Optimizing Enterprise Networks through SD-AVC (Software Define Application Visibility and Control)

Size: px
Start display at page:

Download "Optimizing Enterprise Networks through SD-AVC (Software Define Application Visibility and Control)"

Transcription

1

2 BRKCRS-2502 Optimizing Enterprise Networks through SD-AVC (Software Define Application Visibility and Control) Guy Keinan

3 Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click Join the Discussion 3. Install Spark or go directly to the space 4. Enter messages/questions in the space cs.co/ciscolivebot#brkcrs Cisco and/or its affiliates. All rights reserved. Cisco Public

4 Guy Keinan SW Development Manager NBAR2 & SD-AVC BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 4

5 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 5

6 This is me BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 6

7 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 7

8 Agenda Introduction Why? NBAR2 SD-AVC Q&A Homework Wrap up

9 Unprecedented Demands on the Network Digital Disruption Complexity Security 63 million new devices online every second by X spend on network operations vs network 2 6 months to detect breach 3 Lack of Business and IT Insights Slow and Error Prone Operations Unconstrained Attack Surface 1: Gartner Report - Gartner s 2017 Strategic Roadmap for Networking 2. McKinsey Study of Network Operations for Cisco Ponemon Research Institute Study on Malware Detection, Mar Cisco and/or its affiliates. All rights reserved. Cisco Public

10 Main Operational Challenges 95% 70% 75% Network Changes Performed Manually Policy Violations Due to Human Error OpEx spent on Network Visibility and Troubleshooting Source: 2016 Cisco Study Traditional Networking CANNOT Keep Pace with the Demands of Digital Business 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public

11 Cisco Application Recognition SD-AVC/NBAR2 Application Recognition Fuels several core solutions: Cisco SD-WAN Cisco EasyQoS Assurance Security The Network. Intuitive. BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 11

12 NBAR2

13 Cisco Application Recognition NBAR2 is a powerful Network Based Application Recognition Engine A complete remake Variety of features: Pack hitless upgrade, attributes, sub-cls & more... Wide Cross pin support (same code everywhere): Routers: ISR4K, ASR1K, CSR1K, ISRv, ISR1100, ISRG2 Switches: Cat3K, Cat9K Wireless: AireOS WLC, IOS Aps 5520/8540, NG Aps 3800/1850 NAM BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 13

14 NBAR2 Classification Main things to keep in mind Stateful classification per session (5 tuple flow) Not only Deep Packet Inspection (DPI) but a combination of different techniques: - DNS snooping - Statistical classification (Machine Learning) - Behavioral classification - Learning of main services and servers - Customization Slow-Path and Fast-Path Model BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 14

15 Application Recognition Rising Challenges BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 15

16 The Cisco Live US 2017 Challenge

17 CLUS17 With NBAR2 this is what we DID see Encrypted Apps 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public

18 CLUS17 With NBAR2 this is what we DID see Encrypted Apps 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public

19 CLUS17 With NBAR2 this is what we DID see Encrypted Apps Encrypted Apps Encrypted Apps 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public

20 Cisco Application Recognition CLUS 17 Less than 1% unknown Less than 1% unclassified encrypted traffic 10G of traffic in less than 14% CPU utilization (ASR1002-HX) Very good classification for encrypted traffic, in pretty good performance BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 20

21 Ready to Dive? BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 21

22 NBAR2 Classification A bit terminology Flow == A session. Identified by 5 tuple (src IP, src Port, dst IP, dst Port, vrf) Socket == Identified by 3 tuple (dst IP, dst Port, vrf). Usually a server FIF == First packet In the Flow Bypass == No processing, just quick forwarding BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 22

23 NBAR2 Classification HL overview Slow Path: Classifies the flow, based on packet processing Potentially first packet (First In Flow FIF classification) Programs the Fast Path with classification result Fast Path: Completely bypasses NBAR2 processing Uses the programmed classification Slow Path (NBAR2) ~5% Fast Path (Flow Table) ~95% BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 23

24 NBAR2 Classification Simplified (Slow Path) FIF Payload Advanced Cache Provisioned L3/4 SD-AVC More than 80% of the flows BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 24

25 NBAR2 Classification Simplified FIF Payload Advanced Cache Result Pattern matching Multi-packet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 25

26 NBAR2 Classification Simplified FIF Payload Advanced Cache result Machine Learning Behavioral Cross Flow BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 26

27 NBAR2 Classification Detailed FIF only (1) L3/L4 Custom IP Cache Socket cache Pre-Flow Cross flow Look- Up Table Flow Table NBAR bypass mng App tracker listener Multiprotocol Multiprotocol Text Parser (MTP) multi-packet (3) Multi-Packet Engine (MPE) (MPE) statistical IANA or VM first payload Only (2) Custom WKPpayload WKP Entry Heuristic logic Single-Packet Single-Packet Engine (SPE) (SPE) on fail success success/fail engine helper WKP = Well Known Packet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 27

28 NBAR2 Classification Detailed Flow FiF FIF only (1) L3/L4 DNS-AS Socket cache L3 LUT Cache Bundle Payload packets Flow Table NBAR bypass mng App tracker Store Set for for current next packets flow multi-packet (3) listner MTP MPE Processing Store for future flows statistical IANA Cross flow LUT or VM first payload Only (2) Custom WKPpayload WKP Heuristic logic SPE on fail success success/fail engine helper BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 28

29 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 31

30 NBAR2 Socket Cache Classification - Example Full classification + Learning the socket MySQL :3306 MySQL server :3306 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 32

31 NBAR2 Socket Cache Classification - Example Full classification + Learning the socket MySQL :3306 MySQL Server :3306 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 33

32 NBAR2 Socket Cache Classification - Example Full classification + Learning the socket MySQL :3306 MySQL Server :3306 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 34

33 NBAR2 Socket Cache Classification - Example Cache in Socket-Cache Full classification + Learning the socket MySQL :3306 Dst IP Dst Port Application MySQL MySQL Server :3306 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 35

34 NBAR2 Socket Cache Classification - Example No Processing. Using Cache! MySQL :3306 Dst IP Dst Port Application MySQL MySQL Server :3306 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 36

35 NBAR2 Socket Cache Classification - Example Dst IP Dst Port Application MySQL MySQL Server :3306 Re-validate the socket every time interval BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 37

36 Classification and Encryption BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 38

37 NBAR2/SD-AVC Encrypted traffic techniques Outside the organization (usually non collaborative): SSL handshake analysis certificate, Server Name Indication (SNI) DNS traffic analysis Machine learning/statistical classification Inside the organization (usually collaborative): Customization of SSL certificates and DNS domains Server and client discovery based on NBAR2 SD-AVC External Sources (more on this later ) BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 39

