Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Architectures
BRKCRS-2000
Cisco Unified
Communications
Cisco IP Routing
WAN termination
Cisco
VPN/IPSec/Remote Access
Cisco vWAAS
Cisco vWLC
Cisco VSM
Switching with
PoE
Desktop Virtualisation
Mission-Critical
applications
BRKCRS-2000
WAN Optimisation
Application Hosting
Wireless LAN/WAN
Unified Communications
Routing/Switching
Security
Cisco Public
Agenda
Evolving Branch
Architecture
Transport Independent
Design
Intelligent Path Control
ISR 4300/4400
Application Hosting
Programmatic Branch
Virtualised Branch Router
BRKCRS-2000
Cisco Public
BRKCRS-2000
Cisco Public
Private
Cloud
MPLS (IP-VPN)
Virtual
Private
Cloud
Branch
Internet
Public
Cloud
Direct Internet
Access
Cisco Public
Dual Internet
Hybrid
Internet
Public
Enterprise
Public
MPLS+
Internet
MPLS
MPLS
Branch
Branch
Enterprise
Public
Internet
Branch
Best price/performance
Most SP flexibility
Enterprise responsible for SLAs
Cisco Public
Private
Cloud
MPLS
Virtual
Private
Cloud
3G/4G-LTE
Branch
Internet
WAAS
Public
Cloud
PfR
Intelligent
Path Control
Improved availability
Application acceleration
and bandwidth
optimisation
Application
Optimisation
Cisco Public
Secure
Connectivity
Comprehensive threat
defence
IWAN 2.0
Automation
Domain Scale
Hundreds of Branches
Transport
Independence
Intelligent Path
Control
(Q4 CY2014)
(DMVPN Phase 2)
Simplified
Path Control PfRv3
(Centralised Provisioning,
Large Scale)
Adaptive AVC
Application
Optimisation
AVC
(Performance Optimisation)
WAAS
Adv. QoS
Akamai Connect
Secure
Connectivity
Management
Cisco Prime
APIC-EM EFT:
LiveAction
PKI Automation
Site-by-Site Provisioning
CVD-based: QoS, AVC, PfR
Glue Networks
BRKCRS-2000
Cisco Public
11
Global
Enterprise
VRF
IPSec Tunnel
Interface
IOS ZBFW or
ACL to permit
only authorised
traffic; i.e. IPsec
Global
F-VRF
Branch LAN
10.1.1.0/24
10.1.2.0/24
BRKCRS-2000
Front Side
Provider VRF
Provider Assigned
WAN IP Address
192.168.254.254
Cisco Public
Data Centre
Cisco Public
ASR 1000
ASR 1000
ISP C
ISP A
DSL
Cable
Branch
Transport-Independent Design
Flexibility in WAN Design
14
IWAN HYBRID
Active/Standby
WAN Paths
Active/Active
WAN Paths
Data Centre
Data Centre
ASR 1000
ASR 1000
SP V
ISP A
DMVPN
GETVPN
MPLS
Internet
ASR 1000
ASR 1000
ISP A
SP V
DMVPN
DMVPN
DMVPN
MPLS
Internet
One WAN
Routing Domain
BRKCRS-2000
Branch
Cisco Public
ISR-G2
Branch
BRKCRS-2000
Cisco Public
Hub
Branch n
IPsec
VPN
ISR G2
ISR G2
ISR G2
Branch 1
Branch 2
Group Key
Server
DMVPN
Overlay Routing
Data Plane
IPsec
BRKCRS-2000
GETVPN
Cisco Public
18
Native Routing
Data Plane
IPsec
Private
Cloud
MPLS
Branch
Internet
Cisco Public
20
Virtual
Private Cloud
PfR
Path Control
Topological state
Least cost path
Static user preference
Application-aware
Policy controlled
Measured performance
Metrics
Path cost
Interface state
Delay
Jitter
Bandwidth
Adaptive
Responds To:
Link and node state
changes (up/down)
BRKCRS-2000
Cisco Public
21
Responds To:
Measured performance
changes (degradation)
ISR G2
ASR1K
Learning
Active TCs
MC
BR
MC+BR
BRKCRS-2000
MC+BR
BR
MC+BR
BR
MC+BR
MC
Performance
