ããã§ãCiscoããŒããã©ãªãªã«SD-WANãç»å Žããåã«ãDMVPNãšPfRãCisco IWANïŒIntelligent WANïŒã¢ãŒããã¯ãã£ã®éèŠãªéšåãæ§æããŠããããšãããã«äºçŽããå¿ èŠããããŸããããã¯ãæ¬æ ŒçãªSD-WANãã¯ãããžãŒã®å身ã衚ããŠããŸãã解決ãããåé¡ãšãããã解決ããæ¹æ³ã®äž¡æ¹ã®äžè¬çãªé¡äŒŒæ§ã«ãããããããIWANã¯SD-WANã«å¿ èŠãªã¬ãã«ã®èªååãæè»æ§ãããã³ã¹ã±ãŒã©ããªãã£ããŸã åããŠããããæéã®çµéãšãšãã«IWANã®éçºã¯å€§å¹ ã«æžå°ããŸãããåæã«ãIWANèªäœãæ§æãããã¯ãããžãŒã¯æ¶æ» ããŠããããå€ãã®ã客æ§ãææ°ã®æ©åšãå«ããããããåŒãç¶ã䜿çšããŠããŸãããã®çµæãè峿·±ãç¶æ³ãçºçããŸãããåãCiscoæ©åšã䜿çšãããšã顧客ã®èŠä»¶ãšæåŸ ã«å¿ããŠãæé©ãªWANãã¯ãããžãŒïŒã¯ã©ã·ãã¯ãDMVPN + PfRããŸãã¯SD-WANïŒãéžæã§ããŸãã
ãã®èšäºã¯ãCisco SD-WANããã³DMVPNãã¯ãããžãŒïŒããã©ãŒãã³ã¹ã«ãŒãã£ã³ã°ã®æç¡ã«ãããããïŒã®ãã¹ãŠã®æ©èœã詳现ã«åæããããšãæå³ããŠããŸãããããã«ã€ããŠã¯ãèšå€§ãªéã®å©çšå¯èœãªããã¥ã¡ã³ããšè³æããããŸããäž»ãªã¿ã¹ã¯ã¯ããããã®ãã¯ãããžãŒéã®äž»ãªéããè©äŸ¡ããããšã§ããããããããã§ãããããã®éãã«ã€ããŠèª¬æããåã«ããã¯ãããžãŒèªäœãç°¡åã«æãåºããŠã¿ãŸãããã
Cisco DMVPNãšã¯äœã§ããïŒãªããããå¿ èŠãªã®ã§ããïŒ
Cisco DMVPNã¯ãã€ã³ã¿ãŒãããïŒ=éä¿¡ãã£ãã«ã®æå·åã䜿çšïŒãå«ãä»»æã®ã¿ã€ãã®éä¿¡ãã£ãã«ã䜿çšããŠãäŒæ¥ã®ã»ã³ãã©ã«ãªãã£ã¹ã®ãããã¯ãŒã¯ãžã®ãªã¢ãŒããã©ã³ããããã¯ãŒã¯ã®åçïŒ=ã¹ã±ãŒã©ãã«ïŒæ¥ç¶ã®åé¡ã解決ããŸããæè¡çã«ã¯ãããã¯ããã¹ã¿ãŒãïŒããã¢ã³ãã¹ããŒã¯ïŒã¿ã€ãã®è«çããããžã䜿çšããŠããã€ã³ãããŒãã«ããã€ã³ãã¢ãŒãã§ä»®æ³åãªãŒããŒã¬ã€L3VPNãäœæããããšã«ãã£ãŠå®çŸãããŸãããããè¡ãããã«ãDMVPNã¯æ¬¡ã®ãã¯ãããžãŒã®çµã¿åããã䜿çšããŸãã
- IPã«ãŒãã£ã³ã°
- ãã«ããã€ã³ãGREãã³ãã«ïŒmGREïŒ
- ãã¯ã¹ãããã解決ãããã³ã«ïŒNHRPïŒ
- IPSecæå·ãããã¡ã€ã«
MPLS VPNãã£ãã«ã䜿çšããåŸæ¥ã®ã«ãŒãã£ã³ã°ãšæ¯èŒããCiscoDMVPNã®äž»ãªå©ç¹ã¯äœã§ããïŒ
- â , IP- , ( ) ( )
- . â , â ( )
- IP- . mGRE , . , .
Cisco Performance Routing ?
