0% found this document useful (0 votes)
57 views247 pages

Cisco Sdwan - Deep Dive

The document provides an overview of Cisco's SD-WAN solution, highlighting its integration with Viptela's architecture and its commitment to various existing products. It details the architecture's components, including orchestration, control, data, and management planes, along with the benefits of a cloud-first approach and simplified deployment. Additionally, it outlines the product offerings, including various vEdge routers designed for different deployment scenarios and capacities.

Uploaded by

vincenzo20210428
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
57 views247 pages

Cisco Sdwan - Deep Dive

The document provides an overview of Cisco's SD-WAN solution, highlighting its integration with Viptela's architecture and its commitment to various existing products. It details the architecture's components, including orchestration, control, data, and management planes, along with the benefits of a cloud-first approach and simplified deployment. Additionally, it outlines the product offerings, including various vEdge routers designed for different deployment scenarios and capacities.

Uploaded by

vincenzo20210428
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Cisco SDWAN

Deep Dive
Jean-Marc Barozet
Principal Engineer – SDWAN/NFV Technical Marketing
Cisco + Viptela = Cisco SDWAN

Cisco is committed Cisco is committed Cisco will commit Cisco will address
to Viptela’s solution to the existing IWAN significant the broadest set
and architecture 2.x, ISR 4K, ASR1K, engineering resources of
ENCS, CSR, and to bring next- use cases to
Meraki SD-WAN generation SD-WAN deliver successful
offerings. solutions to market customer outcomes

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Why Viptela?

Cloud-first Accelerate key Sophisticated, but


management SD-WAN use cases; still simple to deploy
with flexible Cloud-edge and and operate
deployment options Segmentation

Cisco Digital Complements Cisco’s Enterprise Networks architecture


Network strategy
Architecture
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential TECCRS-2004
Cisco Fabric Architectures
Multitenant/ Rich Highly
Cloud-Delivered Analytics Automated

USERS

SDWAN
Cloud
OnRamp
.… IoT

ACI
DC Fabric
DEVICES
APPs
SDA Fabric DC

(branch & campus)


SDWAN Fabric
IaaS

THINGS SaaS

End-to-end Context
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
From Managed WAN To SDWAN Network-as-a-
Service 1
Cloud delivered WAN with
operational simplicity &
End-point flexibility: Cloud Delivered Analytics analytics
4 • Physical or virtual
• Rich services or lite
• Branch, Agg, Cloud 3 Application QOE
USERS
5
Cloud
SD-WAN .… Use-Cases

DC
WAN
L E A R N IN G

DEVICE IaaS
D N A C enter Apps
S
Policy Autom ation Analytics

IN T E N T C O N TEX T SaaS
Intent-based
N etw ork Infrastructure

vDC
S E C U R IT Y

THINGS

0 Transport Independent Superior security architecture


2 – cloud based & on-prem
WAN Fabric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Why Fabric Architectures
• Simple: Single Hop, Input / Output
• Overlay on Any Transport
• Consistent Policy Enforcement Points
• Carry New and Useful Context
• User / Device Identity, Network-wide
• Policy Abstraction at User / Group
and Application levels
• Policy at Fabric Edge. Over-the-top.
• Increased Simplicity. Seamless
Mobility
• Leverage Automation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Solution Overview

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Architecture
The Power of Abstraction
Orchestration Plane

vManage

APIs Management Plane


3rd Party
vAnalytics
Automation

vBond
Control Plane
vSmart Controllers

MPLS 4G

INET
vEdge Routers

Data Plane
Cloud Data Center Campus Branch SOHO

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Orchestration Plane
Orchestration Plane

vManage Cisco vBond

APIs

3rd Party • Orchestrates control and


vAnalytics management plane
Automation
• First point of authentication
vBond (white-list model)
• Distributes list of vSmarts/
vSmart Controllers
vManage to all vEdge routers
• Facilitates NAT traversal
MPLS 4G
• Requires public IP Address
INET
vEdge Routers [could sit behind 1:1 NAT]
• Highly resilient

Cloud Data Center Campus Branch SOHO

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Control Plane
Control Plane

vManage Cisco vSmart

APIs
• Facilitates fabric discovery
3rd Party
vAnalytics • Dissimilates control plane
Automation
information between vEdges
vBond • Distributes data plane and app-
aware routing policies to the
vSmart Controllers
vEdge routers
• Implements control plane policies,
MPLS 4G
such as service chaining, multi-
INET topology and multi-hop
vEdge Routers
• Dramatically reduces control plane
complexity
• Highly resilient
Cloud Data Center Campus Branch SOHO

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Data Plane Data Plane
Physical/Virtual

vManage Cisco vEdge

APIs • WAN edge router


• Provides secure data plane with
3rd Party
vAnalytics remote vEdge routers
Automation
• Establishes secure control plane
vBond with vSmart controllers (OMP)
• Implements data plane and
vSmart Controllers application aware routing policies
• Exports performance statistics
MPLS 4G • Leverages traditional routing
protocols like OSPF, BGP and
INET
vEdge Routers VRRP
• Support Zero Touch Deployment
• Physical or Virtual form factor
(100Mb, 1Gb, 10Gb)
Cloud Data Center Campus Branch SOHO

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Solution Elements
Management Plane
Management Plane

vManage
Cisco vManage
APIs
• Single pane of glass for Day0,
3rd Party Day1 and Day2 operations
vAnalytics
Automation
• Multitenant with web scale
vBond • Centralized provisioning
• Policies and Templates
vSmart Controllers
• Troubleshooting and
Monitoring
MPLS 4G
• Software upgrades
INET
vEdge Routers • GUI with RBAC
• Programmatic interfaces
(REST, NETCONF)
Cloud Data Center Campus Branch SOHO • Highly resilient

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SDWAN Topology SITE-ID

• Unique per-site numeric


identifier used in policy
Site 1 Site 2 application

R11 R12 R21 R22 Site6


[Link] [Link] [Link] [Link]
vManage

vbond61

vsmart66
[Link]/16 MPLS [Link]/16 INET
vsmart67

TLOC

• Transport attachment point and next


R41 hop route attribute.
R31
[Link] [Link] • Comprises of “system-ip”, “color”
R51 R52 and “encap”
[Link] [Link]

SYSTEM-IP COLOR

• Unique
Site 3 identifier per-device.
Site 4 Site 5 • Each tunnel interface is assigned a
• Router-id for BGP, OSPF “color”
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Viptela Fabric Terminology
• Overlay Management Protocol – Control plane protocol distributing
reachability, security and policies throughout the fabric
• Transport Locator (TLOC) – Transport attachment point and next hop
route attribute
• Color – Control plane tag used for IPSec tunnel establishment logic
• Site ID – Unique per-site numeric identifier used in policy
application
• System IP – Unique per-device (vEdge and controllers) IPv4 notation
identifier. Also used as Router ID for BGP and OSPF.
• Organization Name – Overlay identifier common to all elements of
the fabric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Network-as-a-Service: SDWAN Offering
Multi-tenant gateway
Multi-tenant: Control, Management,
2
Orchestration With vManage, vManage Existing / home
3 grown MNS services
vAnalytics and VMS/NSO VMS
vSmart
(e.g. UCaaS)
vBond

NSO

SaaS
Business VPN
4 Cloud networking
1 Gray, White or Black box
Internet

IaaS
… 3rd
Party (or) 4G/LTE

MSP
X86 DC

NFVI MSP Shared


Services

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multi-Tenant Orchestration Solution
Multi-Tenant vManage

vSmart vContainer1 vSmart vContainer2 Multi Tenant vBond

Customer1 vEdge Routers Customer2 vEdge Routers Customer3 vEdge Routers

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SDWAN Products

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Platform Options
Providing for flexibility in deployment

Branch Services SD-WAN


vEdge 100 vEdge 1000 vEdge 2000
ISR 1000 ISR 4000 ASR 1000

• 100 Mbps • Up to 1 Gbps • 10 Gbps


• 4G LTE & Wireless • Fixed • Modular
• 200 Mbps • Up to 2 Gbps • 2.5-200Gbps
• Next-gen • Modular • High-performance vEdge 5000
connectivity service w/hardware
• Integrated service
• Performance assist
flexibility containers
• Hardware & software
NEW
• Compute with UCS E
redundancy • ~30 Gbps
• Modular

Virtualization Public Cloud


ENCS 5100 ENCS 5400

• Up to 250Mbps • 250Mbps – 2GB

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco vEdge Routers

1/10Gb+
vEdge 5000/2000

1Gb
vEdge Cloud
vEdge 1000

100Mb

vEdge 100

Small Office Branch Large Campus Virtualized Branch


Home Office Campus Data Center Cloud
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential TECCRS-2004
vEdge Platform Portfolio
SOHO Head-End Higher Capacity IaaS & Cloud
Branch NFV, vCPE
SMB Aggregation Aggregation Interconnect
(1 G) (N x cores)
(100 M) (10 G) (20 G+) (Nx cores)

vEdge-100 vEdge-1000 vEdge-2000 vEdge-5000 vEdge-Cloud vEdge-Cloud


Tunnels: 250 Tunnels: 1500 Tunnels: 6000 Tunnels: 6000 Tunnels: 2500 Tunnels: 2500
Routes: 25k Routes: 128k Routes: 125k Routes: 128k Routes: 128k Routes: 128k
VPN’s: 62+2 VPN’s: 62+2 VPN’s: 62+2 VPN’s: 62+2 VPN’s: 62+2 VPN’s: 62+2

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-1000 and vEdge-2000 Routers
vEdge 1000 vEdge 2000

 1 Gbps AES-256  10 Gbps AES-256


 1RU, standard rack mountable  1RU, standard rack mountable
 8x GE SFP (10/100/1000)  4x Fixed GE SFP (10/100/1000)
 TPM chip  2 Pluggable Interface Modules
 3G/4G via USB (or) Ethernet  8 x 1GE SFP (10/100/1000)
 Security, QoS  2 x 10GE SFP+
 Dual Power supplies  TPM chip
(external)  3G/4G via USB (or) Ethernet
 Low power consumption  Security, QoS
 Dual power supplies (internal)
 Redundant fans

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-100 Routers
vEdge 100m vEdge 100mw

vEdge 100

 100 Mbps AES-256  100 Mbps AES-256  100 Mbps AES-256


 5x 1000Base-T  1RU  1RU
 TPM chip  5x 1000Base-T  5x 1000Base-T
 1x POE port  1x POE port
 Security, QoS
 2G/3G/4G LTE  2G/3G/4G LTE
 External AC PS
 Internal AC PS  802.11a/b/g/n/ac
 Kensington lock
 1x USB-3.0  Internal AC PS
 Fan-less  TPM Board-ID  1x USB-3.0
 9” x 1.75” x 5.5”  Kensington lock  TPM Board-ID
 GPS  Low power fan  Kensington lock
 GPS  Low power fan
 GPS

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge 5000
Campus and Data Center Edge

Platform Capabilities:

• 4 Network Interface Modules


(NIM) slots

• Variety of NIM options


8 x 1G
4 x 10G
2 x 40G

• Feature parity with Cisco vEdge


2000 platform

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Shipping Now
Q3 CY17

ENCS 5000 Series Portfolio

ENCS5412
12-Core
ENCS5408
NEW 8-Core
CiscoLive 2017 Las Vegas
ENCS5406
6-Core • ISRv + 9 core VNF
ENCS5104 PoE
4-Core
• ISRv + 5 core VNF
• PoE

ISRv + 3 core VNF


LAN Ports
ISRv + 2 core VNF
NIM LTE, DSL, T1
LTE on Radar
HDD, SSD
RAID, HW Crypto

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Network Functions Virtualization
Infrastructure

Orchestration and Management (MANO)

Virtual WAN Virtual Wireless


Virtual Router Virtual Router Virtual Firewall
Optimization LAN Controller 3rd Party VNFs
(ISRv) (vEdge) (ASAv)
(vWAAS) (vWLC)

Network Functions Virtualization Infrastructure Software (NFVIS)

ISR 4000 + UCS-E- Enterprise Network Compute


UCS C-Series COTS
Series Systems (ENCS)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
vEdge Cloud Virtual Routers
Virtualized Branch or Cloud
On-Premise Hosted
vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud vEdge Cloud

ESXi or KVM AWS or Azure

VM VM
Physical Server Throughput:
2x vCPU 500Mb/s
4x vCPU 1Gb/s
8x vCPU 1.5Gb/s
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controllers
Cloud or On-Premise Delivered
On-Premise Hosted
vBond* vManage vSmart vSmart vBond vManage vSmart vSmart

ESXi or KVM AWS or Azure

VM VM

Physical Server vContainer vContainer

* Can be deployed as physical vEdge appliance


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco’s Commitment

Cisco is committed Cisco is committed Cisco will commit Cisco will address
to Viptela’s to the existing significant the broadest set
solution and ISR 4K, ASR1K, engineering of
architecture ENCS, CSR, IWAN resources to bring use cases to
2.x, and Meraki next-generation SD- deliver successful
WAN solutions to
SD-WAN offerings. partner and
market
customer outcomes

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Fabric
Instantiate Control Plane
Elements

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud-Delivered Control Flexible Deployment Options

Cisco Cloud Ops MSP Ops Team Enterprise IT

Deploy Deploy Deploy

vManage vManage vManage

vSmart vBond vSmart vBond vSmart vBond


Viptela MSP Private
Cloud Cloud Cloud

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controllers Deployment Methodology
On-Premise/SP Hosted Cloud Hosted

vBond vManage vSmart vSmart vBond vManage vSmart vSmart

ESXi or KVM AWS or Azure

VM VM

Physical Server Container Container

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage Deployment
NIC1 NIC0
 Cloud or on-premise
deployment
 Separate interfaces for
VPN0 VPN512 control and management
 Separate VPNs for control and
eth1 eth0 management
Control Management Zone-based security
Interfac Interface
e  Minimal configuration for
bring-up
ESXi, KVM, AWS, MS Azure
Connectivity, System IP,
Site ID, Org-Name, vBond IP

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vBond Deployment
NIC1 NIC0
 Cloud or on-premise
deployment
 Separate interfaces for
control and management
VPN0 VPN512
 Separate VPNs for control and
Ge0/0 eth0 management
Zone-based security
Control Management
Interfac Interface  Minimal configuration for
e
bring-up
Connectivity, System IP,
ESXi, KVM, AWS, MS Azure Site ID, Org-Name, vBond IP
(local)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Deployment
NIC1 NIC0
 Cloud or on-premise
deployment
 Virtual machine or container

VPN0 VPN512
 Separate interfaces for
control and management
eth1 eth0  Separate VPNs for control and
Control Management management
Interfac Interface Zone-based security
e
 Minimal configuration for
ESXi, KVM, AWS, MS Azure
bring-up
Connectivity, System IP,
Site ID, Org-Name, vBond IP
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Fabric
Establish Control Plane

