Resilient WAN and Security for Distributed Networks with Cisco Meraki MX

Similar documents
We re ready. Are you?

Ciprian Stroe Senior Presales Consultant, CCIE# Cisco and/or its affiliates. All rights reserved.

Cisco Meraki Cloud Managed IT Solution Derrick Phua. May 12, 2017

JURUMANI MERAKI CLOUD MANAGED SECURITY & SD-WAN

MX Cloud Managed Security Appliance Series

Peter Henry Andersen Cisco SE Ib Hansen Cisco SE Tech Update 04 Maj Cisco and/or its affiliates. All rights reserved.

MX Cloud Managed Security Appliance Series

Intelligent WAN Sumanth Kakaraparthi Principal Product Manager PSOCRS-2010

Cloud-Managed Security for Distributed Networks with Cisco Meraki MX

Cisco Meraki Cloud-Managed Networking. George Carlan

Meraki MX Family Cloud Managed Security Appliances

Introduction to Cloud Networking. Company and Product Overview

Meraki MX Family Cloud Managed Security Appliances

MX Cloud Managed Security Appliance Series

Meraki 2014 Solution Brochure

Prepare Your Network for BYOD. Meraki Webinar Series

Meraki Solution Brochure

MR Cloud Managed Wireless Access Points

Meraki 2018 Solution Brochure

MX Sizing Guide. 4Gon Tel: +44 (0) Fax: +44 (0)

VeloCloud Cloud-Delivered WAN Fast. Simple. Secure. KUHN CONSULTING GmbH

Cisco Comstor

MR Cloud Managed Wireless Access Points

Deploying Intrusion Prevention Systems

MR Cloud Managed Wireless Access Points

Meraki Z-Series Cloud Managed Teleworker Gateway

Meraki MX Cloud Managed Security & SD-WAN

Cisco Meraki MX products come in 6 models. The chart below outlines MX hardware properties for each model:

Introduction. Trusted by Thousands of Customers Worldwide. Recognized for Innovation

Cloud Managed Networking with Meraki

Simplifying the Branch Network

Meraki MX Family. Overview

Cisco Meraki Overview. March 21, 2017

Network Automation and Branch Agility The Network Helps Enable Digital Business. Rajinder Singh Product Sales Specialist June 2016

Virtualized Video Processing: Video Infrastructure Transformation Yoav Schreiber, Product Marketing Manager, Service Provider Video BRKSPV-1112

Cisco Meraki solution overview Cisco and/or its affiliates. All rights reserved.

Meraki MX CLOUD MANAGED SECURITY & SD-WAN

DMVPN for R&S CCIE Candidates Johnny Bass CCIE #6458

Cloud-Managed Wireless Access Points

DMVPN for R&S CCIE Candidates

Cisco Meraki Wireless Solution Comparison

Delivering the Wireless Software-Defined Branch

NETWORKING &SECURITY SOLUTIONSPORTFOLIO

Cloud Managed Security with Meraki MX

Cloud Mobility: Meraki Wireless & EMM

Cisco SD-WAN (Viptela) Migration, QoS and Advanced Policies Hands-on Lab

WHITE PAPER ARUBA SD-BRANCH OVERVIEW

Cisco Tetration Analytics

Our Virtual Intelligent Network Overlay (VINO) solutions bring next-generation performance and efficiency to business networks throughout North

Next generation branch with SD-WAN and NFV

Cisco SD-WAN. Intent-based networking for the branch and WAN. Carlos Infante PSS EN Spain March 2018

Meraki's Cloud-Managed Networking Solution

Cato Cloud. Software-defined and cloud-based secure enterprise network. Solution Brief

Key Security Measures to Enable Next-Generation Data Center Transformation

Connected Experiences

Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service

Cloud-Ready WAN For IAAS & SaaS With Cisco s Next- Gen SD-WAN

Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service

Beyond the network Meraki MC & MV. October 26, 2016

Introducing Avaya SDN Fx with FatPipe Networks Next Generation SD-WAN

Evolution of Data Center Security Automated Security for Today s Dynamic Data Centers

Benefits of SDN Modeling and Analytics tool for complex Service Provider Network

SD-WAN Deployment Guide (CVD)

Hybrid Cloud with Intercloud Fabric Percy Wadia, Manager, Product Management PSOCLD-1001

Designing Network Encryption for the Future Emily McAdams Security Engagement Manager, Security & Trust Organization BRKSEC-2015

Cisco Meraki Cloud Managed Networking

Networking Drivers & Trends

Meraki MS22 / MS42 Cloud Managed Gigabit PoE Switch Family

Distributed Branch Deployment Costs

Wireless LAN Solutions

Passit4Sure (50Q) Cisco Advanced Security Architecture for System Engineers

ISG-600 Cloud Gateway

Cisco Unified Computing System

MR74. Datasheet MR74. Dual-band 2x2 MIMO ac Wave 2 access point with separate radios dedicated to security, RF Management, and Bluetooth

BYOD the HP Way: Secure, Device-Agnostic Network Access Management Jochen Fischer Solution Architect (MASE) September 2013

Meraki vs. Ruckus: The Reality Check

Introduction to Cisco Virtual Topology System DP Ayyadevara, Product Manager, Cloud Virtualization Cisco PSOSDN-1050

CCNA Routing and Switching Study Guide Chapters 7 & 21: Wide Area Networks

SteelConnect. The Future of Networking is here. It s Application- Defined for the Cloud Era. SD-WAN Cloud Networks Branch LAN/WLAN

SD-Access Wireless: why would you care?

