36 · Explaining Software-Defined Networking說明軟體定義網路

Introducing Cisco Catalyst SD-WANCisco Catalyst SD-WAN 簡介

Traditionally, WANs were designed to connect users at the branch or campus to applications hosted on servers in the data center. Typically, dedicated multiprotocol label switching (MPLS) circuits were used to help ensure security and reliable connectivity. This function no longer works in a cloud-centric world because WAN networks designed for a different era are not ready for the unprecedented explosion of WAN traffic that cloud adoption brings. That traffic causes management complexity, application performance unpredictability, and data vulnerability.

傳統上,WAN 的設計目的是將分公司或園區的使用者連接到資料中心伺服器上代管的應用程式。通常會使用專屬的多重協定標籤交換(MPLS)電路,以協助確保安全性與可靠的連線。在雲端為中心的世界中,這種做法已不再適用,因為為不同時代設計的 WAN 網路,無法應付雲端採用所帶來前所未見的 WAN 流量爆炸性成長。這種流量會造成管理複雜度增加、應用程式效能難以預測,以及資料易受攻擊等問題。

Cisco Catalyst SD-WAN is a software-defined approach to managing WANs. Cisco Catalyst SD-WAN simplifies the management and operation of a WAN by separating the networking hardware from its control mechanism. This solution virtualizes much of the routing that used to require dedicated hardware.

Cisco Catalyst SD-WAN 是一種軟體定義的 WAN 管理方法。Cisco Catalyst SD-WAN 藉由將網路硬體與其控制機制分離,簡化了 WAN 的管理與操作。此解決方案將許多過去需要專屬硬體的路由功能虛擬化。

SD-WAN represents an evolution of networking from an older, hardware-based model to a secure, software-based, virtual IP fabric. The overlay network forms a software overlay that runs over standard network transport services, including the public internet, MPLS, and broadband. The overlay network also supports next-generation software services, thereby accelerating the shift to cloud networking.

SD-WAN 代表網路從舊有的硬體式模型演進為安全的軟體式虛擬 IP 網路架構。覆蓋網路形成一個軟體覆蓋層,運行於標準網路傳輸服務之上,包括公用網際網路、MPLS 與寬頻。覆蓋網路也支援次世代軟體服務,藉此加速轉向雲端網路。

The Cisco Catalyst SD-WAN solution is comprised of separate orchestration, management, control, and data planes:

Cisco Catalyst SD-WAN 解決方案由各自獨立的協調平面、管理平面、控制平面與資料平面組成:

  • The orchestration plane assists in the automatic onboarding of the SD-WAN routers into the SD-WAN overlay.協調平面協助 SD-WAN 路由器自動上線加入 SD-WAN 覆蓋網路。
  • The management plane is responsible for centralized configuration and monitoring.管理平面負責集中式設定與監控。
  • The control plane builds and maintains the network topology and makes decisions on where traffic flows.控制平面建置並維護網路拓樸,並決定流量的走向。
  • The data plane is responsible for forwarding packets based on decisions from the control plane.資料平面負責根據控制平面的決策轉送封包。

The primary components for the Cisco Catalyst SD-WAN solution consist of the SD-WAN Manager network management system (management plane), the SD-WAN Controller (control plane), the SD-WAN Validator (orchestration plane), and the WAN Edge router (data plane). The components are:

Cisco Catalyst SD-WAN 解決方案的主要元件包括:SD-WAN Manager 網路管理系統(管理平面)、SD-WAN Controller(控制平面)、SD-WAN Validator(協調平面),以及 WAN Edge 路由器(資料平面)。這些元件為:

  • Management plane (SD-WAN Manager):Centralized network management system provides a GUI interface to monitor, configure, and maintain all Cisco SD-WAN devices and links in the underlay and overlay network.管理平面(SD-WAN Manager):集中式網路管理系統,提供 GUI 介面,用於監控、設定與維護底層與覆蓋網路中所有 Cisco SD-WAN 裝置與連結。
  • Control plane (SD-WAN Controller):This software-based component is responsible for the centralized control plane of the SD-WAN network. It establishes a secure connection to each WAN Edge router and distributes routes and policy information via the Overlay Management Protocol (OMP). It also orchestrates the secure data plane connectivity between the WAN Edge routers by distributing crypto key information.控制平面(SD-WAN Controller):此軟體式元件負責 SD-WAN 網路的集中式控制平面。它會與每台 WAN Edge 路由器建立安全連線,並透過覆蓋管理協定(OMP)分發路由與政策資訊。它也會透過分發加密金鑰資訊,協調 WAN Edge 路由器之間的安全資料平面連線。
  • Orchestration plane (SD-WAN Validator):This software-based component performs the initial authentication of WAN Edge devices and orchestrates vSmart and WAN Edge connectivity. It also has an important role in enabling the communication of devices that sit behind Network Address Translation (NAT).協調平面(SD-WAN Validator):此軟體式元件負責 WAN Edge 裝置的初始驗證,並協調 vSmart 與 WAN Edge 之間的連線。它在啟用位於網路位址轉換(NAT)後方的裝置通訊方面也扮演重要角色。
  • Data plane (WAN Edge Router):This device, available as either a hardware appliance or software-based router, sits at a physical site or in the cloud and provides secure data plane connectivity among the sites over one or more WAN transports. It is responsible for traffic forwarding, security, encryption, QoS, routing protocols such as BGP and OSPF, and more.資料平面(WAN Edge Router):此裝置可為硬體設備或軟體式路由器,位於實體站點或雲端,透過一個或多個 WAN 傳輸提供站點之間的安全資料平面連線。它負責流量轉送、安全性、加密、QoS、路由協定(如 BGP 與 OSPF)等。
  • Programmatic APIs (REST): Programmatic control over all aspects of SD-WAN Manager administration.可程式化 API(REST): 對 SD-WAN Manager 管理的所有層面提供可程式化控制。
  • Analytics (SD-WAN Analytics):Adds a cloud-based predictive analytics engine for Cisco Catalyst SD-WAN.分析(SD-WAN Analytics):為 Cisco Catalyst SD-WAN 新增以雲端為基礎的預測分析引擎。

This sample topology depicts two sites and two public internet transports. The SD-WAN Controllers (vSmart1 and vSmart2), and the SD-WAN Validator, along with the SD-WAN Manager reside on the internet, and are reachable through either transport.

此範例拓樸描繪兩個站點與兩個公用網際網路傳輸。SD-WAN Controller(vSmart1 與 vSmart2)、SD-WAN Validator 以及 SD-WAN Manager 都位於網際網路上,並可透過任一傳輸連接。

At each site, WAN Edge routers are used to directly connect to the available transports. Colors are used to identify an individual WAN transport, as different WAN transports are assigned different colors, such as mpls, private1, biz-internet, metro-ethernet, lte, and so on. The topology uses one color for the biz-internet transport and a different one for the public-internet transport.

在每個站點,WAN Edge 路由器用於直接連接到可用的傳輸。顏色用於識別個別 WAN 傳輸,因為不同的 WAN 傳輸會分配不同的顏色,例如 mpls、private1、biz-internet、metro-ethernet、lte 等等。此拓樸使用一種顏色代表 biz-internet 傳輸,另一種顏色代表 public-internet 傳輸。

The WAN Edge routers form a Datagram Transport Layer Security (DTLS) or Transport Layer Security (TLS) control connection to the SD-WAN Controllers and connect to both of the SD-WAN Controllers over each transport. The WAN Edge routers securely connect to WAN Edge routers at other sites with IPsec tunnels over each transport. The Bidirectional Forwarding Detection (BFD) protocol is enabled by default and will run over each of these tunnels, detecting loss, latency, jitter, and path failures.