38 NBAR2 Encryption Classification Automatic (Signature) Custom "(.*[.])?((youtube(-nocookie)? ytimg googlevideo)[.]com) youtu[.]be" cisco(config)#ip nbar custom CCSOC composite server-name "*ccsocdev.net" BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 40

39 NBAR2 DNS Classification - Example Regex Pattern Matching DNS Request [cisco.webex.com] DNS Server Webex BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 41

40 NBAR2 DNS Classification - Example DNS Response [ ] IP Cache IP Application webex Webex BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 42

41 NBAR2 DNS Classification - Example First Packet webex IP Application webex Encrypted Webex BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 43

42 NBAR2 Encrypted Traffic Classification Summary Most of the traffic is encrypted traffic and is SSL/TLS Testing shows more than 80% of SSL traffic is classified by NBAR2 All major internet/cloud applications are supported Hundreds of applications NBAR2 classifies both cloud and local encrypted traffic NBAR2/SD-AVC use a variety of techniques to classify encrypted traffic BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 44

43 Performance BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 45

44 NBAR2 Performance Optimization Techniques Optimized C code engines Optimized processing skips most of the traffic Wise caching techniques we ve added many of these NBAR2 Default (Performance-Optimized) Mode: Application Classification Supported on all platforms NBAR2 Fine-Grain Mode: Analytics (Deep DPI) Supported on routers-only BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 46

45 NBAR2 Performance Testing Results Fast Path Validated in real live networks and Tested on Enterprise Traffic Mix (EMIX) benchmark BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 47

46 NBAR2 Performance Ongoing Improvements 40% Improvement in just 2 releases Based on a generic Enterprise Traffic Mix (EMIX) BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 48

47 NBAR2 Protocol Discovery Performance Most XE routers: Line rate in working point of 70% CPU utilization 9300: 2000 CPS, 10,000 b-directional flows for each 24 ports. CPU at ~50% (HTTP profile) BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 49

48 No. of Apps/Domains Recognized Application Recognition: NBAR Evolution Network Level Analytics External Sources ~1500 Apps ~150 Encrypted Apps DPI, Signatures, Custom Apps Heuristic, Statistical+Behaviorial Standard Port based 100s of Apps DPI, Signatures, Custom Apps Pre-NBAR NBAR Version 1 NBAR Version 2 SD-AVC BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 50

49 Application Recognition at Network Level SD-AVC

50 Why SD-AVC? Useful and easy Application BW monitoring at a network level Better application recognition in asymmetric environments Better application recognition for encrypted applications Better first packet classification for path selection and marking policies Improved performance Automatic protocol pack deployment at a network level Serviceability and troubleshooting tools for application recognition issues Key for Cisco solutions such as SD-WAN, EasyQoS, Assurance. BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 52

51 Why SD-AVC? Reduce Operational Complexity Improve Application Visibility & Policy Efficiency BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 53

52 SD-AVC HL Concept Service automation SD-AVC Analytics & Telemetry MS Office365 DNS Catalyst 3850 ASR1001x ASR1001x BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 54

53 What is SD-AVC? A network service which ensures Application recognition for visibility, Analytics and application based policy solutions. Analytics processing at a network level Synchronizing application state between network nodes Serves as a gateway for external sources, provisioning into Cisco Network Auto-learning and auto-signature algorithms Provides pack update capability at a network level for thousands of devices BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 55

54 What is SD-AVC? Current form factor Hosted on IOS-XE devices using Linux container (LXC) as a virtual-service (Future: DNA-C) 3G RAM and 4 CPUs Serve more than 6K devices BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 56

55 How Does SD-AVC work? (Basics) SD-AVC defines Sensors and Consumers in the network data plane Sensors are network devices (with NBAR2) that produce classification information and export it to the SD-AVC network service Up to 2Kbps for a small branch router Consumers are network devices that consume classification information from the SD-AVC network service A network device can be a sensor, a consumer or both BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 57

56 How Does SD-AVC work? (Basics) Sensors with NBAR2, classify traffic & cache results in the form of Application Rules Application Rule is defined as an L3/L4 to App-ID mapping Application Rule Example: id IP port L4 vrf-id vrf name app-id eng-id sel-id app-name #hits black weight rating ============================================================================================================================== TCP 0 global vnc 1 no 69 1 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 58

57 How SD-AVC works? (Basics) cont. The SD-AVC service compiles application rules received from the different network sensors (as well as external authoritative sources) The service generates an Application Rules Pack Consumers pull the application rules pack from the SD-AVC service and install the application rules in their data-plane On-device classification is enhanced with the newly installed SD-AVC application rules This process is periodic BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 59

58 SD-AVC Asymmetric Webex example branch NBAR2 Classify first flow as Webex (based on Certificate) MPLS NBAR2 Classify first flow upstream as Webex (based on Certificate) Webex br1 hub rtr Corporate Servers Webex DNS br0 Webex br2 mc Path Policy: Webex => MPLS Internet The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 60

59 SD-AVC Asymmteric Webex example branch NBAR2 Classify first flow as Webex (based on Certificate) MPLS NBAR2 Classify first flow upstream as Webex (based on Certificate) Webex br1 hub rtr Corporate Servers Webex DNS br0 mc Webex br2 SD- AVC Path Policy: Webex => MPLS Internet The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 61

60 Exported sockets: ================= SD-AVC Asymmteric Webex example id IP port L4 vrf-id vrf name app-id eng-id sel-id app-name black =========================================================================================== NBAR TCP 2 Mgt vnc Classify first flow upstream as no branch MPLS Webex (based on Certificate) hub TCP 2 Mgt vnc no TCP 2 Mgt vnc no NBAR2 TCP 2 Mgt webex-meeting no Classify first flow Webex br1 as Webex (based on Certificate) rtr Corporate Servers Webex DNS br0 mc Webex br2 SD- AVC Path Policy: Webex => MPLS Internet The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 61

61 Exported sockets: ================= SD-AVC Asymmteric Webex example id IP port L4 vrf-id vrf name app-id eng-id sel-id app-name black =========================================================================================== NBAR TCP 2 Mgt vnc Classify first flow upstream as no branch MPLS Webex (based on Certificate) hub TCP 2 Mgt vnc no TCP 2 Mgt vnc no NBAR2 TCP 2 Mgt webex-meeting no Classify first flow Webex br1 as Webex (based on Certificate) rtr Corporate Servers Webex DNS br0 mc Webex br2 SD- AVC Path Policy: Webex => MPLS Internet The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 61

62 SD-AVC Asymmetric Webex example branch NBAR2 Classify first flow as Webex (based on Certificate) MPLS NBAR2 Classify first flow upstream as Webex (based on Certificate) Webex br1 hub rtr Corporate Servers Webex DNS br0 mc Webex br2 SD- AVC Path Policy: Webex => MPLS Internet The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 64