ãã©ã³ãéãããã¯ãŒã¯ã§DMVPNã䜿çšããå Žåã1ã€ã®éåžžã«éèŠãªè³ªåãæªè§£æ±ºã®ãŸãŸã§ããçµç¹ã«ãšã£ãŠéèŠãªãã©ãã£ãã¯ã®èŠä»¶ã«æºæ ããŠãããã©ãããåDMVPNãã³ãã«ã®ç¶æ ãåçã«è©äŸ¡ãããã®è©äŸ¡ã«åºã¥ããŠãåã«ãŒãã£ã³ã°ãåçã«æ±ºå®ããæ¹æ³ãæããŠãã ãããå®éããã®éšåã®DMVPNã¯ãåŸæ¥ã®ã«ãŒãã£ã³ã°ãšããã»ã©éãã¯ãããŸãããæåã®æ¹æ³ã¯ãçºä¿¡æ¹åã®ãã©ãã£ãã¯ã«åªå é äœãä»ããQoSã¡ã«ããºã ãæ§æããããšã§ããããã¹å šäœã®ç¶æ ãäžåºŠã«èæ ®ã«å ¥ããããšã¯ã§ããŸããã
ãããŠããã£ãã«ãå®å šã§ã¯ãªãéšåçã«å£åããå Žåã¯ã©ãããã°ããã§ããïŒãããæ€åºããŠè©äŸ¡ããæ¹æ³ã¯ïŒ DMVPNèªäœã¯ãããè¡ãããšãã§ããŸããããã©ã³ããæ¥ç¶ãããã£ãã«ãããŸã£ããç°ãªããã¯ãããžãŒã䜿çšããŠãŸã£ããç°ãªãéä¿¡äºæ¥è ãééã§ããããšãèãããšããã®ã¿ã¹ã¯ã¯éåžžã«ç°¡åã§ã¯ãããŸããããããŠããããCisco Performance Routingãã¯ãããžãŒãæãã®æãå·®ã䌞ã¹ãå Žæã§ããããã®æç¹ã§ãã§ã«ããã€ãã®éçºæ®µéãçµãŠããŸããã
Cisco Performance RoutingïŒä»¥äžãPfRïŒã®ã¿ã¹ã¯ã¯ããããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠéèŠãªäž»èŠãªã¡ããªãã¯ïŒé å»¶ãé å»¶å€åïŒãžãã¿ïŒãããã³ãã±ããæå€±ïŒããŒã»ã³ãïŒïŒã«åºã¥ããŠããã©ãã£ãã¯ãããŒã®ãã¹ïŒãã³ãã«ïŒã®ç¶æ ãæž¬å®ããããšã§ãã..ãããã«ã䜿çšåž¯åå¹ ãæž¬å®ã§ããŸãããããã®æž¬å®ã¯å¯èœãªéããªã¢ã«ã¿ã€ã ã«è¿ãæ¹æ³ã§è¡ãããä¿èšŒãããŠããŸãããããã®æž¬å®ã®çµæã«ãããPfRã䜿çšããã«ãŒã¿ãŒã¯ãç¹å®ã®ã¿ã€ãã®ãã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ã倿Žããå¿ èŠæ§ã«ã€ããŠåçã«æ±ºå®ã§ããŸãã
ãããã£ãŠãDMVPN / PfRãçµã¿åãããåé¡ã¯æ¬¡ã®ããã«ç°¡åã«èª¬æã§ããŸãã
- ã客æ§ãWANãããã¯ãŒã¯äžã®ä»»æã®éä¿¡ãã£ãã«ã䜿çšã§ããããã«ããŸã
- ãããã®ãã£ãã«ã§éèŠãªã¢ããªã±ãŒã·ã§ã³ã®å¯èœãªéãæé«ã®å質ã確ä¿ãã
Cisco SD-WANãšã¯äœã§ããïŒ
Cisco SD-WANã¯ãSDNã¢ãããŒãã䜿çšããŠçµç¹ã®WANãæ§ç¯ããã³éçšãããã¯ãããžãŒã§ããç¹ã«ãããã¯ããã¹ãŠã®ãœãªã¥ãŒã·ã§ã³ã³ã³ããŒãã³ãã®éäžåããããªãŒã±ã¹ãã¬ãŒã·ã§ã³ãšèªåæ§æãæäŸãããããããã³ã³ãããŒã©ãŒïŒãœãããŠã§ã¢èŠçŽ ïŒã®äœ¿çšãæå³ããŸããæšæºã®SDNïŒã¯ãªãŒã³ã¹ã¬ãŒãã¹ã¿ã€ã«ïŒãšã¯ç°ãªããCisco SD-WANã¯äžåºŠã«è€æ°ã®ã¿ã€ãã®ã³ã³ãããŒã©ãŒã䜿çšãããããããç¬èªã®åœ¹å²ãæãããŸããããã¯ãããåªããã¹ã±ãŒã©ããªãã£ãšå°ççåé·æ§ãæäŸããããã«æå³çã«è¡ãããŸãã