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Software Defined Centralized Control
• Virtual Fabric over any transport
• Virtual or Physical Platforms
Control Elements (vEdge)
• Centralized reachability,
security and application policies
• Secure Channel to SD-WAN
Control Plane
Controller (vSmart, vBond,
DTLS/TLS
vManage)
Single extensible control plane
Operates over DTLS/TLS authenticated
and secured tunnels
• Data Plane tunnels between vEdges
• Dramatically lowers complexity
and increases overall solution
scale

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Certificate-Based Trust
Administrator • Bi-directional certificate-based trust between all
Signed
Defined
vEdge List elements
Controllers
Public or Enterprise PKI
vManage • White-list of valid vEdges and controllers
Certificate serial number as unique identification

vBond vSmart

vEdge

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Appliance – Router Identity
During Manufacturing
• Each physical vEdge router is uniquely
TMP identified by the chassis ID and certificate
Chip serial number
• Certificate is stored in onboard Temper Proof
Module (TPM)
- Installed during manufacturing process

Device
• Certificate is signed by Avnet root CA
Certificate - Trusted by Control Plane elements

• Symantec root CA chain of trust is used to


validate Control Plane elements
• Alternatively, if used, Enterprise root CA
Root Chain chain of trust can be used to validate Control
Plane elements
- Can be automatically installed during ZTP
In Viptela Software
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Cloud – Router Identity
Issued by vManage
• OTP/Token is generated by vManage
- One per (chassisID, serial number) in the uploaded
vEdge list

• OTP/Token is supplied to vEdge Cloud in Cloud-Init


during the VM deployment
Device
Certificate • vManage issues self-signed certificate for the
vEdge Cloud post OTP/Token validation
- vManage removes OTP to prevent reuse

• Symantec root CA chain of trust is used to


validate Control Plane elements
• Alternatively, if used, Enterprise root CA chain
Root Chain of trust can be used to validate Control Plane
elements
- Can be provided in Cloud-Init
In Viptela Software
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane Whitelisting – Controllers
Administrator • Administrator adds controllers in the
Defined vManage GUI
Controllers

vManage

x.509

• Automated certificate signing through


Symantec
x.509 x.509 Can use Enterprise CA
• Controllers list is distributed by
vBond vSmart
vManage to all the controllers
Controllers’ certificates serial
numbers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart ⟺ vBond
Validate: Root trust, certificate serial,
org-name • Symantec signed certificate identity
(default)
• vBond validates:
vBond
Root Trust for vSmart certificate root CA
Certificate serial number against authorized
white-list (from vManage)
DTLS Signed Organization name (received certificate OU)
against locally configured one
• vSmart validates:
Root vSmart Trust for vBond certificate root CA
Organization name (received certificate OU)
against locally configured one
Validate: Root trust,
org-name
• Persistent DTLS connection comes up
vBond is the server
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage ⟺ vBond
Validate: Root trust, certificate serial,
org-name • Symantec signed certificate identity
(default)
• vBond validates:
vBond
Root Trust for vManage certificate root CA
Certificate serial number against
authorized white-list (from vManage)
DTLS Signed Organization name (received certificate OU)
against locally configured one
• vManage validates:
Root vManage Trust for vBond certificate root CA
Organization name (received certificate OU)
against locally configured one
Validate: Root trust,
org-name
• Persistent DTLS connection comes up
vBond is the server
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart ⟺ vSmart
Validate: Root trust, certificate serial,
org-name
• Redundant vSmart deployment
• Symantec signed certificate identity
Root
vSmart (default)
• Each vSmart validates:
Trust for other vSmart certificate root CA
TLS/DTLS Signed Certificate serial number against
authorized white-list (from vManage)
Organization name (received certificate
vSmart
OU) against locally configured one
Root
• Persistent DTLS/TLS connection comes up
vSmart with highest public IP address is
Validate: Root trust, certificate serial, the server
org-name

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage ⟺ vSmart
Validate: Root trust, certificate serial, • Symantec signed certificate identity
org-name (default)
• vSmart validates:
Trust for vManage certificate root CA
vSmart Certificate serial number against authorized
Root
white-list (from vManage)
Organization name (received certificate OU)
against locally configured one
TLS/DTLS Signed
• vManage validates:
Trust for vSmart certificate root CA
Certificate serial number against authorized
Root vManage
white-list (from vManage)
Organization name (received certificate OU)
against locally configured one
Validate: Root trust, certificate serial,
org-name
• Persistent DTLS/TLS connection comes up
vSmart is the server
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane Whitelisting – vEdge
vEdge List Identity
• Administrator uploads digitally
(White-List) Trust
signed vEdge list in the vManage GUI
Valid
- White-list for vEdge routers
Invalid
- Downloadable from Viptela support page
Staging

vManage

x.509

• Administrator decides on identity


vSmart vBond
trust
Valid, invalid, staging
x.509 x.509

• vEdge list and identity trust are


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
distributed by vManage to vSmart and
Plug-n-Play vEdge Secure Bring-up (Zero
Trust)
Administrator Installer
ZTP Identity Trust
Server

vEdge List vEdge Configuration Network Power


(White-List) Template

vManage
DHCP

TPM

vEdge
Identity
vSmart vBond (X.509)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Zero Touch Provisioning – vEdge Appliance
Control and Policy
Zero Touch Provisioning Elements
Server

2
3 5

Full Registration and


Configuration
1
4

Assumption:
 DHCP on Transport Side (WAN)
 DNS to resolve [Link]*

vEdge
 Delivered as-a-Service
* Factory default config
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Zero Touch Provisioning – vEdge Cloud
vManage Control and Policy
Elements
#cloud-config
vinitparam: 1
- otp : 139a24ccd4add6bc0278fde0cb366f60
- vbond : [Link]
- uuid : 0a4a4c78-35a8-4c1c-bbd2-e02516606fd7
- org : Cisco Sy1 - 19968

Cloud-Init
VM
NSO 3
Provisioning
(SDWAN-SITE FP) Tool
5
Full Registration
2
and Configuration

Boot using cloud-init


information.

vEdge Cloud

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Single-Tenant ZTP Workflow

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ZTP Process
1. The hardware vEdge router powers up.
2. The router contacts a DHCP server and receives its IP address from the
server.
3. The router contacts a DNS server to resolve the hostname
[Link] and receives the IP address of the Viptela ZTP server
4. The router connects to the ZTP server. The ZTP server verifies the
vEdge router and sends the IP address of the vBond orchestrator. This
is a vBond orchestrator that is in the same organization as the vEdge
router.
5. The router establishes a transient connection to the vBond orchestrator
and sends its chassis ID and serial number. (At this point in the ZTP
process, the router does not have a system IP address, so the
connection is established with a null system IP address.) The vBond
orchestrator uses these two numbers to verify the router. The vBond
orchestrator then sends the IP address of the vManage NMS to the
router.
6. The router establishes a connection to the vManage NMS and is verified
by the NMS. The vManage NMS sends the router its system IP address.
7. The router re-establishes a connection to the vBond orchestrator using
its system IP address.
8. The router re-establishes a connection to the vManage NMS using its
system IP address. If necessary, the NMS pushes the proper software
image to the vEdge router. As part of the software image installation,
the router reboots.
9. After the reboot, the router re-establishes a connection to the vBond
orchestrator, which again verifies the router.
10. The router establishes a connection to the vManage NMS, which pushes
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
the full configuration to the router. (If the router has rebooted, it
Multi-Tenant ZTP Workflow

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Appliance ⟺ vBond, vSmart, vManage
Validate: Root trust,
Validate: Root trust,
Validate: Root trust,
certificate serial certificate serial certificate serial • Avnet signed certificate identity (TPM
org-name org-name org-name
Chip)
vBond vSmart vManage • vBond, vSmart and vManage validate:
Trust for vEdge certificate root CA
Root Root Root Certificate serial numbers against
authorized white-list (from vManage)
Organization name (received certificate
Signed OU) against locally configured one
Signed Signed
• vEdge validates:
Trust for vBond, vSmart and vManage
certificate root CA
vEdge Organization name (received certificate
OU) against locally configured one
Root Signed
• Persistent DTLS/TLS connection comes up
between vEdge and vSmart/vManage
DTLS
Validate: Root trust, vEdge is a client
org-name DTLS/TLS

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Cloud ⟺ vBond, vSmart, vManage
Validate: Root trust,
Validate: Root trust,
Validate: Root trust,
certificate serial certificate serial certificate serial • vManage root cert is distributed to
org-name org-name org-name
controllers
vBond vSmart vManage • vManage issues certificate identity

Root
• vBond, vSmart and vManage validate:
Root Root
Trust for vEdge certificate root CA
Certificate serial numbers against
Signed authorized white-list (from vManage)
Signed Signed
Organization name (received certificate
OU) against locally configured one
• vEdge validates:
Trust for vBond, vSmart and vManage
vEdge
certificate root CA
Organization name (received certificate
Root Signed
OU) against locally configured one

DTLS
• Persistent DTLS/TLS connection comes up
Validate: Root trust, between vEdge and vSmart/vManage
org-name DTLS/TLS
vEdge is a client
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Control Plane Transport
• vEdge router will by default try to
vBond vSmart vManage
establish control connections over
all provisioned transports
• Administrator can control which
transports vEdge router uses for
establishing control connections

MPLS INET

DTLS
DTLS/TLS
vEdge

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Control Plane Sessions
DTLS only
• Secure Channel to SD-WAN • Viptela Primitives
• Permanent
Controllers (vSmart, vBond, vManage
• Multiple Sessions
vManage) vBond
• Single extensible control
plane vSmart vSmart

• Operates over DTLS/TLS


authenticated and secured
tunnels DTLS or TLS
DTLS or TLS
• Viptela Primitives
• OMP - between vEdge routers • Viptela Primitives
• NETCONF
• OMP
• Permanent
and vSmart controllers and • Permanent • 1 session / vSmart / TLOC
• Single Session
between the vSmart
controllers DTLS Only
• Viptela Primitives
• NETCONF – Provisioning • Temporary

from vManage
vEdge

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management Protocol (OMP)
Unified Control Plane
• TCP based extensible control plane
protocol
vSmart
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
- Inside TLS/DTLS connections

vSmart vSmart • Leverages address families to advertise


reachability for TLOCs,
unicast/multicast destinations
(statically/dynamically learnt service
side routes), service routes (L4-L7),
BFD stats (TE and H-SDWAN) and Cloud
onRamp for SaaS probe stats (gateway)
- Uses attributes

• Distributes IPSec encryption keys, and


vEdge vEdge data and app-aware policies (embedded
NETCONF)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Default – No Port
Offset Configured and

Firewalls Ports – DTLS DTLS

vManage – IP1
UDP
Core0 - 12346
Core1 - 12446 UDP
vBond – IP1 vSmart – IP1 Core2 - 12546 Core0 - 12346
vBond – IP2 vSmart – IP2 Core3 - 12646 Core1 - 12446
Core4 - 12746 Core2 - 12546
Core5 - 12846 Core3 - 12646
vBond orchestrators do not Core6 - 12946 Core4 - 12746
support multiple cores. vBond Core7 – 13046 Core5 - 12846
orchestrators always use DTLS 12346 UDP UDP Core6 - 12946
tunnels to establish control UDP Core7 – 13046
connections with other
Viptela devices, so they The vManage NMSs and vSmart controllers can
run on a virtual machine (VM) with up to
always use UDP. The UDP port eight virtual CPUs (vCPUs). The vCPUs are
is 12346 designated as Core0 through Core7.
Each core is allocated separate base ports
Firewall for control connections

Red signifies primary protocol or first port


UDP used
• vBond IP’s are not Elastic, its
12346
vEdge 12366 vEdge recommended to permit UDP/12346 to/from any
12386 from the vEdge.
12406
12426 • vEdge’s can port hop to establish a
connection, its recommended to permit all 5
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
UDP ports inbound to all vEdges
The Fabric
Data Plane

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Transport Locators (TLOCs)
TLOCs vSmart
vSmarts advertise TLOCs to
vEdges in TLOC routes

SD-WAN Fabric TLOCs advertised to


with TLOCs as vSmarts in TLOC routes
tunnel endpoints vEdge

IPsec
IPsec Local TLOCs
IPsec
(System IP, Color, Encap
MPLS INET
Pub IP/Port, Priv IP/Port)
vEdge vEdge

vEdge vEdge
Transport Locator (TLOC) OMP IPSec Tunnel
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Transport Colors
T3 T4 T1 T2
T3 T4
Internet1 T1 T2 Internet
T1 T3
T3 vEdge vEdge
T1
vEdge vEdge T2 T4
T2 T4
MPLS

T1, T3 – Internet Color T2, T4 – MPLS Color


Internet2
T1, T3 – Internet1 Color T2, T4 – Internet2 Color
T1 T3 T2 T4
T1 T3 T2 T4

T1 T4 T2 T3
T1 T4 T2 T3

Color restrict will prevent attempt to establish IPSec tunnel to TLOCs


with different color

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Fabric Operation
Fabric Walk-Through
OMP Update:
vSmart  Reachability – IP Subnets, TLOCs
OMP
 Security – Encryption Keys
DTLS/TLS Tunnel
 Policy – Data/App-route Policies
IPSec Tunnel
OMP OMP
BFD Update Update
Policies
OMP OMP
Update Update

vEdge1 vEdge2
T1
Transport1 T3
T3 T4 TLOCs TLOCs T1 T2
T4
T2
VPN1 VPN2 Transport2 VPN1 VPN2
BGP, OSPF, BGP, OSPF,
Connected, Connected,
Static A B C D Static

Subnets Subnets
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Bidirectional Forwarding Detection (BFD)
vEdge • Path liveliness and quality measurement
detection protocol
- Up/Down, loss/latency/jitter, IPSec
tunnel MTU
• Runs between all vEdge and vEdge Cloud
routers in the topology
- Inside IPSec tunnels
vEdge vEdge - Automatically invoked after each IPSec
tunnel establishment
- Cannot be disabled

• Uses hello (up/down) interval, poll (app-


aware) interval and multiplier for
vEdge vEdge detection
- Fully customizable per-vEdge, per-color

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
End to End Segmentation
VPN 1
Interface VPN1 SD-WAN VPN1 Interface
IPSec VPN 2
VLAN VPN2 Tunnel VPN2 VLAN
VPN 3
Ingress Egress
vEdge vEdge

IP UDP ESP LBL Original Packet

• Segment connectivity across fabric w/o • vEdge routers maintain per-VPN routing
reliance on underlay transport table for complete control plane separation
• Interfaces and sub-interfaces (802.1Q • Labels are used to map packets into VPNs
tags) are mapped into VPNs for complete data plane separation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Data Plane Security Encryption
 Each vEdge advertises its local IPsec  Can be rapidly rotated
encryption keys as OMP TLOC attributes vSmart
Controllers  Symmetric encryption keys used
 Encryption keys are per-transport asymmetrically

