nexus1000v-series-switches webcast indepth part2 17feb

152
Vishal Mehta Technical Marketing Engineer February 17, 2015 Cisco Nexus 1000v Series Switches, Part 2: Meet the 1000v Family: The Secret of Unity February 17, 2015 Cisco Support Community Deep Dive Expert Series Webcast

Upload: yibrail-veliz-plua

Post on 25-Dec-2015

15 views

Category:

Documents


2 download

DESCRIPTION

Nexus 1000v

TRANSCRIPT

Page 1: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Vishal Mehta

Technical Marketing Engineer

February 17, 2015

Cisco Nexus 1000v Series Switches, Part 2: Meet the 1000v Family: The Secret of Unity – February 17, 2015

Cisco Support Community

Deep Dive Expert Series Webcast

Page 2: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Upcoming Expert Series Webcast

Game Changer: Silver Lining in the Cloud the 1000v Family: The Secret of Unity February 24, 2015 Where Vishal will continue the topic by discussing Nexus 1000v through deployment phases for enabling ICF

In-Depth on Cisco Nexus

1000V Series Switches, Part 3

http://tools.cisco.com/gems/cust/custome

rSite.do?METHOD=E&LANGUAGE_ID=E&SEMINAR_CODE=S22085

March 17th, 2015

Ever wonder what VFC, VETH, VIF and HIF are in UCS and which path your packets are taking?

UCS infrastructure has several virtual components and this makes it challenging to troubleshoot but it is critical to understand. Cisco Expert, Niles Pyelshak will discuss UCS interfaces and how packets travels from the UCS server.

Demystifying Unified Computing System

(UCS) Interfaces for troubleshooting.

https://supportforums.cisco.com/event/12413

926/expert-webcast-demystifying-unified-computing-system-ucs-interfaces-

troubleshooting

Page 3: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Now through February 27th

Ask the Expert Events – Active

Join the discussion for these Ask The Expert Events:

https://supportforums.cisco.com/expert-corner/knowledge-sharing

Cisco Email Security Appliance (ESA), Web

Security Appliance (WSA), and Content

Security Management Appliance (SMA).

Join Cisco Expert, Nasir Abbas

Page 4: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Rate Content Now your ratings on documents, videos, and blogs count give points to the authors!!!

So, when you contribute and receive ratings you now get the points in your profile.

Help us to recognize the quality content in the community and make your searches easier. Rate content in the community.

https://supportforums.cisco.com/blog/154746

Encourage and acknowledge

people who generously share their

time and expertise

Page 6: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Cisco Support Community Expert Series Webcast

• Today’s featured expert is Cisco Technical Marketing Engineer Vishal Mehta

• Ask your questions now in the Q&A window

Vishal Mehta

Technical Marketing Engineer

February 17, 2015

Cisco Nexus 1000v Series Switches,

Meet the 1000v Family: The Secret of

Unity

Page 7: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Topic: Part 2: Meet the 1000v Family: The Secret of Unity

Technical Expert – Question Manager

Gunjan Patel

Page 8: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

If you would like a copy of the presentation slides, click the PDF file link in the chat box on the right or go to:

https://supportforums.cisco.com/document/12427796/expert-depth-series-cisco-nexus-1000v-series-switches-part-2-slides

Or, https://supportforums.cisco.com/expert-corner/knowledge-sharing

Thank You For Joining Us Today!

Page 9: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Now through February 27th

Ask the Expert Event following the Webcast

Join the discussion for these Ask The Expert Events:

https://supportforums.cisco.com/expert-corner/knowledge-sharing

Vishal will be continuing the discussion in an Ask

the Expert event. So if you have more

questions, please visit the Knowledge Center on

the Cisco Support Community

https://supportforums.cisco.com/discussion

/12412941/ask-expert-deepdive-cisco-nexus-

1000v-series-switches

Page 10: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Submit Your Questions Now! Use the Q & A panel to submit your questions

and the panel of experts will respond.

