SlideShare a Scribd company logo
Policy-based Infrastructure Provisioning for Recover
Point with Cisco ACI
Carly Stoughton – Cisco Technical Marketing Engineer
Thomas Scheibe – Cisco Senior Director Product Management
§ Group-Based Policy Concept in Cisco ACI
§ Integration of RecoverPoint for VMs and Cisco ACI
§ ACI Security/ Compliance Properties
Agenda
Enable the Cloud
2009 20142008
Consolidation Virtualization Automation
Enabling
the Cloud
LAN SAN
Network
Compute
Storage
Access
Network
Apps Policy
Today
Policy
PolicyCisco ACI
RAPID APPLICATION EVOLUTION
Policy
Vision: Scale, Security and Full Visibility
Physical
Networking
Compute L4–L7
Services
StorageHypervisors
and Virtual
Networking
Multi DC
WAN and Cloud
Enabled by physical and virtual integration
Tenant Application
2
0
Automation through Policy
Physical, Virtual and Containers
Open, Standards and Embedded Security
The Problem
DBAPP
ADC
WEBF/W
ADC
MGMT
Data Applications
Infrastructure
Applications
Management
Applications
Challenges attempting to automate network configurations
•  Provisioning models are built around the device
•  Build separate networks for the apps for policy, visibility, and security
•  Legacy network security limits our ability to implement policy with mobility & cloud
VMOTION
DNS
Group Based Policy Model
Define Once – Deploy Consistently
COMPONENTS OF A
Group Based Policy
Endpoint Group:
A set of endpoints (VMs/
servers) with
the same policy
Contracts:
A set of rules governing
communication between
endpoint groups
Service Chains:
A set of network services
between endpoint groups
OUTSIDE
WEBAPPDBCRM
APP
ADC
F/W
ADC
ContractContract
Context-Aware Segmentation
Dynamic Content
User and Devices
Resources and Demands
Marking Traffic with Consistent Policy Context
(Device, Group, Role) Immune to Network Changes
Abstracted Policy
Business Policy
X
Distributed Enforcement
End Point Group TagTAG
Contract Contract Contract
DBAPPWEB
ADC
F/W
ADC
Group Policy
OVS Driver
Neutron Networking
APIC Group Driver
W
eb
W
eb
W
eb
W
eb
Ap
p
Ap
p
D
B
D
B
HYPERVISOR HYPERVISOR HYPERVISOR
OpenStack extensions on top of Neutron exposing a policy API
Group-Based Policy And OpenStack
Group Policy Plugin
§ Group-Based Policy Concept in Cisco ACI
§ Integration of RecoverPoint for VMs and Cisco ACI
§ ACI Security/ Compliance Properties
Agenda
§  Automate network policies – define once/ deploy consistently
§  Pre-configure four network instances on the VMware vSphere ESXi Servers
where RecoverPoint for VMs will be installed
–  LAN Network
–  WAN Network
–  iSCSI1 & iSCSI2 Network
§  Associate the four RecoverPoint for VMs network interfaces (i.e., LAN
Interface, WAN Interface, iSCSI1 Interface and iSCSI2 Interface) to the pre-
configured network instances
RecoverPoint for VMs & ACI - Objective
§  VMware ESXi has been installed on the servers that will be used for
RecoverPoint for VMs and that all servers have been assigned an IP Address
§  The “VM Network” shown in the logical topology has been created.
§  VMware vCenter server has been installed and all servers (single or multiple
vCenter instances are possible)
§  Cisco ACI has been physically installed and all leaf switches have been
initialized and are visible in the APIC Fabric Topology view.
§  Servers running VMware ESXi have been physically cabled to the Cisco ACI
leaf switches as shown in the physical topology diagram.
Assumptions
Logical Topology View
Physical Topology View
1. ACI Configuration
§  a. Configure Fabric
§  b. Add VMware vCenter to APIC
§  c. Verify connectivity
2. VMware vCenter Configuration
§  a. Configure the Distributed vSwitch in vcenter
3. Tenant (RP4VM network) Configuration
§  a. Create the RP4VM Networks via APIC
§  b. Modify iSCSI Port Groups to allow iSCSI via VMware vCenter
§  c. Configure vmknics and attach to iSCSI Port Groups via VMware vCenter
§  d. Install RP4VM Appliance via VMware vCenter
Overview of Configuration Steps
§ Group-Based Policy Concept in Cisco ACI
§ Integration of RecoverPoint for VMs and Cisco ACI
§ ACI Security/ Compliance Properties
Agenda
Security: P+V = C
VIRTUALIZATION
CENTRIC
No Physical
Support
Limited
Visibility
Management
Complexity
APPLICATION CENTRIC Any workload and any place Full VisibilityAutomated
PERIMETER CENTRIC Manual and
Complex
Error-ProneStatic
Topology
Limited
Places
+
=
PCI Compliant Network with Cisco ACI
•  Simplifies audit based on higher level
policy
•  Secure network segmentation and
isolation
•  Defense in depth with advanced L4-7
security (NGFW, IDS/IPS, DDoS)
integration
•  Centralized Auditing and Security
Monitoring
SECURE
NETWORK
ACCESS
CONTROL
SECURITY
POLICY
CENTRALIZED
AUDIT
MONITORING
ACCESS
Cisco ACI Main Session EMC World 2015
A C I- R E A D Y
VBLOCK SYSTEMS
WITH ACI-READY
NEXUS 9000
• Policy management enhances
operational simplicity
• Use policies to accelerate
network configuration
• ACI further reduces risk
through policy automation
Vblock Systems with ACI
Further extend IT agility Vblock™ 340 and Vblock™ 720
Converged Infrastructure

