180 likes | 387 Views
Enabling the Intelligent Information Network. Chris Coleman Mission Architect, National Programs. Today’s Agenda. Value of the Intelligent Information Network Service Oriented Network Architecture Intelligent Service Delivery Q&A. Business Processes. Networked Infrastructure.
E N D
Enabling the Intelligent Information Network Chris Coleman Mission Architect, National Programs
Today’s Agenda • Value of the Intelligent Information Network • Service Oriented Network Architecture • Intelligent Service Delivery • Q&A
Business Processes Networked Infrastructure • Active participation in application and service delivery • A systems approach integrates technology layers to reduce complexity • Flexible policy controls adapt this intelligent system to dynamically and rapidly accommodate change Resilient Integrated Adaptive Applications and Services The Network as the Platform Network Intelligencerequires:
Service Oriented Networking Architecture (SONA) Instant Messaging Unified Messaging Meeting Place IPICS IP Phone IPTV Voice Services Computer Services Identity Services Headquarters Remote Office Data Center MAN / WAN Mobile User Server Storage Devices Mission Services Collaboration Services Data Mining CaseManagement GeoSpatial Analysis Application Layer Message Traffic Watch List Application-Enhancing Services Collaboration-Enhancing Services Interactive Services Layer Adaptive Policy Security Services Infrastructure- Enhancing Services Mobility Services Storage Services Network Virtualization Services Networked Infrastructure Layer Places in the Network
Instant Messaging Unified Messaging Meeting Place Mission Services Collaboration Services Data Mining CaseManagement GeoSpatial Analysis Application Layer IPCC IP Phone IPTV Message Traffic Watch List Application-Enhancing Services Collaboration-Enhancing Services Voice Services Interactive Services Layer Adaptive Policy Security Services Infrastructure- Enhancing Services Computer Services Mobility Services Identity Services Storage Services Headquarters Headquarters Remote Office Remote Office Data Center Data Center MAN / WAN MAN / WAN Mobile User Mobile User Network Virtualization Services Network Virtualization Services Networked Infrastructure Layer Networked Infrastructure Layer Server Server Storage Storage Devices Devices Networked Infrastructure Layer Fabric of the Enterprise End-to-End Transport Dynamic platform IP-everywhere
Instant Messaging Unified Messaging Meeting Place Mission Services Collaboration Services Data Mining CaseManagement GeoSpatial Analysis Application Layer IPCC IP Phone IPTV Message Traffic Watch List Application-Enhancing Services Collaboration-Enhancing Services Voice Services Interactive Services Layer Adaptive Policy Security Services Infrastructure- Enhancing Services Computer Services Mobility Services Identity Services Storage Services Headquarters Remote Office Data Center MAN / WAN Mobile User Network Virtualization Services Networked Infrastructure Layer Places in the Network Server Storage Devices Interactive Services Layer Policy-driven Demand-driven Transformation Intelligent
Instant Messaging Instant Messaging Unified Messaging Unified Messaging Meeting Place Meeting Place Mission Services Collaboration Services Data Mining CaseManagement GeoSpatial Analysis Application Layer Data Mining CaseManagement GeoSpatial Analysis IPCC IPICS IP Phone IP Phone IPTV IPTV Message Traffic Watch List Application Layer Message Traffic Watch List Application-Enhancing Services Collaboration-Enhancing Services Voice Services Interactive Services Layer Adaptive Policy Security Services Infrastructure- Enhancing Services Computer Services Mobility Services Identity Services Storage Services Headquarters Remote Office Data Center MAN / WAN Mobile User Network Virtualization Services Networked Infrastructure Layer Places in the Network Server Storage Devices Application Layer Enhanced Delivery Network-enabled Highly Available Interactive
Intelligent Service Delivery Network Virtualization
