January 2022 Improving user access to applications and ease communication without compromise SD-WAN
Agenda 1 2 Why SD-WAN ICT Direction for Ministry of Defense
Private WAN Data Center Remote and Branch Office Remote and Branch Office Regional Hub and Campus Disaster Recovery Site IT Ops App. teams 2014 & Earlier Your IT used to look like this WWW
Private WAN Public Internet Data Center Remote and Branch Office Remote and Branch Office Mobile Regional Hub and Campus Disaster Recovery Site Carrier Neutral Facilities I aaS SaaS Global Ops 2016+ More and more it’s looking like this DoD Apps
Application delivery & communication is becoming complex Local Branch Applications SaaS t o Branch Applications Data Center t o Branch Applications Source: ESG 2015. ROBO TRENDS SURVEY Application diversity on a stretched perimeter The edge is becoming a hub of communication Faster user behavior changes Non-scalable change implementation based on legacy concepts Faster business driven changes The faster pace of changes drives IT operations to evolve
Network transformation Apps: Hosted in datacenter Users: Connected to corporate network to work Network: Centralized Security: On-premises security stack Apps: More hosted in the cloud Users: More work done off-network Network: De-centralized Security: Gaps in protection Internet VPN MPLS SaaS IaaS Private cloud Browsing Internet VPN MPLS Bottle neck Before What’s changed
Networking and Security teams struggle to… …connect users to applications and data Poor user experience when accessing cloud apps Complexity in connecting to multiple cloud providers Lack of end-to-end granular visibility of application performance …protect against evolving threat vectors Gaps in security protection Inconsistent policies enforced across disparate locations Difficult to verify identity of users and devices This requires a new approach to networking and security…
Drives the need for a secure access service edge (SASE) architecture Today’s cloud-centric world Combine networking and security functions in the cloud Connect users to the apps and data needed — in any environment, from anywhere Control access and enforce the right security protection consistently Headquarters/ campus Interne t/ Saa S/ IaaS Secure Access Service Edge Remote workers All locations
Factors why the traditional Network Can no longer sustain todays Communications Connect Users everywhere to a pplications anywhere Secure Secure user access & p rotect from threats Automate Insights that help deliver optimal experience
User Access is Shifting Transition to the new norm: a hybrid work environment 82% of workers will work in a hybrid model after 2020 Situation How to secure access from anywhere How to ensure optimal application experience from anywhere Impact
Cloud Access is Shifting Cloud migration for IT agility in delivering best experience 60% of organizations expect majority of apps to be SaaS 20 is the # public cloud services enterprises connect to on average Situation Gaps in visibility beyond the campus network boundaries Complexity in provisioning across multiple cloud providers in many ways Expanded attack surface Impact
Predictable app experience Multicloud Access To connect a hybrid workforce to apps anywhere SD-WAN for the new norm Right security, right place Always on, easily available Secure WAN Edge To secure access to apps and data from everywhere Analytics To deliver end-to-end visibility for actionable insights
Agenda 1 2 Why SD-WAN ICT Direction for Ministry of Defense
General notes about Platform slides: Title is taking focus – platform should be the focus; make it larger, it should take up about a quarter of the slide. It also looks more transparent now. If you need, you can put a white box behind it. For text in bottom table – vertically align text so that it is centered between lines. Make “TM” smaller after each word. Software-Defined WAN Approach “By the end of 2019, 30% of enterprises will use SD- WAN products in all their branches, up from less than 1% today .” 1 Gartner, Jul 2015 “Technology Overview for SD-WAN” “SD-WAN is a new and transformational way to architect, deploy and operate corporate WANs, as it provides a dramatically simplified way of deploying and managing remote branch office connectivity in a cost-effective manner. ” 1 Simplicity Reliability Agility Cost Business Performance 2 Gartner, Dec 2015 “Market Guide for Software-Defined WAN”
Flexible Connectivity Application-aware Routing with any Topology App Aware Routing Policy Latency ≤ 150ms Loss ≤ 2% Jitter ≤ 10ms Internet MPLS 4G LTE Manage SD-WAN Tunnel Remote Site Data Center Path 2 App A Path 1 Path 3 Traffic Engineering Policy Internet MPLS Manage Remote Site Data Center Augment MPLS with Internet bandwidth A B SD-WAN Tunnel Bandwidth Augmentation Critical Application SLA Bandwidth Augmentation
Internet MPLS Manage Remote Site Data Center App A (VPN1) VPN1 Parity VPN1 P1 P2 P3 P4 Parity Receiver Sender P1 P2 P3 P4 Parity P1 P2 P3 P4 Parity FEC guarantees voice/critical traffic across unreliable WAN links Reduces retransmissions and improves throughput Internet MPLS 4G LTE Manage Remote Site Data Center Path 2 Packets sent on preferred path and a secondary path is chosen to duplicate packets Packet duplication helps voice, video to work well over unreliable WAN links Path 1 Path 3 App A (VPN1) P1 P2 P3 P4 P5 P1 P2 P3 P4 P5 P1 P2 P3 P4 P5 Voice Optimization Improve reliability with FEC and Packet Duplication Forward Error Correction Packet Duplication
