Cisco Sdwan - Deep Dive
Cisco Sdwan - Deep Dive
Deep Dive
Jean-Marc Barozet
Principal Engineer – SDWAN/NFV Technical Marketing
Cisco + Viptela = Cisco SDWAN
Cisco is committed Cisco is committed Cisco will commit Cisco will address
to Viptela’s solution to the existing IWAN significant the broadest set
and architecture 2.x, ISR 4K, ASR1K, engineering resources of
ENCS, CSR, and to bring next- use cases to
Meraki SD-WAN generation SD-WAN deliver successful
offerings. solutions to market customer outcomes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Why Viptela?
USERS
SDWAN
Cloud
OnRamp
.… IoT
ACI
DC Fabric
DEVICES
APPs
SDA Fabric DC
THINGS SaaS
End-to-end Context
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
From Managed WAN To SDWAN Network-as-a-
Service 1
Cloud delivered WAN with
operational simplicity &
End-point flexibility: Cloud Delivered Analytics analytics
4 • Physical or virtual
• Rich services or lite
• Branch, Agg, Cloud 3 Application QOE
USERS
5
Cloud
SD-WAN .… Use-Cases
DC
WAN
L E A R N IN G
DEVICE IaaS
D N A C enter Apps
S
Policy Autom ation Analytics
IN T E N T C O N TEX T SaaS
Intent-based
N etw ork Infrastructure
vDC
S E C U R IT Y
THINGS
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Architecture
The Power of Abstraction
Orchestration Plane
vManage
vBond
Control Plane
vSmart Controllers
MPLS 4G
INET
vEdge Routers
Data Plane
Cloud Data Center Campus Branch SOHO
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Orchestration Plane
Orchestration Plane
APIs
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Control Plane
Control Plane
APIs
• Facilitates fabric discovery
3rd Party
vAnalytics • Dissimilates control plane
Automation
information between vEdges
vBond • Distributes data plane and app-
aware routing policies to the
vSmart Controllers
vEdge routers
• Implements control plane policies,
MPLS 4G
such as service chaining, multi-
INET topology and multi-hop
vEdge Routers
• Dramatically reduces control plane
complexity
• Highly resilient
Cloud Data Center Campus Branch SOHO
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Data Plane Data Plane
Physical/Virtual
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Management Plane
Management Plane
vManage
Cisco vManage
APIs
• Single pane of glass for Day0,
3rd Party Day1 and Day2 operations
vAnalytics
Automation
• Multitenant with web scale
vBond • Centralized provisioning
• Policies and Templates
vSmart Controllers
• Troubleshooting and
Monitoring
MPLS 4G
• Software upgrades
INET
vEdge Routers • GUI with RBAC
• Programmatic interfaces
(REST, NETCONF)
Cloud Data Center Campus Branch SOHO • Highly resilient
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SDWAN Topology SITE-ID
vbond61
vsmart66
[Link]/16 MPLS [Link]/16 INET
vsmart67
TLOC
SYSTEM-IP COLOR
• Unique
Site 3 identifier per-device.
Site 4 Site 5 • Each tunnel interface is assigned a
• Router-id for BGP, OSPF “color”
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Viptela Fabric Terminology
• Overlay Management Protocol – Control plane protocol distributing
reachability, security and policies throughout the fabric
• Transport Locator (TLOC) – Transport attachment point and next hop
route attribute
• Color – Control plane tag used for IPSec tunnel establishment logic
• Site ID – Unique per-site numeric identifier used in policy
application
• System IP – Unique per-device (vEdge and controllers) IPv4 notation
identifier. Also used as Router ID for BGP and OSPF.
• Organization Name – Overlay identifier common to all elements of
the fabric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Network-as-a-Service: SDWAN Offering
Multi-tenant gateway
Multi-tenant: Control, Management,
2
Orchestration With vManage, vManage Existing / home
3 grown MNS services
vAnalytics and VMS/NSO VMS
vSmart
(e.g. UCaaS)
vBond
NSO
SaaS
Business VPN
4 Cloud networking
1 Gray, White or Black box
Internet
IaaS
… 3rd
Party (or) 4G/LTE
MSP
X86 DC
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multi-Tenant Orchestration Solution
Multi-Tenant vManage
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SDWAN Products
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Platform Options
Providing for flexibility in deployment
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco vEdge Routers
1/10Gb+
vEdge 5000/2000
1Gb
vEdge Cloud
vEdge 1000
100Mb
vEdge 100
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-1000 and vEdge-2000 Routers
vEdge 1000 vEdge 2000
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-100 Routers
vEdge 100m vEdge 100mw
vEdge 100
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge 5000
Campus and Data Center Edge
Platform Capabilities:
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Shipping Now
Q3 CY17
ENCS5412
12-Core
ENCS5408
NEW 8-Core
CiscoLive 2017 Las Vegas
ENCS5406
6-Core • ISRv + 9 core VNF
ENCS5104 PoE
4-Core
• ISRv + 5 core VNF
• PoE
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Network Functions Virtualization
Infrastructure
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
vEdge Cloud Virtual Routers
Virtualized Branch or Cloud
On-Premise Hosted
vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud
VM VM
Physical Server Throughput:
2x vCPU 500Mb/s
4x vCPU 1Gb/s
8x vCPU 1.5Gb/s
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controllers
Cloud or On-Premise Delivered
On-Premise Hosted
vBond* vManage vSmart vSmart vBond vManage vSmart vSmart
VM VM
Cisco is committed Cisco is committed Cisco will commit Cisco will address
to Viptela’s to the existing significant the broadest set
solution and ISR 4K, ASR1K, engineering of
architecture ENCS, CSR, IWAN resources to bring use cases to
2.x, and Meraki next-generation SD- deliver successful
WAN solutions to
SD-WAN offerings. partner and
market
customer outcomes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Fabric
Instantiate Control Plane
Elements
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud-Delivered Control Flexible Deployment Options
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controllers Deployment Methodology
On-Premise/SP Hosted Cloud Hosted
VM VM
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage Deployment
NIC1 NIC0
Cloud or on-premise
deployment
Separate interfaces for
VPN0 VPN512 control and management
Separate VPNs for control and
eth1 eth0 management
Control Management Zone-based security
Interfac Interface
e Minimal configuration for
bring-up
ESXi, KVM, AWS, MS Azure
Connectivity, System IP,
Site ID, Org-Name, vBond IP
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vBond Deployment
NIC1 NIC0
Cloud or on-premise
deployment
Separate interfaces for
control and management
VPN0 VPN512
Separate VPNs for control and
Ge0/0 eth0 management
Zone-based security
Control Management
Interfac Interface Minimal configuration for
e
bring-up
Connectivity, System IP,
ESXi, KVM, AWS, MS Azure Site ID, Org-Name, vBond IP
(local)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Deployment
NIC1 NIC0
Cloud or on-premise
deployment
Virtual machine or container
VPN0 VPN512
Separate interfaces for
control and management
eth1 eth0 Separate VPNs for control and
Control Management management
Interfac Interface Zone-based security
e
Minimal configuration for
ESXi, KVM, AWS, MS Azure
bring-up
Connectivity, System IP,
Site ID, Org-Name, vBond IP
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Fabric
Establish Control Plane
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Software Defined Centralized Control
• Virtual Fabric over any transport
• Virtual or Physical Platforms
Control Elements (vEdge)
• Centralized reachability,
security and application policies
• Secure Channel to SD-WAN
Control Plane
Controller (vSmart, vBond,
DTLS/TLS
vManage)
Single extensible control plane
Operates over DTLS/TLS authenticated
and secured tunnels
• Data Plane tunnels between vEdges
• Dramatically lowers complexity
and increases overall solution
scale
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Certificate-Based Trust
Administrator • Bi-directional certificate-based trust between all
Signed
Defined
vEdge List elements
Controllers
Public or Enterprise PKI
vManage • White-list of valid vEdges and controllers
Certificate serial number as unique identification
vBond vSmart
vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Appliance – Router Identity
During Manufacturing
• Each physical vEdge router is uniquely
TMP identified by the chassis ID and certificate
Chip serial number
• Certificate is stored in onboard Temper Proof
Module (TPM)
- Installed during manufacturing process
Device
• Certificate is signed by Avnet root CA
Certificate - Trusted by Control Plane elements
vManage
x.509
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage ⟺ vSmart
Validate: Root trust, certificate serial, • Symantec signed certificate identity
org-name (default)
• vSmart validates:
Trust for vManage certificate root CA
vSmart Certificate serial number against authorized
Root
white-list (from vManage)
Organization name (received certificate OU)
against locally configured one
TLS/DTLS Signed
• vManage validates:
Trust for vSmart certificate root CA
Certificate serial number against authorized
Root vManage
white-list (from vManage)
Organization name (received certificate OU)
against locally configured one
Validate: Root trust, certificate serial,
org-name
• Persistent DTLS/TLS connection comes up
vSmart is the server
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane Whitelisting – vEdge
vEdge List Identity
• Administrator uploads digitally
(White-List) Trust
signed vEdge list in the vManage GUI
Valid
- White-list for vEdge routers
Invalid
- Downloadable from Viptela support page
Staging
vManage
x.509
vManage
DHCP
TPM
vEdge
Identity
vSmart vBond (X.509)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Zero Touch Provisioning – vEdge Appliance
Control and Policy
Zero Touch Provisioning Elements
Server
2
3 5
Assumption:
DHCP on Transport Side (WAN)
DNS to resolve [Link]*
vEdge
Delivered as-a-Service
* Factory default config
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Zero Touch Provisioning – vEdge Cloud
vManage Control and Policy
Elements
#cloud-config
vinitparam: 1
- otp : 139a24ccd4add6bc0278fde0cb366f60
- vbond : [Link]
