Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Thursday, 23 July 2026

500-560 Exam: Your Cisco Networking Cloud Roadmap

A professional tech expert overseeing a visually split hybrid network, showing on-premise server racks on one side and abstract cloud elements on the other, with a glowing digital roadmap connecting them and leading to a success icon. The image prominently features the text 'Cisco 500-560: Your Cloud Roadmap'.

In the rapidly evolving landscape of network infrastructure, understanding both on-premise and cloud solutions is no longer an option but a necessity. The Cisco 500-560 Exam, officially known as Cisco Networking - On-Premise and Cloud Solutions (OCSE), serves as a critical milestone for professionals looking to validate their expertise in modern networking. This certification is a cornerstone for those aiming to achieve the Cisco Networking Express Specialization, demonstrating a robust understanding of current and future networking paradigms.

As organizations increasingly integrate hybrid cloud strategies, the demand for skilled professionals who can navigate and implement these complex environments continues to grow. This exam is designed to equip you with the knowledge to deploy, manage, and troubleshoot Cisco networking cloud solutions, ensuring seamless operations across diverse platforms. Whether you are an experienced network engineer or an aspiring architect, the 500-560 OCSE certification offers a structured roadmap to enhance your capabilities and career trajectory in the dynamic world of Cisco networking.

This comprehensive guide will walk you through everything you need to know about the 500-560 exam. From understanding its core objectives and syllabus topics to effective study strategies and practical tips for exam day, we will provide a supportive and step-by-step approach to help you confidently prepare. Embark on this journey to master Cisco's on-premise and cloud networking offerings, solidifying your position as a valuable asset in today's technology-driven market.

What is the Cisco 500-560 OCSE Exam?

The Cisco 500-560 OCSE exam, or Cisco Networking - On-Premise and Cloud Solutions, is specifically designed to assess a candidate's fundamental knowledge of Cisco's networking solutions across both traditional on-premise and modern cloud environments. This exam is a key requirement for partners seeking to achieve the Cisco Networking Express Specialization, a prestigious accreditation that signifies a company's ability to sell, deploy, and support Cisco networking solutions.

The primary goal of the 500-560 exam is to ensure that professionals understand how Cisco's expansive portfolio of switches, routers, wireless access points, Meraki products, and security features integrate and operate in a hybrid setting. It validates your capability to articulate the value proposition of Cisco networking cloud solutions to customers and to design and implement basic configurations.

Candidates for this exam are typically sales engineers, field engineers, network architects, and technical support staff who are involved in recommending, selling, or deploying Cisco networking solutions. It provides a foundational understanding necessary for addressing customer needs related to network connectivity, security, and cloud integration, making it an essential certification for anyone working with Cisco technologies.

The certification focuses on equipping individuals with the skills to discuss, position, and provide initial support for Cisco's networking products and services. This includes a solid grasp of how various components contribute to a robust, scalable, and secure network infrastructure, both within a data center and in the cloud. Understanding the exam objectives is the first step towards achieving your Cisco On-Premise and Cloud Solutions certification.

Why Pursue the Cisco OCSE Certification?

Earning the Cisco On-Premise and Cloud Solutions certification through the 500-560 exam offers a multitude of benefits, both for individual career growth and for partner organizations. In an era where digital transformation is paramount, possessing validated skills in `Cisco networking cloud` environments is a significant differentiator.

For individuals, this certification acts as a strong testament to your technical acumen. It signals to employers and clients that you have a comprehensive understanding of Cisco's diverse networking portfolio, capable of navigating the complexities of hybrid network architectures. This can lead to enhanced career opportunities, better job prospects, and increased earning potential, as certified professionals are often prioritized for critical roles.

Furthermore, achieving this certification demonstrates your commitment to continuous learning and staying abreast of the latest industry trends. The `Cisco networking cloud solutions exam` verifies your ability to articulate the advantages of Cisco's integrated approach to networking, which is invaluable in a consultative or technical sales role. It showcases your proficiency in a critical area, directly impacting business outcomes through effective solution design and implementation.

For Cisco partners, having a team of OCSE-certified professionals is crucial for meeting the requirements of the `Cisco Networking Express Specialization`. This specialization opens doors to exclusive resources, incentives, and a higher level of trust with Cisco, allowing partners to better serve their customers and expand their market reach. It signifies a partner's expertise and dedication to delivering high-quality `Cisco networking cloud specialization` services.

Ultimately, pursuing the Cisco OCSE certification is an investment in your professional future. It equips you with the knowledge and credibility to tackle the challenges of modern networking, ensuring you remain relevant and highly sought-after in a competitive technological landscape. It's not just about passing an exam; it's about building a foundation for continued success in `Cisco networking cloud` innovation.

Cisco 500-560 Exam Details at a Glance

Understanding the administrative details of the Cisco 500-560 exam is crucial for effective planning and preparation. These `Cisco 500-560 exam details` will help you set realistic expectations and manage your study schedule efficiently.

  • Exam Name: Cisco Networking - On-Premise and Cloud Solutions
  • Exam Code: 500-560 OCSE
  • Exam Price: $300 USD
  • Duration: 60 minutes
  • Number of Questions: 45-55 questions
  • Passing Score: Variable (typically 750-850 out of 1000, approximate)

The relatively short duration of 60 minutes for 45-55 questions means you'll need to manage your time wisely during the exam. Each question counts, and a solid grasp of the subject matter is essential for quick, accurate responses. The variable passing score reflects Cisco's adaptive testing methodologies, emphasizing a comprehensive understanding across all domains rather than rote memorization.

Candidates should be aware that the `Cisco OCSE certification cost` of $300 USD is for each attempt. Therefore, thorough preparation to pass on the first try is highly recommended to save both time and money. For a more granular breakdown of what to expect and a detailed list of competencies, referring to the comprehensive 500-560 exam syllabus is an excellent first step in your preparation journey.

Decoding the Cisco 500-560 Syllabus Topics

The `Cisco 500-560 syllabus topics` provide a clear outline of the knowledge and skills tested in the exam. Each section carries a specific weight, indicating its importance. A strategic approach to your `Cisco 500-560 course content` involves allocating study time proportionally to these percentages. Let's delve into each domain:

Switching Overview and Features - 15%

This section focuses on the foundational elements of switching, which are critical for any on-premise network and often extend into hybrid `Cisco networking cloud` architectures. You will need to understand the basic functions of Cisco Catalyst switches, including their role in connecting devices within a local area network (LAN).

Key areas include knowledge of Ethernet concepts, such as half-duplex and full-duplex communication, and the basics of switching operations like MAC address learning and forwarding. Understanding VLANs (Virtual Local Area Networks) is paramount, covering how they segment networks for security and performance, and how trunking protocols like 802.1Q enable communication between VLANs across multiple switches. You should also be familiar with common switching features like Power over Ethernet (PoE) and basic stackwise technology.

