36 · Explaining Software-Defined Networking說明軟體定義網路

Introducing Cisco SD-AccessCisco SD-Access 簡介

Over the years, the networking technologies that have been the foundation of interconnectivity between clients, devices, and applications have generally remained static. While IT teams have a number of technology choices about ways to design and operate their networks, there has not been a comprehensive, turnkey solution to address the rapidly evolving enterprise needs around mobility, Internet of Things (IoT), cloud, and security.

多年來,作為用戶端、裝置與應用程式之間互連基礎的網路技術大致維持不變。雖然 IT 團隊在設計與維運網路方面有許多技術選擇,但一直缺乏一套完整的一站式解決方案,來因應企業對行動化、物聯網(IoT)、雲端與安全性等快速演變需求。

Challenges with Traditional Networks

傳統網路面臨的挑戰

A slow-to-deploy network impedes the ability of many organizations to innovate rapidly and adopt new technologies such as video, collaboration, and connected workspaces. The ability of a company to adopt any of these is impeded if the network is slow to change and adapt. In addition, one of the major challenges with wireless deployment today is that it does not easily utilize network segmentation. While wireless can leverage multiple service set identifiers (SSIDs) for traffic separation over the air, these are limited in the number that can be deployed and are ultimately mapped back into VLANs at the wireless LAN controller (WLC). The WLC itself has no concept of virtual routing and forwarding (VRF) or Layer 3 segmentation, making deployment of a true wired and wireless network virtualization solution very challenging.

部署速度緩慢的網路會妨礙許多組織快速創新與採用新技術(例如視訊、協作與連接式工作空間)的能力。若網路變更與調適速度緩慢,企業採用這些技術的能力就會受阻。此外,目前無線部署的主要挑戰之一,是無法輕易運用網路區隔。雖然無線網路可以利用多個服務集識別碼(SSID)在空中進行流量分離,但可部署的數量有限,且最終都會對應回無線 LAN 控制器(WLC)上的 VLAN。WLC 本身並沒有虛擬路由與轉送(VRF)或第 3 層區隔的概念,這使得真正的有線與無線網路虛擬化解決方案很難部署。

Policy is one of those abstract words that can mean many different things to different people. However, in the context of networking, every organization has multiple policies that they implement. Use of security access control lists (ACLs) on a switch, or security rulesets on a firewall, is security policy. Using quality of service (QoS) to sort traffic into different classes, and using queues on network devices to prioritize one application versus another, is QoS policy. Placing devices into separate VLANs based on their role is device-level access control policy. The traditional methods used today for policy administration (large and complex ACLs on devices and firewalls) are difficult to implement and maintain. Also, most organizations want to establish user and device identity for end-to-end policy. In addition, most organizations lack comprehensive visibility into network operation, limiting their ability to proactively respond to changes. All these issues influence how long it takes for a new network service to be deployed. A more comprehensive, end-to-end approach is needed, one that allows insights to be drawn from the mass of data that potentially can be reported from the underlying infrastructure.

「政策(Policy)」是個抽象的詞,對不同的人可能代表不同的意思。然而,在網路情境中,每個組織都會實施多種政策。在交換器上使用安全性存取控制清單(ACL),或在防火牆上使用安全規則集,就是安全政策。使用服務品質(QoS)將流量分類,並在網路裝置上使用佇列來排定某應用程式優先於另一應用程式,就是 QoS 政策。依裝置角色將其分配到不同 VLAN,就是裝置層級的存取控制政策。目前用於政策管理的傳統方法(裝置與防火牆上龐大且複雜的 ACL)難以實作與維護。此外,大多數組織都希望建立使用者與裝置身分,以實現端對端政策。此外,大多數組織缺乏對網路運作的全面可見性,限制了主動回應變化的能力。所有這些問題都會影響部署新網路服務所需的時間。因此需要一套更全面的端對端方法,能從底層基礎設施可能回報的大量資料中萃取洞見。

What is Cisco SDA?

什麼是 Cisco SDA?

The Cisco Software-Defined Access (SD-Access) solution is a programmable network architecture that provides software-based policy and segmentation from the edge of the network to the applications. SD-Access is implemented via Cisco Catalyst Center, which provides design settings, policy definition, and automated provisioning of the network elements, as well as assurance analytics for an intelligent wired and wireless network.

