Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Integrating the
Meraki SD-WAN
Solution with the
traditional Enterprise
network
Arul Jagadeesan – Solution Integration Architect
Kevin Wetzel – Solution Integration Architect
BRKCRS-2103
#CLUS
Cisco Webex Teams
Questions?
Use Cisco Webex Teams (formerly Cisco Spark)
to chat with the speaker after the session
How
1 Find this session in the Cisco Events App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
#CLUS © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Complete your online session evaluation
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Agenda
• Introduction
• Meraki Customer Case Study
• SDWAN Considerations
• Building the SDWAN Solution
• Mapping Classic QoS to Meraki
• Operations and Support
• Conclusion
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Meraki Customer Case
Study
Customer Case Study
Situation Desired Outcome
• 1000+ Independent • Reduce Risk
• LDoS & Non Standard • Foundation for consistent
performance
• Mid-cycle Refresh
• Reduce Cost-to-Serve
Silver
Current State Vision
• (4) Deployment Models • Silver
• 3925 & 800 Routers • Gold
Gold
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Customer Case Study - Outcomes
• Design & Topology • Financial Model • Outcomes
• Network
• Dependents
• Carrier Topologies
• Last Mile
• Dependencies
• Faxing
• E911
• Voice Redundancy
• Multi-cast
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Customer Case Study - Outcomes
• Design & Topology • Financial Model • Outcomes
• Network • PROs
• Dependents • 30% Savings in WAN
• Carrier Topologies costs
• Last Mile • 86% Savings in CAPEX
45% Savings in OPEX
• Dependencies •
• Faxing
• E911 • CONs
• Voice Redundancy • Added “Last Mile” costs
• Multi-cast • Depreciation Remaining
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Customer Case Study - Outcomes
• Design & Topology • Financial Model • Outcomes
• Network • PROs • Risk Reduction
• Dependents • 30% Savings in WAN • LCM
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Moral of the Story
• Understand the environment
• Capabilities
• Dependent
• Dependencies
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
SDWAN Considerations
Architectural Considerations
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Architecture – Service Layer Options
Data
Center
Edge
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Architecture - Carrier Service Considerations
Description MPLS Tier 1 Internet Tier X Internet
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Architecture – Carrier Service
Tier x Internet
Data
Center
Edge
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Architecture – Last Mile (Data Center Locations)
Description SONNET Ethernet
Physical Medium Fiber Fiber or Copper
Type of Service Commercial Commercial
Native HA Self Healing Self Healing
MTTR Auto Fail-over Auto Fail-over
Escalation Process Yes Yes
RoM Cost $$$$$ $$$$
Scalability Virtually Unlimited Virtually Unlimited
Monitoring/Alerting Advanced Advanced
Topology Point-to-Point Point-to-Point
User Capacity Very Large Very Large Configurable
Configurable
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Architecture – Last Mile (Remote Locations)
Description T-1 4LTE DSL Cable
Physical Medium Copper Cellular Copper Fiber or Copper
Type of Service Commercial Consumer Consumer Consumer
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Architecture – Premise Equipment (Remote Locations)
• Demark location in perspective to
office
• Extended Wiring
• Carrier Service Hand-off
Data • Interfaces
Center • V.35, RS232, 449, RJ48, Ethernet
Edge • Carriers Devices
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Architecture - Common Office Services
(Dependencies)
• Special Considerations
• No voice termination
• Voice HA
• e911
• Multi-cast
Data • Options
Center
• Mobility
Edge
• Cloud
• Centralized
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Determining the Right SDWAN Approach
Prizes simplicity and full stack branch management / “Lean IT” organization
Needs end-to-end WAN segmentation across on-prem and public cloud infrastructure