- uuid : 0a4a4c78-35a8-4c1c-bbd2-e02516606fd7
- org : Cisco Sy1 - 19968
Cloud-Init
VM
NSO 3
Provisioning
(SDWAN-SITE FP) Tool
5
Full Registration
2
and Configuration
vEdge Cloud
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Single-Tenant ZTP Workflow
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ZTP Process
1. The hardware vEdge router powers up.
2. The router contacts a DHCP server and receives its IP address from the
server.
3. The router contacts a DNS server to resolve the hostname
[Link] and receives the IP address of the Viptela ZTP server
4. The router connects to the ZTP server. The ZTP server verifies the
vEdge router and sends the IP address of the vBond orchestrator. This
is a vBond orchestrator that is in the same organization as the vEdge
router.
5. The router establishes a transient connection to the vBond orchestrator
and sends its chassis ID and serial number. (At this point in the ZTP
process, the router does not have a system IP address, so the
connection is established with a null system IP address.) The vBond
orchestrator uses these two numbers to verify the router. The vBond
orchestrator then sends the IP address of the vManage NMS to the
router.
6. The router establishes a connection to the vManage NMS and is verified
by the NMS. The vManage NMS sends the router its system IP address.
7. The router re-establishes a connection to the vBond orchestrator using
its system IP address.
8. The router re-establishes a connection to the vManage NMS using its
system IP address. If necessary, the NMS pushes the proper software
image to the vEdge router. As part of the software image installation,
the router reboots.
9. After the reboot, the router re-establishes a connection to the vBond
orchestrator, which again verifies the router.
10. The router establishes a connection to the vManage NMS, which pushes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
the full configuration to the router. (If the router has rebooted, it
Multi-Tenant ZTP Workflow
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Appliance ⟺ vBond, vSmart, vManage
Validate: Root trust,
Validate: Root trust,
Validate: Root trust,
certificate serial certificate serial certificate serial • Avnet signed certificate identity (TPM
org-name org-name org-name
Chip)
vBond vSmart vManage • vBond, vSmart and vManage validate:
Trust for vEdge certificate root CA
Root Root Root Certificate serial numbers against
authorized white-list (from vManage)
Organization name (received certificate
Signed OU) against locally configured one
Signed Signed
• vEdge validates:
Trust for vBond, vSmart and vManage
certificate root CA
vEdge Organization name (received certificate
OU) against locally configured one
Root Signed
• Persistent DTLS/TLS connection comes up
between vEdge and vSmart/vManage
DTLS
Validate: Root trust, vEdge is a client
org-name DTLS/TLS
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Cloud ⟺ vBond, vSmart, vManage
Validate: Root trust,
Validate: Root trust,
Validate: Root trust,
certificate serial certificate serial certificate serial • vManage root cert is distributed to
org-name org-name org-name
controllers
vBond vSmart vManage • vManage issues certificate identity
Root
• vBond, vSmart and vManage validate:
Root Root
Trust for vEdge certificate root CA
Certificate serial numbers against
Signed authorized white-list (from vManage)
Signed Signed
Organization name (received certificate
OU) against locally configured one
• vEdge validates:
Trust for vBond, vSmart and vManage
vEdge
certificate root CA
Organization name (received certificate
Root Signed
OU) against locally configured one
DTLS
• Persistent DTLS/TLS connection comes up
Validate: Root trust, between vEdge and vSmart/vManage
org-name DTLS/TLS
vEdge is a client
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Control Plane Transport
• vEdge router will by default try to
vBond vSmart vManage
establish control connections over
all provisioned transports
• Administrator can control which
transports vEdge router uses for
establishing control connections
MPLS INET
DTLS
DTLS/TLS
vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane Sessions
DTLS only
• Secure Channel to SD-WAN • Viptela Primitives
• Permanent
Controllers (vSmart, vBond, vManage
• Multiple Sessions
vManage) vBond
• Single extensible control
plane vSmart vSmart
from vManage
vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management Protocol (OMP)
Unified Control Plane
• TCP based extensible control plane
protocol
vSmart
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
- Inside TLS/DTLS connections
vManage – IP1
UDP
Core0 - 12346
Core1 - 12446 UDP
vBond – IP1 vSmart – IP1 Core2 - 12546 Core0 - 12346
vBond – IP2 vSmart – IP2 Core3 - 12646 Core1 - 12446
Core4 - 12746 Core2 - 12546
Core5 - 12846 Core3 - 12646
vBond orchestrators do not Core6 - 12946 Core4 - 12746
support multiple cores. vBond Core7 – 13046 Core5 - 12846
orchestrators always use DTLS 12346 UDP UDP Core6 - 12946
tunnels to establish control UDP Core7 – 13046
connections with other
Viptela devices, so they The vManage NMSs and vSmart controllers can
run on a virtual machine (VM) with up to
always use UDP. The UDP port eight virtual CPUs (vCPUs). The vCPUs are
is 12346 designated as Core0 through Core7.
Each core is allocated separate base ports
Firewall for control connections
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Transport Locators (TLOCs)
TLOCs vSmart
vSmarts advertise TLOCs to
vEdges in TLOC routes
IPsec
IPsec Local TLOCs
IPsec
(System IP, Color, Encap
MPLS INET
Pub IP/Port, Priv IP/Port)
vEdge vEdge
vEdge vEdge
Transport Locator (TLOC) OMP IPSec Tunnel
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Transport Colors
T3 T4 T1 T2
T3 T4
Internet1 T1 T2 Internet
T1 T3
T3 vEdge vEdge
T1
vEdge vEdge T2 T4
T2 T4
MPLS
T1 T4 T2 T3
T1 T4 T2 T3
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Fabric Operation
Fabric Walk-Through
OMP Update:
vSmart Reachability – IP Subnets, TLOCs
OMP
Security – Encryption Keys
DTLS/TLS Tunnel
Policy – Data/App-route Policies
IPSec Tunnel
OMP OMP
BFD Update Update
Policies
OMP OMP
Update Update
vEdge1 vEdge2
T1
Transport1 T3
T3 T4 TLOCs TLOCs T1 T2
T4
T2
VPN1 VPN2 Transport2 VPN1 VPN2
BGP, OSPF, BGP, OSPF,
Connected, Connected,
Static A B C D Static
Subnets Subnets
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Bidirectional Forwarding Detection (BFD)
vEdge • Path liveliness and quality measurement
detection protocol
- Up/Down, loss/latency/jitter, IPSec
tunnel MTU
• Runs between all vEdge and vEdge Cloud
routers in the topology
- Inside IPSec tunnels
vEdge vEdge - Automatically invoked after each IPSec
tunnel establishment
- Cannot be disabled
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
End to End Segmentation
VPN 1
Interface VPN1 SD-WAN VPN1 Interface
IPSec VPN 2
VLAN VPN2 Tunnel VPN2 VLAN
VPN 3
Ingress Egress
vEdge vEdge
• Segment connectivity across fabric w/o • vEdge routers maintain per-VPN routing
reliance on underlay transport table for complete control plane separation
• Interfaces and sub-interfaces (802.1Q • Labels are used to map packets into VPNs
tags) are mapped into VPNs for complete data plane separation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Data Plane Security Encryption
Each vEdge advertises its local IPsec Can be rapidly rotated
encryption keys as OMP TLOC attributes vSmart
Controllers Symmetric encryption keys used
Encryption keys are per-transport asymmetrically
OMP OMP
Update Update
Local
Local
Transport1
vEdge-A vEdge-B
Transport2
Remote
Remote
AES256-GCM
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Control Plane
Anti-Replay Protection
Encrypted packets are assigned sequence Upon receipt of a packet with higher
numbers. vEdge routers drop packets with sequence number than received thus far,
duplicate sequence numbers vEdge router will advance the sliding
- Replayed packet window
vEdge routers drop packets with sequence Sliding window is COS aware to prevent low
numbers lower than the minimal number of priority traffic from “slowing down” high
the sliding window priority traffic
- Maliciously injected packet
Sliding Window
Packet
Sequence
Numbers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
WAN Communication
Traffic Forwarding
Per-Session Loadsharing Per-Session Weighted Application Pinning Application Aware Routing
Active/Active Active/Active Active/Standby SLA Compliant
SLA SLA
Core
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management
Protocol (OMP)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management Protocol (OMP)
Unified Control Plane
• TCP based extensible control plane
protocol
vSmart
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
- Inside TLS/DTLS connections
vEdge vEdge
OMP Peers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing: TLOC Routes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing: OMP Routes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing: Network Service Routes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP Best-Path Algorithm and Loop Avoidance
Next hop TLOC is reachable
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Understanding NAT Types (1/2)
Full-Cone Symmetric
Source: Z / 3001 Source: Z / 3001
Dest: B / 90 Dest: B / 90
Port 90 Port 90
Site Site
NAT NAT
Port 2001 Port 2001
Host A Port 90 Host A Port 90
Host C Host C
Port 91 Port 91
Local Addr / Port <-> External Addr / Port External Address mask Local Addr / Port <-> External Addr / Port External Address mask
Source: [Link]
29/[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Understanding NAT Types (2/2)
Restricted-Cone NAT Port-Restricted-Cone NAT
Source: Z / 3001 Source: Z / 3001
Dest: B / 90 Dest: B / 90
Port 90 Port 90
Site Site
NAT NAT
Port 2001 Port 2001
Host A Port 90 Host A Port 90
Host C Host C
Port 91 Port 91
Local Addr / Port <-> External Addr / Port External Address mask Local Addr / Port <-> External Addr / Port External Address mask
Source: [Link]
29/[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Traversal Combinations
Side A Side B IPSec Tunnel Status
Public Public
Public Symmetric
Symmetric Symmetric
Direct IPSec Tunnel No Direct IPSec Tunnel (traffic traverses hub) Mostly Encountered
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Traversal – Dual Sided Full Cone
vBond
NAT Detection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN Port Handling and Firewall
• By default, all Viptela devices use base port 12346 for establishing the connections that handle
control and traffic in the overlay network. Each device uses this port when establishing connections
with other Viptela devices
• Port Offset
• When multiple Viptela devices are installed behind a single NAT device. For NAT devices that can differentiate among the
devices behind the NAT, you do not need to configure the port offset.
