Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

Brkarc 2014

Download as pdf or txt
Download as pdf or txt
You are on page 1of 77

BRKARC-2014

Branch Virtualization
The Evolving NFV Landscape

Matt Bolick - Technical Marketing Manager


Matt Bolick
Enterprise Routing Architect
bolick@cisco.com
@mattbolick

• 22 years in Technical Marketing


• Enterprise Routing and Network
Management
• 7200, 7500, 7600, 10000,
ASR1000, 2600/3600, ISR G1,
ISR G2, ISR 4000, ISR 1000,
ENCS, Virtualization
• Winston-Salem, NC

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda
• Branch Service Virtualization
Motivations
• Enterprise NFV
• SD Branch
• Enterprise Network Compute System (ENCS)
• UCS E-Series
• Open Service Containers and IOX

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Cisco Webex Teams

Questions?
Use Cisco Webex Teams (formerly Cisco Spark)
to chat with the speaker after the session

How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space

cs.co/ciscolivebot#BRKARC-2014

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Virtualization in the Data Center

Physical Servers & Appliances Virtualized Data Center

Long, Expensive Roll-Outs Service Agility


Under Utilization Efficient Resource Utilization
Inflexibility Opex Savings

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Application Virtualization in the Lean Branch Office
Balancing IT Efficiency and User Experience

Serverless Branch Lean Branch Full-Service Branch


Data Center/ Data Center/ Data Center/
Cloud Cloud Cloud

WAN/Internet WAN/Internet
WAN/Internet

Branch Office Branch Office Branch Office

• No local servers • 4-5 local servers • All servers local


• Full reliance on WAN • Full reliance on WAN except for • No reliance on WAN
• Simplicity, low cost mission-critical applications • Complexity, high cost
• No service guarantees • Service guarantees
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Function Virtualization in the Branch

Physical Branch Virtualized Branch

Long, Expensive Roll-Outs Service Agility


Under Utilization Efficient Resource Utilization
Inflexibility Opex Savings

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Network Function Virtualization in the Branch
Enterprise Service Provider
Increase revenue by accelerating
Reduction of network elements to delivery of new and differentiated
manage & deploy services

Service Elasticity & Reduce upfront Cap-Ex


Automated Network Operations Improve Asset Utilization

Operational efficiencies through Provide on-demand service delivery


virtualization – No Truck Roll through customer self-service portals

Deployment of best-of-breed Reduce Op-Ex & time-to-service from


months to weeks

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Levels of Network Function Virtualization
Fully Virtualized Branch
• General Purpose X86 Compute
• Full Service Virtualization
• Best-of-Breed Service Options

Integrated Services with Dedicated Server


• ISR4K + UCS C/E Series
• Native ISR Services + NFV Hardware
• Separate Administration Domains

Integrated Services
• ISR4K + IOX / Service Containers (KVM/LXC)
• Native ISR Services + Open NFV Flexibility
• All in One Design
BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Enterprise NFV and
SD Branch
Application Hosting Spectrum
Different models for different application needs.

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Application Hosting Spectrum
Cisco Enterprise Network Function Virtualization

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
What is Software Defined Branch Architecture?
Solution Oriented Approach
Centralized Orchestration and Management
SDN Applications

Consistent, trusted network services across all the platforms


Network Services and Applications

Hardware and software independence


Virtualization layer

Freedom of choice
Hardware platform

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Software Defined Branch
Deploy Services on Any Platform

Cisco DNA Center/ Network Service Orchestrator/ Virtual Managed Services

Virtual WAN
Virtual Router Virtual Firewall Optimization Third-Party
(ISRv,CSR,vEdge) (ASAv, NGFWv) (vWAAS) applications/VNFs

Network Functions Virtualization Infrastructure Software (NFVIS)

Enterprise Network
Cisco 4000 Series ISR + CSP-2100
UCS® E-Series
Compute System Cisco® UCS C-Series
(ENCS)

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
What SD Branch Can Do for You

Quickly roll out new services and locations


Simple and easy
to design, provision,
and manage the
Give you flexible deployment options
trusted services that
are critical
to your business
Simplify day-to-day operations