Typical SD-WAN Solutions Right Security, Right Place Direct Internet/Cloud Access Exposure to attacks from Internet/cloud Data breaches Guest access liability SD-WAN Fabric Branch Data Center Internet SaaS IaaS Internal Data Access Compliance (PCI, HIPPA, GDPR) Lateral movements Challenge of Balancing Security and User Experience Adding various point-solution securities (on-premise and/or cloud) will compromise security, application experience or performance. Cisco SD-WAN Security FW IPS URL AMP SIG Secure SD-WAN Fabric Branch Data Center Internet SaaS IaaS “No Compromise” Solution Single management console for networking and security with zero-trust fabric authentication and end-to-end segmentation that stop breach propagation. DNS CD FW SWG Threat Intelligence
The End Vision E2E Segmented Network Architecture SD-WAN Cloud Edge Data Center Internet Public Cloud SaaS Direct Internet Access SD Campus / Branch Users Devices 1 1 1 1 1 1 1 1 1 Deliver better digital experiences, anytime, anywhere
Why Cisco SD-WAN Right Security, Right Place Optimized for Multicloud Predictable Application Experience Resiliency with enterprise-grade scalable infrastructure foundation On-premises or cloud-based security with secure SD-WAN for a SASE-enabled architecture where and when it's needed Connect from anywhere * 17.6 Aug2021 Cloud OnRamp enables IaaS integrations, enhanced application experience with SaaS optimization, and cloud-agnostic branch connectivity ThousandEyes extends application visibility into the internet and cloud for actionable insights. Cisco SD-WAN
Business Value of Cisco SD-WAN Full IDC report available on www.cisco.com /go/ sdwan $14.98M increased revenue per organization Lower five-year cost of WAN operations Faster to implement policy/ configuration changes Less unplanned downtime 38% 58% 94%
What we deliver? Connect with Multicloud Extend visibility across the internet, cloud, and SaaS to pinpoint application issues and gain actionable insights Automate with Analytics/Insights Secure user and application access for on-premises or via cloud-delivered SASE enabled architecture Secure with SASE Deliver automated, optimized, multicloud access at scale with Cloud OnRamp for IaaS, SaaS, Colo and SDCI
Unified single subscription SASE offer Cisco SD-WAN Innovations & Execution - Delivered 20 # public cloud services e nterprises connect to on average Driving industry firsts 40% of SD-WAN deployments will improve SaaS performance 30% of medium/large enterprises will employ SDCI services 73% of organizations plan to optimize existing use of cloud 60% of organizations expect majority of apps to be SaaS 1 st to trifecta of cloud-integrations: AWS, Azure, Google 1 st to M365 optimizations: MS Network Informed Routing Cloud agnostic backbone with SDCI: Megaport (& Equinix) Cloud backbone: 1 st to integrate with Google Cloud NCC Internet and cloud actionable insights with ThousandEyes int. Webex optimization (Jan’22)
Cloud On-Ramp for SaaS Optimized Connectivity to SaaS Apps hosted in the Cloud SaaS SD-WAN Fabric Data Center Corporate Software Users Branch/Campus Optimal SaaS experience Optimal path selection through proactive link probing for supported SaaS Applications Local breakout Policy (DIA) from remote site Visibility on QoE metrics COR for SaaS
Cloud On-Ramp for Multi-cloud Automate SD-WAN extension to IaaS via vManage Cisco is the only market player to partner with top 3 cloud providers for end-to-end solution Cisco SD-WAN 5G MPLS Internet Greater automation Automate SD-WAN extension to the cloud with just a few clicks Normalized multicloud experience Consistent UI and workflow in vManage Unified security policies Extend consistent enterprise segmentation policy into the cloud Ease of management Orchestrate Cisco and cloud provider networking resources via vManage COR for IaaS
Only SD-WAN provider to support top 3 cloud service providers 3 Application optimization for 14 major SaaS applications 14 1st SD-WAN provider to provide SDCI underlay to customers Cisco SD-WAN Cloud On-Ramp ? Largest MSP provider 1 st to build joint solution, Cloud Hub, with Google Cloud “Cisco SD-WAN ‘Turbocharges’ Microsoft Office, Azure Environments” – CRN “Cisco, Megaport embrace multicloud with SD-WAN” – SDX Central Optimization with granular policy definition and informed network routing
The new enterprise reality Expanding to the cloud can limit the visibility and control of your IT organization
Empowering MoD IT Team for faster resolution Delivering Optimal User Experience Underlay Issue ISP Mitigation NetOps Application Issue ITOps /DevOps IT Evidence Escalation pinpoint Evidence Escalate accurately Evaluate persistently Correlated networked application performance. Define what good looks like End-to-End path insights Optimization opportunities in the service delivery chain Act based on empirical evidence. Expedited fault domain Identification