SD-WANã®å Žåããã¹ãŠã®ã¿ã€ãã®ãã£ãã«ã䜿çšããããžãã¹ã¢ããªã±ãŒã·ã§ã³ã®åäœãä¿èšŒããã¿ã¹ã¯ã¯æ®ããŸãããåæã«ããã®ãããªãããã¯ãŒã¯ã®èªååãã¹ã±ãŒã©ããªãã£ãã»ãã¥ãªãã£ãããã³æè»æ§ã«å¯ŸããèŠä»¶ãé«ãŸããŸãã
éãã®è°è«
ãããã®ãã¯ãããžãŒã®éããåæãå§ãããšã次ã®ããããã®ã«ããŽãªã«åé¡ãããŸãã
- ã¢ãŒããã¯ãã£ã®éã-ãœãªã¥ãŒã·ã§ã³ã®ããŸããŸãªã³ã³ããŒãã³ãéã§æ©èœãã©ã®ããã«åæ£ããããã®ãããªã³ã³ããŒãã³ãã®çžäºäœçšã¯ã©ã®ããã«ç·šæãããããã¯ãã¯ãããžãŒã®æ©èœãšæè»æ§ã«ã©ã®ããã«åœ±é¿ããŸããïŒ
- æ©èœæ§-ãããã¯ãããžãŒã§ã§ããããšãå¥ã®ãã¯ãããžãŒã§ã¯ã§ããªãããšã¯äœã§ããïŒãããŠããã¯ãšãŠãéèŠã§ããïŒ
ã¢ãŒããã¯ãã£ã®éãã¯äœã§ããïŒãããã¯éèŠã§ããïŒ
æå®ãããåãã¯ãããžãŒã«ã¯å€ãã®ãå¯åéšåããããããããã¯åœ¹å²ã ãã§ãªããçžäºäœçšã®ååãç°ãªããŸãããœãªã¥ãŒã·ã§ã³ã®ã¹ã±ãŒã©ããªãã£ãéå®³èæ§ãããã³å šäœçãªå¹çã¯ããããã®ååãšãœãªã¥ãŒã·ã§ã³ã®äžè¬çãªä»çµã¿ãã©ãã ãããèããŠãããã«çŽæ¥äŸåããŸãã
ã¢ãŒããã¯ãã£ã®ããŸããŸãªåŽé¢ã«ã€ããŠè©³ããèŠãŠãããŸãããã
ããŒã¿ãã¬ãŒã³ã¯ãéä¿¡å ãšå®å ã®éã§ãŠãŒã¶ãŒãã©ãã£ãã¯ã転éãããœãªã¥ãŒã·ã§ã³ã®äžéšã§ãã DMVPNããã³SD-WANã§ã¯ãéåžžããã«ããã€ã³ãGREãã³ãã«ã«åºã¥ããŠã«ãŒã¿ãŒèªäœã«åãæ¹æ³ã§å®è£ ãããŸããéãã¯ããããã®ãã³ãã«ã«å¿ èŠãªãã©ã¡ãŒã¿ã®ã»ãããã©ã®ããã«åœ¢æããããã§ãã
- DMVPN/PfR â «» Hub-n-Spoke. Hub Spoke Hub, NHRP data-plane . , Hub, , / WAN- .
- ã§SD-WANã¯ãã³ã³ãããŒã«ãã¬ãŒã³ïŒOMPãããã³ã«ïŒãšãªãŒã±ã¹ãã¬ãŒã·ã§ã³ã»ãã¬ãŒã³ïŒã³ã³ãããŒã©çºèŠããã³NATãã©ããŒãµã«ã¿ã¹ã¯ã®vBondã³ã³ãããŒã©ãšã®çžäºäœçšïŒã«åºã¥ããŠç¢ºç«ããããã³ãã«ã®ãã©ã¡ãŒã¿ãçºèŠããããã®å®å šã«åçã¢ãã«ã§ãããã®å Žåãéãåãããããããžã¯ãéå±€çãªããããžãå«ããä»»æã®ããããžã«ããããšãã§ããŸãã確ç«ãããéãåãããã³ãã«ããããžå ã§ãåã ã®VPNïŒVRFïŒã®è«çããããžãæè»ã«æ§æã§ããŸãã
ã³ã³ãããŒã«ãã¬ãŒã³-ãœãªã¥ãŒã·ã§ã³ã³ã³ããŒãã³ãéã®ã«ãŒãã£ã³ã°ããã³ãã®ä»ã®æ å ±ã®äº€æããã£ã«ã¿ãªã³ã°ãããã³å€æŽã®æ©èœã
- DMVPN/PfR â Hub Spoke. Spoke . , Hub control-plane data-plane, Hub , .
