Virtualized Multiservice Data Center with Virtualized Services 2013 Cisco and/or its affiliates. All rights reserved.
Date/Time Thur, Feb 21st at 0900 PST Topic Cisco Open Network Environment (Cisco ONE) Next Phase of Network Programmability and SDN Thur, Feb 28th at 0900 PST Cisco One Platform Kit (onepk): Technical Deep Dive and key use cases Wed, Mar 6th at 0900 PST Nexus 1000V for Hyper-V with Microsoft SCM integration Wed, Mar 13th at 0900 PST Cisco ONE Controller: Technical Deep Dive and key use cases Wed, Mar 20th at 0900 PST 5000 Seat VDI Reference Architecture: Cisco UCS & Nexus 1000V, Citrix XenDesktop, and EMC VNX Wed, Mar 27th at 0900 PST Nexus 1000V v2.2 for vsphere: More scale, Multicast-less VXLAN, and VXLAN Gateway Wed, April 3rd at 0900 PST Cloud Services Router (CSR 1000V) - technical deep dive and key use cases Wed, April 10th at 0900 PST Cloud Security with ASA 1000V and Virtual Security Gateway v2.1 (VSG) Wed, April 17th at 0900 PST Secure Hybrid Cloud solution with Nexus 1000V InterCloud & VNMC InterCloud Wed, April 24th at 0900 PST Wed, May 1st at 0900 PST Wed, May 8th at 0900 PST Nexus 1100 Series Cloud Services Platform: new services & ecosystem including VXLANto-VLAN GW and Imperva's SecureSphere WAF Cloud Networking Services: vwaas and vnam Virtualized Multiservice Data Center (DC) with Virtualized Services Wed, May 15th at 0900 PST Nexus 1000V for K (with OpenStack and VXLAN) Register and view recordings/presentations here: www.cisco.com/go/1000vcommunity 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2
Zettabytes / Year Global Data Center Traffic Growth Data Center Traffic Nearly Quadruples from 2011 to 2016 7.0 6.0 5.0 31% CAGR 2011 2016 5.2 ZB 6.6 ZB 4.0 4.1 ZB 3.0 3.3 ZB 2.0 1.0 1.8 ZB 2.6 ZB 0.0 2011 2012 2013 2014 2015 2016 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3
Installed Workloads in Millions Workload Shift: Cloud vs. Traditional Nearly Two-thirds of all Workloads Will Be Cloud-based by 2016 200 180 160 140 120 100 80 60 40 20 0 20% CAGR 2011 2016 Cloud Data Center Traditional Data Center 62% 52% 30% 48% 38% 70% 2011 2012 2013 2014 2015 2016 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
Global Data Center Traffic by Destination Most Data Center Traffic Consistently Stays Within the Data Center A Within Data Center (76%) Storage, production and development data, authentication Data Centerto-Data Center 7% Data Centerto-User 17% B Data Center-to- Data Center (7%) Replication, inter-database links Within Data Center 76% C Data Center-to-User (17%) Web, email, internal VoD, WebEx, et al. 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
Cisco s Cloud Strategy Enabling Cloud Applications/Services by Uniquely Combining the Unified Data Center and Cloud Intelligent Network Tailored Solutions for Building Clouds Rich Ecosystem of Integrated Solutions Innovative Cloud Services Research In Motion SAMSU NG Enable customers to build and operate private, public or hybrid clouds Enable customers to deploy tested, best of breed solutions Enable cloud services including peoplecentric collaboration and other applications 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 6
What is Virtualized Multiservice Data Center? (DC) A validated reference architecture Reducing time to deployment Reducing risk Increasing flexibility Improving operational efficiency A blueprint enabling customer to readily deploy services or applications A flexible, modular design that can be used as a blueprint for cloud deployments A prescriptive package available to customers as a whole offer An architecture built to scale An architecture that combines integrated compute stacks, unified data center and data center interconnect into an end-to-end architecture Architecture for customers deploying virtualized services (application workloads) in a cloud-style environment, sharing common infrastructure for multiple cloud consumers or tenants 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7