OMP OMP
Update Update
Local
Local
Transport1

vEdge-A vEdge-B
Transport2

Remote
Remote
AES256-GCM
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Control Plane
Anti-Replay Protection
 Encrypted packets are assigned sequence  Upon receipt of a packet with higher
numbers. vEdge routers drop packets with sequence number than received thus far,
duplicate sequence numbers vEdge router will advance the sliding
- Replayed packet window
 vEdge routers drop packets with sequence  Sliding window is COS aware to prevent low
numbers lower than the minimal number of priority traffic from “slowing down” high
the sliding window priority traffic
- Maliciously injected packet

Drop Accept Range Advance Window

Sliding Window

Packet
Sequence
Numbers
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
WAN Communication
Traffic Forwarding
Per-Session Loadsharing Per-Session Weighted Application Pinning Application Aware Routing
Active/Active Active/Active Active/Standby SLA Compliant

SLA SLA

Hierarchical Multihop Fabric Single-hop Fabric

Core

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management
Protocol (OMP)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management Protocol (OMP)
Unified Control Plane
• TCP based extensible control plane
protocol
vSmart
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
- Inside TLS/DTLS connections

vSmart vSmart • Leverages address families to advertise


reachability for TLOCs,
unicast/multicast destinations
(statically/dynamically learnt service
side routes), service routes (L4-L7),
BFD stats (TE and H-SDWAN) and Cloud
onRamp for SaaS probe stats (gateway)
- Uses attributes

• Distributes IPSec encryption keys, and


vEdge vEdge data and app-aware policies (embedded
NETCONF)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Management Protocol Overview
• TCP based extensible control plane
vSmart2 protocol
• Runs between vEdge routers and vSmart
controllers and between the vSmart
controllers
Inside permanent TLS/DTLS connections
Automatically enabled on bringup
vSmart1 vSmart3
• vSmarts create full mesh of OMP peers
• vEdge routers need not peer with all
vSmarts

vEdge vEdge

OMP Peers

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing: TLOC Routes

• Routes connecting locations to


physical networks
vSmart
• Advertised to vSmart controllers
OMP Update • Most prominent attributes:
Site-ID
MPLS INET Encap-SPI
Encap-Authentication
Encap-Encryption
TLOCs Public IP
vEdge Public Port
Private IP
Private Port
Connected BFD-Status
Tag
Static Preference
Weight
Dynamic (OSPF/BGP)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing: OMP Routes

• Routes learnt from local service


vSmart side
• Advertised to vSmart controllers
MPLS INET • Most prominent attributes:
OMP Update TLOC
Site-ID
Label
vEdge VPN-ID
Tag
Preference
Connected Originator System IP
Service
Origin Protocol
Static Side
Origin Metric
Dynamic (OSPF/BGP)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing: Network Service Routes

vSmart • Routes for advertised network


services, i.e. Firewall, IDS,
IPS, generic
MPLS INET • Advertised to vSmart controllers
OMP Update
• Most prominent attributes:
VPN-ID
vEdge
Service-ID
Label
Originator System IP
Network TLOC
Service
Firewall

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP Best-Path Algorithm and Loop Avoidance
Next hop TLOC is reachable

• vSmart will advertise 4 ECMP


Prefer vEdge-sourced route over vSmart-sourced route paths by default
Max 16 paths
Prefer OMP route with lower admin distance
• vSmart can send backup path
for faster reroute on vEdge
Prefer OMP route with higher route preference

Prefer OMP route with higher TLOC preference

Prefer highest origin


(Connected, Static, eBGP, OSPF Intra, OSPF Inter, OSPF
External, iBGP, Unknown/Unset)

Prefer route from higher Router-ID (System-IP)

Prefer highest TLOC private IP address


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Overlay Routing
• Uniform control plane
protocol
Dynamic (OSPF/BGP)
Dynamic (OSPF/BGP)
Static
Static • OMP learns and translates
Connected routing information across
Connected
the overlay
Site2 OMP routes, TLOC routes,
Site1 vSmart network service routes
Overlay Unicast and multicast
Management address families
Protocol IPv4 and IPv6 (future)
Site3
Site4 • Distribution of data-plane
Connected security parameters and
Connected Static policies
Static
Dynamic (OSPF/BGP)
Dynamic (OSPF/BGP)
• Implementation of control
(routing) and VPN membership
policies
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Port Handling and NAT

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Understanding NAT Types (1/2)
Full-Cone Symmetric
Source: Z / 3001 Source: Z / 3001
Dest: B / 90 Dest: B / 90
Port 90 Port 90

Source: A / 2001 Initial Packet Source: A / 2001 Initial Packet


Dest: B / 90 Host B Dest: B / 90 Host B
Port 91 Port 91

Site Site
NAT NAT
Port 2001 Port 2001
Host A Port 90 Host A Port 90

Host C Host C
Port 91 Port 91

NAT Binding NAT Filter NAT Binding NAT Filter

Local Addr / Port <-> External Addr / Port External Address mask Local Addr / Port <-> External Addr / Port External Address mask

A / 2001 <-> Z / 3001 * / * A / 2001 <-> Z / 3001 B / 90

Source: [Link]
29/[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Understanding NAT Types (2/2)
Restricted-Cone NAT Port-Restricted-Cone NAT
Source: Z / 3001 Source: Z / 3001
Dest: B / 90 Dest: B / 90
Port 90 Port 90

Source: A / 2001 Initial Packet Source: A / 2001 Initial Packet


Dest: B / 90 Host B Dest: B / 90 Host B
Port 91 Port 91

Site Site
NAT NAT
Port 2001 Port 2001
Host A Port 90 Host A Port 90

Host C Host C
Port 91 Port 91

NAT Binding NAT Filter NAT Binding NAT Filter

Local Addr / Port <-> External Addr / Port External Address mask Local Addr / Port <-> External Addr / Port External Address mask

A / 2001 <-> Z / 3001 B / * A / 2001 <-> Z / 3001 * / 90

Source: [Link]
29/[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Traversal Combinations
Side A Side B IPSec Tunnel Status
Public Public

Full Cone Full Cone

Full Cone Port/Address Restricted

Port/Address Restricted Port/Address Restricted

Public Symmetric

Full Cone Symmetric

Symmetric Port/Address Restricted

Symmetric Symmetric

Direct IPSec Tunnel No Direct IPSec Tunnel (traffic traverses hub) Mostly Encountered

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Traversal – Dual Sided Full Cone
vBond
NAT Detection

IP1’ IP2’ • vBond discovers post-NAT


Port1 Port2 public IP and communicates
vSmart back to vEdges
STUN Server

• vEdges notify vSmart of their


NAT Filter: NAT Filter: post-NAT public IP address
Any source IP/Port Any source IP/Port
IP1’ Full Full IP2’ • NAT devices enforce no filter
Port1 Cone Cone Port2 Full-cone NAT

IP1 IP2’ IP1’ IP2


Port1 Port2 Port1 Port2
vEdge1 vEdge2

Successful IPSec connection


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Traversal – Full Cone and Symmetric
vBond
NAT Detection
• vBond discovers post-NAT public
IP1’ IP2’
IP and communicates back to
Port1 Port2
vEdges
vSmart STUN Server
• vEdges notify vSmart of their
post-NAT public IP address
NAT Filter:
NAT Filter: Only from vBond • Symmetric NAT devices enforce
Any source IP/Port From IP1’/Port1 filter
IP1’ Full IP2’ Only allows traffic from vBond
Symmetric
Port1 Cone Port2 • vEdge behind symmetric NAT
reaches out to remote vEdge
NAT entry created with filter to
IP1 IP2’ IP1’ IP2 allow remote vEdge return traffic
Port1 Port2 Port1 Port2 Remote vEdge will learnt new
vEdge1 vEdge2 symmetric NAT source port (data
plane learning)
Successful IPSec connection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Port Handling and
Firewall

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN Port Handling and Firewall
• By default, all Viptela devices use base port 12346 for establishing the connections that handle
control and traffic in the overlay network. Each device uses this port when establishing connections
with other Viptela devices
• Port Offset
• When multiple Viptela devices are installed behind a single NAT device. For NAT devices that can differentiate among the
devices behind the NAT, you do not need to configure the port offset.
• Different port numbers used for each device so that the NAT can properly identify each individual device.
• Port offset from the base port 12346. For example, device with a port offset of 1, that device uses port 12347. The port
offset can be a value from 0 through 19. The default port offset is 0.
• Port Hopping
• Devices try different ports when attempting to establish connections with each other in the event that a connection
attempt on the first port fails.
• After such a failure, the port value is incremented and the connection attempt is retried. The software rotates though a
total of five base ports, waiting longer and longer between each connection attempt.
• If you have not configured a port offset, the default base port is 12346, and port hopping is done sequentially among
ports 12346, 12366, 12386, 12406, and 12426, and then returning to port 12346.

[Link]
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Routers – Base Ports

vBond vManage vSmart • When a vEdge router joins the overlay network, it
establishes DTLS control plane connections with
the controller devices—the vBond orchestrator,
the vManage NMS, and the vSmart controller

DTLS DTLS
• When initially establishing these DTLS
UDP UDP connections, the vEdge router uses the base port
DTLS
UDP
12346. If it is unable to establish a connection
using this base port, it port-hops through ports
INET MPLS 12366, 12386, 12406, and 12426, returning, if
necessary, to 12346
• This same port number is used to establish the
IPsec connections and BFD sessions to the other
12346
vEdge routers in the overlay network.
12366 UDP
12386 • Command: show control local-properties
12406
12426 12346
12366
12386
12406
12426

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Controllers – Base Ports

vBond UDP vManage UDP vSmart UDP • The vManage NMSs and vSmart controllers can
12346 Core0 - 12346 Core0 - 12346
Core1 - 12446 Core1 - 12446 run on a virtual machine (VM) with up to
Core2
Core3
- 12546
- 12646
Core2
Core3
- 12546
- 12646
eight virtual CPUs (vCPUs). The vCPUs are
Core4 - 12746 Core4 - 12746 designated as Core0 through Core7.
Core5 - 12846 Core5 - 12846

DTLS DTLS
Core6 - 12946 Core6 - 12946 • Each core is allocated separate base ports
Core7 – 13046 Core7 – 13046
UDP UDP for control connections. The base ports
DTLS
UDP
differ, depending on whether the connection
is over a DTLS tunnel (which uses UDP) or a
INET MPLS TLS tunnel (which uses TCP).
• vBond orchestrators do not support multiple
cores. vBond orchestrators always use DTLS
tunnels to establish control connections
with other Viptela devices, so they always
UDP use UDP. The UDP port is 12346.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Default – No Port
Offset Configured and

Firewall Ports for Viptela Deployments DTLS

vManage – IP1
UDP
Core0 - 12346
Core1 - 12446 UDP
vBond – IP1 vSmart – IP1 Core2 - 12546 Core0 - 12346
vBond – IP2 vSmart – IP2 Core3 - 12646 Core1 - 12446
Core4 - 12746 Core2 - 12546
Core5 - 12846 Core3 - 12646
vBond orchestrators do not Core6 - 12946 Core4 - 12746
support multiple cores. vBond Core7 – 13046 Core5 - 12846
orchestrators always use DTLS 12346 UDP UDP Core6 - 12946
tunnels to establish control UDP Core7 – 13046
connections with other
Viptela devices, so they The vManage NMSs and vSmart controllers can
run on a virtual machine (VM) with up to
always use UDP. The UDP port eight virtual CPUs (vCPUs). The vCPUs are
is 12346 designated as Core0 through Core7.
Each core is allocated separate base ports
Firewall for control connections

Red signifies primary protocol or first port


UDP used
• vBond IP’s are not Elastic, its
12346
vEdge 12366 vEdge recommended to permit UDP/12346 to/from any
12386 from the vEdge.
12406
12426 • vEdge’s can port hop to establish a
connection, its recommended to permit all 5
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
UDP ports inbound to all vEdges
Default – No Port Offset
Configured and TLS

Firewalls Ports – TLS


vManage – IP1
TCP
Core0 - 23456 TCP
Core1 - 23556 Core0 - 23456
vBond – IP1 vSmart – IP1 Core2 - 23656 Core1 - 23556
vSmart – IP2 Core3 - 23756 Core2 - 23656
Core4 - 23856 Core3 - 23756
Core5 - 23956 Core4 - 23856
Core6 - 24056 Core5 - 23956
Core7 – 24156 Core6 - 24056
12346 UDP TCP Core7 – 24156
TCP

Firewall

Red signifies primary protocol or first port


UDP used
• vBond IP’s are not Elastic, its
12346
vEdge 12366 vEdge recommended to permit UDP/12346 to/from any
12386 from the vEdge.
12406
12426 • vEdge’s can port hop to establish a
connection, its recommended to permit all 5
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
UDP ports inbound to all vEdges
NAT Traversal Details

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vBond – NAT Traversal Discovery
vEdge-A
Public: Z / 3001 vBond-C
Private: A / • In order to successfully establish
12346
vEdge-B IPSec tunnels between the vEdge
Public: Y / 4001
Private: B / routers, Cisco SD-WAN fabric has to
12366
successfully operate across the NAT
boundaries.
INET1 • vBond discovers vEdge public IP
address and port, even if traverses
Source: Z / 3001 Source: Y / 4001 NAT
Dest: C / 12346 Dest: C / 12346

• vBond communicates (public IP, public


port) to the vEdge
Full Cone ISP1 ISP1
Symmetric
Box1 Box2

Source: A / Source: B / • vEdge computes AH value based on the


12346
Dest: C / 12346
12366
Dest: C / 12346 post NAT public IP
• Packet integrity (+IP headers) is
preserved across NAT
vEdge-A vEdge-B

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NAT Filtering Table
vEdge-A
Public: Z / 3001 vBond-C
Private: A / • Symmetric NAT on ISP1 Box2
12346
vEdge-B
Public: Y / 4001
Private: B /
• Binding Entry created:
12366
• [Internal IP : Internal Port] <->
[External IP : External Port]
INET1

NAT Inbound Filter NAT Inbound Filter


* / * C / 12346

Full Cone ISP1 ISP1


Symmetric
Box1 Box2

IP: A IP: B
Port: 12346 Port: 12366

vEdge-A vEdge-B

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP – TLOC Advertisement
• Routes connecting locations to physical
networks
• Advertised to vSmart controllers

vSmart • Most prominent attributes:


Site-ID
Encap-SPI
Encap-Authentication
Encap-Encryption
OMP Update Public IP
MPLS INET
Public Port
Private IP
Private Port
TLOCs BFD-Status
vEdge
Tag
Preference
Weight
• vEdge in the Fabric will receive TLOCs and
know Public IP and Port for all remote
vEdge

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-A TLOC Advertisement
vEdge-A TLOC vSmart
Public: Z / 3001
Private: A / • vEdge-A uses A / 12346 and is
12346
translated by ISP box1 to Z / 3001
• vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1 • From vEdge-A ‘s perspective, vedge-
vEdge-A TLOC vEdge-A TLOC B dest ip will be Y and dest port
Public: Z / 3001
Private: A /
OMP OMP
Public: Z / 3001
Private: A / will be 4001.
12346 12346

