Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
BRKVIR-2017
BRKVIR-2017
Cisco Public
Agenda
Ciscos Virtual Networking Vision
Cisco Nexus 1000V Portfolio Overview
Recent Pricing Changes Architectural Overview Services Architecture
VSM VSG NAM DCNM Partners
Demo
vPath
Q&A
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved.
Nexus 1000V
Cisco Public 3
Forward-Looking Information
The information presented here on Nexus 1000V for Windows Server 2012 is under development and is subject to change before the general availability of these products.
BRKVIR-2017
Cisco Public
HYPERVISOR
VDC-1
VDC-2
BRKVIR-2017
Cisco Public
** 1H CY 2013
Network Services
Aggregation Typical L3/L2 boundary. Physical network services Unified Access Non-blocking paths to servers & IP storage devices
L2
NEXUS 5000
L2
VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM
NEXUS 2000
VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM
VM VM VM
VM VM VM
VM VM VM
VM VM VM
VM VM VM
VM VM VM
VM VM VM
VM VM VM
Rack 1
Rack 2 Rack 3
VM VM VM VM VM VM
Virtual Access Virtual network switches Virtual services with horizontal scaling
Cisco Public 6
Rack 1
Rack x
BRKVIR-2017
Multi-Cloud
Multi-Services
Multi-Hypervisor
BRKVIR-2017
Cisco Public
vCloud Director/ DynamicOps NSM ASA 1KV, vNAM vWAAS, VSG CSR 1KV vPath Nexus 1KV
System Centre NSM ASA 1KV, vNAM vWAAS, VSG CSR 1KV vPath Nexus 1KV
Open Source NSM ASA 1KV, vNAM vWAAS, VSG CSR 1KV vPath Nexus 1KV
Open Source (Xen, KVM)
CIAC/ OpenStack/ Partners NSM ASA 1KV, vNAM vWAAS, VSG CSR 1KV vPath Nexus 1KV
vSphere, Hyper-V, Xen, KVM
Hypervisor
vSphere
Hyper-V
Computing Platform
Physical Network Storage Platform
Tenant A
vWAAS Cloud Services Router 1000V Citrix NetScaler VPX
Zone B
vPath VXLAN
Nexus 1000V
Multi-Hypervisor (VMware, Microsoft*, RedHat*, Citrix*) Physical Infrastructure (Compute, Network, Storage)
Nexus 1000V
Distributed switch NX-OS consistency
VSG
VM-level controls Zone-based FW
ASA 1000V
Edge firewall, VPN Protocol Inspection
vWAAS
WAN optimisation App, traffic
CSR 1000V
(Cloud Router)
WAN L3 gateway Routing and VPN
Ecosystem
Services
Citrix NetScaler VPX
virtual ADC
Imperva Web App.
7000+ Customers
BRKVIR-2017
Shipping
Shipping
Shipping
CY2013
Cisco Public
Firewall CY2013
9
Utility
Community
Public
Network Services
Enterprise-Grade Crypto and Firewalling within & across clouds Transparent Application Migration; Centralised Management Choice of Provider Clouds and Hypervisors
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview
Recent Pricing Changes Architectural Overview Services Architecture
VSM VSG NAM DCNM Partners
Demo
Q&A
vPath
Nexus 1000V
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Advanced ($695/cpu)
Management
vTracker vCenter Plugin Virtual Security Gateway
12
Advanced Edition Get a 60-day free trial when you use essential
Download Software v2.1 from cisco.com
Get free upgrade to v2.1 Advanced Edition (at no cost) upgrade to This upgrade also includes free VSG licenses Existing TAC support contract will include VSG support Advanced Edition