WAN Edge 路由器會與 SD-WAN Controller 建立資料包傳輸層安全(DTLS)或傳輸層安全(TLS)控制連線,並透過每個傳輸連接到兩台 SD-WAN Controller。WAN Edge 路由器會透過每個傳輸,以 IPsec 通道與其他站點的 WAN Edge 路由器安全連接。雙向轉送偵測(BFD)協定預設為啟用,會在這些通道上運行,用於偵測遺失、延遲、抖動與路徑故障。

WAN Edge routers are delivered as hardware, software, cloud, or virtualized components that sit at the perimeter of a site, such as a remote office, branch office, campus, or data center. They participate in establishing a secure virtual overlay network over a mix of any WAN transports.

WAN Edge 路由器以硬體、軟體、雲端或虛擬化元件的形式提供,位於站點(例如遠端辦公室、分公司、園區或資料中心)的邊界。它們參與在多種 WAN 傳輸混合環境上建立安全的虛擬覆蓋網路。

Policies are an important part of the Cisco Catalyst SD-WAN solution and are used to influence the flow of data traffic among the WAN Edge routers in the overlay network. Policies apply either to control plane or data plane traffic and are configured either centrally on SD-WAN Controllers (centralized policy) or locally (localized policy) on WAN Edge routers.

政策是 Cisco Catalyst SD-WAN 解決方案的重要部分,用於影響覆蓋網路中 WAN Edge 路由器之間的資料流量走向。政策可套用於控制平面或資料平面流量,並可集中設定於 SD-WAN Controller(集中式政策),或在本地端(本地化政策)設定於 WAN Edge 路由器上。

Centralized control policies operate on the routing and transport location (TLOC) information and allow for customizing routing decisions and determining routing paths through the overlay network. These policies can be used in configuring traffic engineering, path affinity, service insertion, and different types of VPN topologies (full-mesh, hub-and-spoke, regional mesh, and so on). Another centralized control policy is application-aware routing, which selects the optimal path based on real-time path performance characteristics for different traffic types. Localized control policies allow you to affect routing policy at a local site.

集中式控制政策作用於路由與傳輸位置(TLOC)資訊,可用於自訂路由決策,並決定通過覆蓋網路的路由路徑。這些政策可用於設定流量工程、路徑親和性、服務插入,以及不同類型的 VPN 拓樸(全網狀、軸輻式、區域網狀等)。另一種集中式控制政策是應用程式感知路由,它會根據不同流量類型的即時路徑效能特性,選擇最佳路徑。本地化控制政策可讓您在本地站點影響路由政策。

Data policies influence the flow of data traffic through the network based on fields in the IP packet headers and VPN membership. Centralized data policies can be used in configuring application firewalls, service chaining, traffic engineering, and QoS. Localized data policies allow you to configure how data traffic is handled at a specific site, such as ACLs, QoS, mirroring, and policing. Some centralized data policy may affect handling on the WAN Edge itself, as in the case of app-route policies or a QoS classification policy. In these cases, the configuration is still downloaded directly to the SD-WAN Controllers, but any policy information that needs to be conveyed to the WAN Edge routers is communicated through Overlay Management Protocol (OMP).

資料政策根據 IP 封包標頭欄位與 VPN 成員資格,影響網路中資料流量的走向。集中式資料政策可用於設定應用程式防火牆、服務鏈、流量工程與 QoS。本地化資料政策可讓您設定資料流量在特定站點的處理方式,例如 ACL、QoS、鏡像與流量管制。某些集中式資料政策可能會影響 WAN Edge 本身的處理方式,例如應用程式路由政策或 QoS 分類政策。在這些情況下,設定仍會下載到 SD-WAN Controller,但任何需要傳達給 WAN Edge 路由器的政策資訊,都會透過覆蓋管理協定(OMP)傳送。

In which two environments should the Cisco Catalyst SD-WAN solution be used? (Choose two.)Cisco Catalyst SD-WAN 解決方案應該用於哪兩種環境?(選擇兩項。)
Which component of the Cisco Catalyst SD-WAN solution is responsible for centralized configuration and monitoring?Cisco Catalyst SD-WAN 解決方案的哪個元件負責集中式設定與監控?