• From vEdge-B ‘s perspective, vedge-


ISP1 ISP1 A dest ip will be Z and dest port
Box1 Box2 will be 3001.
IP: A IP: B
Port: 12346 Port: 12366

vEdge-A vEdge-B

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-B TLOC Advertisement
vEdge-A TLOC vSmart
Public: Z / 3001
Private: A / • vEdge-A uses A / 12346 and is
12346
vEdge-B TLOC translated by ISP box1 to Z / 3001
Public: Y / 4001
Private: B /
12366 • vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1 • From vEdge-A ‘s perspective, vedge-
vEdge-B TLOC
vEdge-B TLOC B dest ip will be Y and dest port
Public: Y / 4001
Public: Y / 4001
Private: B /
OMP OMP Private: B / will be 4001.
12366
12366

• From vEdge-B ‘s perspective, vedge-


ISP1 ISP1 A dest ip will be Z and dest port
Box1 Box2 will be 3001.
IP: A IP: B
Port: 12346 Port: 12366

vEdge-A vEdge-B

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP – TLOC Received

vedge-A# show omp tlocs received

PUBLIC PRIVATE
PUBLIC PRIVATE
PSEUDO PUBLIC PRIVATE PUBLIC IPV6 PRIVATE IPV6 BFD
KEY PUBLIC IP PORT PRIVATE IP PORT IPV6 PORT IPV6 PORT STATUS
-----------------------------------------------------------------------------------------------------
1 [Link] 62140 [Link] 12346 :: 0 :: 0 up

[SNIP]

vedge-B

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
OMP – TLOC Received

vedge-B# show omp tlocs received

PUBLIC PRIVATE
PUBLIC PRIVATE
PSEUDO PUBLIC PRIVATE PUBLIC IPV6 PRIVATE IPV6 BFD
KEY PUBLIC IP PORT PRIVATE IP PORT IPV6 PORT IPV6 PORT STATUS
-----------------------------------------------------------------------------------------------------
1 [Link] 65130 [Link] 12366 :: 0 :: 0 up

[SNIP]

vedge-A

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-A to setup Data Tunnel to vEdge-B (1/2)
vEdge-A TLOC
Public: Z / 3001 vSmart-D
Private: A / • vEdge-A uses A / 12346 and is
12346
vEdge-B TLOC translated by ISP box1 to Z / 3001
Public: Y / 4001
Private: B /
12366 • vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1
• From vEdge-A ‘s perspective, vedge-
B dest ip will be Y and dest port
will be 4001.
NAT Inbound Filter
C / 12346
• From vEdge-B ‘s perspective, vedge-
ISP1
Box
ISP1
Box
Symmetric A dest ip will be Z and dest port
IP: A IP: B
will be 3001.
Port: 12346 Source: A / 12346
Port: 12366
Dest: Y / 4001

vEdge1 vEdge2

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge-A to setup Data Tunnel to vEdge-B (2/2)
vEdge-A
Public: Z / 3001 vSmart-D
Private: A / • vEdge-A uses A / 12346 and is
12346
vEdge-B translated by ISP box1 to Z / 3001
Public: Y / 4001
Private: B /
12366 • vEdge-B uses B / 12366 which is
translated into Y / 4001 by ISP box2
INET1
• From vEdge-A ‘s perspective, vedge-
B dest ip will be Y and dest port
will be 4001.
Source: Z / 3001 NAT Inbound Filter
C / 12346
Dest: Y / 4001
• From vEdge-B ‘s perspective, vedge-
ISP1
Box
ISP1
Box
Symmetric A dest ip will be Z and dest port
IP: A IP: B
will be 3001.
Port: 12346 Port: 12366

vEdge1 vEdge2

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Security

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Secure Segmentation – VPNs

IF IF MPLS

Service Transport
(VPNn) (VPN0)

IF IF INET

Management • VPNs are isolated from each other, each VPN has
(VPN512) its own forwarding table
• vEdge router allocates label to each of it’s
IF
service VPNs and advertises it as route
attribute in OMP updates
- Labels are used to identify VPN in the incoming
packets

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Labels
• Labels identity VPN route table on
IP
vEdge router
UDP Per-VPN
Locally significant on each vEdge
ESP
• Pushed on the ingress vEdge, popped
Label on the egress vEdge
• Appear in encrypted part of the IPSec
Encrypted
Original packet
Packet
• Exchanged through the OMP routes
• Used for segmentation
[Link]

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
End-to-End Segmentation vSmart

Route
Tables

A A
B B
C C
vEdge Router vEdge Router

IP UDP ESP LBL Original Packet

• Segment connectivity across fabric w/o • vEdge routers maintain per-VPN routing
reliance on underlay transport table for complete control plane separation
• Interfaces and sub-interfaces (802.1Q • Labels are used to map packets into VPNs
tags) are mapped into VPNs for complete data plane separation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Segmentation and Multi-Topology
UC Compliancy Regions

Full Mesh Hub and Spoke Partial Mesh

CoLos Extranet DIA

Regional Mesh Point to Point Zero

Any Arbitrary Topology


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Local SD-WAN Fabric Secure Perimeter
Fabric Security
• Centralized data policy is defined on
vManage vManage and distributed by vSmart
controllers
• Centralized data policy match on
vSmart
application traffic of interest
DPI or 6 tuple matching
Centralized Localized • Centralized data policy takes drop
Data Policy Data Policy
action to block unwanted traffic
Can log
vEdge vEdge • Localized data policy works similarly to
centralized data policy, but it is
distributed directly from vManage
Trust Zone Un-trust Zone Fabric Security
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Local SD-WAN Fabric Secure Perimeter
In-Line Firewall
Physical Virtual
• Inline Firewall to inspect traffic arriving
NIC1 from the LAN environment
vEdge

vSwitch1
• Works for both physical, virtual and
mixed environments

vSwitch2
• Can be used in conjunction with fabric
vSwitch0 security
Firewall
Centralized or localized data policy
x86
NIC0

Trust Zone Un-trust Zone Fabric Security


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Regional Secure Perimeter – Single Service
Policy
vSmart Advertisement*
(+ Service) • Service node is connected to
Traffic Path vEdge
Service Directly or IPSec IKE v1/v2
OMP Advertisement
Routed or bridged
FW
VPN1
• vEdge router advertises service
VPN1 - Service route + Service label
- Specific VPN
VPN1 • Observe Firewall trust and untrust
Regional
Hub Data zones
Center
• Control or data policies are used
MPLS 4G
Remote
INET
to insert the service node
Office
* For data policy only. Control policy enforced on vSmart.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Regional Secure Perimeter – Multiple
Services Policy
vSmart Advertisement* • Service nodes are connected to
(+ Service) vEdge
Traffic Path Service Directly or IPSec IKE v1/v2
Advertisement
OMP Routed or bridged
FW IDS
• Service nodes can be connected to
different vEdge routers
VPN1 Can be in different sites
VPN1 • vEdge routers advertise service
VPN1 - Service route + Service label
Regional
Data - Specific VPN
Hub
Center • Observe Firewall trust and untrust
MPLS 4G zones
Remote
Office
INET
• Control or data policies are used to
* For data policy only. Control policy enforced on vSmart.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
insert the service nodes
DIA Security
Fabric DIA Security
Data Center
Branch
• vEdge performs DIA
Campus
• vEdge performs Port-Address
Restricted NAT
Internet MPLS • Centralized or localized data policies

Firewall + Fabric DIA Security


NAT • vEdge performs DIA
DIA
• Firewall enforces security for DIA traffic
DIA
• Firewall performs NAT
• Additional protection for vEdge
NAT
• Centralized or localized data policies
Site1 Site2
Trust Zone Un-trust Zone Fabric Security
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Regional Internet Security
• Internet connectivity is
Internet
provisioned in the Regional Hubs
NAT NAT
• Regional Hub vEdge routers
vSmart
Firewall Firewall advertise default route to remote
site vEdge routers
VPN aware
• Regional Firewalls provide
VPN1 VPN1 security inspection
Regional
Regional
Hub Hub
• Control policy can constrain
default route to a given region
4G
Region can have multiple hubs for
VPN1 MPLS VPN1
INET
redundancy and load-sharing
Branch Branch
* For data policy only. Control policy enforced on vSmart. Traffic Path OMP Control Plane
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Cloud Security

• vEdge router intercepts client DNS


queries
Deep Packet Inspection

POP1 POP2
• DNS queries are forwarded to Cisco
Umbrella DNS servers either
unconditionally or based on the policies
Regional
Data Center • Cisco Umbrella enforces security policy
DIA ISP A compliance based on DNS resolution
• Cisco Umbrella can act as proxy for
ISP B
application traffic with full Unified Threat
SD-WAN Management capabilities
Remote Site Data Center
Fabric
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DNS or Application Traffic
3rd Party Cloud Security

Exploits Malware ATP Botnets

RGN RGN
POP1 POP2 1 2

IPSec Tunnels
GRE/IPSec Tunnels

DIA Regional
ISP A
Data Center

ISP B

SD-WAN SD-WAN
Remote Site Remote Site
Fabric Fabric Data Center

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Data Traffic
Cloud Security with Zscaler
• vEdge router creates a GRE tunnel to
one or more Zscaler Enforcement Nodes
Exploits Malware ATP Botnets
(PoPs)
- Redundant PoPs, redundant ISPs
POP1 POP2
• Eliminates backhaul of traffic
destined to Internet and cloud
Regional applications
Data Center
ISP1 • Provides advanced security services
- Can inspect SSL encrypted data,
SD-WAN
Fabric
requires installation of Zscaler root
ISP2 certificate on the hosts

Remote Site Data Center • Cloud onRamp for SaaS can choose the
path across best performing Zscaler
GRE Tunnel Enforcement Node (PoP) for selected
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SaaS applications
DDoS Protection for vEdge Routers
vBond

Authenticated
Sources

vSmart vManage

CPU
Implicitly SD-WAN IPSec
Trusted
Sources Control Plane Policing:
vEdge  300pps per flow
 5,000pps

Packet
Explicitly Forwarding
Defined
Sources
Cloud Security

Deny except:
Unknown 1. Return packets matching flow entry (DIA enabled)
Sources 2. DHCP, DNS, ICMP

Other * Can manually enable :SSH, NETCONF, NTP, OSPF, BGP, STUN
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DDoS Protection for Controllers
vBond

Authenticated
Sources

vSmart vManage
CPU
vEdge
Control Plane Policing:
 500pps per flow
 10,000pps
vManage
Packet
Forwarding
Unknown vSmart
Sources Note: vBond control plane policing is the
same as vEdge
Other

Deny except:
DHCP, DNS, ICMP, NETCONF

* Can manually enable :SSH, NTP, STUN, HTTPS (vManage)


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Streaming Content Distribution
Multicast Traffic
 vEdges interoperate with IGMP v1/v2 and PIM on  vEdge Replicators replicate multicast stream to
the service side receivers
 vEdges advertise receiver multicast groups using  Multicast is encapsulated in point-to-point
OMP tunnels

vSmart Controllers
OMP
Update
IGMP/PIM OMP
Update
SD-WAN
OMP Sender
Update Fabric
Receiver Branch OMP
Update
Data
IGMP/PIM
Center
RP

Receiver Branch
Replicators Control Plane Multicast Stream
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast Support Models
• PIM-SM with Auto-RP
• For cases with many receivers
• Replicators can be at the source or dispersed at different geo
locations
• PIM-SSM
• For cases with many sources aggregating at a headend/DC site
• Replicators should be defined at the receiver side
• SSM mapping defined on a non-viptela device

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast Support with Auto-RP
• Source register itself to an RP
• Receiver sends the (*,G) join
• First Join gets forwarded to the vSmart as an OMP packet and then forwarded to the
replicator
• Replicator forwards (*,G) to the RP
• RP forwards it to the source
• Stream is forwarded to the receiver through the replicator. Stream never goes to vSmart
• Once receiver has the source information, it will the join using (S,G)
• First (S,G) join gets forwarded as an OMP control packet to the vSmart and then to
replicator
• Replicator then forward the (S,G) to the source
• vEdge ignores subsequent joins and depends on the prune message to stop the stream from
the replicator

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Multicast Support with PIM-SSM
Partner Internet Head End
Location
5 6
vEdge will vEdge will receive
7
start sending multicast over a
Stream is forwarded
multicast unicast tunnel
to the receiver
Stream will be Forward the stream on
send over a the interface it
unicast tunnel receives join
IPSec Unicast Tunnel
(AES 256)
PIM-SSM

SOURCE VE2K
Internet Receiver

VE100

PIM-SSM
VE2K

2
4 3 SSM Mapping defined 1
on non-viptela
(S,G) is received (S,G) join router (*,G) join to a
by the remote forwarded to (*,G) join non-viptela router
vEdge remote Viptela converted to (S,G) From encoders
site over a (S,G) join
unicast tunnel forwarded to
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Viptela
Configurations

Replicator

vpn 10
router pim
interface ge2/0
autorp
pim multicast-replicator local

Non-Replicator

vpn 10
router pim
interface ge2/0
autorp

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application Experience
and QoS

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application Recognition
Cloud Data Deep Packet Inspection Engine
Center

App 1
App 2

App 3,000
vEdge Router
MPLS INET
Data
3G/4G Center
Primary Use Cases:
- Application visibility
Small Office - Application Firewall
Home Office - Traffic prioritization
Campus
- Transport selection

Branch
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Bidirectional Forwarding Detection (BFD)
• Path liveliness and quality measurement
vEdge
detection protocol
- Up/Down, loss/latency/jitter, IPSec
tunnel MTU
• Runs between all vEdge and vEdge Cloud
routers in the topology
- Inside IPSec tunnels
vEdge vEdge - Automatically invoked after each IPSec
tunnel establishment
- Cannot be disabled

• Uses hello (up/down) interval, poll (app-


aware) interval and multiplier for
detection
vEdge vEdge
- Fully customizable per-vEdge, per-color

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
BFD – Tunnel Down

Multiplier = 7

BFD Probe

Hello Interval (ms)

• Each vEdge router generates BFD packet every • Hello interval and multiplier determine
“hello” interval for path liveless how many BFD packets need to be lost to
detection declare IPSec tunnel down

• BFD packets are generated for each transport • Multiplier = 7 by default


individually. Timers can be adjustment for
quicker detection.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
BFD - Transport SLA Monitoring
App-Route Multiplier (6)

Poll Interval Poll Interval Poll Interval (ms)

vEdge Router

Hello Interval (ms) BFD Probe

• Each vEdge router generates BFD packet • Poll interval determines the average path
every “hello” interval for path quality quality measurement (loss, latency,
• BFD packets are generated for each jitter)
transport individually. Timers can be • App-route multiplier determines the
adjustment for quicker detection. average path quality measurement across
the poll intervals
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Critical Applications SLA
Application Aware Routing
 By default, without any local or vManage
centralized data policies, App Aware Routing Policy
Cisco SDWAN performs flow-based load App A path must have
sharing across all transports available
between the vEdge routers latency <150ms and loss <2%
 With Policies:
vSmart Controllers
Enforce SLA compliant path for
applications of interest
Other applications will follow
active/active behavior across all paths
Internet
vEdge vEdge