Getting the Most out of your BYOD Investment A Deep Dive of ISE BYOD Policy

Borderless Networks. Tom Schepers, Director Systems Engineering

SEVONE END USER EXPERIENCE

CCIE Collaboration Lab

Cato Networks. Network Security as a Service

Design and Deployment of SourceFire NGIPS and NGFWL

Cisco Meraki Licensing

Cisco Meraki Cisco and/or its affiliates. All rights reserved.

Cloud-Enable Your District s Network For Digital Learning

Partner Onboarding Guide

Ipswitch: The New way of Network Monitoring and how to provide managed services to its customers

Cloud Controlled Network for Service Providers

Cisco SD-WAN and DNA-C

IWAN APIC-EM Application Cisco Intelligent WAN

Juniper SD-WAN Alexandre Cezar Consulting Systems Engineer, Security/Cloud

APIC-EM / EasyQoS - End to End Orchestration of QoS in Enterprise Networks

From Zero Touch Provisioning to Secure Business Intent

UCS Management Deep Dive

Business Strategy Theatre

VPN Cloud. Mako s SD-WAN Technology

Transcription:

Resilient WAN and Security for Distributed Networks with Cisco Meraki MX Daghan Altas, Director of Product Management BRKSEC-2900

Agenda Problem Cisco CNG Live network creation demo (45m) Product Brief Q&A

How can I keep my PCI traffic isolated from guest traffic? What if my Internet goes down? I pay too much for MPLS! What happens if I discover a threat? What if my firewall dies? I need a solution that just works! BYOM! How do I discover a threat? What about DR? We have a small team responsible for 1000 store networks

WAN access needs to change Cost Agility Security Bandwidth costs MPLS costs Increased bandwidth demands High cost and complexity of network management: Truck roles Zero local IT Difficulty with troubleshooting CPE complexity Management Configuration New WAN architecture demands Agility Migration to Metro-E Adoption of Internet (and DIA) Service creation Intelligent QoS Security is more important than ever: Direct Internet Access to SaaS Guest wireless access BYOD APT protection

Secure and reliable networks that are easy to manage

Cisco CNG

Cloud-managed networking Cisco Meraki MR Wireless LAN Cisco Meraki MX Security Appliances Cisco Meraki MS Ethernet Switches Cisco Meraki SM Mobile Device Management

Cloud-managed networking architecture Network endpoints securely connected to the cloud Cloud-hosted centralized management platform Intuitive browser-based dashboard

A complete Unified Threat Management solution Security NG Firewall, Client VPN, Site to Site VPN, IPS, Geo IP Networking NAT/DHCP, 3G/4G failover, Intelligent WAN (IWAN) Application Control Web caching, Traffic Shaping, Content Filtering 7 models scaling from teleworker and small branch to campus / datacenter

Target customers

Why choose the Cisco Meraki MX? Intuitive centralized management No training, no command line Templates to configure at-scale Packet capture, built-in tools and diagnostics Designed for distributed enterprises Single pane of glass visibility Zero-touch provisioning Seamless updates from the cloud Site-to-site IPSec VPN in 3 clicks Industry-leading visibility Fingerprints users, applications, and devices Network-wide monitoring and alerts Full stack: APs, switches, Security, MDM

Ironclad security Best IPS SOURCEfire IDS / IPS, updated every day Content Filtering Geo-based security AV / antiphishing PCI compliance 4+ billions URLS, updated in real-time Block attackers from rogue countries Kaspersky AV, updated every hour PCI L1 certified cloud-based management

Rock-solid UTM for multi-site organizations Largest diversified provider of postacute care in USA 2000+ locations in 46 states, 75,000+ employees Why Cisco Meraki MX? Lean IT staff; needed centralized remote management for easily-deployed UTMs (zero-touch) Intuitive site-to-site VPN HIPAA compliant Needed single-box solution (MX60W) for security and wireless at rehabilitation centers Guest hotspots provided with MX60W Wi-Fi and 3G/4G uplinks

Penn Mutual saves $858K Projects / Pain Points: Implement a BYOD platform at 50 remote sites Managed Service Provider & MPLS costs Solution: Complete Meraki Stack: MR, MS, MX Phase off MPLS to Broadband Business Outcomes: Reduced Telco Spend by 40% Single platform in branch improved IT efficiency

