPN) consists of multiple remote peers transmitting private data securely to one another over an unsecured network, such as the Internet. Site-to-site VPNs use tunnels

More information

Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies)

Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies) CVP CVP Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies) 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.

More information

Dynamic Multipoint VPN (DMVPN) Deployment Models

Dynamic Multipoint VPN (DMVPN) Deployment Models Dynamic Multipoint VPN (DMVPN) Deployment Models BRKSEC-4054 Cisco Public 2 Agenda DMVPN Overview NHRP Details Deployment Models Recent and New Features Cisco Public 3 DMVPN Overview What is Dynamic Multipoint

More information

Cisco Exam Questions & Answers

Cisco Exam Questions & Answers Cisco 300-209 Exam Questions & Answers Number: 300-209 Passing Score: 800 Time Limit: 120 min File Version: 35.4 http://www.gratisexam.com/ Exam Code: 300-209 Exam Name: Implementing Cisco Secure Mobility

More information

Configuring Basic Performance Routing

Configuring Basic Performance Routing Performance Routing (PfR) provides additional intelligence to classic routing technologies to track the performance of, or verify the quality of, a path between two devices over a Wide Area Networking

More information

Power Your Branch with Intelligent WAN

Power Your Branch with Intelligent WAN Power Your Branch with Intelligent WAN Introducing the ISR4400 series Updating the ASR1000 series Enterprise Networking David Roten - Technical Marketing Engineer What s Happening in Your World? MOBILITY,

More information

CCNA Routing and Switching Study Guide Chapters 7 & 21: Wide Area Networks

CCNA Routing and Switching Study Guide Chapters 7 & 21: Wide Area Networks CCNA Routing and Switching Study Guide Chapters 7 & 21: Wide Area Networks Instructor & Todd Lammle Chapter 21 objectives The ICND2 topics covered in this chapter include: 2 Chapter 21 objectives (con

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

PfRv3 Path of Last Resort

PfRv3 Path of Last Resort The PfRv3 path of last resort feature allows the traffic to be routed to the path of last resort. Feature Information for, page 1 Restrictions for, page 2 Information About, page 2 How to Configure, page

More information

Configuring Advanced BGP

Configuring Advanced BGP CHAPTER 6 This chapter describes how to configure advanced features of the Border Gateway Protocol (BGP) on the Cisco NX-OS switch. This chapter includes the following sections: Information About Advanced

More information

MPLS in the DCN. Introduction CHAPTER

MPLS in the DCN. Introduction CHAPTER CHAPTER 5 First Published: January 3, 2008 Last Updated: January 3, 2008 Finding Support Information for Platforms and Cisco IOS and Catalyst OS Software Images Use Cisco Feature Navigator to find information

More information

CCIE R&S v5.0. Troubleshooting Lab. Q1. PC 110 cannot access R7/R8, fix the problem so that PC 110 can ping R7

CCIE R&S v5.0. Troubleshooting Lab. Q1. PC 110 cannot access R7/R8, fix the problem so that PC 110 can ping R7 Troubleshooting Lab Q1. PC 110 cannot access R7/R8, fix the problem so that PC 110 can ping R7 Q2. R17 should have one default route which points to R12 via PPP as shown below R17# sh ip route S* 0.0.0.0/0

More information

Help! BRKRST Cisco and/or its affiliates. All rights reserved. Cisco Public 2

Help! BRKRST Cisco and/or its affiliates. All rights reserved. Cisco Public 2 Help! 2 Understanding and Troubleshooting Intelligent Path Control in IWAN Brandon Lynch Network Engineer, Core Software Group Richard Furr Technical Leader, Technical Services Agenda Introduction PfRv3

More information

Cisco recommends that you have basic knowledge of Performance Routing (PfR).

Cisco recommends that you have basic knowledge of Performance Routing (PfR). Contents Introduction Prerequisites Requirements Components Used Configure Network Diagram Configurations R3 Master Hub Router R4 Hub Border Router R5 Hub Border Router R9 Branch Master Router R10 Branch

More information

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. 1 Agenda 1. Overview and company presentation 2. Solution presentation 3. Main benefits to show to customers 4. Deployment models 2 VeloCloud Company

More information

Advanced DMVPN Designs

Advanced DMVPN Designs Advanced DMVPN Designs Alex HONORÉ Cisco TAC ahonore@cisco.com Session Agenda DMVPN refresher Review of Phase 3 logic Per-Tunnel Quality of Service DMVPN virtualization MPLS over DMVPN Multicast over DMVPN

More information

Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites

Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites Fundamentals and Deployment of Cisco SD-WAN Duration: 3 Days (24 hours) Prerequisites The recommended knowledge and skills that a learner must have before attending this course are as follows: Knowledge

More information