Cisco Virtualized Multiservice Data Center A Cloud Ready Data Center Architecture Enhanced Data Center Interconnect Unified Data Center Networking Integrated Compute Stacks Data Center Core Aggregation Services Access DC DC DC Cloud Service Management Business Support Provisioning Configuration Portability/ Interoperability DC Validated Design Comprehensive Modular Flexible Approach Reduced Risk Increased Flexibility Operational Efficiency Service Tiers NAS Compute SAN 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 8
Unit Feature Integration System Customer Cisco Validated Design Process Innovation and Quality Through System Level Design and Validation Key Customer Engagements Consider end-to-end view Product Development Cross platform collaboration System Development Fundamentals Thought Leadership System level innovations System Delivery Tested and validated designs System Development Guidelines Planning Design End-To-End Validation Documentatio n 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 9
Virtualized Multiservice Data Center (DC) Cloud Infrastructure Inter-Data Center Networking Multi-Site Connectivity WAN Cloud Service Management Unified Fabric and Data Center Networking Providing Network and Services Virtualization Networking Fabric Services Network Fabric Cloud Ready Infrastructure Business Support Provisioning Configuration DC Unified Computing and Integrated Systems FlexPod with NetApp Unified Computing Vblock with VCE Access Storage Portability/ Interoperability CIAC Providing Server and Application Virtualization NAS VIA with HDS Compute SAN Compute BMC CLM Zenoss 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10
The Challenge: How do I scale my data center? Service Appliances Data Center Services Node Integrated Compute Stack Storage Network Compute Integrated Compute Stack Storage Network Compute PoD Point of Delivery (PoD) Architectural consistency through a modular approach Modular, tiered construct consisting of groupings of integrated compute stacks plus storage and networking infrastructure A single Pod can be deployed and operated by itself or connected together to other Pods to achieve scale DC validates 2 styles of Pods: Compact and Large The Solution Point of Delivery (POD) Benefits Simplified capacity planning Ease of new technology adoption Consistent and efficient operation 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11 11
Scalable Compute: DC Supported ICS VCE S Vblock Family of Cloud Infrastructure Packages Pre-Integrated and Supported Cloud Infrastructure Focus teams on using infrastructure vs. assembling and supporting the individual components Cloud Service Provider Operational Model Provisioning, service delivery, chargeback, etc. Accelerates the Shift to a Private Cloud Model Less time debating, more time using Vblock Series 700 Storage: EMC Symmetrix Vmax Compute: Cisco UCS Virtualization: ware Orchestration: Unified Infrastructure Manager (UIM) Vblock Series 700 model MX Vblock Series 300 Storage: EMC VNX Compute: Cisco UCS Virtualization: ware Orchestration: Unified Infrastructure Manager (UIM) Four Models 12 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12
Scalable Compute: DC Supported ICS Cisco and NetApp s FlexPod Reference Architecture Standard, pre-validated, best-inclass infrastructure building blocks Flexible: One platform scales to fit many environments and mixed workloads Add applications and workload Scale up and out Simplified management and repeatable deployments Design and sizing guides Services: Facilitate deployment of different environments Cisco UCS B- Series Blade Servers and UCS Manager Cisco Nexus 5000 Family Switches NetApp FAS 10GE and FCoE 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13 13
DC PoD Construct DC 2.2 Components WAN Edge / DCI Core Component SW Versions ASR9000 XR 4.1.0 ASR1006 XE 3.4.0 15.1(3)S Nexus 7010 NXOS 5.2.1 Aggregation/ Access Services ASA5585-60X 8.4.2 ACE30 A 4.2.1 Compute Storage Cat 6509 UCS 6140, B200 VSG Nexus 1000V ware MDS9513 IOS 12.2.33 SXJ 1.4(2b) 4.2(1)SV1(2) - VNMC: 1.2(1b) NXOS 4.2.1 SV1(1.4a) vsphere 4.1 U1, ESXi NXOS 5.0.4d 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14 14
