Branch Deployment Automation with Prime Infrastructure and APIC-EM Prakash Rajamani, Manager, Product Management Bipin Kapoor, Manager, Technical Marketing PSONMS-2003
Distributed Branch Deployment Costs Capital Expenses 67% Operational Expenses 33% Onsite expert visit is necessary for execution High cost of expert time (frequently outsourced) High cost of travel to distributed branches Complex deployments across WAN/Access/WLAN Manual device-centric processes
Technical Tasks with Branch Infra Management Device Rack/Stack and LAN Cabling Can be done by local tech New Device Onboarding New Device Configuration New Services Configuration Existing device OS upgrade/reimaging Existing device reconfiguration Existing services reconfiguration Requires expert personnel usually from central IT/Network engineering team or Outsourced Consulting Service Provider (~2 Branch visits / year) Management tool integration Branch Network Operations Performed remotely by central IT Ops
Distributed Branch Infrastructure Deployment Standardized Branch Design Approvals and Bill of Shipment Rack and Stack Deployment Network Svcs Deployment Automated Monitoring Standardized branch designs Upfront and test and validation Inventory of branch sites and associated type Integration with management tools like IPAM Workflow automation for review and approval Generation of bill of shipment Change Management processes Router Switch WLC Access Points Physical or virtual Orchestration and Service Chaining IWAN Unified Access Converged Access High Density WLAN Instant Access Security Automation FCAPS Day 2 Monitoring Reporting Trending Capacity Planning Network Upgrades
Op-Ex is continuing to shrink Networks are growing How do you effectively manage this situation?
Agenda Branch Service Automation Service Design Service Request Service Approval Service Provisioning Service Subscription Virtual Branch Management
Role Process Branch Service Automation Process Architecture Service Design Service Catalog Service Request Service Provisioning Service Management Branch Design for Wireless, Routing and Switching Embedded CVD best practices Custom and prescriptive designs User, Application, Security, Access and Quality of Experience policy definition Branch designs (e.g. Small, Medium, Large) committed to Service Catalog as a service offering Setting up of business entities and groups for which services can be ordered Ordering of Branch type when new site(s) or new services are needed Approval workflow with embedded test / validation SLA definition for branch users and applications Orchestration of devices and network services enablement for the Branch using PnP and PKI Automation on APIC- EM APIC-EM led Policy compliance enforcement Business and Service level dash boarding / reporting for Network, SLA s, Security Status and Changes Drill down into events, monitoring and analytics tools for troubleshooting Network Architect, Security Admin Network Architect, Security Admin Network Operations, Application Admin Network Operations, Security Operations Network Operations, Security Operations High Cost, Skilled Resource, One Time Automated (Low TCO), Low Skill, Continuous
Branch Service Automation Components
Systemic View of Management / Control Roles Orchestrates sequential changes and enables IT process execution Network Infra Stores, processes and visualizes all historical data for monitoring and network change Owns the communication to/from the network and drives programmability
Cisco Controller and Management System Common Automation Layer System of Automation Branch Service Automation Common Monitoring / Assurance Feature Configurable Provisioning Policy Prescriptive Provisioning Common Controller Layer for Campus/ Branch System of Record System of Change Prime Infrastructure Prime Infrastructure APIC-EM Multiple APIC-EM Apps NE NE NE NE NE NE NE NE NE NE
Common Policy Model from Branch to DC Consistent Policy Across Cloud, DC, WAN and Access APIC APIC Application Network Profile SLA, Security, QoS, Load Balancing User/Things Network Profile QoS, Security, SLA, Device Cloud Data Center WAN Access
Introducing Cisco APIC - Enterprise Module Network Abstraction and Automation Cisco APIC - Enterprise Module Software or Appliance Based Open Daylight, RESTful, OpenFlow, CLI, onepk Existing & New Installations Catalyst, ISR, ASR, WLC Agile Integration Model Masking Network Complexity, Exposing Network Intelligence Base Software & Base Apps via DevNet, Premium & Partner Apps Priced (Cisco ONE Foundation)