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Platform Built for Enterprise NFV
Branch/Campus
Colocation Center
ENCS 5000 Series for the Branch Public Cloud

Best of Routing Complete Open for Third Party


& Compute Virtualized Services Services and Apps

Enterprise Network Compute System

ENCS 5100 Series

ENCS 5400 Series

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
ENCS 5000 Series - Chassis Options

ENCS 5412
ENCS 5408 12-Core
ENCS 5406 8-Core
ENCS 5104 6-Core
4-Core

ENCS 5104 ENCS 5406 ENCS 5408 ENCS 5412


CPU 4-core, 3.4 GHz 6-core, 1.9GHz 8-core, 2.0GHz 12-core, 1.5GHz
LAN PoE No No 200W 200W
Capacity Guidance ISRv + 1 VNF ISRv + 2 VNFs ISRv + 3 VNFs ISRv + 5 VNFs

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
ENCS 5400 Series – I/O Side
Dedicated Lights- (Optional) Internal
Integrated 16 - 64 GB 6, 8, or 12-Core
out Management Hardware RAID M.2 Storage
Power Supply DRAM Intel Xeon-D
(CIMC) Controller 64 – 400 GB

8 Integrated LAN Ports USB 3.0 Network Interface 2 HDD or SSD


with Optional POE Storage Module for LTE & WAN RAID 0 & 1

Hardware 2 Onboard Gigabit


Acceleration for VM Ethernet ports with SFP
Traffic

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
ENCS 5100 Series - I/O Side

Size: 1 RU 16 & 32 GB 4-Core CPU M.2 Storage


DRAM ISRv + 1 VNF 64 – 400 GB Built-In 4G
13” x 10” LTE

Integrated Console 4 GE ports 2 x USB 3.0


Power Supply & MGMT with 2 SFPs Storage

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Data Path
Control Path

ENCS 5400 Internal Networking


ENCS 5400 Series

VNF 1 ISRv VNF 2


(NIC aware) (NIC aware)
HW offload for
VM-VM traffic Software
switched path
X86 / NFVIS

High-speed Lights-out
NIC CIMC
backplane management

Switch

VLAN-aware
X86 CIMC
HW Switch NIM
POE MGMT MGMT

Dual-PHY
Cellular, T1, Dedicated management
WAN GE or
DSL, LAN, GE ports
LAN uplink

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Typical ENCS 5400 CPU Allocation
• For Network VM Performance:
1 core = 1 vCPU = 1 physical core
(no hyperthreading)

Windows VM
Linux VM
• 1-core allocation for NFVIS to cover

vWAAS
NFVIS

ASAv
ISRv

OS, Hypervisor & vSwitch functions

• 2-core minimum allocation for ISRv

1 2 3 4 5 6 7 8 9 10 11 12 • Multiple VNF profiles target specific


Cores

performance

• Cisco VNFs will be pinned to


12-core CPU (ENCS 5412) respective cores for performance.
(Hyper-threading enabled)

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
ENCS-W vs ENCS
ENCS-W ENCS

• Standalone WAVE Replacement • Part of SD-Branch Solution


• Managed completely by WCM • vWAAS along with other VNFs
orchestrated by Cisco DNAC
• No interaction with • VM lifecycle management via
hypervisor(NFVIS) required hypervisor(NFVIS)
• Scale up to 6000 CC • Scales upto 750 CC
• Positioned when use-case • Positioned when usecase
involves standalone WAN / involves collapsing multiple
Application acceleration services (Routing, Firewall,
WAN-opt, etc) into single
• Perpetual license bundled with platform
appliance, same as WAVE • Term based licensing per VNF

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Purpose built Network Hypervisor
Enterprise NFV Infrastructure Software (NFVIS)
Network Hypervisor Zero-Touch Deployment Monitoring

 Supports segmentation of virtual  Automatic connection to PnP  Netconf Notification


networks server  Host and VM Statistics
 Abstract CPU, memory, and  Highly secure connection to the  Packet Capture
storage resources orchestration system
 Easy day-0 provisioning