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Seamless
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview
Recent Pricing Changes Architectural Overview Services Architecture
VSM VSG NAM DCNM Partners
Demo
Q&A
vPath
Nexus 1000V
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
1. VM Migration moves VMs across physical portsthe network policy must follow this VM Motion (across racks, PODS, DCs)
Port Group
Security Admin
BRKVIR-2017
Cisco Public
15
Operational Complexity Managing networks across physical & virtual environments Consistent Operational Model
Complex Workloads Requirement for a secure virtual environment with rich network services Multi-services support
Resource Utilisation
Multi-hypervisor Support
Multi-cloud support
VSM2
Modular Switch
Supervisor-1 Back Plane Supervisor-2
Linecard-1
Linecard-2
Linecard-N
VEM-1 VEM-2 VEM-N
Hypervisor
VSM: Virtual Supervisor Module VEM: Virtual Ethernet Module
BRKVIR-2017
Hypervisor
Hypervisor
Server Admin
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Nexus 1110
VSM NAM VSG
VSM: Virtual Supervisor Module VEM: Virtual Ethernet Module vPath: Virtual Service Data-path Virtual Blades
Virtual Supervisor Module (VSM) Network Analysis Module (NAM) Virtual Security Gateway (VSG)
vPath
Service Binding (Traffic
WS 2012 Hyper-V
WS 2012 Hyper-V
BRKVIR-2017
Cisco Public
18
Port management
VLAN
PVLAN Port-Channel
ACL
Netflow Port security QoS
Cisco Public 19
BRKVIR-2017
BRKVIR-2017
Cisco Public
20
Hypervisor
VM Connection Policy
Defined in the network Applied in Virtual Centre Linked to VM UUID
VM Mgmt Station Server Server
BRKVIR-2017
Cisco Public
21
Hypervisor
Hypervisor
VM Networking Mobility
VMotion for the network Ensures VM security Maintains connection state
Server
Server
VM Mgmt Station
BRKVIR-2017
Cisco Public
22
Non-disruptive Operational Model with Consistent NX-OS Feature-set and Services N1KV
VM Mgmt Center Nexus1000v VSM
Network Admins
Nexus OS CLI
Server Admins
VM Mgmt Interface
Install hypervisor on hosts with N1KV VEM Create VM and assign Port profiles to VM
No hand-off required between network and server admins Complete visibility to the VM-to-VM traffic Consistent feature-set & CLI for physical & virtual networks Same management tools used across physical & virtual networks
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
NAM (N1010)
Vblock FlexPOD Virtual Desktop Virtual Multi-tenant DC (VMDC) DC-to-DC vMotion PCI 2.0
Hosted Collaboration
BRKVIR-2017
24
DC
POD POD
DC
POD
POD
VLAN
VLAN
VLAN
VLAN VXLAN
BRKVIR-2017
Cisco Public
25
CDP
Syslog
vm-network-definition (id, vlan, ip-pool) for network segments logical-network-definition (name, id, connected-ports) fabric n/w virtual-port-profile (type, id, maxports, switch-id) for vEth uplink-port-profile (state, type, id, maxports, switch-id) for PNIC ip-address-pool (name, dhcp-server, range etc.) for ip-pools
BRKVIR-2017
Cisco Public
26
Cisco VNMC
Other ISVs
Virtualisation Vendors
NX-OS CLI, SNMP, NetConf/XML, REST* CDP, NTP, Telnet/SSH Syslog, ACL- Logging, TACACS+, RADIUS Netflow, SPAN, ERSPAN, REST-ful APIs
