Enterprise Networks Architecture Krish Venkataraman Technical Marketing Engineer, Enterprise Networking Group
Agenda Enterprise Networks Trends and Challenges Redefining Access - Unified Access Application & Services Intelligence IWAN Mobility Experience - CMX IT Simplicity & Programmability APIC-EM Key Takeaways Additional Resources 3
Collaboration Mobility THE NETWORK Cloud SECURITY IT PRODUCTIVITY
We Are Entering the Age of the Internet of Everything The Network Is the Platform to Connect the Previously Unconnected Device Growth of things are unconnected BYOD Traffic Growth Simple Intelligent Transition to Cloud* Mobility of Traffic (Video over Mobile Devices)* Mobile and Cloud Programmable *Cisco VNI Study 2012
Access Transformation 5+ years ago Today / Soon x2 x10 x15 x15 Not connected x2 x4
WAN Transformation 5+ Years Ago Today / Soon DC applications Internet edge SaaS Private Cloud IaaS Internet MPLS or other private MPLS MPLS Hybrid WAN MPLS Internet Branch applications Guest WiFi Video VDI Direct Internet Access
Business Transformation EN Infrastructure transformation is necessary to meet it Business Before Business Now Applications: Delivered to Desktops e.g. CRM, Finance Apps: Delivered from Cloud to Any Device, Business and Personal apps, High Video Mix Devices: Mostly PCs, Workstations and Desk Phones Devices: Smartphones, Tablets, Video End Points and Phones, Scanners, Sensors etc. Users: Tied to Single Physical Location, Only IT Provided Applications Users: Mobile, Choice of non-it Cloud Based Apps Analytics and Intelligence: Determined by Workflow, Manual Analytics and Intelligence: Real Time on Any Device, Any Location
EN Infrastructure Transformation Infrastructure Before Infrastructure Now Mostly Wired Connections: More Switches, PoE Wired Connections: Fewer High Performance and Scalable Switches, PoE+/UPOE Wireless in Infancy: Few APs, Spotty Wi-Fi, No Mobility Wireless as Primary Access: More APs, 802.11ac HDX Wi-Fi, Mobility & Guest Access Basic Security: Perimeter-based, Single dimension Advanced Security : Context Based, Centralized Policy, Distributed Enforcement, Threat Defense Simple: Single type of User, Standard business applications Agile: Multiple User and Application types, Automated and Programmable, Resilient
GOVERNMENT HEALTHCARE MANUFACTURING EDUCATION FINANCIAL Real-Time Response Better Diagnostics Efficient Operations Learning Options Low-Latency Trading
IT Top of Mind 1 2 3 How do I manage complexity to reduce costs? Can I offer secure, mission critical & agile IT services? Am I investing in an architecture futureproofed for scale? Is My Network Ready?
Cisco Enterprise Network Vision Connecting Clouds Simple Secure Connecting People Reduced TCO Connecting Things Cisco ONE Enterprise Networks Architecture
13 Unified Access - UA
Unified Access Deployment Modes Wired Traditional Access Instant Access Wireless Centralized Flex Autonomous Wired-wireless Converged Access Simple Secure Reduced TCO One pane of glass Wired Wireless Single point to Define Policy Multiple Policy enforcement points Cisco ONE Enterprise Networks Architecture
Unified Access: Campus Deployment Models One Cisco Prime Management Infrastructure Cisco ISE One Policy Centralized Wireless Distributed Wireless Si Si VSS Si Si VSS MA MA MA MA MA MA MA MA MA MA MA MA MA MA MA MA MA MA Traditional Access Instant Access Converged Access