Demo

New Features: IWAN

What is IWAN? Intelligent WAN (IWAN) is a collection of Cisco technologies and products that enable transport independence, intelligent path control, application optimization, and secure connectivity for multi-site deployments. Need screenshot Transport Independence Application Optimization Intelligent Path Control Secure Connectivity IPsec overlay (Auto VPN) Scalable (cloud architecture) Traffic distribution over multiple pathways (Internet, cellular, MPLS) App visibility & control (Meraki dashboard, group-based policies, traffic analytics) Application QoS & bandwidth optimization (Traffic shaping) Uplink chosen by link latency, data loss, etc. (PfR, aka performance-based routing) Uplink assigned by traffic protocol, subnet, source, destination, etc. (PbR, aka policy-based routing) Intuitive, automatic, scalable VPN solution to connect remote branch sites (Auto VPN)

New IWAN features for the Meraki MX Dual-active path: Active-active VPN - dual internet Active-active Internet-VPN & MPLS 3G/4G for backup only (no active/active Performance-based routing: Automatic failover based on loss, latency and jitter Ensures the best uplink is used based on performance WAN 1 Secure VPN tunnel (active) Latency / loss > threshold WAN 2 Secure VPN tunnel (active) Latency / loss < threshold Policy-based routing: Dual active VPN uplinks, with automatic failover Allows uplinks to be intelligently utilized with traffic-steering based on protocol, subnet, source, destination, etc. Data

Setting up dual-dc VPN network

End goal: DC-to-DC failover and load-balancing Active VPN Tunnel Failover VPN Tunnel Internet Active VPN Tunnel Failover VPN Tunnel HA PAIR DC1 DC2 HA PAIR Branches connected to DC1 Branches connected to DC2

Demo: Resilient WAN and security under 30 min Internet 10..0.10 10.2.0.10 DC1: 10.0.0.0/16 DR: 10.0.0.0/16 Template: West Template: East Branch1: 10.100.0.0/24 HA within DC DC to DC failover WAN link failover (4G) Automated VPN between sites Full UTM features IPS Content Filtering AV L7 firewall rules

Demo: Resilient WAN and security under 30 min Internet 10.2.0.1/24 10.2.0.1/24 10.2.0.2/24 10.2.0.2/24 DC1: 10.0.0.0/16 DR: 10.0.0.0/16 Template: West Template: East Branch1: 10.100.0.0/24

Product Brief

MX64 / MX64W Speed Industry s first 802.11ac UTM Dual radio ~3X speed of 11n wireless 2-3X faster than MX60 / MX60W Security UTM provides one-stop security IPS, content filtering, malware / antiphishing Seamless, automatic updates PCI 3.0-certified cloud backend SKU List Price MX64-HW $595 LIC-MX64-ENT-3Y $600 LIC-MX64-SEC-3Y $1200 MX64W-HW $945 LIC-MX64W-ENT-3Y $650 LIC-MX64W-SEC-3Y $1300

Choosing the right MX for your environment MX64/64W Where Small branches (~25 users) Features Wireless (MX60W) Throughput 100 Mbps MX80 Mid-size branches (~100 users) Mid-size branches (~500 users) Large Web cache (1TB) SFP ports Large Web cache (1TB) 250 Mbps 500 Mbps Z1 For teleworkers (1-5 users) Dual-radio wireless MX100 MX400 Large branch /campus (~2,000 users) Modular interface Large Web cache (1TB) 1 Gbps FW throughput: 50 Mbps MX600 Large branch /campus (~10,000 users) Modular interface Large Web cache (4TB) 2 Gbps All devices support 3G/4G

MX Security Appliances: Licenses Enterprise License Advanced Security License Stateful firewall Site to site VPN Branch routing Intelligent WAN (IWAN) Application control Web caching All enterprise features, plus Content filtering (with Google SafeSearch) Kaspersky Anti-Virus and Anti-Phishing SourceFire IPS / IDS Geo-based firewall rules ` Client VPN

MX Sizing Guide

Q & A

Free evaluations available Try Cisco Meraki with no risk or commitment Complimentary technical assistance available Start trial at meraki.cisco.com/eval

Participate in the My Favorite Speaker Contest Promote Your Favorite Speaker and You Could Be a Winner Promote your favorite speaker through Twitter and you could win $200 of Cisco Press products (@CiscoPress) Send a tweet and include Your favorite speaker s Twitter handle @DaghanAltas Two hashtags: #CLUS #MyFavoriteSpeaker You can submit an entry for more than one of your favorite speakers Don t forget to follow @CiscoLive and @CiscoPress View the official rules at http://bit.ly/cluswin

Complete Your Online Session Evaluation Give us your feedback to be entered into a Daily Survey Drawing. A daily winner will receive a $750 Amazon gift card. Complete your session surveys though the Cisco Live mobile app or your computer on Cisco Live Connect. Don t forget: Cisco Live sessions will be available for viewing on-demand after the event at CiscoLive.com/Online

Continue Your Education Demos in the Cisco campus Walk-in Self-Paced Labs Table Topics Meet the Engineer 1:1 meetings Related sessions

Thank you