- ã§SD-WAN -ã³ã³ãããŒã«ãã¬ãŒã³ã¯ãã«ãŒã¿éã§çŽæ¥è¡ãããããšã¯ãããŸãã-çžäºäœçšã¯ãOMPãããã³ã«ã«åºã¥ããŠãããå¿ ããããã©ã³ã¹ãå°ççåé·æ§ããã³ã·ã°ããªã³ã°è² è·ã®éäžå¶åŸ¡ã®å¯èœæ§ãæäŸvSmartã³ã³ãããŒã©ã®å¥ã®ç¹æ®ãªã¿ã€ããä»ããŠè¡ãããŸããOMPãããã³ã«ã®ãã1ã€ã®æ©èœã¯ãæå€±ã«å¯Ÿãã倧ããªèæ§ãšãã³ã³ãããŒã©ãŒãšã®éä¿¡ãã£ãã«ã®é床ããã®ç¬ç«æ§ã§ãïŒãã¡ããã劥åœãªå¶éå ã§ïŒãããã¯ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ãããããªãã¯ã¯ã©ãŠããŸãã¯ãã©ã€ããŒãã¯ã©ãŠãã§SD-WANã³ã³ãããŒã©ãŒããã¹ãããå Žåã«ãåæ§ã«æåããŸãã
ããªã·ãŒãã¬ãŒã³-WANã§ã®ãã©ãã£ãã¯å¶åŸ¡ããªã·ãŒã®å®çŸ©ãé åžãããã³å®æœãæ åœãããœãªã¥ãŒã·ã§ã³ã®äžéšã
- DMVPN â (QoS), CLI Prime Infrastructure.
- DMVPN/PfR â PfR Master Controller (MC) CLI MC. , data-plane. , . IP- Hub Spoke. MC DMVPN . ( ) Prime Infrastructure . â â .
- SD-WAN â Cisco vManage ( ). vSmart ( ). data-plane , .. .
â , â , , ..
Orchestration- plane-ã³ã³ããŒãã³ããçžäºã«åçã«æ€åºããåŸç¶ã®çžäºäœçšãæ§æããã³èª¿æŽã§ããããã«ããã¡ã«ããºã ã
- DMVPN / PfRã¯ãã«ãŒã¿ã«ãã£ãŠçžäºçºèŠã¯ãããè£ çœ®ã®éçãªæ§æãšã¹ããŒã¯è£ 眮ã®å¯Ÿå¿ããæ§æã«åºã¥ããŠããŸããåçæ€åºã¯ãããæ¥ç¶ãã©ã¡ãŒã¿ãŒãããã€ã¹ã«éä¿¡ããã¹ããŒã¯ã«å¯ŸããŠã®ã¿çºçããŸããããã€ã¹ã¯ãã¹ããŒã¯æ§æã§äºåæ§æãããŠããŸããIPæ¥ç¶ããªããšãå°ãªããšã1ã€ã®ãããæã€ã¹ããŒã¯ã¯ããŒã¿ãã¬ãŒã³ãŸãã¯ã³ã³ãããŒã«ãã¬ãŒã³ã圢æã§ããŸããã
- SD-WAN vBond, ( vManage/vSmart) IP-.
â - vBond. â ( ) vBond, vBond vManage vSmart ( ), .
次ã®ã¹ãããã§ã¯ãæ°ããã«ãŒã¿ãŒã¯ãvSmartã³ã³ãããŒã©ãŒãšã®OMP亀æãä»ããŠããããã¯ãŒã¯å ã®æ®ãã®ã«ãŒã¿ãŒã«ã€ããŠåŠç¿ããŸãããããã£ãŠãã«ãŒã¿ãŒã¯ãæåã¯ãããã¯ãŒã¯ãã©ã¡ãŒã¿ãŒã«ã€ããŠäœãç¥ããã«ãã³ã³ãããŒã©ãŒãå®å šã«èªåçã«æ€åºããŠæ¥ç¶ããæ¬¡ã«ä»ã®ã«ãŒã¿ãŒãèªåçã«æ€åºããŠæ¥ç¶ã圢æããããšãã§ããŸããåæã«ããã¹ãŠã®ã³ã³ããŒãã³ãã®æ¥ç¶ãã©ã¡ãŒã¿ãŒã¯æåã¯äžæã§ãããæäœäžã«å€æŽãããå¯èœæ§ããããŸãã
管çãã¬ãŒã³ã¯ãéäžç®¡çãšç£èŠãæäŸãããœãªã¥ãŒã·ã§ã³ã®äžéšã§ãã
- DMVPN/PfR â management-plane . , Cisco Prime Infrastructure. CLI. API .
- SD-WAN â vManage. vManage, REST API.
SD-WAN vManage â (Device Template) , . vManage, , / , .
vManage Cisco SD-WAN, DPI .
, ( ) CLI, . ( ) , â vManage.
çµ±åã»ãã¥ãªãã£-ããã§ã¯ããªãŒãã³ãã£ãã«ãä»ããŠéä¿¡ãããšãã®ãŠãŒã¶ãŒããŒã¿ã®ä¿è·ã ãã§ãªããéžæãããã¯ãããžã«åºã¥ãWANãããã¯ãŒã¯ã®å šäœçãªã»ãã¥ãªãã£ã«ã€ããŠã説æããå¿ èŠããããŸãã
- DMVPN/PfR . , IPS/IDS. VRF. () .