Unified Access: Wireless Deployment Options Cisco Cloud Networking Prime Cisco Unified Access: 1 Architecture, 4 Deployment Modes ISE Dashboard WAN Intranet AUTONOMOUS CLOUD MANAGED FLEX CONNECT CENTRALIZED CONVERGED Common OS Lean IT Mid-Market / Distributed Enterprise MR Access Points MS switches MX security Dashboard Intended for static installations SP Hotspots Aironet Access Points 11ac: 3700 / 2700 11n: 1600 / 700 Catalyst Switches 3850 / 3650 2960-X Controllers N / A Data center hosted controller Distributed enterprises Aironet Access Points 11ac: 3700 / 2700 11n: 1600 / 700 Catalyst Switches 6800/4500/3850/3650 4500-X / 2960-X Controllers 8510 / 7510/vWLC Premise-based controller Traditional Overlay Model Highly Scalable Aironet Access Points 11ac: 3700 / 2700 11n: 1600 / 700 Catalyst Switches 6800/4500/3850/3650 4500-X / 2960-X Controllers 8510 / 5760 / 5508 / WiSM2 /2504 / Common OS Consistent Wired/Wireless Highest performance Aironet Access Points 11ac: 3700 / 2700 11n: 1600 / 700 Catalyst Switches 4500*/3850/3650 Controllers Integrated 5760 external MC * Roadmap
Cisco Catalyst Switches from Access to Backbone Complete portfolio refresh in 2013! Catalyst 2960-X/XR Catalyst 3850/3650 Catalyst 4500E with SUP8-E Catalyst 6800 Smart, simple, green & secure wired access Advanced fixed switching with Unified Access Flexible, scalable, feature-rich modular access Enterprise backbone optimized for 10/40/100G LOWER TCO END-TO-END SECURITY APPLICATION VISIBILITY INVESTMENT PROTECTION PERFORMANCE & SCALE
F eature s Catalyst Access Portfolio Essential connectivity to Unified Access for next-generation workspaces UNIFIED WORKSPACE BYOD Video Mobility C o n v e r g e d W i r e d / W i r e l e s s A c c e s s L e a d S t a c k a b l e S w i t c h L e a d M o d u l a r S w i t c h Secure, reliable access Low TCO & energy-efficient Competitive Feature Set at Compelling Prices S cale Upto 480G Stacking Upto 4x10G Uplinks Stackpower with 3850 Supports up to 50AP s Scale and Performance 928G Backplane 8 Modular 1/10G Uplinks Supports 50AP s*
Features Catalyst Core and Aggregation Portfolio Unmatched scale and features for the enterprise backbone Comprehensive Borderless Feature Set Highest Performance and Scalability Lower TCO Fixed Space Constrained 10G Aggregation Industry's Most Scalable and Feature Rich Extensible Fixed Campus Backbone Platform Baseline Backbone Features Collapsed Access Dense 1 RU 1/10GE Aggregation Scale Radically Improved 10G Economics Competitive Feature Set at Compelling Prices Industry-Leading Campus Backbone Platform Lead Platform to Enable Video, Cloud, and BYOD
WLAN Controller Branch & Campus Industry s broadest portfolio Catalyst 3850 Catalyst 4500-E Sup8E* Large Campus 5508 WISM2 5760 Service Provider 8500 *Q4 CY14 1-50 AP/switch per stack (Directly connected APs) 2000 clients/stack 40 Gbps/switch 1 to 50 APs 2000 clients 20 Gbps 12 to 500 APs 7000 clients 8 Gbps 100 to 1000 APs 15,000 clients 20 Gbps 25 to 1000 APs 12,000 clients 60 Gbps 300 to 6000 APs 64,000 clients 10 Gbps Small Campus / Branch (Controller On-Premise) 2500 Virtual WLC e.g. UCS-E on ISR G2 Catalyst 3650 Catalyst 3850 Branch (Controller in DC) Virtual Controller Flex 7500 5 to 75 APs 1000 clients 1 Gbps 5 to 200 APs 3000 clients 500 Mbps 1-25 APs per switch/stack (Directly connected APs) 1000 clients per stack 40 Gbps per switch 1-50 APs per switch/stack (Directly connected APs) 2000 clients per stack 40 Gbps per switch 5 to 200 APs 3000 clients 500 Mbps 300 to 6000 APs 64,000 clients 1 Gbps central
Cisco Aironet Indoor Access Points Sub 1K Family Enterprise Class 1K Family Mission Critical 2K Family Best in Class 3K Family AP-3600 AP-3700 AP-702 AP-1600 AP-2700 OEAP-600 AP-3500 Targeted Enterprise Mission Critical Best In Class
Intelligent WAN - IWAN
Branch is More Relevant than Ever Where You Engage Customers Source of Business Intelligence Up to 80% of Your Employees To Grow Your Business & Innovate Your Remotes Sites Must Keep Pace with HQ
Emerging Branch Demands Change of Application landscape Applications are Moving to the Data Center and Cloud Cloud Branch Internet Edge Is Moving to the Branch Pressures on the WAN Data Centers Cloud of CIOs Expect to Operate via the Cloud by 2015 Mobility More Mobile Data Traffic by 2015 Fat Apps Of Mobile Traffic will be Video