Cisco 軟體定義存取(SD-Access,SDA)解決方案是一種可程式化的網路架構,能從網路邊緣到應用程式提供以軟體為基礎的政策與區隔。SD-Access 是透過 Cisco Catalyst Center 實作,該中心提供設計設定、政策定義、網路元件的自動化佈建,以及智慧型有線與無線網路的保證分析。

In an enterprise architecture, the network may span multiple domains, locations, or sites such as main campuses and remote branches, each with multiple devices, services, and policies. The Cisco SD-Access solution offers an end-to-end architecture that ensures consistency in terms of connectivity, segmentation, and policy across different locations (sites).

在企業架構中,網路可能橫跨多個網域、地點或站點(例如主要園區與遠端分支),各自有多種裝置、服務與政策。Cisco SD-Access 解決方案提供端對端架構,確保不同地點(站點)之間在連線性、區隔與政策方面的一致性。

Cisco SD-Access comprises these elements:

Cisco SD-Access 由下列元素組成:

  • Cisco Catalyst Center:Cisco SDN Controller for automation, policy, assurance, and integration infrastructureCisco Catalyst Center:用於自動化、政策、保證與整合基礎設施的 Cisco SDN 控制器
  • SD-Access fabric: Physical and logical network-forwarding infrastructureSD-Access 網路架構(fabric): 實體與邏輯網路轉送基礎設施

SD-Access Management with Cisco Catalyst Center

透過 Cisco Catalyst Center 進行 SD-Access 管理

Cisco Catalyst Center provides a central management plane for building and operating an SD-Access fabric. The management plane is responsible for forwarding configuration and policy distribution, as well as device management and analytics.

Cisco Catalyst Center 提供集中式管理平面,用於建置與維運 SD-Access 網路架構。管理平面負責轉送設定與政策分發,以及裝置管理與分析。

There are two main functions of Cisco Catalyst Center: automation and assurance:

Cisco Catalyst Center 有兩大主要功能:自動化與保證:

  • Cisco Catalyst Center automation provides the definition and management of SD-Access group-based policies, along with the automation of all policy-related configurations. Cisco Catalyst Center integrates directly with Cisco ISE to provide host onboarding and policy enforcement capabilities. With SD-Access, Cisco Catalyst Center uses controller-based automation as the primary configuration and orchestration model, to design, deploy, verify, and optimize wired and wireless network components for both nonfabric and fabric-based deployments.Cisco Catalyst Center 自動化提供 SD-Access 群組式政策的定義與管理,並自動化所有政策相關設定。Cisco Catalyst Center 直接與 Cisco ISE 整合,提供主機上線與政策執行能力。在 SD-Access 中,Cisco Catalyst Center 以控制器式自動化作為主要的設定與協調模型,用於設計、部署、驗證與最佳化非網路架構與網路架構部署中的有線與無線網路元件。
  • Network assurance quantifies availability and risk from an IT network perspective, based on a comprehensive set of network analytics. Beyond general network management, network assurance measures the impact of network change on security, availability, and compliance.網路保證從 IT 網路角度,根據一套完整的網路分析,量化可用性與風險。除了一般網路管理外,網路保證還能衡量網路變更對安全性、可用性與合規性的影響。

The key enabler to Cisco Catalyst Assurance is analytics—the ability to continually collect data from the network and transform it into actionable insights. To achieve this, Cisco Catalyst Center collects a variety of network telemetry, in traditional forms (SNMP, NetFlow, syslogs, and so on) and also emerging forms (NETCONF, YANG, streaming telemetry, and others). Cisco Catalysts Assurance then performs advanced processing to evaluate and correlate events to continually monitor how devices, users, and applications are performing.

Cisco Catalyst 保證的關鍵推手是分析能力,也就是持續從網路收集資料並轉化為可行洞見的能力。為此,Cisco Catalyst Center 收集各種網路遙測資料,包括傳統形式(SNMP、NetFlow、系統紀錄等)以及新興形式(NETCONF、YANG、串流遙測等)。接著 Cisco Catalyst 保證會執行進階處理,評估並關聯事件,持續監控裝置、使用者與應用程式的運作情況。

Correlation of data is key since it allows for troubleshooting issues and analyzing network performance across both the overlay and underlay portions of the SD-Access fabric. Other solutions often lack this level of correlation and thus lose visibility into underlying traffic issues that may affect the performance of the overlay network. By providing correlated visibility into both underlay and overlay traffic patterns and usage through fabric-aware enhancements to NetFlow, SD-Access ensures that network visibility is not compromised when a fabric deployment is used.

