SlideShare a Scribd company logo
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Software Defined Access (SDA)
Transformational Approach to Network Design & Provisioning
Doan Nguyen Lam
Cisco Solution Engineer, Cisco Systems
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
What is Network about?
Today...In the past...
Voice
Video
Data
Mobility
Security
Cloud
IOT
Source: google.de images
Source: google.de images
What really matters !!!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Challenge.
“I want to design and deploy a network.”
Platform choices
Best practices
Manageable
Design options
On time
Future ready
Within budget
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Typical Traditional Campus
Data
Centre
WAN/BRANCH
Access
Points
Core
Switches
Aggregation
Switches
Access
Switches
WLC
ETHERCHANNEL
HSRP SPANNING TREECLI
L2/L3
AVC
VLANS
ACL
802.1x
FNF
Very powerful and feature
rich but:
- Complex to operate
- Difficult to scale
- Difficult to secure
- Inflexible and closed
architecture
- And you manage it all
with CLI…
Internet
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
How we build Traditional Network
Box by Box
Manual | Error Prone
ip domain-name cisco.local
no ip http server
ip http secure-server
ip ssh version 2
ip scp server enable
line vty 0 15
transport input ssh
transport preferred none
Manually
Repetitive Steps
CLI
Skill | Time | Effort
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Key Challenges for Traditional Networks
Difficult to Segment
Ever increasing number of
users and endpoint types
Ever increasing number of
VLANs and IP Subnets
Complex to Manage
Multiple steps,
user credentials, complex
interactions
Multiple touch-points
Slower Issue Resolution
Separate user policies for
wired and wireless networks
Unable to find users
when troubleshooting
Traditional Networks Cannot Keep Up!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco’s Intent-based Networking
Intent Context
Security
Learning
Network Infrastructure
DNA Center
AnalyticsPolicy Automation
Switching Routers Wireless
Powered by Intent.
Informed by Context.
The Network. Intuitive.
7
CISCO CONNECT 2018 . IT’S ALL YOU
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Intent-based Networking Model – Industry Approach
Activation
Physical and Virtual Infrastructure
Translation
Assurance
Orchestrate policies
& configure systems
Capture business intent,
translate to policies, and
check integrity Continuous verification,
insights & visibility, and
corrective actions
Cisco DNA
Intent-based Networking
Industry Initiative
8
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Automated
Network Fabric
Single Fabric for Wired & Wireless
with Workflow-based Automation
Insights
& Telemetry
Analytics and insights into
user and application behavior
Identity-based
Policy & Segmentation
Decoupled security policy definition
from VLAN and IP Address
Software-Defined Access
Networking at the speed of Software!
DNA Center
AnalyticsPolicy Automation
IoT Network Employee Network
SDA-Extension User Mobility
Policy stays with user
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
What is SD-Access?
Campus Fabric + DNA Center (Automation & Assurance)
APIC-EM
1.X
Campus
Fabric
ISE PI
Automation
Policy Assurance
DNA Center
B
C
B
 Campus Fabric
An Overlay network is a logical
topology used to virtually connect
devices
Separated management systems
 SD-Access
GUI approach provides
automation & assurance of all
Fabric configuration,
management and group-based
policy
DNA Center integrates multiple
systems, to orchestrate your
LAN, Wireless LAN and WAN
access
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Software-Defined Access
AssuranceAutomation Policy
Routers Switches Wireless AP WLC
DNA Center
DESIGN PROVISION POLICY ASSURANCE
DNA Center:
Simple Workflows
Solution Components
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
You Need a Network that Drives your Digital Business
With SDA Cisco Rewriting the Networking
Playbook
Hardware Centric Software Driven
Manual (eg CLI) Automated
Silo’ed Security Integrated Security
Network Monitoring Analytics and Insights
Historicaly Digital-Ready Network
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Network Design & Build Work Flow
Assure
Assure
Design
Network Hierarchy
Network Settings
Image Management
Network Profiles
Policy
Virtual Networks
Access Control
Application Priority
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Network Design & Build Work Flow
Assure
Provision Assure
Provision
Device Onboarding
Host Onboarding
Device Inventory
Fabric Administration
Assurance
Network Health Score
Client 360
Device 360
Application 360
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Syslog
Server
SDA Design in DNA Center – Global Setup
AAA
Server
Site1
North
America
South
America
Site2
Africa
EMEAR
AAA
Server
DNS
Server
Syslog
Server
DHCP
Server
• Ability to Define
Global Settings
once and
replicate to all
sites/devices
• Automated
Provisioning
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
L2 Switch
L3 Switch
Trunks
Trunk
BYOD Employee Contractor
One SSID
Production
Servers
AAA
DHCP
AD
WLAN
Developer
Servers
LAN Core
Multiple Steps and
Touch Points
1. Define Groups in AD
2. Define Policies
 VLAN/subnet based
3. Implement VLANs/Subnets
 Create VLANs
 Define DHCP scope
 Create subnets and L3 interfaces
 Routing for new subnets
 Map SSID to Interface/VLAN
4. Implement Policy
 Define ACLs
 Apply ACLs
5. Many different User Interfaces
AAA WLC Devices CLI
….