More Related Content

PPTX
OpenStack at Cisco, June 2015
PDF
Cisco and F5 accelerate Application Delivery
PDF
【Cisco OpenStack Seminar 2015.10.26】 OpenStack as Strategy for future growth
PDF
Tokyo meetup 20160224
PDF
Cisco Connect 2018 Vietnam - hyper flex
PPTX
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
PDF
【Cisco OpenStack Seminar 2015.10.26】 Cisco UCS Integrated Infrastructure - En...
PDF
Infrastructure as Code 101: Steve Tegeler + Nathan Ness, VMware
OpenStack at Cisco, June 2015
Cisco and F5 accelerate Application Delivery
【Cisco OpenStack Seminar 2015.10.26】 OpenStack as Strategy for future growth
Tokyo meetup 20160224
Cisco Connect 2018 Vietnam - hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
【Cisco OpenStack Seminar 2015.10.26】 Cisco UCS Integrated Infrastructure - En...
Infrastructure as Code 101: Steve Tegeler + Nathan Ness, VMware

What's hot (20)

DOCX
Cisco one advanced security
PPTX
You Can Build Your OpenStack and Consume it Too
PPTX
Cisco Application Centric Infrastructure
PDF
UCS Automation through the use of API's and UCS PowerTool
PDF
APPLICATION CENTRIC INFRASTRUCTURE
PDF
Seven Criteria for Building an AWS Global Transit Network
PDF
OpenStack and Application Delivery: Joy and Pain of an Intricate Relationship
PPTX
How to Quickly Implement a Secure Cloud for Government and Military | Webinar
PDF
Cisco Connect 2018 Malaysia - Next-generation hyperconverged infrastructure-s...
PDF
Successfully Interconnecting Data Centers
PDF
The Changing Data Center Landscape
DOCX
Cisco ucs s3260 the new storage building blocks
PPT
Calico and simple policy
PPTX
Implementing the Hybrid Data Center
PPT
Calico and ubuntu
PPTX
Prevent threats With Analytics Driven Web Application Firewall
PDF
IPv6 on the Cisco Campus
PDF
Introduction to MANTL Data Platform
PDF
OpenStack-Ansible Security
Cisco one advanced security
You Can Build Your OpenStack and Consume it Too
Cisco Application Centric Infrastructure
UCS Automation through the use of API's and UCS PowerTool
APPLICATION CENTRIC INFRASTRUCTURE
Seven Criteria for Building an AWS Global Transit Network
OpenStack and Application Delivery: Joy and Pain of an Intricate Relationship
How to Quickly Implement a Secure Cloud for Government and Military | Webinar
Cisco Connect 2018 Malaysia - Next-generation hyperconverged infrastructure-s...
Successfully Interconnecting Data Centers
The Changing Data Center Landscape
Cisco ucs s3260 the new storage building blocks
Calico and simple policy
Implementing the Hybrid Data Center
Calico and ubuntu
Prevent threats With Analytics Driven Web Application Firewall
IPv6 on the Cisco Campus
Introduction to MANTL Data Platform
OpenStack-Ansible Security
Ad

