Automatisierung im LAN Der Start in eine neue Ära des Networkings Thomas Spiegel Consulting Systems Engineer September 2017
Cisco Disclaimer Cisco Roadmap Disclaimer. Some of the products and features described herein remain in varying stages of development and will be offered on a when-andif-available basis. This roadmap is subject to change at the sole discretion of Cisco, and Cisco will have no liability for delay in the delivery or failure to deliver any of the products or features set forth in this document
Enterprise Network Trends Digital Transformation Next generation Workspace Seamless Mobility, Consistent User Policy Explosion of User devices Device onboarding, segmentation, mobility, policy Internet of Things End to End Network Segmentation Manage an Increased Threat Landscape Easier to manage, flexible network solutions Device Abstractions, Northbound APIs Controller Based Networking Enterprise Network
Agenda SDN & Network Programmability SD-Access & DNA Center neue LAN Switches
SDN & Network Programmability
What is Software-Defined Networking (SDN)? An approach and architecture in networking where control and data planes are decoupled and intelligence and state are logically centralized An enabling technology where underlying network infrastructure is abstracted from the applications [network virtualization] A concept that leverages programmatic interfaces to enable external systems to influence network provisioning, control and operations 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
The Traditional Network Control and Data Plane resides within Physical Device CP DP CP DP Control Plane (CP) Data Plane (DP) CP DP CP DP CP DP CP DP CP DP CP DP Control plane learns/computes forwarding decisions Data plane acts on the forwarding decisions 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
The Network As It Could Be to an SDN Purist Control Plane (CP) CP DP CP DP CP Data Plane (DP) CP DP CP DP CP DP CP DP CP DP CP DP Control plane becomes centralized Physical device retains Data plane functions only 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
The Network As It Could Be In a Hybrid SDN CP DP CP DP CP Controller CP DP CP DP CP DP CP DP CP DP CP DP A Controller is centralized and separated from the Physical Device, but devices still retain a localized Control plane intelligence 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
SDN Addresses Needs for Centralized configuration, management/control, monitoring of network devices (physical or virtual) Ability to override traditional forwarding algorithms to suite unique business or technical needs Allowing external applications or systems to influence network provisioning and operation Rapid and scalable deployment of network services with life-cycle management 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 1
Change to Programmatic Interfaces Familiar Manual, CLI-driven, device-by-device approach is inefficient Increased need for programmatic interfaces which allow faster and automated execution of processes and workflows with reduced errors Need for a central source of truth and touch-point 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
So Are All Network Engineers Becoming Programmers? var myquestion = { question": All Engineers Becoming Programmers?", answer":[true,false] }; 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
What Skills Are Helpful to a Network Engineer Branching Out? Basic Programming constructs (conditionals, loops, data structures) Basic Python / Perl REST / Web Services Regular Expression Data encoding - XML / XSLT; JSON Basic SQL Basic shell scripting - grep #1 - Communicating Effectively with Programmers The Thinker, Auguste Rodin 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Network Programmability Cisco Education Offerings Course Description Cisco Certification Developing with Cisco Network Programmability (NPDEV) Designing and Implementing Cisco Network Programmability (NPDESI) Provides Application Developers with comprehensive curriculum to develop infrastructure programming skills; Addresses needs of software engineers who automate network infrastructure and/or utilize APIs and toolkits to interface with SDN controllers and individual devices Provides network engineers with comprehensive soup-to-nuts curriculum to develop and validate automation and programming skills; Directly addresses the evolving role of network engineers towards more programmability, automation and orchestration Cisco Network Programmability Developer (NPDEV) Specialist Certification Cisco Network Programmability Design and Implementation (NPDESI) Specialist Certification Programming for Network Engineers (PRNE) Learn the fundamentals of Python programming within the context of performing functions relevant to network engineers. Use Network Programming to simplify or automate tasks Recommended pre-requisite for NPDESI and NPDEV Specialist Certifications Cisco Digital Network Architecture Implementation Essentials (DNAIE) This training provides students with the guiding principles and core elements of Cisco s Digital Network Architecture (DNA) architecture and its solution components including; APIC-EM, NFV, Analytics, Security and Fabric. None For more details, please visit: http://learningnetwork.cisco.com Questions? Visit the Learning@Cisco Booth 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
DevNet http:// https://developer.cisco.com 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
What Are Cisco's SDN solutions?
