Presentation Title Meraki SD-WAN: A Global Solution For Distributed Networks
Presentation Title Meraki SD-WAN: A Global Solution For Distributed Networks
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 1
Agenda
• About the MX
• Connectivity and SD-WAN
• Monitoring and visibility
• Demo
• What’s new
• Product Portfolio
• Q&A
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
About the Meraki MX
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Simplifying IT with cloud management
A complete cloud managed IT solution
Wireless, switching, security, SD-WAN,
communications, EMM, and security
cameras
Integrated hardware, software, and cloud
services
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Benefits of a cloud managed solution
Security
Reliability
Scalability
Future-proofing
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
A complete connectivity and threat management solution
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Why customers choose the Cisco Meraki MX
Powerful security that’s easy to implement
• Robust suite of Cisco Security technologies
• Intuitive GUI-based configuration
• Seamless updates from the cloud
Exceptional scalability
• Zero-touch provisioning with cloud brokered VPN
• Easy centralized management with built-in remote
troubleshooting tools
• Multi-location configuration templates
Industry-leading visibility
• Fingerprints users, applications, devices, and threats
• Monitor one location or an entire deployment
• Unified monitoring and reporting with other Cisco Meraki
technologies
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Connectivity and
SD-WAN
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Projected Costs for Legacy 3-Year WAN Run Rate
Deep dive: Penn Mutual Internet Connectivity (3 years) $2,016,000
saves $858K
Traditional T1 VPB hub-and-spoke model x 45 sites $582,000 / year
(1.544-4.632Mbps Ethernet)
WAN at HQ & DR (45Mbps x 2) $90,000 / year
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Automated site-to-site VPN (Auto VPN)
Simple Create VPN tunnels between locations with easy point-and-click interface, or apply configuration
templates to enable and configure VPN at many locations at once
Automatic VPN configuration generated and deployed automatically from the cloud – create a mesh or hub-
and-spoke topology with only a few clicks
Resilient Automatically adjusts to changes in order to maintain secure connectivity during an ISP or
datacenter outage, hardware failure, or IP address update
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Auto VPN orchestration Subnet Uplink IP Public IP
1 New MX registers its Uplink IP, 1. A new MX registers its IP and subnets
Public IP and local subnets
2. The information is propagated to other
MX via the Dashboard
3. They establish VPN connection
a) With unique pre-shared keys
b) Try Uplink IP first (private link?)
3 New MX establishes c) Try Public IP second
site-to-site VPN connection
New route is propagated 2
to all MX peers
automatically
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Supported topologies
Full Mesh Hub-and-Spoke
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Multiple hub-and-spoke and failover
10.0.0.0/8 10.0.0.0/8
10.100.0.0/16 10.200.0.0/16
HA PAIR DC1 DC2 HA PAIR
HQ Regional Office
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
High availability and path redundancy
Avoid downtime and disruption
• Automatic datacenter outage detection
• Automatic failover to warm spare appliance
• Dual WAN uplinks for ISP load balancing and redundancy
• MPLS route health tracking with MPLS-to-VPN failover
• 3G/4G cellular uplink via USB modem
Reduce complexity
• VPN and route changes made automatically
• Configuration templates for configuring multiple locations
• Intuitive, centralized configuration and monitoring
Reduce costs
• HA warm spare only requires a single license
Example hub-and-spoke datacenter failover • Safely leverage low-cost broadband or LTE connections for
topology your business critical traffic
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
SD-WAN Scenario 1
“Vanilla”
• Branch office
• Two uplinks
• No load balancing
Diagram here
• Hub & Spoke VPN back to DC
• Split tunnel
• No SD-WAN configuration
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
SD-WAN Scenario 1: How does it Flow?
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
SD-WAN Scenario 2
“Vanilla with sprinkles”
• Branch office
• Two uplinks
• No load balancing
Diagram here
• Hub & Spoke VPN back to DC
• Split tunnel
PbR rules configured for VoIP traffic
○ Prefer to send VoIP traffic
across a VPN path over
secondary Internet connection
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
SD-WAN Scenario 2: How does it Flow?
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
SD-WAN Scenario 3
“Chocolate”
• Branch office
• Two uplinks
• No load balancing
Diagram here
• Hub & Spoke VPN back to DC
• Split tunnel
PbR rules for FTP traffic
○ Prefer to send FTP traffic path on
the secondary Internet connection
PfR rules also configure for VoIP traffic
○ VoIP traffic should only traverse
low latency paths
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
SD-WAN Scenario 3: How does it Flow?
