Thursday, August 30, 2018

Use Cases: Cisco’s 25G/100G Technology–Enabling Architectural Transformation

Upgrading the network from 10G to 25G is a straightforward migration option. Hence Cisco offers a gradual migration path with the support of dual-rate optics, where the same 25G optics can operate at both 10G and 25G speeds. With this approach, distribution layer devices can be upgraded to 25G while the access layer still operates at 10G, and the access layer switches can be upgraded over a period of time.

Use case 1: Speed transition with similar cable distances
As access bandwidth increases, campus backbones are transitioning from 10G and 40G speeds to 25G and 100G speeds, and customers are demanding newer optics to support a cabling distance similar to that of existing optics. Cisco’s innovative SFP-10/25G-CSR-S modules support traditional link lengths of up to 300 or 400 m over OM3/OM4 (depending on the fiber quality), now at 25G speeds (Figure 5).
Figure5. Speed transition with similar cable distances


Use case2: Speed migration with dual-rate optics
25G switches and optics provide 2.5 times more bandwidth and are not significantly more expensive than 10G Ethernet solutions. Cisco’s 25G portfolio provides full backward compatibility with 10G with dual-rate optics. These optics will automatically negotiate with the far-end device to the highest speed supported. For example, if the far-end device is capable only of 10 Gbps, the two devices would settle at 10 Gbps speed, meaning that you don’t need to upgrade your infrastructure to 25G right away. Instead you can upgrade the network as part of regular refresh cycles and still have it ready for 25G capabilities (Figure 6).
Figure6. Speed migration with dual-rate optics


Use case3: Speed transition with similar oversubscription ratios
Oversubscription in enterprise campus networks isn’t new. For a long time, the rule of thumb for oversubscription was about 20:1 for access ports and 4:1 for distribution to core. However, these numbers do not really hold up in modern network design. Hence, to retain the recommended oversubscription ratio there is a need to upgrade the uplinks (switch to switch). As natural successors to 10G and 40G technologies, 25G and 100G will help retain the same oversubscription ratios (Figure7).
Figure7. Speed transition with similar oversubscription ratio


Use case4: Access speed transition to 5G
The next generation of Wi-Fi is driving the need for higher speeds, including 2.5G, 5GBASE-T, and 10GBASE-T, in the campus. Most larger enterprise campus networks implement multitier architecture, and these are generally oversubscribed. Network expansions at access or edge have always demanded refreshing the campus core switching capacity. IT needs to reevaluate two major bottleneck points in campus networks, those being the distribution layer that aggregates 10G physical connections and the core switching capacity to maintain 4:1 oversubscription ratios. While mitigating campus core scale and performance challenges and protecting oversubscription ratios, the Cisco Catalyst 9500 Series Switches allow easy and seamless upgrade from existing 10G- or 40G-based infrastructure to 40G- or 100G-based infrastructure (Figure 8).
Figure8. Access speed transition to 5G


Use case5: Load sharing vs. higher speeds
Speed upgrades have outpaced the refresh cycles for cabling, and until now there were two options: (1) rip and replace your existing cabling to support higher speeds, or (2) add additional links to satisfy bandwidth requirements. Neither of these options is ideal. There are significant cost implications, and adding additional uplinks compounds the challenges of achieving effective load sharing that depends on the hashing technologies supported by switches. Moving to faster Ethernet technologies can overcome those concerns as well as add more bandwidth.
Figure9. Load sharing vs. higher speed topologies



More Related

Thursday, June 21, 2018

Help Wireless Customers Select the Right Cisco Wireless Solutions

Today we believe that every company relies on wireless technology to operate its business. So to meet customers’ diverse needs, particularly for small and medium-sized businesses, Cisco can provide a broad portfolio of wireless solutions.

How to help wireless customers select the right wireless solutions? In the following part there are three approaches for a range of customers.

Three Approaches for a Range of Customers
It is easier when you offer appliance-free, appliance-based, and cloud-based solutions.

On Premises and Appliance-Free











With these solutions, the access points handle the wireless management. So no additional hardware is necessary. They are easy to use, affordable, and work well in environments with up to 25 access points.

Off Premise and Cloud Based


These Cisco® Meraki® cloud-managed solutions are ideal for deployments with access points in multiple remote locations. They are highly scalable, are license based, and require little or no IT staff on site.

On Premises and Appliance-Based













When a company needs 25 to 250 access points in one location, these are the solutions to sell. Network administrators manage the numerous access points with a centralized, wireless LAN controller.

Three Common Network Models
Most customers have small wireless networks, distributed branch locations, or large campuses.
Small Business Local Networks
These customers generally have one location with 25 access points or fewer. They need wireless solutions that are easy to install, easier to manage, and completely reliable. And they want competitive features and performance for an affordable price.
Branch Office Networks
This category of customers requires 25 or more access points in distributed locations. They want wireless solutions that can be licensed, secured, and managed by remote staff, and that will scale up or down quickly to meet changing demand.
Central Campus Networks
This enterprise customer group uses up to 250 access points in a centralized complex. They need broader services, premium performance, bulletproof security, greater network traffic visibility, and simple, centralized control of the many access points.


