Thursday, 13 June 2019

3 Ways Intent-Based Networking Fulfills Business Intent with Multidomain Integration

Today, 'cisco' takes major steps to link the treating of these domains together.

Each domain has its own purpose


So why do we want these integrations? Why don't you simply have the whole enterprise network run like a single fabric?

Within the real life, each network domain serves a distinctive group of needs. The campus network handles wireless and wired clients rich in mobility demands and different identity mechanisms. The WAN finds the best route from user to application with the multiple connectivity options. The information center delivers high east-west bandwidth and control, integrating with virtual machine and container environments.



It isn't enough to possess intent-based networking only in those silos.


Make a situation where the application service needs, consumer experience needs, or segmentation coverage is converted and put on just one network domain - and never others. What can which means that for the efficiency and security needs? Your IT teams for each one of the domains will have to share, translate, and implement policy in own environments. All by hand. Using the rapid pace of change, would that be also possible?

We have to stitch these fabrics together - instantly and seamlessly - to offer the full business intent.

The automated integration of policy between domains is the easiest method to preserve domain uniqueness but still provide consistency and management. With policy integration, each domain, while functioning individually, can collaborate with other people for the advantage of the whole network. You are able to define an insurance policy once, put it on everywhere, and monitor it systematically to make sure it is realizing its business intent.

Towards an intent-based architecture


'cisco' takes steps to stitch the domains together. Not by looking into making them identical and getting them lower towards the cheapest common denominator, but by getting them share policy elements, to enable them to cooperate with one another to satisfy the collective intent.

Segmentation policy integrations


Segmenting a network reduces congestion, improves security and compliance, and possesses network problems. Within the campus, Cisco’s SD-Access solution uses (and improves on) fraxel treatments to group users and devices inside the segments it makes based on their access rights. Similarly, 'cisco' ACI creates categories of similar applications within the data center.

When integrated, SD-Access and ACI exchange their groupings and supply one another a comprehension to their access policies. With this particular understanding, each one of the domains can map user groups with applications, jointly enforce policies, and block unauthorized use of applications.

In another segmentation policy integration, 'cisco' SD-WAN connects with SD-Access and distributes user and device groups between an organization’s campus and branches, covering all of them inside a seamless access fabric. Access policies based on SD-Access now apply consistently across all of the organization’s sites.

These two policy integrations together allow uniform access controls to be relevant to users, devices, and applications no matter where they connect with the network, or are located and just how they move between sites, or between data center and cloud. The integrations assist in avoiding the complex configurations and frequent changes that might be needed to offer the same objectives.

Consider for example an IoT installation. There might be a large number of IoT devices distributed through the enterprise, and applications within the data center they access. With segmentation policy integrations between SD-Access, SD-WAN, and ACI, the network can limit the access of those devices to simply individuals applications, wherever the devices and applications reside, where they move.

Application experience policy integration


Making certain that users have a very good quality of expertise once they run applications and access data in data centers and clouds is really a high priority for this. It's usually been difficult to carry it out finish-to-finish.

With policy integration between ACI and SD-WAN, application SLAs could be defined within the data center and propagated instantly to SD-WAN, which could then correctly prioritize the traffic because it travels to users in campus and branches. The SLA propagation can help to save network operators from getting to define these parameters by hand in SD-WAN increase them each time the applying or small business change.

Returning to our IoT example, this kind of integration would make sure that any urgent action that should be conveyed from a tool and the controlling application is prioritized with the SD-WAN.

Security across domains


Security should be built-into systems. It can’t just run in the perimeter. Integration between security and also the network enables security applications and also the network to operate together to lessen time for you to prevent, identify, and mitigate threats.

Cisco’s security applications are pervasive and built-in into campus, branch, WAN, data center, co-location centers, and cloud. They safeguard users, wherever they could be, because they connect to the internet or applications running within their data centers, hybrid clouds, or with a SaaS provider.

No comments:

Post a Comment