cisco connect toronto 2017 - simplifying cloud adoption

61
© 2016 Cisco and/or its affiliates. All rights reserved. 1 Cisco Connect Simplifying Cloud Adoption with Cisco Ronnie Scott Technical Solutions Architect 12-Oct-2017

Upload: cisco-canada

Post on 22-Jan-2018

155 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1

CiscoConnect

Simplifying Cloud Adoption with CiscoRonnie ScottTechnical Solutions Architect

12-Oct-2017

Page 2: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

2© 2016 Cisco and/or its affiliates. All rights reserved.

The World of Many Clouds

Page 3: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 3

The World of Many Clouds

Private Cloud

SDN Controller

Automation / Orchestration

Data Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Page 4: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 4Presentation ID

Defining the Hybrid Cloud

Cloud Management Platform

Public Cloud

Community Cloud

Private Cloud

Policy

Page 5: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 5Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a shared pool of

configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 6: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 6Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a shared pool of

configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 7: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 7Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a shared pool of

configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 8: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 8Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a shared pool of

configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 9: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 9Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a (e.g., networks,

servers, storage, applications, anshared pool of configurable

computing resourcesd services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 10: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 10Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a shared pool of

configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 11: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 11Presentation ID

Cloud computing is a model for enabling ubiquitous,

convenient, on-demand network access to a shared pool of

configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly

provisioned and released with minimal management effort or

service provider interaction.

NIST Cloud Computing Definition

Page 12: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 12

The Cost Benefits

HW/SW Costs Licencing Costs

Maintenance Costs

Environmental Costs Support Costs

Page 13: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1313Presentation ID

Low Utilization Costs Money

0

2

4

6

8

10

12

5 10 15 20 25 30 35 40 45 50

Public

Private

Legacy

Page 14: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1414Presentation ID

So Do Value-Added Cloud Services

0

2

4

6

8

10

12

14

16

5 10 15 20 25 30 35 40 45 50

Public

Private

Legacy

Redundant

Gauranteed

Page 15: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1515Presentation ID

Reduced Complexity = Increased ReturnSaaS

• No Infrastructure

• No Management

• No Helpdesk

• Universal Access

Page 16: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1616Presentation ID

Reduced Complexity = Reduced ControlSaaS

• Who Owns Your Data?

• What Customization Is Available?

• How Much Help Is Their Helpdesk?

• What Security Do They Offer?

• Can You Repatriate Data?

• What Is Their SLA?

Page 17: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1717Presentation ID

Account Sprawl

ITFinance

HR

ProcurementSales

Manufacturing

Page 18: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 1818Presentation ID

Utilise Existing Resources

• Idle Resources Are Cheaper Than Any Cloud

Page 19: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

19© 2016 Cisco and/or its affiliates. All rights reserved.

Building the Private Cloud

Page 20: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 20

IT as a Service IaaS | PaaS | SaaS | XaaS

Flexible Consumption Models

CONSOLIDATIONVIRTUALIZATION

HYBRID CLOUDS

POLICY DRIVENAUTOMATION

TRADITIONAL DATA CENTER

We are here

CLOUD-READY DATA CENTER

Page 21: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 21Presentation ID

Build The Foundation

Private Cloud

Element ManagerData Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Page 22: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 22

“How do I automate and orchestrate the network?”

Page 23: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 23

Automation

Page 24: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 24

Orchestration

Page 25: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 25

Two approaches to Control Systems

Air traffic control tells where to take off from, but not how to fly the plane

Baggage handlers follow sequences of simple, basic instructions

IMPERATIVE CONTROL DECLARATIVE CONTROL

Page 26: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 26

“Cisco UCS provides a true single point of management, simplifying orchestration”

Page 27: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 27

Subject Matter ExpertsDefine Policies

1

UCS: Embedded AutomationIntegrated, Policy-Based Infrastructure Management

Policies CreateService Profile Templates

Clone Templates toCreate Service Profiles

Associate Service Profiles to Configure Hardware

Uplink port configuration, VLAN, VSAN, QoS, and EtherChannels

Server port configuration including LAN and SAN settings

Network interface card (NIC) configuration: MAC address,VLAN, and QoS settings;host bus adapter HBA configuration: worldwide names (WWNs), VSANs, and bandwidth constraints;and firmware revisions

Unique user ID (UUID), firmware revisions,and RAID controller settings

Service profile assigned to server, chassis slot, or pool

Uplink port configuration, VLAN, VSAN, QoS, and EtherChannels

Server port configuration including LAN and SAN settings

Network interface card (NIC) configuration: MAC address,VLAN, and QoS settings;host bus adapter HBA configuration: worldwide names (WWNs), VSANs, and bandwidth constraints;and firmware revisions