資料關聯至關重要,因為它能讓人在 SD-Access 網路架構的覆蓋層與底層兩部分之間,同時進行疑難排解與網路效能分析。其他解決方案通常缺乏這種程度的關聯性,因而失去對可能影響覆蓋網路效能之底層流量問題的可見性。透過對 NetFlow 進行網路架構感知強化,提供底層與覆蓋層流量模式與使用情況的關聯可見性,SD-Access 確保在使用網路架構部署時,網路可見性不會受到損害。

Cisco SD-Access Fabric

Cisco SD-Access 網路架構

Part of the complexity in a network comes from the fact that policies are tied to network constructs such as IP addresses, VLANs, ACLs, and so on. The concept of fabric changes that. With a fabric, an enterprise network is thought of as being divided into two different layers, each for different objectives. One layer is dedicated to the physical devices and forwarding of traffic (known as an underlay), and the other entirely virtual layer (known as an overlay) is where wired and wireless users and devices are logically connected together, and services and policies are applied. This provides a clear separation of responsibilities and maximizes the capabilities of each sublayer while dramatically simplifying deployment and operations since a change of policy would only affect the overlay and the underlay would not be touched.

網路複雜性的一部分來自於政策與 IP 位址、VLAN、ACL 等網路構件綁定的事實。網路架構(fabric)的概念改變了這一點。透過網路架構,企業網路可視為分為兩個不同的層,各自有不同的目標。一層專用於實體裝置與流量轉送(稱為底層),另一層則是完全虛擬的層(稱為覆蓋層),有線與無線使用者及裝置在此邏輯連接在一起,並套用服務與政策。這提供了明確的職責分離,並最大化每個子層的能力,同時大幅簡化部署與維運,因為政策變更只會影響覆蓋層,底層不會受到影響。

The combination of an underlay and an overlay is called a "network fabric".

底層與覆蓋層的組合稱為「網路架構(network fabric)」。

The concepts of overlay and fabric are not new in the networking industry. Existing technologies such as Multiprotocol Label Switching (MPLS), Generic Routing Encapsulation (GRE), Locator/ID Separation Protocol (LISP), and Overlay Transport Virtualization (OTV) are all examples of network tunneling technologies that implement an overlay. Another common example is Cisco Unified Wireless Network (Cisco UWN), which uses Control and Provisioning of Wireless Access Points (CAPWAP) to create an overlay network for wireless traffic.

覆蓋層與網路架構的概念在網路業界並非新事物。現有技術如多重協定標籤交換(MPLS)、通用路由封裝(GRE)、定位器/識別碼分離協定(LISP)以及覆蓋傳輸虛擬化(OTV),都是實作覆蓋層的網路穿隧技術範例。另一個常見範例是 Cisco 統一無線網路(Cisco UWN),它使用無線基地台的控制與佈建協定(CAPWAP)為無線流量建立覆蓋網路。

The Cisco SD-Access architecture is supported by a fabric technology implemented for the campus, enabling the use of virtual networks (overlay networks) running on a physical network (underlay network) creating alternative topologies to connect devices.

Cisco SD-Access 架構是由針對園區實作的網路架構技術所支援,能在實體網路(底層)上運行虛擬網路(覆蓋網路),建立連接裝置的替代拓樸。

What is Cisco SD-Access Underlay?

什麼是 Cisco SD-Access 底層?

Cisco SD-Access network underlay (or simply, underlay) is comprised of the physical network devices, such as routers, switches, and WLCs, plus a traditional Layer 3 routing protocol. This provides a simple, scalable, and resilient foundation for communication between the network devices. The network underlay is not used for client traffic (client traffic uses the fabric overlay).

Cisco SD-Access 網路底層(或簡稱底層)由實體網路裝置(如路由器、交換器與 WLC)加上傳統第 3 層路由協定組成。這為網路裝置之間的通訊提供了簡單、可擴充且具韌性的基礎。網路底層不用於用戶端流量(用戶端流量使用網路架構覆蓋層)。

All network elements of the underlay must establish IPv4 connectivity between each other. This means an existing IPv4 network can be leveraged as the network underlay. Although any topology and routing protocol could be used in the underlay, the implementation of a well-designed Layer 3 access topology (that is, a routed access topology) is highly recommended. Using a routed access topology (leveraging routing all of the way down to the access layer) eliminates the need for Spanning Tree Protocol (STP), VLAN Trunk Protocol (VTP), Hot Standby Router Protocol (HSRP), Virtual Router Redundancy Protocol (VRRP), and other similar protocols in the network underlay, simplifying the network and at the same time increasing resiliency and improving fault tolerance.

