Le SD-WAN Pour Les Nuls: JRES 2017 - Nantes
Le SD-WAN Pour Les Nuls: JRES 2017 - Nantes
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
La digitalisation met les sites distants sous pression
Plus
80%
Of employee and
d’utilisateurs customers are served in
branch offices*
Digital
Displays
Omni-channel
Apps
SaaS Enterprise
Apps
Plus 73%
d’équipements Growth in in mobile devices
from 2014 - 2018**
Guest HD Online
Plus 20-50%
WiFi Video Training
Site distant d’applications Increase in Enterprise
bandwidth per year
through 2018**
Plus de 30%
Of advanced threats will
Social OS Mobile menaces target branch offices by
Media Updates Apps
2016 (up from 5%) **
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Une nouvelle tendance sur les sites distants
Applications
rtp
Applications
sip cirix
dns Ssl
cifs sip
skype
hsrp
webex-meeting
icmp
https
ldap flash-video
msnp dns
sap facebook
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
La nécessité du DPI (Deep Packet Inspection)
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Evolution de l’internet
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Introduction au SD-WAN
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
L’ONUG – Open Networking User Group
• Communauté d’utilisateurs
• Définition des besoins des grandes entreprises
• Travaux importants sur le SD-WAN
https://www.onug.net © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Le SD-WAN selon l’ONUG
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
10 pré-requis SD-WAN selon l’ONUG (1/2)
1. Gestion de plusieurs liens actifs (publics et privés)
2. WAN construit sur des équipements physiques et virtuels
3. WAN hybride sécurisé permettant d'appliquer une ingénierie de
trafic par application, prenant en compte la performance des liens
4. Visibilité et priorisation des applications critiques et temps réel selon
les règles définies
5. Architecture hautement redondante
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
10 pré-requis SD-WAN selon l’ONUG (2/2)
6. Intéropérabilité au niveau 2 et 3 avec le reste de l'infrastructure
7. Interface de management centralisée avec tableaux de bord par
application, site et VPN
8. Programmabilité de l’infrastructure à travers des API sur un
contrôleur qui fournit une abstraction de l’ensemble. Envoi des logs
vers collecteurs tiers (SIEM...)
9. Un équipement doit pouvoir être déployé sans configuration et un
minimum d'effort sur l'infrastructure actuelle
10. Certification FIPS-140-2 pour le chiffrement
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Une transition au niveau du SLA
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
WAN hybride et overlay
TRADITIONAL HYBRID FULL SD-WAN OVERLAY
Active/Standby Active/Active
WAN Paths WAN Paths
Data Center Data Center
Branch Branch
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Exemples …
Downtime
per Year 99.95%* Downtime 99.90%*
1 routeur per Year
MPLS 8 Hours Internet
1 connexion 4–9 Hours 46 Minutes
2 routeurs
5 Minutes
2 connexions MPLS MPLS MPLS Internet Internet Internet
* Typical MPLS and Business Grade Broadband Availability SLAs and Downtime per Year, calculated with Cisco AS DAAP tool.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Quelques points de vigilance
• Le coût
• La sécurité
• Le cloud
• La migration
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
La virtualisation sur les sites
distants
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Autres challenges sur les sites distants
Plusieurs Complexes à OPEX
équipements manager important
Routeurs, Appliances, Serveurs Intégration des équipements Upgrades, renouvellements,
déplacements sur site
Orchestration &
Automation
Platform
Platform
Platform
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
… andif aa solution
What company could
widebe deployed
webcast in under
needed a day
to be run …
Orchestration &
Automation
Video
Platform
Video
Platform Video
Platform
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
When the webcast is over, resources are released
Orchestration &
Automation
Video
Platform
Video
Platform Video
Platform
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
But
Whatyou
if acould
new deploy a solution
ERP package in under
couldn’t a day
be leveraged
Orchestration &
Automation
Platform
Platform
Platform
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
What if some sites needed new wireless control
Orchestration &
Automation
Platform
Platform
Platform
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
ButConsider a new threat
a new defense thecan
network business
be up in minutes
… everywhere at once
Orchestration &
Automation
Platform
Platform
Platform
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
La Virtualisation sur les sites distants
Spécificités
Toutes les VNF sur le
même serveur
Management
7
Routeur 5 FW
1 4
Faible débit Virtual 6
latence SW-1
L2 VLANLAN SW
Pas de lien de
management dédié
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
La Virtualisation sur les sites distants
Spécificités
• Format du serveur (Encombrement,
bruit, durcissement…)
• Connectivité (LTE, DSL…?)
• Simplicité de déploiement (ZTP)
• Ouverture à de nombreuses VNF
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
La Virtualisation sur les sites distants
Spécificités
• Performance
• Management
• Intégration dans l’écosystème réseau
SF SF SF
Service Service Service
Function 1 Function 2 Function 3
SC SFF SFF
Service Service
Service
Function Function
Classifier Forwarder Forwarder
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Demo
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Conclusion
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Conclusion
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Merci !
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public