Unique user ID (UUID), firmware revisions,and RAID controller settings

Service profile assigned to server, chassis slot, or pool

Uplink port configuration, VLAN, VSAN, QoS, and EtherChannels

Server port configuration including LAN and SAN settings

Network interface card (NIC) configuration: MAC address,VLAN, and QoS settings;host bus adapter HBA configuration: worldwide names (WWNs), VSANs, and bandwidth constraints;and firmware revisions

Unique user ID (UUID), firmware revisions,and RAID controller settings

Service profile assigned to server, chassis slot, or pool

Uplink port configuration, VLAN, VSAN, QoS, and EtherChannels

Server port configuration including LAN and SAN settings

Network interface card (NIC) configuration: MAC address,VLAN, and QoS settings;host bus adapter HBA configuration: worldwide names (WWNs), VSANs, and bandwidth constraints;and firmware revisions

Unique user ID (UUID), firmware revisions,and RAID controller settings

Service profile assigned to server, chassis slot, or pool

Uplink port configuration, VLAN, VSAN, QoS, and EtherChannels

Server port configuration including LAN and SAN settings

Network interface card (NIC) configuration: MAC address,VLAN, and QoS settings;host bus adapter HBA configuration: worldwide names (WWNs), VSANs, and bandwidth constraints;and firmware revisions

Unique user ID (UUID), firmware revisions,and RAID controller settings

Service profile assigned to server, chassis slot, or pool

2 3 4

NetworkSME

ServerSME

StorageSME

Page 28: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 28

Leaf / Spine Forwarding

Leaf

Spine Spine SpineSpine

Leaf

PacketSent

Lookup NextHop

Encapsulate &forward

Decapsulate &Deliver

ServiceLeaf

BorderLeaf

Campus Network

Controller

Page 29: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 29

APIC

Software Defined Networks – ACI

ADC APP DBF/WADC

WEB

HYPERVISORHYPERVISOR HYPERVISOR

Page 30: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 3030

Automate and Orchestrate - UCS Director

Policy-Driven Provisioning

VMsComputeNetwork Storage

Tenant

BTenant

CTenant

A

Virtualized and Bare-Metal

Physical Compute

B CANetwork and Services

VM VM BareMetal

BRKPCA-2020

Page 31: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 31

Private Cloud

Element ManagerSDN Controller

Automation / Orchestration

Deliver a Cloud Experience

Data Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Page 32: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 32

TCP: *,443 C

C

C

Provisioning Automation

Self-Service Catalog

Application-Centric Infrastructure

Self-Describing Packaging Manageability Fault-Tolerant Self-Optimizing

Application Developers Cloud Orchestration DC Resources

AutomationPacks

C

C

C

C

C

DEPLOYCLICKMODEL

WEB APP

Page 33: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

33© 2016 Cisco and/or its affiliates. All rights reserved.

Consuming the "Right" Cloud

Page 34: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 34

Cost Security DRAvailabilityTimeliness

Scalability Performance RepatriationComplianceSupport

Defining Application Priorities

Page 35: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

35© 2016 Cisco and/or its affiliates. All rights reserved.

Cisco's Cloud Tools

Page 36: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 3636Presentation ID

Defining Application Linkages

• Application Team Knowledge

• Network AnalysisTetration

• Cloud Management ToolsCisco Cloud Center

Page 37: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 3737Presentation ID

Define Network Relationships

Page 38: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 38

Security

Dependencies

Application

Service Offering

Service

Service Category

(Service Owner)

Create Application Dependency Map – Tetration

Use CiscoTetration Analytics™outcome to generate

white-list policies

Page 39: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 39

Infrastructure-CentricCloud-Specific workflows and ScriptsLabor /Services Intensive

UniqueScript /

Workflow

Application-Centric

Cloud-Agnostic

Low TCOUniqueScript /

Workflow

UniqueScript /

Workflow

Script-Based Application Profile-Based

Create Application Profiles – CloudCenter

Page 40: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 40

Create Application Profiles – CloudCenter

DataCenter

DEPLOY

MANAGE

MODEL

Public Cloud

PrivateCloud

One Integrated Platform

Lifecycle Management

New and ExistingApplications

Page 41: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 41

Reduce to to valueto provision VM or Application

Enable governance on policies and sharing across business units

Control application development costs across SDLC

Cisco Services for CloudCenter

CloudCenter Deployment

Configure CloudCenter

Model Application Profile

Analyze Environment Readiness

Configure Governance

& Policy

Deploy and Validate

Page 42: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 42

Cloud Based Network Function Virtualization

• CSR 1000v

• ASAv

• NGFWv

• Meraki vMX100

• ACI Anywhere

Page 43: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

43© 2016 Cisco and/or its affiliates. All rights reserved.