Measurements
Cisco Public
MC+BR
MC+BR
MC
Best
Path
BR
MC+BR
BR
MC+BR
Measurement
MC+BR
MC+BR
BR
BR
MC+BR
Path Enforcement
Master Controller
commands path changes
based on traffic class
policy definitions
Data Centre
DC/MC
BR
BR
DSL
BRKCRS-2000
Cisco Public
MC+BR
Branch
DC/MC
Domain
Controller
Master
Controller
BR
BR
MC/BR
WAN2
MC/BR
MC/BR
Cisco Public
24
BR
PfR Config
learn
pfr-map PFRMAP 10
set periodic 90
set periodic 90
Cisco Public
Link Characteristics
Define the
traffic to learn
BRKCRS-2000
25
PfR version 2
IOS 15.2(3)T, IOS-XE 3.6
PfR version 3
IOS 15.4(3)M, IOS-XE 3.13
PfR Domain
One touch & APIC-EM provisioning
Auto Discovery of sites
NBAR2 support (*)
Passive Monitoring (performance
monitor)
Smart Probing
VRF Awareness
IPv4/IPv6 (Future)
<10 lines of configuration and
centralised
Blackout 6 seconds
Brownout 9 seconds
Limited scalability due to
provisioning (~ tens of sites)
Blackout 6 seconds
Brownout 9 seconds
Scale 500 sites
Blackout ~ 2 second
Brownout ~ 2 sec
Scale 2000 sites
BRKCRS-2000
Cisco Public
26
ISR 4351
200-400 Mbps
ISR 4431
500-1000 Mbps
ISR 4331
100-300 Mbps
ISR 4321
50-100 Mbps
4-10X Faster
Add performance and services anytime
Flexible consumption options
BRKCRS-2000
Cisco Public
Branch consolidation
3945E
3925E
4431
(1 RU, 500-1000 Mbps)
3945
3925
4351
(2 RU, 200-400 Mbps)
2951
4331
(1 RU, 100-300 Mbps)
2921
2911
4321
(1 RU (Desktop), 50-100 Mbps)
2901
1921
1941
Application services
BRKCRS-2000
Cisco Public
For Your
Reference
Cisco
3900E ISR
Cisco Public
Entity
ISR 4451
CPU architecture
Network Interface
Modules
Enhanced Service
Modules
Front-Panel Ethernet
ISC slot
Power
Dual internal AC or DC
Control/services
memory
Mgmt Ethernet
1 Gbps
For Your
Reference
ISR4431/K9
Cisco
Cisco Public
Entity
ISR 4431
CPU architecture
4 core control/services
6 core data plane
Network Interface
Modules
Enhanced Service
Modules
Front-Panel Ethernet
ISC slot
Power
Dual internal AC or DC
Control/services
memory
Mgmt Ethernet
1 Gbps
For Your
Reference
ISR4351/K9
Cisco
2951 ISR
Cisco Public
Entity
ISR 4351
CPU architecture
8-core CPU
Network Interface
Modules
Enhanced Service
Modules
Front-Panel Ethernet
ISC slot
Power
Single internal AC or DC
Control/services
memory
Mgmt Ethernet
1 Gbps
For Your
Reference
ISR4331/K9
Cisco Public
Entity
ISR 4331
CPU architecture
8-core CPU
Network Interface
Modules
Enhanced Service
Modules
Front-Panel Ethernet
ISC slot
Power
1 internal AC
Control/services
memory
Mgmt Ethernet
1 Gbps
For Your
Reference
ISR4321/K9
Cisco
Cisco Public
Entity
ISR 4321
CPU architecture
4-core CPU
Network Interface
Modules
Enhanced Service
Modules
Front-Panel Ethernet
ISC slot
Power
1 external AC
Control/services
memory
Mgmt Ethernet
1 Gbps
4400 Family
Benefits
Cisco Public
1.5
Enabling Technologies
Multicore architecture
Multigigabit fabric
Benefits
0.5
0
Scalability
Layer 7 services
Software-only router
BRKCRS-2000
Cisco Public
BRKCRS-2000
Without
Performance
License
With
Performance
License
Cisco Public
37
G2 to 4k Performance Improvement
Radically different, more predictable performance curve on ISR 4K.