Furthermore, the exam will test your awareness of how these on-premise switching capabilities integrate with or lay the groundwork for cloud-managed networking solutions. While the focus is on traditional switching, a conceptual understanding of how these principles translate to a cloud context, such as managing switch configurations from a centralized cloud dashboard, is beneficial. This involves recognizing the value of automation and simplified management inherent in `Cisco networking cloud solutions exam` objectives.

Routing Overview and Features - 15%

Routing forms the backbone of communication across different networks, both local and wide area. This segment of the `Cisco 500-560 exam blueprint` covers the core principles of Cisco routers and their role in directing traffic between disparate networks, including connections to the internet and cloud services.

Expect questions on basic IP routing concepts, including IP addressing (IPv4 and IPv6), subnetting, and the purpose of default gateways. You should understand the differences between static and dynamic routing and be familiar with common dynamic routing protocols like OSPF (Open Shortest Path First) and EIGRP (Enhanced Interior Gateway Routing Protocol), even if only at a conceptual level of their operation and benefits.

Network Address Translation (NAT) is another crucial topic, particularly how it allows multiple devices on a private network to share a single public IP address when accessing external networks, including cloud resources. Understanding the different types of NAT (static, dynamic, PAT) and their use cases is important. This section also touches upon WAN connectivity options and VPN (Virtual Private Network) fundamentals, which are essential for secure remote access and connecting on-premise networks to `Cisco networking cloud` environments. The interplay between on-premise routing and cloud connectivity is a strong focus here.

Wireless Overview and Features - 25%

Wireless networking holds the largest individual percentage of the exam, underscoring its critical role in modern network access, especially in highly mobile and distributed environments that often leverage `Cisco networking cloud` management. This section will test your knowledge of Cisco's wireless solutions, from individual access points to centralized wireless controllers and cloud-managed Wi-Fi.

You should be proficient in understanding basic WLAN (Wireless Local Area Network) concepts, including Wi-Fi standards (e.g., 802.11ac, 802.11ax/Wi-Fi 6), SSIDs, and various authentication and encryption methods like WPA2 and WPA3. The exam will likely cover the different modes of operation for Cisco Access Points (APs), such as autonomous APs and controller-based APs, and the advantages of each.

Central to this section is an understanding of Wireless LAN Controllers (WLCs), their function in managing multiple APs, and how they simplify the deployment and management of large-scale wireless networks. Furthermore, the increasing adoption of cloud-managed wireless solutions, particularly Cisco Meraki Wi-Fi, will be a significant area of focus. You should be able to articulate the benefits of cloud management for wireless networks, including simplified deployment, centralized visibility, and reduced operational overhead. This domain directly ties into the broader `Cisco networking cloud specialization` and its practical applications.

Meraki Overview and Products - 35%

With the highest percentage weighting, the Meraki Overview and Products section is arguably the most critical part of the 500-560 OCSE exam. Cisco Meraki is a leading provider of cloud-managed IT solutions, perfectly embodying the `Cisco networking cloud` philosophy. This section requires a deep understanding of the Meraki portfolio and its operational advantages.

You must understand the core concept of cloud management as applied by Meraki – devices configured and monitored through a centralized web-based dashboard, simplifying deployment and ongoing administration. This includes Meraki's various product lines: MS Switches (cloud-managed switches), MX Security Appliances (cloud-managed firewalls and SD-WAN), MR Access Points (cloud-managed wireless), and MV Security Cameras.

For each product line, you should know their primary features, use cases, and how they contribute to a cohesive and easily manageable network infrastructure. For instance, understand how Meraki MX appliances provide comprehensive security services, VPN capabilities, and intelligent SD-WAN functionalities. Similarly, grasp how Meraki MS switches simplify switch configuration and monitoring, and how MR access points enable seamless wireless connectivity with advanced features.

Beyond individual products, focus on the overall Meraki ecosystem and its benefits, such as zero-touch provisioning, centralized network visibility and analytics, and automated firmware updates. This section is a direct test of your understanding of modern `Cisco networking cloud solutions`, showcasing the power of cloud-driven network management for simplified operations and scalability.

Security Overview and Features - 10%

Network security is paramount in both on-premise and `Cisco networking cloud` environments, and this section covers fundamental security concepts and Cisco's approach to securing the network. While it's a smaller percentage, a strong understanding of these principles is crucial for building resilient network infrastructures.

You should be familiar with basic security concepts such as firewalls (both stateful and stateless), intrusion prevention systems (IPS), and intrusion detection systems (IDS). Understanding the role of access control lists (ACLs) in filtering network traffic is essential. The exam will also touch upon VPN technologies for secure remote access and site-to-site connectivity, which are vital for protecting data in transit to and from cloud resources.

Authentication, Authorization, and Accounting (AAA) concepts will also be covered, including RADIUS and TACACS+, which are used to control who can access the network and what they can do. Furthermore, understanding how Cisco integrates security across its product portfolio, including security features embedded in switches, routers, and wireless APs, is important. For instance, port security on switches or basic firewall capabilities on routers.

Lastly, be aware of how cloud-managed security solutions, particularly Meraki MX security appliances, offer simplified deployment and management of advanced security features. This includes an understanding of unified threat management (UTM) capabilities and how they protect the network perimeter against various cyber threats in a `Cisco networking cloud` context. This section ensures you grasp the multi-faceted approach to network protection.

Crafting Your Cisco 500-560 Study Guide

A well-structured `Cisco 500-560 study guide` is your most valuable asset in preparing for the On-Premise and Cloud Solutions exam. Effective preparation goes beyond memorizing facts; it involves understanding concepts and applying them. Here's a practical, step-by-step approach to build your study plan for `Cisco networking cloud exam preparation`.

Leverage Official Cisco Resources

Start by exploring the `official Cisco 500-560 exam page` on Cisco's website. This page provides the most accurate and up-to-date information regarding the exam objectives, recommended training, and links to relevant documentation. Cisco also offers an official training course, “Cisco Networking: On-Premise and Cloud Solutions”, which is specifically designed to cover all the exam topics. While no direct URL was provided for the training, seeking this official course is highly recommended as it aligns perfectly with the exam content.

Dive deep into Cisco's documentation for the product families covered in the syllabus – Catalyst switches, ISR routers, Aironet/Catalyst wireless, and especially the Meraki product line. These resources offer detailed explanations and configuration examples that reinforce theoretical knowledge with practical context.