• Different port numbers used for each device so that the NAT can properly identify each individual device.
• Port offset from the base port 12346. For example, device with a port offset of 1, that device uses port 12347. The port
offset can be a value from 0 through 19. The default port offset is 0.
• Port Hopping
• Devices try different ports when attempting to establish connections with each other in the event that a connection
attempt on the first port fails.
• After such a failure, the port value is incremented and the connection attempt is retried. The software rotates though a
total of five base ports, waiting longer and longer between each connection attempt.
• If you have not configured a port offset, the default base port is 12346, and port hopping is done sequentially among
ports 12346, 12366, 12386, 12406, and 12426, and then returning to port 12346.
[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Routers – Base Ports
vBond vManage vSmart • When a vEdge router joins the overlay network, it
establishes DTLS control plane connections with
the controller devices—the vBond orchestrator,
the vManage NMS, and the vSmart controller
DTLS DTLS
• When initially establishing these DTLS
UDP UDP connections, the vEdge router uses the base port
DTLS
UDP
12346. If it is unable to establish a connection
using this base port, it port-hops through ports
INET MPLS 12366, 12386, 12406, and 12426, returning, if
necessary, to 12346
• This same port number is used to establish the
IPsec connections and BFD sessions to the other
12346
vEdge routers in the overlay network.
12366 UDP
12386 • Command: show control local-properties
12406
12426 12346
12366
12386
12406
12426
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controllers – Base Ports
vBond UDP vManage UDP vSmart UDP • The vManage NMSs and vSmart controllers can
12346 Core0 - 12346 Core0 - 12346
Core1 - 12446 Core1 - 12446 run on a virtual machine (VM) with up to
Core2
Core3
- 12546
- 12646
Core2
Core3
- 12546
- 12646
eight virtual CPUs (vCPUs). The vCPUs are
Core4 - 12746 Core4 - 12746 designated as Core0 through Core7.
Core5 - 12846 Core5 - 12846
DTLS DTLS
Core6 - 12946 Core6 - 12946 • Each core is allocated separate base ports
Core7 – 13046 Core7 – 13046
UDP UDP for control connections. The base ports
DTLS
UDP
differ, depending on whether the connection
is over a DTLS tunnel (which uses UDP) or a
INET MPLS TLS tunnel (which uses TCP).
• vBond orchestrators do not support multiple
cores. vBond orchestrators always use DTLS
tunnels to establish control connections
with other Viptela devices, so they always
UDP use UDP. The UDP port is 12346.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Default – No Port
Offset Configured and
vManage – IP1
UDP
Core0 - 12346
Core1 - 12446 UDP
vBond – IP1 vSmart – IP1 Core2 - 12546 Core0 - 12346
vBond – IP2 vSmart – IP2 Core3 - 12646 Core1 - 12446
Core4 - 12746 Core2 - 12546
Core5 - 12846 Core3 - 12646
vBond orchestrators do not Core6 - 12946 Core4 - 12746
support multiple cores. vBond Core7 – 13046 Core5 - 12846
orchestrators always use DTLS 12346 UDP UDP Core6 - 12946
tunnels to establish control UDP Core7 – 13046
connections with other
Viptela devices, so they The vManage NMSs and vSmart controllers can
run on a virtual machine (VM) with up to
always use UDP. The UDP port eight virtual CPUs (vCPUs). The vCPUs are
is 12346 designated as Core0 through Core7.
Each core is allocated separate base ports
Firewall for control connections
Firewall
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vBond – NAT Traversal Discovery
vEdge-A
Public: Z / 3001 vBond-C
Private: A / • In order to successfully establish
12346
vEdge-B IPSec tunnels between the vEdge
Public: Y / 4001
Private: B / routers, Cisco SD-WAN fabric has to
12366
successfully operate across the NAT
boundaries.
INET1 • vBond discovers vEdge public IP
address and port, even if traverses
Source: Z / 3001 Source: Y / 4001 NAT
Dest: C / 12346 Dest: C / 12346
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Filtering Table
vEdge-A
Public: Z / 3001 vBond-C
Private: A / • Symmetric NAT on ISP1 Box2
12346
vEdge-B
Public: Y / 4001
Private: B /
• Binding Entry created:
12366
• [Internal IP : Internal Port] <->
[External IP : External Port]
INET1
IP: A IP: B
Port: 12346 Port: 12366
vEdge-A vEdge-B
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP – TLOC Advertisement
• Routes connecting locations to physical
networks
• Advertised to vSmart controllers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-A TLOC Advertisement
vEdge-A TLOC vSmart
Public: Z / 3001
Private: A / • vEdge-A uses A / 12346 and is
12346
translated by ISP box1 to Z / 3001
• vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1 • From vEdge-A ‘s perspective, vedge-
vEdge-A TLOC vEdge-A TLOC B dest ip will be Y and dest port
Public: Z / 3001
Private: A /
OMP OMP
Public: Z / 3001
Private: A / will be 4001.
12346 12346
vEdge-A vEdge-B
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-B TLOC Advertisement
vEdge-A TLOC vSmart
Public: Z / 3001
Private: A / • vEdge-A uses A / 12346 and is
12346
vEdge-B TLOC translated by ISP box1 to Z / 3001
Public: Y / 4001
Private: B /
12366 • vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1 • From vEdge-A ‘s perspective, vedge-
vEdge-B TLOC
vEdge-B TLOC B dest ip will be Y and dest port
Public: Y / 4001
Public: Y / 4001
Private: B /
OMP OMP Private: B / will be 4001.