Cisco SDN solutions Data Center: WAN: LAN / WLAN: Application Centric Infrastructure SD-WAN / NFV Solutions SD-Access & DNA Center Open NX-OS Release for Nexus Platforms Open IOS-XE Release for Catalyst & ISR4k/ASR1k Platforms 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
APIC-EM Application Policy Infrastructure Controller - Enterprise Module A purpose-built, easy to use SDN controller Does NOT require programming experience [but does have REST NBI] Does NOT require HW/SW upgrades to take advantage of controller model (but depending on intended network solution) Has specific applications built-in to address common network needs (Base Automation): Enterprise Service Automation (ESA), Intelligent WAN (IWAN), Plug-and-play (PnP), Path Trace, Easy QoS, SD-Bonjour-App, CAA- Life Cycle Management Is the Base System for the DNA Center in the SD-Access Solution Focus: Enterprise Customers with Few to No Programming Resources that desires a Commercially-supported solution that preserves existing investment and doesn t require HW/SW upgrades (depending on intended network solution) 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Software Defined Network is here today 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
SDA Design
SDA Simplified Management
SDA Segmentation & Policies 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SD-Access - Two Level Hierarchy Network Building Management VN 1 1 Virtual Network (VN) VRF Campus Users VN First level Segmentation that ensures zero Communication between Building Management and Campus Users 2 Group Policy 2 Scalable Group SGT/SGACL Second level Segmentation ensures role based access control between two groups within a Virtual Network 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
SDA Assurance * * Roadmap 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Know What Is Happening End user on-boarding and connectivity insights Application visibility and performance Network health and status Configuration compliance* 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Outcome based insights *Post FCS
GUI ** * * Campus Fabric: = Fabric-Protokolle (VXLAN, LISP, SGT) auf IOS-Level ** SD-Access: Automatisierung der Campus Fabric mittels DNA Center auf Basis APIC-EM NDP: Roadmap
SD-Access Architecture Roles and Terminology Group Repository Fabric Border VXLAN Overlay ISE / AD B DNA Center APIC-EM B NDP C DNA Controller Analytics Engine Fabric Mode WLC Control-Plane Nodes Control-Plane Nodes Map System that manages Endpoint ID to Device relationships Border Nodes A Fabric device (e.g. Core) that connects External L3 network(s) to the SD-Access Fabric Edge Nodes A Fabric device (e.g. Access or Distribution) that connects Wired Endpoints to the SD-Access Fabric Fabric Wireless Controller Wireless Controller (WLC) that is fabric-enabled Fabric Mode APs Access Points that are fabric-enabled. Intermediate Nodes Underlay Intermediate Nodes (Underlay) Fabric Edge Nodes Fabric Mode APs Overlay Endpoint traffic carried within VXLAN frames between Fabric Edges and between Fabric Edges and Border Nodes
SD-Access Platform Support A single fabric for your digital ready network Switching Routing Wireless SDA Extension NEW Catalyst 9400 NEW NEW Catalyst 9300 ASR-1000-X ASR-1000-HX ISR 4430 AIR-CT5520 AIR-CT8540 NEW NEW Catalyst Digital Building Catalyst 9500 ISR 4450 AIR-CT3504 ISR 4351 Wave 2 APs (1800, 2800,3800) Catalyst 3560-CX Catalyst 4500E Catalyst 6K Nexus 7700 ISR 4331 Catalyst 3850 and 3650 CSRv ENCS 5400** Wave 1 APs* (1700, 2700,3700) IE Switches** (2K/3K/4K/5K) 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public *with Caveats **Future
Zusammenfassung SD-Access Weiterentwicklung der Campus Switching Infrastruktur L3-basiertes & best practise Underlay L2 & L3 Overlay Wireless integriert integrierte Segmentierung integriertes Policy-Management User/Devices Unified Access Data Plane: Foundational Technology for DNA Fabric Unified IOS-XE 16.x Software: Foundational Technology for DNA Fabric DNA Center (APIC-EM): The FINAL Piece of the Puzzle Orchestration Software
neue LAN Switches: Catalyst 9000
Catalyst 9K Family One ASIC, OS & Licensing Converged ASIC UADP 2.0 Catalyst 9400 Lead Modular Access Converged OS Open IOS-XE Catalyst 9500 Lead Fixed Core Converged Licensing Catalyst 9300 Lead Fixed Access The Catalyst 9K Family is built on common attributes
Zusammenfassung DNA Digital Network Architecture Lösungen für die Anforderungen an Netzwerke heute & morgen APIC-EM der Cisco SDN Policy Controller für die Vereinfachung des Netzwerkbetriebes, LAN/WLAN/WAN APIC-EM Controller Software 1.5 und Basis-Apps kostenfrei und noch verfügbar heute beginnen! APIC-EM Controller Software 2.0 nicht mehr kostenfrei (inkludiert in Switch DNA Lizenzen) Software Defined Access Next Generation Campus Switching Infrastruktur automatisiert über die DNA-Center App auf dem APIC-EM Switching-Komponenten bei der Auswahl beachten, ob SDA-Readiness gegeben sein soll bevorzugt C9500 bzw. C6800 im Core/Distribution, alternativ N7700 bevorzugt C3650/C9300/C9400 im Access, alternativ C4500E, C2960X