Hands-On Experience is Key

Theoretical knowledge alone isn't enough. For the `best Cisco on-premise cloud training`, strive for hands-on experience. If possible, set up a lab environment with physical or virtual Cisco devices. For Meraki products, take advantage of their free trials or online sandboxes to get familiar with the cloud dashboard and configuration workflows. There's no substitute for configuring VLANs, setting up routing protocols, or deploying Meraki MX security appliances yourself.

Consider using network simulation tools like Cisco Packet Tracer or GNS3 to practice switching and routing configurations. For wireless, explore features in a simulated or small-scale lab. The practical application of concepts will solidify your understanding and help you recall information more effectively during the exam.

Join Study Groups and Online Communities

Collaborating with peers can significantly enhance your learning experience. Join online study groups or forums dedicated to Cisco certifications. Discussing challenging topics, sharing resources, and asking questions can provide different perspectives and clarify complex concepts. Many professionals find that explaining a topic to someone else is one of the best ways to test their own understanding.

For more insights into effective certification preparation, you might find valuable strategies discussed in articles like how to gain success in Cisco exams. Engaging with a community also keeps you motivated and provides a support system throughout your study journey.

Create a Study Schedule and Track Progress

Develop a realistic study schedule based on the exam's syllabus weighting. Allocate more time to Meraki and Wireless topics, given their higher percentages. Break down the `Cisco 500-560 syllabus topics` into manageable chunks and set weekly goals. Use practice questions at the end of each module to assess your comprehension before moving on.

Regularly review previously studied material to reinforce your memory. Flashcards for key terms, protocols, and features can be very effective. Consistent review ensures that information is retained long-term, rather than being forgotten shortly after initial learning. This systematic approach is crucial for a comprehensive `Cisco networking cloud specialization` learning path.

Effective Strategies for Passing the Cisco 500-560 Exam

Passing the Cisco 500-560 OCSE exam requires more than just knowing the material; it demands strategic preparation and smart test-taking skills. Here are some effective strategies to maximize your chances of success and learn `how to pass Cisco 500-560`.

Utilize Cisco 500-560 Practice Questions and Tests

One of the most effective ways to prepare is by taking `Cisco 500-560 practice questions` and `Cisco On-Premise and Cloud Solutions practice tests`. These resources simulate the actual exam environment, helping you become familiar with the question types, format, and time constraints. They are invaluable for identifying your weak areas and understanding where to focus your remaining study efforts.

When reviewing practice test results, don't just look at the correct answers. Analyze why you got certain questions wrong. Was it a lack of understanding, a misinterpretation of the question, or poor time management? Use these insights to refine your study plan. Many reputable platforms offer `Cisco 500-560 practice questions` that mimic the difficulty and style of the real exam.

Understand the Cisco 500-560 Exam Blueprint

Beyond the syllabus topics, take time to truly understand the `Cisco 500-560 exam blueprint`. This document often provides more detail on the specific tasks and knowledge areas associated with each objective. It helps you grasp the depth and breadth of knowledge expected for each topic. Knowing the blueprint ensures you cover all necessary aspects and don't spend too much time on irrelevant details.

The blueprint is your guide to what Cisco deems important for a professional in this domain. Aligning your study material and practice efforts with this blueprint is a key step towards efficient and targeted `Cisco networking cloud exam preparation`.

Time Management During the Exam

With 45-55 questions in 60 minutes, time management is critical. Aim to spend approximately 1 to 1.5 minutes per question. If you encounter a particularly difficult question, make an educated guess, flag it for review if the exam system allows, and move on. Don't get stuck on one question for too long, as this can eat into time for questions you might know.

Practice reading questions carefully to avoid misinterpretations. Pay attention to keywords like “NOT” or “BEST” or “LEAST.” A hurried read can lead to incorrect answers even if you know the underlying concept. Develop a rhythm that allows you to efficiently process each question without rushing through it.

Review and Reinforce

Regular review of all `Cisco 500-560 course content` is vital. This isn't just about reading your notes; it's about actively recalling information. Quiz yourself, explain concepts aloud, or teach them to someone else. This active recall helps solidify memories and ensures you can access the information quickly during the exam.

Pay special attention to the areas where you scored poorly in practice tests. Revisit those `Cisco 500-560 syllabus topics` with fresh eyes. Reinforce your understanding of foundational principles of cloud computing and how they integrate with Cisco's specific implementations. This holistic approach ensures comprehensive `Cisco networking cloud` knowledge.

Understanding the Cisco Networking Express Specialization

The Cisco Networking Express Specialization is a significant recognition for Cisco channel partners, indicating their proficiency in providing fundamental networking solutions. The 500-560 OCSE exam is a mandatory component for achieving this specialization, making it a critical step for partners aiming to enhance their capabilities and market position within the `Cisco networking cloud` ecosystem.

Achieving this specialization demonstrates a partner’s ability to sell, deploy, and support Cisco's core networking technologies. It signifies that the partner has a baseline understanding of how to implement secure and reliable networks for small to medium-sized businesses and enterprise branch offices. This includes expertise in switching, routing, wireless, security, and crucially, cloud-managed solutions like Cisco Meraki.

The `Cisco Networking Express Specialization requirements` extend beyond just the 500-560 exam. Typically, it also involves sales qualifications and other technical certifications, ensuring a well-rounded skill set within the partner organization. This comprehensive approach ensures that specialized partners can effectively articulate the value of Cisco solutions and provide robust technical support to their customers.

For individuals, contributing to this specialization by passing the 500-560 exam makes you an invaluable asset to your organization. It aligns your personal career path with the strategic goals of your company, particularly in the realm of `Cisco networking cloud specialization`. This learning path not only validates your technical skills but also enhances your strategic importance in a partner's ability to capitalize on Cisco's channel programs and incentives. Understanding the career outlook for IT professionals can emphasize the importance of such specializations.

This specialization is more than just a badge; it's a testament to a partner's dedicated investment in Cisco technologies and their commitment to delivering high-quality `Cisco networking cloud solutions`. It empowers partners to unlock greater opportunities, receive better support from Cisco, and ultimately, better serve their client base with cutting-edge networking infrastructure.

Scheduling Your 500-560 Exam

Once you've diligently prepared and feel confident in your `Cisco networking cloud` knowledge, the next step is to schedule your Cisco 500-560 OCSE exam. Cisco partners with Pearson VUE for the delivery of its certification exams, providing a global network of testing centers and online proctoring options.

To schedule your exam, you will need to visit the Pearson VUE website for Cisco exams. From there, you can locate a testing center near you or opt for a convenient online proctored exam, allowing you to take the exam from the comfort of your home or office, provided you meet the technical requirements.

Before scheduling, ensure you have created a Cisco Learning Network account, as your certification status will be managed through this portal. The `Cisco OCSE certification cost` is $300 USD, which will be payable during the scheduling process. It's advisable to schedule your exam a few weeks in advance, especially if you have specific date or time preferences, as slots can fill up quickly.