SDN Led Automation Dramatically Lowers Cost and Risk RISK / COMPLEXITY High Device / Platform 100 s of Features End User Validate and Test COST High Operational Cost Cisco Solution Validated Medium Operational cost CVD Best Practices Low Policy Abstraction of Best Practices through APIC-EM APIC-EM Automated Cost saving through Automation
Cisco Prime Infrastructure Realizing the Vision of One Management Lifecycle Converged management with integrated best practices Data Center Bridging Network and Compute Assurance End-to-end application experience and visibility Campus Branch to DC Day 0 to Day N Application-Centric
Service Design
Design the Services for the branch Customizable Specify the network configuration via CLI Customize the branch based on Enterprise design Prescriptive Cisco Validated best practice design Policy based network configuration Mixed Prescriptive for network services Customizable for Enterprise operational policies
Branch - Deployment Options Wireless Branch Access Branch Branch Network
Prescriptive Design
Design flow Screen shots from BSA
Profiles Created Pending Approval In design mode Non Approved profiles cannot be provisioned to a branch
Customizable Design
Router Configuration/Switch Configuration Router bootstrap Running Config Software Image Version Switch bootstrap Software Image Version
Wireless - Site/Store Design Wireless Networks Guest Access Buildings and Floor AP Details Wireless network (SSID) Security configuration Direct internet access for guests Guest network parameters Building Floor Design Floor plan APs per floor Naming convention AP Group mapping Flex connect group mapping AP to WLC mapping
Wireless Network Design AP Group/ RF Profiles Flex Connect Group 802.11 unicast data rates 802.11 multicast data rates MCS Settings RRM Transmit Power Control RRM Coverage Hole Detection High density parameters Client load balancing Efficient AP Image Upgrade VLAN ACL Mapping WLAN ACL Mapping Webauth ACL Central DHCP WLAN Mapping
Service Request
Create a new Branch - Inputs Routers and switches Access Points Naming of devices Branch specific inputs Exception configuration/overrides Serial Numbers for site Controller IP address and S/No Convention for branch Routing configuration (VRF) Customization for the branch
BSA Service Request
Select the Serial Number that maps to the site for the device Input the custom parameters for the site Repeat the process for all of the devices in the site
Select the IP Address Range for the site Based on the IP Address range the devices get populated automatically Specify the naming convention for devices in the site
Design Version Control Mapping of branches to design Provides the ability to track design versions and branches associated with the design Compare versions for design changes Re-Provision branches with updated design version
Service Approval
Sites Pending Approval User has the option to select individual sites and View Profile details (Questionnaire that led to the site design) Choose to approve site design for service request (provisioning)
Service Provisioning
BSA Process flow Orchestration Branch Service Automation Network services provisioning Zero Touch Deployment of Day 0/Day 1 configuration Provisioning Prime Infrastructure APIC-EM (PnP Server) NETWORK
Branch Configuration Router configuration Router bootstrap Segmentation/ IWAN Config Branch Profile Switch Configuration WLC Configuration Switch bootstrap VLAN/Uplink/ Security WLC bootstrap and networks Flexconnect configuration Radio Configuration
Router Deployment Workflow Router setup in a store by tech Router pass serial number Router gets running config Router bootup using USB or iphone app Router get bootstrap config Router IWAN services enabled Router connect to PnP Server Image of Router upgraded Restart Router
Branch Wireless Configuration Branch Profile WLAN Templates (if does not exist) Guest Access Templates (if does not exist) Create Site/Buildings Create Floors and Upload floor plan Automatic templates for branch AP Group Templates Flex Connect Templates RF Profiles
Access Point Deployment Workflow AP setup in a store by tech AP set to WLC by rule AP set to AP group by naming rule AP associated to default controller AP placed in map AP set to flex connect group by naming rule New AP detected by MAC address AP renamed per site naming rule Restart Access Point