- â .. , , . - SD-WAN DMVPN , L3/VRF (, IPS/IDS, URL-, DNS-, AMP/TG, SASE, TLS/SSL proxy ..). vSmart ( ), , DTLS/TLS . .
(-, ) DTLS/TLS. /. / SD-WAN :
- «» .
SD-WAN DMVPN/PfR
æ©èœã®éãã®èª¬æã«ç§»ããšããããã®å€ãã¯ã¢ãŒããã¯ãã£ã®éãã®ç¶ãã§ããããšã«æ³šæããŠãã ããããœãªã¥ãŒã·ã§ã³ã®ã¢ãŒããã¯ãã£ã圢æãããšãã«ãéçºè ãæçµçã«ååŸãããæ©èœããéå§ããããšã¯åšç¥ã®äºå®ã§ãã2ã€ã®ãã¯ãããžãŒã®æãéèŠãªéããèããŠã¿ãŸãããã
AppQïŒã¢ããªã±ãŒã·ã§ã³å質ïŒ-ããžãã¹ã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã£ãã¯éä¿¡ã®å質ãä¿èšŒããæ©èœ
ãããã®ãã¯ãããžãŒã®äž»ãªæ©èœã¯ã忣ãããã¯ãŒã¯ã§ããžãã¹ã¯ãªãã£ã«ã«ãªã¢ããªã±ãŒã·ã§ã³ã䜿çšããéã®ãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ãå¯èœãªéãåäžãããããšãç®çãšããŠããŸããããã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžéšãITã«ãã£ãŠå¶åŸ¡ãããŠããªãå ŽåããŸãã¯ããŒã¿è»¢éã®æåãä¿èšŒããªãå Žåã«ç¹ã«éèŠã§ãã
DMVPNã¯ãããèªäœã§ã¯ãã®ãããªã¡ã«ããºã ãæäŸããŸãããåŸæ¥ã®DMVPNãããã¯ãŒã¯ã§å®è¡ã§ããæåã®ããšã¯ãçºä¿¡ãã©ãã£ãã¯ãã¢ããªã±ãŒã·ã§ã³ããšã«åé¡ããWANãªã³ã¯ã®æ¹åã«åªå é äœãä»ããããšã§ãããã®å ŽåãDMVPNãã³ãã«ã®éžæã¯ããã®å¯çšæ§ãšã«ãŒãã£ã³ã°ãããã³ã«ã®çµæã®ã¿ã«åºã¥ããŠããŸããåæã«ããã¹/ãã³ãã«ã®ãšã³ãããŒãšã³ãã®ç¶æ ãšããããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠéèŠãªäž»èŠãªã¡ããªãã¯ïŒé å»¶ãé å»¶å€åïŒãžãã¿ïŒãæå€±ïŒïŒ ïŒïŒã®èгç¹ããã®éšåçãªå£åã®å¯èœæ§ã¯èæ ®ãããŠããŸããããã®ç¹ã§ãAppQã®åé¡ã解決ãããšãã芳ç¹ãããåŸæ¥ã®DMVPNãSD-WANãšçŽæ¥æ¯èŒããããšã¯æå³ããããŸãããDMVPNã¯ãã®åé¡ã解決ã§ããŸããããã®ã³ã³ããã¹ãã«CiscoPerformance RoutingïŒPfRïŒãã¯ãããžã远å ããããšãç¶æ³ãå€åããCiscoSD-WANãšã®æ¯èŒãããé©åã«ãªããŸãã
éãã«ã€ããŠèª¬æããåã«ããã¯ãããžãŒãã©ã®ããã«é¡äŒŒããŠããããç°¡åã«ãŸãšããŸãããããã£ãŠãäž¡æ¹ã®ãã¯ãããžãŒïŒ
- ç¹å®ã®ã¡ããªãã¯ã®ã³ã³ããã¹ãã§ç¢ºç«ãããåãã³ãã«ã®ç¶æ ãåçã«è©äŸ¡ã§ããã¡ã«ããºã ããããŸã-å°ãªããšãé å»¶ãé å»¶å€åãããã³ãã±ããæå€±ïŒïŒ ïŒ
- ãã³ãã«ã®äž»èŠãªã¡ããªãã¯ã®ç¶æ ãæž¬å®ããçµæãèæ ®ã«å ¥ããŠããã©ãã£ãã¯å¶åŸ¡ã«ãŒã«ïŒããªã·ãŒïŒã®åœ¢æãé åžãããã³é©çšã«ç¹å®ã®ããŒã«ã»ããã䜿çšããŸãã
- ã«ãŒã¿ãŒã«çµã¿èŸŒãŸããŠããDPIã¡ã«ããºã ã«åºã¥ããŠãOSIã¢ãã«ã®L3-L4ã¬ã€ã€ãŒïŒDSCPïŒãŸãã¯L7ã¢ããªã±ãŒã·ã§ã³çœ²åã§ã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ãåé¡ããŸãã
- éèŠãªã¢ããªã±ãŒã·ã§ã³ãã¡ããªãã¯ã®èš±å®¹å¯èœãªãããå€ãããã©ã«ãã®ãã©ãã£ãã¯éä¿¡ã®ã«ãŒã«ããããå€ãè¶ ãããšãã«ãã©ãã£ãã¯ãåã«ãŒãã£ã³ã°ããããã®ã«ãŒã«ãå®çŸ©ã§ããããã«ããŸãã
- GRE/IPSec DSCP GRE/IPSEC , QoS ( SLA).