What if You Need to Add Another Group & Policy?
Network Segmentation Policy Rollout Today
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
How SDA Simplifies Network Segmentation
Access Layer
Enterprise
Backbone
Voice
VLAN
Voice
Data
VLAN
Employee
Aggregation Layer
Supplier
Guest
VLAN
BYOD
BYOD
VLAN
Non-Compliant
Quarantine
VLAN
VLAN
Address
DHCP Scope
Redundancy
Routing
Static ACL
VACL
Security Policy based on Topology
High cost and complex maintenance
Voice
VLAN
Voice
Data
VLAN
Employee Supplier BYODNon-Compliant
Use existing topology and automate
security policy to reduce OpEx
ISE
No VLAN Change
No Topology Change
Central Policy Provisioning
Micro/Macro Segmentation
Employee Tag
Supplier Tag
Non-Compliant Tag
Access Layer
Enterprise
Backbone
DC Firewall / Switch
DC Servers
Policy
TrustSecTraditional Segmentation
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Employees Contractors Production Development
Source Destination
FABRIC NODES
Contract
CISCO
DNA CENTER
CISCO ISE
FABRIC POLICIES
PERMIT
Employees Production
Employees Production
API
POLICY DOWNLOAD
SDA Segmentation Policy Automation
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Network quality is a complex, end-to-end problem
* Both = Join/roam and quality/throughput
APs
Local WLCs
Network services DCOffice site
ISE
DHCP
Mobile clients
CUCM
Client firmware
AP coverage
WAN Uplink usage
WAN QoS, Routing, ...
End-User services
RF Noise/Interf.
Client density
...
Cisco Prime™
Configuration
Addressing
Authentication
Affects Join/Roam
Affects Quality/Throughput
WLC Capacity
Affects Both*
Affects Both*Affects Both*
Affects Both*
Affects Both*
Affects Quality/Throughput
Affects Quality/Throughput Affects Join/Roam
Affects Join/Roam
WAN
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
When users complain about Application Problem
Wireless Network Issue
Increased Latency
WAN Network Issue
Application Problem
Server Problem
User Problem
Network is so
slow I cannot get
any work done
today
I do not see
anything
wrong
End Users
Network
Admin
What the users see What network admins see What can happen
ping – OK
show ip route - OK
traceroute - OK
show interface - OK
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Reverse Path
Lookup
SDA Assurance Path Visualization
Enhanced App Flow Visibility
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Global health - Network and clients
Application and compliance health require DNA advantage.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Global health : Floor-level health score
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Real-time dashboard & analytics
Client/Sensor/Device health
360 view
offers
complete
troubleshooti
ng info on a
per client
basis.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Application performance troubleshooting
Application Health shows you top apps
with performance issues.
