Secure Intelligent Platforms P.Pavlu oct2018 - Cisco · Secure Intelligent Platforms for the...

Post on 22-May-2020

11 views 0 download

transcript

Petr PavluDirector, Systems Engineering, Cisco EETivat, October 30, 2018

Delivering Value Beyond Connectivity

Secure Intelligent Platforms for the Digital Business

Traditional Network

Value

New World

PlatformValue

Where is our Value Today?Value Beyond Connectivity

Analytics & Assurance

Security Policy & BehaviourAutomation

Value Beyond Connectivity

The Network is the Foundation

High Security High Availability High Performance

The world is changing according to Gartner

Source: Gartner Symposium ITXPO, Dubai, March 2018

Digital Business

SecurityMobile IoT Cloud

the secure, intelligent PLATFORM delivering value beyond Connectivity

Complexity

Why Platforms:What is Different?

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Windows/x86 was the most successful

platform in the 80’s and 90’s

Google has evolved to become much more

than search

eBay expanded from an online auction

community into voice services

Apple expands beyond music into digital

entertainment

A Platform:

• Delivers applications or services to a user with a consistent experience

• Can mobilize seamlessly an ecosystem – open standards

• Is pervasive, extensible, and based on open architectures

Examples:

Successful Platforms Evolve Over Time

Today’s Networks are not a Digital Platform But Can Evolve to Become One

Platform Approach

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Windows/x86 was the most successful

platform in the 80’s and 90’s

Google has evolved to become much more

than search

eBay expanded from an online auction

community into voice services

Apple expands beyond music into digital

entertainment

A Platform:

• Delivers applications or services to a user with a consistent experience

• Can mobilize seamlessly an ecosystem – open standards

• Is pervasive, extensible, and based on open architectures

Examples:

Successful Platforms Evolve Over Time

Today’s Networks are not a Digital Platform But Can Evolve to Become One

Platform Approach

Cisco’s R&D Strategy has been focused

on building platform

User Experience

Open Architecture

Systems Integration

Cisco Container Platform DNA Centre

Software Defined Access (SDA)

Network Function Virtualization

(NFV)

Intelligent WAN (SD WAN)

Network Assurance Engine

Jasper Provisioning and Connectivity

Management

App Dynamic

Industrial/Field Network Director

Connected Grid Endpoints

APIC-EM

Hyperflex 3.0

Cisco DevNet

Cisco has been working toward this for years

Now we’re bringing them all together with a Platform ApproachA Platform Approach: Differentiated and based on Software

Analytics & Assurance

Automation

Security & Compliance

Increased Pace of Innovation

Secure, Intelligent Platform for Digital Business

Reinvent the Network

Embrace aMulti-Cloud

WorldUnlock the

Power of DataEmployee and

CustomerExperience

Security is Foundational

Reinvent Networking

The role of the network...the birth of an I.T. headache

Convergence of data and voice –my first ip phone

Petr goes mobile, wlan, laptop and

mobile

Ohoo – security isgetting complicated

Data, voice, video and sharing – hyperconnected and communicative

Where does the application live – Petr

does not care as long as it works

Petr and his desktop PC

43% of time on troubleshooting

Network managment

still CLI

IT can barelycope

Is the Network Ready to Provide a Digital Foundation?

Network

Yesterday`s Network

SecureReliable

Performance

Is the Network Ready to Provide a Digital Foundation?

Network

Yesterday`s Network

SecureReliable

Performance

Today

Visibility Flexible

Cloud Ready Programability

The Network needs to deliver more Value

Visibility Flexible

Cloud Ready Programability

TodayTomorrow

Analytical Insight

BehaviourAware

FullyAutomated

Tomorrow

Analytical Insight

BehaviourAware

FullyAutomated

Vision

The Potential is for a Complete Autonomic Environment

Intent-based Networking

Network infrastructure

Business requirements/needs

VLANs

Subnets

ACLs

AAA

VRFs

VPNs

Abstraction, Intelligence, Automation (Software Defined)

Intent-based network for WANOptimize and secure application performance over any connection to the cloud.

AccessSegment your network and secure user access from the edge to the cloud

Data CenterRun any traditional or cloud native application across any environment

Cloud EdgeSecurely connect and protect workloads moving into the cloud and between clouds.

Intent-based network for

I N T E N T C O N T E X T

S E C U R I T Y

L E A R N I N G

Embrace a Multi-Cloud World

A multicloudapproach enablescustomers to consume services from two or moreclouds where at leastone cloud is public.