New IP Apps New IP Apps MPLS Routers Facility 1 Facility 1 ATM CES Service Site A MPLS Router IP KG IP KG IP KG IP KG IP KG IP KG Load Balancers SSL Offload DB Servers Firewalls Storage Security Mgmt Network Mgmt etc.. Load Balancers SSL Offload DB Servers Firewalls Storage Security Mgmt Network Mgmt etc.. ATM UNI VRF X VRF Y VRF Z VRFS ATM Core KG KG KG KG ATM KG ATM KG IPKG IPKG IPKG IPKG Service Provider A Service Provider A VRF X VRF Y VRF Z MPLS Router ATM Switch IP Core Router IP KG MPLS Router Optical Transport ATM CES Service Service Provider B Service Provider B MPLS Router x1 IP KG ATM UNI x3 IP Core Router IP KG IP KG VRF X VRF Y VRF Z ATM Switch MPLS Router Facility 2 Facility 2 Primary Data Center } like Classification (PL3) Formal Access Req Primary Data Center Compartment X Compartment Y Compartment Z Headquarters Remote Office VLAN, Multi VRF, MPLS, GRE, L2TPv3, DMVPN, etc… Data Center MAN / WAN Mobile User Network Virtualization Services Networked Infrastructure Layer Server Storage Devices Network Virtualization Services
Intelligent Service Delivery Security
MPLS Routers Facility 1 IOS Adv. Security Feature Set Network Admission Control (NAC) Provision or deny network Access based on policy Specific Security controls Per virtualized network (IPSec) Validate user , host and Baseline compliance VRF X VRF Y VRF Z VRFS IP KG IP KG VRF X VRF Y VRF Z IPKG Service Provider A 802.1x ASA/FWSM Context X ASA/FWSM Context Y ASA/FWSM Context Z ASA/FWSM Context S IOS Adv. Security Feature Set Service Provider B Application-Enhancing Services Collaboration-Enhancing Services Voice Services VRF X VRF Y VRF Z Interactive Services Layer NAC Appliance Adaptive Policy Security Services Facility 2 IP KG Infrastructure- Enhancing Services Computer Services Mobility Services Identity Services Primary Data Center Storage Services 802.1x, TACACS+, IPSec, Day-Zero, etc… MPLS/ GRE IPSec /MPLS/ GRE Crypto Engine Security Services
Intelligent Service Delivery Collaboration
Instant Messaging Telepresence Meeting Place MPLS Routers Agency X X Data Center Mission Services Collaboration Services Data Mining CaseManagement GeoSpatial Analysis ANDVT ANDVT IP KG IP KG IP KG VRF Y VRF 23 IPICS IP Phone IPTV Agency X WAN Application Layer IPKG Message Traffic Watch List VRF Y: Data VRF 23: Voice SIP SBC/ IP to IP Gateway H.323 to SIP H.323 Community Extranet Application-Enhancing Services Collaboration-Enhancing Services Voice Services Interactive Services Layer VRF Z: Data VRF 145: Voice Adaptive Policy Security Services IP KG Infrastructure- Enhancing Services Agency Y Computer Services Mobility Services VRF Y: Data VRF 23: Voice Identity Services Storage Services Some where over the rainbow QoS, LFI, SCCP, SIP, SRTP, SBC, etc.. Collaboration Services
Intelligent Service Delivery Data Center
Consolidation Virtualization Automation Virtualization • Scale • Performance • Density • Availability • Operational Manageability • Investment Protection • Net-Centric Server Evolution • Virtual Machine Network Coupling • Inline Data Protection • Separation of Policy and Forwarding Rack Rack Blade Blade • Power Savings • Service Velocity • Opex Alignment • Capital Utilization Improvement Headquarters Remote Office Data Center MAN / WAN Mobile User Network Virtualization Services Networked Infrastructure Layer Innovation and Integration • Unified Network Fabric • Integrated Provisioning • Data Center Class Platform • Integrated Services Server Storage Devices 15 BCN Service Oriented Data Center
The Intelligent Information Network SYSTEMS APPROACH POLICY CONTROLS ACTIVE PARTICIPATION • Takes action based on awareness of application and service operation • Dynamically adapts to maximize efficiency and effectiveness • All components within the infrastructure function as part of an overall, integrated system • Both “horizontally” across the network and “vertically” between the different layers of the infrastructure • High level policies direct the network to dynamically provision appropriate resources and controls • Implements business rules ,simplifies changes, reduces risk of change
Q and A • Chris Coleman • ccolema2@cisco.com • (703) 484-0134