Why Move to Internet as WAN Low Cost Alternative of Organizations Are Planning to Transition to Internet Connections 1. Internet Transit Pricing based on surveys and informal data collection primarily from Internet Operations Forums street pricing estimates 2. Packet delivery based on 15 years of ping data from PingER for WORLD (global server sample) f fromedu.stanford.slac in California Source: William Norton (DrPeering.net); Stanford ping end-to-end reporting (PingER)
Internet becoming an Extension of Enterprise WAN Commodity Transports Viable Now Dramatic Bandwidth, Price Performance Benefits Higher Network Availability Improved Performance Over Internet
Cisco Intelligent WAN (IWAN) Uncompromised Experience Over Any Connection AVC Internet 3G/4G-LTE Branch MPLS WAAS PfR Data Center Transport Independent Secure Connectivity Intelligent Path Control Application Optimization Provider Flexibility Lower Cost Direct, Scalable Security Protect Resources Dynamic Path Selection High Quality Experience App Acceleration Minimize Downtime 27
Intelligent WAN Deployment Models Dual MPLS Hybrid Dual Internet Public Public Enterprise Internet MPLS MPLS Internet MPLS Internet Internet Highest Service Level (SLA) Enable SaaS and/or high BW apps Best price/performance x Inflexible for new services Balanced Service Level (SLA) IT Managed Service Levels x Expensive Up to 99.999% Reliability Up to 99.999% Reliability Consistent VPN Overlay Enables Security Across Transition 28
Cisco ISR-AX Built on the Cisco ISR G2 Optimal Application Experience Anywhere IT Simplicity through Unified Services Priced for Wide-Scale Adoption Cisco 3900-AX Cisco 2900-AX Cisco 1900-AX
Cisco ISR 4451-AX and ASR1000-AX Optimal Application Experience from Anywhere ISR 4451-AX ASR 1000-AX Services When and Where You Need Them One Platform, Many Services, No Appliances Gigabit Speed with Services, LAN-like Experience
Connected Mobility Experience - CMX
Toward A More Mobile Workplace Mobility Increase Driving Wi-Fi Organizations Looking to Monetize Wi-Fi Wi-Fi as a Platform to Deliver Services More than 10 billion by 2017 1 1 Cisco 2013 Visual Networking Index (VNI) Report
To Take Advantage Of These New Opportunities Requires Detecting and Locating Devices to Provide: Enhanced Customer Engagement Context-Aware Marketing Opportunities On-Premises Customer Visibility Engagement Services Analytics Increased Revenue Opportunities
Cisco Connected Mobile Experience (CMX) DETECT CONNECT ENGAGE GUEST PRESENCE Mobile device detected GUEST ACCESS Seamless, secure Wi-Fi on-boarding Cisco Connected Mobile Experience GUEST EXPERIENCE Local services
Apply Location-Based Services To Your Business Unlocking Unprecedented Business Value Indoor GPS Targeted Messaging Location-Specific On-Boarding System Integration Analytics Turn-by-turn directions to any location within a venue Targeted personalized messaging based on customer location Location-based push notifications Targeted information for guests based on their location (captive portal) Automatically connect to the dedicated wireless SSID network Connect with other systems, such as registration, property management, product databases, or location-based services Gain insight into online, onsite, and social customer trends Analyze aggregate locations, URLs, and demographics
CMX Industry Specific Solutions RETAIL HOSPITALITY TRAVEL HEALTHCARE EDUCATION Consumers Guests Passengers Patients Students Location- and dwell-time-based notifications Personalized promotions Customer analytics Maps with featured attractions Personalized thirdparty advertising Nearby amenities Wait times and gate directions Improved passenger traffic flow Third-party advertising Way finding patient apps Simplified onboarding Nearby services discovery Safety and security Campus map and directions Guided tours Stadiums 36