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
SDWAN Key Capabilities
Meraki MX vEdge
Simple, cross-functional management Highly flexible and customizable
• Support for up to 3 SDWAN Connection • Support for 3 or more uplinks
• Single pane of glass management for full stack • Service chaining at L4-L7
branch infrastructure (security, WAN, switching, • TCP Optimization and WAN acceleration
wireless, and more) • Highly flexible segmentation with customizable
• Cisco Advanced Malware Protection topologies on a per-VRF basis
• Cisco Snort IPS • Multicast support over WAN
• Integrated URL filtering • VNF capabilities for gray and white-box MSP/SP offers
• Geo-IP based firewalling • IPv6 support
• Intuitive GUI-based configuration and monitoring • On-premises and private cloud management
• Support for integrating multiple VPC workloads
(OnRamp) and extending WAN segmentation into IaaS
Shared Capabilities
• Layer 3 VPN overlay for hub-and-spoke deployments • Highly scalable (10,000+ sites)
• Layer 3 and 7 policy and performance based routing • LTE failover
• Transport independence across a variety of connection types • Virtual platform for AWS / Azure
• Zero touch deployment with support for templated configurations • Public cloud management
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Architecture – Network Device (HDW/SFW Capabilities)
Z1/Z3 Wireless
MX64W
MX64 / 64W
MX65W
MX65 / 65W
Z3 802.1x
vEdge 100
MX80 vMX100
MX64 / 64W
MX84
MX100
MX65 / 65W
vEdge 1000
MX400
POE
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
24
• MX in the Branch
• Demo
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
SD-WAN Multiple Pathways
Transport
Load Balancing
Independence
Automatic Failover
Network Visibility
Application
Optimization Quality of Service
Auto VPN
Secure
Connectivity AES Encryption
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
MX in Data Center
Deployment Modes
Passthrough or VPN
NAT Mode
Concentrator Mode
VPN VPN
Internet connection
VPN tunnel
Internet
SDWAN SDWAN
VPN VPN
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Reset
Bypass Bypass
Bypass Bypass i
i
Reset Reset
Core
Primary Secondary
Data MPLS Extranet Data
Center WAN Center
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Data Center Deployment Models
• NAT Mode
• NAT Mode HA
• VPN Concentrator Mode
(One Armed)
• VPN Concentrator Mode
(One Armed-HA)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
DC Deployment – NAT Mode
Internet
• One Ethernet connection (WAN)
to Upstream Network and one
Ethernet (LAN) to Downstream
MX600 Network
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Bypass Bypass
i
•
WAN 1 LAN 1 WAN 2 LAN 2 1 2 3 4 5 6 7 8 1 2
10G SFP+
WAN interface
• Decrypted Traffic sent and
received on LAN interface
Layer 3
Distribution
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
DC Deployment – NAT Mode (HA)
Internet • WAN Interfaces
• Same IP subnet on WAN Interfaces
• The virtual IP address (VIP) is shared by both the
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
primary and warm spare
LAN Interfaces
Management USB Module 1 Module 2
Bypass Bypass
Reset i
Bypass Bypass
i
•
WAN 1 LAN 1 WAN 2 LAN 2 1 2 3 4 5 6 7 8 1 2
10G SFP+
MX600 MX600
• Appliance IPs in any configured VLANs
• VIPs are not required
• Failure Detection
• WAN Failover
• DNS, ICMP & ARP Tests
Layer 3
Distribution • LAN Failover
• VRRP is used for sharing health information and detect failure
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
DC Deployment – VPN Concentrator (One Armed)
Reset
Bypass Bypass
i
•
MX600
Firewall MX appliances serving as VPN
termination points into the
datacenter
• One-armed concentrators MX
Layer 3
Distribution
appliances should always be
deployed behind an edge firewall
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
DC Deployment – VPN Concentrator (One Armed – HA)
• WAN Interfaces
Internet
• Same IP subnet on WAN Interfaces
Primary • The virtual IP address (VIP) is shared by
i
Drive 1
Management
Bypass
Drive 2
USB
Bypass
Reset
Drive 3
Module 1
Drive 4
Module 2
both the primary and warm spare
WAN 1 LAN 1 WAN 2 LAN 2 1 2 3 4 5 6 7 8 1 2
10G SFP+