Review the Pearson VUE policies regarding rescheduling, cancellations, and identification requirements well in advance to avoid any last-minute issues. Being fully informed about these procedures ensures a smooth experience on exam day. Taking this final step brings you closer to earning your Cisco Networking Express Specialization and showcasing your expertise in `Cisco networking cloud` environments.

Conclusion

The Cisco 500-560 Exam: On-Premise and Cloud Solutions (OCSE) is more than just a certification; it's a strategic stepping stone in your journey to becoming a recognized expert in `Cisco networking cloud` technologies. By mastering the core concepts of switching, routing, wireless, Meraki products, and security across hybrid environments, you position yourself at the forefront of modern network infrastructure design and implementation.

This guide has provided a comprehensive roadmap, from understanding the exam's objectives and detailed syllabus to crafting an effective study plan and implementing winning exam strategies. The `Cisco On-Premise and Cloud Solutions certification` validates your ability to articulate, deploy, and support Cisco's innovative solutions, making you an invaluable asset to any organization navigating the complexities of digital transformation.

Embrace the challenge, dedicate yourself to thorough preparation, and leverage all available resources. The knowledge gained and the certification earned will not only boost your career but also contribute significantly to your company's `Cisco Networking Express Specialization` goals. Your commitment to mastering `Cisco networking cloud solutions` will undoubtedly open doors to new opportunities and greater professional growth.

Ready to validate your expertise and advance your career? Start preparing today, and remember to hone your exam preparation skills with proven methods. Your future in `Cisco networking cloud` awaits!

Frequently Asked Questions (FAQs)

1. What is the Cisco 500-560 OCSE exam primarily focused on?

The Cisco 500-560 OCSE exam, or Cisco Networking - On-Premise and Cloud Solutions, primarily focuses on a candidate's foundational knowledge of Cisco's networking solutions across both traditional on-premise environments and modern cloud-managed platforms, particularly Cisco Meraki. It covers switching, routing, wireless, Meraki products, and security features.

2. How long is the Cisco 500-560 exam and how many questions does it have?

The Cisco 500-560 OCSE exam has a duration of 60 minutes and consists of approximately 45-55 multiple-choice questions. This requires candidates to manage their time efficiently to answer all questions within the given period.

3. What is the passing score for the Cisco 500-560 certification exam?

The passing score for the Cisco 500-560 exam is variable, typically falling in the range of 750-850 out of a possible 1000 points. Cisco exams often use an adaptive scoring model, which means the exact passing score can fluctuate slightly.

4. Is the Cisco 500-560 exam required for any specific Cisco specialization?

Yes, the Cisco 500-560 OCSE exam is a key requirement for individuals and partners seeking to achieve the Cisco Networking Express Specialization. This specialization signifies a partner's capability in selling, deploying, and supporting Cisco networking solutions.

5. What kind of training is recommended for the Cisco 500-560 exam?

Cisco recommends its official training course, “Cisco Networking: On-Premise and Cloud Solutions,” which aligns directly with the exam objectives. Additionally, hands-on experience with Cisco hardware and Meraki cloud dashboards, supported by official documentation and practice tests, is highly beneficial for comprehensive preparation.

Saturday, 11 May 2024

Secure Firewall & Multicloud Defense: Secure Connectivity With Simplified Policy Across Clouds

Most of our large customers today have datacenters and leverage multiple clouds to maximize flexibility and agility for meeting their business needs. Traditionally, the security for these environments has rested with different teams, each having their own tools and processes. But as our application and IT environments become more interwoven, the complexity of the environments and the challenge of securing them has massively increased. Siloed tools and teams are now part of the problem, generating new gaps and blind spots. Attackers are growing more sophisticated and taking advantage of these new challenges. In fact, last year, 39% of breaches spanned multiple environments and cost organizations an average of $4.75M per breach globally.

It is time to rethink how organizations approach the hybrid-multicloud security strategy — converging the fabrics between on-premises and cloud network security to foster collaboration across teams and deliver a unified edge security strategy.

Today, we are we’re bringing on-prem and cloud security together into one unified platform through the Cisco Security Cloud to marry the power of Cisco Secure Firewall and Cisco Multicloud Defense. Combined, these solutions provide multi-environment customers with greater visibility and protection across environments, more consistent control to reduce risk, and simplified security policy creation to alleviate complex operations.

This year at RSA Conference 2024, customers can experience where security meets the network with new capabilities between these solutions — as part of our unified security platform.

Multicloud networking: Secure connectivity from ground to cloud


Imagine you have an application on-prem that needs to talk to an application in the cloud, how would you approach this challenge? Traditionally, organizations have had to rely on 3rd party native tools. However, these services can be costly — especially as you scale applications and environments. And as you scale, the complexity increases, reducing visibility and control of critical security functions. Now, by leveraging our unified platform with the Cisco Security Cloud, customers can build these connections in house with secure site-to-cloud and cloud-to-cloud connectivity between applications and environments. With this, organizations will be able to securely scale hybrid cloud operations while reducing cost and maintain visibility and control of their connections and data.

Secure Firewall & Multicloud Defense: Secure Connectivity With Simplified Policy Across Clouds

New network object sharing further simplifies policy creation across multi-environments


In many cases today, organizations are building, deploying, and managing policies in silos. This disparate method strains teams — creating laborious, redundant steps in the policy building process, leads to increased risk of human error and cues the dreaded swivel chair scenario — hopping between numerous tools and platforms to build policies.

At Cisco Live EMEA, we announced general availability of network object sharing for static objects. Today at RSA Conference, we’re reducing multi-environment complexity even further with the ability to now share dynamic objects using our unified management fabric. This gives organizations a single location to pool objects, simplifying policy building and management across environments. Baked into the Cisco Security Cloud platform, this capability empowers organizations to easily share objects between Secure Firewall and Multicloud Defense, reducing complexity, removing duplicative processes, and stopping the pain of maintaining yet another case of siloed operations across separate solutions.

Secure Firewall & Multicloud Defense: Secure Connectivity With Simplified Policy Across Clouds

As we continue to innovate across the Cisco Security Cloud, synergies across the network security portfolio will continue to grow. The launch of these shared capabilities between Cisco Secure Firewall and Cisco Multicloud Defense is a significant step towards converging the fabrics of best-in-class data center and cloud security to protect customers from ground to cloud.

Looking to get started? Understand your risk by signing up for our free Cloud Visibility and Risk Report. Powered by Cisco Defense Orchestrator and Cisco Multicloud Defense, our solutions run alongside your clouds to help you understand your risk with pervasive visibility into assets and connections — our experts then provide you with actionable security insights and recommendations to better protect your infrastructure.