12366
12366
vEdge-A vEdge-B
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP – TLOC Received
PUBLIC PRIVATE
PUBLIC PRIVATE
PSEUDO PUBLIC PRIVATE PUBLIC IPV6 PRIVATE IPV6 BFD
KEY PUBLIC IP PORT PRIVATE IP PORT IPV6 PORT IPV6 PORT STATUS
-----------------------------------------------------------------------------------------------------
1 [Link] 62140 [Link] 12346 :: 0 :: 0 up
[SNIP]
vedge-B
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP – TLOC Received
PUBLIC PRIVATE
PUBLIC PRIVATE
PSEUDO PUBLIC PRIVATE PUBLIC IPV6 PRIVATE IPV6 BFD
KEY PUBLIC IP PORT PRIVATE IP PORT IPV6 PORT IPV6 PORT STATUS
-----------------------------------------------------------------------------------------------------
1 [Link] 65130 [Link] 12366 :: 0 :: 0 up
[SNIP]
vedge-A
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-A to setup Data Tunnel to vEdge-B (1/2)
vEdge-A TLOC
Public: Z / 3001 vSmart-D
Private: A / • vEdge-A uses A / 12346 and is
12346
vEdge-B TLOC translated by ISP box1 to Z / 3001
Public: Y / 4001
Private: B /
12366 • vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1
• From vEdge-A ‘s perspective, vedge-
B dest ip will be Y and dest port
will be 4001.
NAT Inbound Filter
C / 12346
• From vEdge-B ‘s perspective, vedge-
ISP1
Box
ISP1
Box
Symmetric A dest ip will be Z and dest port
IP: A IP: B
will be 3001.
Port: 12346 Source: A / 12346
Port: 12366
Dest: Y / 4001
vEdge1 vEdge2
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-A to setup Data Tunnel to vEdge-B (2/2)
vEdge-A
Public: Z / 3001 vSmart-D
Private: A / • vEdge-A uses A / 12346 and is
12346
vEdge-B translated by ISP box1 to Z / 3001
Public: Y / 4001
Private: B /
12366 • vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1
• From vEdge-A ‘s perspective, vedge-
B dest ip will be Y and dest port
will be 4001.
Source: Z / 3001 NAT Inbound Filter
C / 12346
Dest: Y / 4001
• From vEdge-B ‘s perspective, vedge-
ISP1
Box
ISP1
Box
Symmetric A dest ip will be Z and dest port
IP: A IP: B
will be 3001.
Port: 12346 Port: 12366
vEdge1 vEdge2
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Security
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Secure Segmentation – VPNs
IF IF MPLS
Service Transport
(VPNn) (VPN0)
IF IF INET
Management • VPNs are isolated from each other, each VPN has
(VPN512) its own forwarding table
• vEdge router allocates label to each of it’s
IF
service VPNs and advertises it as route
attribute in OMP updates
- Labels are used to identify VPN in the incoming
packets
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Labels
• Labels identity VPN route table on
IP
vEdge router
UDP Per-VPN
Locally significant on each vEdge
ESP
• Pushed on the ingress vEdge, popped
Label on the egress vEdge
• Appear in encrypted part of the IPSec
Encrypted
Original packet
Packet
• Exchanged through the OMP routes
• Used for segmentation
[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
End-to-End Segmentation vSmart
Route
Tables
A A
B B
C C
vEdge Router vEdge Router
• Segment connectivity across fabric w/o • vEdge routers maintain per-VPN routing
reliance on underlay transport table for complete control plane separation
• Interfaces and sub-interfaces (802.1Q • Labels are used to map packets into VPNs
tags) are mapped into VPNs for complete data plane separation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Segmentation and Multi-Topology
UC Compliancy Regions
vSwitch1
• Works for both physical, virtual and
mixed environments
vSwitch2
• Can be used in conjunction with fabric
vSwitch0 security
Firewall
Centralized or localized data policy
x86
NIC0
POP1 POP2
• DNS queries are forwarded to Cisco
Umbrella DNS servers either
unconditionally or based on the policies
Regional
Data Center • Cisco Umbrella enforces security policy
DIA ISP A compliance based on DNS resolution
• Cisco Umbrella can act as proxy for
ISP B
application traffic with full Unified Threat
SD-WAN Management capabilities
Remote Site Data Center
Fabric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DNS or Application Traffic
3rd Party Cloud Security
RGN RGN
POP1 POP2 1 2
IPSec Tunnels
GRE/IPSec Tunnels
DIA Regional
ISP A
Data Center
ISP B
SD-WAN SD-WAN
Remote Site Remote Site
Fabric Fabric Data Center
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Data Traffic
Cloud Security with Zscaler
• vEdge router creates a GRE tunnel to
one or more Zscaler Enforcement Nodes
Exploits Malware ATP Botnets
(PoPs)
- Redundant PoPs, redundant ISPs
POP1 POP2
• Eliminates backhaul of traffic
destined to Internet and cloud
Regional applications
Data Center
ISP1 • Provides advanced security services
- Can inspect SSL encrypted data,
SD-WAN
Fabric
requires installation of Zscaler root
ISP2 certificate on the hosts
Remote Site Data Center • Cloud onRamp for SaaS can choose the
path across best performing Zscaler
GRE Tunnel Enforcement Node (PoP) for selected
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SaaS applications
DDoS Protection for vEdge Routers
vBond
Authenticated
Sources
vSmart vManage
CPU
Implicitly SD-WAN IPSec
Trusted
Sources Control Plane Policing:
vEdge 300pps per flow
5,000pps
Packet
Explicitly Forwarding
Defined
Sources
Cloud Security
Deny except:
Unknown 1. Return packets matching flow entry (DIA enabled)
Sources 2. DHCP, DNS, ICMP
Other * Can manually enable :SSH, NETCONF, NTP, OSPF, BGP, STUN
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DDoS Protection for Controllers
vBond
Authenticated
Sources
vSmart vManage
CPU
vEdge
Control Plane Policing:
500pps per flow
10,000pps
vManage
Packet
Forwarding
Unknown vSmart
Sources Note: vBond control plane policing is the
same as vEdge
Other
Deny except:
DHCP, DNS, ICMP, NETCONF
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Streaming Content Distribution
Multicast Traffic
vEdges interoperate with IGMP v1/v2 and PIM on vEdge Replicators replicate multicast stream to
the service side receivers
vEdges advertise receiver multicast groups using Multicast is encapsulated in point-to-point
OMP tunnels
vSmart Controllers
OMP
Update
IGMP/PIM OMP
Update
SD-WAN
OMP Sender
Update Fabric
Receiver Branch OMP
Update
Data
IGMP/PIM
Center
RP
Receiver Branch
Replicators Control Plane Multicast Stream
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast Support Models
• PIM-SM with Auto-RP
• For cases with many receivers
• Replicators can be at the source or dispersed at different geo
locations
• PIM-SSM
• For cases with many sources aggregating at a headend/DC site
• Replicators should be defined at the receiver side
• SSM mapping defined on a non-viptela device
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast Support with Auto-RP
• Source register itself to an RP
• Receiver sends the (*,G) join
• First Join gets forwarded to the vSmart as an OMP packet and then forwarded to the
replicator
• Replicator forwards (*,G) to the RP
• RP forwards it to the source
• Stream is forwarded to the receiver through the replicator. Stream never goes to vSmart
• Once receiver has the source information, it will the join using (S,G)
• First (S,G) join gets forwarded as an OMP control packet to the vSmart and then to
replicator
• Replicator then forward the (S,G) to the source
• vEdge ignores subsequent joins and depends on the prune message to stop the stream from
the replicator
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast Support with PIM-SSM
Partner Internet Head End
Location
5 6
vEdge will vEdge will receive
7
start sending multicast over a
Stream is forwarded
multicast unicast tunnel
to the receiver
Stream will be Forward the stream on
send over a the interface it
unicast tunnel receives join
IPSec Unicast Tunnel
(AES 256)
PIM-SSM
SOURCE VE2K
Internet Receiver
VE100
PIM-SSM
VE2K
2
4 3 SSM Mapping defined 1
on non-viptela
(S,G) is received (S,G) join router (*,G) join to a
by the remote forwarded to (*,G) join non-viptela router
vEdge remote Viptela converted to (S,G) From encoders
site over a (S,G) join
unicast tunnel forwarded to
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Viptela
Configurations
Replicator
vpn 10
router pim
interface ge2/0
autorp
pim multicast-replicator local
Non-Replicator
vpn 10
router pim
interface ge2/0
autorp
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application Experience
and QoS
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application Recognition
Cloud Data Deep Packet Inspection Engine
Center
App 1
App 2
App 3,000
vEdge Router
MPLS INET
Data
3G/4G Center
Primary Use Cases:
- Application visibility
Small Office - Application Firewall
Home Office - Traffic prioritization
Campus
- Transport selection
Branch
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Bidirectional Forwarding Detection (BFD)
• Path liveliness and quality measurement
vEdge
detection protocol
- Up/Down, loss/latency/jitter, IPSec
tunnel MTU
• Runs between all vEdge and vEdge Cloud
routers in the topology
- Inside IPSec tunnels
vEdge vEdge - Automatically invoked after each IPSec
tunnel establishment
- Cannot be disabled
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
BFD – Tunnel Down
Multiplier = 7
BFD Probe
• Each vEdge router generates BFD packet every • Hello interval and multiplier determine
“hello” interval for path liveless how many BFD packets need to be lost to
detection declare IPSec tunnel down
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