MX600
• LAN Interfaces
Warm Standby
Firewall
Drive 1
Management
Drive 2
USB
Drive 3
Module 1
Drive 4
Module 2
• Make sure MXs are not connected directly
via their LAN ports
Reset
Bypass Bypass
i
MX600
• Failure Detection
• VRRP is used for sharing health information
and detect failure
Layer 3 • Failover < 30 seconds
Distribution
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Meraki SD-WAN Hub Topology
Internet MPLS
Reset
Bypass Bypass
i
Reset
Bypass Bypass
i
MX600
• The IP address of the one-armed
MX terminates both AutoVPNs
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
VPN Aggregation Topology (Logical)
BGP
Internet
default
MX600
Drive 1 Drive 2 Drive 3 Drive 4
Primary
Reset
Bypass Bypass
i
Reset
Bypass Bypass
i
Internet
WAN 1 LAN 1 WAN 2 LAN 2 1 2 3 4 5 6 7 8
Warm Standby
10G SFP+ 1 2
Layer 3
Distribution
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
VPN Aggregation Topology (Physical)
Internet
Link to active device
Link to standby device
MX600
Internet Layer Drive 1
Management
Drive 2
USB
Drive 3
Module 1
Drive 4
Module 2
Internet
i
WAN 1
Bypass
LAN 1 WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Primary
5 6 7 8 10G SFP+ 1 2
Firewall
(pair)
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Bypass Bypass
i
Warm Standby
MX600 (VPN concentrator mode)
Layer 3
Distribution
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Demo DC 1 ARM HA
Addressing and VLANs (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Warm Spare (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Active Appliance Status Summary (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Active Appliance Status Uplink (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Passive Appliance Status Summary (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Passive Appliance Status Uplink (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Routing
Cloud Maintains Dynamic Table to track all MX
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
OSPF
BRKCRS-2103
OSPF
• Pass Through VPN
concentrator mode only
• Not available on MX devices
operating in NAT mode
• Only advertise routes with
OSPF; MX will not learn OSPF
routes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
One Armed Concentrator - OSPF
• Pass Through VPN concentrator mode only
• Not available on MX devices operating in NAT mode
• Only advertise routes with OSPF; MX will not learn OSPF routes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Inbound Data Flow (OSPF)
Internet Enable
Enable OSPF OSPF
OSPF Neighbor
10.100.30.3 Drive 1
Management
Drive 2
USB
Drive 3
Module 1
Drive 4
Module 2
Primary
Reset
Bypass Bypass
i
(OSPF learned i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
Warm Standby 1 2
10.1.1.0/24 remote
Auto VPN Sites)
Encrypted Flow
Cleartext Flow
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Outbound Data Flow (OSPF)
Internet Enable
Enable OSPF OSPF
OSPF Neighbor
10.100.30.3 Drive 1 Drive 2 Drive 3 Drive 4
Primary
Reset
Bypass Bypass
i
(OSPF learned i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
Warm Standby 1 2
10.1.1.0/24 remote
Sites)
Branch
Distribution layer
(OSPF learned routes to remote sites) Data
Center
Encrypted Flow
Cleartext Flow
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
One Armed Concentrator - OSPF
MX Configuration Layer 3 Router Configuration
router ospf 1
router-id 10.100.30.254
10.100.30.3
log-adjacency-changes
area 100 authentication message-digest
network 10.100.30.0 0.0.0.255 area 100
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
One Armed Concentrator – OSPF
MX Configuration
Enable OSPF
10.100.30.3 The OSPF Router ID that the MX will use to identify itself
to neighbors
The OSPF Area ID that the MX will use when sending
route advertisements
(Defaults to 1) The route cost attached to all OSPF routes advertised from
the MX.
(Defaults to 10) How frequently the MX will send OSPF Hello packets
in seconds.
(Defaults to 40) How long the MX will wait (in seconds) to see Hello packets
from a particular OSPF neighbor before considering that neighbor inactive
MD5 hashing will be used to authenticate potential OSPF neighbors.