Please take a moment to

complete the survey at

the end of the webcast

Page 11: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Polling Question 1

How do you provide Security to Virtual Workloads ?

a. We rely on Physical Security Devices

b. We are using mix of Physical and Virtual security applications

c. We are using Virtual Security

Page 12: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Vishal Mehta

Technical Marketing Engineer

February 17, 2015

Cisco Support Community Deep Dive Expert Series Webcast

Cisco Nexus 1000V Series Switches Part 2: Conquered Territory: Multi-Hypervisor

Page 13: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 14: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Conquered Territory: Multi-Hypervisor

14 14

Page 15: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

1.5.1 2.2 3.0 Strategy

VXLAN

• VXLAN 1.0

• Multicast based

• Flood and Learn

• VXLAN 1.5

• Single VSM only

• Mac-distribution

• No flood and learn

• VXLAN 2.0

• BGP Control Plane

• VTEP distribution

• Continue supporting multi-

cast based VXLAN for

standards compliance and

interoperability w ith Nexus

hardw are

• BGP control plane for

interoperability w ith

Nexus9K and for better

physical virtual story

1.5.1 2.2 3.0 Strategy

VXLAN GATEWAY

• N/A • Nexus 1110 • GW as a VM • Minimize investment in

softw are VLXAN GW since

Nexus hardw are w ill have

GW functionality at a

cheaper price-point

• Develop GW as a VM for

Proof of Concepts and

cloud use cases

VXLAN Strategy

Page 16: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

16 16

1000v L2-7 Services

Page 17: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 18: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

18 18

Page 19: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

19 19

vPath Explanation

Page 20: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 21: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

21 21

Page 22: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

22 22

PNSC

Page 23: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

PNSC - Look & Feel

Page 24: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Prime NSC Functional Components Functional

Component

Description

Service Registry • A central registry of endpoints - VSM, VSG, ASA 1000v, ICS, ICX, CVSM and providers – RM, PM,

VMM, MC

• Org Repository for multi-tenancy

Policy Manager • Centralized repository of device, firewall and InterCloud tunnel policies

• Policy authoring and administration

Resource Manager • Management of VSG, ASA 1000v, VSM, VMware vCenter, InterCloud Link and Cloud VM

• Image Management for endpoints and Cloud VM

• Configures endpoints, Discovers Port Profiles and VM attributes from VSMs

• Create ICX VM on vCenter

• Assign mac address and port id for cloud VM overlay interfaces

VM Manager • Collects VM Attributes from VMware vCenter

Management

Controller

• VNMC system management: DNS, NTP, syslog, core files…

Cloud Provider

Manager

• Image manipulation – probing, conversion

• Interface with Cloud Provider to implement cloud VM Lifecycle

Page 25: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Prime NSC Functional Components (Contd.) Functional

Component

Description

Policy Agent on

VSG/ASA 1000v

• Registration of VSG/ASA 1000v with VNMC

• Configures Policy Engine on VSG/ASA 1000v(firewall policies and device policies)

Policy Agent on

Nexus 1000v

• Registration of VSM with VNMC

• Notifies VNMC when VMs are attached/detached

• Notifies VNMC when VM IP addresses are learned

Policy Agent on

ICS/ICX

• Configures tunnel & key policy

• Cloud VM configuration is sent to ICS

GUI • Flash-based GUI – Internet Explorer, Mozilla Firefox, Google Chrome

API • HTTP/XML APIs – Used by GUI and northbound API clients

PMON • Manages NSC processes – start, stop, monitor and restart

Page 26: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Hypervisor Hypervisor Hypervisor

VSM VSG

PNSC / VSG / VSM System Architecture

VC

VSM VSG

Hypervisor

VEM SDP

VM Management

VNMC

Packets

Via Overlay Tunnel

Policy

Resolution

Port Profiles

and Security Profiles

VM

Attributes

Centralized Management Plane

Centralized Policy Repository

Centralized Policy Administration

VM Attributes from vCenter

REST XML API

NOT in the data path – VNMC can be

shutdown and the VM traffic will still flow

Each VSG handles the traffic of one tenant

No Persistent Configuration

Centralized Run-Time State, Flow Table

Policy Engine, Stateful Firewall

Distributed Data Plane

Embedded in VEM, 1 Per ESX Host

Intercepts Traffic using Service Table

Redirects Traffic via Overlay Tunnel

Fast-Path using Flow Table

Virtual Security Gateway(VSG)

Service Data Path (SDP)

Virtual Network Manager Center (VNMC)