From landing, drill down App Health to see which
applications have issues
1 2
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
SDA Ready Platforms
ASR-1000-X
ASR-1000-HX
ISR 4430
ISR 4450
WIRELESSROUTINGSWITCHING
AIR-CT5520
AIR-CT8540
Wave 2 APs (1800, 2800,3800)
Wave 1 APs* (1700, 2700,3700)
Catalyst 9400
Catalyst 9300
Catalyst 9500
Catalyst 4500E Catalyst 6K Nexus 7700
Catalyst 3850 and 3650
AIR-CT3504
CSR 1000V
*with Caveats
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9000 Platform
World’s Most Advanced Enterprise Switches
Catalyst 9300
Fixed Access
Catalyst 9400
Modular Access
Catalyst 9500
Fixed Core
Programmable Mobile Ready
Cloud Ready
Design
Integrated Security
IoT Ready
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
The Catalyst 9K Family
Catalyst 9300
Catalyst 9400
Catalyst 9500
Stackable Access Modular Access Fixed Aggregation
Built on Cisco’s Innovative UADP ASIC & Open IOS-XE
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
4000+
Customers
Wins
Gaining Momentum with the Catalyst 9000!
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Some Early Recognitions…
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9300
1G Data
mGig UPOE
1G UPOE/POE+
2.5G at the
Price of 1G
40G at the
Price of 10G
New Generation of Fixed Access
24 Ports
Modular Power SuppliesModular UplinksModular Fans
UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics (ETA)*
256 bit MACSEC*
Trustworthy Systems
StackWise Virtual*
IEEE1588 & AVB*
NBAR2
Perpetual/Fast PoE
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry
48 Ports
8x10G 2x40G 4x mGig 4x1G 350W 715W 1100W
Only
Stackable
Switch with 8X
10G Uplinks
Highest
2.5G/mGig
Density in the
Industry
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9400
New Generation of Modular Access
4-Slot* 7-Slot 10-Slot
Power Supply
3200W AC
3200W DC*
2400W AC*
Core Linecards
24x 10G SFP+*
48x1G SFP*
24x1G SFP*
Access Linecards
24xmGig + 24xUPOE*
48xUPoE
48xPoE+*
48xData
Supervisor
Sup-1: 80G/Slot Access Optimized
Sup-1XL*: 120G/Slot Core
Optimized
Redundancy
is now
Table-stake
Industry’s
Highest PoE
Scale
9Tbps
System
b/w
UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics*
256 bit MACSEC*
Trustworthy
Systems
StackWise Virtual*
IEEE1588 & AVB*
NBAR2
Perpetual PoE*
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry*
*not available at FCS
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Catalyst 9500
Catalyst 9500-40X
Catalyst 9500-24Q
Catalyst 9500-12Q
New Generation of Purpose Built Fixed Core/Aggregation UADP 2.0
Open IOS-XE
SD-Access
X86 CPU & Containers
Encrypted Traffic
Analytics*
256 bit MACSEC*
Trustworthy
Systems
StackWise Virtual
IEEE1588 & AVB*
NBAR2
Model Driven
Programmability
Patching/GIR
Catalyst 9K Leadership
Streaming Telemetry*
40G at the
Price of 10G
8X Buffering
vs.