SD-WAN DMVPN/PfR?
DMVPN/PfR
- , (Probes). â , ( ).
- â .
- . DMVPN/PfR .
- PfR TCA (Threshold Crossing Alert) , , , TCA-. , .
SD-WAN
- BFD echo-. TCA â . .
- BFD .
- BFD . . WAN- MPLS L2/L3 VPN QoS SLA â DSCP- BFD ( IPSec/GRE) , . BFD - . Cisco SD-WAN BFD, BFD DSCP- ( ).
- BFD , . SD-WAN , MTU TCP MSS Adjust, .
- SD-WAN QoS L3 DSCP , L2 CoS , â , IP-
, AppQ ?
DMVPN/PfR:
- (-) () CLI CLI- . CLI- .
- / .
- .
- , , .
- . , . / .
- , .
- , WAN- , .
SD-WAN:
- vManage .
- , , , .
- ()
- , / vSmart â data-plane . IP- .

- , , , , :
- FEC (Forward Error Correction) â . , FEC . , .

- ããŒã¿ã¹ããªãŒã ã®è€è£œ-FECã«å ããŠãããªã·ãŒã¯ãFECã䜿çšããŠè£åã§ããªãããã«æ·±å»ãªã¬ãã«ã®æå€±ãçºçããå Žåã«ãéžæããã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã£ãã¯ã®èªåè€è£œãæäŸã§ããŸãããã®å ŽåãéžæãããããŒã¿ã¯ãã¹ãŠã®ãã³ãã«ãä»ããŠåä¿¡ãã©ã³ãã«éä¿¡ããããã®åŸéè€æé€ãããŸãïŒäžèŠãªãã±ããã®ã³ããŒãç Žæ£ãããŸãïŒããã®ã¡ã«ããºã ã«ããããã£ãã«ã®äœ¿çšçãå€§å¹ ã«åäžããŸãããäŒéã®ä¿¡é Œæ§ãå€§å¹ ã«åäžããŸãã
- FEC (Forward Error Correction) â . , FEC . , .
Cisco SD-WANæ©èœãDMVPN / PfRã«çŽæ¥ã¢ããã°ã¯ãããŸãã
å Žåã«ãã£ãŠã¯ãCisco SD-WANãœãªã¥ãŒã·ã§ã³ã®ã¢ãŒããã¯ãã£ã«ãããDMVPN / PfRã®ãã¬ãŒã ã¯ãŒã¯å ã§ã®å®è£ ãéåžžã«å°é£ã§ããããå¿ èŠãªäººä»¶è²»ã®ããã«éçŸå®çã§ãããããŸãã¯å®å šã«äžå¯èœã§ããæ©äŒãåŸãããšãã§ããŸãããããã®äžã§æãè峿·±ããã®ãèããŠã¿ãŸãããïŒ
ãã©ãã£ãã¯ãšã³ãžãã¢ãªã³ã°ïŒTEïŒ
TEã«ã¯ãã«ãŒãã£ã³ã°ãããã³ã«ã«ãã£ãŠåœ¢æãããæšæºãã¹ãããã©ãã£ãã¯ãè¿åãããã¡ã«ããºã ãå«ãŸããŠããŸãã TEã¯ãã¡ã€ã³ãã¹ã§é害ãçºçããå Žåã«ãµãŒãã¹ã®å質ãŸãã¯å埩é床ãåäžãããããã«ãéèŠãªãã©ãã£ãã¯ã代æ¿ã®ïŒéè€ããªãïŒäŒéãã¹ã«è¿ éã«ããã³/ãŸãã¯é²ããããšãã§ããããããããã¯ãŒã¯ãµãŒãã¹ã®é«å¯çšæ§ãæäŸããããã«ãã䜿çšãããŸãã