Policy Agent

Policy Agent

Resource

Manager

VM

Manager

Policy

Manager

Service

Registry

GUI

REST-XML API

DME model-driven framework

VM IP Learning

VM Attach Port Profiles

XML API Client

XML Over HTTPS

Page 27: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

27 27

Page 28: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

28 28

Family Photo

Page 29: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

29 29

Family Photo

Page 30: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

30 30

Family Photo

Page 31: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

31 31

Family Photo

Page 32: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

32 32

Family Photo

Page 33: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 34: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

34 34

VSG Deployments

Page 35: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

35 35

VSG HA Setup

Page 36: Nexus1000v-Series-switches Webcast Indepth Part2 17feb
Page 37: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Virtual Security Gateway Intelligent Traffic Steering with vPath

Nexus 1000V Distributed Virtual Switch

VM VM VM

VM VM

VM

VM VM VM

VM

VM

VM VM VM

VM VM VM VM

VM

vPath

PNSC

Log/Audit

Initial Packet

Flow

VSG

1 Flow Access Control

(policy evaluation)

2

Decision

Caching 3

4

Page 38: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Virtual Security Gateway Performance Acceleration with vPath

Nexus 1000V

Distributed Virtual Switch

VM VM VM

VM VM

VM

VM VM VM

VM

VM

VM VM VM

VM VM VM VM

VM

vPath

Remaining

packets from flow

ACL offloaded to

Nexus 1000V

(policy enforcement)

PNSC

Log/Audit

VSG

Page 39: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

TENANT A

VSG

ASA 1000V

Hypervisor Nexus1000V vPath

Virtual Network Management Center (VNMC)

vCenter

TENANT B

VSG

VSG

VSG

vApp

vApp

ASA 1000V

VDC VDC

Page 40: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

40 40

Page 41: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Interface security-profile 2

security-profile db-server

nameif db

no ip address

Nexus 1000

Nexus 1000V

VM VM VM VM VM VM

Port Group 1 Port Group 2

Port Profile 1

Edge Security Profile: web-server

Port Profile 2

Edge Security Profile: db-server

ASA

1000V VM Port Profile 3

Port Group 3

inside

outside

Interface security-profile 1

security-profile web-server

nameif web

no ip address

security-level 100

Interface GigabitEthernet0/0

nameif inside

ip address 192.168.0.1

security-level 100

service-interface security-profile all inside

Interface GigabitEthernet0/1

nameif outside

ip address 201.24.56.11

security-level 0

Page 42: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 43: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VPC Challenges

VPC Customer 1

10.0.1.0/24

VPC Customer 2

VPC Customer 4094

• Point-to-Point tunnel between DC and VPC adds network latency

• Terminating WAN at Cloud Provider’s edge limits VPC scalability

• Disjoint local networks complicate application on-boarding to VPC

• Lack of traffic control in VPC restricts use of networking services

192.168.1.0/16

• QoS

• Acceleration

• Visibility

Customer 1

Data Center

Branch A

Branch B

VRF Cloud

Provider

MPLS

Internet

Page 44: Nexus1000v-Series-switches Webcast Indepth Part2 17feb
Page 45: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Cisco CSR1000v

• Direct VPN connectivity to VPC reduces network latency

• Termination of MPLS at VPC eliminates dependence on VLANs

• Extending DC network to VPC simplifies application deployment

• Traffic control at VPC edge enables support of network services

VPC Customer 1

VPC Customer 2

VPC Customer N

Customer 1

Data Center

Branch A

Branch B

Cloud

Provider

CSR

1000v

LISP for

VM Mobility

LISP

Router

QoS

Internet

MPLS

vWAAS

Page 46: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VPN Gateway for VPC

• Enterprise VPNs

• S2S (IPSec) VPN

• DMVPN

• EZVPN

• FlexVPN

• SSLVPN (future)

• Routing

Static

EIGRP

OSPF

BGP

• Addressing

NAT/PAT

DHCP

• Firewall & ACLs

• AAA

Data Center

Branch B

Cloud Provider

Branch A

VPC

CSR

1000v Internet

Public WAN VPN tunnel

Private address space

Page 47: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

MPLS Gateway for VPC

• Overcomes VRF to VLAN mapping limitation at DC edge router

• Extends MPLS WAN directly to VPC for any-to-any connectivity

VPC Customer 1

VPC Customer 2

MPLS

CSR

1000v

MPLS MPLS MPLS

MPLS VPN 1

MPLS VPN 2

DC Edge

Router

• MPLS

Traditional

Secure (GETVPN)