The heavier the services, the higher performance delta between platforms
@22%
CPU
@53%
CPU
@43%
CPU
@81%
CPU
@65%
CPU
@20%
CPU
BRKCRS-2000
Cisco Public
@89%
CPU
@54%
CPU
@33%
CPU
For Your
Reference
ISR G2
HSEC+ISM
VPN
Tunnels
Tunnels
Tunnels
1941
150
500
250
4321
2901
150
700
1000
4331
2911
225
1000
1500
2921
900
1500
2000
4351
4431
2951
1000
2000
4000
4451
3925
1500
2500
3945
2000
3000
3925E
3000
3945E
3000
Cisco Public
ISR 4K IPsec
VPN Tunnel
Scalability
For Your
Reference
BRKCRS-2000
Mbps @ IMIX
With ISMVPN
Mbps @
IMIX
Mbps @
IMIX
1941
60
170.0
100
4321
2901
60
170.0
300
4331
2911
65
170.0
400
4351
2921
80
215.0
1,000
4431
2951
150
395.0
1,300
4451
3925
215
715.0
3945
245
715.0
3925E
630
3945E
800
No ISM-VPN
Cisco Public
500
100
100
100
50
50
4331
4351
(2 RU, 200-400 Mbps)
4321
(1 RU(Desktop), 50-100 Mbps)
2911
2901
100
35
35
BRKCRS-2000
200
50
50
2921
400
100
100
3925
2951
600
150
250
Cisco Public
800
250
730
3000
350
1200
4451
4431
3945
950
350
1200
For Your
Reference
6000
450
2000
3925E
2100
400
1350
3945E
2500
450
1500
CUBE
CME
SRST
Front-Panel GE
RJ45/SFP GE Interfaces
BRKCRS-2000
USB Connections
Cisco Public
Service containers
live here
Control Plane (1
core) and Services
Plane (3 cores)
Data Plane (6 or 10
cores)
FPGE
Multigigabit
Fabric
ISR-WAAS
KVM - Hypervisor
Service Plane
(control plane CPU)
BRKCRS-2000
NIM
Cisco Public
ISC
SM-X
Control Plane
(1 core) and Services
Plane (3 cores)
Data Plane (6 or 10
cores)
4xSGMII
FPGE
4xPCIe
DRAM
Mgt Eth
Cons/Aux
USB
4xPCIe
10G XAUI
System
FPGA
1 Gb SGMII
ISC
Platform
Controller
Hub
Multigigabit
Fabric
2 Gb/slot
Flash
NIM
BRKCRS-2000
Cisco Public
10 Gb/slot
SM-X
IOS
FPGE
Service Container
Multigigabit
Fabric
ISR-WAAS
KVM - Hypervisor
Service Plane
(control plane CPU)
BRKCRS-2000
NIM
Cisco Public
ISC
SM-X
ISR 4000
EHWIC
NIM
ISM
ISC
PVDM-3
PVDM-4
SM-X
SM
SM-X
SM-X
BRKCRS-2000
(backward compatible)
Cisco Public
NIM-2MFT-T1/E1
BRKCRS-2000
Cisco Public
With NIM
Blank
Cisco Public
Type
Name
LAN
SM-X
LAN
NIM
For Your
Reference
Availability
Now
Q2 CY15
UCS E-Series
SM-X
Now
UCS E-Series
NIM
CPU: 2 cores
Voice
NIM
Now
Voice
NIM
Now
Voice
NIM
Voice
PVDM
Voice
NIM
Q3 CY15
Q4 CY14
Now
Q4 CY15
WAN Ethernet
SM-X
Now
WAN Ethernet
SM-X
1GE: 6 ports
Now
WAN Ethernet
NIM
BRKCRS-2000
Cisco Public
Q2 CY15
Type
Name
WAN 4G / LTE
NIM
WAN T3/E3
SM-X
WAN T1/E1
For Your
Reference
Availability
Q2 CY15
T3/E3: 1-port
Now
NIM
Now
WAN T1/E1
NIM
T1/E1: 8 ports
Q3 CY14
WAN xDSL
NIM
Q4 CY14
WAN xDSL
NIM
G.SHDSL
Q4 CY15
WAN Serial
NIM
Now
Disk
NIM
Now
NIM Adaptor
BRKCRS-2000
SM-X
Cisco Public
Q4 CY14
On Roadmap
L2/L3 Routing
AAA, ACL, AToM, BFD, BGP, CEF, CoPP, DHCP,
DNS, EIGRP,EEM, EIGRP, Frame Relay, FHRP,
Flexible Netflow, HSRP, HTTP(S), IEEE 802.1Q,
IGMP, IP SLA, IPv6 (Multicast, QoS, IS-IS, BGP,
OSPF, RIPng, Switching), ISIS, L2TPv3,LISP,
L2VPN, LLQ, MLPPP, MPLS (TE, VPN), MLPPP,
Mobile IPv6, NAT, NBAR, NSF, Net Flow, NTP,
NHRP, OER, OSPFv3, PIMv6, PPPoE, PfR, PBR,
QoS, RADIUS, RGMP, RSVP, RRI, SNMPv3, SSH,
SCPv2, SSM, TACACs+, VRRP, X.25
Voice
Security
CUBE, CME, SRST,
TrustSec, DMVPN,
TDM GW, TCL, MGCP,
TrustSec, MVPN,
H323, SIP, SCCP,EDMVPN, GETVPN,
SRST, RSVP, CAC
FlexVPN, SSLVPN,
SNA,
EasyVPN, PKI server,
SNAs
ZBFW, IPS
w
DLSw,
STUN
BSTU
N
BRKCRS-2000
Cisco Public
No Support on IOS