Source: cisco.com

Tuesday, 30 May 2023

To the Cloud and Beyond―A Comprehensive Model for Enhanced NetOps and User Experience

Cloud computing has become wildly popular among IT organizations for a number of reasons, including its ability to enhance efficiency, security, agility, and cost-effectiveness. But now cloud features and principles have also become the building blocks of something even bigger and more all-encompassing: a unified IT operating model that spans people, devices, networks, applications, and things across the digital infrastructure.

With end-to-end visibility and centralized, cloud-based management, IT can monitor, manage, and control an organization’s entire networking, cloud, and security infrastructure. A unified cloud operating model makes it easier for organizations to pivot as their needs change. Organizations can quickly deploy innovative applications, respond to disruptions and threats, and scale performance and capacity. The model is an antidote to separate, complex, operational silos on-premises, on the internet, and in the cloud. The overall goal of the model is to dramatically improve the efficiency, reliability, and resiliency of IT operations, as well as the quality of user experience.

The Need for a Comprehensive Operating Model 


Recent research conducted by IDC has found IT staff worldwide engaged in a struggle with highly specialized, complex, and manual management tools and procedures in use across on-premises, internet, cloud, and security silos. Between all of the silos are management and security gaps. Integration is limited. Efficiency and time-to-market suffer.

Meanwhile, IT is being asked to innovate in the use of applications and data intelligence, to create great and secure user experiences, to scale up or down in response to demand, and to do it all efficiently and cost-effectively.

Enter the cloud operating model.

With the cloud operating model, cloud principles like anywhere access, self-service dashboards, policy automation, end-to-end visibility, microservices, continuous integration, and continuous delivery (CI/CD), and extensibility can be applied across the entire digital infrastructure from access to internet to cloud (Figure 1). That includes all endpoints and systems whether they are on-premises, in the cloud, in remote offices, or mobile.

Cisco Career, Cisco Certification, Cisco Learning, Cisco Tutorial and Materials, Cisco Certification Exam, Cisco Career, Cisco Skill
Figure 1. The Cloud Operating Model

With consistent policies and governance within and across operational domains, the cloud operating model can improve cross-functional collaboration, eliminating disparate processes and disjointed efforts that hamper better business outcomes.

An Ongoing Journey


Achieving a cloud operating model is a journey for organizations requiring a significant shift in how they approach their IT operations:

  • A shift in thinking from viewing cloud and on-premises environments as separate entities to looking at how the best features of both can converge
  • A cultural shift that embraces breaking down silos, promoting collaboration, and encouraging cross-functional innovation
  • New skills, tools, and processes to manage infrastructure, such as automation, DevOps, and agile methodologies
  • Integration of cloud management platforms with legacy systems, which requires careful assessment and a migration strategy

Achieving a cloud operating model is not a one-time event but rather an ongoing journey of continuous improvement across the entire IT environment. Cloud features and a unified management platform provide the means to monitor, optimize, and innovate to help ensure that organizations are getting the most value from their investments.

Where to Begin?


Start by evaluating which cloud principles exist in which domains. At Cisco, we’re developing a new tool that helps organizations define their various infrastructure principles within the access network, software-defined WAN (SD-WAN), and data center. By overlaying principles on infrastructures, an organization can identify opportunities to integrate silos to help meet business and operational objectives.

Some organizations are starting the journey to the cloud operating model by extending SD-WAN connectivity across multiple clouds for simpler IT management and a better application experience. With a distributed SD-WAN, they can apply policy, visibility, control, and zero trust consistently across all clouds, software-as-a-service (SaaS), and middle-mile providers. Other organizations are planning to use this SD-WAN foundation to transition to a secure access service edge (SASE) architecture to connect network and security domains across branches and remote clients.

With our broad cloud and networking platform portfolio, Cisco provides a comprehensive set of solutions with the visibility, consistent policy governance, and insights-driven automation necessary to support an effective cloud operating model. For example, in campus networking, the Cisco Meraki platform supports many key cloud principles.

The Meraki dashboard provides cloud-based management for connected access points and IoT devices, plus monitoring and management of switches. Through the dashboard, configuration and access policies can be defined and automated throughout the network. The dashboard interface is a visual representation of all connected devices, showing the real-time status of each device. And Meraki has a marketplace of partner applications that leverage APIs to extend these capabilities across the network.

Source: cisco.com

Thursday, 8 December 2022

Application Resource Management in Healthcare

Resource Management in Healthcare, Dell EMC Study, Dell EMC Preparation, Dell EMC Career, Dell EMC Skills, Dell EMC Jobs

Four Ways Healthcare Providers Have Benefited from Intersight Workload Optimizer


IT operations teams are like doctors. Doctors practice preventive medicine to help patients keep their health on track. When a patient’s health goes off track, the doctor minimizes symptoms through medication and rest, and they perform assessments to identify the root cause of the ailment.

In a similar way, IT operations teams keep their organizations’ mission-critical applications on track by providing computing, networking, and storage resources. Sometimes an application demonstrates symptoms indicating there’s something wrong (such as sluggish performance). If the root cause is serious enough and goes unaddressed, it can lead to downtime and impact the end user experience.

Treating the symptoms of poor application performance


Too often IT teams spend most of their time addressing the symptoms of underperforming applications or resuscitating them when they go offline. They’re alerted when there’s an issue, but they can’t easily pinpoint the root cause. This means the symptoms get treated to keep applications running, but the underlying cause or causes go untreated, which can lead to recurring application performance issues and costly staff time spent addressing them.

How to stay ahead of application resource issues


Application resource management solutions like Cisco Intersight Workload Optimizer (IWO) provide vital capabilities to help IT teams prevent application resource issues from occurring while optimizing costs to control their budgets.

Cisco Prep, Cisco Tutorial and Material, Cisco Skill, Cisco Jobs, Cisco Certification

Here are four examples where Cisco healthcare customers used application resource management to maintain the health of their organizations’ applications in fiscally responsible ways.

1) Ensuring mission-critical application performance

A healthcare services provider was experiencing performance issues with mission-critical applications. They couldn’t identify where in the stack the issues were originating from, so they used AppDynamics and IWO to gain deep visibility from their applications through their underlying computing infrastructure, particularly into hundreds of virtual machines. The visibility showed them when application performance began to stretch VM workloads and how to optimize their virtual environment to ensure continuous resources for optimal application performance. In addition to providing continuous up-time for their mission-critical applications, the customer has used IWO to optimize workloads in the public cloud and reduce public cloud spend by 40%.