2013 Cisco and/or its affiliates. All rights reserved.
Advanced NX-OS switching features, including security, visibility, QoS, segmentation (VXLAN), port channel,
Separation of duties between network & server admins Dynamic provisioning and VM mobility awareness
BRKVIR-2017
Cisco Public
28
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview
Recent Pricing Changes Architectural Overview Services Architecture
VSM VSG NAM DCNM Partners
Demo
Q&A
vPath
Nexus 1000V
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
VDC-1
Hypervisor
VDC-2
FW
WAN Opt
ADC/ SLB
Virtual appliance form factor Dynamic instantiation/provisioning Service transparent to VM mobility Support scale-out Large scale multitenant operation
Cisco Public 30
BRKVIR-2017
Hypervisor
Hypervisor
VSN VSN
Virtual Service Nodes Virtual Service Nodes
Cisco Public
31
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
Nexus 1000V
Distributed Virtual Switch
vPath
Log/Audit
32
BRKVIR-2017
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
Nexus 1000V
Distributed Virtual Switch
vPath
Log/Audit
33
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Product Overview Port-profiles & network segments SCVMM Networking Concetps Powershell & SCOM Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
BRKVIR-2017
Server
BRKVIR-2017
Cisco Public
35
vmknic
Folder/Data Centre vMotion
Host VNIC
Host Group Live Migration
Dynamic Optimisation
Power Management SCVMM, SCO Hyper-V Replica Virtual Hard Disk (VHDX)
BRKVIR-2017
Cisco Public
36
BRKVIR-2017
Cisco Public
37
BRKVIR-2017
Cisco Public
38
Policy
database
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
VM
VM
VM
VM
Cisco Nexus 1000V VEM
VM
VM
VM
VM
Cisco Nexus 1000V VEM
VM
VM
VM
WS 2012 Hyper-V
WS 2012 Hyper-V
WS 2012 Hyper-V
Server
Server
Server
Switching
Security Network Services Provisioning Visibility Management
BRKVIR-2017
L2 Switching, 802.1Q Tagging, VLAN, Rate Limiting (TX) IGMP Snooping, QoS Marking (COS & DSCP) Policy Mobility, Private VLANs w/ local PVLAN Enforcement Access Control Lists, Port Security, Cisco TrustSec Support* Dynamic ARP inspection*, IP Source Guard*, DHCP Snooping*
Virtual Services Datapath (vPath) support for traffic steering & fast-path off-load [leveraged by Virtual Security Gateway (VSG)* and other services]
Port Profiles, Integration with virtualisation & cloud mgmt. tools Optimised NIC Teaming with Virtual Port Channel Host Mode VM Migration Tracking, NetFlow v.9 w/ NDE, CDP v.2 VM-Level Interface Statistics, SPAN & ERSPAN (policy-based) Integrated Provisioning with SCVMM, Cisco LMS, Cisco DCNM, Cisco VNMC Cisco CLI, Radius, TACACs, Syslog, SNMP (v.1, 2, 3) Hitless upgrade, SW Installer
* Available only with Advanced Edition
Cisco Public 41
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Product Overview Port-profiles & network segments SCVMM Networking Concetps Powershell & SCOM Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
BRKVIR-2017
Source: http://images.webmagic.com/klov.com/screens/S/wSpace_Invaders.png
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Private VLANs
and all other port config!
# port-profile webserver switchport mode access switchport access vlan 243 access list, etc. commands # port-profile webserver no shut switchport mode access switchport access vlan 752 access list, etc. commands no shut
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved.
Port Profiles are Live: Network Admin can change them any time!
Cisco Public
45
Network Segment
Tenant A Intranet
Tenant B Intranet
BRKVIR-2017
Cisco Public
47
DB Servers
VM VM
DB Network
N1KV/Hyper-V Version
# network-segment db-network switchport mode access switchport access vlan 10 # port-profile db-client ip port access-group dbclient in no shut state enabled
# port-profile db-server switchport mode access # port-profile db-server switchport access vlan 10 ip port access-group dbserver in ip port access-group dbserver in no shut no shut state enabled Cisco Public state enabled BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved.