Lifecycle Management Service Chaining Open API

 Provisioning and launch of VNFs  Elastic service insertion  Programmable API for
 Failure and recovery monitoring  Multiple independent service service orchestration
 Stop and restart services paths based on applications or  Rest and NETCONF API
 Dynamically add and remove user profiles
services

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
NFVIS Software Stack
Power in Software
Console/ DNA Local Device
NSO Web Portal
SSH Center

Health Monitoring Plug-n-Play RBAC

Syslog SNMP
CLI NETCONF REST HTTPS
Host
Hypervisor Layer Virtual Switch Management
Orchestration API

Linux

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Cisco SD Branch Chain of Trust

VNF Third Party


D (ISRv) VNFs
Virtual UEFI secure boot
C
Chain of Trust

Hypervisor (NFVIS)

B UEFI BIOS UEFI secure boot

Cisco Proprietary
A ENCS / UCS HW authenticity check

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Services from Cisco
Consistent software across physical and virtual

ISRv/SD-WAN ASAv/FTD* vWAAS vWLC


High Performance Application
Full DC-Class Built for small and
Optimization and
Rich Features Featured Functionality medium branches
Akamai Connect

Windows Server Linux 3rd Party


Active Directory, File Network Services
Custom Applications
Share, Server Management &
DNS/DHCP
Applications Monitoring

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
ISRv and CSR

Integrated Services Router - Virtual Cloud Services Router

Packaged for NFVIS Cloud and VDC Deployments


Branch-Specific Features Aggregation Use-Cases
Branch-Specific Pricing Flexible Pricing & Packaging
Look-and-feel of an ISR 4000 Virtual ASR 1000 Series
Not available separately Available on multiple platforms

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Reference
Third party VNF Certification Resources
http://cisco.com/go/enfv

Certification Program at DevNet, http://cs.co/3nfv

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
BRKRST-2112
Automated Orchestration, Management, Policy
Cisco DNA-C NFV Management

• Create standard profiles for different types of branches


• Cisco® tested and validated designs
• Embedded approval process and versioning

• Zero-touch deployment
• Automated orchestration of platform and VNFs
• Service chaining and licensing

• Health monitoring
• Dynamic scaling of services
• Operational SLA management

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Design your branch WAN connections

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Build your VMs

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
SDWAN onboarding using Zero Touch
Provisioning
Cisco SD-WAN Control and Policy
Redirect Elements
PnP Server 4
Server
3
Token and Serial Number
2 vEdge-cloud

PnP Call home


5

Deploy VNF Service


6
8

Chain
Full Registration and
1 Configuration

Assumption:
 DHCP on Transport Side (ENCS mgmt)  DHCP or Static IP (WAN Transport)
 DNS to resolve devicehelper.cisco.com*  DNS to resolve vbond fqdn
* Factory default config NFVIS

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
BRKARC-2112
Harnessing the power of Software
Defined Branch and SD-WAN

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
UCS E-Series
Cisco End-to-End Solution
UCS B-Series, C-Series and E-Series for Data Center and Branch Locations
Cisco UCS B/C Series Data Center/Cloud
Consolidate
Unified compute platform for infrastructure
Infrastructure
consolidation in the data center and large
branch offices. Offers innovative virtualization,
memory, provisioning, I/O, and management
capabilities. Centralize
Applications

Cisco UCS E-Series Servers WAN/Internet Support User


Residual compute platform with experience
all-in-one device convergence that facilitates
centralization of small to mid size branch office Address WAN-induced
performance,
applications into the data center. availability, compliance
challenges
Branch Office

Location-Suitable Form Factors, Consistent Device Management

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Application Hosting Spectrum
Different models for different application needs.