• Routing

EIGRP, OSPF

BGP, Static

• Traffic Management

QoS

IP SLAs

Page 48: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Extend DC Network to VPC

• L2 connectivity and L3 address mobility between DC and VPC

• Transparent on-boarding of existing business applications to VPC

Data Center

Cloud Provider

VPC

CSR

1000v

L2 over WAN

LISP protocol

Internet

Enterprise LISP VM

Mobility

LISP Tunnel

Router

• L2 over WAN

EoMPLS over GRE

• Addressing

NAT/PAT

VRF-Lite

• Transport Services

LISP for VM Mobility

Multicast

Page 49: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Network Services in VPC

• Traffic crossing VPC edge can be redirected to network services

Data Center

Branch B

Cloud Provider

Branch A

VPC

CSR 1000v Internet or

MPLS

Optimized TCP

vWAAS

WAAS

WAAS WAAS

• Transport services

QoS

• Resiliency HSRP

• Interception

WCCP

AppNav

• Monitoring

AVC

NetFlow

NBAR

Page 50: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Each router interface has one host Ethernet interface.

Multiple interfaces sharing one host Ethernet interface

Trunking all the way

Page 51: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

On Vmware ESXi host, assign VM Network adapters to appropriate VLANS in vSwitch

Page 52: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

52 52

Page 53: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Polling Question 2

Can 3rd party tool use vPath with 1000v ?

a. Yes

b. No

Page 54: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 55: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

vPath 3.0

Page 56: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Cisco & Citrix Product Break-out

VPX MPX

HW

Appliance

SDX

HW

Appliance

Product

N1110

NetScaler

1000V

NetScaler 1000V = VPX w/ Cisco Competing features disabled & vPath toggle Current Citrix NetScaler Architecture

x86 X86 Platform

1. Cisco Competing features that have been disabled:

• Citrix® Branch Repeater® (now Cloud Bridge), • NetScaler CloudConnectors™,

• Citrix Access Gateway™ EE SSL VPN (now NetScaler Gateway), 2. Throughputs: 10M, 200M, 500M, 1G, 2G, 3G & 4G (w/ and w/o Clustering)

3. Ability to enable/disable (toggle) vPath; disabling vPath allows you to load balance physical servers 4. 141x SKUs NOW orderable on Cisco’s Global Price List (GPL); includes ALL upgrade SKUs

5. Since vPath is optional the Nexus 1000V is also now optional so customer does NOT need vSphere Enterprise Plus to utilize

Page 57: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Citrix NetScaler 1000V

• Citrix Netscaler 1000V as a Virtual Service Blade (VSB) on Nexus 1110 or 1110. Virtual Appliance option available too.

• Simplified Operations: Create Netscaler instance from Nexus 1110/1010 management console

• Ease of Deployment: Customers have deployment flexibility to meet their performance use case

• 2 vCPU for low performance (500 Mbps)

• 6-8 vCPU for high performance (2 Gbps)

• Full Cisco HA: Netscaler HA enabled on Nexus 1110/1010 pairs

Page 58: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

58 58

Page 59: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

59 59

Page 60: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

60 60

Page 61: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 62: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

62 62

Page 63: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

63 63

Page 64: Nexus1000v-Series-switches Webcast Indepth Part2 17feb
Page 65: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Cisco Virtual WAAS Cloud-ready WAN Optimization

ESX ESXi Hypervisor w/Nexus 1000

UCS /x86 Servers

Virtual WAAS “Appliances”

vPath

Virtual WAAS

on Nexus 1000V with vPath

FEATURES

Allows Agile, Elastic, & Multi Tenant

Deployment

Supports DRE Cache in SAN

Policy-based Provisioning w/ Nexus 1000V

Extends WAAS Solution Portfolio

BUSINESS BENEFITS

Business Agility w/on-demand orchestration

Lower operational cost & migration risk

Fault-tolerance with VM mobility awareness

Page 66: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

66 66

vWAAS

Page 67: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 68: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

68 68

Multi-tenant

Page 69: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

69 69

Within tenant

Page 70: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

71 71

VSM-VSG-NetScaler topology

Page 71: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

72 72

VSM-VSG-NetScaler Chaining

Page 72: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Polling Question 3

Is there a easy way to deploy all 1000v products ?

a. Yes

b. No

Page 73: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• vPath – The Secret