Cisco Wireless Solutions

Small Campus or Branch (Number of Access Points)
Large Campus (Number of Access Points)
Deployment Model
Cisco Product
Portfolio
1 to 10
Access Points
1 to 25
Access Points
25 to 50
Access Points
50 to 500 Access
Points
500 to 1000 Access
Points
More Than 1000
Access Points
Off-premises
Cisco Meraki cloudbased portfolio
Cisco Meraki MR18
Cisco Meraki MR32
and MR34
MR32 and MR34
MR32 and MR34
MR32 and MR34
MR32 and MR34
On-premises
Purpose-built, non
Cisco IOS® Software
Cisco WAP131 and WAP551/WAP561
Access Points
Cisco WAP371
Access Point
On-premises
• Classic Cisco IOS Software solutions
• Cisco Mobility
Express Applianceless
Controller,
• Cisco Aironet®
1850/1830 Series
Access Points
• Cisco Mobility
Express
Applianceless
Controller,
• 1850/1830 Series
Access Points
Switches
• 1850/1830 Series
Access Points
3700/2700/1700
Series Access Points
• Cisco 5520 Series
Wireless Controller
• Cisco 5760 Wireless
LAN Controller, Cisco
Catalyst 4500-E
Supervisor Engine
• 1850/1830 Series
Access Points
• 3700/2700/1700
Series Access Points
Controller, Cisco
Wireless Services
Module 2
• 5760 wireless LAN
Controller, 4500-E
Supervisor
• 1850/1830 Series
Access Points
• 3700/2700/1700
Series Access Points
• 5760 wireless
LAN Controller,
4500-
E-supervisor
1850/1830
Series Access Points
• 3700/2700/1700
Series Access Points
A Solution for Every Situation
Whether your customer maintains a small office, several branches, or a bustling campus, Cisco has just the right wireless solution. Cisco’s appliance-free, appliance-based, and Cisco Meraki cloud-based offerings help you present more solutions to more customers than ever before. Refer to the table above for specific examples.

More Related

Friday, April 27, 2018

Cisco ASA with FirePower Services vs. FTD

More questions about the Cisco ASA with firepower services and FTD:

“What’s the difference between traditional Cisco ASA with firepower and new Cisco Firepower threat defense?”
“Why customer will go for Firepower threat defense, if they already have Cisco ASA with firepower services.”
“What are the benefits of FTD and additional features in FTD?”
“What are the key benefits of Cisco Firepower appliances (4100, 9300) and what are the limitations of Firepower Appliances?”

All the questions above have one point: What are the difference between FTD and Firepower appliance? 

In which scenarios they use and other use cases? 

FTD combines both ASA and firepower code into a single image. At the moment FTD has not reached feature parity with ASA features (no remote-access vpn, no multiple-context mode, no clustering, etc.) but it will be the way forward.

One of the benefits is that you won’t need to configure two separate instances (ASA & Firepower), but have a unified security policy that is managed either with Firepower Device Manager for small to mid-range deployments (ASA 5506-X-5525-X) or using the central management with Firepower Management Center.

The Firepower appliances (4100, 9300) are the new NGFW hardware platform that can run either ASA (without firepower services) or FTD software. They are basically the evolution of the asa hardware platform that support higher throughput.

You may want to go down the FTD road if do not require the features not yet implemented from ASA as stated above. In about two years it should be the defacto standard.

Feature Comparison (Q4, 2016):
FTD is an integrated image which combines all of the FirePOWER Services features with many (but not all) ASA firewall services.

If a customer is already running ASA with FirePOWER services, they may want to migrate in the long term to simplify management and operations. Short term, there are few compelling reasons.
Right now there are very few FTD features that are not available with a combination of ASA and FirePOWER services. Longer term, more development resources on the FTD side may change that equation.

The 4100 and 9300 series are a whole new hardware platform for security appliances based on the UCS hardware. They offer much higher performance for a very attractive price when compared to the ASA platforms.

FTD runs on either the new 4100 and 9300 series or the ASA appliances (except 5585-X). FirePOWER appliances run only the legacy FirePOWER image and will not run FTD image.

What is Cisco Firepower Threat Defense (FTD)?

Cisco Firepower Threat Defense (FTD) is a unified software image, which includes the Cisco ASA features and FirePOWER Services. This unified software is capable of offering the function of ASA and FirePOWER in one platform, both in terms of hardware and software features. This seems to be a good approach taken by Cisco especially when most of the Next Generation Firewall Vendors are offering Next Generation Solutions on a single platform with unified image. Currently the Cisco Firepower Threat Defense (FTD) unified software image is available in the following releases
  • 6.0
  • 6.2
The Cisco Firepower Threat Defense (FTD) is capable of offering following Next-Generation Firewall Services
  • Stateful firewall Capabilities
  • Static and dynamic routing
    • Supports RIP, OSPF, BGP, Static Routing
  • Next-Generation Intrusion Prevention Systems (NGIPS)
  • URL Filtering
  • Application visibility and control (AVC)
  • Advance Malware Protection
  • ISE Integration
  • SSL Decryption
  • Captive Portal
  • Multi-Domain Management
Currently Cisco Firepower Threat Defense (FTD) unified software can be deployed on Cisco Firepower 4100 Series and the Firepower 9300 appliances as well the FTD can be also be deployed on Cisco Firepower Threat Defense (FTD) ASA 5506-X, ASA 5506H-X, ASA 5506W-X, ASA5508-XASA 5512-X, ASA 5515-X, ASA 5516-X, ASA 5525-X, ASA 5545-X, and ASA 5555-X. However, the Cisco Firepower Threat Defense (FTD) unified software cannot be deployed on Cisco ASA 5505 and 5585-X Series appliances.

Some of the key features which Currently Cisco Firepower Threat Defense (FTD) lacks are as follows:
  • VPN Function
  • Multi Context mode
  • EIGRP and Multicast
  • Does not support Cisco ASA 5505 & 5585-X Appliances
The lack of VPN function is a major drawback which Cisco needs to overcome in upcoming release of Cisco Firepower Threat Defense image. This certainly discourages the enterprise customers to adopt the Cisco Firepower Threat Defense unified image on their supported ASA 5500- Series platforms.

More Related