Port-Classifications in SCVMM
Port-Classifications
Provide a level of indirection to Virtual Port Profiles Provide a way to group Port Profiles from different Hyper-V switch extensions
BRKVIR-2017
Cisco Public
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Product Overview Port-profiles & network segments SCVMM Networking Concepts Powershell & SCOM Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
BRKVIR-2017
BRKVIR-2017
Cisco Public
51
Seattle
Host Host
Network Site
Network Site
Logical Network represents a network with a certain type of connectivity characteristics (for eg. DMZ network, intranet, isolation) An instantiation of a Logical network on a set of host-groups (for eg. hosts in a POD) is called a Network Site Network sites can be defined based on physical network connectivity or based on isolating traffic to specific host-groups
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
BRKVIR-2017
Cisco Public
53
# network-segment Intranet_POD1_SUBNET1 switchport mode access switchport access vlan 20 ip-pool Intranet_POD1_Pool1
BRKVIR-2017
Cisco Public
54
# network-segment Intranet_POD1_SUBNET3 switchport mode access switchport access vlan 22 ip-pool Intranet_POD1_Pool2 network-definition Intranet_POD1
BRKVIR-2017 2013 Cisco and/or its affiliates. All rights reserved.
A Network Site is a grouping of VM Networks that are always available together on the same host simultaneously A host uplink can be configured to carry one or more Network Sites
Cisco Public
55
Seattle
Host
Network Site
Network Site
SCVMM uses the list of network sites available on a host to make placement decisions Live-Migration domain is constrained to a network-site that the VM network is bound to
BRKVIR-2017
Cisco Public
56
VM Connectivity to VM Networks
BRKVIR-2017
Cisco Public
57
BRKVIR-2017
Cisco Public
58
SCVMM Networking
Putting it all together !
Port Classifications
Port Profiles
Guest access Intranet client Privileged intranet client Web server
VM Network DMZ_POD1_SUBNET1
IP Pool 8
BRKVIR-2017
Cisco Public
59
SCVMM manages the placement and livemigration of the VMs based on the constraints between VM networks and the network sites. Server Admin
SCVMM
WS 2012 Hyper-V
Network Create networks & policies Admin Nexus 1000V (logical networks, network VSM sites, VM networks)
BRKVIR-2017
Cisco Public
60
BRKVIR-2017
Cisco Public
61
Clients
Servers
mydhcpnet1
DHCP Server
BRKVIR-2017
Cisco Public
62
BRKVIR-2017
Cisco Public
63
BRKVIR-2017
Cisco Public
64
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Product Overview Port-profiles & network segments SCVMM Networking Concetps Powershell & SCOM Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
BRKVIR-2017
Successfully created "port-profile BRKVIR-2017 2013 Cisco and/or its affiliates.pp-new" All rights reserved.
Cisco Public
66
TCP Connections
Uptime Traffic, total, error etc. Bandwidth
BRKVIR-2017
Cisco Public
67
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Product Overview Port-profiles & network segments SCVMM Networking Concetps Powershell & SCOM Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
BRKVIR-2017
BRKVIR-2017
Cisco Public
70
BRKVIR-2017
Cisco Public
71
BRKVIR-2017
Cisco Public
72
BRKVIR-2017
Cisco Public
73
BRKVIR-2017
Cisco Public
74
BRKVIR-2017
Cisco Public
75
Select Fabric tab Select the host Right-Click for Properties Select Virtual Switches For each uplink, select N1KV as the logical switch & the uplink port-profile
BRKVIR-2017
Cisco Public
76
Select VM & Services tab Select the host Select the VM Right-Click for Properties Select Hardware Configuration Select Network Adapters
BRKVIR-2017
Cisco Public
77
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Port-profiles & network segments SCVMM Networking Concetps Powershell & SCOM Services using vPath Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
BRKVIR-2017
Demo Topology
Employee Contractor
Web Server
Nexus 1000V VEM
Configure the port-profiles so that web-server access is restricted: Employee can access Contractor is restricted
NAM (or any other monitoring tool) can be configured to analyse the VM-to-VM traffic using ERSPAN on N1KV.