Performance Validation

Page 44: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 44

www

User Applications Code Infrastructure

AppDynamics: End-to-End Application Intelligence

AppDynamics

Fast Time To ValueAutomated map and correlation

Unified VisibilityEUM, APM, Infrastructure

Contextual & ActionableBusiness Transactions

Page 45: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 45

AppDynamics: Highly Correlated Data ModelThe Business Transaction Enables Unifying and Strategic Context

“Before AppDynamics, we were paramedics, but with AppDynamics we are brain surgeons.”

Server UserSession

Network

Database AppCode

Business Transaction BusinessMetrics

INFRAInfrastructure

Visibility

EUMEnd User Monitoring

APMApplication

Performance Management

Page 46: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 46

Cisco Workload Optimization Manager Automated Decision Engine determines workload placement and scaling by matching resource demands to available supply.

• Deploys in <20 minutes

• Performance analysis in 1 hour

• Full demand profile in 72 hours

Page 47: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 47

Automatable Upsizing

Continuous VM resource monitor

Add CPU or Memory to running VM – no reboot or downtime required

Targeted Rightsizing

Track historical VM resource utilization

Reduce CPU or Memory allocated to a VM – during maintenance downtime

Fundamental Capabilities: Scaling

Page 48: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 48

Data Center

Moves workloads, assures performance, increases density

Placements abide by business or license constraints.

Cloud

Placement in public cloud based on best cost, while assuring performance.

Placements abide by business, license, or data sovereignty constraints.

Fundamental Capabilities: Placement

$

Page 49: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

Use Cases

Data Center Modernization

Data Center Optimization

Hybrid Cloud Optimization

Page 50: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

50© 2016 Cisco and/or its affiliates. All rights reserved.

Cloud Security

Page 51: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 51

Cisco Cloud Security

UmbrellaSecure Internet GatewaySecure access to the internet

wherever users go, even off VPN

CloudlockCloud Access Security Broker

Secure users, data, and apps across SaaS, PaaS, and IaaS

Users Data Apps

SAAS / PAAS / IAAS

Umbrella InvestigateThreat intelligence

View relationships between malware, domains, and IPs across the internet

Page 52: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 52

UmbrellaStart blocking in minutes

Easiest security product you’ll ever deploy

Signup1

2 Point your DNS

3 Done

Page 53: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 53

Investigate: the most powerful way to uncover threats

Console

API

SIEM, TIP

Key points

Intelligence about domains, IPs, and malware across the internet

Live graph of DNS requests and other contextual data

Correlated against statistical models

Discover and predict malicious domains and IPs

Enrich security data with global intelligence

domains, IPs, ASNs, file hashes

Page 54: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 54

Cisco Cloudlock addresses customers’ most critical cloud security use cases

Discover and Control

User and EntityBehavior Analytics

Cloud Data Loss Prevention (DLP) Apps Firewall

Cloud Malware

Shadow IT/OAuth Discovery and Control

Data Exposures and Leakages

Privacy and Compliance Violations

Compromised Accounts

Insider Threats

Page 55: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 55

CASB – API Access (cloud to cloud)

ADMINOAUTH

ACCESS

Public APIsADMINOAUTH

ACCESSAuthorized

Cisco NGFW / Umbrella

ManagedUsers

ManagedDevices

ManagedNetwork

UnmanagedUsers

UnmanagedDevices

UnmanagedNetwork

Page 56: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

56© 2016 Cisco and/or its affiliates. All rights reserved.

Conclusion

Page 57: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 5757Presentation ID

Understand Your Customer Expectations

• Simplified User Portals

• Rapid Delivery Times

• Cost Effective Infrastructure

• Strong Security

• Flexible Access Models

Page 58: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 58

Private Cloud

Element ManagerSDN Controller

Automation / Orchestration

Become More Cloudy

Data Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Page 59: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 59

Leverage All Available Resources

Private Cloud

SDN Controller

Automation / Orchestration

Data Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Private Cloud

SDN Controller

Automation / Orchestration

Data Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Private Cloud

SDN Controller

Automation / Orchestration

Data Center 1

Leaf Leaf Leaf

Spine Spine Spine Spine

Border Border

Data Center 2Spine Spine Spine Spine

Leaf Leaf Leaf Border Border

Data Center Interconnect

Page 60: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

© 2016 Cisco and/or its affiliates. All rights reserved. 60

Put Security Everywhere

Page 61: Cisco Connect Toronto 2017 - Simplifying Cloud Adoption

Thank you.