Service Subscription
Branch Operational Management
Service Compliance and Monitoring Automated configuration compliance based on what is enabled on the network devices Automated monitoring of service enabled Routing Switching Wireless Service Health for applications Management by Store/Branch/Site
Service Management Enterprise Business Unit Correlated Service Health Correlated Alarms Region Site/Branch Best practice configuration / CVDs One-click configurability Out-of-box monitoring Executive dashboards Applications Users Network Services Devices Wired devices Wireless devices Converged devices Firewalls, Load Balancers Example Service Meta Data Branch Type Business Unit / Region SLA Policy
Virtual Branch
vbranch Components VNF Repository Hosting Platform Provisioning Day 0/Day 1 Day 2 Management NfV repository Application repository Version management Update and upgrade of applications and NfV services ISR with UCS-E UCS C Series Servers OVS Physical Switch Inventory management Orchestration of host platform and VNF deployment Initialization and deployment of VnF Service chaining of VnF VNF Licensing Monitoring of VnF and Host platform Dynamic scaling of VnF by usage Service deployment and Operational SLA management
vbranch Orchestration and Management Platform Vnf and Mgmt Orchestration Branch Design (BSA) Branch Configuration PnP APIC-EM/Prime Infrastructure NfV (CSR, vasa, vwlc, vnam) NFV Platform (VMWare, KVM, OVS) Platform (UCS, UCS-E)
Deployment workflow CSX + PnP + NFVOS Internet APIC EM PnP Service BSA Prime Infrastructure PnP Agent PnP Server IP Available 1 DHCP option 43 and 60 PnP server IP 2 DHCP Request DHCP Response PnP Agent on registers with APIC-EM CSX registered with Orchestrator and PI 4 3 Provision CSR router (vbo API) with running config 5 Provision vasa router (vbo API) 6 Provision vasa router (vbo API) Service chain the VNFs 7
Manageability Branch in a box Service chaining of network services Initialize ASA and WLC with initial configuration Service chain network services Day 0 configuration of network services Install WAAS and ASA from OVA images WAAS vasa Discover and manage ESXi or OSP on UCS-E Discover and manage UCS-E on ISR ESXi or KVM on UCS-E UCS-E Plug and Play to initialize Router 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Key Takeaways Branch Deployment aligned to ITIL process flow Design once and deploy many times with confidence Automation of network deployment reduces operational cost One tool to deploy physical and virtual branch networks
Additional Content
Prime Demo Series Every Week: Same Time. Same Place. Day Prime Demo Series Topic Same Time Same Place Every Monday Cisco Prime LMS Every Tuesday Every Wednesday Cisco Prime Collaboration Cisco Prime NAM & NGA 11:00 AM PST (90 Min) tinyurl.com/primedemo Password: Prime Every Thursday Cisco Prime Infrastructure (incl. Assurance) Format is identical: 20 minutes technical overview 60 minutes demo 10 minutes Q&A
YouTube How To Videos http://www.youtube.com/user/cisco
Product Information Cisco Prime Infrastructure For Your Reference External: http://www.cisco.com/go/primeinfrastructure Cisco NetFlow Generation Appliance (NGA) External: http://www.cisco.com/go/nga Cisco Prime Network Analysis Module (NAM) External: http://www.cisco.com/go/nam Cisco Prime External: http://www.cisco.com/go/prime
Participate in the My Favorite Speaker Contest Promote Your Favorite Speaker and You Could Be a Winner Promote your favorite speaker through Twitter and you could win $200 of Cisco Press products (@CiscoPress) Send a tweet and include Your favorite speaker s Twitter handle <@prajamani> Two hashtags: #CLUS #MyFavoriteSpeaker You can submit an entry for more than one of your favorite speakers Don t forget to follow @CiscoLive and @CiscoPress View the official rules at http://bit.ly/cluswin
Complete Your Online Session Evaluation Give us your feedback to be entered into a Daily Survey Drawing. A daily winner will receive a $750 Amazon gift card. Complete your session surveys though the Cisco Live mobile app or your computer on Cisco Live Connect. Don t forget: Cisco Live sessions will be available for viewing on-demand after the event at CiscoLive.com/Online
Continue Your Education Demos in the Cisco campus Walk-in Self-Paced Labs Table Topics Meet the Engineer 1:1 meetings Related sessions
Thank you