BFD - Transport SLA Monitoring
App-Route Multiplier (6)
vEdge Router
• Each vEdge router generates BFD packet • Poll interval determines the average path
every “hello” interval for path quality quality measurement (loss, latency,
• BFD packets are generated for each jitter)
transport individually. Timers can be • App-route multiplier determines the
adjustment for quicker detection. average path quality measurement across
the poll intervals
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Critical Applications SLA
Application Aware Routing
By default, without any local or vManage
centralized data policies, App Aware Routing Policy
Cisco SDWAN performs flow-based load App A path must have
sharing across all transports available
between the vEdge routers latency <150ms and loss <2%
With Policies:
vSmart Controllers
Enforce SLA compliant path for
applications of interest
Other applications will follow
active/active behavior across all paths
Internet
vEdge vEdge
Path 2 MPLS
App A
4G LTE
Path1: 10ms, 0% loss
Path2: 200ms, 3% loss IPSec Tunnel
Path3: 140ms, 1% loss
Control Plane
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Optimal Network Utilization for App Traffic
Path MTU Discovery
Automatic and proactive Network Path Automatic MSS adjust for TCP traffic
MTU Discovery leveraging BFD protocol Can also be manually configured
Support for Host Path MTU Discovery IP ICMP Unreachable (type 3, code 4)
Transport1
Host Path
MTU Discovery
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Example
App Policy applied with DSCP EF
preferred path MPLS, rest is
default
Simulation with DSCP 0(default)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
QoS
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Router Device QoS Overview
Data Policy
vManage Classification of application traffic into QoS
forwarding classes (queues)
Egress Interface
Ingress Interface
Q1 - Q0 is LLQ
Q2 - vEdge control traffic (DTLS/TLS, BFD, routing
protocols) goes into Q0
o Not subjected to LLQ policer
Q7
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Shaping
Rate
Tokens • Shaping effective on egress
Token Bucket physical interfaces
- Not supported on sub-interfaces
Egress Interface
Ingress Interface
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policing
• Ingress and Egress Policing
Rate
Tokens
- Interface/Sub-Interface based
Token Bucket - DPI or 6 tuple matching using
centralized or localized data
policy
Egress Interface
Ingress Interface
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policing with Packet Loss Priority
Rate
Tokens
Token Bucket
DSCP
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Behavior Changes with QoS Data Policy
When you want to modify the default packet forwarding flow, you design and provision QoS policy
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Forwarding Classes and Scheduler
Map Forwarding Class to Output queues
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
QoS Scheduler
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Apply the Queue Map to an Egress Interface
QoS
Scheduler
Out
Q
Q
Q
Shaping Bandwidth %
Buffer %
WARNING: Scheduling Priority
QoS shaping rates might be Drop
inaccurate for rates less than
2 Mbps. [VIP-3860]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Apply the Queue Map to an Egress Interface
QoS
Scheduler
Out
Q
Q
Q
Shaping
Bandwidth %
Buffer %
Scheduling Priority
WARNING:
Drop
QoS shaping rates might be
inaccurate for rates less than
2 Mbps. [VIP-3860]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configuration
• Ingress
• Use a localized policy with ACL
• Or use a Global Data Policy
• Match application, group or prefix etc
• Action: set DSCP and select Forwarding Class
• Egress
• class-map
• qos-scheduler
• Apply on egress interface
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configure Class-Map and Scheduler (1/2)
Step1: Configure forwarding classes and mapping to output queues Step2: Configure the QoS scheduler forwarding classes
policy
policy qos-scheduler be-scheduler
class-map class best-effort
class best-effort queue 3 bandwidth-percent 20
buffer-percent 20
class bulk-data queue 2 scheduling wrr
class critical-data queue 1 drops red-drop
class voice queue 0 !
qos-scheduler bulk-scheduler
class bulk-data
bandwidth-percent 20
buffer-percent 20
scheduling wrr
drops red-drop
!
qos-scheduler critical-scheduler
class critical-data
bandwidth-percent 40
buffer-percent 40
scheduling wrr
drops red-drop
!
qos-scheduler voice-scheduler
class voice
bandwidth-percent 20
buffer-percent 20
scheduling llq
drops tail-drop
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configure Class-Map and Scheduler (2/2)
policy
qos-map MyQoSMap
qos-scheduler be-scheduler
qos-scheduler bulk-scheduler
qos-scheduler critical-scheduler
qos-scheduler voice-scheduler
interface ge0/1
shaping-rate 5000
qos-map MyQoSMap
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Classify Traffic into Classes
Step1. Define an Access List to Classify Data Step2. Apply the Access List to an Interface
Packets into appropriate Forwarding Classes
policy vpn 10
access-list MyACL
sequence 10
interface ge0/0
match access-list MyACL in
dscp 46
! !
action accept
class voice
!
!
sequence 20
match
source-ip [Link]/24
destination-ip [Link]/24
!
action accept
class bulk-data
set
dscp 32
!
!
!
sequence 30
match
!
destination-ip [Link]/24 Or use Global Data Policy and assign
action accept
class critical-data traffic to Forwarding Class
set
dscp 22
!
!
!
sequence 40
action accept
class best-effort
set
dscp 0
!
!
!
default-action drop
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Rewrite Rule
• This example shows how to configure the rewrite rule
to overwrite the DSCP field of the outer IP header.
policy
rewrite-rule transport • Here the rewrite rule "transport" overwrites the DSCP
class af1 low dscp 3 value for forwarding classes based on the drop
class af1 high dscp 4 profile.
class af2 low dscp 5
class af2 high dscp 6 • Since all classes are configured with RED drop, they
class af3 low dscp 7 can have one of two profiles: high drop or low drop.
class af3 high dscp 8
class be low dscp 1 • The rewrite rule is applied only on the egress
class be high dscp 2 interface, so on the way out, packets classified as
! "af1" and a Packet Loss Priority (PLP) level of low
! are marked with a DSCP value of 3 in the IP header
field, while "af1" packets with a PLP level of high
are marked with 4. Similarly, "af2" packets with a PLP
level of low are marked with a DSCP value of 5, while
"af2" packets with a PLP level of high are marked with
6, and so on.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Classification using Global Data Policy
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
TCP Optimization
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
TCP Optimization
Optimized
TCP Connections TCP Connections TCP Connections
SD-WAN
Fabric
Users vEdge vEdge Application
Router High Latency / Lossy Path Router Servers
• High latency or/and lossy path between • Optimized TCP connections use selective
users and applications, i.e. geo-distances acknowledgements to prevent unnecessary
retransmissions of received segments
• vEdge routers terminate TCP sessions and
provide local acknowledgements • Hosts using older TCP/IP stacks will see the
- Hosts don’t have to wait for end-to-end TCP most benefit
ACKs and pause TCP transmission
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Optimal MTU with Host PMTUD
IP MTU 1500 Bytes SD-WAN
Service Side Transport Side Fabric
DF=1 Fragmentation
Host
Packet
1500B Needed
Adjust IP MTU
Inner Outer
Packet DF=1 No (DF=1) DF=1 No
< 1500B Fragmentation Fragmentation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Packet Fragmentation
IP MTU 1500 Bytes SD-WAN
Service Side Transport Side Fabric
Inner Outer
Host
1500B Needed
Fragment
IPSec
Host vEdge vEdge Application
Router SD-WAN Fabric Router Servers
Signaled MSS Signaled MSS
1460B MSS Adjust 1320B Send MSS
to 1320B 1320B
Signaled MSS Signaled MSS
Send MSS 1320B MSS Adjust 1460B
1320B to 1320B
Send TCP MSS is min (local link IP MTU - 40B*, signaled MSS value)
Signaled in SYN packets
Can manually set TCP MSS value on vEdge router
Per-interface
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud Adoption
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Shifts in Enterprise Workloads
Public/Hybrid Cloud Cloud Applications
IaaS SaaS
IaaS SaaS
Public Cloud Cloud
Data Center Applications
Data Data
Center Center
SD-WAN
ISP2 Fabric
User Remote Site Data Center
MPLS
Viptela vEdge Router
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Direct Internet Access
Quality Probing
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS – DIA and Gateways
• Detect application performance
through DIAs and gateways
Customer/SP owned and
operated
ISP2 Security, performance, reliability
Loss/
Latency • vEdge routers chose best
Regional
Data Center performing path
! Per-Application, Per-VPN
ISP1
SD-WAN • Automatic failover in case of
Fabric performance degradation
MPLS
Remote Site Data Center
• Fully automated
Quality Probing
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS Quality Probing
• DNS resolution for the configured
DNS Server(s)
Cloud onRamp SaaS applications
• Periodic quality probes toward the
Loss/ configured Cloud onRamp SaaS
Latency
applications
Best !