Path 2 MPLS
App A

4G LTE
Path1: 10ms, 0% loss
Path2: 200ms, 3% loss IPSec Tunnel
Path3: 140ms, 1% loss
Control Plane
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Optimal Network Utilization for App Traffic
Path MTU Discovery
 Automatic and proactive Network Path  Automatic MSS adjust for TCP traffic
MTU Discovery leveraging BFD protocol Can also be manually configured
 Support for Host Path MTU Discovery  IP ICMP Unreachable (type 3, code 4)

Transport1

vEdge Transport2 vEdge

Network Path IPSec Tunnel


MTU Discovery

Host Path
MTU Discovery
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Example
App Policy applied with DSCP EF
preferred path MPLS, rest is
default
Simulation with DSCP 0(default)

App Policy applied with DSCP EF


preferred path MPLS
Simulation with DSCP 46 (EF)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
QoS

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Router Device QoS Overview
Data Policy
vManage Classification of application traffic into QoS
forwarding classes (queues)

Ingress Interface Egress Interface


QoS forwarding QoS
classes Scheduler
FC Q
In FC Q Out
FC Q

Policing Map into FCs Policing Shaping Bandwidth %


Buffer %
Scheduling Priority
Rewrite inner DSCP Map into Rewrite outer DSCP Drop
Egress Queue
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Queueing
• Classification
- Flow match on 6-tuple (ACL, Data Policy)
vEdge - Application match on DPI (Data Policy)

Q0 • Per-Egress Interface Queuing

Egress Interface
Ingress Interface

Q1 - Q0 is LLQ
Q2 - vEdge control traffic (DTLS/TLS, BFD, routing
protocols) goes into Q0
o Not subjected to LLQ policer
Q7

• Scheduling for Q1-Q7 is WRR*


Bandwidth percent determines queue weight
Unused Q0 bandwidth is distributed between
Classification Queuing other queues

• Queue drop is RED** or tail-drop


- Linear drop probability, i.e. X% queue depth
* Weighted Round-Robin results in X% drop probability
** Random Early Discard

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Shaping
Rate
Tokens • Shaping effective on egress
Token Bucket physical interfaces
- Not supported on sub-interfaces

• Forward traffic that conforms to

Egress Interface
Ingress Interface

configured shape rate


- There are tokens in the bucket

• Queue traffic that exceeds


configured shape rate
- There are no tokens in the bucket
- Weighted Round-Robin
Shaping Queuing

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policing
• Ingress and Egress Policing
Rate
Tokens
- Interface/Sub-Interface based
Token Bucket - DPI or 6 tuple matching using
centralized or localized data
policy

• Forward traffic that conforms to

Egress Interface
Ingress Interface

configured policer rate


- There are tokens in the bucket

• Drop traffic that exceeds


configured policer rate
- There are no tokens in the bucket

Classification Policing Queuing • Configurable Burst Rate


Token bucket depth

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policing with Packet Loss Priority
Rate
Tokens
Token Bucket

• Set PLP=High value for traffic


that exceeds configured policer
rate
There are no tokens in the bucket
TLOC A
Default is PLP=Low
Policing
• Data policy can match on PLP
high value and set different
local TLOC
Decision is taken on per-packet
level

• Non-conforming traffic spills


over to a different circuit
TLOC B
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Marking and Re-marking

Default Behavior • Comply with service providers


provisioned classes of service
• Ingress Classification
- DPI or 6 tuple matching using
centralized or localized data policy
Egress Interface
Ingress Interface • Ingress interface marks/re-marks
inner DSCP bits
DSCP
DSCP

DSCP

• Inner DSCP bits are copied to the


outer DSCP bits

Modify with • Egress interface re-write rules


Modify with
ACL/Data Policy re-write rules
remark outer DSCP bits

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Behavior Changes with QoS Data Policy

When you want to modify the default packet forwarding flow, you design and provision QoS policy

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Forwarding Classes and Scheduler
Map Forwarding Class to Output queues

• You can classify incoming traffic by


Voice Q0 associating each packet with a
Q1 forwarding class.
Critical-data Q2
• Forwarding classes group data
Best Effort Q3
packets for transmission to their
Q4
destination.
Q5
Q6 • Based on the forwarding class, you
Q7 assign packets to output queues.
• The vEdge routers service the output
policy
class-map
queues according to the associated
class best-effort queue 3
class critical-data queue 2
forwarding, scheduling, and
class voice queue 0 rewriting policies you configure.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
QoS Scheduler

Configure Scheduler – Bandwidth allocation

• You can configure a QoS map for


Q0 20%
each output queue to specify the
bandwidth, delay buffer size, and
packet loss priority (PLP) of
Q2 30% output queues.
• The Viptela software supports
eight queues, which are numbered 0
Q4 40% to 7. Queue 0 is reserved, and is
used for both control traffic and
low-latency queuing (LLQ) traffic.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Apply the Queue Map to an Egress Interface

QoS
Scheduler

Out
Q
Q
Q

Shaping Bandwidth %
Buffer %
WARNING: Scheduling Priority
QoS shaping rates might be Drop
inaccurate for rates less than
2 Mbps. [VIP-3860]

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Apply the Queue Map to an Egress Interface

QoS
Scheduler

Out
Q
Q
Q

Shaping
Bandwidth %
Buffer %
Scheduling Priority
WARNING:
Drop
QoS shaping rates might be
inaccurate for rates less than
2 Mbps. [VIP-3860]

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configuration
• Ingress
• Use a localized policy with ACL
• Or use a Global Data Policy
• Match application, group or prefix etc
• Action: set DSCP and select Forwarding Class

• Egress
• class-map
• qos-scheduler
• Apply on egress interface

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configure Class-Map and Scheduler (1/2)
Step1: Configure forwarding classes and mapping to output queues Step2: Configure the QoS scheduler forwarding classes
policy
policy qos-scheduler be-scheduler
class-map class best-effort
class best-effort queue 3 bandwidth-percent 20
buffer-percent 20
class bulk-data queue 2 scheduling wrr
class critical-data queue 1 drops red-drop
class voice queue 0 !
qos-scheduler bulk-scheduler
class bulk-data
bandwidth-percent 20
buffer-percent 20
scheduling wrr
drops red-drop
!
qos-scheduler critical-scheduler
class critical-data
bandwidth-percent 40
buffer-percent 40
scheduling wrr
drops red-drop
!
qos-scheduler voice-scheduler
class voice
bandwidth-percent 20
buffer-percent 20
scheduling llq
drops tail-drop

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Configure Class-Map and Scheduler (2/2)

Step 3: Define QoS Map by grouping QoS Schedulers.

policy
qos-map MyQoSMap
qos-scheduler be-scheduler
qos-scheduler bulk-scheduler
qos-scheduler critical-scheduler
qos-scheduler voice-scheduler

Step 4: Apply the QoS map to the egress interface

interface ge0/1
shaping-rate 5000
qos-map MyQoSMap

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Classify Traffic into Classes
Step1. Define an Access List to Classify Data Step2. Apply the Access List to an Interface
Packets into appropriate Forwarding Classes
policy vpn 10
access-list MyACL
sequence 10
interface ge0/0
match access-list MyACL in
dscp 46
! !
action accept
class voice
!
!
sequence 20
match
source-ip [Link]/24
destination-ip [Link]/24
!
action accept
class bulk-data
set
dscp 32
!
!
!
sequence 30
match

!
destination-ip [Link]/24 Or use Global Data Policy and assign
action accept
class critical-data traffic to Forwarding Class
set
dscp 22
!
!
!
sequence 40
action accept
class best-effort
set
dscp 0
!
!
!
default-action drop

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Rewrite Rule
• This example shows how to configure the rewrite rule
to overwrite the DSCP field of the outer IP header.
policy
rewrite-rule transport • Here the rewrite rule "transport" overwrites the DSCP
class af1 low dscp 3 value for forwarding classes based on the drop
class af1 high dscp 4 profile.
class af2 low dscp 5
class af2 high dscp 6 • Since all classes are configured with RED drop, they
class af3 low dscp 7 can have one of two profiles: high drop or low drop.
class af3 high dscp 8
class be low dscp 1 • The rewrite rule is applied only on the egress
class be high dscp 2 interface, so on the way out, packets classified as
! "af1" and a Packet Loss Priority (PLP) level of low
! are marked with a DSCP value of 3 in the IP header
field, while "af1" packets with a PLP level of high
are marked with 4. Similarly, "af2" packets with a PLP
level of low are marked with a DSCP value of 5, while
"af2" packets with a PLP level of high are marked with
6, and so on.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Classification using Global Data Policy

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
TCP Optimization

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
TCP Optimization
Optimized
TCP Connections TCP Connections TCP Connections

SD-WAN
Fabric
Users vEdge vEdge Application
Router High Latency / Lossy Path Router Servers

• High latency or/and lossy path between • Optimized TCP connections use selective
users and applications, i.e. geo-distances acknowledgements to prevent unnecessary
retransmissions of received segments
• vEdge routers terminate TCP sessions and
provide local acknowledgements • Hosts using older TCP/IP stacks will see the
- Hosts don’t have to wait for end-to-end TCP most benefit
ACKs and pause TCP transmission
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Optimal MTU with Host PMTUD
IP MTU 1500 Bytes SD-WAN
Service Side Transport Side Fabric

Host vEdge Transport(s)


Network

Automatic Tunnel MTU


Discovery using BFD

DF=1 Fragmentation
Host

Packet
1500B Needed

Adjust IP MTU
Inner Outer
Packet DF=1 No (DF=1) DF=1 No
< 1500B Fragmentation Fragmentation
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Packet Fragmentation
IP MTU 1500 Bytes SD-WAN
Service Side Transport Side Fabric

Host vEdge Transport(s)


Network

Automatic Tunnel MTU


Discovery using BFD

Inner Outer
Host

Packet DF=0 Fragmentation (DF=0) DF=1

1500B Needed
Fragment

 vEdge routers perform fragmentation then encapsulation


 Reassembly is done by the server
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Optimal MTU with TCP MSS Adjust
MTU
MTU <1500 Bytes MTU
1500 Bytes 1500 Bytes

IPSec
Host vEdge vEdge Application
Router SD-WAN Fabric Router Servers
Signaled MSS Signaled MSS
1460B MSS Adjust 1320B Send MSS
to 1320B 1320B
Signaled MSS Signaled MSS
Send MSS 1320B MSS Adjust 1460B
1320B to 1320B

 Send TCP MSS is min (local link IP MTU - 40B*, signaled MSS value)
Signaled in SYN packets
 Can manually set TCP MSS value on vEdge router
Per-interface
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud Adoption

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Shifts in Enterprise Workloads
Public/Hybrid Cloud Cloud Applications

IaaS SaaS

Traditional On-Premise Data Centers


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud Ready WAN

IaaS SaaS
Public Cloud Cloud
Data Center Applications

Data Data
Center Center

Small Office Small Office


Home Office Secure Home Office Secure
SD-WAN SD-WAN
Fabric Fabric

Branch Campus Branch Campus

Cloud On-Ramp IaaS Cloud On-Ramp SaaS


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud Applications

Which way is cloud?


1. Direct Internet Access
2 2. Regional Breakout
3. Data Center Backhaul
Regional
Data Center
1 3
ISP1

SD-WAN
ISP2 Fabric
User Remote Site Data Center
MPLS
Viptela vEdge Router

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Direct Internet Access

Internet • Local DIA or Regional Internet Exit


- Per-VPN behavior
• All traffic or policy based
6-tuple or DPI matching
INET NAT • Secure Access
Port-Address Restricted NAT
Regional
Data Center Local Firewall
NAT Regional Firewall
INET
SD-WAN • For optimal quality of experience toward
INET
Fabric SaaS applications use Cloud onRamp
MPLS
Data Center
Remote Site
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS – DIA

• Detect application performance


through one or more Direct
Internet Access circuits
• vEdge routers chose best
Loss/
Latency performing path
Regional
Data Center Per-Application, Per-VPN
!
ISP1 • Automatic failover in case of
SD-WAN performance degradation
Fabric
ISP2 • Fully automated
Remote Site Data Center

Quality Probing

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS – DIA and Gateways
• Detect application performance
through DIAs and gateways
Customer/SP owned and
operated
ISP2 Security, performance, reliability
Loss/
Latency • vEdge routers chose best
Regional
Data Center performing path
! Per-Application, Per-VPN
ISP1
SD-WAN • Automatic failover in case of
Fabric performance degradation
MPLS
Remote Site Data Center
• Fully automated
Quality Probing
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS Quality Probing
• DNS resolution for the configured
DNS Server(s)
Cloud onRamp SaaS applications
• Periodic quality probes toward the
Loss/ configured Cloud onRamp SaaS
Latency
applications
Best !
Performing ISP1 ISP2 • vQoE score is determined based
on loss and latency reported by the
IF IF quality probes
• vEdge router determines best
VPN0 performing DIA circuit toward Cloud
DNS Query onRamp SaaS applications based
vEdge Router Quality Probe on vQoE scores
(remote site)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vQoE

• Every site where SaaS application is


Score Color
enabled, is classified as performing
8-10 Green
Good, Average or Bad
5-8 Yellow
0-5 Red • Sites are color coded based on the
performance
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS Application Traffic
Steering
DNS Server(s) • Host initiates communication with the
Cloud onRamp SaaS application
NAT
• vEdge router forwards host DNS query
Best ! along the best performing path
Performing ISP1 ISP2
Loss/ Identified with DPI
Latency
IF IF
• vEdge router identifies application
Cache Table
using DPI
VPN0
dstIP/dstPort -> SaaS App Decision is cached
DPI Cache expedites subsequent
forwarding decisions
vEdge Router
Host • Application is forwarded along best
DNS Query Best performing path
performing path
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS (GW) Quality Probing
DNS Server(s)

• DNS resolution for the configured Cloud


onRamp SaaS applications
Best
DNS Server(s) Performing ISP2 • Periodic quality probes toward the
configured Cloud onRamp SaaS
IF applications
Loss/
Latency • vQoE score for DIA and gateway
ISP1
! VPN0 Composite metric of quality probes and
BFD for gateway
vEdge
IF Router • vEdge router determines best
(gateway)
performing path toward Cloud onRamp
MPLS 4G
SaaS applications based on vQoE
INET
VPN0 scores
vEdge Router
(remote site) DNS Query Quality Probe BFD
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for SaaS (GW) Application
TrafficDNS Steering
Server(s)

• Host initiates communication with the Cloud


onRamp SaaS application
NAT
• Remote site vEdge router forwards host
Best DNS query along the best performing path
ISP2 Performing
Cache Table DIA or gateway
Loss/
dstIP/dstPort -> SaaS App
IF Identified with DPI
Latency
VPN0
• vEdge router identifies application using
! DPI
ISP1
DPI
Decision is cached
Cache Table vEdge
Router
Cache expedites subsequent forwarding
dstIP/dstPort -> SaaS App
IF (gateway) decisions
Repeated on remote site vEdge and
VPN0 gateway vEdge
4G