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Application Hosting Spectrum
Cisco UCS E-Series with Enterprise Network Function Virtualization
Cisco UCS E-Series with hypervisor or OS

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Cisco UCS E-Series DC-class Servers
Intel Broadwell

Intel Ivy Bridge Cisco UCS


Intel Broadwell E180D/1120D
Cisco ® UCS E160D
Intel Ivy Bridge  Double-Wide Service Module
Cisco UCS ® E160S  VMware, Hyper-V,
 Double-Wide Service Citrix certified
Cisco UCS ® E140S Module  Intel E5 8 core processor
 Single-Wide Service
module  VMware, Hyper-V,  96GB DRAM
Scalability

 Service module Citrix certified


 VMware, Hyper-V,
Citrix certified  Intel E5 6 core processor
 VMware, Hyper-V,
Citrix certified  Intel Broadwell 6 core  96GB DRAM
 Intel E3 4 core processor processor
 16GB DRAM  32GB DRAM
 USB 3.0 & 10Gb Interface

Performance
BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Cisco UCS E-Series Single-Wide Blade
Compact Blade Housed in Cisco ISR G2 and 4000 Series ISR
Chassis - Cisco UCS E140S M2 and E160S M3

Maximum 65 W power draw Intel® 4 Core Xeon® E3 family


80 percent less than server quad-core processor
8, 12, 16 GB and 32 6 Core Broadwell
GB DRAM options

Configuration and
management through
Remote and CIMC/IMC SUP or UCSD
schedulable power
management

Two SD cards: One for the CIMC


One external and temporary storage of OS and
10/100/1000 and two one as a blank virtual drive
internal GE ports No SD card on M3. UCS Flex Flash
10/100 Ethernet Up to 2 SATA, SAS, or SSD hard drives
management port
USB 2.0 or 3.0 port for
KVM console connector
external device connectivity
Wire-free, plug-and-play modularity, Onboard hardware RAID 0/1 with hot-
low shipping weight (2.5 lb/1.1 kg) swappable capability

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Cisco UCS E-Series Double-Wide Blade
Server Blade Housed in ISR 4000 – UCS-E140D/UCS-E160D/UCS-E180D/UCS-
E1120D

Maximum 130 W power draw, Intel Xeon Quad Core/Six-


8 GB – 96(128) 80 percent less than server Core/Eight-Core/12-Core iSCSI initiator
GB DRAM options Processor hardware offload

Remote and
schedulable power Out-of-band
management with super configuration and
capacitors management through
CIMC
Front-panel VGA, 2 USB 3.0, and
serial console connectors
Up to 3(4) SATA, SAS, SSD hard drives
Two SD Cards: one for the CIMC or 2 HDD and a PCIe card
and temporary storage of OS
and one for a blank virtual drive On-board hardware RAID 0, 1,
and 5 configuration options
with hot-swappable capability
Two external and two internal
GE(10GE) ports with TCP/IP Wire-free, plug-and-play modularity,
acceleration low shipping weight (7 lb / 3.2 kg)

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Cisco UCS E-Series Network Compute Engine
Compact, Multipurpose Blade Housed in 4000 Series ISR -
Cisco UCS EN140N M2

Up to 8 GB RAM

50, 100, 200 GB mSATA


SSD options
Intel® Atom
quad-core processor

One 2GB SD card


for CIMC
Dedicated
management port
KVM console
connector
USB 2.0 port for
external device
connectivity One external Gigabit
Ethernet port/ Two
internal Gigabit
Ethernet ports

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Cisco UCS E-Series Servers Support Model
Hardware Support Provided by Cisco
 Cisco UCS® E-Series hardware supported under host ISR SMARTnet® at no additional cost
 Hypervisor and OS supported by hypervisor and OS vendor
 Supported
by OS / hypervisor
vendor
 Option for Cisco
hypervisor (NFVIS)
 Purchased
Hypervisor separately or from
Cisco (NFVIS)
 Supported
Cisco® UCS E-Series Server Module by Cisco
SMARTnet
 Attached to ISR
ISR 4K

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
KVM Hosting on IOS-XE
Routers
ISR 4K, ASR1K, CSR1Kv
Cisco IOx
Cisco IOx is a simple yet powerful infrastructure framework allowing developers and operators to
securely onboard legacy and greenfield applications to their IoT edge infrastructure at massive scale and
creating business value from previously untapped data