Performing ISP1 ISP2 • vQoE score is determined based
on loss and latency reported by the
IF IF quality probes
• vEdge router determines best
VPN0 performing DIA circuit toward Cloud
DNS Query onRamp SaaS applications based
vEdge Router Quality Probe on vQoE scores
(remote site)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vQoE
DPI
MPLS
INET
• Application is forwarded along best
Host performing path
vEdge Router
© 2018
(remote site)
Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DNS Query Best performing path
SD-WAN and Public Cloud
Branch
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Deployment Models
Application VPC Gateway Transit Hub Router
R R R
AZ1 AZ2 AZ1 AZ2 AZ1 AZ2
VGW VGW
MPLS INET
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS – Attached Compute
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS – Gateway
Compute
• A pair of vEdge routers is
VPCs/VNETs
instantiated in Amazon VPC or
Microsoft Azure VNET
- Gateway VPC/VNET
Gateway
VPC/VNET • A pair of standard-based IPSec tunnels
Cloud is stretched from gateway VPC/VNET to
Data Center each host VPCs/VNETs
- Connectivity redundancy
• BGP is established across IPSec
SD-WAN tunnels for route advertisement
Fabric - Bi-directional BGP/OMP redistribution
on the gateway VPC/VNET vEdge routers
Campus
Remote Site • Entire process is automated through
vManage workflow
• No change to existing compute
Branch VPCs/VNETs
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS – Gateway VPC/VNET
Standard IPSec + BGP
• Fully automated through
AZ1
BGP <-> OMP
vManage wizard
R
• Greatly simplifies brownfield
VGW
AZ2 IGW integration
AZ1
Host VPC vEdge GW
INET No changes are required on
host VPCs
MPLS
AZ2
vEdge GW
VGW Direct
Connect
• Multipathing, segmentation,
QoS
AZ1 Gateway VPC
R
VGW
• Fast failover
vManage instantiated and
AZ2 managed Speed of BGP convergence
Host VPC
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Horizontal Solution Scale
Orchestration Plane Management Plane Control Plane
(vBond) (Multi-tenant or Dedicated) (Containers or VMs)
(vManage) (vSmart)
Add vBond Orchestrators to Create vManage cluster to Add vSmart Controllers for
increase vEdge bringup capacity accommodate more vEdge routers more control plane capacity
vSmart Controllers
MPLS Control
Data
Center
INET Data MPLS
Site
INET
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy - Site with LAN Routing
A S A S
• VRRP Active vEdge router responds to
vEdge A vEdge B
VRRP Grp 1
ARP requests for the virtual IP
VRRP Grp 2
• In case of failover, new VRRP Active
VLAN 1
VLAN 2 vEdge router sends out gratuitous ARP
to update ARP table on the hosts and
mac address table on the intermediate
L2 switches
Host Host
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – Meshed Transports
• vEdge routers are directly • SD-WAN tunnels are built
connected to all the transports through all directly connected
transports
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – Extended Transports
• Each vEdge router is connected • SD-WAN tunnels are built
to a given transports through local and remote
transports
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Transport Redundancy – TLOC Extension
• vEdge routers are connected only to their
respective transports
• vEdge routers build IPSec tunnels across
MPLS INET
directly connected transport and across the
transport connected to the neighboring vEdge
router
• Neighboring vEdge router acts as an underlay
router for tunnels initiated from the other vEdge
vEdge vEdge
• If one of the vEdge routers fails, second
vEdge router takes over forwarding the
traffic in and out of site
• Only transport connected to the remaining vEdge
Site Network router can be used
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
TLOC Extension Configuration
vpn 0 vpn 0
ip route [Link]/32 [Link]
interface ge0/0 interface ge0/0
description MPLS tunnel description INET tunnel
ip address [Link]/30 Add route to ip dhcp-client
tunnel-interface reach br1-vedge2 nat
Do not forget NAT
encapsulation ipsec mpls tunnel end- !
color mpls restrict point tunnel-interface
max-control-connections 1 encapsulation ipsec
MPLS INET
[service list] color biz-internet restrict
! max-control-connections 1
interface ge0/2 [service list]
description INET tunnel !
ip address [Link]/24 interface ge0/2
! ip address [Link]/24
tunnel-interface ge0/0 ge0/0 tloc-extension ge0/0
[Link]/24 dhcp
encapsulation ipsec preference 100 no shutdown
color biz-internet restrict ge0/2 ge0/2 !
max-control-connections 1 [Link]/24 [Link]/24 interface ge0/3
[service list] description MPLS tunnel
! ip address [Link]/24
interface ge0/3 tunnel-interface
ip address [Link]/24 ge0/3 ge0/3 encapsulation ipsec
tloc-extension ge0/0 [Link]/24 [Link]/24 color mpls restrict
no shutdown br1-vedge1 br1-vedge2 max-control-connections 1
! [service list]
ip route [Link]/0 [Link] !
ip route [Link]/0 [Link] ip route [Link]/0 [Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – Path and Headend
• vEdge routers leverage BFD for detecting end-to-end
tunnel liveliness
Data
Center • If intermediate network path through the SD-WAN
fabric fails or if the remote-end vEdge router (e.g.
data center) fails, BFD hellos will time out and
remote site vEdge router will bring down its
relevant IPSec tunnels
Internet MPLS
• Traffic will be rerouted after the failed condition
had been detected
• BFD timers can be tweaked for faster detection
Remote
Site
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Use Cases and Deployment
Models
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud-Delivered Control Flexible Deployment Options
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Viptela hosted Controllers / Public Cloud
Region 1 Region 2
optional/
standby
Private IPs Private IPs vManage
1:1 NAT 1:1 NAT
Public IPs Public IPs
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Hybrid Cloud Controller Deployment
DC/Region 1 DC/Region 2
No NAT optional/
standby
Public IPs Public IPs vManage
DMZ
FW BGP
BGP DMZ
FW
• Control Plane on MPLS and
Internet
• Public IPs are assigned to the
controllers
MPLS INET
• No NAT is used
• For security compliance FW/DMZ
on Internet facing side
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Hybrid Cloud Controller Deployment
DC/Region 1 DC/Region 2
optional/
standby
Private IPs Private IPs vManage
NAT +
DMZ/FW • Control on MPLS and Internet.
BGP NAT +
BGP Public IP DMZ/FW • Private IPs on the controllers.
Public IP • NAT/FW facing the internet
No NAT
NAT • vBond must have Public IP or
MPLS INET sit behind 1:1 NAT
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Public Cloud Controller Deployment
DC/Region 1 DC/Region 2
vpn512 vpn512
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Gateway - DC Site Deployment and Migration
DC/Gateway Site
• Identify Gateway/DC Sites providing
BGP/OSPF connectivity between SD-WAN and legacy sites
• Legacy sites talk to each other directly
Internet SD-WAN
MPLS
OVERLAY
OMP
OMP
OMP Legacy/MPLS Sites
SD-WAN Sites
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Large Enterprise with Global Distribution
WAN Components connected via overlays from Viptela SEN utilizing Internet, LTE, etc.
Viptela
ZTP/Central Done on Monitoring/Syslog Done on
Viptela Connectivity Active-Active
Config/Policy /NetFlow Viptela, Nagios
App-
Done on Built-in/ No
Routing/PfR/Servic Segmentation Multiple VPNs Encryption
Viptela key-mgmt
e Chain
SECURE
CONTROL PLANE
Ethernet Exit
(DSL/Cable/LTE/MPLS)
Internet SECURE
WiFi APs DATA PLANE
SECURE Selective
CONTROL PLANE Traffic Symmetry Done on
Split-Tunnel 80/443 GRE to VPN Topology Full Mesh IAAS and SAAS AWS, SFDC, o365
across regions Viptela
ZScaler
Platinum
(Dual MPLS, Dual Broadband) North America DCs APAC DC Europe DC
Gold
Data Center Data Center
(Single MPLS, Single Broadband) Data Center
DC Core DC Core DC Core
Silver
(Dual Broadband)
Bronze
(Single Broadband)
vEdge Router
Switch
Existing Existing
vEdge vEdge vEdge vEdge
Router Router
Existing Existing
Router vEdge Router vEdge vEdge vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Framework
Centralized and Localized Policies
vManage
NETCONF/YANG
OMP
• With Localized Data policy, also called an access list, you can provision QoS to:
• Classify incoming data packets into multiple forwarding classes based on importance.
• Spread the forwarding classes across different interface queues.
• Schedule the transmission rate or weights for each queue
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Driven WAN Infrastructure
Policy Augmented Dynamic Routing
3
vEdge
WAN
router Execute AAR and Data Policy as received
Dynamic Routing and Policies Combine to
dictate behavior
Access Layer
Branch/DC
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Distribution
Data Policy Control Policy
Local Policies
App Aware Routing Policy VPN Membership Policy
OMP OMP
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Packet Flow Through the vEdge Router
Local Policy,
Centralized Application Aware Shaping and ACL
Routing
Routing Policy
Forwarding Shaping
Re-marking
Path selection based on SLA Policer, ACL
4
2 6
1 3 5
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Centralized (vSmart) Policy Architecture
• vSmart Policies consist of these building blocks:
• Lists used for defining targets of policy application or matching
• Policies controlling aspects of control and forwarding
Control Policy
Application Aware Policy
Data Policy
cflowd-template
vpn-membership-policy
• Policy Application to control towards what a policy is applied
Site-oriented and defined by a site-list
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Routing Policy Architecture
• Routing Policies are traditional routing policies
• Attaches to BGP or OSPF locally on the vEdge
• Used in the traditional sense for controlling BGP and OSPF
Information exchange
Attributes
Path Selection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Construction
• Lists – list of
data-prefix-list Policy Definition Policy Application
prefixes for use with a data-
policy
• prefix-list – list of • Control Policies
prefixes for use with any
affect overlay routing • An apply directive
other policy
• Site-list – list of site-id:s
• Application Aware is used in
for use in policy and apply- Routing policy is used conjunction with
policy in conjunction with site lists to
• Tloc-list – list of tloc:s SLAs to steer traffic enable specific
for use in policy • Data policies provide policies at
• Vpn-list – list of vpn:s for VPN level policy based specific locations
use in policy routing
• Colors – List of colors for
use in policy
• SLAs – SLA definitions
Centralized policy definition configured on vManage and enforced across entire network
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Construction - Lists
• application-list used in data-policy to define
policy specific applications for traffic matching and
lists
data-prefix-list app1 policy actions
ip-prefix [Link]/32
port 100 • data-prefix-list used in data-policy to define
! prefix and upper layer ports in various
prefix-list pfx1 combinations for traffic matching
ip-prefix [Link]/32
! • prefix-list used in control-policy to define
site-list site1
site-id 100
prefixes for RIB matching site-list used in
! control-policy and apply-policy to match source
tloc-list site1_tloc sites or define sites for policy application
tloc [Link] color mpls
vpn-list vpn1 • tloc-list used in control-policy to define
vpn 1 tlocs for RIB matching and to apply redefined
!
!
tlocs to vroutes
• vpn-list used in control-policy to define
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential prefixes for RIB matching, in data-policy and
vSmart Policy Construction – Policies
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Example
apply-policy
site-list site1 Apply the defined policy
control-policy prefer_local out towards the sites in
!
site-list
policy Define the lists required for
lists apply-policy and for use
site-list site1
site-id 100
within the policy
tloc-list prefer_site1
tloc [Link] color mpls preference 400
!
control-policy prefer_local Define the actual policy to
sequence 10
be applied
match route
site-list site1
!
Lists previously defined
action accept used within policy
set
tloc-list prefer_site1
! Note: Items listed as presented in node
! configuration. The order in which elements are
! configured should be lists, control-policy then
apply-policy
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Processing
• Policies are processed sequentially. Order is important!
• When a match occurs, the matched entity is subject to the configured
action of the sequence and is then no longer subject to continued
processing.
• Any entity not matched in a sequence is subject to the default
action for the policy.
• Any node will make use of any and all available routing information
• In a multi-vSmart deployment, every vSmart acts independently to
disseminate information to other vSmarts and vEdges
• vManage acts as the entity to ensure all vSmarts are synchronized.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
1. Control Policies
• Control policies are executed on vSmarts to influence overlay
routing.
• Control Policies are used to enable the following services:
• Service Chaining
• Traffic Engineering
• Extranet VPNs
• Service path affinity
• Arbitrary VPN Topologies
• Control Policy is a powerful tool for any type of path
construction that simplifies policy operations by being
centrally managed.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Centralized Control Policy: Inbound vs.
Outbound
• Inbound Policy: determines
which routes are installed in
the local routing database of
the vSmart controller.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
2. Application-Aware Routing Policy
• Application-aware routing consists of three components:
Identify the applications of interest. To determine which applications are running on
vEdge routers, you enable application visibility on these devices. Then you configure
an application-aware routing policy on the vSmart controller, which defines the
applications of interest and the data plane tunnel performance characteristics
required to transmit an application's data traffic. These characteristics are called
a service-level agreement (SLA). The controller automatically pushes the policy to
the appropriate vEdge routers.
Monitor and measure data plane tunnel performance is done automatically and
continuously by the vEdge routers, by tracking BFD Hello packets. Application-aware
routing periodically polls the performance statistics to calculate the packet jitter
and latency and packet loss information for each tunnel. The default polling interval
is good for most network situations, but you can modify it to meet specific business
needs.
Map application traffic to a specific data plane tunnel is done on the vEdge routers,
based on the SLA requirements defined in application-aware routing policy and based
on the real-time performance of the vEdge routers' data plane tunnels. You can modify
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application Aware Routing
• An app-route policy is defined through the following steps:
• Define the required SLA classes
• Define the app-route-policy
• Apply the app-route-policy towards the applicable sites
• The SLA-class defines the required loss, latency and jitter
thresholds for the application that is to go via the overlay
path
• The app-route-policy defines the traffic that is to belong to
a defined class in a fashion similar to a data-policy
• Configuring an app-route-policy includes a reference to a
VPN-list to dictate which VPNs will benefit from the policy
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application-Aware Routing Policy
Configuration
Step 1: Create a list of sites to which the
application-aware routing policy is to be applied
policy
lists
site-list mySites Step 3: Create lists of applications, IP
site-id 100-200 prefixes, and VPNs to use in identifying
! application traffic of interest (in the match
section of the policy definition
policy
lists
Step 2: Create SLA classes and traffic vpn-list myVPN
vpn 10
characteristics to apply to matching application !
data traffic.
policy data-prefix-list approute-Prefixes
sla-class bulk-data-sla ip-prefix [Link]/16
latency 150 !
! app-list myApps
sla-class critical-data-sla app office365
loss 5 app salesforce
latency 150 !
! !
sla-class voice-sla !
loss 1
latency 100
jitter 5
!
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application-Aware Routing Policy
Configuration
Step 4: Create an application-aware routing Step 5: Within the policy, create one or more
policy instance and associate it with a list of numbered sequence of match–action pairs
VPNs
policy
policy
app-route-policy myApproutePolicy
app-route-policy myApproutePolicy
vpn-list myVPN
vpn-list myVPN
!
sequence 10
!
match
app-list myApps
!
action
Step 6: Specify the default action for the sla-class critical-data-sla preferred-color mpls
policy !
policy
app-route-policy myApproutePolicy !
vpn-list myVPN sequence 20
default-action sla-class bulk-data-sla match
! dscp 46
! !
! action
sla-class voice-sla preferred-color mpls
!
!
sequence 30
Step 7: Apply the policy to a site list: match
destination-data-prefix-list approute-Prefixes
apply-policy !
site-list mySites action
app-route-policy myApproutePolicy backup-sla-preferred-color public-internet
! sla-class bulk-data-sla preferred-color biz-internet
! !
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
3. Data Policy - Applications and Services
• Data Policies provide the functionality equivalent to traditional Policy
Routing.
• Data policies are configured and applied centrally (vSmart), then pushed to
vEdge to enforce the configured policy in the data plane
• Some of the applications enabled by Control Policies can also be enabled by Data
Policies, in addition to more traditional Policy Routing as well as data-plane bound
functions
apply-policy
site-list mySites
data-policy myDataPolicy (all | from-service | from-tunnel)
!
!
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
4. Cflowd flow data collection
• Cflowd flow collection is enabled by means of a vSmart policy
• Capturing and exporting flow data is controlled via 2 different
policies:
• Cflowd-template for configuring flow cache behavior and flow export
• Data-policy for selection of traffic subject to flow data collection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
VPN Membership Policy Example
Policy Policy
lists vpn-membership acme_1
site-list sites_1 sequence 10
site-id site1 match vpn-list sites_1
site-id site2 action accept
! !
site-list sites_2 !
site-id site3 default-action reject
site-id site4 !
! vpn-membership acme_2
vpn-list sites_1 sequence 10
vpn 10, 20 match vpn-list sites_2
! action accept
vpn-list sites_2 !
vpn 30, 40 !
! default-action reject
! !
! !
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Single Pane of Glass Operations
vManage GUI
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Template-Based Configurations
Centralized Device Configuration Enforcement
• Templates are attached to provisioned
vEdge routers
• Variables are used for rapid bulk
configuration rollout with unique per-
device settings
• Local configuration changes are not
allowed
- Prevents configuration drift
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Granular Policies
Centralized Control over Fabric Behavior
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Troubleshooting and Verification
Transparent Operations
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Self-Healing
Software Upgrade and Configuration Change
Failed
2 Upgrade 1 vManage
Attach Template
Active Software A Rollback
Available Software B
Activate 3
Available Software C Connectivity
2 Lost
1 Available Software D
Rollback
3
vEdge Router vEdge Router
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Current Orchestration and APIs
REST
vManage Management
Netconf Monitoring
Provisioning
Syslog Troubleshootin
g
vSmart * [Link]
SNMP
cFlowd*
CLI
Secure
Internet Control Plane
4G/LTE
MPLS
Secure
Data Plane
vEdge Routers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Network Automation
decouple Lifecycle of Product-Services and Network Resources Services
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN MSP Management Options
NSO/vManage Split NSO Single Entry Point
REST/NETCONF
REST/NETCONF REST
NSO vManage
REST Other CFP vBranch CFP vManage NED
SDWAN –SITE vManage
CFP NED
vBranch
CFP NETCONF vManage
NETCONF NETCONF
NETCONF
• vManage and NSO Entry Point (REST APIs) • NSO Single Entry Point
• vManage improved with NSO (and vBranch, SDWAN, • SDWAN network wide Service Model that includes:
potentially SAE CFP) VNFs instantiation (including 3rd party VNFs) and vEdge
activation
• vManage and/or NSO as potential entry point
Controller instantiation
• Reporting and Alerts Device template definition
SDWAN policies definition
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Topology definition
vEdge Cloud Provisioning / Activation
vManage Control and Policy
Network Service Orchestrator (NSO) 2 Elements
7
3 Full Registration and
Configuration
6
4
VNFs instantiated and loaded with vEdge
Bootstrap Configuration cloud-
init file. Chaining of VNFs Virtual Networks
occurred if requested. (ENCS)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NSO with the vBranch
Function Pack
On Boarding ENCS/NFVIS
Network Service Orchestrator (NSO) Network Service Orchestrator (NSO)
1
NFVIS 5
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NSO with the SDWAN-SITE
Function Pack
vEdge-Cloud Onboarding process
• 1) Upload vEdge Certified Serial Numbers onto vManage
NSO Network Service Orchestrator (NSO) (one time setup)
• 2) Get the unclaimed vEdge Cloud router list from
PnP Core FP (vBranch) Core FP (SDWAN-SITE)
vManage
• 3) Instruct vManage to generate a Bootstrap
1 Configuration file for the vEdge Cloud Router (OTP,
2 UUID, vBond, Org Name)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics
Customer Data Data Transfer and Storage
• Client authenticated and data securely
transmitted from vManage to vAnalytics
• Data storage isolation between
vAnalytics customers
Clusters Data Lake
• No PII (Personal Identifiable
Information) is collected
Data Correlation and Algorithms
• Only management data (stats, flows)
information collected
• All algorithms visualization done on a
per-customer basis
• IP Addresses collected for provider
look-ups
• Peer benchmarking (future use cases)
only on a group basis. No individual
customer data used
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Power of Analytics
Application Centric (Based on DPI/cflowd)
1. Bandwidth Usage:
1. Identification of top sources / top destinations / top application (family)
2. Drill-down into information on a per-Site basis
3. Identification of top sources
2. Application Performance:
1. Application to tunnel-binding and performance information
3. Anomaly Detection:
1. Baseline of Application usage. Anomaly detection based on overall application
usage / by Family / by Site
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Power of Analytics
Network Centric
1. Site Availability (SD-WAN value prop)
1. List of Sites with down-time comparing to TLOCs with their down-time
2. Network Availability
1. List of sites by down-time
2. Comparison of Site down-time vs TLOC down-time (SD-WAN value prop)
3. Down site count on a time basis with the ability to drill-down into Sites and
downtimes
4. Carrier Performance
1. App-Route stats based on a per-carrier basis
2. Ability to drill-down on a specific carrier and visibility into various remote
© 2018
carrier connectivity
Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics Dashboard
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics – BW Consumption by Applications
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics – Network Health by Carriers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Pricing Structure
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SDWAN Pricing Model
The Cisco SDWAN pricing model consists of two components
1. Subscription* license (1YR, 3YR and 5YR) for Viptela software charged per CPE. This cost is dependent on
two factors:
• Service bandwidth. Slide 5 covers how service bandwidth is calculated.
• Features: Slide 3 covers feature buckets.
Subscription
Perpetual cost of Viptela Operational
cost of software cost of
Viptela CPE (Includes SD- Viptela
hardware WAN controller solution
+ CPE software)
*Note: Subscription cost of Viptela software includes cost of SD-WAN controllers, 24x7x365 Viptela support, next day hardware
replacement for Viptela CPE, software upgrades on all components and the cost of hosting the Viptela controllers in the
Viptela cloud.
**Note: CPE can be Viptela manufactured or in the case of Virtual CPE customer/partner provisioned. Cost here implies
Viptela CPE only.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Feature License Tiers
Plus Professional Enterprise
SDWAN management, SDWAN management, SDWAN management,
controllers Analytics
controllers controllers
Dynamic
Dynamic
Routing
Routing
Hub
Hub Spoke IaaS
Hub Spoke IaaS
Cloud
Cloud
AAR
AAR AAR
MPLS Interne Local Interne
MPLS MPLS Internet
t breakout E2E t
Segmentation SAAS E2E SAAS
Segmentation
• Fabric: Management, Controllers, ZTP • All Plus tier features • All Professional tier features
• Routing: Static • Routing: Dynamic routing (OSPF/BGP) • Segmentation: Unlimited VPNs
• Topology: Hub-n-spoke only • Topology: Mesh topology, any • Analytics: vAnalytics platform
• Internet/Cloud: NAT, Split tunnel, IPSec • Internet/Cloud: Cloud onRamp for IaaS/SaaS • Optimizations: TCP Optimization
IKEv1/v2, GRE • Policy: Control policy, service insertion,
• Policy: Local ACL only, Data policy extranet
• QoS • Segmentation: 5 VPNs (transport + 4x
• SLA: Application aware routing (5 tuple service)
only) • SLA: Application aware routing (DPI)
• Segmentation: 2 VPNs (service + • Multicast
transport)
•© Visibility : DPI
2018 Cisco and/or for visibility
its affiliates. All rightsonly
reserved. Cisco Confidential
Pricing Tiers - Detailed
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 247
Bandwidth Licensing
Bandwidth entitlement* on vEdge is the sum of
peak bandwidth (either upstream or downstream)
across all WAN circuits.
TLOC
TLOC extension interface bandwidth is not
extension included in bandwidth entitlement.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Key Takeaways
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN Rollout and Positioning
Phase 1 – FY18 Phase 2 – 1HFY19 Phase 3-2HFY19
No Integration Platform Integration Management Integration
Deployment Scenarios
DNA Center
vManage vManage + SD-WAN
-
-or- Meraki or- Meraki -or- Meraki
Dates
Late 2018
GPL = Feb’18 GA – Jul’18
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Clarification On SDWAN Terminology
"SDWAN Enabled Only Features Highlighted In The Next Slide Are Included In The SD-WAN
ISR"
Image
Traditional IOSXE With IWAN capabilities, for ISR4K, ASR, CSR &
ISR ISRv
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
251
Integration Roadmap In Planning
CSR 1000V
• 10 Mbps to 10 Gbps • Up to 100 Mbps • Up to 250 Mbps • Up to 2 Gbps • 2.5-200Gbps
• DNA Virtualization • Fixed and fanless • Fixed and fanless • Modular • High-performance
• Extend enterprise • Enterprise-class • SD-WAN ready • Integrated service w/hardware
routing, security & branch routing • Integrated wired & container assist
management to cloud with security wireless access applications • Hardware & software
• Compute with UCS E redundancy
Virtual
ISRv • 50 Mbps to 2.5 Gbps Cisco ENCS • Service chaining virtual
• Virtual enterprise-class networking functions
• Run on x86 compute platform • Modular WAN connectivity
• ENFV orchestration & management • Open for 3rd party services &
apps
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
MSP: SD-WAN Deployment Options
Virtual Managed Services Cisco
NSO + Core FPs
Deployment Model (VMS) NG SDWAN
vEdge vEdge
(vitual/Physic VNFs (vitual/Physic VNFs
al) al)
Data Plane
ENCS ISR vEdge ISR ENCS ISR
Converged Converged Converged
IOS / IOS / IOS /
vEdge SW vEdge SW vEdge SW
(Future) (Future) (Future)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
25