DPI
MPLS
INET
• Application is forwarded along best
Host performing path
vEdge Router
© 2018
(remote site)
Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DNS Query Best performing path
SD-WAN and Public Cloud

VPC VPC VNET VNET

VPC VPC VNET VNET

Cloud How to provide security,


Data Center
segmentation, QoS and
reliability to the cloud
SD-WAN workloads?
Fabric
Campus
Remote Site

Branch
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Deployment Models
Application VPC Gateway Transit Hub Router

R R R
AZ1 AZ2 AZ1 AZ2 AZ1 AZ2

VGW VGW

CSR1000v Standard IPSec + BGP


vEdge Cloud
Transit VPC

MPLS VGW IGW


INET
Direct
Connect

MPLS INET

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS – Attached Compute

Compute Compute • vEdge Cloud routers are instantiated


VPC/VNET VPC/VNET in Amazon VPCs or Microsoft Azure
VNETs
- Posted in marketplace
- Use Cloud-Init for ZTP
Cloud • One vEdge Cloud router per VPC/VNET
Data Center - Redundancy is handled through cloud
provider
• vEdge Cloud routers join the fabric,
SD-WAN all fabric services are extended to
Fabric the IaaS instances, e.g.
Campus multipathing, segmentation and QoS
Remote Site
- For multipathing, can combine AWS
Direct Connect or Azure ExpressRoute
with direct Internet connectivity
Branch

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS – Gateway
Compute
• A pair of vEdge routers is
VPCs/VNETs
instantiated in Amazon VPC or
Microsoft Azure VNET
- Gateway VPC/VNET
Gateway
VPC/VNET • A pair of standard-based IPSec tunnels
Cloud is stretched from gateway VPC/VNET to
Data Center each host VPCs/VNETs
- Connectivity redundancy
• BGP is established across IPSec
SD-WAN tunnels for route advertisement
Fabric - Bi-directional BGP/OMP redistribution
on the gateway VPC/VNET vEdge routers
Campus
Remote Site • Entire process is automated through
vManage workflow
• No change to existing compute
Branch VPCs/VNETs
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS – Gateway VPC/VNET
Standard IPSec + BGP
• Fully automated through
AZ1
BGP <-> OMP
vManage wizard
R
• Greatly simplifies brownfield
VGW
AZ2 IGW integration
AZ1
Host VPC vEdge GW
INET No changes are required on
host VPCs
MPLS

AZ2
vEdge GW
VGW Direct
Connect
• Multipathing, segmentation,
QoS
AZ1 Gateway VPC
R

VGW
• Fast failover
vManage instantiated and
AZ2 managed Speed of BGP convergence
Host VPC

AWS Region vManage


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud onRamp for IaaS Dashboard

• Centralized provisioning wizard on


vManage
• No need to operate marketplace
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
High Availability and
Redundancy

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Horizontal Solution Scale
Orchestration Plane Management Plane Control Plane
(vBond) (Multi-tenant or Dedicated) (Containers or VMs)
(vManage) (vSmart)

Horizontal Scale Out Model

Add vBond Orchestrators to Create vManage cluster to Add vSmart Controllers for
increase vEdge bringup capacity accommodate more vEdge routers more control plane capacity

• Choose vEdge platform with


appropriate IPSec tunnel
4G/LTE Internet scale
MPLS • Use control policies to define
VPN topologies

Data Center Campus Branch Home Office


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – vSmart Control Controllers
vSmart • vSmart controllers exchange OMP messages
Controllers
and they have identical view of the SD-
Control Plane
WAN fabric
Data Plane
• vEdge routers connect to upto three
vSmart controllers for redundancy
Cloud
Data Center • No impact as long as vEdge routers can
connect to at least one vSmart
Controller
Data Center
MPLS 4G
INET
• If all vSmart controllers fail or become
unreachable, vEdge routers will continue
Small Office operating on a last known good state for
Home Office a configurable amount of time
Campus
No changes allowed
Branch
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – vManage System
• vManage servers form a cluster for
vManage
Cluster redundancy and high availability
Management Plane • All servers in the cluster act as
Data Plane active/active nodes
- All members of the cluster must be in the
same DC / metro area
Cloud
Data Center
• For geo-redundancy, vManage servers
operate in active/standby mode
- Not clustered
Data Center
MPLS 4G - Database replication between sites
INET
• Loss of all vManage servers has no
Small Office impact on fabric operation
Home Office
- No administrative changes
Campus
Branch - No statistics collection
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
High Availability and Redundancy Overview
Site Redundancy Transport Redundancy

MPLS INET MPLS INET

VRRP OSPF/ OSPF/


BGP BGP

Network/Headend Redundancy Control Redundancy

vSmart Controllers
MPLS Control
Data
Center
INET Data MPLS
Site
INET
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy - Site with LAN Routing

SD-WAN • Redundant vEdge routers


Fabric
• OSPF/BGP between vEdge routers and site
router(s)
• Bi-directional redistribution between
vEdge A vEdge B
OMP and OSPF/BGP
Loop prevention

Site Router Site Router • Multipathing for remote destinations


across SD-WAN Fabric
- Can manipulate OSPF/BGP to prefer one
vEdge router over the other
Host
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy - Site with LAN Bridging

SD-WAN • Redundant vEdge routers


Fabric
• VRRP between vEdge routers
Operates per-VLAN

A S A S
• VRRP Active vEdge router responds to
vEdge A vEdge B
VRRP Grp 1
ARP requests for the virtual IP
VRRP Grp 2
• In case of failover, new VRRP Active
VLAN 1
VLAN 2 vEdge router sends out gratuitous ARP
to update ARP table on the hosts and
mac address table on the intermediate
L2 switches
Host Host

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – Meshed Transports
• vEdge routers are directly • SD-WAN tunnels are built
connected to all the transports through all directly connected
transports

Circuit Failure Transport Failure Router Failure

Internet MPLS Internet MPLS Internet MPLS

Site Network Site Network Site Network

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – Extended Transports
• Each vEdge router is connected • SD-WAN tunnels are built
to a given transports through local and remote
transports

Circuit Failure Transport Failure Router Failure

Internet MPLS Internet MPLS Internet MPLS

Site Network Site Network Site Network

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Transport Redundancy – TLOC Extension
• vEdge routers are connected only to their
respective transports
• vEdge routers build IPSec tunnels across
MPLS INET
directly connected transport and across the
transport connected to the neighboring vEdge
router
• Neighboring vEdge router acts as an underlay
router for tunnels initiated from the other vEdge
vEdge vEdge
• If one of the vEdge routers fails, second
vEdge router takes over forwarding the
traffic in and out of site
• Only transport connected to the remaining vEdge
Site Network router can be used

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
TLOC Extension Configuration
vpn 0 vpn 0
ip route [Link]/32 [Link]
interface ge0/0 interface ge0/0
description MPLS tunnel description INET tunnel
ip address [Link]/30 Add route to ip dhcp-client
tunnel-interface reach br1-vedge2 nat
Do not forget NAT
encapsulation ipsec mpls tunnel end- !
color mpls restrict point tunnel-interface
max-control-connections 1 encapsulation ipsec
MPLS INET
[service list] color biz-internet restrict
! max-control-connections 1
interface ge0/2 [service list]
description INET tunnel !
ip address [Link]/24 interface ge0/2
! ip address [Link]/24
tunnel-interface ge0/0 ge0/0 tloc-extension ge0/0
[Link]/24 dhcp
encapsulation ipsec preference 100 no shutdown
color biz-internet restrict ge0/2 ge0/2 !
max-control-connections 1 [Link]/24 [Link]/24 interface ge0/3
[service list] description MPLS tunnel
! ip address [Link]/24
interface ge0/3 tunnel-interface
ip address [Link]/24 ge0/3 ge0/3 encapsulation ipsec
tloc-extension ge0/0 [Link]/24 [Link]/24 color mpls restrict
no shutdown br1-vedge1 br1-vedge2 max-control-connections 1
! [service list]
ip route [Link]/0 [Link] !
ip route [Link]/0 [Link] ip route [Link]/0 [Link]

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Redundancy – Path and Headend
• vEdge routers leverage BFD for detecting end-to-end
tunnel liveliness
Data
Center • If intermediate network path through the SD-WAN
fabric fails or if the remote-end vEdge router (e.g.
data center) fails, BFD hellos will time out and
remote site vEdge router will bring down its
relevant IPSec tunnels
Internet MPLS
• Traffic will be rerouted after the failed condition
had been detected
• BFD timers can be tweaked for faster detection

Remote
Site
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Use Cases and Deployment
Models

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cloud-Delivered Control Flexible Deployment Options

Cisco Cloud Ops MSP Ops Team Enterprise IT

Deploy Deploy Deploy

vManage vManage vManage

vSmart vBond vSmart vBond vSmart vBond


Viptela MSP Private
Cloud Cloud Cloud

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Viptela hosted Controllers / Public Cloud

Region 1 Region 2

optional/
standby
Private IPs Private IPs vManage
1:1 NAT 1:1 NAT
Public IPs Public IPs

• Control Plane on Public Internet Only

INET • Most commonly deployed model


• Supports data plane on other
transports (MPLS, Leased Line, etc)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Hybrid Cloud Controller Deployment
DC/Region 1 DC/Region 2

No NAT optional/
standby
Public IPs Public IPs vManage
DMZ
FW BGP
BGP DMZ
FW
• Control Plane on MPLS and
Internet
• Public IPs are assigned to the
controllers
MPLS INET
• No NAT is used
• For security compliance FW/DMZ
on Internet facing side

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Hybrid Cloud Controller Deployment

DC/Region 1 DC/Region 2

optional/
standby
Private IPs Private IPs vManage

NAT +
DMZ/FW • Control on MPLS and Internet.
BGP NAT +
BGP Public IP DMZ/FW • Private IPs on the controllers.
Public IP • NAT/FW facing the internet
No NAT
NAT • vBond must have Public IP or
MPLS INET sit behind 1:1 NAT

• Controllers have to talk to


vBond through NAT for this to
work

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Control Plane Deployment
Public Cloud Controller Deployment
DC/Region 1 DC/Region 2
vpn512 vpn512

INET vEdge Cloud co-exist with the controllers

vEdge participate in the overlay

Traffic between the controllers and NMS


DC systems in the DC goes on the overlay
TACACS/RADUIUS
Syslog Server tunnels securely
SNMP Server
NMS Tools
etc

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Gateway - DC Site Deployment and Migration
DC/Gateway Site
• Identify Gateway/DC Sites providing
BGP/OSPF connectivity between SD-WAN and legacy sites
• Legacy sites talk to each other directly

• SD-WAN sites talk to each other directly


OMP
• Legacy router/connectivity is dropped in the
DC/Gateway sites once migration is complete

Internet SD-WAN
MPLS
OVERLAY

OMP
OMP
OMP Legacy/MPLS Sites

SD-WAN Sites
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Large Enterprise with Global Distribution
WAN Components connected via overlays from Viptela SEN utilizing Internet, LTE, etc.
Viptela
ZTP/Central Done on Monitoring/Syslog Done on
Viptela Connectivity Active-Active
Config/Policy /NetFlow Viptela, Nagios

App-
Done on Built-in/ No
Routing/PfR/Servic Segmentation Multiple VPNs Encryption
Viptela key-mgmt
e Chain
SECURE
CONTROL PLANE

North America DCs APAC DC Europe DC

Data Center Data Center


Data Center
DC Core DC Core DC Core

Ethernet Exit
(DSL/Cable/LTE/MPLS)

vEdge Router Viptela SEN


LTE
Backup
Switch

Internet SECURE
WiFi APs DATA PLANE

Field Field Field


Stores Offices Distribution Centers Stores Offices GS Stores Offices

© 2018 Cisco and/or its affiliates. AllAmericas


rights reserved. Cisco Confidential Asia Europe
Example Of 100-site (Small Enterprise) -
Agilent ZTP/Central
Done on Active- Monitoring/Syslog/
vManage
HP NNM
Seemly Migration
No impact to
traffic:
Config/Policy/SW Connectivity (Brownfield)
Viptela Viptela Active cFlow Riverbed Migrated to Non-
Upgrade
Stealcentral migrated

order ISP DIA


Rapid Site
App-Routing/Circuit Done on Single circuits first,
Segmentation Encryption Done on Viptela Bring-up
Selection Viptela VPN then MPLS (if
(Paradigm Shift)
needed)

SECURE Selective
CONTROL PLANE Traffic Symmetry Done on
Split-Tunnel 80/443 GRE to VPN Topology Full Mesh IAAS and SAAS AWS, SFDC, o365
across regions Viptela
ZScaler
Platinum
(Dual MPLS, Dual Broadband) North America DCs APAC DC Europe DC

Gold
Data Center Data Center
(Single MPLS, Single Broadband) Data Center
DC Core DC Core DC Core
Silver
(Dual Broadband)

Bronze
(Single Broadband)

vEdge Router

Switch

OBS Viptela SEN


MPLS

Business Class Internet SECURE


DATA PLANE

Large Medium Medium Small Large Medium Medium Small


Medium Small

© 2018 Cisco and/or its affiliates. AllAmericas


rights reserved. Cisco Confidential Asia Europe
Variety Of Deployment Models
Side-by-Side Hybrid With Fallback Full SDWAN

Site B Site B Site B

Existing Existing
vEdge vEdge vEdge vEdge
Router Router

MPLS Internet MPLS Internet MPLS Internet

Existing Existing
Router vEdge Router vEdge vEdge vEdge

Site A Site A Site A

Secure Virtual Fabric Secure Tunnel


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Framework

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Framework
Centralized and Localized Policies
vManage

NETCONF/YANG

Device Configuration Device Configuration

Centralized Control Policy Local Control Policy


(Fabric Routing) (OSPF/BGP)
Localized
Centralized Data Policy
Centralized Policies Local Data Policy
(Fabric Data Plane) Policies (QoS/Mirror/ACL)
Centralized App-Aware Policy
(Application SLA)

OMP

Centralized Data Policy Centralized App-Aware Policy


vSmart (Fabric Data Plane) (Application SLA) vEdge
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Centralized and Localized Policies
• The Cisco SDWAN policy software design provides a clear separation between centralized and localized
policies. Centralized policy is provisioned on the centralized vSmart controllers and the localized
policy is provisioned on vEdge routers

• With Localized Data policy, also called an access list, you can provision QoS to:
• Classify incoming data packets into multiple forwarding classes based on importance.
• Spread the forwarding classes across different interface queues.
• Schedule the transmission rate or weights for each queue

• With Centralized policies on vSmart controllers:


• Centralized Control policies affect routing policy to influence routing decisions on the vEdge routers. This
type of policy allows you to set preferences for the routes or paths on the vSmart controller and is
reflected in forwarding tables on the vEdge routers.
• Application-Aware routing policies select the best path for a given application based on SLA requirements.
These requirements include latency, packet loss, and jitter. Application-aware routing policies are
configured on vSmart controllers and are enforced by vEdge routers.
• Centralized Data policies are used for traffic classification, DSCP marking, path selection, service
insertion, policing, etc. Data policies are configured on vSmart controllers and enforced by vEdge routers.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Driven WAN Infrastructure
Policy Augmented Dynamic Routing