63 SD-AVC Asymmetric Webex example Imported sockets: ================= branch NBAR2 Classify first flow br0 MPLS NBAR2 Classify first flow upstream as Webex (based on Certificate) Webex id IP port L4 vrf-id vrf name app-id eng-id sel-id app-name black as Webex ========================================================================================== (based on = Certificate) TCP 2 Mgt vnc no TCP 2 Mgt vnc no TCP 2 Mgt vnc no TCP 2 Mgt webex-meeting no Webex br1 br2 hub rtr mc SD- AVC Corporate Servers Path Policy: Webex => MPLS Webex DNS Internet The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 65

64 SD-AVC Asymmetric Webex example branch NBAR2 Classify first flow as Webex (based on Certificate) MPLS NBAR2 Classify first flow upstream as Webex (based on Certificate) Webex br1 hub rtr Corporate Servers Webex DNS br0 mc Webex br2 SD- AVC Path Policy: Webex => MPLS Internet Imported sockets: ================= id IP port L4 vrf-id vrf name app-id eng-id sel-id app-name black =========================================================================================== TCP 2 Mgt vnc no TCP 2 Mgt vnc no TCP 2 Mgt vnc no TCP 2 Mgt webex-meeting no The problem: Webex downstream Is routed via Internet due to bad classification NBAR2 Can t classify flow in the downstream (no certificate) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 66

65 Asymmetric Fixed Webex example - with SD-AVC branch MPLS NBAR2 Classify first flow upstream as Webex (based on Certificate) hub NBAR2 Classify first flow as Webex (based on Certificate) Webex br1 rtr Corporate Servers Webex DNS br0 mc SD- AVC Path Policy: Webex => MPLS br2 Internet Imported sockets: ================= id IP port L4 vrf-id vrf name app-id eng-id sel-id app-name black =========================================================================================== TCP 2 Mgt vnc no TCP 2 Mgt vnc no TCP 2 Mgt vnc no TCP 2 Mgt webex-meeting no Webex Downstream Is routed via MPLS NBAR2 Classify Webex Downstream (based on SD-AVC) internet BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 67

66 SD-AVC External Sources BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 68

67 SD-AVC and External sources The SD-AVC service connects with external authoritative sources to enrich application classification dynamically and seamlessly Enables us to: Connect Cisco Security databases Provide real-time Cloud/SaaS information Provision Home-grown Applications Example use cases are: Automatic Enrichment of Cloud/SaaS applications (MS RSS, CASI) Automatic Learning of Enterprise Local or Private apps (Infoblox/ACI/CUCM) BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 69

68 SD-AVC Operation (Data Flow) CloudLock 2 Application Rules Pack Generation Network Service SD-AVC 4 MS RSS Infoblox Controller 5 Network Layer 3 Application Rules pack Cached application rules (JSON) Application Rules Pack 3 1 Consumer Sensor & Consumer BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 70

69 SD-AVC Connectors Microsoft Office 365 contains geolocation and world wide FQDN and URL information (PoC) CASI contains 10,000 applications with domain and certificate information - Provides DNS information for home grown applications (PoC) BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 71

70 SD-AVC and Microsoft Office365

71 Using Microsoft RSS How does it work? Office 365 URLs and IP address ranges Requires connectivity to the internet (from the SD-AVC service) XML format Huge list of IP addresses and ranges Much more robust list of domains BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 73

72 Using Microsoft RSS How does it work? BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 74

73 Using Microsoft RSS How does it work? Imported Data from Microsoft Cisco Protocol Pack Application Data New Domain Information from Microsoft Example: jpn.delve.office.com BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 75

74 Using Microsoft RSS How does it work? Imported Data from Microsoft Cisco Protocol Pack Application Data New Domain Information from Microsoft jpn.delve.office.com BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 76

75 Using Microsoft RSS How does it work? (Second step) 1. Find the correct application for the new domains 2. Using machine learning based on the previous learning set of Office 365 and existing host mappings supplied by Cisco NBAR2 Protocol Pack Algorithm: Given a the previous learning set and a new domain that we want to map it to an application: host1 host2 host3 app1 app2 app3 jpn.delve.office.com ms-office365??? BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 77

76 Using Microsoft RSS How does it work? (Third Step) Compile a new pack with the new signature and make it available for the devices The secondary pack is installed along side with Cisco NBAR2 protocol-pack New domains are now supported automatically SD-AVC BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 78

77 Demo

78 What we ll show in the Demo We will demonstrate how complete asymmetric devices can teach each other with classification information, using SD-AVC. We will show how external sources can enhance application recognition We will show these new automatic signatures help the application recognition in an asymmetric scenario with SD-AVC BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 80

79 Microsoft Office365 RSS SD-AVC Pull Application Rules Data Analytics (JSON) Pull Application Rules Data Analytics (JSON) CSR1Kv CSR-Demoupstream Down Stream Down Stream CSR1Kv csr-demodownstream Upstream Trex Traffic Generator Upstream BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 81

80 Demo Script Note: We expedited some of the timers, this may lead to skew in status indications 1. Downstream Setup Not connected to SD-AVC 2. Connect Downstream to the SD-AVC Network Service First level of Asymmetry fix 3. Enrich the devices with a Secondary Pack based on MS Office365 Cloud Info 4. Downstream Setup classifies based on the MS Info using SD-AVC Second level of Asymmetry fix BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 82

81 SD-AVC and Cloudlock CASI

82 SD-AVC and Cloudlock CASI Why? Database synchronization between Cloudlock SaaS Security Index and SD-AVC/NBAR Better SaaS application recognition leveraging on Cloudlock Security Cloud infrastructure Better response time to the application and domain changes Cloudlock Shadow IT visibility leveraging SD-AVC on Cisco enterprise network BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 84

83 SD-AVC and Cloudlock Self-Learning Network Application database & Shadow-IT Cloudlock Analysis & Feedback SD-AVC Learning Network Device BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 85

84 How it works? Cloudlock CASI Enterprise Network SD-AVC 1 Learning process of unfamiliar domains BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 86

85 How it works? Cloudlock CASI 2 Enterprise Network SD-AVC BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 87

86 How it works? Cloudlock CASI 2 Enterprise Network SD-AVC BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 88

87 How it works #2? Cloudlock CASI 2 Enterprise Network SD-AVC 1 Update CASI with offline application information from NBAR/CASI R&D BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 89