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
BGP
One Armed Concentrator - BGP
• Pass Through VPN concentrator mode only
• Not available on MX devices operating in NAT mode
• iBGP across Organization (Meraki)
• eBGP to the Data Center Devices
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Inbound Data Flow - BGP
Internet Enable
Enable
eBGP BGP
BGP
10.100.30.3 Drive 1 Drive 2 Drive 3 Drive 4
Primary
Reset
Bypass Bypass
i
(BGP learned i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
Warm Standby 1 2
10.1.1.0/24 remote
Auto VPN Sites)
Distribution layer
Branch Data
(BGP learned routes to remote
sites) Center
Encrypted Flow
Cleartext Flow
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Outbound Data Flow - BGP
Internet Enable
Enable
eBGP
eBGP eBGP
10.100.30.3 Drive 1 Drive 2 Drive 3 Drive 4
Primary
Reset
Bypass Bypass
i
(BGP learned i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
Warm Standby 1 2
10.1.1.0/24 remote
Sites)
Branch
Distribution layer
(BGP learned routes to remote sites) Data
Center
Encrypted Flow
Cleartext Flow
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
One Armed Concentrator - BGP
MX Configuration Layer 3 Router Configuration
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Demo BGP
BGP Configuration (Data Center 1)
MX Configuration
Enable BGP
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
BGP Configuration (Data Center 1)
L3 Router Configuration
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
BGP Configuration (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
BGP Configuration (Data Center 1)
L3 Router Routing Table
DC1-FW-IL-SJC-01#sh ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Branch Design
Branch Design
• Dual WAN Links
• Single SD-WAN Topology
• Highly Available SD-WAN Topology
• SD-WAN Requirements
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Dual WAN Links
Internet + 4G SDWAN Hybrid SDWAN Dual Internet
Bypass Bypass
i
Reset
Reset
Bypass Bypass
i Bypass Bypass
i
WAN 1 LAN 1 WAN 2 LAN 2 1 2 3 4 5 6 7 8 1 2
10G SFP+
Internet
Internet 4G MPLS Internet Internet
Internet
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Single SD-WAN Topology - Branch
Links: Active/Active
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Highly Available SD-WAN Topology - Branch
Links: Active/Active
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Meraki SD-WAN Branch Requirements
• Each WAN interface must have
Internet
reachability to the address of
MPLS
each SD-WAN hub
• Each WAN interface must have
reachability to Meraki
dashboard (This means the MPLS
network must have access to Internet
either directly or through the hub site)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Initializing Auto VPN Registration
Auto VPN
Auto VPN Simple
Auto-provisioning IPsec Branch to Headquarters
VPN
Branch to Branch
Data Center
Cloud Enabled
Automatically
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Bypass Bypass
i
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Auto VPN Registry Successful
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Demo Auto VPN
Data Center Auto VPN
SDWAN SDWAN
VPN VPN
Internet connection
VPN tunnel
Internet
SDWAN SDWAN
VPN VPN
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Reset
Bypass Bypass
Bypass Bypass i
i
Reset
Reset
Bypass Bypass
i
Bypass Bypass
i
Core
Primary Secondary
Data Data
MPLS Extranet
Center WAN Center
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Auto VPN Configuration (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Auto VPN Configuration (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Branch Auto VPN
SDWAN SDWAN
VPN VPN
Internet connection
VPN tunnel
Internet
SDWAN SDWAN
VPN VPN
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Reset
Bypass Bypass
Bypass Bypass i
i
Reset
Reset
Bypass Bypass
i
Bypass Bypass
i
Core
Primary Secondary
Data MPLS Extranet Data
Center WAN Center
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Auto VPN Configuration (BRANCH)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Auto VPN Configuration (BRANCH)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Monitoring Auto VPN (BRANCH)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Monitoring Auto VPN Subnets (BRANCH)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Monitoring Auto VPN (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Auto VPN Registry Unsuccessful