• Prime NSC (* VNMC)

• Firewalls – VSG & ASAv

• Cloud Service Router – CSRv

• Netscaler Load-Balancer

• vNAM & vWAAS

• Common Deployments

• VACS - Containers

Agenda

Page 74: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Current Service Delivery is Manual & Complex

Architect Design

- QoS - Security - Compliance

Identify

Resources

License Install Provision Secure Test

Manual

Capacity On-Demand

Policy-Based Provisioning

Flexible, Agile Resource Utilization

From Weeks to Minutes

Automated Self-Service Provisioning

Page 75: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

DC Edge Security

Low efficiency due to uncontrolled VM sprawl

VM’s talking to

each other

Lack of

Security

Manually

Provisioned

Lack of

Visibility

Troubleshooting is

a nightmare

Weeks to onboard

customer/app

Page 76: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

From VM Sprawl to On-Demand Containers

DC Edge Security

Containers that are: Secured

Added Visibility

Automated Provisioning

Enterprise

Apps

Enterprise

Apps

Enterprise

Apps

Page 77: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Virtual Fabric—Nexus 1000V Platform for Distribute FW

Zone Based FW— Virtual Security Gateway

Edge FW—ASA 1000V

Routing—CSR 1000V

Automated Provisioning and Orchestration—UCS Director

VACS Built on Proven Technology

Enterprise Apps

Enforced by Best in

Class Services Built on flag ship Cisco NXOS & IOS SW

Unified Licensing Per Server based

Page 78: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

WEB APP DB

Automated Service Delivery for Applications

CONTAINER

WEB APP DB

Virtual Application

Container Services

• Provision Regulatory

Compliant Containers in

minutes

• Multi Hypervisor support

• Provisioning and Virtual

Services included in single

SKU

Page 79: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Deploy Multi-Tenants as Containers

Container A Container B

VMware vSphere

Microsoft HyperV

Virtual Services Portfolio

vPath

Stingray Orchestration

(UCS Director)

1. Automation & Agility through UCS Director as the management plane:

• No CLI experience

• Simplified Install and Configuration of :

• Virtual Fabric – Nexus 1000V

• Virtual Routing – CSR 1000V

• Virtual Security – Virtual Security Gatew ay & CSR 1000V

2. Multi Hypervisor support – vSphere & Hyper-V

3. Easy to create and deploy Virtual Network Containers

• Deploy Netw ork Container w ith less than 6 logical questions

4. Unified Licensing - Single License for all virtual components

Page 80: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS Architecture

UCSD

PNSC vCenter N1000V

CSR VSG CSR VSG CSR VSG CSR VSG

Container Container Container Container

Page 81: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS hierarchy

UCSD vCenter

vCenter

PNSC

PNSC

N1000V

N1000V

N1000V

N1000V

Page 82: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS container types • Three types

• 3 tier internal

• 3 tier external

• Custom

• Both three tier container types contain a single network (can be vlan or vxlan) with three pre-defined zones and zone policies.

• Internal and external container types differ in which zones are allowed access to/from outside the container

• Custom containers can contain multiple networks, zones and custom firewall policies

• Application VMs may be deployed at container deployment time or afterwards. This facilitates template re-use by de-coupling workloads from network topologies

Page 83: Nexus1000v-Series-switches Webcast Indepth Part2 17feb
Page 84: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Deploy 3-Tier Application Container – Internal Access

• 3 Pre-created Zones with External connectivity for Web Tier Only

Upstream Router

1. NAT (Optional)

2. L3 Routing – EIGRP 3. Edge FW

4. Monitoring Features

VACS – 3 Tier App Container

Zone based FW

Routing – EIGRP or Static

VLAN 1/ VXLAN 101

Web Tier App Tier DB Tier

VSG

CSR 1000V

Page 85: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Deploy 3-Tier Application Container – External Access

• 3 Pre-created Zones with External connectivity for all Tiers

Upstream Router

1. NAT (Optional)

2. L3 Routing – EIGRP 3. Edge FW

4. Monitoring Features

VACS – 3 Tier App Container

Zone based FW

Routing – EIGRP or Static

VLAN 1/ VXLAN 101

Web Tier App Tier DB Tier

VSG

CSR 1000V

Page 86: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS Custom Container

• Providing capability to design custom containers with N Tiers

Upstream Router

1. NAT (Optional)

2. L3 Routing – EIGRP 3. Edge FW

4. Monitoring Features

VACS – Custom Container

Zone based FW

Routing – EIGRP or Static

VLAN 1/ VXLAN 101

VLAN 2/ VXLAN 202

CSR 1000V

VSG

Tier 1 Tier 2 Tier 3 . .