vAnalytics: Translate Real-time Data into Intelligent Insights Application performance Network KPIs Multi-layer insights Granular visibility Intuitive UI Visibility for branch, multicloud , and remote worker Visualized KPIs and historical trends Correlate application behavior ( QoE ) with the underlying network conditions for intelligent insights Robust, scalable, cloud-native architecture
Cisco SD-WAN Benefits and Differentiation Multicloud Security Analytics Cisco SD-WAN Connect Secure Automate True SD-WAN Architecture flexibility: Separate and dedicated components for the control plane, data plane, management and orchestration of the WAN designed for scalability and flexibility to implement overlay, underlay, physical, and virtual networks Multigigabit wireless performance : Enables >1Gbps for both 5G and WiFi networks with Cisco multigigabit technology for performance improvements Integrated Unified Communications: SD-WAN/ UC supported within a single platform to reduce both CapEx and OpEx costs Extensive Cloud OnRamp integrations: Enables seamless automated connectivity with any site-to-cloud and site-to-site configuration. Industry Firsts Offer cloud onramp to the top three cloud service providers and first to deliver integrations for Google Cloud Network Connectivity Center, Megaport Virtual Edge, Microsoft Virtual Hub NVA, and Microsoft 365 informed network routing. End-to-end visibility (Cisco ThousandEyes): Extends end-to-end visibility into network health and application performance F ull hop-by-hop analysis across the internet and cloud. I solates fault domains and provides actionable insights that drastically expedite troubleshooting and resolution, before they impact users. Micro-segmentation and identity-based policy management: Cisco TrustSec ® provides micro-segmentation and identity-based policy management for SDA and non-SDA branches Drives consistent multidomain policy enforcement. Cisco Catalyst 8K / Cisco SD-WAN portfolio has achieved MEF SD-WAN 3.0 Certification.
The Cisco advantage The Confidence The Experience The Cost Platform consolidation and efficiency Multitenancy Manage tenant resources Integrated Unified Communications Eliminate UC Platform Integrated 5G Cellular (PIM) Eliminate additional platform Security and certification Robust Security Integrated everywhere Talos protection TrustSec ® Comprehensive SASE architecture MEF 3.0 SD-WAN Certification Catalyst 8000 Edge Platform Family and SD-WAN Portfolio Customer satisfaction Extensive Cloud Integrations Extensive Google Cloud, MS Azure, AWS Integrations Extensive analytics, troubleshooting, operational simplification ThousandEyes Integration Co-management Cloud-based for cloud, hybrid, or on-prem deployments Multigigabit support Up to 3.3Gbps capability for 5G and WiFi
Built to enable multitude of use cases at the WAN Edge Edge Computing Edge compute and acceleration for low latency applications including IoT Software-Defined WAN Automate your entire network, from policies to multicloud access 5G Ready Connecting remote sites at speeds that go beyond broadband using 5G Secure Remote Access Cloud delivered security for securing direct internet access SASE Architecture Evolve your WAN architecture to a Secure Access Service Edge (SASE) Software-Defined Branch Consolidate branch services in a single edge platform
Cisco Remote Teleworker Use Case Advance application experience with comprehensive security using Cisco ISR1K End – End Enterprise Security & Segmentation Zero Trust Fabric & VPN Segmentation. Advance Threat Protection (IPS, URL Filtering, AMP) Cloud OnRamp & Security Cloud OnRamp with Advance DIA Cloud security with Umbrella Enhanced Application Optimization & Experience Application SLA and WAN Path Optimization IP Multicast capabilities for time sensitive data Fast Set Up and Simplified Management ZERO touch provisioning (No Staging) Centralized Proactive Monitoring and Troubleshooting High Availability & Investment Protection 5G ready for backhaul Integrated Wi-Fi Home Office Cisco Home Workforce Advance Solution Umbrella Centralized Orchestration SIG Umbrella IaaS SaaS Internet
Cisco SD-WAN Unified Communications Integration –Use Case Delivers Webex gateway and optimization All UC, Voice and App QoE features come with DNA Advantage License Reduced CapEx and OpEx costs by integrating into a single platform Provides integration of analog, digital, and IP telephony interfaces which drastically simplifies deployment of UC in remote and branch locations.
Enabling Secure, High Speed Wireless Connectivity Shipping Cellular Gateways Integrated Solutions ISR1K/ISR4K/C8K Network Modules 4G/Cat18 (PIM) 4G/Cat18 CAT 18 1.2 Gbps DL CAT 11 600 Mbps DL CAT 6 300 Mbps DL CAT 4 150 Mbps DL 5G Up to 4.4 Gbps DL 5G LTE LTE Advanced 4G LTE Advanced Pro Speed transitions shaping the cellular industry 5G/Sub-6 GA Mar FY22 5G/sub-6 (PIM) GA Aug FY21 Shipping 5G/ mmWave 1 st SD-WAN w/ multigigabit 5G!
Predictable Application Experience Cisco SD-WAN Benefits Pervasive Security Optimized for Cloud Visibility and Actionable Insights
SD-WAN 5 Year ROI Calculator www.cisco.com/c/en/us/solutions/enterprise-networks/sd-wan/roi-calculator.html