TEå®è£ ã®è€éãã¯ã代æ¿ãã¹ãäºåã«èšç®ããŠäºçŽïŒãã§ãã¯ïŒããå¿ èŠãããããšã«ãããŸãããã¬ã³ã ãªãã¬ãŒã¿ãŒã®MPLSãããã¯ãŒã¯ã§ã¯ããã®åé¡ã¯ãIGPãããã³ã«ããã³RSVPãããã³ã«ã®æ¡åŒµãåããMPLSãã©ãã£ãã¯ãšã³ãžãã¢ãªã³ã°ãªã©ã®ãã¯ãããžãŒã䜿çšããŠè§£æ±ºãããŸãããŸããæè¿ã§ã¯ãäžå åãããæ§æãšãªãŒã±ã¹ãã¬ãŒã·ã§ã³çšã«ããã«æé©åãããã»ã°ã¡ã³ãã«ãŒãã£ã³ã°ãã¯ãããžãŒã®äººæ°ãé«ãŸã£ãŠããŸããåŸæ¥ã®WANãããã¯ãŒã¯ã§ã¯ããããã®ãã¯ãããžãŒã¯ãååãšããŠããã©ãã£ãã¯ãåå²ã§ããããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ïŒPBRïŒãªã©ã®ããããã€ãããã¡ã«ããºã ã®äœ¿çšã«ä»£è¡šãããªãããåæžãããŸããããããã¯ãŒã¯ã®å šäœçãªç¶æ ãèæ ®ããã«ãåã«ãŒã¿ãŒã«åå¥ã«å®è£ ããŸãã PBRã¯ãåã®ã¹ããããŸãã¯åŸç¶ã®ã¹ãããã«ãªããŸãããããã®TEãªãã·ã§ã³ã䜿çšããçµæã¯æåŸ å€ãã§ããæ§æãšæäœãè€éãªãããMPLS TEã¯ååãšããŠãããã¯ãŒã¯ã®æãéèŠãªéšåïŒã³ã¢ïŒã§ã®ã¿äœ¿çšãããPBRã¯ãããã¯ãŒã¯å šäœã§ç¹å®ã®çµ±åPBRããªã·ãŒã圢æããæ©èœãªãã§åã ã®ã«ãŒã¿ãŒã§äœ¿çšãããŸããæããã«ãããã¯DMVPNã«åºã¥ããããã¯ãŒã¯ã«ãåœãŠã¯ãŸããŸãã
ãã®ç¹ã§SD-WANã¯ãæ§æãç°¡åã§ããã ãã§ãªããå€§å¹ ã«ã¹ã±ãŒã©ãã«ãªãã¯ããã«æŽç·Žããããœãªã¥ãŒã·ã§ã³ãæäŸããŸããããã¯ã䜿çšãããŠããã³ã³ãããŒã«ãã¬ãŒã³ããã³ããªã·ãŒãã¬ãŒã³ã¢ãŒããã¯ãã£ã®çµæã§ããSD-WANããªã·ãŒãã¬ãŒã³ã®å®è£ ã«ãããäžå åãããTEããªã·ãŒå®çŸ©ãå¯èœã«ãªããŸã-ã©ã®ãã©ãã£ãã¯ã«é¢å¿ããããŸããïŒã©ã®VPNçšã§ããïŒã©ã®ããŒã/ãã³ãã«ãä»ããŠä»£æ¿ã«ãŒãã圢æããå¿ èŠããããŸããããããšãéã«çŠæ¢ãããŠããŸããïŒæ¬¡ã«ãvSmartã³ã³ãããŒã©ãŒã«åºã¥ãã³ã³ãããŒã«ãã¬ãŒã³å¶åŸ¡ã®éäžåã«ãããåã ã®ããã€ã¹ã®èšå®ã«é Œãããšãªãã«ãŒãã£ã³ã°çµæã倿Žã§ããŸããã«ãŒã¿ãŒã¯ãvManageã€ã³ã¿ãŒãã§ã€ã¹ã§åœ¢æãããvSmartã«äœ¿çšããããã«è»¢éãããããžãã¯ã®çµæã®ã¿ãæ¢ã«èªèããŠããŸãã
ãµãŒãã¹ãã§ãŒã³
ãµãŒãã¹ãã§ãŒã³ã®åœ¢æã¯ããã§ã«èª¬æãããã©ãã£ãã¯ãšã³ãžãã¢ãªã³ã°ã¡ã«ããºã ããããåŸæ¥ã®ã«ãŒãã£ã³ã°ã§ã¯ããã«é¢åãªäœæ¥ã§ããå®éããã®å Žåãç¹å®ã®ãããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠç¹å®ã®ç¹å¥ãªã«ãŒãã圢æããã ãã§ãªããç¹å¥ãªã¢ããªã±ãŒã·ã§ã³ãŸãã¯ãµãŒãã¹ïŒITUããã©ã³ã·ã³ã°ããã£ãã·ã³ã°ãæ€æ»ïŒã§åŠçããããã«ããããã¯ãŒã¯ããSD-WANãããã¯ãŒã¯ã®ç¹å®ã®ïŒãŸãã¯ãã¹ãŠã®ïŒããŒãã«ãã©ãã£ãã¯ãåºåããæ©èœãæäŸããå¿ èŠããããŸãããã©ãã£ãã¯ãªã©ïŒãåæã«ããã©ãã¯ããŒã«ã®ç¶æ³ãé²ãããã«ããããã®å€éšãµãŒãã¹ã®ç¶æ ãå¶åŸ¡ã§ããå¿ èŠããããŸãããŸããç¹å®ã®ãã©ã³ãã®ãã©ãã£ãã¯ãåŠçããããã«æé©ãªãµãŒãã¹ããŒãããããã¯ãŒã¯ãèªåçã«éžæããæ©èœãåãããåãã¿ã€ãã®å€éšãµãŒãã¹ãç°ãªãå°ççå Žæã«é 眮ããã¡ã«ããºã ãå¿ èŠã§ãã ..