底層的所有網路元素之間都必須建立 IPv4 連線。這表示可以利用現有的 IPv4 網路作為網路底層。雖然底層可以使用任何拓樸與路由協定,但強烈建議實作設計良好的第 3 層存取拓樸(即路由式存取拓樸)。使用路由式存取拓樸(將路由一路延伸到存取層)可省去在網路底層中使用生成樹協定(STP)、VLAN 中繼協定(VTP)、熱備援路由器協定(HSRP)、虛擬路由器備援協定(VRRP)及其他類似協定的需要,簡化網路的同時也提高了韌性並改善容錯能力。

Cisco Catalyst Center provides a prescriptive LAN automation service to automatically discover, provision, and deploy network devices according to Cisco design best practices. Once discovered, the automated underlay provisioning leverages plug-and-play (PnP) to apply the required IP address and routing protocol configurations.

Cisco Catalyst Center 提供一套規範式的 LAN 自動化服務,可依 Cisco 設計最佳實務自動探索、佈建與部署網路裝置。裝置一經探索,自動化底層佈建即會利用隨插即用(PnP)套用所需的 IP 位址與路由協定設定。

What is Cisco SD-Access Overlay?

什麼是 Cisco SD-Access 覆蓋層?

Cisco SD-Access fabric overlay (or simply, overlay) is the logical, virtualized topology built on top of the physical underlay. An overlay network is created on top of the underlay to create a virtualized network. In the SD-Access fabric, the overlay networks are used for transporting user traffic within the fabric. The fabric encapsulation also carries scalable group information used for traffic segmentation inside the overlay. The data plane traffic and control plane signaling are contained within each virtualized network, maintaining isolation among the networks as well as independence from the underlay network. The SD-Access fabric implements virtualization by encapsulating user traffic in overlay networks using IP packets that are sourced and terminated at the boundaries of the fabric. The fabric boundaries include borders for ingress and egress to a fabric, fabric edge switches for wired clients, and fabric APs for wireless clients. Overlay networks can run across all or a subset of the underlay network devices. Multiple overlay networks can run across the same underlay network to support multitenancy through virtualization.

Cisco SD-Access 網路架構覆蓋層(或簡稱覆蓋層)是建立在實體底層之上的邏輯虛擬化拓樸。覆蓋網路建立在底層之上,用以建立虛擬化網路。在 SD-Access 網路架構中,覆蓋網路用於在網路架構內傳輸使用者流量。網路架構封裝也會攜帶用於覆蓋層內流量區隔的可擴充群組資訊。資料平面流量與控制平面訊令都包含在各自的虛擬化網路內,維持網路之間的隔離,並獨立於底層網路。SD-Access 網路架構透過在來源與終止於網路架構邊界的 IP 封包中封裝使用者流量來實作虛擬化。網路架構邊界包括網路架構進出流量的邊界(border)、供有線用戶端使用的網路架構邊緣交換器,以及供無線用戶端使用的網路架構 AP。覆蓋網路可以在全部或部分底層網路裝置上運行。多個覆蓋網路可以在同一底層網路上運行,以透過虛擬化支援多租戶。

There are three primary types of policies that can be automated in the SD-Access fabric:

可在 SD-Access 網路架構中自動化的政策主要有三種類型:

  1. Security: Access control policy, which dictates who can access what安全性: 存取控制政策,決定誰可以存取什麼
  2. QoS: Application policy, which invokes the QoS service to provision differentiated access to users on the network, from an application experience perspectiveQoS: 應用程式政策,從應用程式體驗的角度呼叫 QoS 服務,為網路上使用者提供差異化存取
  3. Copy: Traffic copy policy, which invokes the traffic copy service for monitoring specific traffic flows複製: 流量複製政策,呼叫流量複製服務以監控特定流量

These services are offered across the entire fabric, independently of device-specific address or location.

這些服務可在整個網路架構中提供,不受特定裝置位址或位置限制。

Cisco SD-Access benefits

Cisco SD-Access 的效益

SD-Access provides automated end-to-end services (such as segmentation, QoS, and analytics) for user, device, and application traffic. SD-Access automates user policy so organizations can ensure that the appropriate access control and application experience are set for any user or device to any application across the network. This is accomplished with a single network fabric across LAN and WLAN, which creates a consistent user experience, anywhere, without compromising on security.

SD-Access 為使用者、裝置與應用程式流量提供自動化端對端服務(例如區隔、QoS 與分析)。SD-Access 自動化使用者政策,使組織能確保任何使用者或裝置存取網路上任何應用程式時,都設有適當的存取控制與應用程式體驗。這是透過跨 LAN 與 WLAN 的單一網路架構實現的,能在任何地方提供一致的使用者體驗,同時不損及安全性。

Where should the Cisco SD-Access solution be used?Cisco SD-Access 解決方案應該用於何處?
What is the role of the SD-Access fabric overlay?SD-Access 網路架構覆蓋層的作用是什麼?