Page 87: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Salient features • Automated installation of all component services

• Integrated licensing model

• Template based container deployment

• Public/Private IP address assignment

• Static/Dynamic NAT or EIGRP

• Vlan and vxlan based networks

• Distributed firewalling for east-west traffic

• HA/HSRP

• ERSPAN

Page 88: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

3-tier Internal Container Traffic walkthrough

WEB Server VM DB VM APP VM

Management VLAN id 30

Workload VM netw ork

VXLAN id 5000

VSG

CSR1000V

VIP – 192.168.1.1

Gig2.31(1) - 31.0.0.10

Gig2.31(2) – 31.0.0.11

Gig1(1) - 30.0.0.103 Gig1(2) – 30.0.0.105

Data/HA VXLAN id 20000

192.168.1.4 192.168.1.5 192.168.1.6

Mgmt IP: 30.0.0.104

Traffic initiated from Inside to Outside (only from WebZone VM) 1. First packet from Web VM enters the VEM and is re-directed to VSG. 2. VSG ACL rule (permit Web to Any) is hit, & vPATH on the VEM is programmed with the flow 3. Packet sent to the gateway, which is CSR’s downlink interface 4. Packet src IP changed to NAT’ed Public IP and sent outside via the Uplink interface 5. Subsequent packets are sent directly to CSR’s downlink interface (skipping step 1-2)

Web Client VM 10.1.1.20

10.2.2.2 (SNAT)

Page 89: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

3-tier External Container Traffic walkthrough

WEB Server VM DB VM APP VM

Management VLAN id 30

Workload VM netw ork

VXLAN id 5000

VSG

CSR1000V

Gig3.2 – 192.168.1.1

Gig2.31- 31.0.0.10

Mgmt Gig1

30.0.0.103

Data/HA VXLAN id 20000

192.168.1.4 192.168.1.5 192.168.1.6

Mgmt IP: 30.0.0.104

Traffic initiated from Outside to Inside (Eg: App VM)

1. VM1 wants to talks to App VM’s Public IP (10.2.2.3)

2. Packet reaches CSR’s uplink (G2.31)

3. NAT translation is done and packet dest.IP is changed to App Server VM’s Private IP – 192.168.1.5

4. Packet is then sent to CSR’s downlink interface (G3.2)

5. On entering N1kv VEM, packet is re-directed to VSG data interface

6. VSG ACL Rule permit Any to App is hit

7. vPATH programmed with the above flow and return flow decisions.

8. Packet sent to App VM

9. Subsequent packets of that session are directly sent to the App VM, (steps 5-6 are skipped)

VM1 10.1.1.30

10.2.2.2 (SNAT) 10.2.2.3 (SNAT)

Page 90: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Physical to

Virtual to

Cloud Journey

Inter Cloud

Private

Cloud

Hybrid

Cloud

Virtualization

Public

Cloud

Page 91: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Submit Your Questions Now! Use the Q & A panel to submit your questions and our expert will respond

Page 94: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

More IT Training Videos and Technical Seminars on the Cisco Learning Network

View Upcoming Sessions Schedule

https://cisco.com/go/techseminars

Page 95: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Please take a moment to complete the survey

Thank you for Your Time!

Page 96: Nexus1000v-Series-switches Webcast Indepth Part2 17feb
Page 97: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS Container Topology Configuration

Page 98: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Install UCSD

Page 99: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Install VACS Patch

You will be prompted to backup, select “n”

Select Option 19 to perform patch update

This will upload all the prerequisite

binaries, ovas, workflows, etc. required for

VACS to be deployed as a value-added

option for UCSD.

Page 100: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• Upload Licenses* • Validate the two licensees

have been installed

* Licenses:

• UCSD.lic

• VACS.lic

• Navigated to licenses

You should see tw o

PAK files

Import UCSD & VACS Licenses

Page 101: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• Selection Option 3 to stop

services

• Select Option 4 to restart the services

• SSH into the UCS-D console • Access Shelladmin/changme

• Select Option 2 repeatedly to

verify all services have

restarted • Your browser session will

expire • You get to see clouds until the

system completely comes back

online.

