Cisco ACI For Enterprise: Phil Casini
Cisco ACI For Enterprise: Phil Casini
Cisco ACI For Enterprise: Phil Casini
Phil Casini
Director Product Management
Cloud and Virtualization Group
Cisco’s IT Company Transformation
Reducing the Need for Business Operations To Be Expert Network Technology Centers
Is A Catalyst for Aligning with New Business Goals
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Increasing Network Programmability
a Key Cisco Strategy
A Controller that Can Manage Policies Across Network Domains is the Missing Piece
To Enabling the Adoption of Programmable END to END IT solutions
for Production Networks
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
ACI Enterprise Architecture
A Rich Portfolio of IT Solutions
SECURITY COLLABORATION SERVICES ORCHESTRATION IoE
Network Aware
Applications
Infrastructure
Endpoints
Technology Transitions
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
APIC for Enterprise:
Software VM for Servers
APIC
Features
OPEX Savings Business Agility
APIC EM
REST APIs
Enterprise Inventory and Identity and Application Policy
Elastic Infrastructure
SAL
CLI
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
SDN Innovation:
Network Information Base Provides One Source of Truth
• User Defined Group Tagging Allows Applications to Segment Analysis and Control (not shown here))
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Abstracts
and Automates
Network Control
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application:
QoS Classification Management
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application:
ACL Management
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Post Release 1.0:
Zero Touch Deployment with APIC-EM
Easy to use
PreProvision IT Admin Configure devices • Work Flow Based
IOS image for update
Sites Configuration Text file
Build site topology
Scales to network size
Assign Installer
Define match policy
• Centralized controller
Secure
• HTTPS based information flow
Internet Unskilled onsite installer
• No CLI
• Installer App for assistance
Device Support
• All Campus and Branch devices (not AireOS)
Installer
Site-1
Zero Touch Automated Device installation
Site-2 Site-3
• No Manual intervention
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Enables Dynamic
Policy Changes
Across the Network
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Policy Management Example:
Intent Based Policies
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Confidential
Enables Dynamic
Policy Changes
Across the Network
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Business Agility Example:
Dynamic Branch Network Security APIC EM Controller
Notification
Controller
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Business Agility Example:
QoS Video Classification Enables Enterprise Wide Jabber
APIC EM
Controller
QoS Changes
Pre-QOS change – Default Classification
Post QoS change - VideoQ
Enterprise Network
3945/ISRG2 3945/ISRG2
AVC
DMVPN
WAAS PfR
IOS FW
Centralized end to end network level view Greater control of Service Level Objectives for critical Apps
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Current Marketing Vision of APIC-EM and PI Roles
Operational Automation
Management Cisco IAC PRIME INFRASTRUCTURE APIC-EM Automated Service Provisioning
& UCSD & NAM Apps
Orchestration Network Aware Application
Layer Catalog/ Fault/ User / Data Performance Reporting /
Dynamic Service Assurance
Provisioning Events Management Monitoring Analytics
Control
Network Intelligence
Cisco APIC
Layer Common ACI Architecture Device Layer Abstraction
APIC for datacenter APIC - Enterprise Module Network Control
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
APIC-EM + Management Unified
Service /Policy Performance Change Reporting /
Definition Management Management Visualization
System of Record Multi-tenant Analytics driven Compliance Trending / Capacity
Operations Center troubleshooting Management Planning
Prime Apps
Hourly – x years of
NB REST API
historical data
Element & N/W
Mgmt Shared Centralized Network Services
Functions
System of Change across Mgmt
and APIC-EM Common Controller Services
~ short span data Southbound Programming Layer
(Common Models, NE communication, APIs)
Infrastructure NE NE NE NE
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Solution Demos Slides
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
List of Solution Demonstrations
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