1 vManage GUI – Policy Orchestration

App-Route Policy: Data Policy:


Control Policy:
App-Aware SLA-based Extensive Policy-based
Routing and Services Routing Routing and Services

Combine and Apply per Site

2 vSmart controller – Policy


Enforcement/Advertisement
Execute Control Policy
Advertise AAR/Data Policies to Sites

3
vEdge
WAN
router Execute AAR and Data Policy as received
Dynamic Routing and Policies Combine to
dictate behavior
Access Layer

Branch/DC

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Distribution
Data Policy Control Policy
Local Policies
App Aware Routing Policy VPN Membership Policy

vManage vManage vManage

NETCONF/YANG NETCONF/YANG NETCONF/YANG

vSmart vSmart vSmart vSmart vSmart vSmart

OMP OMP

vEdge vEdge vEdge

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Packet Flow Through the vEdge Router
Local Policy,
Centralized Application Aware Shaping and ACL
Routing
Routing Policy
Forwarding Shaping
Re-marking
Path selection based on SLA Policer, ACL

4
2 6

Service VPN Transport VPN

1 3 5

Centralized Data Policy Scheduling


Local Policy / Configuration and Queuing
Policer
Policer LLQ
Admission Control
Admission Control WRR
Classification
Classification RED
Marking / Remarking
Marking
Path Selection

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Centralized (vSmart) Policy Architecture
• vSmart Policies consist of these building blocks:
• Lists used for defining targets of policy application or matching
• Policies controlling aspects of control and forwarding
Control Policy
Application Aware Policy
Data Policy
cflowd-template
vpn-membership-policy
• Policy Application to control towards what a policy is applied
Site-oriented and defined by a site-list

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vEdge Routing Policy Architecture
• Routing Policies are traditional routing policies
• Attaches to BGP or OSPF locally on the vEdge
• Used in the traditional sense for controlling BGP and OSPF
Information exchange
Attributes
Path Selection

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Construction
• Lists – list of
data-prefix-list Policy Definition Policy Application
prefixes for use with a data-
policy
• prefix-list – list of • Control Policies
prefixes for use with any
affect overlay routing • An apply directive
other policy
• Site-list – list of site-id:s
• Application Aware is used in
for use in policy and apply- Routing policy is used conjunction with
policy in conjunction with site lists to
• Tloc-list – list of tloc:s SLAs to steer traffic enable specific
for use in policy • Data policies provide policies at
• Vpn-list – list of vpn:s for VPN level policy based specific locations
use in policy routing
• Colors – List of colors for
use in policy
• SLAs – SLA definitions
Centralized policy definition configured on vManage and enforced across entire network

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Construction - Lists
• application-list used in data-policy to define
policy specific applications for traffic matching and
lists
data-prefix-list app1 policy actions
ip-prefix [Link]/32
port 100 • data-prefix-list used in data-policy to define
! prefix and upper layer ports in various
prefix-list pfx1 combinations for traffic matching
ip-prefix [Link]/32
! • prefix-list used in control-policy to define
site-list site1
site-id 100
prefixes for RIB matching site-list used in
! control-policy and apply-policy to match source
tloc-list site1_tloc sites or define sites for policy application
tloc [Link] color mpls
vpn-list vpn1 • tloc-list used in control-policy to define
vpn 1 tlocs for RIB matching and to apply redefined
!
!
tlocs to vroutes
• vpn-list used in control-policy to define
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential prefixes for RIB matching, in data-policy and
vSmart Policy Construction – Policies

• Policy definition dictates type of policy and


the appropriate syntax
policy
policy-type <name> • VPN-list used by data-policy and app-route-
vpn-list <vpn-list>
sequence <n>
policy to list the VPNs for which the policy
match <route|tloc|vpn|other> is applicable
!
action <accept|reject|drop> set • Sequence defines each sequential step of the
<attribute> <value> policy by sequence number
!
default-action <reject|accept> • Match decides what entity to match on in the
!
! specific policy sequence
!
!
• Action determines the action for the preceding
match statement
• Default-action is the action to take for any
entity that was not matched in any sequence of
the policy (set to reject by default
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Construction – Policy Application

• Site-list determines to which sites a given


policy is applied
• Direction applies only to control-policies
apply-policy
site-list <name>
• Policy Type and Name refers to an already
control-policy <name> <in|out> configured policy to be applied towards sites
!
site-list <name>
specified in the site-list for the section
data-policy <name>
vpn-membership <name>
!
!

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Example
apply-policy
site-list site1 Apply the defined policy
control-policy prefer_local out towards the sites in
!
site-list
policy Define the lists required for
lists apply-policy and for use
site-list site1
site-id 100
within the policy
tloc-list prefer_site1
tloc [Link] color mpls preference 400
!
control-policy prefer_local Define the actual policy to
sequence 10
be applied
match route
site-list site1
!
Lists previously defined
action accept used within policy
set
tloc-list prefer_site1
! Note: Items listed as presented in node
! configuration. The order in which elements are
! configured should be lists, control-policy then
apply-policy

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vSmart Policy Processing
• Policies are processed sequentially. Order is important!
• When a match occurs, the matched entity is subject to the configured
action of the sequence and is then no longer subject to continued
processing.
• Any entity not matched in a sequence is subject to the default
action for the policy.
• Any node will make use of any and all available routing information
• In a multi-vSmart deployment, every vSmart acts independently to
disseminate information to other vSmarts and vEdges
• vManage acts as the entity to ensure all vSmarts are synchronized.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
1. Control Policies
• Control policies are executed on vSmarts to influence overlay
routing.
• Control Policies are used to enable the following services:
• Service Chaining
• Traffic Engineering
• Extranet VPNs
• Service path affinity
• Arbitrary VPN Topologies
• Control Policy is a powerful tool for any type of path
construction that simplifies policy operations by being
centrally managed.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Centralized Control Policy: Inbound vs.
Outbound
• Inbound Policy: determines
which routes are installed in
the local routing database of
the vSmart controller.

• Outbound Policy: applied AFTER


a route is retrieved from
routing database, but BEFORE
the vSmart controller
advertises it.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
2. Application-Aware Routing Policy
• Application-aware routing consists of three components:
Identify the applications of interest. To determine which applications are running on
vEdge routers, you enable application visibility on these devices. Then you configure
an application-aware routing policy on the vSmart controller, which defines the
applications of interest and the data plane tunnel performance characteristics
required to transmit an application's data traffic. These characteristics are called
a service-level agreement (SLA). The controller automatically pushes the policy to
the appropriate vEdge routers.
Monitor and measure data plane tunnel performance is done automatically and
continuously by the vEdge routers, by tracking BFD Hello packets. Application-aware
routing periodically polls the performance statistics to calculate the packet jitter
and latency and packet loss information for each tunnel. The default polling interval
is good for most network situations, but you can modify it to meet specific business
needs.
Map application traffic to a specific data plane tunnel is done on the vEdge routers,
based on the SLA requirements defined in application-aware routing policy and based
on the real-time performance of the vEdge routers' data plane tunnels. You can modify
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application Aware Routing
• An app-route policy is defined through the following steps:
• Define the required SLA classes
• Define the app-route-policy
• Apply the app-route-policy towards the applicable sites
• The SLA-class defines the required loss, latency and jitter
thresholds for the application that is to go via the overlay
path
• The app-route-policy defines the traffic that is to belong to
a defined class in a fashion similar to a data-policy
• Configuring an app-route-policy includes a reference to a
VPN-list to dictate which VPNs will benefit from the policy
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application-Aware Routing Policy
Configuration
Step 1: Create a list of sites to which the
application-aware routing policy is to be applied
policy
lists
site-list mySites Step 3: Create lists of applications, IP
site-id 100-200 prefixes, and VPNs to use in identifying
! application traffic of interest (in the match
section of the policy definition
policy
lists
Step 2: Create SLA classes and traffic vpn-list myVPN
vpn 10
characteristics to apply to matching application !
data traffic.
policy data-prefix-list approute-Prefixes
sla-class bulk-data-sla ip-prefix [Link]/16
latency 150 !
! app-list myApps
sla-class critical-data-sla app office365
loss 5 app salesforce
latency 150 !
! !
sla-class voice-sla !
loss 1
latency 100
jitter 5
!

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Application-Aware Routing Policy
Configuration
Step 4: Create an application-aware routing Step 5: Within the policy, create one or more
policy instance and associate it with a list of numbered sequence of match–action pairs
VPNs
policy
policy
app-route-policy myApproutePolicy
app-route-policy myApproutePolicy
vpn-list myVPN
vpn-list myVPN
!
sequence 10
!
match
app-list myApps
!
action
Step 6: Specify the default action for the sla-class critical-data-sla preferred-color mpls
policy !
policy
app-route-policy myApproutePolicy !
vpn-list myVPN sequence 20
default-action sla-class bulk-data-sla match
! dscp 46
! !
! action
sla-class voice-sla preferred-color mpls
!
!
sequence 30
Step 7: Apply the policy to a site list: match
destination-data-prefix-list approute-Prefixes
apply-policy !
site-list mySites action
app-route-policy myApproutePolicy backup-sla-preferred-color public-internet
! sla-class bulk-data-sla preferred-color biz-internet
! !

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
3. Data Policy - Applications and Services
• Data Policies provide the functionality equivalent to traditional Policy
Routing.
• Data policies are configured and applied centrally (vSmart), then pushed to
vEdge to enforce the configured policy in the data plane
• Some of the applications enabled by Control Policies can also be enabled by Data
Policies, in addition to more traditional Policy Routing as well as data-plane bound
functions

• A Data policy acts on an entire VPN and is not interface-specific


• Data Policies are used to enable the following services:
• QoS Classification
• Service Chaining
• cflowd
• NAT
© 2018 •CiscoTraffic Policing
and/or its affiliates. and Counting
All rights reserved. Cisco ConfidentialTransport Selection
Centralized Data Policy Configuration
Step 1: Create a list of sites to which the
Step 3: Create a data policy instance and associate
centralized data policy is to be applied
it with a list of VPNs. Within the policy, create
policy
one or more numbered sequence of match–action pairs
lists
site-list mySites
site-id 100-200 policy
! data-policy myDataPolicy
vpn-list myVPN
sequence 10
Step 2: Create lists of IP prefixes and VPNs, as match
needed app-list myApps
policy !
lists action
prefix-list myPrefixes accept
ip-prefix prefix/length set
! dscp 32
vpn-list myVPN !
vpn 1
!
app-list myApps
app office365 Step 4: Apply the policy to one or more sites in the
app salesforce overlay network
!

apply-policy
site-list mySites
data-policy myDataPolicy (all | from-service | from-tunnel)
!
!

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
4. Cflowd flow data collection
• Cflowd flow collection is enabled by means of a vSmart policy
• Capturing and exporting flow data is controlled via 2 different
policies:
• Cflowd-template for configuring flow cache behavior and flow export
• Data-policy for selection of traffic subject to flow data collection

• The Cflowd template is optional and without is the flow cache in


vEdge nodes is managed using default setting and no flow-export
takes place
• The data-policy can be configured to be very specific or as a
general flow collection filter, depending on requirements
• Both components controlled and distributed from vSmart to ease
© 2018
enablement and configuration
Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cflowd Example
apply-policy
site-list site100
data-policy cflowd_data all
cflowd-template cflowd_temp
!
!
policy
Data-policy
data-policy cflowd_data
vpn-list cflowd_vpn • Covers traffic subject to flow data
sequence 10 collection
match
protocol 17
!
action accept
cflowd
!
! cflowd-template
default-action drop
! • Manages settings related to cache
! management and flow export (not
cflowd-template cflowd_temp mandatory)
flow-active-timeout 60
flow-inactive-timeout 60
collector vpn 100 address [Link] port 4739 transport transport_udp
!
!
* vpn-list and site-list excluded, please refer to app-route section *
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
5. VPN Membership Policy
Functionality

• The default behavior of the SDWAN OMP architecture is to advertise any


configured VPN to any node where it is configured
• This automatically establishes connectivity without unnecessary configuration
and operational overhead
• However, certain VPNs may be of a sensitive nature such that their membership
must be tightly controlled
• The VPN Membership Policy serves to restrict the distribution of VPN
information from vSmart to those that are explicitly approved
• Both Whitelist and Blacklist behavior can be established

• With a VPN Membership Policy, a node not explicitly allowed to participate in


a VPN may have the VPN configured but will only see local connectivity and
routing information

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
VPN Membership Policy Example
Policy Policy
lists vpn-membership acme_1
site-list sites_1 sequence 10
site-id site1 match vpn-list sites_1
site-id site2 action accept
! !
site-list sites_2 !
site-id site3 default-action reject
site-id site4 !
! vpn-membership acme_2
vpn-list sites_1 sequence 10
vpn 10, 20 match vpn-list sites_2
! action accept
vpn-list sites_2 !
vpn 30, 40 !
! default-action reject
! !
! !

vpn-lists define the VPN match data apply-policy


site-list sites_1
vpn-membership acts as either vpn-membership acme_1
whitelist or blacklist for VPN filtering !
site-list sites_2
apply-policy acts in both directions to vpn-membership acme_2
determine which VPN(s) are allowed !
from a given site !
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Operational Simplicity
and Transparency

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Single Pane of Glass Operations
vManage GUI

• Intuitive GUI driven operations


Management, monitoring and
troubleshooting
• Cloud Delivered
Private, hosted or managed
• Single or Multi-tenant
• Role-based Access Control
• Clustered for scale and high
availability
• REST APIs based

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Template-Based Configurations
Centralized Device Configuration Enforcement
• Templates are attached to provisioned
vEdge routers
• Variables are used for rapid bulk
configuration rollout with unique per-
device settings
• Local configuration changes are not
allowed
- Prevents configuration drift

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Granular Policies
Centralized Control over Fabric Behavior

• Centralized data, control and


application aware routing policies
• Defined on vManage, enforced on
vSmart controllers (control policies)
or vEdge routers (data and
application aware routing policies)
• Individual site, collection of sites or
the entire fabric policy scope

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Troubleshooting and Verification
Transparent Operations

• Embedded tools for data plane


connectivity verification
• Control plane health verification
• Real-time GUI based
troubleshooting
• Full command line interface and
Linux shell for expert level
troubleshooting
• Alarms for triggered events

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Self-Healing
Software Upgrade and Configuration Change

Failed
2 Upgrade 1 vManage

Attach Template
Active Software A Rollback
Available Software B
Activate 3
Available Software C Connectivity
2 Lost
1 Available Software D

Rollback

3
vEdge Router vEdge Router

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Current Orchestration and APIs
REST

vManage  Management
Netconf  Monitoring
 Provisioning
Syslog  Troubleshootin
g
vSmart * [Link]
SNMP
cFlowd*
CLI

Secure
Internet Control Plane
4G/LTE
MPLS
Secure
Data Plane

vEdge Routers

Data Center Campus Branch Home Office


© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vManage Programmatic Access
REST API Documentation

• API Documentation built-in – [Link]

• Test calls can be executed directly from doc page

• API programming documented at:


[Link]
w/Using_the_vManage_REST_APIs

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Network Automation
decouple Lifecycle of Product-Services and Network Resources Services

• Decouples the Network from


OSS/ITIL
OSS / ITIL • Unlocks agility and
Product/ flexibility at the Resource
Service Facing Services layer (RFS)
Systems
Lifecycle • Enables DevOps at the
network/RFS layer
Well-defined API
• Network changes and new
Resource Facing Services (RFS) features can be rolled out
continuously during
Physical Networks Virtual Networks run-time, i.e. DevOps Network
Service Orchestration System
Network
Service
Lifecycle

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN MSP Management Options
NSO/vManage Split NSO Single Entry Point

OSS/BSS - VMS OSS/BSS

REST/NETCONF
REST/NETCONF REST

NSO SDWAN CFP

NSO vManage
REST Other CFP vBranch CFP vManage NED
SDWAN –SITE vManage
CFP NED

vBranch
CFP NETCONF vManage

NETCONF NETCONF
NETCONF

Cisco ENCS vEdge cEdge Cisco ENCS vEdge cEdge


Router NFVIS Appliance Appliance Router NFVIS Appliance Appliance

• vManage and NSO Entry Point (REST APIs) • NSO Single Entry Point
• vManage improved with NSO (and vBranch, SDWAN, • SDWAN network wide Service Model that includes:
potentially SAE CFP) VNFs instantiation (including 3rd party VNFs) and vEdge
activation
• vManage and/or NSO as potential entry point
Controller instantiation
• Reporting and Alerts Device template definition
SDWAN policies definition
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Topology definition
vEdge Cloud Provisioning / Activation
vManage Control and Policy
Network Service Orchestrator (NSO) 2 Elements

Core FP Core FP Get the unclaimed vEdge Cloud


(vBranch) (SDWAN-SITE)
router list from vManage. Get
Bootstrap Configuration file
Define SDWAN Service on (cloud-init config file) which
1 ENCS (VNF and Chaining) contains cloud-config
(bootstraps) and cloud-boothook
(day0) sections 5

7
3 Full Registration and
Configuration
6

4
VNFs instantiated and loaded with vEdge
Bootstrap Configuration cloud-
init file. Chaining of VNFs Virtual Networks
occurred if requested. (ENCS)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NSO with the vBranch
Function Pack

On Boarding ENCS/NFVIS
Network Service Orchestrator (NSO) Network Service Orchestrator (NSO)

PnP 3 Core FP (vBranch)

• 1) ENCS boots and creates basic n/w


infrastructure

• 2) NFVIS registration to NSO using PnP


2 4 – IP + serial + model + capabilities

• 3) NFVIS registered to NSO

• 4) NSO connects to branch NFVIS (NETCONF)

• 5) ENCS/NFVIS on-boarded in NSO


PnP VNFM vEdge

1
NFVIS 5

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
NSO with the SDWAN-SITE
Function Pack
vEdge-Cloud Onboarding process
• 1) Upload vEdge Certified Serial Numbers onto vManage
NSO Network Service Orchestrator (NSO) (one time setup)
• 2) Get the unclaimed vEdge Cloud router list from
PnP Core FP (vBranch) Core FP (SDWAN-SITE)
vManage
• 3) Instruct vManage to generate a Bootstrap
1 Configuration file for the vEdge Cloud Router (OTP,
2 UUID, vBond, Org Name)

3 • 4) Get Bootstrap Configuration file for the vEdge


Cloud router (cloud-init config file) which contains
5 6 4
cloud-config (bootstraps) and cloud-boothook (day0)
9 sections
• 5) VNFs instantiated and loaded with Bootstrap
Configuration cloud-init file. Chaining of VNFs
vManage occurred if requested.
• 6) NFVIS notifies NSO vEdge is alive
7 • 7) vEdge to Viptela Control Plane Initial control
VNFM vEdge communication
• 8) vManage installs certificate into vEdge Cloud
NFVIS 8 router and sync up. vEdge Cloud router is ready for
configuration from vManage
• 9) Poll vManage to verify vEdge Cloud router is in-
Value added services sync
BranchInfra Viptela callback
provided by sdwan-site
© 2018 Cisco and/or its
functionality
affiliates. All rights reserved.
activity
Cisco Confidential
vAnalytics

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics
Customer Data Data Transfer and Storage
• Client authenticated and data securely
transmitted from vManage to vAnalytics
• Data storage isolation between
vAnalytics customers
Clusters Data Lake
• No PII (Personal Identifiable
Information) is collected
Data Correlation and Algorithms
• Only management data (stats, flows)
information collected
• All algorithms visualization done on a
per-customer basis
• IP Addresses collected for provider
look-ups
• Peer benchmarking (future use cases)
only on a group basis. No individual
customer data used

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Power of Analytics
Application Centric (Based on DPI/cflowd)
1. Bandwidth Usage:
1. Identification of top sources / top destinations / top application (family)
2. Drill-down into information on a per-Site basis
3. Identification of top sources

2. Application Performance:
1. Application to tunnel-binding and performance information

3. Anomaly Detection:
1. Baseline of Application usage. Anomaly detection based on overall application
usage / by Family / by Site

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
The Power of Analytics
Network Centric
1. Site Availability (SD-WAN value prop)
1. List of Sites with down-time comparing to TLOCs with their down-time

2. Network Availability
1. List of sites by down-time
2. Comparison of Site down-time vs TLOC down-time (SD-WAN value prop)
3. Down site count on a time basis with the ability to drill-down into Sites and
downtimes

3. Site Usage Analysis


1. Bandwidth consumed by Site (Top Sites)
2. Drill-down to show historical bandwidth consumption by time

4. Carrier Performance
1. App-Route stats based on a per-carrier basis
2. Ability to drill-down on a specific carrier and visibility into various remote
© 2018
carrier connectivity
Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics Dashboard

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics – BW Consumption by Applications

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
vAnalytics – Network Health by Carriers

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Pricing Structure

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SDWAN Pricing Model
The Cisco SDWAN pricing model consists of two components

1. Subscription* license (1YR, 3YR and 5YR) for Viptela software charged per CPE. This cost is dependent on
two factors:
• Service bandwidth. Slide 5 covers how service bandwidth is calculated.
• Features: Slide 3 covers feature buckets.

2. Perpetual cost of Viptela CPE** element.

Subscription
Perpetual cost of Viptela Operational
cost of software cost of
Viptela CPE (Includes SD- Viptela
hardware WAN controller solution
+ CPE software)

*Note: Subscription cost of Viptela software includes cost of SD-WAN controllers, 24x7x365 Viptela support, next day hardware
replacement for Viptela CPE, software upgrades on all components and the cost of hosting the Viptela controllers in the
Viptela cloud.

**Note: CPE can be Viptela manufactured or in the case of Virtual CPE customer/partner provisioned. Cost here implies
Viptela CPE only.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco SD-WAN Feature License Tiers
Plus Professional Enterprise
SDWAN management, SDWAN management, SDWAN management,
controllers Analytics
controllers controllers
Dynamic
Dynamic
Routing
Routing
Hub
Hub Spoke IaaS
Hub Spoke IaaS
Cloud
Cloud
AAR
AAR AAR
MPLS Interne Local Interne
MPLS MPLS Internet
t breakout E2E t
Segmentation SAAS E2E SAAS
Segmentation

Spoke Spoke Spoke Spoke Spoke Spoke


Spoke Spoke Spoke
Dynamic Routing Dynamic Routing

• Fabric: Management, Controllers, ZTP • All Plus tier features • All Professional tier features
• Routing: Static • Routing: Dynamic routing (OSPF/BGP) • Segmentation: Unlimited VPNs
• Topology: Hub-n-spoke only • Topology: Mesh topology, any • Analytics: vAnalytics platform
• Internet/Cloud: NAT, Split tunnel, IPSec • Internet/Cloud: Cloud onRamp for IaaS/SaaS • Optimizations: TCP Optimization
IKEv1/v2, GRE • Policy: Control policy, service insertion,
• Policy: Local ACL only, Data policy extranet
• QoS • Segmentation: 5 VPNs (transport + 4x
• SLA: Application aware routing (5 tuple service)
only) • SLA: Application aware routing (DPI)
• Segmentation: 2 VPNs (service + • Multicast
transport)
•© Visibility : DPI
2018 Cisco and/or for visibility
its affiliates. All rightsonly
reserved. Cisco Confidential
Pricing Tiers - Detailed

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 247
Bandwidth Licensing
Bandwidth entitlement* on vEdge is the sum of
peak bandwidth (either upstream or downstream)
across all WAN circuits.

Example: If a 50Mbps bandwidth license is


MPLS Internet 3G/4G/LTE
purchased the sum of peak circuit bandwidth
(either upstream or downstream) across Circuits
1, 2 and 3 must be less than or equal to 50Mbps.

Bandwidth entitlement also includes


Circuit Circuit Circuit i. Split tunnel (Direct Internet Breakout)
1 2 3 ii. Traffic offloaded to 3rd party cloud
services i.e zScaler.

TLOC
TLOC extension interface bandwidth is not
extension included in bandwidth entitlement.

*Note: Entitlement assumes the peak bandwidth


usage 95% of the time. This accommodates traffic
Branch bursts that might happen.

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Key Takeaways

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SDWAN Rollout and Positioning
Phase 1 – FY18 Phase 2 – 1HFY19 Phase 3-2HFY19
No Integration Platform Integration Management Integration
Deployment Scenarios

DNA Center
vManage vManage + SD-WAN

vEdge vEdge ASRISR + vEdge SW vEdge ISR4K + vEdge SW


Motion

vManage w/ vEdge/ENCS vManage w/ Any EN Platform DNA Center w/ Any Platform


Lead

-
-or- Meraki or- Meraki -or- Meraki
Dates

vEdge on ENCS (x86) = Nov’17 LA – Mar’18


Key

Late 2018
GPL = Feb’18 GA – Jul’18

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Clarification On SDWAN Terminology

Viptela H/W With All Software Capabilities As-Is


vEdge

SDWAN Enabled IOSXE for ISR4K, ASR, CSR & ISRv

"SDWAN Enabled Only Features Highlighted In The Next Slide Are Included In The SD-WAN
ISR"
Image

Traditional IOSXE With IWAN capabilities, for ISR4K, ASR, CSR &
ISR ISRv
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
251
Integration Roadmap In Planning

March 2018 -EFT July 2018 -GA release Post GA Roadmap

SD WAN Features: SD WAN Feature SD WAN Features:


 ZTP  All EFT features Cloud Onramp-SAAS
 App Route Policy  TLOC Extension TCP Optimizations
 QoS  Loopback interface IPv6 support (Service & Transport)
 Cloud Onramp –IAAS  Generic IPSEC Tunnel (IKEv1 and IKEv2) Service chaining
 Segmentation
 NAT DIA Monitoring & Troubleshooting Services
vEdge Capabilities

 BFD PMTU  vManage with DPI & Cflowd, Analytics • Multicast


Routing Protocols
 BGP, OSPF
Other Features
 VRRP
 DHCP server, DNS, RADIUS, Syslog, NTP
Monitoring & Troubleshooting
 System & Interface stats Capabilities:
• App QoE
Capabilities: • Security
 Security: • Umbrella
• Umbrella (DNS redirect) Services
Capabilities: • Zone Based Firewall
IOS Capabilities

 NBAR2 • AppNav Functionality


 Services • UC –SRST, PSTN GW, SIP GW
• NBAR2 SD-AVC • NBAR2-Custom App
Platform Platforms:
 ISR 4331, ASR 1001-x SDA segmentation use case
 C11xx, ISR43xx, ISR4221, ASR1001-X, ASR1002-X, Platforms:
ASR 1001-HX, ASR 1002 –HX, C111, ISRv (ENCS) • CSR, ENCS, ISR-4451, ISR-4431
New Interfaces 5412
 Ethernet, 4G LTE, T1/E1 • New Interfaces
New Interfaces: • Port Channel
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco  xDSL
Confidential
Cisco Enterprise Routing Portfolio moving forward
Cloud Branch WAN Edge
ISR 800 ISR 1000 ISR 4000 ASR 1000

CSR 1000V
• 10 Mbps to 10 Gbps • Up to 100 Mbps • Up to 250 Mbps • Up to 2 Gbps • 2.5-200Gbps
• DNA Virtualization • Fixed and fanless • Fixed and fanless • Modular • High-performance
• Extend enterprise • Enterprise-class • SD-WAN ready • Integrated service w/hardware
routing, security & branch routing • Integrated wired & container assist
management to cloud with security wireless access applications • Hardware & software
• Compute with UCS E redundancy

vEdge Cloud vEdge 100 vEdge 1000 vEdge 2000


• 10 Mbps to 100
Mbps
• Extend overlay to • 100 Mbps • Up to 1 Gbps • 10 Gbps
public cloud
• 4G LTE & Wireless • Fixed • Modular

Virtual
ISRv • 50 Mbps to 2.5 Gbps Cisco ENCS • Service chaining virtual
• Virtual enterprise-class networking functions
• Run on x86 compute platform • Modular WAN connectivity
• ENFV orchestration & management • Open for 3rd party services &
apps

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
MSP: SD-WAN Deployment Options
Virtual Managed Services Cisco
NSO + Core FPs
Deployment Model (VMS) NG SDWAN

Use Cases All 3 Standalone SD-WAN All 3


Consumption Models aaS, Cloud, SP managed Cloud, SP Managed SP Managed
Viptela for pure play SD WAN
Turnkey services: SDWAN with Infrastructure orchestration
(Network as a Service)
SP Value Prop vBranch supporting additional supporting vBranch and NFV
security and VNF service chains provisioning
SP Infrastructure Service Provider OSS/BSS
End User & Operator SP Viptela
VMS Portal o Portal or SP Provided SP Provided
Portals Provided
r
VMS Platform SP Dev & Integration SP Dev & Integration
Service Creation and APIs | Ordering | Billing | Ordering | Billing | Tenancy | Ordering | Billing | Tenancy |
Delivery Tenancy | Analytics | Assurance | Analytics | Assurance | Analytics | Assurance |
Management Management Management
Technology stack

NSO **optional* NSO NSO


Service VNF Mgmt
vManage
* VNF Mgmt
Orchestration
vManage vManage

vSmart, vSmart, vSmart,


Services NFVIS
vBond vBond vBond NFVIS
Infrastructure IOS-XE
vOS vOS vOS

vEdge vEdge
(vitual/Physic VNFs (vitual/Physic VNFs
al) al)
Data Plane
ENCS ISR vEdge ISR ENCS ISR
Converged Converged Converged
IOS / IOS / IOS /
vEdge SW vEdge SW vEdge SW
(Future) (Future) (Future)

© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
25

You might also like