Three components of IOx

IOx-enabled devices Developer tool Manageability tool

IOx
• Execute container or Virtual Machine • Zero touch deployment of devices
concurrently • Centralized device and application
• Run Windows or Linux applications life-cycle management at scale
• Easily-consumable System Services • End-to-End security

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Smooth workflow from developer to operator
Flexible, industry standard, purpose-built, and optimized for IoT edge

IOx Developer Tools IOx Management Tools

o o
App in any r r
language Custom
Custom IOx App
app in Package
(Windows app in .OVA
Docker
or Linux VM
containers
Developer based) Operator

Remote
Assets

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Application Hosting Spectrum
Different models for different application needs.

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Application Hosting Spectrum
Linux Containers

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Application Hosting Spectrum
Cisco Developed IOX & Service Containers

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Application Hosting Spectrum
Open IOX & Service Containers

Native Process LXC Docker KVM Type 1


• Very Tight • Strict Kernel • Emerging Industry • Any OS Hypervisor
Integration Requirements Standard • Complete • Service Module
• Best Performance • Good performance • Future Support separation Only
with some security • Linux host OS • VMWare, HyperV,
normally – Type 2 Zen…
hypervisor

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
IOS-XE Software Architecture
Customer and 3rd Party
IOSd Cisco Apps (WAAS, Snort)
Applications
Control Plane
KVM/LXC Virtual Ethernet

Linux OS

Platform-Specific Data Plane ERSPAN NSH AppNav

Internal Services Blade External Services Blade


(UCS® E-Series) (UCS)

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Cisco ISR 4400 Series Architecture
Hosted Apps live IOS
here
Control Plane (1 Data Plane (6 or 10
core) and Services cores)
Plane (3 cores)

FPGE

ISC
Multigigabit
Hosted App Fabric SM-X
KVM - Hypervisor

Service Plane
(control plane CPU) NIM
b BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Cisco ISR 4300 Series Architecture
Data Plane Cores

IOS

FPGE
Hosted Apps

Multigigabit ISC
Fabric
Hosted App SM-X

KVM - Hypervisor

Service Plane NIM


(control plane CPU) Note:4321 uses 2DP, 1CP & 1SC cores

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Cisco WAAS
Improve application performance and user experience
Virtual WAAS
• Application acceleration from
Private/Virtual Private Cloud
• VMWare ESX/ESXi and UCS
WAAS Appliance deployments
• Agile, elastic, multi-tenant deployment
• Application acceleration • vCM: common virtualized management
• Virtual blades in branch offices for physical/virtual WAAS
• Scalable platforms for range of
deployments
Hosted
App
ISR-WAAS on ISR 4K
• Integrated on platform
• Full Feature Parity
• Software on-demand provisioning
• No fork lift upgrade

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
IPS/IDS

Product Overview
 Open source intrusion prevention system for real-time traffic analysis
 Lightweight threat defense for price sensitive customers
 Integrated in ISR 4K as a hosted app
 IPS/IDS functionality with an IOS IPS look and feel

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Positioning IPS/IDS Solution for the WAN
Regulatory/ PCI Direct Internet access to partner sites or public Full DIA
Compliance cloud (i.e. Office365, Salesforce.com)

Internet guest Full DIA


access ISR 4451
115 – 270 Mbps
MSSP

ISR 4351
75 – 170 Mbps

ISR 4331
60 – 140 Mbps
ISR 4321
Up to 50 Mbps

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Common Open KVM Use Cases
Troubleshooting VM
General purpose virtual machine with custom and open-source troubleshooting tools.
(Wireshark, Speedtest, etc.)

Network Functions

Common network functions such as Print Server, Domain Controller, File Storage, etc.

Analytics

Network Analysis and Application Performance Monitoring without a dedicated probe.

Device Customization
Augment the capabilities of the host platform in some way. (Custom encryption,
business-based routing, specialized API interface)
BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Real-World Example

Example: Hybrid Services – Cisco IT


Problem: How to consistently monitor and troubleshoot a growing set of
business critical hybrid services (on-premise + cloud-based) ?