Similar to Cisco ACI Main Session EMC World 2015 (20)

PDF
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
PDF
Cisco at v mworld 2015 cs integrated infrastructure_vmworld_cisco_v1
PPTX
Cisco ACI version 6.0.4F Release BDM Deck.PPTX
PDF
Build 4 The Cloud By Cisco&VMware1
PPTX
Self service it with v realizeautomation and nsx
PDF
VMworld 2013: NSX PCI Reference Architecture Workshop Session 3 - Operational...
PPTX
OpenStack As A Strategy For Future Growth at Cisco
PDF
cisco-aci-virtualization-guide-52x
PDF
Simplifier le deploiement d'applications dans le nuage hybride
PDF
VMware goes container crazy with vSphere integrated containers
PDF
DevNetCreate - ACI and Kubernetes Integration
PDF
PROACT SYNC 2013 - Breakout - Cisco UCS Director Live Demo
PPTX
VMworld 2015: What's New in vSphere?
PDF
4. Kubernetes - Application centric infrastructure kubernetes, contiv
PDF
Converge ou Hyperconverge? Cisco HyperFlex
PDF
Cisco UCS Solution EMC World 2015
PPTX
Presentation cisco ucs director
PDF
VMware and AWS Together - VMware Cloud on AWS
PDF
PLNOG15: Cisco Application Centric Infrastructure - why ...? - Krzysztof Mazepa
PDF
Set_up_Kubernetes_clusters_on_premises_&_on_AWS_with_Cisco_Container_Platform...
VMworld 2014: VMware NSX and vCloud Automation Center Integration Technical D...
Cisco at v mworld 2015 cs integrated infrastructure_vmworld_cisco_v1
Cisco ACI version 6.0.4F Release BDM Deck.PPTX
Build 4 The Cloud By Cisco&VMware1
Self service it with v realizeautomation and nsx
VMworld 2013: NSX PCI Reference Architecture Workshop Session 3 - Operational...
OpenStack As A Strategy For Future Growth at Cisco
cisco-aci-virtualization-guide-52x
Simplifier le deploiement d'applications dans le nuage hybride
VMware goes container crazy with vSphere integrated containers
DevNetCreate - ACI and Kubernetes Integration
PROACT SYNC 2013 - Breakout - Cisco UCS Director Live Demo
VMworld 2015: What's New in vSphere?
4. Kubernetes - Application centric infrastructure kubernetes, contiv
Converge ou Hyperconverge? Cisco HyperFlex
Cisco UCS Solution EMC World 2015
Presentation cisco ucs director
VMware and AWS Together - VMware Cloud on AWS
PLNOG15: Cisco Application Centric Infrastructure - why ...? - Krzysztof Mazepa
Set_up_Kubernetes_clusters_on_premises_&_on_AWS_with_Cisco_Container_Platform...
Ad

More from ldangelo0772 (20)