ãCisco SD-WANã®å Žåãããã¯ãã¿ãŒã²ãããµãŒãã¹ãã§ãŒã³ã®ãã¹ãŠã®åŽé¢ãåäžã®å šäœã«ãæ¥çãããå¿ èŠãªå Žæãšã¿ã€ãã³ã°ã§ã®ã¿ããŒã¿ãã¬ãŒã³ãšå¶åŸ¡ãã¬ãŒã³ã®ããžãã¯ãèªåçã«å€æŽããé©åãªéäžåããªã·ãŒãäœæããããšã§ç°¡åã«å®çŸã§ããŸãã
ç¹æ®ãªïŒãã ãSD-WANãããã¯ãŒã¯èªäœãšã¯é¢ä¿ãããŸããïŒæ©åšã§ãéžæããã¿ã€ãã®ã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã£ãã¯ã®å°ç忣åŠçãç¹å®ã®é åºã§åœ¢æããæ©èœã¯ãåŸæ¥ã®ãã¯ãããžãäžéšã®ä»£æ¿SDãœãªã¥ãŒã·ã§ã³ã«å¯ŸããCiscoSD-WANã®å©ç¹ãæãé®®æã«ç€ºããŠããŸãã -ä»ã®ã¡ãŒã«ãŒã®WANã
åçã¯äœã§ããïŒ
æããã«ãDMVPNïŒããã©ãŒãã³ã¹ã«ãŒãã£ã³ã°ãããŸãã¯ãªãïŒãšCisco SD-WANã®äž¡æ¹ããçµç¹ã®åæ£WANãããã¯ãŒã¯ã«é¢ããŠéåžžã«é¡äŒŒããåé¡ãæçµçã«è§£æ±ºããŸããåæã«ãCisco SD-WANãã¯ãããžãŒã®ã¢ãŒããã¯ãã£ãšæ©èœã®å€§ããªéãã«ããããããã®åé¡ã解決ããããã»ã¹ãç°ãªãå質ã¬ãã«ã«ãªããŸããèŠçŽãããšãSD-WANãã¯ãããžãŒãšDMVPN / PfRãã¯ãããžãŒã®éã®æ¬¡ã®éèŠãªéãã«æ³šæããããšãã§ããŸãã
- DMVPN/PfR VPN data-plane SD-WAN , Hub-n-Spoke. , DMVPN/PfR , SD-WAN ( per-application BFD).
- control-plane . SD-WAN , , «» â . - ( ) .
- SD-WAN DMVPN/PfR â -, Hub, , .
- . DMVPN , - , . SD-WAN , « » , « » â , data-plane , / .
- , SD-WAN DMVPN/PfR, CLI NMS .
- SD-WAN DMVPN . â , .
ãããã®åçŽãªçµè«ãããDMVPN / PfRã«åºã¥ããããã¯ãŒã¯ã®äœæã仿¥ãã¹ãŠã®é¢é£æ§ã倱ã£ããšãã誀ã£ãå°è±¡ã圢æãããå¯èœæ§ããããŸããããã¯ç¢ºãã«å®å šã«çå®ã§ã¯ãããŸãããããšãã°ããããã¯ãŒã¯äžã§å€ãã®ã¬ã¬ã·ãŒæ©åšã䜿çšãããŠãããããã眮ãæããæ¹æ³ããªãå ŽåãDMVPNã䜿çšãããšããå€ããããã€ã¹ãšãæ°ãããããã€ã¹ã1ã€ã®å°ç忣ãããã¯ãŒã¯ã«çµåããŠãäžèšã®å€ãã®å©ç¹ãåŸãããšãã§ããŸãã
äžæ¹ãIOS XEïŒISR 1000ãISR 4000ãASR 1000ãCSR 1000vïŒã«åºã¥ãçŸåšã®ãã¹ãŠã®CiscoäŒæ¥ã«ãŒã¿ãŒã¯ãçŸåšãåŸæ¥ã®ã«ãŒãã£ã³ã°ãšDMVPNããã³SD-WANã®äž¡æ¹ã®ããããåäœã¢ãŒãããµããŒãããŠããããšãèŠããŠããå¿ èŠããããŸããéžæã¯ãçŸåšã®ããŒãºãšãåãæ©åšã§ãã€ã§ãããé«åºŠãªãã¯ãããžãŒã«ç§»è¡ã§ãããšããçè§£ã«ãã£ãŠæ±ºãŸããŸãã