Solution: Detect and Alert via ThousandEyes Probes:


• Leverage existing Cloud-based Probes
• Deploy Mac-Mini Probes into key Locations
• Deploy Virtual Probes into key Locations
(IOS XE Virtual-Service on ISR 4451)

• Reduce MTTT -43% and MTTR -8%

See: blog.thousandeyes.com/troubleshooting-cloud-services-cisco © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
CA Unified Infrastructure Management
Unified IT Monitoring Providing Broad Coverage
A unified view and architecture
to manage
your internal and external infrastructure
.
MONITOR
BIG DATA MAINFRAME

APPLICATION VIRTUALIZATION
• Predictive Analytics
• SLA Compliance
• Dashboards &
USER EXPERIENCE Reporting STORAGE
• Intelligent Alerts

CLOUD
POWER & COOLING

DATABASE SERVER
NETWORK

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
UIM Reference Architecture Recommended Probe
Technologies included with
UIM CORE ISR UIM OVAs:
UIM • CDM/RSP
Virtual Image DB • SNMPC
Requirements: UIM • UCS
• Relay Hub: 1 CPU – Quad Portal UIM • URL Response
Core, 8GB Memory. Primary HUB • Net Connect
Redhat/CentOS 6 or 7. • DNS Response
• Polling Robot: 1 CPU – • XenApp
Quad Core, 8GB Memory. • e2e appmon
Redhat/CentOS 6 or 7.
Location Location Location
1 2 3
ISR 4400/4300 ISR 4400/4300 ISR 4400/4300
KVM KVM KVM KVM KVM KVM
Relay Polling Relay Polling Relay Polling
Hub Robot Hub Robot Hub Robot

Servers Network Servers Servers Network


Network
w/Robots Infrastructure w/Robots w/Robots Infrastructure
Infrastructure
BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Ned.io – Open Source Service Container
http://www.nedi.ch/running-nedi-on-a-cisco-router/
• Network Discovery,
Operation and Management
• Open application built
without any Cisco
involvement.
• Terrific option for low-
footprint branch
management

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
What do I need to add to an ISR4K system?
Memory
• Service Containers (currently) REQUIRE additional DRAM beyond the 4GB system
default
• Additional DRAM beyond 4GB will be available to a KVM application
• Example: 8GB DRAM will have 4GB available to Service Containers
• Example: 16GB DRAM will have 12GB available to Service Containers

Storage

• No storage is included by default and applications do not have access to bootflash.


• Options include internal MSATA SSD on 4300 Series, NIM-SSD or NIM-HD on all
ISR4K.
• Smaller sizes and lower reliability SSD options at lower price will be available in CY15.

Note: Newer ISRs ship with 8GB DRAM and often do not require more.
BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
ISR4K Services Core Specifications
Speed Relative Compute Min Additional Min Additional Min Additional
Platform Service Cores
(GHz) Power DRAM SSD HDD
ISR4451
3 2 6P 4GB 200GB 1TB
(Gladden)
ISR4431
3 1 3P 4GB 200GB 1TB
(Gladden)
ISR4351
3 2.4 3P 4GB 50GB 1TB
(Rangeley)
ISR4331
3 2.0 2.5 P 4GB 50GB 1TB
(Rangeley)
ISR4321
1 2.4 P 4GB 50GB 1TB
(Rangeley)
UCS-E NIM 4 1.6 2.6 P N/A N/A N/A

UCS-E EHWIC 2 1.6 1.3 P N/A N/A N/A

Normalize to Rangley 2.4 GHz core = 1P


Gladden 1GHz = Rangley 2.4 GHz

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Guest Shell Application
• Linux Shell Environment On Your Switch or Router
• Maintain IOS-XE system integrity
• Isolated User Space
• Fault Isolation
Linux
• Resource Isolation applications

• On-box rapid prototyping


Guest Shell
• Device-level API Integration
• Scripting (Python) Open Application Container
• Linux Commands API