2) Maintaining application performance at a lower cost

1) In order to provide continuous application uptime, a healthcare provider in the midwestern United States uses on-premises infrastructure and hosting services through a public cloud provider. However, the costs for on-premises infrastructure and cloud resources were rising rapidly and not sustainable. Using IWO’s “what-if” scenario planning, Cisco worked with the client’s IT group to demonstrate how they could right-size new server purchases and identify the most cost-effective cloud resources to meet their budget requirements. As a result, the healthcare provider can continue to deliver computing resources to provide experiences their application users expect while delivering tangible cost savings.

2) A healthcare provider in the southeastern United States and Cisco UCS customer needed to improve overall infrastructure availability, specifically by getting better insight into the real-time status of VMs and other computing resources. With a restricted IT budget, they also needed to extend the life of existing systems to reduce their CapEx expenses. Using IWO, the healthcare provider identified an opportunity to reduce the number of hosts by 50% while maintaining the same levels of utilization and avoiding unnecessary CapEx investments. At the same time, the healthcare provider used IWO to ensure workload configurations comply with its policies, which has helped the customer improve its HIPAA compliance posture.

3) Conducting an EHR cloud migration analysis

This healthcare provider needed to refresh its Epic hyperspace environment for its primary electronic health record (EHR) system. Their IT team was considering moving to the EHR provider’s cloud-based IaaS solution. The Cisco team used IWO to conduct a detailed total cost of ownership (TCO)/return on investment (ROI) analysis. The study showed the ability to maintain desired application performance with fewer servers (and less cost) than the EHR provider prescribed. The analysis revealed the healthcare provider would save $500,000 per month over three years, or $18 million, by using an on-premises UCS solution instead of the hosted solution. The healthcare provider also went on to use IWO to continue optimizing its virtual environment for ongoing application resource management and cost containment.

Keep your applications in shape through application resource management


As a healthcare provider, your patients, caregivers, and others rely on your applications. With solutions like IWO at your disposal, you have the power to adopt best practices in application resource management and ensure uptime to deliver the experiences your users expect while gaining cost-containment capabilities. Rise above treating the symptoms of an ailing infrastructure; exercise proactive application resource management with Cisco Intersight Workload Optimizer to keep your applications and infrastructure in outstanding shape.

Source: cisco.com

Saturday, 19 November 2022

Cisco Intersight Gets a New Look

Cisco Intersight, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Certification, Cisco Preparation

New User Interface Signals Milestone for Hybrid Cloud Operations Platform


Cisco Intersight, Cisco’s hybrid cloud operations platform, passed a major milestone with the recent release of its new user interface (UI). The UI introduces Cisco’s new branding for its Cloud Networking and Computing software portfolio, brings Nexus Cloud (Cisco’s cloud-managed platform for networking) into the Intersight platform, and improves readability and task findability.

Consistent User Experience

“One of our priorities for the software-as-a-service offerings in Cisco’s Networking and Computing portfolio is to provide a consistent and familiar user experience, no matter which product someone’s using,” said Jeff New, Cisco Intersight Product Manager. Intersight is the first platform to introduce Cisco’s common UI that will be rolled out across its data center computing, networking, and security solutions to provide a more consistent experience for customers.

Cloud Networking, Newest Intersight Platform Service

Intersight’s new UI also introduces cloud-managed networking as the platform’s newest IT operations service. This signals the next step in the platform’s vision to simplify IT operations through a cloud operations model that extends the principles of the cloud to the entire cloud/network IT stack. Nexus Cloud will debut as a service on Cisco Intersight following its current tech preview.

Cisco Intersight, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Certification, Cisco Preparation
Intersight users can select the IT operations functions they need to perform using the multi-service selector

To easily access Intersight’s services, the new UI introduces a multi-service selector. From the selector, users can choose:

◉ Infrastructure Service – visualize, control, and automate Cisco UCS, HyperFlex, and third-party computing devices

◉ Cloud Orchestrator – automate workflows with a drag-and-drop designer to accelerate delivery of apps and infrastructure

◉ Workload Optimizer – ensure applications get resources when and where needed, at the lowest cost
Nexus Cloud – deploy, manage, and operate your Cisco Nexus networks from the cloud

◉ My Dashboard – personalize a multi-service dashboard using widgets for capabilities across the services on the Intersight platform

◉ System – Claim devices, licensing, identity access management, and other account settings

Intersight users will have access to the functions they have licensed and their corresponding permissions. Once users are in a specific service, they’ll find capabilities in a familiar way.

Command Palette – Get to Actions and Information Quickly

Intersight is a comprehensive solution for hybrid cloud operations with a robust feature set. Intersight users have asked for a faster way to find specific objects in their environments as well as the actions they want to take.

To do this, we’ve introduced the Command Palette. Based on a simple search approach, users can input what they want to do and select from the search results. (“Command K” for Mac users and “Control K” for PC users.) The command palette shows suggestions based on your current context and items you’ve used recently.

Users who took part in the tech preview of the new UI report being pleased with the shortcut to specific tasks they want to execute. This lets them launch operations and begin working in fewer clicks.

Cisco Intersight users can find actions fast using the Command Palette.
Cisco Intersight, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Certification, Cisco Preparation
Users can find actions fast using the Command Palette

The new UI also improves readability. The classic Intersight UI presented information in a dense way with heavy text on a single screen. In the new UI, users will find that readability is improved with more relevant information on individual screens and more space that allows users to focus on what’s most important.

One UI, Multiple Benefits

“The new UI is more than an improved look and feel,” said New. “The release of the new UI marks the next significant milestone on our vision to deliver a flexible hybrid cloud operations platform to help customers simplify IT operations. Cloud networking joins the suite of Intersight services, with more to come. And through the common UI, we’re lowering the learning curve for customers of Cisco software so it’s easier to get up and running.”

Source: cisco.com

Thursday, 17 November 2022

Vacationing and IT Operations Part 3: Manage the Change

You are looking forward to a day of island hopping. The cruise has been booked, swimming trunks and snorkels packed – you are ready to dive right in. Alas, on the day of the trip the weather gods decided to rain on your parade. Literally. Now what? You can’t afford to waste a precious vacation day cooped up in a hotel room but it’s too late to plan an alternative.

Continuously Optimize for changes


Thankfully, your hotel has an awesome concierge desk. They have been monitoring the weather forecast and proactively created a few alternate options should things not go according to plan. Within minutes of your cruise being canceled, you get a call from the concierge desk offering day passes to the local indoor amusement park. Wave pool, bowling, rides, food court – the whole nine yards. Wouldn’t it be great if your IT infrastructure was this smart in handling change?

Change Management


Change is the only constant. Your IT team knows this too well. Maintaining the health of an ever-changing hybrid cloud environment is not easy: multiple layers of heterogeneous infrastructure, distributed workloads, and applications across different platforms, dynamically changing, require constant monitoring, and decisions about cost, performance and compliance are made at the speed of the cloud. This is a challenge beyond the human scale, and it requires the power of data and analytics to solve.