QoS Video Classification Enables Enterprise Wide Jabber
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Business Agility Example:
QoS Video Classification Enables Enterprise Wide Jabber
Cisco
QO
1. Define new Application – Jabber Video APIC-
Enterprise S 2. Update QoS Policy
Module
EN
Controller
APIC-EM
QoS Changes
Pre-QOS change – Default Classification
Post QoS change - VideoQ
Enterprise Network
3945/ISRG2 3945/ISRG2
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application Driven Network Dynamics:
Dynamic Policy Management for Lync Audio/Video
Policy
Policy
REST API
APIC Applicati
QoS Markin
g Policy on
Dynamic Policy
Management
Traffic Queuing
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Dynamic Network Branch Security
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Dynamic Network Branch security
Controller
Notification
SDN Controller
Host Quarantined
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public SourceFire Senso
Investigation, Mitigation and Remediation using APIC-EM
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Investigation, Mitigation and Remediation using APIC-EM
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Investigation, Mitigation and Remediation using APIC-EM
Identity
APIC Enterprise Module
Context Security Services pxGrid
Quarantine
Investigation, Mitigation,
SIEM Remediation ISE
Core Services
Network Data
(Netflow, WSA, IPS)
Other Data
Intranet
Catalyst 3850 ASA
Sensitive Data
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Investigation, Mitigation and Remediation using APIC-EM
APIC Enterprise Module
NB-API Security Services pxGrid
Quarantine
Investigation, Mitigation,
SIEM Remediation ISE
Core Services
IPS
Investigate
Other Data
Intranet
Catalyst 3850 ASA
Sensitive Data
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Investigation, Mitigation and Remediation using APIC-EM
APIC Enterprise Module
NB-API Security Services pxGrid
Quarantine
Investigation, Mitigation,
SIEM Remediation ISE
Core Services
Mitigate
Security Group Tag = Suspicious
Other Data
Intranet
Catalyst 3850 ASA
Sensitive Data
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Investigation, Mitigation and Remediation using APIC-EM
APIC Enterprise Module
NB-API Security Services pxGrid
Quarantine
Investigation, Mitigation,
SIEM Remediation ISE
Core Services
Remediate
(Contain)
Other Data
Intranet
Catalyst 3850 ASA
Sensitive Data
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Threat Defense:
Investigation, Mitigation and Remediation using APIC-EM
APIC Enterprise Module
NB-API Security Services pxGrid
Quarantine
Investigation, Mitigation,
SIEM Remediation ISE
Core Services
Mitigate
(Block)
Other Data
Intranet
Catalyst 3850 ASA
Sensitive Data
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Optimizing Video for Citrix VDI
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application Driven Network Dynamics:
Optimizing Video for Citrix VDI
Cisco APIC Enterprise Module
Policy
Policy
APIC REST AP
I
QoS Mar
kin g Policy
Traffic Queuing
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco APIC-EM Extension for Mission-Critical Apps – SAP HANA
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application Driven Network Dynamics:
Cisco APIC-EM Extension for Mission-Critical Apps – SAP HANA
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application Driven Network Dynamics:
Cisco APIC-EM Extension for Mission-Critical Apps – SAP HANA
APPLICATION SAP BW on HANA
LAYER
• Provides a cross-layer solution that SAP Business Suite
Non-SAP
Apps
on HANA
optimizes the network for application SAP Legacy
Apps
Analytics on HANA
performance, in real-time, as business SAP HANA
Guided
Procedures
needs change in real-time.
Open
• Receives and processes real-time APIC-EM Apps-Driven
Network Dynamics Extension
SAP
Add-On
Interfac
e
performance data directly from the
application, database, and network. Plugin for SAP
Orchestration Management
• Isolates and remediates performance
Knowledge Base and Orchestrated Intelligent Actions
problems in the application, database Topology Mapping REST WS/CLI
and network, in real-time. Adapter Adapter
APIC-EM
• Listens to the application. Network Device Inventory Policy Management
PHARMACEUTICAL DISTRIBUTOR
ETL (Data SAP Distribution
Services) HANA Analytics
ITPA ELK
Data Center
PROVIDER
CAT 3850 Campus
onePK
ISR 2811
Presentation_ID © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public