Competition
Industry’s
First 40G
Enterprise
Switch
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Current three-tier packaging
IP Services
Full Layer 3 and Advanced Networking
IP Base
Traditional Access and Basic Layer 3 features
LAN Base
L2 Features
Simplified two-tier packaging
DNA Essentials
Simplified Network Operations Solution Package
DNA Advantage
Software Defined Access, Assurance and ETA
Solution Package
Network Advantage
Full L3 with flexible Segmentation and Network
Resiliency
Network Essentials
Competitive Parity with Full L2 and Routed Access
Catalyst 9K: Simplified packaging
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
CISCO CONNECT 2018 . IT’S ALL YOU
Single
SKU
Prime
DNA Advantage
(Includes DNA Essentials)
DNA EssentialsDNA Essentials
Single
SKU
DNA Essentials
Cat 9K w/ Network Advantage
(Full Layer 3 Routing)
Cat 9K w/ Network Essentials
(Layer 2 & Routed Access)
Base Automation & Monitoring SDA & Assurance Capable
Stealthwatch
Single
SKU
ISE Base + ISE Plus
DNA Advantage
(Includes DNA Essentials)
SDA & Assurance Ready
DNA Advantage
Cisco ONE Advantage
Catalyst 9K Switching Software
Must Attach Cisco ONE Advantage or DNA Advantage or DNA Essentials as Subscription with 9K
• Available in 3/5/7 year subscriptions
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

More Related Content

PDF
TechWiseTV Workshop: Cisco DNA Center Assurance
PPTX
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
PPTX
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
PPTX
Cisco connect winnipeg 2018 a look at network assurance in dna center
PDF
PDF
[Cisco Connect 2018 - Vietnam] Yedu s. introducing cisco dna assurance
PDF
Cisco Connect Toronto 2018 DevNet Overview
PDF
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocence
TechWiseTV Workshop: Cisco DNA Center Assurance
[Cisco Connect 2018 - Vietnam] 2. lam doan software-defined access-a transf...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
Cisco connect winnipeg 2018 a look at network assurance in dna center
[Cisco Connect 2018 - Vietnam] Yedu s. introducing cisco dna assurance
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Ottawa 2018 dna assurance shortest path to network innocence

What's hot (20)

PDF
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
PDF
Cisco Connect Toronto 2018 sixty to zero
PDF
Cisco Connect Halifax 2018 Cisco dna - network intuitive
PDF
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
PDF
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
PDF
Cisco Connect 2018 Philippines - introducing cisco dna assurance
PDF
Cisco Connect Vancouver 2017 - Cisco Meraki -Let Simple Work For You
PDF
Cisco Digital Network Architecture - Introducing the Network Intuitive
PDF
Cisco connect winnipeg 2018 introducing the network intuitive
PDF
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
PDF
Cisco connect winnipeg 2018 simply powerful networking with meraki
PDF
Cisco Connect Vancouver 2017 - Optimizing your client's wi fi experience
PDF
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
PDF
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
PDF
Cisco Connect Halifax 2018 Cisco dna - deeper dive
PDF
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
PPTX
Cisco connect winnipeg 2018 simple it leads to simple it management
PDF
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
PDF
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco Connect Ottawa 2018 Cisco digital buildings and the 4th utility w co...
Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Halifax 2018 Cisco dna - network intuitive
Cisco Connect Ottawa 2018 dna automation the evolution to intent-based netw...
Cisco Connect Vancouver 2017 - How to have magical meeting experiences
Cisco Connect 2018 Philippines - introducing cisco dna assurance
Cisco Connect Vancouver 2017 - Cisco Meraki -Let Simple Work For You
Cisco Digital Network Architecture - Introducing the Network Intuitive
Cisco connect winnipeg 2018 introducing the network intuitive
[Cisco Connect 2018 - Vietnam] Rajinder singh cisco sd-wan-next generation ...
Cisco connect winnipeg 2018 simply powerful networking with meraki
Cisco Connect Vancouver 2017 - Optimizing your client's wi fi experience
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Halifax 2018 Cisco dna - deeper dive
Cisco Connect Vancouver 2017 - Cisco's Digital Network Architecture - deeper ...
Cisco connect winnipeg 2018 simple it leads to simple it management
Cisco Connect Ottawa 2018 data center - protecting your data with Cisco hyp...
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Ad

Similar to [Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transformational approach to network design and provisioning (20)

PPTX
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
PDF
Cisco Connect 2018 Singapore - Cisco Software Defined Access
PDF
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
PDF
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
PPTX
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
PDF
Cisco Connect 2018 Singapore - En06 jason pernell
PDF
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
PPTX
Cisco Connect 2018 Indonesia - Introducing cisco dna assurance
PDF
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
PDF
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
PDF
Smau Padova 2018 - Cisco
PDF
Cisco Connect 2018 Thailand - Innovation towards sp transformation mr.sean wa...
PDF
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
PDF
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
PDF
Интуитивная сеть как платформа для надежного бизнеса
PDF
Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM...
PPTX
Cisco Connect 2018 Indonesia - Delivering intent for data center networking
PDF
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
PDF
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
PDF
Understanding Cisco Next Generation SD-WAN Solution
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Singapore - Cisco Software Defined Access
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
Cisco Connect 2018 Singapore - En06 jason pernell
Cisco Connect Toronto 2017 - Introducing the Network Intuitive
Cisco Connect 2018 Indonesia - Introducing cisco dna assurance
Cisco Connect 2018 Thailand - Software defined access a transformational appr...