Transform data into insights across your entire environment


A key part of the value proposition of Intersight is how the platform optimizes your environment and constantly adapts to changes.

Cisco Career, Cisco Tutorial and Materials, Cisco Prep, Cisco Preparation, Cisco Certification
Increase your situational awareness and remediate faster to stay ahead of problems

Intersight leverages intelligence across all layers


Starting with Cisco Intersight Infrastructure Services, hardware and firmware are monitored to help ensure that your systems are always compliant with the Cisco Hardware Compatibility List (HCL)—any unsupported configurations cause automatic alerts. At the same time, Cisco Intersight Workload Optimizer analyzes and correlates telemetry across your full stack, from your physical servers to virtualized resources, Kubernetes clusters, and application components, wherever they are, to visualize application and infrastructure dependencies.

In addition, Cisco Intersight offers an always-on connection to the Cisco Technical Assistance Center (TAC), constantly monitoring your environment to help identify configuration issues before they become problems. It watches for anomalous infrastructure events, capturing log information and providing centralized alerts about failure notifications or policy violations.

Reduce risk and costs – optimize performance


Cisco Career, Cisco Tutorial and Materials, Cisco Prep, Cisco Preparation, Cisco Certification
Automate complex workload placement decisions with intelligent recommendations

All this telemetry and intelligence captured by Intersight across the different layers of your stack is used to automate tasks and decisions that would be otherwise manual, enabling your environment to truly scale. Using an AI-powered recommendation engine, Intersight continuously assures application performance by automating scaling and placement actions, provisioning resources to meet demand, or correcting misconfigurations to avoid disruptions and unnecessary costs.

Intersight gets smarter over time and adapts better to your unique needs with historical data feeds, producing better real-time recommendations and advanced scenario modelling outputs. Examples of automated tasks include applying security patches and operating system upgrades for physical servers, to licensing for databases on your virtual machines, to resizing and moving workloads for performance and cost, auto-scaling Kubernetes clusters, or applying user access policies across all layers of infrastructure etc.

Finally, Intersight can automatically generate and forward Cisco TAC support cases when required and even raise service requests and return material authorizations (RMAs) automatically.

With complete visibility into on-premises and public cloud application requirements, resource utilization, availability, and costs, Cisco Intersight can improve your overall situational awareness, reduce risk and cost, and free your teams to focus on more important things.

The show must go on


Cisco Intersight can help you smoothly manage disruptions and reduce risk and cost, through complete visibility into on-premises and public cloud application requirements resource utilization, and availability. Allowing your teams to free their focus for more important things, like soaking up that awesome wave pool. Rain or shine.

Source: cisco.com

Tuesday, 8 November 2022

Introducing Cisco Cloud Network Controller on Google Cloud Platform – Part 3

Part 1 and Part 2 of this blog series covered native cloud networking and firewall rules automation on GCP, and a read through is recommended for completeness. This final post of the series is about enabling external access for cloud resources. More specifically, it will focus on how customers can enable external connectivity from and to GCP, using either Cloud Native Router or Cisco Cloud Router (CCR) based on Cisco Catalyst 8000v, depending on use case.

By expanding previous capabilities, Cisco Cloud Network Controller (CNC) will provision routing, automate VPC peering between infra and user VPCs, and BGP IPSec connectivity to external networks with only a few steps using the same policy model.

Scenario


This scenario will leverage the existing configuration built previously represented by network-a and network-b VPCs. These user VPCs will be peered with the infra VPC in a hub and spoke architecture, where GCP cloud native routers will be provisioned to establish BGP IPSec tunnels with an external IPSec device. The GCP cloud native routers are composed by the combination of a Cloud Router and a High-availability (HA) Cloud VPN gateway.

The high-level topology below illustrates the additional connections automated by Cisco CNC.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

Provisioning Cloud Native Routers


The first step is to enable external connectivity under Region Management by selecting in which region cloud native routers will be deployed. For this scenario, they will be provisioned in the same region as the Cisco CNC as depicted on the high-level topology. Additionally, default values will be used for the IPSec Tunnel Subnet Pool and BGP AS under the Hub Network representing the GCP Cloud Router.

The cloud native routers are being provisioned purposely on a different region to illustrate the ability of having a dedicated hub network with external access. However, they could have been deployed on the same region as the user VPCs.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

Note: a brief overview of the Cisco CNC GUI was provided on Part 1.

Enabling External Networks


The next step is to create an External Network construct within the infra tenant. This is where an external VRF is also defined to represent external networks connected to on-premises data centers or remote sites. Any cloud VRF mapped to existing VPC networks can leak routes to this external VRF or can get routes from it. In addition to the external VRF definition, this is also where VPN settings are entered with the remote IPSec peer details.

The configuration below illustrates the stitching of the external VRF and the VPN network within the region where the cloud native routers are being provisioned in the backend. For simplicity, the VRF was named as “external-vrf” but in a production environment, the name should be defined wisely and aligned to the external network as to improve operations.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

The VPN network settings require public IP of the remote IPSec device, IKE version, and BGP AS. As indicated earlier, the default subnet pool is being used.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

Once the external network is created, Cisco CNC generates a configuration file for the remote IPSec device to establish BGP peering and IPSec tunnels with the GCP cloud native routers. Below is the option to download the configuration file.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

Configuring External IPSec Device


As the configuration file provides most of the configuration required for the external IPSec device, customization is needed only on tunnel source interface and routing settings where applicable to match local network requirements. In this example, the remote IPSec device is a virtual router using interface GigabitEthernet1. For brevity, only one of the IPSec tunnels config is shown below along with all the other config generated by Cisco CNC.

vrf definition external-vrf
    rd 100:1
    address-family ipv4
    exit-address-family

interface Loopback0
    vrf forwarding external-vrf
    ip address 41.41.41.41 255.255.255.255

crypto ikev2 proposal ikev2-1
    encryption aes-cbc-256 aes-cbc-192 aes-cbc-128
    integrity sha512 sha384 sha256 sha1
    group 24 21 20 19 16 15 14 2

crypto ikev2 policy ikev2-1
    proposal ikev2-1

crypto ikev2 keyring keyring-ifc-3
    peer peer-ikev2-keyring
        address 34.124.13.142
        pre-shared-key 49642299083152372839266840799663038731

crypto ikev2 profile ikev-profile-ifc-3
    match address local interface GigabitEthernet1
    match identity remote address 34.124.13.142 255.255.255.255
    identity local address 20.253.155.252
    authentication remote pre-share
    authentication local pre-share
    keyring local keyring-ifc-3
    lifetime 3600
    dpd 10 5 periodic