DC Secure Containers Service Levels Bronze Silver Gold Palladium L3 L3 L3 FW vfw LB Public Zone Private Zone LB FW L3 L3 L3 L3 L2 L2 L2 L2 LB vfw vfw vfw vfw 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
DC Container Model Tiered Security - Logical Perimeters and Zones Private (Tenant VRF) Public/Shared VRF Less Trusted Zones Front-end Tenant Perimeter ASA Context (per tenant) Protected VRF (control point) Nexus 1000v vpath VSG Back-end Tenant Perimeter Front-end Zones Back-end Zones Sub- Zone W Sub- Zone X Public Zone (DMZ) Protected FE Zone 1 Zone 2 Sub- Zone Zone Y 3 Sub- Zone Z Back-end Management Perimeter Note: RA VPN Concentrators not shown 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
Cisco Virtual Networking and Cloud Network Services Cloud Network Services WAN Router Virtualized/Cloud Data Center Switches Servers Imperva SecureSphere WAF Citrix NetScaler VPX Cloud Services Router 1000V vwaas Network Analysis Module (vnam) ASA 1000V Cloud Firewall Cisco Virtual Security Gateway Zone A Tenant A Zone B Physical Infrastructure vpath VXLAN Nexus 1000V Multi-Hypervisor (ware, Microsoft*, RedHat*, Citrix*) Nexus 1000V (Dist. Virtual Switch) Distributed switch NX-OS consistency VSG (Zone-based FW) -level controls Zone-based FW ASA 1000V (Cloud FW) Edge firewall, VPN Protocol Inspection vwaas (WAN Optimization) WAN optimization Application traffic 7000+ Customers Available Now Available Now Available Now CSR 1000V (Cloud Router) WAN L3 gateway Routing and VPN Available Now vnam (Network Analytics) App Visibility (L2- L7) Overlay Intelligence (OTV, VXLAN, FP**) 1H 2013 Ecosystem Services Citrix NetScaler VPX virtual ADC Imperva Web App. FW 1H 2013 **MSFT: 2Q CY2013; Open-source: In PoC **FP: FabricPath 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17
DC VSA: Sample Virtual Private Cloud Container Components: IOS XR 4.3 CSR XE 3.9 (IOS FW, RaaS, AppNav Controller, NBAR2) Netscaler VPX 10.1 vwaas 5.2 (vpath and AppNav redirection) vnam 6.0 N1KV 2.2 VXLAN on N1kV IPv6 Dual Stack (TBC) Hyper-V (TBC) VPX L3 VPN VPX b- b- Public Zone Zon Zon e Y e Z (DMZ) Protected FE Zone 1 Zone 2 Zone 3 Front-end Zones CSR1000v (vce) vwaas Internet RA VPN Option ASA1000v VPN VPX vwaas VSG Back-end Zones vnam Su b- Zon e W Su Su b- Zon e X Su Nexus 1000v + VPATH 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18
Virtual Services Architecture: Key Concepts Overlay networking VXLAN for scalable tenant segmentation and intra-dc L2 extension Virtual services with single service instance per tenant Virtual + physical also supported RAAS virtual router for tenant routing Abstracted network control via DC network controller L3 VPN Citrix Netscaler VSG Zone Public Zone Protected FE Zone 1 Zone 2 Y Zone 3 Z Front-end Zones CSR1000v Internet ASA1000v VPN Back-end Zones Sub- Zone W Sub- Zone X Sub- Sub- Zone Nexus 1kv + VPATH 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19
Virtual Services Architecture: Key Concepts (Cont d) End to End differentiated SLA Support and Application Visibility NBAR2 on CSR for application-based differentiation vnam Network Analysis L3 VPN Citrix Netscaler CSR1000v Internet ASA1000v VPN VSG vnam vwaas Application Performance Tuning vwaas for end-to-end application optimization Sub- Sub- Zone Zone W X Sub- Sub- Zone Zone Public Zone Protected FE Zone 1 Zone 2 Y Zone 3 Z Front-end Zones Back-end Zones Nexus 1kv + VPATH 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Security Services Chaining With vpath Intelligent Traffic Steering Through Multiple Network Services 5 4 VSG Cisco Nexus 1000V Distributed Virtual Switch vpath 1 2 3 Cisco ASA 1000V 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
Cisco CSR 1000V Cisco IOS Software in Virtual Form-Factor App OS App OS CSR 1000V Selected feature set of Cisco IOS XE Virtual Route Processor (RP) Virtual Forwarding Processor (FP) VPC/vDC Hypervisor Virtual Switch Optimized for single tenant use cases Server Multi-Hypervisor (see Roadmap) Virtual switch agnostic 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
Cisco ASA 1000V: Features and Capabilities Built using ASA technology IPSec VPN (Site-to-Site) NAT Interoperability with VSG using service chaining Support for Virtual Extensible LAN (VXLAN) Multitenant management through VNMC DHCP Default Gateway Static Routing Stateful Inspection IP Audit 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23