Cisco Connect 2018 Malaysia - Innovation towards SP transformation
Smau Padova 2018 - Cisco
Cisco Connect 2018 Thailand - Innovation towards sp transformation mr.sean wa...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
Интуитивная сеть как платформа для надежного бизнеса
Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM...
Cisco Connect 2018 Indonesia - Delivering intent for data center networking
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
Understanding Cisco Next Generation SD-WAN Solution
Ad

More from Nur Shiqim Chok (20)

PPTX
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
PPTX
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
PPTX
[Cisco Connect 2018 - Vietnam] Joseph yap journey to the multi cloud
PPTX
[Cisco Connect 2018 - Vietnam] Jeff chua hcm print - cisco connect 2018 (hc...
PPTX
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
PPTX
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
PPTX
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
PDF
Brink sanders cisco architecture keynote
PDF
[Cisco Connect 2018 - Vietnam] Brian cotaz cyber security strategy
PPTX
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
PPTX
[Cisco Connect 2018 - Vietnam] 1. lam doan introducing cisco dna assurance-...
PDF
[Cisco Connect 2018 - Vietnam] Vipul shah intel it transformation an imperat...
PDF
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
PPTX
[Cisco Connect 2018 - Vietnam] Vib 30 min hcmc cisco connect 2018
PPTX
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
PDF
[Cisco Connect 2018 - Vietnam] Yedu s. cisco cmx
PPTX
[Cisco Connect 2018 - Vietnam] Vib 15 min hn cisco connect 2018
PDF
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
PPTX
[Cisco Connect 2018 - Vietnam] Thuy luong hcm welcome & opening address
PPTX
[Cisco Connect 2018 - Vietnam] Pauline hampshire vietnam cisco connect with...
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
[Cisco Connect 2018 - Vietnam] Joseph yap journey to the multi cloud
[Cisco Connect 2018 - Vietnam] Jeff chua hcm print - cisco connect 2018 (hc...
[Cisco Connect 2018 - Vietnam] It transformation an imperative for driving bu...
[Cisco Connect 2018 - Vietnam] Huyen duong hn_cisco aci_delivering intent for...
[Cisco Connect 2018 - Vietnam] Brink sanders cisco connect opening_keynote_vn_v4
Brink sanders cisco architecture keynote
[Cisco Connect 2018 - Vietnam] Brian cotaz cyber security strategy
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
[Cisco Connect 2018 - Vietnam] 1. lam doan introducing cisco dna assurance-...
[Cisco Connect 2018 - Vietnam] Vipul shah intel it transformation an imperat...
[Cisco Connect 2018 - Vietnam] Vib nang cap ha tang cntt san sang cho chuyen ...
[Cisco Connect 2018 - Vietnam] Vib 30 min hcmc cisco connect 2018
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
[Cisco Connect 2018 - Vietnam] Yedu s. cisco cmx
[Cisco Connect 2018 - Vietnam] Vib 15 min hn cisco connect 2018
[Cisco Connect 2018 - Vietnam] Trung nguyen and an le demo security everywher...
[Cisco Connect 2018 - Vietnam] Thuy luong hcm welcome & opening address
[Cisco Connect 2018 - Vietnam] Pauline hampshire vietnam cisco connect with...

Recently uploaded (20)

PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Empathic Computing: Creating Shared Understanding
PDF
Getting Started with Data Integration: FME Form 101
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Tartificialntelligence_presentation.pptx
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PPT
Teaching material agriculture food technology
PPTX
Machine Learning_overview_presentation.pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Encapsulation theory and applications.pdf
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Machine learning based COVID-19 study performance prediction
Assigned Numbers - 2025 - Bluetooth® Document
Empathic Computing: Creating Shared Understanding
Getting Started with Data Integration: FME Form 101
OMC Textile Division Presentation 2021.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
SOPHOS-XG Firewall Administrator PPT.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Tartificialntelligence_presentation.pptx
Group 1 Presentation -Planning and Decision Making .pptx
Teaching material agriculture food technology
Machine Learning_overview_presentation.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
MIND Revenue Release Quarter 2 2025 Press Release
Encapsulation theory and applications.pdf
cloud_computing_Infrastucture_as_cloud_p
Diabetes mellitus diagnosis method based random forest with bat algorithm
Per capita expenditure prediction using model stacking based on satellite ima...