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Demo DC Traffic Flows
Traffic Flow Between Branch and Data Center
SDWAN SDWAN
VPN VPN
Internet connection
VPN tunnel
Internet
SDWAN SDWAN
VPN VPN
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Reset
Bypass Bypass
Bypass Bypass i
i
Reset
Reset
Bypass Bypass
i
Bypass Bypass
i
Core
Primary Secondary
Data MPLS Extranet Data
Center WAN Center
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Auto VPN Configuration (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Auto VPN Configuration (Data Center 1)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Auto VPN Configuration (Data Center 2)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Auto VPN Configuration (Data Center 2)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
BGP Configuration (DC 1 and DC 2 are Up)
no auto-summary
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
BGP Outputs (DC 1 and DC 2 are Up)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
BGP Outputs (DC 1 and DC 2 are Up)
DC1-FW-IL-SJC-01#sh ip bgp
BGP table version is 4, local router ID is 10.10.10.10
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
r RIB-failure, S Stale Secondary Data Center
Origin codes: i - IGP, e - EGP, ? - incomplete MX VPN Concentrator
Network Next Hop Metric LocPrf Weight Path
* 10.1.1.0/24 10.100.30.13 0 65512 65512 i
*> 10.100.30.3 0 65512 i
*> 10.10.10.0/24 0.0.0.0 0 32768 i
*> 10.100.30.0/24 0.0.0.0 0 32768 i
DC1-FW-IL-SJC-01# Primary Data Center
MX VPN Concentrator
(PREFERRED)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
DC to Branch Reachability via Primary Path
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Branch to DC Reachability via Primary Path
Branch to Data Center Reachability
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Demo Meraki HA and DC Failover
Primary MX Failure
SDWAN SDWAN
VPN VPN
Internet connection
VPN tunnel
Internet
SDWAN SDWAN
VPN VPN
X
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
Reset
Reset
Bypass Bypass
Bypass Bypass i
i
Reset
Reset
Bypass Bypass
i
Bypass Bypass
i
Core
Primary Secondary
Data MPLS Extranet Data
Center WAN Center
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Data Center 1 Failure
SDWAN SDWAN
VPN VPN
Internet connection
VPN tunnel
Internet
SDWAN SDWAN
VPN VPN
Drive 1 Drive 2 Drive 3 Drive 4
Drive 1 Drive 2 Drive 3 Drive 4
X
Management USB Module 1 Module 2
Management USB Module 1 Module 2
Reset
Reset
Bypass Bypass
Bypass Bypass i
i
Reset
Reset
Bypass Bypass
i
Bypass Bypass
i
Core
Primary Secondary
Data MPLS Extranet Data
Center WAN Center
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
BGP Outputs (DC 1 is Down and DC 2 is Up)
DC1-FW-IL-SJC-01#sh ip bgp summary Primary DC MX VRRP = 10.100.30.3
BGP router identifier 10.10.10.10, local AS number 65513 Secondary DC MX VRRP = 10.100.30.13
BGP table version is 7, main routing table version 7
3 network entries using 396 bytes of memory
3 path entries using 156 bytes of memory
3/2 BGP path/bestpath attribute entries using 504 bytes of memory
1 BGP AS-PATH entries using 24 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory Primary Data Center
Bitfield cache entries: current 2 (at peak 2) using 60 bytes of memory
BGP using 1140 total bytes of memory MX VPN Concentrator
BGP activity 25/22 prefixes, 36/33 paths, scan interval 60 secs (DOWN)
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
BGP Outputs (DC 1 is Down and DC 2 is Up)
DC1-FW-IL-SJC-01#sh ip bgp
BGP table version is 7, local router ID is 10.10.10.10
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, Secondary Data Center
r RIB-failure, S Stale MX VPN Concentrator
Origin codes: i - IGP, e - EGP, ? - incomplete
(PREFERRED)
Network Next Hop Metric LocPrf Weight Path
*> 10.1.1.0/24 10.100.30.13 0 65512 65512 i
*> 10.10.10.0/24 0.0.0.0 0 32768 i
*> 10.100.30.0/24 0.0.0.0 0 32768 i
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
DC to Branch Reachability via Secondary Path
DC1-FW-IL-SJC-01#ping 10.1.1.254 source 10.10.10.10 repeat 500 Branch Subnet = 10.1.1.0
Data Center Subnet = 10.10.10.0
Type escape sequence to abort.