Fragmented

Complex

No Data Control

Transforming Management of Multicloud Complexity

GCP

AWS

Other Public Clouds

Azure

SaasSaas

Saas

Saas

SaasSaas

Saas

SaasHybridClouds

Private Private

Multicloud

Cisco Multicloud Software Platform

MulticloudPortfolio

CloudConnect

CloudProtect

CloudAdvisory

CloudConsume

Design, plan, accelerate,and de-risk your multicloud migrations

Deploy, monitor and optimize applications in multicloud environments

Securely extend your private networks into public clouds and ensure the application experience

Protect multicloud identities, direct-to-cloud connectivity, data, and applications including SaaS

Cisco Multicloud Benefits

MulticloudSoftware Analytics ManagementSecurityNetworking

…to connect, protect and consume cloud services.

Unlock the Power of Data

Unlock the Power of DataHigh Level Strategy: Monitor, Analyze, Act

Collection Analytics ExperienceFull Stack Monitoring

Process Analyze Predict Visualize

End User Monitoring

• Data Normalization• Time Normalization• Baselining• Auto-Tagging• Alert Prioritization

• Statistical Analysis• Event Correlation• Application Threat

Analysis• Compliance Analysis• Transaction Analysis

• Pattern Recognition• Classification• Anomaly Detection• Cost Modeling• Trends

• Real-time Analytics• Tag-based Search• Recommendations

Log Analytics Optimize

3rd Party Integrations

• Automation• Remediation

Real Time Analytics for amazing User Experience and Business Insight

Business / App Owner

Acquire and retainhappy users

Drive business outcomes

App Developer

Iterate and release faster with confidence

Focus on building vs. Scale headaches

App Operations

Run the app with high availability/prerf

Rapid time to resolveapp issues/problems

Infrastructure Operations

Understanddependencies & migrate across infrastructure

Troubleshoot data center, latency issues

Security Operations

Secure apps across data center and

network

Regulate & enforce security/whitelist

policies

User

Seamless & secureaccess

Delightful & consistentexperience

DNA Center

Enrich the Employee/Customer Experience

Every Platform Has API’s

DNAWebex Teams Multi-CloudSecurity

Embed innovative services to improve user

experience

Improved flexibility to access your favorite tools

wherever you work

Increased simplicity to build customized solutions

for verticals

- -

Improved integration with your existing

IT management tools

Humans won’t scale to manage networks that deliver the customerexperience demanded.

A delightful user experience

Petr enters the room

System recognizes Petr’s

phone (wifi)

Facial recognition„its definitely Petr”

Petr has TP meeting NOW!

Starts automaticaly.Video traffic

prioritised on WAN.

Network detects two other people with Petr

in room.

Facilites app – trendsroom booking info.

Heating app – adjusts heating accordingly.

Meetingfinishes

QOS turned off on WAN

TP Unit powers down

Lights switch OFF

...but a challenge for IT

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Today TodayMajor Bank Major Retailer

150kemployees

866k devices

8.2kIT staff

~105 devices per IT person

340k employees

605k devices

2.8kIT staff

~216 devices per IT person

1:200

1:1,000,000

new IT staff

18,518

4,000,0005,000,000

47,619

new IoT connections

Major Bank Major Retailer

Security is Foundational

Increased use of Cloud Services and Mobile devices demands a newapproach to Security.

Full lifecycle of on-prem and cloudhosted solutions to maximizeprotection.

Reduced Complexity by reducingthe Number of Vendors required.

Automated Network Segmentationenables Customers to addressCompliance requirements.

Security

Security

Cloud Security

Threat Detection Behavior Analysis

ContentProtection

Identity, Policyand Access

CiscoCybersecurity Portfolio

Deploy Security Everywhere

UTM

NetworkAnalytics

AdvancedMalware

Secure Internet Gateway

WebW W W

Policy and Access

Email

Cloud Access Security

Threat protection Visibility Segmentation

Global Security Intelligence and Telemetry

19.7BThreats Per Day

1.4M

1.1M

1.8B

1B

8.2B

Incoming Malware Samples Per Day

Sender Base Reputation Queries

Per Day

Web Filtering Blocks Per Month

AV Blocks Per Day

Spyware Blocks Per Month

250Threat Researchers

100TBThreat Intelligence

Conclusion

Impacting total IT spend by 4-6%

Customer Cost Benefit:30% Networking Saving, 4-6% IT Budget Saving

Source: Gartner IT Key Metrics Data (2015)

Benefits

End User

Application

Compute + Storage

Network

IT Management, Finance, Admin +IT Service Desk

4-6% Saving

30%+ savings after investments

End User

Applications

Network

Compute +Storage

IT Management, Finance, Admin+ Service Desk

Enterprise IT Spend

Network IT spend typically 15% of total IT spend

Addressable Network Spend

Spend is a mix of Opex and Capex

Opex = 65%

Capex = 35%

Operations Opex

Automation

As-Is to To-Be

As-Is To-Be

30% Savings

NetworkTransport

+Operations

Operations Capex

Transport Charges

NetworkTransport

60%

Operations40%

24%

15%

11%

33%

17%

Unbundled Transport

+Wireless

Virtualization

Analytics Automation Security