Machine learning based COVID-19 study performance prediction

[Cisco Connect 2018 - Vietnam] Lam doan software-defined access-a transformational approach to network design and provisioning

  • 1. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco Software Defined Access (SDA) Transformational Approach to Network Design & Provisioning Doan Nguyen Lam Cisco Solution Engineer, Cisco Systems
  • 2. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public What is Network about? Today...In the past... Voice Video Data Mobility Security Cloud IOT Source: google.de images Source: google.de images What really matters !!!
  • 3. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Challenge. “I want to design and deploy a network.” Platform choices Best practices Manageable Design options On time Future ready Within budget
  • 4. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Typical Traditional Campus Data Centre WAN/BRANCH Access Points Core Switches Aggregation Switches Access Switches WLC ETHERCHANNEL HSRP SPANNING TREECLI L2/L3 AVC VLANS ACL 802.1x FNF Very powerful and feature rich but: - Complex to operate - Difficult to scale - Difficult to secure - Inflexible and closed architecture - And you manage it all with CLI… Internet
  • 5. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU How we build Traditional Network Box by Box Manual | Error Prone ip domain-name cisco.local no ip http server ip http secure-server ip ssh version 2 ip scp server enable line vty 0 15 transport input ssh transport preferred none Manually Repetitive Steps CLI Skill | Time | Effort
  • 6. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Key Challenges for Traditional Networks Difficult to Segment Ever increasing number of users and endpoint types Ever increasing number of VLANs and IP Subnets Complex to Manage Multiple steps, user credentials, complex interactions Multiple touch-points Slower Issue Resolution Separate user policies for wired and wireless networks Unable to find users when troubleshooting Traditional Networks Cannot Keep Up!
  • 7. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco’s Intent-based Networking Intent Context Security Learning Network Infrastructure DNA Center AnalyticsPolicy Automation Switching Routers Wireless Powered by Intent. Informed by Context. The Network. Intuitive. 7 CISCO CONNECT 2018 . IT’S ALL YOU
  • 8. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Intent-based Networking Model – Industry Approach Activation Physical and Virtual Infrastructure Translation Assurance Orchestrate policies & configure systems Capture business intent, translate to policies, and check integrity Continuous verification, insights & visibility, and corrective actions Cisco DNA Intent-based Networking Industry Initiative 8
  • 9. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Automated Network Fabric Single Fabric for Wired & Wireless with Workflow-based Automation Insights & Telemetry Analytics and insights into user and application behavior Identity-based Policy & Segmentation Decoupled security policy definition from VLAN and IP Address Software-Defined Access Networking at the speed of Software! DNA Center AnalyticsPolicy Automation IoT Network Employee Network SDA-Extension User Mobility Policy stays with user
  • 10. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU What is SD-Access? Campus Fabric + DNA Center (Automation & Assurance) APIC-EM 1.X Campus Fabric ISE PI Automation Policy Assurance DNA Center B C B  Campus Fabric An Overlay network is a logical topology used to virtually connect devices Separated management systems  SD-Access GUI approach provides automation & assurance of all Fabric configuration, management and group-based policy DNA Center integrates multiple systems, to orchestrate your LAN, Wireless LAN and WAN access
  • 11. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Software-Defined Access AssuranceAutomation Policy Routers Switches Wireless AP WLC DNA Center DESIGN PROVISION POLICY ASSURANCE DNA Center: Simple Workflows Solution Components
  • 12. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU You Need a Network that Drives your Digital Business With SDA Cisco Rewriting the Networking Playbook Hardware Centric Software Driven Manual (eg CLI) Automated Silo’ed Security Integrated Security Network Monitoring Analytics and Insights Historicaly Digital-Ready Network