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
VPN tunnels
Flow decision examples
Example 1: MX #1
uplink1 uplink2
Both peers are dual WAN with MPLS
and Broadband
Internet
MPLS
uplink1 uplink2
MX #2
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
VPN tunnels
Flow decision examples
Example 1: MX #1
uplink1 uplink2
Both peers are dual WAN with MPLS
and Broadband
First packet
Internet
For a given flow: MPLS
1. MX2 send a packet up
• Local uplink decision: Based on PbR / dynamic path selection
uplink1 uplink2
• Remote uplink decision: Only available path MX #2
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
VPN tunnels
Flow decision examples
Example 1: MX #1
uplink1 uplink2
Both peers are dual WAN with MPLS
and Broadband
Steady State
Internet
For a given flow: MPLS
1. MX2 send a packet up
• Local uplink decision: Based on PbR / dynamic path selection
uplink1 uplink2
• Remote uplink decision: Only available path MX #2
2. MX1 replies through its uplink1 to MX2 uplink1
• Local uplink decision: Based on PbR / dynamic path selection
• Remote uplink decision: Only available path
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
VPN tunnels
Internet
uplink1 uplink2
MX #2
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
VPN tunnels
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
VPN tunnels
Second packet
For a given flow: Internet
1. MX2 send a packet up
• Local uplink decision: Based on PbR / dynamic path selection
uplink1 uplink2
• Remote uplink decision: First packet, pick a tunnel (round robin) MX #2
2. MX1 replies through its uplink1 to MX2 uplink1
• Local uplink decision: Based on PbR / dynamic path selection
• Remote uplink decision: MX1 registers that the packet came from MX2 uplink1
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
VPN tunnels
Steady State
For a given flow: Internet
1. MX2 send a packet up
• Local uplink decision: Based on PbR / dynamic path selection
uplink1 uplink2
• Remote uplink decision: First packet, pick a tunnel (round robin) MX #2
2. MX1 replies through its uplink1 to MX2 uplink1
• Local uplink decision: Based on PbR / dynamic path selection
• Remote uplink decision: MX1 registers that the packet came from MX2 uplink1
3. MX2 replies through its uplink1 to MX1 uplink1
• Local uplink decision: Based on PbR / dynamic path selection
• Remote uplink decision: MX2 registers that the packet came from MX1 uplink1
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Performance probes
Each uplink send a probe across all available paths
In this example, MX2 sends 4 probes
Uplink Uplink
The receiving MX will reply with 4 probes 1 2
These values are computed from all possible paths (max 4) per MX
Path Latency
Incoming latency Current average:
value 10 15 20 20 15 10 15 ms
Path Jitter
Calculated Jitterk = Current average:
|latencyk – latencyk-1| 5 5 0 5 5 … 2.5 ms
Packet loss
Incoming loss (1/0) Current average:
value 0 0 0 0 0 0 0%
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Connections that fit your business and location needs
Broadband + MPLS Broadband + 4G Dual Broadband
Auto VPN Auto VPN Auto VPN Auto VPN Auto VPN Auto VPN
Broadband MPLS Broadband LTE Broadband Broadband
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
MPLS with Broadband
• Use MPLS for mission critical traffic MPLS + Broadband
• VoIP
• PoS (point of sales, a.k.a credit card traffic)
• Video / Teleconferencing Data Center
• Database traffic
• Email
• Backups, file transfers
Branch
MPLS with Broadband
• Get more out of your existing MPLS MPLS + Broadband
Branch
Dual Broadband
Dual Broadband
• Not as reliable as MPLS
Internet Internet
Branch
Dual Broadband
Dual Broadband
• More bandwidth
Internet
Auto VPN
Internet
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
In-depth
visibility
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Traffic monitoring and analytics
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
VPN health, bandwidth, and performance monitoring
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Email alerts from the cloud
Fully integrated alerting - no need for
an email server
Customizable alerting – only get
emails about the things you need to
know about
Get alerts if critical network clients go
offline
Configure alerting for all Cisco
Meraki devices in one simple
interface
Send alerts to network administrators
or custom recipients
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
DEMO
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
What’s new
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Available now
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
MX Product Updates – Past 6 Months
BETA BETA
Threat Grid for Template support Multicast routing BGP routing
BETA
No-NAT
Meraki MX for SD-WAN (PIM-SM)
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
MX Portfolio
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
MX Portfolio – Fall 2017
Teleworker Small Branch Medium Branch
New
FW throughput: 4 Gbps FW throughput: 1 Gbps FW throughput: 6 Gbps FW throughput: 1 Gbps VPN & SD-WAN features
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Licensing that fits the business’ needs
Site-to-site and client VPN Content filtering (with Google SafeSearch enforcement)
Web caching
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
The Meraki Full Stack
MR MX MS
Wireless Security and WAN Switching
Systems Manager MC MV
EMM IP Telephony Security Cameras
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Cisco Spark
Questions?
Use Cisco Spark to chat with the
speaker after the session
How
1. Find this session in the Cisco Live Mobile App
2. Click “Join the Discussion”
3. Install Spark or go directly to the space
4. Enter messages/questions in the space
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Complete Your Online Session Evaluation
• Give us your feedback about the session
you just joined
Ø Complete your session surveys through the
Cisco Live mobile app:
https://www.ciscolive.com/latam/attend/attendee-info/#mobile-app (English)
https://www.ciscolive.com/latam/attend-es/attendee-info/#mobile-app (Español)
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Q&A
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Thank you
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
BRKCRS-214 2 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 54