crypto ipsec transform-set ikev-transport-ifc-3 esp-gcm 256
    mode tunnel

crypto ipsec profile ikev-profile-ifc-3
    set transform-set ikev-transport-ifc-3
    set pfs group14
    set ikev2-profile ikev-profile-ifc-3

interface Tunnel300
    vrf forwarding external-vrf
    ip address 169.254.0.2 255.255.255.252
    ip mtu 1400
    ip tcp adjust-mss 1400
    tunnel source GigabitEthernet1
    tunnel mode ipsec ipv4
    tunnel destination 34.124.13.142
    tunnel protection ipsec profile ikev-profile-ifc-3

ip route 34.124.13.142 255.255.255.255 GigabitEthernet1 192.168.0.1

router bgp 65002
    bgp router-id 100
   bgp log-neighbor-changes
    address-family ipv4 vrf external-vrf
        network 41.41.41.41 mask 255.255.255.255
        neighbor 169.254.0.1 remote-as 65534
        neighbor 169.254.0.1 ebgp-multihop 255
        neighbor 169.254.0.1 activate

Verifying External Connectivity status


Once configuration is applied, there are a few ways to verify BGP peering and IPSec tunnels between GCP and external devices: via CLI on the IPSec device itself and via Cisco CNC GUI on the External Connectivity dashboard.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

In the GCP console (infra project), under Hybrid Connectivity, it shows both the IPSec and BGP sessions are established accordingly by the combination of a Cloud Router and an HA Cloud VPN gateway automated by Cisco CNC, upon definition of the External Network. Note that the infra VPC network is named as overlay-1 by default as part of the Cisco CNC deployment from the marketplace.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

Route Leaking Between External and VPC Networks


Now that BGP IPSec tunnels are established, let’s configure inter-VRF routing between external networks and existing user VPC networks from previous sections. This works by enabling VPC peering between the user VPCs and the infra VPC hosting VPN connections, which will share these VPN connections to external sites. Routes received on the VPN connections are leaked to user VPCs, and user VPC routes are advertised on the VPN connections.

Using inter-VRF routing, the route is leaked between the external VRF of the VPN connections and the cloud local user VRFs. The configuration below illustrates route leaking from external-vrf to network-a.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

The reverse route leaking configuration from network-a to external-vrf is filtered with Subnet IP to show granularity. Also, the same steps were performed for network-b but not depicted for brevity.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

In addition to the existing peering between network-a and network-b VPCs, now both user VPCs are also peered with the infra VPC (overlay-1) as depicted on the high-level topology.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

By exploring one of the peering connection details, it is possible to see the external subnet 41.41.41.41/32 in the imported routes table.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

On the remote IPSec device, the subnets from network-a and network-b VPCs are learned over BGP peering as expected.

remote-site#sh bgp vpnv4 unicast vrf external-vrf
<<<output omitted for brevity>>>
     Network          Next Hop            Metric LocPrf Weight Path
Route Distinguisher: 100:1 (default for vrf external-vrf)
 *>   41.41.41.41/32   0.0.0.0                  0         32768 i
 *    172.16.1.0/24    169.254.0.5            100             0 65534 ?
 *>                    169.254.0.1            100             0 65534 ?
 *    172.16.128.0/24  169.254.0.5            100             0 65534 ?
 *>                    169.254.0.1            100             0 65534 ?
remote-site#

Defining External EPG for the External Network


Up to this point, all routing policies were automated by Cisco CNC to allow external connectivity to and from GCP. However, firewall rules are also required for end-to-end connectivity. This is accomplished by creating an external EPG using subnet selection as the endpoint selector to represent external networks. Note that this external EPG is also created within the infra tenant and associated to the external-vrf created previously.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

The next step is to apply contracts between the external EPG and the previously created cloud EPGs to allow communication between endpoints in GCP and external networks, which in this scenario is represented by 41.41.41.41/32 (loopback0 on remote IPSec device). As this is happening across different tenants, the contract scope is set to global and exported from the engineering tenant to the infra tenant and vice-versa, if allowing traffic to be initiated from both sides.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials
To the cloud connectivity

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials
From the cloud connectivity

On the backend, the combination of contracts and filters translates into proper GCP firewall rules, as covered in details on Part 2 of this series. For brevity, only the outcome is provided below.

remote-site#ping vrf external-vrf 172.16.1.2 source lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.1.2, timeout is 2 seconds:
Packet sent with a source address of 41.41.41.41 !!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 84/84/86 ms

remote-site#ping vrf external-vrf 172.16.128.2 source lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.128.2, timeout is 2 seconds:
Packet sent with a source address of 41.41.41.41 !!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 132/133/138 ms

root@web-server:/home/marinfer# ping 41.41.41.41
PING 41.41.41.41 (41.41.41.41) 56(84) bytes of data.
64 bytes from 41.41.41.41: icmp_seq=1 ttl=254 time=87.0 ms
64 bytes from 41.41.41.41: icmp_seq=2 ttl=254 time=84.9 ms
64 bytes from 41.41.41.41: icmp_seq=3 ttl=254 time=83.7 ms
64 bytes from 41.41.41.41: icmp_seq=4 ttl=254 time=83.8 ms
root@web-server:/home/marinfer# 

root@app-server:/home/marinfer# ping 41.41.41.41
PING 41.41.41.41 (41.41.41.41) 56(84) bytes of data.
64 bytes from 41.41.41.41: icmp_seq=1 ttl=254 time=134 ms
64 bytes from 41.41.41.41: icmp_seq=2 ttl=254 time=132 ms
64 bytes from 41.41.41.41: icmp_seq=3 ttl=254 time=131 ms
64 bytes from 41.41.41.41: icmp_seq=4 ttl=254 time=136 ms
root@app-server:/home/marinfer#

Advanced Routing Capabilities with Cisco Cloud Router


Leveraging native routing capabilities as demonstrated may suffice for some specific use cases and be limited for others. Therefore, for more advanced routing capabilities, Cisco Cloud Routers can be deployed instead. The provisioning process is relatively the same with CCRs also instantiated within the infra VPC in a hub and spoke architecture. Besides having the ability to manage the complete lifecycle of the CCRs from the Cisco CNC, customers can also choose different tier-based throughput options based on requirements.

One of the main use cases for leveraging Cisco Cloud Routers is the BGP EVPN support across different cloud sites running Cisco CNC, or for hybrid cloud connectivity with on-prem sites when policy extension is desirable. The different inter-site uses cases are being documented on specific white papers, and below is a high-level topology illustrating the architecture.

Cisco Cloud Network, Google Cloud Platform, Cisco Career, Cisco Skills, Cisco Jobs, Cisco Tutorial and Materials, Cisco Learning, Cisco Tutorial and Materials

Source: cisco.com