From stopping and restarting services and the GUI come back to a

login prompt is ~ 10 minutes

Restarting Services: License & Workflows Activation

Page 102: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Configure Physical Accounts, Site & Pod

• Create a POD, specifying a name, type and address

• Navigate to Administration Physical Accounts

• Provide a Site Name and Contact

Page 103: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• Select the CSR License Button & Navigate to the location of the CSR Token. Cut-n-Paste the license into the dialogue box, and upload

• Navigate to Policy Application Containers

• Select the VACS/Stingray Containers Tab

• Next select the Package Upload button

~4-5 minutes

• Then navigate to the “” then select the service request to monitor the status of the package upload

Installing VACS Components

Page 104: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

• Cloud added successfully and

verification

• Navigate to Administration

Virtual Accounts

• Select Add Cloud and populate

accordingly

• Select Converged Tab, then

double click the Pod to see

the associations

Add Virtual Account and Setup Cloud

Page 105: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Make sure your storage has over 250Gb

~ 15 minutes to deploy PNSC

You should see in VC that

the PNSC is being deployed

Install PNSC

Page 106: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Install N1KV/VSG (Part 1)

Page 107: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Install N1KV/VSG (Part 2)

Page 108: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Add Host (i.e., Install VEMs on hosts)

Page 109: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Create Compute & Storage Policies

Page 110: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

First Time Template Creation (includes resource pools)

Page 111: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Deploying a Secure Container from VACS Template

Page 112: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Container template

Page 113: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Template types

Page 114: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS deployment options (for internal template type)

Page 115: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Container application size

Page 116: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Policies

Page 117: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS Network resource pool

Page 118: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Routing protocol

Page 119: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VM networks entry (vlan)

Page 120: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VM networks entry (vxlan)

Page 121: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VM networks entry (vxlan)

Page 122: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Virtual machines

Page 123: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Virtual machines entry

Page 124: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VM network interfaces entry

Page 125: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS Summary

Page 126: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Custom template type

Page 127: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Custom-Security zones

Page 128: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Custom-ACL rules entry

Page 129: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Custom-ACL rules entry

Page 130: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Custom-ALG options

Page 131: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Custom-VM network options

Page 132: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

After the template is submitted successfully, there are default policies being created:

• Virtual Infrastructure Policies

• Tiered Application Gateway Policies

• PNSC firewall policies

Page 133: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VIP

Policies -> Application Containers->Virtual Infrastructure Policies

Page 134: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VIP

Page 135: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VIP – PNSC information

Page 136: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VIP - Gateway

Page 137: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VIP - Summary

Page 138: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Tiered Application Gateway Policies

Policies -> Application Containers ->Tiered Application Gateway Policies

Page 139: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Gateway policy

Page 140: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

CSR configuration

Page 141: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Gateway Policy - Summary

Page 142: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

PNSC firewall policies

Physical->Network->PNSC accounts->PNSC->PNSC Firewall Policies

Page 143: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

PNSC policy

Page 144: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

PNSC zones

Page 145: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

PNSC – ACL rules

Page 146: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

PNSC-VSG config

Page 147: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Publishing catalog

Policies ->Catalogs

Page 148: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Add catalog

Page 149: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Catalog - Summary

Page 150: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

Catalog published

Page 151: Nexus1000v-Series-switches Webcast Indepth Part2 17feb

VACS Workflows ( Policies -> Orchestration ->Workflows)

Workflow Description

VACS Container Setup This Workflow is executed when a VACS container deployment is requested, based on a

VACS template. The workflow deploys a VACS container based on the compute, storage, network policies

associated with the template, network configuration, firewall and routing configuration and workload VM specifications.

Add VMs to VACS Container This workflow is executed when a VACS user requests addition of VMs to an existing

VACS container.

VACS Delete VMs This workflow is executed when a VACS user requests deletion of VMs from an existing

VACS container.

VACS Static NAT This workflow is executed when a VACS user requests Static NAT configuration for

workload VMs in a VACS Container

VACS ERSPAN This workflow is executed when a VACS user requests monitoring of VM traffic for one or

more VMS

Page 152: Nexus1000v-Series-switches Webcast Indepth Part2 17feb