• Application Hosting Network OS


• Integrate into your Linux workflow

• Integrated with IOS-XE

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Cisco Guest Shell Capabilities
Guest Shell 1.0 Guest Shell 1.0

Operating System IOS-XE IOS-XE

Platforms CAT 3650, CAT3850 CAT 9K, ISR 4000

Guest Shell Environment MontaVista CGE7 CentOS 7

Python 2.7 ✓ ✓

Python 3.0 ✗ ✓

Python GNU C Compiler ✗ ✗

RPM Install ✗ ✓

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Cisco Fog Director/Cisco DNA-C: App Life Cycle
Management
App Management & Monitoring at Scale
Easy to use
•Simplified application lifecycle management
•Stand Alone UI or may be integrated into 3rd party
applications restful APIs

Managing Application Resources


•Tracks IOx resource utilization (CPU, Memory, BW)
•Display per application and per device historical trends
•Establish per application status frequency from the onboard
agent

Manage Application Lifecycle


•Stage the application image within the local application
catalog
•Push changes to end-points
•Detailed application rollout tracking

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Fog Director/Cisco DNA-C: Application Dashboard
Enables management of application deployment to the edge devices at scale

View of installed
Apps Resource
consumption
dashboard

Instant status of
Apps running

Apps that are ready


to deploy

Apps that have not


cleared deployment
readiness yet

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Cisco Fog Director/Cisco DNA-C: Application Dashboard
Drilling down on deployed applications

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Hosted Application Support Model

CiscoParty
Third Support:
& Community Support:
Call TAC
TAC and they’ll
will redirect you.help you out.
Customer and 3rd
IOSd WAAS
Party Applications
Control Plane
KVM/LXC Virtual Ethernet

Linux OS

Platform-Specific Data Plane Cisco Devnet Provides:


• Community support for developers
• Documentation
• Developer Tools
• Access to Cisco Engineers
• Sample open source VMs
• Share open source projects
• Examples from Cisco Engineers

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
More Information
Cisco DevNet
• Online community for developers
• Direct access to Cisco Engineers and
Product Teams
• Repository of how-to guides, best
practices and sample code
• This will be the primary source for IOx &
Service Container documentation and
sample OVAs
• Due to Cisco support requirements,
VMs will generally not be posted to https://developer.cisco.com/site/iox/
Cisco.com directly.
https://developer.cisco.com/site/kvm/

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
IOx Sandbox: Online virtual test bed

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Product Specifications Comparison
ISR 4000 Series ISR 4000 Series
ENCS 5400 Series
with Hosted App with UCS-E

Embedded IOS-XE Container for light- Dedicated x86 blade server for Shared x86 platform for Routing &
Architecture
weight applications applications hosted applications

Legacy WAN Multiple Multiple Single

4G / LTE Support Yes Yes Yes

TDM Voice Yes Yes No

Switch-ports 72 64 8

Routing Throughput 2 Gbps 2 Gbps 1 Gbps

Resources for Applications

CPU Cores 1-3 12 9

RAM 12 GB 128 GB 64 GB

4 TB disks +
Disk 800 GB 8 TB
400 GB SSD

VMware ESXi, Microsoft HyperV &


OS / Hypervisors IOS-XE with embedded KVM NFVIS with embedded KVM
Citrix XenServer and more…

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Cisco Webex Teams

Questions?
Use Cisco Webex Teams (formerly Cisco Spark)
to chat with the speaker after the session

How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space

cs.co/ciscolivebot#BRKARC-2014

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Complete your online
session survey
• Please complete your Online Session
Survey after each session
• Complete 4 Session Surveys & the Overall
Conference Survey (available from
Thursday) to receive your Cisco Live T-
shirt
• All surveys can be completed via the Cisco
Events Mobile App or the Communication
Stations

Don’t forget: Cisco Live sessions will be available for viewing


on demand after the event at ciscolive.cisco.com

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Continue Your Education

Demos in Meet the Related


Walk-in
the Cisco engineer sessions
self-paced
Showcase labs 1:1
meetings

BRKARC-2014 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Thank you

You might also like