Cisco Virtual WAAS Virtual WAAS Appliances ESX ESXi Hypervisor w/nexus 1000 vpath UCS /x86 Servers Virtual WAAS on Nexus 1000V with vpath FEATURES Full feature parity with traditional WAAS Allows Agile, Elastic, & Multi Tenant Deployment Supports Data Redundancy Elimination (DRE) Cache in SAN Policy-based Provisioning w/ Nexus 1000V wccp, vpath, or AppNav based deployment BUSINESS BENEFITS Business Agility with on-demand orchestration Lower operational cost, reduced migration risk Fault-tolerance with mobility awareness 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 24
Managing with NC Proven Cisco security: virtualized physical and virtual consistency Cisco Virtual Network Management Center (VNMC) Collaborative security model Cisco Virtual Secure Gateway (VSG) for intra-tenant secure zones Tenant A VDC Tenant B VDC vapp Cisco ASA 1000V for tenant edge controls Cisco VSG Cisco VSG vapp Cisco VSG Transparent integration With Cisco Nexus 1000V Switch and Cisco vpath Scale flexibility to meet cloud demand Multi-instance deployment for scaleout deployment across the data center Cisco ASA 1000V Hypervisor Cisco ASA 1000V Cisco vpath Cisco Nexus 1000V Cisco VSG 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
DC with Virtualized Network Services PoC/Demo Setup WAN Edge ASR9K Data Center Customer Edge Tenant Entry Point) TenantA Nexus 7000 CSR V TenantB Cisco Nexus 1110-X VSMs Cisco Nexus 1110-X VSMs Virtual Access/ Compute Nexus 1000V Outside: 10.40.25.101 ASA1000v Inside: 192.168.1.100 Nexus 1000V Outside: 10.40.26.101 ASA1000v Inside: 192.168.2.100 VLAN101 (Port Profile: TenantA) VLAN102 (Port Profile: TenantB) VSG vwaas 192.168.1.110 VSG Application Win7 (DHCP) Win7 (DHCP) Tenant DHCP Range: 192.168.1.200-210 Web Srv DB Srv Web: 192.168.1.1/24 DB: 192.168.1.2/24 VCM 192.168.1.111 Win7 (DHCP) Tenant DHCP Range: 192.168.2.200-210 Win7 (DHCP) 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
Demo: Service Chaining of Virtualized Network Services (Products: vwaas, ASA1000v, VSG) TenantA Containe r Mgmt ASR1K INTERNET Bank.com VNMC DCNM 10.40.99.7 10.40.99.5 Nexus 1000V Outside: 10.40.25.101 ASA1000v Inside: 192.168.1.100 Remote DR Site vwaas ISR VLAN101 (Port Profile: TenantA) Win Clients (DHCP) Tenant DHCP Range: 192.168.1.200-210 File Server Web Server VSG X Database Server 192.168.1.216 192.168.1.1 192.168.1.2 vwaas 192.168.1.110 vwaas Central Mgr Data Center Remote Backup Service (w/ vwaas) Backup1 10.140.10.10/24 WAN Edge 10.140.11.10/24 Remote Backup Service (no vwaas) Backup2 172.28.224.102 172.28.224.103 VSG: Virtual Security Gateway ASA: Adaptive Security Appliances vwaas: Virtual Wide Area Application Service 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
DC Resource Links DC Design Zone http://www.cisco.com/go/vmdc Questions: ask-vmdc-external@cisco.com (Core team members, including mgmt, planning, architecture and test engineers) DU Publications (Internal) select DC and associated Orchestration and DCI system IDs http://sdu.cisco.com/systems/ DC Webex Social Page (Internal) http://iwe.cisco.com/web/sdu/vmdc SDC 2.2 CVD http://www.cisco.com/en/us/partner/docs/solutions/enterprise/data_center/dc/2.2/implementation_guide/vmdcimpl ementationguide22.html DC 3.0 CVD http://www.cisco.com/en/us/partner/docs/solutions/enterprise/data_center/dc/3.0/ig/dc_3.0_ig.html Cisco Cloud Megatest (based on DC) http://www.cisco.com/en/us/solutions/ns341/eantc_cloud.html Data Center Interconnect Design Zone http://www.cisco.com/en/us/partner/netsol/ns749/networking_solutions_sub_program_home.html DC Orchestration with BMC CLM http://www.cisco.com/en/us/partner/solutions/ns340/ns414/ns742/cloud_orchestration_bmc_clm.html#~entitled DC Assurance with Zenoss CSA http://www.cisco.com/en/us/partner/solutions/ns340/ns414/ns742/dz_cloudservice.html Cloud Enablement Services Website http://www.cisco.com/en/us/products/ps11104/serv_home.html 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28
Thank you.