BRKRST-1888 Routing Underlay and NFV Automation with DNA Center Prakash Rajamani, Director, Product Management
Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click Join the Discussion 3. Install Spark or go directly to the space 4. Enter messages/questions in the space cs.co/ciscolivebot#brkpar-4980 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Agenda DNA Center Software Update Routing Underlay Automation NFV Automation Cloud Connect Intent Based Networking Application Policy Conclusion
The Current Enterprise Branch Landscape Multiple Devices Routers, Appliances, Servers Difficult to Manage Device integration and operation Costly to Operate Upgrades, refresh cycles, site visits Virtualization solves all these challenges BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
What does this lead to? BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
* The Cost of Doing Business in the Digital World Why are companies spending so much? 95% 70% 75% Network Changes Performed Manually Policy Violations Due to Human Error OpEx Spent on Network Changes & Troubleshooting *McKinsey study conducted for Cisco in 2016 BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
The Network. Intuitive. Constantly learning, adapting and protecting. DNA Center Policy Automation Analytics L E A R N I N G Informed by Context Visibility into traffic and threat patterns Who, What, When, Where, How Powered by Intent I N T E N T Translate Business Intent to Network Policy Automate the management and provisioning millions of devices instantly S E C U R I T Y BRKRST-1888 C O N T E X T Intent-based Network Infrastructure 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Digital Network Architecture (DNA) DNA Software Capabilities Cloud Service Management Automation Analytics Virtualization DNA-Ready Physical and Virtual infrastructure Automation & Assurance Security & Compliance Insights & Actions Security BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
DNA Solution Cisco Enterprise Portfolio DNA Center: Simple Workflows DESIGN PROVISIO N POLICY ASSURANC E DNA Center Automation Analytics Software-Defined Access (SDA) + Non SDA Policy Routers Switches Wireless AP WLC BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
DNA Center: Design, Policy, Provision, Assurance A better way to manage your network Logical workflow to design, provision, set policy Respond to changes faster Monitor end-to-end network performance Predict and act on problems before they happen Pinpoint problems faster Reduce downtime with an end-to-end view instead of hop by hop Manage hardware and software lifecycles Keep up to date, meet compliance and plan for refresh DNA Center: Design, provision, automate policy and assure services from one place BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Automation Using DNA Center
DNA Automation Principles IT Process Automation Zero Touch Deployment Policy Based Automation BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Getting Started With Automation
Network Changes for Automation Network Change Standard Change: Automated Change Request No Approval Required Fully owned by Network Engg team with minimal to zero downtime Settings Update (Syslog, NTP) Password Update Port Settings, VLAN changes Non-Standard Change Require Approval by Change Board May require service disruption Co-ordination with Application team during change window New device/site deployment Software Update New service/update service BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Network Settings Update (Standard) DHCP Server North America EMEAR DNS Server Use Case: Adding a new Syslog (Ex: Splunk) in the network SoX requirements to update password every 6 months Syslog Server South America Site2 AAA Server Benefits: AAA Server Site1 Africa Syslog Server Repeated manual error prone tasks automated Engg get additional time to focus on design and deployment Standard change automation removes the lead time to make changes BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Network Settings Roll Out New! What s new!! Password roll out with embedded recovery mechanism Scheduler for config update Banner Updates in Settings SWIM Provisioning is now Time Zone Aware BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
IT Process Automation - Software Image Management
Managing Software Lifecycle Use Case: Ensure Consistency of Software for all network devices (by platform type) React to PSIRT and bugs fast Deploy software with confidence Benefits: Golden Image based workflows drive software consistency Pre/Post check ensures that software updates do not have adverse effects on the network Patching provides small updates to react quickly to security fixes BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Core Principles of Software Upgrade 1 2 3 Intent based Network Upgrades Upgrade Pre/Post Checks Patching Support Intent based network upgrades allows for image standardization, much desired by all network admins. Pre and post checks allows network admins more control and visibility over network upgrades Patches are supported in DNAC from intent to prepost checks in same way we manage regular images BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
SWIM and IT Process Automation How to interpret the colors Indicates ITSM Process Steps Actions outside of NMS, mostly manual Steps covered in NMS Tool Steps covered in DNA-C Steps to Update Software Image Update Plan a Image Upgrade Select Golden Image Identify devices to upgrade Create a Change Request Approval of CR Pre-Check validations Distribute Image Activate Image Post Upgrade Validation Close CR Traditional NMS Software Image Update Plan a Image Upgrade Select Golden Image Identify devices to upgrade Create a Change Request Approval of CR Pre-Check validations Distribute Image Activate Image Post Upgrade Validation Close CR DNA Center Based Software Update Plan a Image Upgrade Select Golden Image Identify devices to upgrade Create a Change Request Approval of CR Pre-Check validations Distribute Image Activate Image Post Upgrade Validation Close CR BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