  • 13. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Network Design & Build Work Flow Assure Assure Design Network Hierarchy Network Settings Image Management Network Profiles Policy Virtual Networks Access Control Application Priority
  • 14. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Network Design & Build Work Flow Assure Provision Assure Provision Device Onboarding Host Onboarding Device Inventory Fabric Administration Assurance Network Health Score Client 360 Device 360 Application 360
  • 15. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Syslog Server SDA Design in DNA Center – Global Setup AAA Server Site1 North America South America Site2 Africa EMEAR AAA Server DNS Server Syslog Server DHCP Server • Ability to Define Global Settings once and replicate to all sites/devices • Automated Provisioning
  • 16. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public L2 Switch L3 Switch Trunks Trunk BYOD Employee Contractor One SSID Production Servers AAA DHCP AD WLAN Developer Servers LAN Core Multiple Steps and Touch Points 1. Define Groups in AD 2. Define Policies  VLAN/subnet based 3. Implement VLANs/Subnets  Create VLANs  Define DHCP scope  Create subnets and L3 interfaces  Routing for new subnets  Map SSID to Interface/VLAN 4. Implement Policy  Define ACLs  Apply ACLs 5. Many different User Interfaces AAA WLC Devices CLI …. What if You Need to Add Another Group & Policy? Network Segmentation Policy Rollout Today
  • 17. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU How SDA Simplifies Network Segmentation Access Layer Enterprise Backbone Voice VLAN Voice Data VLAN Employee Aggregation Layer Supplier Guest VLAN BYOD BYOD VLAN Non-Compliant Quarantine VLAN VLAN Address DHCP Scope Redundancy Routing Static ACL VACL Security Policy based on Topology High cost and complex maintenance Voice VLAN Voice Data VLAN Employee Supplier BYODNon-Compliant Use existing topology and automate security policy to reduce OpEx ISE No VLAN Change No Topology Change Central Policy Provisioning Micro/Macro Segmentation Employee Tag Supplier Tag Non-Compliant Tag Access Layer Enterprise Backbone DC Firewall / Switch DC Servers Policy TrustSecTraditional Segmentation
  • 18. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Employees Contractors Production Development Source Destination FABRIC NODES Contract CISCO DNA CENTER CISCO ISE FABRIC POLICIES PERMIT Employees Production Employees Production API POLICY DOWNLOAD SDA Segmentation Policy Automation
  • 19. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Network quality is a complex, end-to-end problem * Both = Join/roam and quality/throughput APs Local WLCs Network services DCOffice site ISE DHCP Mobile clients CUCM Client firmware AP coverage WAN Uplink usage WAN QoS, Routing, ... End-User services RF Noise/Interf. Client density ... Cisco Prime™ Configuration Addressing Authentication Affects Join/Roam Affects Quality/Throughput WLC Capacity Affects Both* Affects Both*Affects Both* Affects Both* Affects Both* Affects Quality/Throughput Affects Quality/Throughput Affects Join/Roam Affects Join/Roam WAN
  • 20. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU When users complain about Application Problem Wireless Network Issue Increased Latency WAN Network Issue Application Problem Server Problem User Problem Network is so slow I cannot get any work done today I do not see anything wrong End Users Network Admin What the users see What network admins see What can happen ping – OK show ip route - OK traceroute - OK show interface - OK
  • 21. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Reverse Path Lookup SDA Assurance Path Visualization Enhanced App Flow Visibility
  • 22. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Global health - Network and clients Application and compliance health require DNA advantage.
  • 23. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Global health : Floor-level health score
  • 24. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Real-time dashboard & analytics Client/Sensor/Device health 360 view offers complete troubleshooti ng info on a per client basis.