Sending 500, 100-byte ICMP Echos to 10.1.1.254, timeout is 2 seconds:
Packet sent with a source address of 10.10.10.10
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!......... Primary Data Center MX VPN Concentrator is DOWN.
...................................................................... And traffic is converging to Secondary Data Center.
..................................!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Traffic successfully converged to Secondary Data Center
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!
Success rate is 77 percent (387/500), round-trip min/avg/max = 64/77/224 ms
DC1-FW-IL-SJC-01#Traceroute 10.1.1.254 source 10.10.10.10
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Primary Data Center Down
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Branch to DC Reachability via Secondary Path
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Traffic Flow and QoS
Traffic Flow
• MX Load Balancing
• MX Flow Preference
• MX VPN Traffic and Custom Performance Classes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
MX Load Balancing
Data
Center
Services
Reset
Bypass Bypass
i
Data i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
1 2
Center
Internet
WAN 1 WAN 2
Branch
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
MX Flow Preferences
Data
Center
Services
Reset
Bypass Bypass
i
Data i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
1 2
Center
Internet
WAN 1 WAN 2
Branch
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
MX VPN Traffic and Custom Performance Classes
Data
Center
Services
Reset
Bypass Bypass
i
Data i
Management
WAN 1
Bypass
LAN 1
USB
WAN 2
Bypass
Reset
LAN 2 1 2 3 4
Module 1
5 6 7 8 10G SFP+
Module 2
1 2
Center
Internet
WAN 1 WAN 2
Branch
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
QoS
• QoS Framework Advancement
• Mapping a 5 Class Framework to Meraki
• Applying QoS on Meraki
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Mapping to a Meraki 3 Queue Framework
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
Meraki Traffic Shaping - Uplink Configuration
• WAN 1 Simple
• Synchronous Uplink & Downlink
• WAN 1 Detail
• Asynchronous Uplink & Downlink
• Enter you uplink and downlink
speeds in their respective fields
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Meraki Traffic Shaping - Uplink Statistics
• Uplink Statistics
• 8.8.8.8 Default
• Unable to modify default
• Uplink Statistics
• Maximum of 3 destination
• Must be Public IPs available to MX
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Meraki Traffic Shaping – Historical Data
• Historical Data
• Last 2 Hours
• Day
• Week
• Month
• Changing Connectivity
• Latency
• Loss
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Global Bandwidth Limits
• Limit users bandwidth
• Slide Rule 50 Kbs - Unlimited
• Enable SpeedBurst
• 10 Second bandwidth burst
• Returned to limit
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
Meraki Traffic Shaping Rules
• Create the Rule
• Select an Expressions
• Expressions equate to
TCP/UDP Ports
• Multiple Expressions
equates to a Definition
• Set bandwidth limits
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Applying DSCP Value
• Select the traffic “Priority”
• Select the DSCP tag
desired
• “Bandwidth Limit” Option
• Select “Priority”
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Creating a Custom Expression
• Additional Network Ports
Telnet (SSH) 22 NTP 123
Telnet 23 SNMP Agents 161
DNS Queries 53 SNMP Servers 162
DHCP 67
https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_num
bers#Well-known_ports
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Attempting to Squelch
• Select Expression
• Choose Limit
• Place in “Low” Priority
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
Demo QoS
Moving to Traffic Shaping Screen Window
• From the Main screen of an MX
security appliance
1. Select “Traffic shaping”
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Moving to Create a New Rule Screen Window
• From the Traffic Shaping
Screen
1. Select “Create A New Rule”
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
Creating a Rule Definition
1. Click on “Add +”
2. Select category
1
3. Select one or more
expressions
3
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
Choosing Bandwidth
1. Choose the Bandwidth Limit
Type
2. Choose bandwidth limit
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
Changing DSCP
1. Click on DSCP Tagging
2. Select DSCP value desired
3. Save your changes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Custom Expression - Port
1. Click on “Add+”
2. Enter port number in box
3. IE “123”
4. Click on “Add Expression”
button to complete
5. Save your changes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 123
Custom Expression - Website
1. Click on “Add+”
2. Enter URL in box
3. IE “Cisco.com”
4. Click on “Add Expression”
button to complete
5. Save your changes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 124
Custom Expression – Network/Port
1. Click on “Add+”
2. Enter network:port in box
3. IE “10.1.24.0:80”
4. Click on “Add Expression”
button to complete
5. Save your changes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 125
Operations and Support
Configuring a Static Address on the Meraki
• High Level Steps of the
process
• Share with the audience that
there are hidden slides
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 127
Accessing the Device
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 128
Entering the Configuration Screen
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 129
Configuring the Static IP and associated
information
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 130
Configuring a Static Address on the Meraki
• Click on Appliance Status • Click on Uplink
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 131
Configuring a Static Address on the Meraki
• Select Static IP
• Add IP address
• Add DNS information
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 132
Organization - Configure
• Organization Settings • Configuration Synch
• Administrators
• License Information
• Bulk Network Creator
• Create a Network
• Inventory
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 133
Organization Settings
• Password Expiration
• User Passwords
• Strong Passwords
• Account Lockout
• Idle Timeout
• Two-factor authentication
• Login IP Ranges
• Deleting a Network
• Additional Resources
Network name Serial Network tags Name Tags Address Notes Static IP Netmask Gateway DNS1 DNS2 VLAN
Store - 1 QXXX-XXXX-XXX1 west tag1 AP - 1 rainbow 1600 Pennsylvania Oval office 5.5.5.1 255.255.255.0 5.5.5.254 5.5.5.253 5.5.5.252 5
Store - 1 QXXX-XXXX-XXX2 west tag1 AP - 2 rainbow 1600 Pennsylvania Situation room 5.5.5.2 255.255.255.0 5.5.5.254 5.5.5.253 5.5.5.252 5
Store - 2 QXXX-XXXX-XXX3 west tag3 AP - 3 rainbow 1600 Pennsylvania Panic room 5.5.5.3 255.255.255.0 5.5.5.254 5.5.5.253 5.5.5.252 5
Path = Organization > Bulk network creation
• Network name
• Model number
• Order number
• Select Networks
• Click on Copy
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 143
Selecting Sync Source
Landing Page
Select Source
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 144
Traffic Rule update to a single device
Updated Traffic Shaping Rule
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 145
Selecting Sync Destination
Target Network
Inconsistency
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 146
Sync Configuration
Click Copy
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 147
Organization - Monitor
• Change Log
• Login Attempts
• Firmware Upgrade Status
• Configuring Network Firmware Upgrades
• Configuration Templates
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 148
Change Log
• Type
• Status
• Time Stamp
• Security Fixes
• Known issues
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 155
Creating a New Template
• Select Create New from drop-down
window
• Initial window
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 156
Create a Template Name
• Create a Template Name • Select an existing network as the
template
• Bind to select existing network
• Build one from scratch
• Close to build from scratch
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 157
Saving Template
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 158
View All Networks
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 159
Setting the Time Zone
Select
General
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 160
Configuring Addresses and VLANs
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 161
Enabling Custom Addresses
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 162
Creating a Unique Subnet Template
Select Unique
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 163
Creating Auto Generated Addresses
VLAN Name
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 164
Creating Auto Generated Addresses
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 165
Unique Subnetting Created
Both the original and Unique configurations exist
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 166
Reserving and IP Range in DHCP
Select DHCP
Select DHCP
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 167
Reserving a Range of IP Addresses
Available IP Addresses
within the range (1 – 254)
Save Changes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 168
Network Q-BR Prior to Bind – Address & VLANs
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 169
Network Q-BR Prior to Bind - DHCP
No Reserved IP range
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 170
Navigating to Bind a Network to the Template
Click on Template
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 171
Bind Network “Q-BR” to “EST W@H” Template
Widow opens to enable binding
a network to the template
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 172
Q-BR Address & VLANs post Bind
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 173
Q-BR Reserved Addresses post Bind
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 174
Navigating to unbind a Network from a Template
Click on Template
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 175
Navigating to unbind a Network from a Template
Click Unbind
Save Changes
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 176
Q-BR after Un-Bind – Address & VLANs
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 177
Q-BR after Un-Bind - DHCP
Returns to No
Reserved IP range
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 178
Local Overrides
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 179
Security
• Access Control
• Splash Page
• Content Filtering
• Threat Protection
• Advanced Malware Protection
• Intrusion Detection and Prevention
• Event Log
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 180
Access Control
Network Access
Walled Garden
Controller
Disconnection Behavior
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 181
Access Control Configuration – Direct Access
• Access Control
• Select VLAN
Target VLAN
• Network Access
• Splash Page
• Network Access Control
No Splash Page
• Captive Portal Strength
• Walled Garden
• Controller Disconnection
Behavior
Path = Security Appliance > Configure > Access Control
• Message
• Splash Logo No Option for Splash Page
• Splash Language
• Splash Behavior
• Splash Frequency
• Where should users
go after splash
page?
• Walled Garden
• Controller Disconnection
Behavior
Path = Security Appliance > Configure > Access Control
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 184
Splash Page
• Message
• Splash Logo
• Splash Language
• Splash Behavior
• Splash Frequency
• Where should users
go after splash
page?
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 185
Access Control Configuration – Sign On
• Access Control Target VLAN
• Select VLAN
• Network Access
• Splash Page Sign-On
• Network Access Control
• Walled Garden
• Controller Disconnection
Behavior
Path = Security Appliance > Configure > Access Control
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 186
Access Control Configuration – Facebook Wi-Fi
• Access Control
• Select VLAN
• Network Access
• Splash Page
Create Page
• Network Access Control
• Walled Garden
• Controller Disconnection
Behavior
Path = Security Appliance > Configure > Access Control
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 187
Splash Page
• Message
• Splash Logo
• Splash Language
Splash Page Settings on
• Splash Behavior Facebook Wi-Fi
• Splash Frequency
• Where should users
go after splash
page?
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 188
Demo Access Control
Content Filtering
Identity Based
Filtering Policies
Automatic, cloud-based
signature updates
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 190
Content Filtering
• Category Filtering
• Blocked Website Categories
• URL Category List Size
• Search Filtering
• Web Search Filtering
• Restricted YouTube Content
• URL Blocking
• Blocked URL Patterns
• Whitelisted URL Patterns
• Event Type
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 193
Client Status
Detection Prevention
Ruleset
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 196
Intrusion, Detection and Prevention Modes
• Mode
• Whitelist URLs
• Whitelist Files
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 197
Intrusion, Detection and Prevention Ruleset
• Connectivity
• Balanced
• Security
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 198
Advanced Malware Protection (AMP)
• Mode
• Whitelist URLs
• Whitelist Files
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 201
Where do we go from here?
• Beta
• Expansion Topics
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Coming soon to an MX near you
Configure PIM routing over Auto VPN for
PIM - SM multicast communication between clients and a
multicast source with IGMP.
Allows configurations where traffic egressing the
No-NAT WAN interface will maintain the private source
address.
Allows specified traffic to exit an MX locally, as
VPN Exclusions opposed to getting full-tunneled, when a default
Auto VPN route is configured.
IKEV2 for non-Meraki IKEV2 will be supported for both non-Meraki and
VPN Client VPN on the MX.
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 203
Expansion Topics
• Umbrella – DNS
• Multicast
• Meraki vMX (Amazon, Azure)
• API Integration
• DNA Center
• ISE
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Conclusion
Complete your online session evaluation
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 206
Continue
your Demos in
the Cisco
Walk-in
self-paced
Meet the
engineer
Related
sessions
education campus labs 1:1
meetings
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 207
208
Thank you
#CLUS
#CLUS
Voice Bandwidth Links & Tools
• Voice Bandwidth Table
http://www.cisco.com/c/en/us/support/docs/voice/voice-quality/7934-bwidth-consume.html
• PVDM Calculator
http://www.cisco.com/web/applicat/dsprecal/dsp_calc.html
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 210
Meraki using the backup connection method
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 211
Meraki using the primary connection method
#CLUS BRKCRS-2103 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 212