88 SD-AVC Delivery Plan

89 SD-AVC Delivery plan Phase 1 (FCS- Oct 2017) IWAN 2.2.1: SD-AVC hosted on XE Container Improved application recognition in Hub Asymmetric Routing environment Improved first packet classification decision Application recognition function serviceability Protocol Pack automatic update Phase 2 (FCS Jan 2018) Cloud/SaaS automatic signatures push (MS RSS) High scale of SD-AVC sensors (6K) support asymmetrical routing in branch routers Support IWAN 2.3 DCA (Direct Cloud Access) FCS March 2018 Furture Unknown and Generic Traffic Discovery High scale custom application support (1000+) Viptela vmanage integration DNA-C App-Policy/EasyQoS use cases Wireless & Switching BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 91

90 Q&A

91 Homework

92 What you can do? - Use Application Visibility on WebUI (Device level visibility) - XE routers supported 3.16 and up - Cat3K/9K supported and up - Download and install SD-AVC on a router (network level visibilty) - Enlist to NBAR2/SD-AVC announcements send an with SUBSCRIBE to cisco-nbar2-pp-announcement@cisco.com BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 94

93 Wrap up - NBAR2 has evolved and matured to tackle today s networks challenges - SD-AVC introduces new innovation and advances to network level using analytics and external sources - The evolution Cisco application recognition technology unleashes great capabilities both in the device side and controller side, to provide application based solutions like SD-WAN, EasyQoS, Assurance and Security BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 95

94 Wrap up SD-AVC makes the network more intuitive. BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 96

95 Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click Join the Discussion 3. Install Spark or go directly to the space 4. Enter messages/questions in the space cs.co/ciscolivebot#brkcrs Cisco and/or its affiliates. All rights reserved. Cisco Public

96 Please complete your Online Session Evaluations after each session Complete 4 Session Evaluations & the Overall Conference Evaluation (available from Thursday) to receive your Cisco Live T-shirt All surveys can be completed via the Cisco Live Mobile App or the Communication Stations Complete Your Online Session Evaluation Don t forget: Cisco Live sessions will be available for viewing on-demand after the event at Cisco and/or its affiliates. All rights reserved. Cisco Public

97 Continue Your Education Come and meet us on DevNet zone SD-AVC Demo Pod Whisper Suite Meet the Engineer 1:1 meetings BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 99

98 Thank you

99

100 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 102

101 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 103

102 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 104

103 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 105

104 BRKCRS Cisco and/or its affiliates. All rights reserved. Cisco Public 106

105

Cisco SD-WAN. Intent-based networking for the branch and WAN. Carlos Infante PSS EN Spain March 2018

Cisco SD-WAN. Intent-based networking for the branch and WAN. Carlos Infante PSS EN Spain March 2018 Cisco SD-WAN Intent-based networking for the branch and WAN Carlos Infante PSS EN Spain March 2018 Aug-12 Oct-12 Dec-12 Feb-13 Apr-13 Jun-13 Aug-13 Oct-13 Dec-13 Feb-14 Apr-14 Jun-14 Aug-14 Oct-14 Dec-14

More information

Routing Underlay and NFV Automation with DNA Center

Routing Underlay and NFV Automation with DNA Center BRKRST-1888 Routing Underlay and NFV Automation with DNA Center Prakash Rajamani, Director, Product Management Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session

More information

Cloud-Ready WAN For IAAS & SaaS With Cisco s Next- Gen SD-WAN

Cloud-Ready WAN For IAAS & SaaS With Cisco s Next- Gen SD-WAN BRKCRS-2113 Cloud-Ready WAN For IAAS & SaaS With Cisco s Next- Gen SD-WAN Sumanth Kakaraparthi Product Leader SD-WAN Manan Shah Director Of Product Management Cisco Spark How Questions? Use Cisco Spark

More information

Cisco SD-AVC User Guide, Release 1.1.0

Cisco SD-AVC User Guide, Release 1.1.0 First Published: 2017-10-22 Last Modified: 2017-10-22 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

DNA Assurance. Predict Network Failures Before They Become Issues

DNA Assurance. Predict Network Failures Before They Become Issues PSOEWN-4360 DNA Assurance Predict Network Failures Before They Become Issues Damodar Banodkar, Product Manager, Enterprise Group Bill Rubino, Product Marketing, Enterprise Group Manuel Ortiz, Senior Wireless

More information

Next generation branch with SD-WAN and NFV

Next generation branch with SD-WAN and NFV Next generation branch with SD-WAN and NFV Kiran Ghodgaonkar, Senior Manager, Enterprise Marketing Mani Ganeson, Senior Product Manager PSOCRS-2004 @ghodgaonkar Cisco Spark How Questions? Use Cisco Spark

More information

Cisco SD-Access Hands-on Lab

Cisco SD-Access Hands-on Lab LTRCRS-2810 Cisco SD-Access Hands-on Lab Larissa Overbey - Technical Marketing Engineer, Cisco Derek Huckaby - Technical Marketing Engineer, Cisco https://cisco.box.com/v/ltrcrs-2810-bcn2018 Password:

More information

Insights into your WLC with Wireless Streaming Telemetry

Insights into your WLC with Wireless Streaming Telemetry Insights into your WLC with Wireless Streaming Telemetry Jeremy Cohoe Technical Marketing Engineer Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this

More information

Get Hands On With DNA Center APIs for Managing Intent

Get Hands On With DNA Center APIs for Managing Intent DEVNET-3620 Get Hands On With DNA Center APIs for Managing Intent Adam Radford Distinguished Systems Engineer Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session

More information

PnP Deep Dive Hands-on with APIC-EM and Prime Infrastructure

PnP Deep Dive Hands-on with APIC-EM and Prime Infrastructure LTRNMS-2007 PnP Deep Dive Hands-on with APIC-EM and Prime Infrastructure Thomas Gerneth, Julian Mueller,Tobias Huelsdau Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after

More information

Cloud Intelligent Network

Cloud Intelligent Network Dubrovnik, Croatia, South East Europe 20-22 May, 2013 Cloud Intelligent Network Mitko Vasilev CIN Lead Central Europe mitko@cisco.com 2011 2012 Cisco and/or its affiliates. All rights reserved. 1 New Application

More information

Serviceability of SD-WAN

Serviceability of SD-WAN BRKCRS-2112 Serviceability of SD-WAN Chandrabalaji Rajaram & Ali Shaikh Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live

More information

Več kot SDN - SDA arhitektura v uporabniških omrežjih

Več kot SDN - SDA arhitektura v uporabniških omrežjih Več kot SDN - SDA arhitektura v uporabniških omrežjih Aleksander Kocelj SE Cisco Agenda - Introduction to Software Defined Access - Brief description on SDA - Cisco SDA Assurance - DEMO 2 New Requirements

More information

Borderless Networks. Tom Schepers, Director Systems Engineering

Borderless Networks. Tom Schepers, Director Systems Engineering Borderless Networks Tom Schepers, Director Systems Engineering Agenda Introducing Enterprise Network Architecture Unified Access Cloud Intelligent Network & Unified Services Enterprise Networks in Action

More information

Technology Overview. Overview CHAPTER

Technology Overview. Overview CHAPTER CHAPTER 2 Revised: July 29, 2013, This overview of AVC technology includes the following topics: Overview, page 2-1 AVC Features and Capabilities, page 2-2 AVC Architecture, page 2-4 Interoperability of

More information

Cisco Container Platform

Cisco Container Platform Cisco Container Platform Pradnesh Patil Suhail Syed Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click

More information

Cisco SD-Access Building the Routed Underlay

Cisco SD-Access Building the Routed Underlay Cisco SD-Access Building the Routed Underlay Rahul Kachalia Sr. Technical Leader Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the

More information

APIC-EM / EasyQoS - End to End Orchestration of QoS in Enterprise Networks

APIC-EM / EasyQoS - End to End Orchestration of QoS in Enterprise Networks APIC-EM / EasyQoS - End to End Orchestration of QoS in Enterprise Networks Saurav Prasad Technical Marketing Engineer CTHNMS-1002 Cisco Spark How Questions? Use Cisco Spark to chat with the speaker after

More information

TRex Realistic Traffic Generator

TRex Realistic Traffic Generator DEVNET-1120 TRex Realistic Traffic Generator Hanoch Haim, Principal Engineer Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco

More information

Transforming the Network for the Digital Business

Transforming the Network for the Digital Business Transforming the Network for the Digital Business Driven by Software Defined Platforms Hugo Padilla Prad Enterprise Networks Digital Acceleration Team CCIE Emeritus #12444 Cisco Forum Kiev, November 14

More information

Demystifying Machine Learning

Demystifying Machine Learning Demystifying Machine Learning Dmitry Figol, WW Enterprise Sales Systems Engineer - Programmability @dmfigol CTHRST-1002 Agenda Machine Learning examples What is Machine Learning Types of Machine Learning

More information

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco

PSOACI Why ACI: An overview and a customer (BBVA) perspective. Technology Officer DC EMEAR Cisco PSOACI-4592 Why ACI: An overview and a customer (BBVA) perspective TJ Bijlsma César Martinez Joaquin Crespo Technology Officer DC EMEAR Cisco Lead Architect BBVA Lead Architect BBVA Cisco Spark How Questions?

More information

PSOACI Tetration Overview. Mike Herbert

PSOACI Tetration Overview. Mike Herbert Tetration Overview Mike Herbert Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click Join the Discussion

More information

Enterprise Recording and Live Streaming Architecture with VBrick

Enterprise Recording and Live Streaming Architecture with VBrick Enterprise Recording and Live Streaming Architecture with VBrick Terry French Technical Manager - International - VBrick Systems Inc BRKCOL-2111 Agenda Enterprise Video Overview VBrick Core Components

More information

Hands-On with IoT Standards & Protocols

Hands-On with IoT Standards & Protocols DEVNET-3623 Hands-On with IoT Standards & Protocols Casey Bleeker, Developer Evangelist @geekbleek Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this

More information

DNA Automation Services Offerings

DNA Automation Services Offerings DNA Automation Services Offerings Jamie Owen, Solutions Architect, Cisco Advanced Services Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session

More information

THE NETWORK. INTUITIVE. Powered by intent, informed by context. Rajinder Singh Product Sales Specialist - ASEAN August 2017

THE NETWORK. INTUITIVE. Powered by intent, informed by context. Rajinder Singh Product Sales Specialist - ASEAN August 2017 THE NETWORK. INTUITIVE. Powered by intent, informed by context. Rajinder Singh Product Sales Specialist - ASEAN August 2017 The Network. Intuitive. Constantly learning, adapting and protecting. L E A R

More information

Cloud Mobility: Meraki Wireless & EMM

Cloud Mobility: Meraki Wireless & EMM BRKEWN-2002 Cloud Mobility: Meraki Wireless & EMM Emily Sporl Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile

More information

Machine Learning with Python

Machine Learning with Python DEVNET-2163 Machine Learning with Python Dmitry Figol, SE WW Enterprise Sales @dmfigol Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session

More information

Cisco Spark Messaging APIs - Integration Platforms as a Service Real World Use-Cases

Cisco Spark Messaging APIs - Integration Platforms as a Service Real World Use-Cases DEVNET-2023 Cisco Spark Messaging APIs - Integration Platforms as a Service Real World Use-Cases David Staudt DevNet Developer Evangelist / Principal Engineer Cisco Spark How Questions? Use Cisco Spark

More information

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016 Network Automation and Branch Agility The Network Helps Enable Digital Business Rajinder Singh Product Sales Specialist June 2016 Agenda WAN Market Drivers Cisco Intelligent WAN (IWAN) Cisco Intelligent

More information

BRKCOC-2399 Inside Cisco IT: Integrating Spark with existing large deployments

BRKCOC-2399 Inside Cisco IT: Integrating Spark with existing large deployments Inside Cisco IT: Integrating Spark with existing large deployments Jan Seynaeve, Sr. Collaborations Engineer Luke Clifford, Sr. Collaborations Engineer Cisco Spark How Questions? Use Cisco Spark to communicate

More information

Automation with Meraki Provisioning API

Automation with Meraki Provisioning API DEVNET-2120 Automation with Meraki Provisioning API Courtney M. Batiste, Solutions Architect- Cisco Meraki Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1.

More information

Release Notes for NBAR2 Protocol Pack for Cisco Wireless Controllers

Release Notes for NBAR2 Protocol Pack for Cisco Wireless Controllers Release Notes for NBAR2 Protocol Pack 19.1.0 for Cisco Wireless Controllers Overview, page 1 Supported Platforms, page 2 New Protocols in NBAR2 Protocol Pack 19.1.0, page 2 Updated Protocols in NBAR2 Protocol

More information

SOLUTION BRIEF Enterprise WAN Agility, Simplicity and Performance with Software-Defined WAN

SOLUTION BRIEF Enterprise WAN Agility, Simplicity and Performance with Software-Defined WAN S O L U T I O N O V E R V I E W SOLUTION BRIEF Enterprise WAN Agility, Simplicity and Performance with Software-Defined WAN Today s branch office users are consuming more wide area network (WAN) bandwidth

More information

NXOS in the Real World Using NX-API REST

NXOS in the Real World Using NX-API REST NXOS in the Real World Using NX-API REST Adrian Iliesiu Corporate Development Engineer Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session

More information

Cisco SD-WAN and DNA-C

Cisco SD-WAN and DNA-C Cisco SD-WAN and DNA-C SD-WAN Cisco SD-WAN Intent-based networking for the branch and WAN 4x Improved application experience Better user experience Deploy applications in minutes on any platform with consistent

More information

Cisco Virtualized Infrastructure Manager

Cisco Virtualized Infrastructure Manager DEVNET-2570 Virtualized Infrastructure Manager Suhail Syed, Product Manager Vamsi Krihsna Kuppur, Product Manager Spark How Questions? Use Spark to communicate with the speaker after the session 1. Find

More information

Tetration Hands-on Lab from Deployment to Operations Support

Tetration Hands-on Lab from Deployment to Operations Support LTRACI-2184 Tetration Hands-on Lab from Deployment to Operations Support Furong Gisiger, Solutions Architect Lawrence Zhu, Sr. Solutions Architect Cisco Spark How Questions? Use Cisco Spark to communicate

More information

Cisco ONE Software Overview. October 2017

Cisco ONE Software Overview. October 2017 Cisco ONE Software Overview October 2017 Agenda Why Cisco ONE Software and the Outcome Offers and Use Case Access (Wireless and Switching) WAN Cloud and Compute DC Networking Smart Accounts Resources Cisco

More information

Cisco SD-WAN (Viptela) Migration, QoS and Advanced Policies Hands-on Lab

Cisco SD-WAN (Viptela) Migration, QoS and Advanced Policies Hands-on Lab Cisco SD-WAN (Viptela) Migration, QoS and Advanced Policies Hands-on Lab Ali Shaikh Technical Leader Faraz Shamim Sr. Technical Leader Mossaddaq Turabi Distinguished ENgineer Cisco Spark How Questions?

More information

Cisco APIC Enterprise Module Simplifies Network Operations

Cisco APIC Enterprise Module Simplifies Network Operations Cisco APIC Enterprise Module Simplifies Network Operations October 2015 Prepared by: Zeus Kerravala Cisco APIC Enterprise Module Simplifies Network Operations by Zeus Kerravala October 2015 º º º º º º

More information

Intelligent WAN : CVU update

Intelligent WAN : CVU update Intelligent WAN : CVU update Deliver enhanced mobile experience at the branch with Intelligent WAN Soren D. Andreasen (sandreas@cisco.com) Technical Solution Architect CCIE# 3252 Agenda IWAN 2.0/2.1 overview

More information

Enabling Quality of Service with Cisco SDN. Jon Snyder

Enabling Quality of Service with Cisco SDN. Jon Snyder Enabling Quality of Service with Cisco SDN Jon Snyder Agenda Introduction SDN: What Do We Mean, and What s the Point? Background Collaboration Applications and the Network SDN and APIC-EM Network Configuration

More information

Pradeep Kathail Chief Software Architect Network Operating Systems Technology Group, Cisco Systems Inc.

Pradeep Kathail Chief Software Architect Network Operating Systems Technology Group, Cisco Systems Inc. Pradeep Kathail Chief Software Architect Network Operating Systems Technology Group, Cisco Systems Inc. March 4 th, 2014 2012 2010 Cisco and/or its affiliates. All rights reserved. 1 2012 Cisco and/or

More information

DevNet Workshop-Hands-on with CloudCenter and Jenkins

DevNet Workshop-Hands-on with CloudCenter and Jenkins DevNet Workshop-Hands-on with CloudCenter and Jenkins Tuan Nguyen, Technical Marketing Engineer, CPSG Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find

More information

Intelligent WAN (IWAN) Design and Deployment

Intelligent WAN (IWAN) Design and Deployment Intelligent WAN (IWAN) Design and Deployment Adam Groudan, Technical Solutions Architect David Prall, Communications Architect BRKCRS-2002 Cisco Spark How Questions? Use Cisco Spark to communicate with

More information

IWAN APIC-EM Application Cisco Intelligent WAN

IWAN APIC-EM Application Cisco Intelligent WAN IWAN APIC-EM Application Cisco Intelligent WAN René og Per Cisco DK SE s Feb 23 th 2016 AVC MPLS Private Cloud 3G/4G-LTE Virtual Private Cloud Branch WAAS PfR Internet Public Cloud Control, Management,

More information

Introduction to Cisco SD- WAN (Viptela)

Introduction to Cisco SD- WAN (Viptela) LTRCRS-2005 Introduction to Cisco SD- WAN (Viptela) Brad Edgeworth, Systems Engineer, CCIE#31574 Dustin Schuemann, Solutions Architect Madhavan Aruanchalam, Technical Marketing Engineer Cisco Spark How

More information

Cisco SD-WAN. Securely connect any user to any application across any platform, all with a consistent user experience.

Cisco SD-WAN. Securely connect any user to any application across any platform, all with a consistent user experience. Cisco Securely connect any user to any application across any platform, all with a consistent user experience. Introduction Moving applications to the cloud requires faster, more reliable connectivity.

More information

DevOps CICD for VNF a NetOps Approach

DevOps CICD for VNF a NetOps Approach DevOps CICD for VNF a NetOps Approach Renato Fichmann Senior Solutions Architect Cisco Advanced Services Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1.

More information

Encrypted Traffic Analytics

Encrypted Traffic Analytics Encrypted Traffic Analytics Introduction The rapid rise in encrypted traffic is changing the threat landscape. As more businesses become digital, a significant number of services and applications are using

More information

Introducing Cisco Network Assurance Engine

Introducing Cisco Network Assurance Engine BRKACI-2403 Introducing Cisco Network Assurance Engine Intent Based Networking for Data Centers Sundar Iyer, Distinguished Engineer Head Cisco Network Assurance Engine Team Dhruv Jain, Director of Product

More information

Hidden Figures: Securing what you cannot see

Hidden Figures: Securing what you cannot see Hidden Figures: Securing what you cannot see TK Keanini, Distinguished Engineer Stealthwatch, Advanced Threat Solutions CID-0006 Hello My Name is TK Keanini Keanini (Pronounced Kay-Ah-Nee-Nee) TK: The

More information

CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies)

CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies) CVP CVP Enterprise Cisco SD-WAN Retail Profile (Hybrid WAN, Segmentation, Zone-Based Firewall, Quality of Service, and Centralized Policies) 2018 Cisco and/or its affiliates. All rights reserved. This

More information

Orange: Cisco & Orange: a human touch for a digital experience

Orange: Cisco & Orange: a human touch for a digital experience BRKPAR-4667 Orange: Cisco & Orange: a human touch for a digital experience Pierre louis Biaggi, SVP Head of Connectivity Business Unit, Orange Business Services Eric Masseboeuf, Collaboration Head of Business

More information

CloudCenter for Developers

CloudCenter for Developers DEVNET-1198 CloudCenter for Developers Conor Murphy, Systems Engineer Data Centre Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the

More information

Introducing Cisco Network Analysis Module (NAM) Software 5.0

Introducing Cisco Network Analysis Module (NAM) Software 5.0 Introducing Cisco Network Analysis Module (NAM) Software 5.0 Next Generation User Experience Deepak Bhargava, Product Manager, Cisco Damien Lim, Technical Marketing Engineer, Cisco February 8/9, 2011 1

More information

Cisco.Network.Intuitive FastLane IT Forum. Andreas Korn Systems Engineer

Cisco.Network.Intuitive FastLane IT Forum. Andreas Korn Systems Engineer Cisco.Network.Intuitive FastLane IT Forum Andreas Korn Systems Engineer 12.10.2017 Ziele dieser Session New Era of Networking - Was ist darunter zu verstehen? Software Defined Access Wie revolutioniert

More information

Simplify and automate your network with Cisco DNA

Simplify and automate your network with Cisco DNA Simplify and automate your network with Cisco DNA Mr. Brink Sanders Managing Director, Software and Network Transformation Cisco Asia Pacific and Japan March, 2017 Agenda Software-Defined Networking (SDN)

More information

A Practical Look at DNA Center: A better way to manage your network in the digital era. Hands-On Lab

A Practical Look at DNA Center: A better way to manage your network in the digital era. Hands-On Lab LTRNMS-2500 A Practical Look at DNA Center: A better way to manage your network in the digital era. Hands-On Lab Saurav Prasad Technical Marketing Engineer San Jose, USA Lila Rousseaux CCIE#6899 Technical

More information

Cisco Cloud Security. How to Protect Business to Support Digital Transformation

Cisco Cloud Security. How to Protect Business to Support Digital Transformation Cisco Cloud Security How to Protect Business to Support Digital Transformation Dragan Novakovic Cybersecurity Consulting Systems Engineer January 2018. Security Enables Digitization Digital Disruption,

More information

Supported Platforms for Cisco Path Trace, Release x. This document describes the supported platforms for the Cisco Path Trace, Release x.

Supported Platforms for Cisco Path Trace, Release x. This document describes the supported platforms for the Cisco Path Trace, Release x. Cisco Path Trace Application for APIC-EM Supported Platforms, Release 1.5.0.x First Published: 2017-06-23, Release 1.5.0.x This document describes the supported platforms for the Cisco Path Trace, Release

More information

Customer s journey into the private cloud with Cisco Enterprise Cloud Suite

Customer s journey into the private cloud with Cisco Enterprise Cloud Suite Customer s journey into the private cloud with Cisco Enterprise Cloud Suite Peter Charpentier, Senior Solution Architect, Cisco AS Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker

More information

Configuring Application Visibility and Control

Configuring Application Visibility and Control Information About Application Visibility and Control, page 1 Restrictions for Application Visibility and Control, page 2 (GUI), page 3 (CLI), page 4 Configuring NetFlow, page 5 Information About Application

More information

Cisco SD-WAN Application Acceleration

Cisco SD-WAN Application Acceleration BRKRST-2514 Cisco SD-WAN Application Acceleration Sukruth Srikantha, Technical Marketing Engineer Hamzah Kardame, Technical Marketing Engineer Atif Khan, Sr. Director Enterprise Routing Cisco Spark How

More information

Cisco Multicloud Portfolio: Cloud Connect

Cisco Multicloud Portfolio: Cloud Connect Deployment Guide Cisco Multicloud Portfolio: Cloud Connect Deployment Guide for Cisco SD-WAN Cloud onramp for SaaS August 2018 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco

More information

Threat Centric Network Security

Threat Centric Network Security BRKSEC-2056 Threat Centric Network Security Ted Bedwell, Principal Engineer Network Threat Defence Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this

More information

Cisco Software-Defined Access

Cisco Software-Defined Access F Cisco Software-Defined ccess What is Cisco Software-Defined ccess? Cisco Software-Defined ccess (SD-ccess) is a central part of the Cisco Digital Network rchitecture (Cisco DN ) solution and represents

More information

How can we gain the insights and control we need to optimize the performance of applications running on our network?

How can we gain the insights and control we need to optimize the performance of applications running on our network? SOLUTION BRIEF CA Network Flow Analysis and Cisco Application Visibility and Control How can we gain the insights and control we need to optimize the performance of applications running on our network?

More information

BUILDING A NEXT-GENERATION FIREWALL

BUILDING A NEXT-GENERATION FIREWALL How to Add Network Intelligence, Security, and Speed While Getting to Market Faster INNOVATORS START HERE. EXECUTIVE SUMMARY Your clients are on the front line of cyberspace and they need your help. Faced

More information

SD-WAN 101. November 3 rd 2016 Rob McBride Marketing

SD-WAN 101. November 3 rd 2016 Rob McBride Marketing SD-WAN 101 November 3 rd 2016 Rob McBride Marketing Email: rob@viptela.com Twitter: @digitalmcb Industry trends impacting networking Cloud Mobile Social 2 Today s WAN is challenged to keep up Complex Operations

More information

DEVNET Introduction to Git. Ashley Roach Principal Engineer Evangelist

DEVNET Introduction to Git. Ashley Roach Principal Engineer Evangelist DEVNET-1080 Introduction to Git Ashley Roach Principal Engineer Evangelist Twitter: @aroach Email: asroach@cisco.com Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the

More information

How to Route Internet Traffic between A Mobile Application and IoT Device?

How to Route Internet Traffic between A Mobile Application and IoT Device? Whitepaper How to Route Internet Traffic between A Mobile Application and IoT Device? Website: www.mobodexter.com www.paasmer.co 1 Table of Contents 1. Introduction 3 2. Approach: 1 Uses AWS IoT Setup

More information

Cisco Enterprise Agreement

Cisco Enterprise Agreement PSODGT-1076 Cisco Enterprise Agreement John Marshall, Global Director: Cisco Enterprise Agreement strategy Vinay Nichani, WW Software Sales Cisco Spark How Questions? Use Cisco Spark to communicate with

More information

Understanding HTTPS to Decrypt it

Understanding HTTPS to Decrypt it Understanding HTTPS to Decrypt it James Everett Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click Join

More information

Git, Atom, virtualenv, oh my! Learn about dev tools to live by!