  • 25. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Application performance troubleshooting Application Health shows you top apps with performance issues. From landing, drill down App Health to see which applications have issues 1 2
  • 26. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU SDA Ready Platforms ASR-1000-X ASR-1000-HX ISR 4430 ISR 4450 WIRELESSROUTINGSWITCHING AIR-CT5520 AIR-CT8540 Wave 2 APs (1800, 2800,3800) Wave 1 APs* (1700, 2700,3700) Catalyst 9400 Catalyst 9300 Catalyst 9500 Catalyst 4500E Catalyst 6K Nexus 7700 Catalyst 3850 and 3650 AIR-CT3504 CSR 1000V *with Caveats
  • 27. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9000 Platform World’s Most Advanced Enterprise Switches Catalyst 9300 Fixed Access Catalyst 9400 Modular Access Catalyst 9500 Fixed Core Programmable Mobile Ready Cloud Ready Design Integrated Security IoT Ready
  • 28. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU The Catalyst 9K Family Catalyst 9300 Catalyst 9400 Catalyst 9500 Stackable Access Modular Access Fixed Aggregation Built on Cisco’s Innovative UADP ASIC & Open IOS-XE
  • 29. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU 4000+ Customers Wins Gaining Momentum with the Catalyst 9000!
  • 30. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Some Early Recognitions…
  • 31. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9300 1G Data mGig UPOE 1G UPOE/POE+ 2.5G at the Price of 1G 40G at the Price of 10G New Generation of Fixed Access 24 Ports Modular Power SuppliesModular UplinksModular Fans UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics (ETA)* 256 bit MACSEC* Trustworthy Systems StackWise Virtual* IEEE1588 & AVB* NBAR2 Perpetual/Fast PoE Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry 48 Ports 8x10G 2x40G 4x mGig 4x1G 350W 715W 1100W Only Stackable Switch with 8X 10G Uplinks Highest 2.5G/mGig Density in the Industry
  • 32. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9400 New Generation of Modular Access 4-Slot* 7-Slot 10-Slot Power Supply 3200W AC 3200W DC* 2400W AC* Core Linecards 24x 10G SFP+* 48x1G SFP* 24x1G SFP* Access Linecards 24xmGig + 24xUPOE* 48xUPoE 48xPoE+* 48xData Supervisor Sup-1: 80G/Slot Access Optimized Sup-1XL*: 120G/Slot Core Optimized Redundancy is now Table-stake Industry’s Highest PoE Scale 9Tbps System b/w UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics* 256 bit MACSEC* Trustworthy Systems StackWise Virtual* IEEE1588 & AVB* NBAR2 Perpetual PoE* Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry* *not available at FCS
  • 33. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Catalyst 9500 Catalyst 9500-40X Catalyst 9500-24Q Catalyst 9500-12Q New Generation of Purpose Built Fixed Core/Aggregation UADP 2.0 Open IOS-XE SD-Access X86 CPU & Containers Encrypted Traffic Analytics* 256 bit MACSEC* Trustworthy Systems StackWise Virtual IEEE1588 & AVB* NBAR2 Model Driven Programmability Patching/GIR Catalyst 9K Leadership Streaming Telemetry* 40G at the Price of 10G 8X Buffering vs. Competition Industry’s First 40G Enterprise Switch
  • 34. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Current three-tier packaging IP Services Full Layer 3 and Advanced Networking IP Base Traditional Access and Basic Layer 3 features LAN Base L2 Features Simplified two-tier packaging DNA Essentials Simplified Network Operations Solution Package DNA Advantage Software Defined Access, Assurance and ETA Solution Package Network Advantage Full L3 with flexible Segmentation and Network Resiliency Network Essentials Competitive Parity with Full L2 and Routed Access Catalyst 9K: Simplified packaging
  • 35. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential CISCO CONNECT 2018 . IT’S ALL YOU Single SKU Prime DNA Advantage (Includes DNA Essentials) DNA EssentialsDNA Essentials Single SKU DNA Essentials Cat 9K w/ Network Advantage (Full Layer 3 Routing) Cat 9K w/ Network Essentials (Layer 2 & Routed Access) Base Automation & Monitoring SDA & Assurance Capable Stealthwatch Single SKU ISE Base + ISE Plus DNA Advantage (Includes DNA Essentials) SDA & Assurance Ready DNA Advantage Cisco ONE Advantage Catalyst 9K Switching Software Must Attach Cisco ONE Advantage or DNA Advantage or DNA Essentials as Subscription with 9K • Available in 3/5/7 year subscriptions
  • 36. © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential