Cisco Prime Network Registrar An Integrated DDI Solution for the Internet of Things Cloud & Virtualization Technology Group
Agenda Global Trends, Challenges, and Operational Requirements Prime Network Registrar Value Proposition An Integrated DDI Solution Customer References 2
Global Factors in IP Traffic, 2014 2019 More Devices More Devices: 21 billion networked devices Faster Broadband Speeds: Up to 6-fold speed increase Faster Broadband Speeds Key Growth Factors More Internet Users More Internet Users: 4 billion global Internet users More Rich-Media Content: IP video will represent 79 percent of all traffic Rich-Media Content Source: Cisco Visual Networking Index (VNI) Global IP Traffic Forecast, 2014 2019 3
The Internet of Everything Connecting people in more relevant and valuable ways. Delivering the right information to the right person (or machine) at the right time. Leveraging data into more useful information for decision making. Physical devices and objects connected to the Internet and each other for intelligent decision making. People-to-People + People-to-Machine + Machine-to-Machine 4
The IP Address Management Challenge The Number of IP Addresses and IP Devices Continues to Increase Dramatically, as does Network Size and Complexity DNS and Dynamic Host Configuration Protocol (DHCP) Are Mission-Critical in Today s Enterprise Networks. New Technologies Are Being Introduced Into the Network: Voice over IP (VoIP), Video, Cloud Computing, Virtualization, etc. Network Operators Are Under Pressure to Reduce Operating Expenses (OpEx). DNS Attacks Are Creating Significant Risks for IT Systems. BYOD Trend: IT Is Challenged with Network Device Detection and Control. IP Address Management (IPAM) Costs Are Rapidly Accelerating, and Manual Processes and Tools Cannot Scale. 5
DDI Solution Operational Requirements DNS, DHCP, and IP Address Management (DDI) Network Operators need an integrated DDI Solution that provides: Reduced OpEx Improved workflow Automation Simplified manageability Security and compliance Access Management Configuration Management Customer Management DDI Operational Tasks Regulatory Compliance Business Support Reporting 6
Cisco Prime Network Registrar An Integrated Solution Four Integrated Components Focused on Scalability, Reliability, and Future-Readiness with Enhanced, Integrated Management DHCP DNS IPAM DNS Caching! Single DHCP server that supports both IPv4 and IPv6 for device network access! Internal and external client reservations! Standards compliant! Single DNS server that supports both IPv4 and IPv6 for IP address translation and service delivery! Standards compliant! Enhanced, comprehensive IPAM integrated with DNS and DHCP for configuration as well as reporting and management of IPv4 and IPv6! Recursive, extremely fast DNS Security Extensions (DNSSEC) caching server to gain better performance! DNS64 support (IPv4 access for hosts with only an IPv6 address) 7
Cloud Ready Tenant A Environment Multitenancy Support for Cloud-Based DHCP and DNS Isolation Within the Secure Cloud Architecture Tenant B Environment Security & Isolation Security & Isolation VMware Virtual Machines VMware Virtual Machines REST / RESTful API Multitenant Virtualized Infrastructure Managed Through a Self-Service Portal or Orchestration 8
REST / RESTful API s! Simple and common communication protocols! Offers a universal interface as an HTTP service! A set of rules to handle requests in a generic way! Used to integrate DDI into the broader Cloud based environment 9
Intelligent Automation for the Cloud 1) Cisco IAC Provisions Tenant Environment Orchestration 2) Requests a service Cloud Admin Creates Tenant Accounts IP Address Blocks Containers Tenant User 3) Provision User Request IP Register Host Update DNS Cisco Prime Network Registrar 10
and IPAM 11 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11
Connectivity Gets Complicated! The world is growing more connected, as is the enterprise. IDC estimates there are now 20.4 billion connected things worldwide, growing to 29.7 billion by 2020.! Cisco Visual Networking Index (VNI) forecasts;! 500 million net new devices and connections were added to the mobile network in 2014! Globally, IPv6 traffic will account for 52% of total mobile data traffic by 2019, compared to 13% at the end of 2014.! There will be 6.2 Billion IPv6-capable devices/connections by 2019, up from 2.0 Billion in 2014. 12
IPAM and The Internet of Things! Managing networks in an ever decreasing IPv4 space! Three of the five regional internet registries have exhausted their IPv4 allocation! Network operators need to Map their IP the network! They want a real-time view of the IP space! They need to identify the relationship between a device type and address pool! The market is transitioning to IPv6 centric devices! In a cloud centric world automation rules! Allocation from specific scope/sub net based on device type or policies! Multi-tenancy / VPN! Service provider / Cloud services (SDN) using DNS to identify clients 13
Comprehensive, Full-Featured IPAM Simple, centralized, integrated management of DHCP and DHCP services, IPv4 and IPv6 address space, subnets, address blocks, and address assignment DHCP and DNS server configuration Automated IP tracking and allocation with full network IP discovery and reconciliation Intuitive GUI for real-time visibility and detailed IP audit reporting and diagnostics Mega menus for easy navigation and faster accessibility of available command options Role-based IPAM delegation of DNS and DHCP Support for open source BIND, Microsoft, and Cisco Prime Network Registrar DNS and DHCP IPAM Is Critical for IP Network Operations 14
Cisco IPAM Approach The number of IP addresses and IP devices continues to increase dramatically, as does network size and complexity Allocations Services! IPv4/IPv6 blocks/subnets Plan! DNS/DHCP deployment! DNS/DHCP configurations! Address space mapped to business operations Discrepancies Reconcile IPAM Lifecycle Deploy! Multiple vendors and/or appliances! Dynamic DNS Actual Network! Reconciliation of actual and planned configurations! Reporting (audit utilization) Discover! Simple Network Management Protocol (SNMP) v2 and v3 discovery! IP host discovery! Switchport mapping! DHCP pool utilization 15
Cisco Prime Network Registrar IPAM! IP address management in a single user interface! Integrated data collection from routers, Address Resolution Protocol (ARP) caches, DHCP servers, and ping sweeps facilitates IP address space discovery, planned vs. actual reconciliation, alerts, and capacity management! Unsurpassed user definability enables customers to manage IP address space consistent with their management methods! Enables easy transition to IPv6 with options to integrate IPv4 and IPv6 networks IP/DHCP/DNS is a critical network services layer. Cisco Prime Network Registrar helps enable network operators to eliminate duplicate IP addresses, accurately configure DHCP services, and centralize IPv4/IPv6 inventory. 16
Lower Risks and Reduced Startup Costs Virtual Appliance Option Deploy Cisco Prime Network Registrar as a preconfigured virtual appliance and simplify installation, lower deployment risks, and reduce startup costs Ideal for organizations that have implemented a virtual infrastructure Enables organizations to benefit from all the key capabilities of Cisco Prime Network Registrar without investing in new hardware Allows rapid DNS/DHCP provisioning for capacity handling and relocation of DNS, DHCP, and IPAM (DDI) services from one server to another for disaster recovery 17
Cisco Prime Network Registrar Jumpstart IPv6-Ready DDI Appliance! Cisco Prime Network Registrar Jumpstart is an appliance providing DNS, DHCP, and IP address management (IPAM) (DDI) for service providers and enterprises looking for fast time to value! Cisco Prime Network Registrar! Integrated, scalable, reliable DDI solution preinstalled on the appliance! Cisco UCS C220 M3! High-density, two-socket, one-rack-unit (RU) rack-mount server DHCP DNS IPAM! VMware ESXi! VMware virtualization technology preinstalled on the appliance Cisco Prime Network Registrar Fast Scalable Extensible Reliable IPV4 /IPv6 Cloud-ready 18
Wrap Up Slide/Slides Looking forward Openstack and REST Scalability, reliability, performance Resilience Cisco centric approach = affords single support and solution provider 19
Moving Forward! Dual stack DDI (DHCP, DNS and IPAM) services! Standards compliance! Resilient and scalable DHCP services! IPAM mapping address space to manage the transition from IPv4 " IPv6! An extensible solution to integrate with existing BSS/OSS applications! A secure DNS solution consisting of DNS Firewall and DNSSEC 20
USGv6 Certification! Cisco Prime Network Registrar has achieved USGv6 (US Government IPv6) certification for its DHCP IPv6 server and may be sold to US Government agencies.! Today, all civilian agency networks are required by law to be IPv6capable. These US Government agencies are required to procure only IPv6 products that are USGv6 certified. 21
Fast and Scalable Distributed architecture that supports an Internet of Everything class install in some of the largest deployments in the world A blazingly fast DHCP server with outstanding performance Dedicated DNS caching server that significantly improves DNS query throughput The industry s most scalable DHCP server, supporting more than 50 million devices in a single customer deployment 22
Reliable Multiple levels of redundancy, with: Support for DHCPv4 and DHCPv6 simple failover and High-Availability DNS (DNS- HA) Patented discriminating rate limiter based on packet prioritization Reduce downtime after network outages Optional chatty-client filter DHCP-Induced Avalanche Request Request Discover Discover Discover Discover Request Discover Discover Discover Discover Discover Request Request Request 23
Extensible DHCP Platform is extremely customizable and flexible using expressions, extensions and REST/RESTful web services API to meet unique business needs Powerful extension support allows network operators to alter and customize DHCP server operations for both IPv4 and IPv6 Extensions easily create new solutions such as billing, security, and lawful interception Extensive SOAP APIs and command-line interfaces (CLIs) enable integration points between the IPAM component and external systems for advanced IPAM automation 24
DNS Caching Server and DNS Security! DNS caching server improves the speed and performance of high-volume recursive queries! Support for DNSSEC helps protect resource records against DNS vulnerabilities: data spoofing, corruption, DNS cache poisoning! DNSSEC helps provide authenticated data to the end user, providing validation that DNS data has been signed 25
DNS Advanced Features DNS Firewall and NXDOMAIN Redirect DNS Caching DNS Firewall! Allows standard Authoritative DNS zones and processes to define lists of FQDNs, IP addresses, subnets and prefixes of end nodes for the purpose of black/white listing.! Subscribe to third party security organizations! Modify DNS query responses to redirect clients away from known risky websites.! Assist users when they query a non-existent domain name (i.e., the server has no entry) by redirecting to customer defined page Optimize the user experience by helping users get to a predefined URL 26
DNS Views DNS Views allow a single DNS server to service multiple copies of the same zone Primarily a function of Authoritative DNS but integrated with other IP Express servers (i.e. DNS Caching and DHCP) DNS requests are mapped to the appropriate view based on matching the view s ACL (aclmatch-clients) CPNR comes pre-configured with an explicit Default view Views are sorted and ACLs mapped based on priority attribute (low to high) After upgrade from pre-8.2, all zones are in Default view Who is Bing.com? 192.168.3.3 DNS Who is Bing.com? 204.79.237.3 Internal External 27
Thank you.
Public Customer References
Cisco Network Registrar Case Study: IBBS Background IBBS is a managed services provider supporting small and medium-sized cable operators. IBBS has 250 customers managing more than 1 million cable modems across North and South America. It automates the provisioning and diagnostics of these devices via a managed service. Cisco Network Registrar has been an important part of this managed service since the business was established in 2001. The solution supports DNS and DHCP services as the basis of a DOCSIS cable modem provisioning system. Cisco Network Registrar is deployed as a single, multitenant cluster in the IBBS data center in Atlanta. Impact on Customer and Results The flexibility and scalability of Cisco Network Registrar have enabled IBBS to provide cable modem access services using a cloud model for the last 10 years with very little cost-long before it was called the cloud. Economies of scale and cost savings far exceed those of the competition. Extension points give IBBS precise control over the DHCP requests coming in and the responses going out, based on very complex and detailed criteria. All day, every day, Cisco Network Registrar reliably identifies each device and class of service, and then provides IP addresses and the right configuration files and profiles to keep each modem up and running. - Kyle Johnson, IBBS Director of Product Strategy 30
Cisco Network Registrar Case Study: Comcast Background! Comcast is a leading media and entertainment company, providing high-speed video, telephony, and Internet services to business and residential customers.! Comcast delivers more than 150,000 TV shows, movies, and other video content to over 49 million customers across North America.! Comcast began planning the transition of its network to IPv6 in 2005. The ability to operate in dual stack mode, to accommodate IPv4 and IPv6 traffic, has been a critical component of its strategy. Impact on Customer and Results! The flexibility and scalability of Cisco Network Registrar have enabled Comcast to transition to IPv6 seamlessly with no disruption to subscribers.! Cisco Network Registrar enabled Comcast to go well beyond feature parity between its management of IPv4 and IPv6 traffic, to actually advance its business by being able to implement advanced features, from device management to subscriber services, while running in dual stack mode.! With Cisco Network Registrar our IPv6 program was able to go well beyond feature parity and device management. We were able to design and implement features that enabled us to advance our business with new subscriber services. - John Brzozowski, Distinguished Engineer, Chief Architect IPv6 Transition, Comcast 31
Competitive Information
INTERNAL USE ONLY Competitive Strengths and Weaknesses Vendor Strengths Weaknesses / Gaps Implications Cisco Prime Network Registrar Alcatel-Lucent Vital QIP Infoblox NIOS BlueCat Networks Proteus 5000 Extensible Scalable Service provider market share Heterogeneous Significant market share Scalable Managed services offering Strong reports and audit capabilities Significant market share Brand recognition User Interface DDI overlay solution User interface DDI overlay solution Appliance and software Cisco partner Historically focused on service provider market Ease of Use Limited service provider market share Historically slow to respond to feature requests Scalability Has not been profitable since going public Scalability Privately funded Market expansion via Enterprise segment leverages Microsoft Active Directory support Telecom, enterprise, government market share Continues to grow market share via aggressive marketing campaign Aggressively pursuing DDI market share ISC BIND Open source (free) Standards compliant Used by multiple competitors Higher support costs due to lack of maintenance agreement Scale and performance Lowers Network Registrar s perceived value Nominum DNS security focus Hosted services Juniper partner Seen as a DNS provider Perceived as high cost 33
INTERNAL USE ONLY Market Analysis Cisco Prime Network Registrar Competitive Positioning Nominum QIP Infoblox BlueCat Microsoft Performance (DHCP) Performance (DNS) Appliance option No Yes Yes Yes No Scalability APIs v6 support GUI Configuration features DHCP extensions No No No No No DNS features Security features High availability Cisco vs.: Exceeds Meets Incremental Gap 34
Product Licensing and Purchase Requirements Cisco Prime Network Registrar is licensed by component Components can be purchased individually or as one of two suites (DHCP/DNS or DHCP/DNS/IPAM). The DNS caching server is always a separate purchase. The components are priced on a per IP node (DHCP and IPAM) or resource record (RR) (DNS) basis. The DNS caching license is a per server license. The customer needs to purchase the base license, which provides the Cisco Prime Network Registrar media kit and 1K IP node/rr license. The customer can purchase additional licenses as needed. Since the release of version 8.0, customers deploying Cisco Prime Network Registrar must install a regional server. 35
Cisco Prime Network Registrar Summary Superior manageability Real-time visibility into IPv4 and IPv6 Accountability promoted through detailed IP audit reporting and diagnostics and granular administrative policies for access Helps ease the transition from IPv4 to IPv6 Discover and take inventory of IPv4 and IPv6 resources Plan and model the way the IPv6 network should be deployed Map current IPv4 network and devices to IPv6 space Scalable and able to grow with the business Secure with DNSSEC and DNS Firewall Easy to deploy with low-risk appliance options 36
Additional Resources Cisco Prime Network Registrar on Cisco.com: www.cisco.com/go/networkregistrar Cisco Network Registrar Tech Center developer support: http://developer.cisco.com/web/cnr/home Cisco Prime Network Registrar internal portal: http://wwwin.cisco.com/nmtg/fieldportal/products /networkregistrar/index.shtml For additional information, please contact: ask-networkregistrar@cisco.com 37
Thank you.
INTERNAL USE ONLY ENTERPRISE-VERSION OF SLIDE Proven Market Leader More than 1200 customer deployments Service providers Cable providers: 90% market share Large enterprises, educational institutions and government agencies Large Enterprises Education Government GOVERNMENT OF THE REPUBLIC OF CHINA (TAIWAN) 39