NAM
BRKVIR-2017
Cisco Public
79
Server
BRKVIR-2017
Cisco Public
80
Validated Designs
Converged Infrastructure Virtual Desktop DC to DC VM Migration DC-wide Mobility Secure Multi-tenancy Private & Public Clouds
Multi-Service
Multi-Cloud
Agenda
Ciscos Virtual Networking Vision Cisco Nexus 1000V Portfolio Overview Cisco Nexus 1000V for Microsoft Hyper-V
Port-profiles & network segments SCVMM Networking Concetps Powershell & SCOM Services using vPath Deploying N1KV
VSG VSM VSG NAM DCNM Partners
Demo Q&A
vPath
Nexus 1000V
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
BRKVIR-2017
Resources
- Reference Solutions - Webinars - Deployment Guides, White Papers, Cheat Sheets - CloudLab On-line lab for N1KV & VSG Solution Guides
Reference Solutions
With Nexus 1000V, Nexus 1010, VSG & vWAAS
vBlock with Nexus 1000V; Vblock with VSG and vWAAS FlexPOD with Nexus 1000V and Nexus 1010 Virtual Multi-tenant Data Center with Nexus 1000V Virtual Desktop
1000V and VMware View 1000V and Citrix XenDesktop
Cisco's Open Network Environment (ONE) update includes network 10/10/2012 programmability, controller & OF, virtual overlays & open clouds
10/24/2012 Securing Clouds with ASA 1000V and VSG w/ vPath 2.0
Cloud Services Router (CSR) 1000V: Connect to provider-hosted clouds 11/7/2012 Openstack @ Cisco & Quantum support for Nexus 1000V on KVM Nexus 1000V for Hyper-V: Enable Multi-hypervisor & Multi-service 11/14/2012 Clouds (w/ demo)
10/31/2012
Play
BRKVIR-2017
Cisco Public
85
Webinar
Play Play Play Play
Preso
PDF PDF PDF PDF
2/29/12
3/7/12 3/14/12 3/21/12 3/28/12 4/4/12 4/11/12 4/18/12
BRKVIR-2017
Play
Play Play
PDF
PDF PDF
vCloud Director, Nexus 1000V, and VXLAN Technical Deep Dive Play Cisco's CloudLab Deep Dive: Hands-on labs for N1KV, VSG & VXLAN Play NAM and DCNM on the Nexus 1010 and 1010-X
2013 Cisco and/or its affiliates. All rights reserved.
PDF
PDF PDF
86
Play
Cisco Public
11/09
Play
Cisco Public
PDF
87
BRKVIR-2017
Virtual Network Services: Virtual Service Datapath (vPath), Network 4/05 Analysis Module (NAM), Virtual Application Acceleration (vWAAS) Virtual Security Gateway 4/19 (VSG) Overview (Installation Videos: Link)
Play
4/26
Play
Journey to the Cloud w/ 5/03 N1KV: vCloud Director & Long Distance vMotion
5/17 Secure Virtual Desktop with Nexus 1000V & VSG
Play Play
PDF PDF
PDF PDF
5/10
Play Play
PDF PDF
PDF PDF
BRKVIR-2017
Cisco Public
88
Cheat Sheets
Nexus 1010 Configuration Cheat Sheet v.2.0
https://communities.cisco.com/docs/DOC-28188
VNMC: www.cisco.com/go/vnmc
vWAAS: www.cisco.com/go/waas NAM on 1010: www.cisco.com/go/nam More on the way
Deployment Guides
Nexus 1000V Deployment Guide Nexus 1000V on UCS Best Practices Nexus 1010 Deployment Guide VSG Deployment Guide
White papers:
Nexus 1000V and vCloud Director N1K on UCS Best Practices Nexus 1000V QoS White paper (draft) VSG and vCloud Director (draft) vWAAS Technical Overview, vWAAS for Cloud-ready WAN Optimization
BRKVIR-2017
Cisco Public
89
Extended duration lab licenses for 1000V and VSG are available upon request
BRKVIR-2017
Cisco Public
90
Q&A
Dont forget to activate your Cisco Live 365 account for access to all session material, communities, and on-demand and live activities throughout the year. Log into your Cisco Live portal and click the "Enter Cisco Live 365" button. www.ciscoliveaustralia.com/portal/login.ww
Cisco Public 93
BRKVIR-2017
BRKVIR-2017
Cisco Public