XE
Application Hosting
Benefits
Better performing network services
Ease of deployment with zero
footprint; no truck roll
Greater security through fault isolation
High reliability
Flexibility to upgrade network services
independent of router IOS Software
BRKCRS-2000
Cisco Public
VM 1
VM 2
VM 3
vWAAS
Energywise
Future App
Cisco UCS-E180D
Scalability
Cisco UCS-E160D
Cisco UCS-E140S
Cisco UCS-EN120S
Service Module
VMware and
Hyper-V Certified
Network Compute
Applications
vWLC, vWAAS
Service Module
Vmware, Hyper-V,
Citrix Certified
Intel E3 4 Core
Processor
vWLC, vWAAS,
Physical Security
Service Module
Vmware, Hyper-V, Citrix
Certified
Intel E5 6 Core
Processor
vWLC, vWAAS, Virtual
Desktops, Physical
Security
Service Module
Vmware, Hyper-V, Citrix
Certified
Intel E5 8 Core Processor
vWLC, vWAAS, Virtual
Desktops, Physical
Security, Security
applications
Feature Richness
BRKCRS-2000
Cisco Public
8, 12, and 16 GB
DRAM options
iSCSI initiator
hardware offload
Configuration and
management through CIMC
Remote and
schedulable power
management
Two SD cards: One for the CIMC
and temporary storage of OS and
one for a blank virtual drive
BRKCRS-2000
Cisco Public
8 GB - 48 GB
DRAM options
iSCSI initiator
hardware offload
Remote and
schedulable power
management
Out-of-band
configuration and
management through
CIMC
BRKCRS-2000
Cisco Public
Storage Options
NIM-SSD:
NIM-HD:
SSD-MSATA-200G:
BRKCRS-2000
Cisco Public
Programmatic Branch
Monitoring
Discovery
Routing
Security
QoS
Interfaces
App
C
Java
Python
EEM (TCL)
Cisco Public
60
CLI
SNMP
HTML
XML
AAA
CDP
Syslog
Netflow
Routing Protocols
Span
New Paradigm
APP
Business
Policy:
App SLA
IT Admin
Access
DMVPN
SLA
QoS
Security
Path
Selection
NETWORK
Application
Network Profile
SDN
Simple Workflow
Templates
Zero Touch
Provisioning
Network, Applications
Monitoring
Business
Level Policies
Cisco Public
Open
Architecture
BRKCRS-2000
Cisco Public
BRKCRS-2000
Cisco Public
BRKCRS-2000
Cisco Public
SP Edge
Network Services VPN Gateway
Control Plane Functions Route Reflector
Cloud
Tenant Scale vCE/vPE
Network Services VPN Gateway
Hybrid Cloud Connectivity L2/L3 extension
BRKCRS-2000
Cisco Public
66
Any Server
Any Switch
Any Hypervisor (ESXI, KVM, Hyper-v, XEN)
CSR 1000V
App
App
OS
OS
VPC/ vDC
RP
ESP
Hypervisor
Virtual Switch
Server
BRKCRS-2000
Cisco Public
STANDARD
(Routing)
ADVANCED
(Standard + Security)
PREMIUM
(Advanced + AppX +
Hybrid Cloud)
BRKCRS-2000
ESXi 5.5
XenServ
er 6.1
KVM
(Ubuntu
12.04
LTS,
RHEV
3.1,
RHEL
6.3)
Hyper-V
2012 R2
IOS-XE Features
Basic Networking: BGP, OSPF, EIGRP, RIP, ISIS, IPv6, GRE, VRF-LITE, NTP
High Availability: HSRP, VRRP, GLBP
Addressing: 802.1Q VLAN, EVC, NAT, DHCP, DNS
Basic Security: ACL, AAA, RADIUS, TACACS+
Management: IOS-XE CLI, SSH, Flexible NetFlow, SNMP, EEM, NETCONF
STANDARD
QoS
Multicast: IGMP, PIM
Advanced Security: Zone Based Firewall, IPSec VPN, EZVPN, DMVPN,
FlexVPN
ADVANCED
Advanced Networking: L2TPv3, BFD, MPLS, VRF, VXLAN
Application Experience: WCCPv2, APPNAV, NBAR2, AVC, IP SLA
Hybrid Cloud Connectivity: LISP, OTV, VPLS, EoMPLS
Cisco Public
68
Summary
PSORST-2002
Cisco Public
70
Related Sessions
BRKRST-2641
BRKRST-2045
BRKRST-2642
Introduction to IWAN
BRKVIR-2605
BRKRST-2362
BRKRST-2042
BRKRST-2041
BRKCRS-2000
Cisco Public
71
Q&A
Cisco Public