Connected Mobile Experience Solution Architecture Mobile Application Services Guest Access Device- Based Services Browser- Based Services Location- Enabled Apps Onsite and Offsite Analytics Social Analytics Marketing Tools CISCO AND ECOSYSTEM PARTNERS APPS AND SERVICES Ads and Offers Mobile Network Services Presence SOAP/XML REST SDK API Service Discovery Location Engine Wireless Security MOBILE SERVICES Visibility Control Optimization Security Analytics Engine Application Engine Network Element Layer One Policy One Management UNIFIED ACCESS One Network
Cisco Mobility Services Engine Choose a Physical Appliance or a Virtual Appliance Cisco Mobility Services Engine Both platforms support Base Location, Connected Mobile Experiences (CMX), and wips Cisco MSE Virtual Appliance tracks up to 50,000 devices Cisco 3355 MSE tracks up to 25,000 devices MSE provides representational state transfer (REST) APIs for location-enabled application development 38
ANALYTICS DATA How CMX Works Built on Cisco Unified Access Access Points Controller (Virtual/Physical) MSE (Virtual/Physical) Depending on Application Layer DEVICE-BASED DISCOVERY LOCATION DATA APPLICATION DATA Mobile Application Server Analytics UI
IT Simplicity & Programmability (APIC-EM)
We Are Entering the Age of the Internet of Everything The Network Is the Platform to Connect the Previously Unconnected Device Growth of things are unconnected BYOD Traffic Growth Simple Intelligent Transition to Cloud* Mobility of Traffic (Video over Mobile Devices)* Mobile and Cloud Programmable *Cisco VNI Study 2012
IT agility at the speed of business Open Simplicity Innovation Manual Automated Closed Systems Open and Programmable Box-Centric Network-Wide Network Data Business Intelligence Provision in weeks Hours and Minutes New Installations Existing + New Installations 42
What is APIC EM? Challenges Solution APIC-EM: Simple & Programmable IT Micro-transactions Decentralization of IT Internet of Things 43
APIC-EM: High level architecture Cisco and Third Party Applications Exposes Network Intelligence For Business Innovation REST API Cisco ONE APIC - Enterprise Module Network Info Database Policy Infrastructure Automation CLI, OpenFlow, OnePK API Network Devices Catalyst, ASR, ISR Abstracts Network Devices to Mask Complexity Treat Network as a System
EN Architecture Key Takeaways
Key Takeaways Unified Access (UA) UA architecture enables Video, Collaboration, Security and simplifies Enterprise Network deployments Traditional, Converged & Instant Access Intelligent WAN (IWAN) Uncompromising user experience Transport independence, Secure Connectivity, Intelligent path control & Application optimization
Key Takeaways Connected Mobility Experience (CMX) Connect and engage with your users and guests - Powerful analytics, Social connector (FB), Location based onboarding, Indoor GPS & Targeted messaging! APIC-EM Network abstraction and standards based support. Simplifying and automating Network tasks with multiple north & south bound interfaces!
Complete Your Online Session Evaluation Give us your feedback and you could win fabulous prizes. Winners announced daily. Complete your session evaluation through the Cisco Live mobile app or visit one of the interactive kiosks located throughout the convention center. Don t forget: Cisco Live sessions will be available for viewing on-demand after the event at CiscoLive.com/Online 48
Additional Learning Opportunities Demos in World of Solutions Enterprise Networking booths Walk-in Self-Paced Labs Table Topics Meet the Engineer 1:1 meetings 49