SWIM Demo
IT Process Integration SWIM SWIM ServiceNow Integration BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Zero Touch Provisioning Router
TODAY Router Day-0 Deployment Automation ORDER EQUIPMENT STAGE AT CENTRAL LOCATION TRUCK ROLL WITH TECHNICIAN DEPLOY DEVICE ONSITE Direct Costs Pre-staging & Shipping costs Travel costs Complexity Configuration errors Different products, IOS Releases Security 3 rd party not secure Rogue devices Time/Productivity Manual process Shipping, Storage, Travel Cisco DNA-C ORDER EQUIPMENT Lower deployment costs DNA-C Automation w/ Plug & Play DEPLOY DEVICE ONSITE ~50 % Day0 OPEX Savings* Drop Ship devices Centralized device discovery (DHCP, DNS, Cloud) Non-technical installer at site Template based configurations Secure SUDI Authentication * OPEX savings based on customer data BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Network Deployment using Profile Network Design Before Plan for the network deployment Feature and Capabilities to be enabled based on requirements Topology for network deployment Deployment Standardization During PnP Based Day 0 Deployment Version management of Profile for Day 2 Change Management Profile Based Deployment Network Compliance After Configuration Compliance Validation against Profile Remediation of Configuration to Golden Configuration Simplified Network Deployment Configuration Consistency Integrated IT Process Flows BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Two Steps to Automate Device Deployment DESIGN PROVISION Network Design and Topology Routing Protocols and WAN Connectivity LAN Connectivity Routing Services Ship Devices to Site Design applicable for site Site specific parameters Network Settings IP Addressing Schema Naming Convention Service Provider Configuration BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Profiles for Underlay Automation PROFILE Network Settings PROFILE 1 DESIGN Named Capability Template Programmer CLI 2 PROVISION BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
CLI Template vs Feature Template CLI Template Named Capability CLI Based Config template and Rollback template Syntax Checking/Validation of CLI Provisioning: Form View Cannot push Policy CLI configuration UI flow to create a feature No CLI to configure a feature Leverage Netconf/Yang to configure a feature Example: DMVPN, Routing protocol: BGP/OSPF, VLAN, SSID, AVC BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Profile with Features Templates PROFILE Enterprise SSID Guest SSID RF Profiles NAMED Capability AVC BandSelect FRA Voice Feature Templates (future) WLAN Override Other BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Router Underlay Design and Provisioning Demo
Enterprise NFV
What Is Enterprise NFV? Centralized Orchestration and Management SDN Applications Consistent, trusted network services across all the platforms Virtual network functions (VNFs) Hardware and software independence Virtualization layer Freedom of choice Hardware platform BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Introducing Cisco Enterprise NFV Network Services in Minutes, on Any Platform Cisco DNA Center (DNA Center) Cisco Network Service Orchestrator (NSO) / Virtual Managed Services (VMS) Virtual Router (ISRv,CSR,vEdge) Virtual Firewall (ASAv, NGFWv) Virtual WAN Optimization (vwaas) Virtual Wireless LAN Controller (vwlc) Third-Party VNFs Network Functions Virtualization Infrastructure Software (NFVIS) Cisco 4000 Series ISR + UCS E-Series Enterprise Network Compute System (ENCS) Cisco UCS C-Series BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Why Virtualization for the Network? Mobility IoT Analytics Cloud Mobile traffic will Exceed wired traffic by 2017 IoT Devices will triple by 2020 AND 76% of companies planning to or investing in Big Data Deploy new capabilities faster Lower operating costs 80% of organizations will primarily use SaaS by 2018 BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
ENCS 5000 Series - Chassis Options What makes this possible ENCS5104 4-Core ENCS5406 6-Core ENCS5408 8-Core ENCS5412 12-Core ENCS 5104 ENCS 5406 ENCS 5408 ENCS 5412 CPU 4-core, 3.4 GHz 6-core, 1.9GHz 8-core, 2.0GHz 12-core, 1.5GHz PoE No No 200W 200W Capacity Guidance ISRv + 1 VNF ISRv + 2 VNFs ISRv + 3 VNFs ISRv + 5 VNFs BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Single slide on NFVIS BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Demo DNA Center
Cloud Connect
Policy Based Automation
Policy Based Automation Access Policy Authentication and Authorization Group Assignment Based on Authentication methods Access Control Policy Who can access what Rules for x-group access Permit group to app Permit group to group Application Policy Traffic treatment QoS for Application Path Optimization Application compression Application caching Transforming network operations through intent expressed as policy BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Key Takeaways BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Cisco Spark How Questions? Use Cisco Spark to communicate with the speaker after the session 1. Find this session in the Cisco Live Mobile App 2. Click Join the Discussion 3. Install Spark or go directly to the space 4. Enter messages/questions in the space cs.co/ciscolivebot#brkrst-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Please complete your Online Session Evaluations after each session Complete 4 Session Evaluations & the Overall Conference Evaluation (available from Thursday) to receive your Cisco Live T-shirt All surveys can be completed via the Cisco Live Mobile App or the Communication Stations Complete Your Online Session Evaluation Don t forget: Cisco Live sessions will be available for viewing on-demand after the event at www.ciscolive.com/global/on-demand-library/. 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Continue Your Education Demos in the Cisco campus Walk-in Self-Paced Labs Tech Circle Meet the Engineer 1:1 meetings Related sessions BRKRST-1888 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Thank you