Git, Atom, virtualenv, oh my! Learn about dev tools to live by! BRKDEV-2633 Git, Atom, virtualenv, oh my! Learn about dev tools to live by! Ashley Roach, Principal Engineer Evangelist Agenda Introduction Why are developer tools useful? What s in the toolbelt? Tool

More information

Performance Routing Version 3 Configuration Guide

Performance Routing Version 3 Configuration Guide First Published: 2014-07-22 Last Modified: 2016-04-20 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Introduction to OpenConfig

Introduction to OpenConfig DEVNET-1775 Introduction to OpenConfig Santiago Álvarez, TME Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App

More information

Cisco ONE Software BRKRST Dan Lohmeyer Senior Director, Software Strategy and Operations

Cisco ONE Software BRKRST Dan Lohmeyer Senior Director, Software Strategy and Operations Cisco ONE Software BRKRST-1213 Dan Lohmeyer Senior Director, Software Strategy and Operations Agenda Introduction Enterprise Challenges Cisco ONE Software Conclusion Enterprise Challenges IT Decision Maker

More information

Automation and Programmability using Cisco Open NXOS and DevOps Tools

Automation and Programmability using Cisco Open NXOS and DevOps Tools Automation and Programmability using Cisco Open NXOS and DevOps Tools Jeff Lester Sr. Solutions Integration Architect Matt Tarkington Consulting Engineer Services Cisco Spark How Questions? Use Cisco Spark

More information

Cisco Tetration Analytics

Cisco Tetration Analytics Cisco Tetration Analytics Real-time application visibility and policy management using advanced analytics Yogesh Kaushik, Sr. Director Product Management PSOACI-2100 Agenda Market context Introduction:

More information

Delivering Enterprise SDN. Now. Simplify and Automate Your Network for Digital Transformation

Delivering Enterprise SDN. Now. Simplify and Automate Your Network for Digital Transformation Delivering Enterprise SDN. Now. Simplify and Automate Your Network for Digital Transformation Agenda Software-Defined Networking (SDN) Market Drivers Cisco APIC-EM Automate Network Configuration & Setup

More information

New Cisco 2800 And 3800 Series Integrated Services Router Wan Optimization Bundles

New Cisco 2800 And 3800 Series Integrated Services Router Wan Optimization Bundles Q&A New Cisco 2800 And 3800 Series Integrated Wan Optimization Bundles Q. What are the components of the new Cisco 2800 and 3800 series integrated services router WAN optimization bundles? A. There are

More information

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC)

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC) Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC) COURSE OVERVIEW: Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent

More information

SDN TO BE OR NOT TO BE. Uwe Richter SE Director Russia/CIS, East and South East Europe

SDN TO BE OR NOT TO BE. Uwe Richter SE Director Russia/CIS, East and South East Europe SDN TO BE OR NOT TO BE Uwe Richter SE Director Russia/CIS, East and South East Europe uwe@juniper.net FUNDAMENTAL PROBLEMS TO SOLVE Want more innovation in networking Want it more quickly too Want more

More information

QoS: NBAR Configuration Guide

QoS: NBAR Configuration Guide Last Modified: 2017-05-22 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS

More information

Converged Access CT 5760 AVC Deployment Guide, Cisco IOS XE Release 3.3

Converged Access CT 5760 AVC Deployment Guide, Cisco IOS XE Release 3.3 Converged Access CT 5760 AVC Deployment Guide, Cisco IOS XE Release 3.3 Last Updated: November, 2013 Introduction This guide is designed to help you deploy and monitor new features introduced in the IOS

More information

Release Notes for NBAR2 Protocol Pack

Release Notes for NBAR2 Protocol Pack Release Notes for Overview, page 1 Supported Platforms, page 1 Supported Releases, page 2 New Protocols in, page 2 Updated Protocols in, page 3 Deprecated Protocols in, page 7 Caveats in, page 7 Downloading,

More information

Hands On Exploration of NETCONF and YANG

Hands On Exploration of NETCONF and YANG Hands On Exploration of NETCONF and YANG Bryan Byrne, CCIE 25607 (R/S) Technical Solutions Architect Enterprise Networks @bryan25607 Agenda Introduction Module 1 YANG Data Modeling Module 2 Introduction

More information

Solution Overview. Cisco Intelligent WAN as a Service: Provide Businesses with Intelligent WAN Services. What You Will Learn.

Solution Overview. Cisco Intelligent WAN as a Service: Provide Businesses with Intelligent WAN Services. What You Will Learn. Solution Overview Cisco Intelligent WAN as a Service: Provide Businesses with Intelligent WAN Services What You Will Learn In order to control their WAN services costs and their user experience with important

More information

Cisco Prime for Enterprise Innovative Network Management

Cisco Prime for Enterprise Innovative Network Management Cisco Prime for Enterprise Innovative Network Management Session ID 1 Agenda Network Management Challenges Cisco Prime for Enterprise Overview Service-Centric Foundation Common Operational Attributes Benefits

More information

SD-Access Wireless: why would you care?

SD-Access Wireless: why would you care? SD-Access Wireless: why would you care? CUWN Architecture - Centralized Overview Policy Definition Enforcement Point for Wi-Fi clients Client keeps same IP address while roaming WLC Single point of Ingress

More information

Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies)

Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies) CVP CVP Enterprise SD-WAN Financial Profile (Hybrid WAN, Segmentation, Quality of Service, Centralized Policies) 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.

More information

LTRDCN-2100 Cloud networking solutions with Cisco Cloud Services Router (CSR 1000V) on AWS and Azure

LTRDCN-2100 Cloud networking solutions with Cisco Cloud Services Router (CSR 1000V) on AWS and Azure LTRDCN-2100 Cloud networking solutions with Cisco Cloud Services Router (CSR 1000V) on AWS and Azure Fan Yang, Cisco, Engineer, Technical Marketing Raghavendra K S, Cisco, Engineer, Technical Marketing

More information

An Introduction to Developing for Cisco Kinetic

An Introduction to Developing for Cisco Kinetic An Introduction to Developing for Cisco Kinetic Krishna Chengavalli Technical Marketing Engineer IoT Software Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session

More information

Advanced CSR Lab with High Availability and Transit VPC

Advanced CSR Lab with High Availability and Transit VPC Advanced CSR Lab with High Availability and Transit VPC Fan Yang, Cisco, Engineer, Technical Marketing Nikolai Pitaev, Cisco, Engineer, Technical Marketing LTRVIR-3004 Agenda Slides (30 Min.): CSR 1000V

More information

Compare Security Analytics Solutions

Compare Security Analytics Solutions Compare Security Analytics Solutions Learn how Cisco Stealthwatch compares with other security analytics products. This solution scales easily, giving you visibility across the entire network. Stealthwatch

More information

Faster, Better, and Cheaper? Building the SD-WAN Business Case

Faster, Better, and Cheaper? Building the SD-WAN Business Case Faster, Better, and Cheaper? Building the SD-WAN Business Case John Burke CIO & Principal Research Analyst Nemertes Research john@nemertes.com @burkejohne #FutureWAN Agenda ±About Nemertes ±The Current

More information

An Introduction to Monitoring Encrypted Network Traffic with "Joy"

An Introduction to Monitoring Encrypted Network Traffic with Joy An Introduction to Monitoring Encrypted Network Traffic with "Joy" Philip Perricone (SE) Bill Hudson (TL) Blake Anderson (TL) David McGrew (Fellow) Cisco Spark How Questions? Use Cisco Spark to communicate

More information