PDF
Cisco at VMworld 2015 - Cisco UCS as the Foundation for Software-Defined Data...
PDF
Cisco at v mworld 2015 vmworld sf 2015 brannon theater 20150829
PDF
Cisco at v mworld 2015 ravi_vmworldtheater2015
PDF
Cisco at v mworld 2015 gpu-solution-c240_m4-082715-vmworld
PDF
Cisco at v mworld 2015 theater presentation brfarnha
PDF
Cisco at v mword 2015
PDF
Cisco at v mworld 2015 joann_starke_let_your_business_soar
PDF
Cisco at v mworld 2015 vmworld_sf-2015-hyperconverged
PDF
Cisco at v mworld 2015 gpu-solution-c240_m4-082715-vmworld
PDF
Cisco at v mworld 2015 vmworld-deck-2015-final
PDF
Cisco at v mworld 2015 vmworld 2015 mds final preso
PDF
Cisco at v mworld 2015 vmworld - cisco mds and emc xtrem_io-v2
PDF
Cisco at v mworld 2015 versastack-customer_vmworld_20150826v3
PDF
Cisco at v mworld 2015 shipped-vmworld
PDF
Cisco at v mworld 2015 intercloud - hybrid cloud solutions for vmware workloa...
PDF
Cisco at v mworld 2015 cisco-on-demand-private-cloud-for-vmworld-01_sep2015-a...
PDF
Cisco at v mworld 2015 cisco powered_vmworld 2015
PDF
Cisco at vmworld 2015 joann_starke_let_your_business_soar
PDF
Cisco MDS Main Session EMC World 2015
PPTX
Itpa sessions
Cisco at VMworld 2015 - Cisco UCS as the Foundation for Software-Defined Data...
Cisco at v mworld 2015 vmworld sf 2015 brannon theater 20150829
Cisco at v mworld 2015 ravi_vmworldtheater2015
Cisco at v mworld 2015 gpu-solution-c240_m4-082715-vmworld
Cisco at v mworld 2015 theater presentation brfarnha
Cisco at v mword 2015
Cisco at v mworld 2015 joann_starke_let_your_business_soar
Cisco at v mworld 2015 vmworld_sf-2015-hyperconverged
Cisco at v mworld 2015 gpu-solution-c240_m4-082715-vmworld
Cisco at v mworld 2015 vmworld-deck-2015-final
Cisco at v mworld 2015 vmworld 2015 mds final preso
Cisco at v mworld 2015 vmworld - cisco mds and emc xtrem_io-v2
Cisco at v mworld 2015 versastack-customer_vmworld_20150826v3
Cisco at v mworld 2015 shipped-vmworld
Cisco at v mworld 2015 intercloud - hybrid cloud solutions for vmware workloa...
Cisco at v mworld 2015 cisco-on-demand-private-cloud-for-vmworld-01_sep2015-a...
Cisco at v mworld 2015 cisco powered_vmworld 2015
Cisco at vmworld 2015 joann_starke_let_your_business_soar
Cisco MDS Main Session EMC World 2015
Itpa sessions

Recently uploaded (20)

PDF
Hybrid model detection and classification of lung cancer
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
Mushroom cultivation and it's methods.pdf
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
Approach and Philosophy of On baking technology
PDF
project resource management chapter-09.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PPTX
A Presentation on Touch Screen Technology
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Getting Started with Data Integration: FME Form 101
PPTX
A Presentation on Artificial Intelligence
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Hybrid model detection and classification of lung cancer
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Assigned Numbers - 2025 - Bluetooth® Document
cloud_computing_Infrastucture_as_cloud_p
1 - Historical Antecedents, Social Consideration.pdf
Mushroom cultivation and it's methods.pdf
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
DP Operators-handbook-extract for the Mautical Institute
Encapsulation_ Review paper, used for researhc scholars
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Approach and Philosophy of On baking technology
project resource management chapter-09.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Programs and apps: productivity, graphics, security and other tools
A Presentation on Touch Screen Technology
A comparative study of natural language inference in Swahili using monolingua...
Getting Started with Data Integration: FME Form 101
A Presentation on Artificial Intelligence
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf

Cisco ACI Main Session EMC World 2015

  • 1. Policy-based Infrastructure Provisioning for Recover Point with Cisco ACI Carly Stoughton – Cisco Technical Marketing Engineer Thomas Scheibe – Cisco Senior Director Product Management
  • 2. § Group-Based Policy Concept in Cisco ACI § Integration of RecoverPoint for VMs and Cisco ACI § ACI Security/ Compliance Properties Agenda
  • 3. Enable the Cloud 2009 20142008 Consolidation Virtualization Automation Enabling the Cloud LAN SAN Network Compute Storage Access Network Apps Policy Today Policy PolicyCisco ACI RAPID APPLICATION EVOLUTION Policy
  • 4. Vision: Scale, Security and Full Visibility Physical Networking Compute L4–L7 Services StorageHypervisors and Virtual Networking Multi DC WAN and Cloud Enabled by physical and virtual integration Tenant Application 2 0
  • 5. Automation through Policy Physical, Virtual and Containers Open, Standards and Embedded Security
  • 6. The Problem DBAPP ADC WEBF/W ADC MGMT Data Applications Infrastructure Applications Management Applications Challenges attempting to automate network configurations •  Provisioning models are built around the device •  Build separate networks for the apps for policy, visibility, and security •  Legacy network security limits our ability to implement policy with mobility & cloud VMOTION DNS
  • 7. Group Based Policy Model Define Once – Deploy Consistently COMPONENTS OF A Group Based Policy Endpoint Group: A set of endpoints (VMs/ servers) with the same policy Contracts: A set of rules governing communication between endpoint groups Service Chains: A set of network services between endpoint groups OUTSIDE WEBAPPDBCRM APP ADC F/W ADC ContractContract
  • 8. Context-Aware Segmentation Dynamic Content User and Devices Resources and Demands Marking Traffic with Consistent Policy Context (Device, Group, Role) Immune to Network Changes Abstracted Policy Business Policy X Distributed Enforcement End Point Group TagTAG
  • 9. Contract Contract Contract DBAPPWEB ADC F/W ADC Group Policy OVS Driver Neutron Networking APIC Group Driver W eb W eb W eb W eb Ap p Ap p D B D B HYPERVISOR HYPERVISOR HYPERVISOR OpenStack extensions on top of Neutron exposing a policy API Group-Based Policy And OpenStack Group Policy Plugin
  • 10. § Group-Based Policy Concept in Cisco ACI § Integration of RecoverPoint for VMs and Cisco ACI § ACI Security/ Compliance Properties Agenda
  • 11. §  Automate network policies – define once/ deploy consistently §  Pre-configure four network instances on the VMware vSphere ESXi Servers where RecoverPoint for VMs will be installed –  LAN Network –  WAN Network –  iSCSI1 & iSCSI2 Network §  Associate the four RecoverPoint for VMs network interfaces (i.e., LAN Interface, WAN Interface, iSCSI1 Interface and iSCSI2 Interface) to the pre- configured network instances RecoverPoint for VMs & ACI - Objective
  • 12. §  VMware ESXi has been installed on the servers that will be used for RecoverPoint for VMs and that all servers have been assigned an IP Address §  The “VM Network” shown in the logical topology has been created. §  VMware vCenter server has been installed and all servers (single or multiple vCenter instances are possible) §  Cisco ACI has been physically installed and all leaf switches have been initialized and are visible in the APIC Fabric Topology view. §  Servers running VMware ESXi have been physically cabled to the Cisco ACI leaf switches as shown in the physical topology diagram. Assumptions
  • 15. 1. ACI Configuration §  a. Configure Fabric §  b. Add VMware vCenter to APIC §  c. Verify connectivity 2. VMware vCenter Configuration §  a. Configure the Distributed vSwitch in vcenter 3. Tenant (RP4VM network) Configuration §  a. Create the RP4VM Networks via APIC §  b. Modify iSCSI Port Groups to allow iSCSI via VMware vCenter §  c. Configure vmknics and attach to iSCSI Port Groups via VMware vCenter §  d. Install RP4VM Appliance via VMware vCenter Overview of Configuration Steps
  • 16. § Group-Based Policy Concept in Cisco ACI § Integration of RecoverPoint for VMs and Cisco ACI § ACI Security/ Compliance Properties Agenda
  • 17. Security: P+V = C VIRTUALIZATION CENTRIC No Physical Support Limited Visibility Management Complexity APPLICATION CENTRIC Any workload and any place Full VisibilityAutomated PERIMETER CENTRIC Manual and Complex Error-ProneStatic Topology Limited Places + =
  • 18. PCI Compliant Network with Cisco ACI •  Simplifies audit based on higher level policy •  Secure network segmentation and isolation •  Defense in depth with advanced L4-7 security (NGFW, IDS/IPS, DDoS) integration •  Centralized Auditing and Security Monitoring SECURE NETWORK ACCESS CONTROL SECURITY POLICY CENTRALIZED AUDIT MONITORING ACCESS
  • 20. A C I- R E A D Y VBLOCK SYSTEMS WITH ACI-READY NEXUS 9000 • Policy management enhances operational simplicity • Use policies to accelerate network configuration • ACI further reduces risk through policy automation Vblock Systems with ACI Further extend IT agility Vblock™ 340 and Vblock™ 720 Converged Infrastructure