A couple weeks ago, we wrapped up a very successful Cisco Live event in Orlando for more than 20,000 attendees. During the conference, we announced a new name for our software product formerly known as Cisco Virtual Network Management Center (VNMC).
Over the last couple of years, Cisco Prime Network Service Controller (Prime NSC) has developed into Cisco’s primary management platform for Layer 4 through 7 network services deployment in a cloud or virtualized environment. Today the software supports multiple different use cases for network services, with several hundred customers worldwide.
Cisco Prime Network Services Controller is the control point and management software for the InterCloud solution – providing VM workload mobility between a private and public cloud while retaining the same IP address and Layer 2 connectivity. As outlined in a recent blog post by my colleague Gary Kinghorn, our new Nexus 1000V InterCloud solution for hybrid cloud was a big hit at Cisco Live. During the InterCloud demonstration at Cisco Live, we showed how this Cisco-created technology allows enterprise organizations to extend their Layer 2 network to public clouds like Amazon Web Services.
The screenshots below illustrate how InterCloud enables the secure migration of a VM to a public cloud environment:
At Cisco Live, we also announced our new fabric path technology called Cisco Dynamic Fabric Automation (DFA). This new Unified Fabric technology enables simplified network automation and provisioning for both physical server and VM deployments. In the DFA architecture, Cisco Prime Network Services Controller is responsible for managing network services insertion – including firewalls and load balancers – when provisioning or moving VMs.
Cisco continues to roll out innovations that will enable the next generations of multi-cloud computing. I’m a product manager working on Cisco’s Cloud Management software, and we’re all about the high-level, self-service, automatic provisioning of services that the end-user cares about. The network just moves ones and zeros, and all protocols of interest (HTTP, SSH, RDP, SQL, etc.) work fine over TCP/IP. The hypervisor takes care of putting that pesky motherboard chipset and storage bus into a black box, right? The end-user doesn’t care about that stuff, or at least doesn’t want to have to care about it.
A common perspective, except among the engineers who manage the network, is that network infrastructure is a bunch of mysterious plumbing that “just works” and how it does what it does doesn’t matter. Indeed, many vendors in the “cloud” arena would like to perpetuate this perspective on the network. They would like you to believe a bunch of dumb pipes can carry traffic and that determination of the traffic (content, flow, etc.) is determined at higher levels in the stack.
In some cases, this is true, but operating this way doesn’t unlock anything new. The model they describe would be brilliant if all of your network requirements were defined in 1998. Few companies can afford to operate technology today like they did in 1998 and remain competitive.
Cisco is announcing a newNexus 1000V(N1KV), and this one changes the game.In brief, the Nexus 1000V is the foundation of the networking services that Cisco brings to virtual computing. The N1KV can be managed using the same NX-OS commands and practices used to manage the Nexus 5K and 7K switches, and extends network control down to the VM and virtual port into which a VM is “plugged in”, even across different vendors’ hypervisors.
The N1KV is also the platform for additional L2 and L3 network services such as those provided by the vASA Firewall, vNAM, and VSG. The new Nexus 1000V InterCloud extends this ability to cloud service providers, such as Amazon, but is “cross-provider” (in fact, it doesn’t even depend on the Cloud Service Provider). For me, in my role as a Cloud Product Manager, this is an important new addition to basic networking capabilities, and is exactly the kind of thing that Cisco can and should do in its role as “Networking Giant” to open up the promise of hybrid or multi-cloud.
I have a mental image of what this can do, and I tried to put this into images to the right. Animation would have been better, I just don’t have the Flash skills to put it together for a quick blog post. I envision a virtual machine as a ghostly “physical” server tower with network cables plugged into it. These network connections can come from end-users in a client-server model, or any of our web-and-mobile constructs. After all, we still are end-users connecting to machines. Of course, the “client” for a compute function could be another compute function, so there is a network cable coming from another nearby ghost server. These ghost servers can today float from blade to blade thanks to most mainstream virtual machine managers (VMM) and a virtual switch like the N1KV, and the cords stay connected throughout. With the new N1KV, that VM can float right out of that VMM and into another VMM (such as across VMware datacenters, or even from VMware to Hyper-V), or out to a public or hosted provider. The cord just magically uncoils to remain connected wherever that machine goes! I love magic.
The N1KV provides that cable that can float after its ethereal virtual machine. It also provides the platform to maintain monitoring by the vNAM, even as the machine moves. You simply can’t economically achieve this using basic dumb pipes. Add to this the new Virtual Network Management Console (VNMC) InterCloud management capabilities. In order for that cord to stay connected, there do have to be network switches or routers along the way that understand how to make that network cable follow the machine. VNMC InterCloud manages these devices, but adds another particularly important capability: actually moving the workload.
VNMC InterCloud adds the ability to discover virtual machines, and convert them to a cloud-provider’s instance format, move what could possibly be a fairly large set of files, and get that machine started back up in a far-away environment, with seamless network consistency. VNMC InterCloud is like a puff of wind that pushes the ghostly VM from my corporate VMWare-based cloud to float over to my hosted private cloud. Remember, ghosts can float through walls.
This is groundbreaking. Workload mobility is one of those hard-to-do core capabilities required for all of us to realize the promise of multi-cloud, and it requires a network that is both dynamic and very high performing. I’ve been looking forward to this from Cisco for some time now.
Today marks the general availability of the eagerly-awaited Microsoft Windows Server 2012 platform. According to Microsoft, “Windows Server 2012 redefines the server category, delivering hundreds of new features and enhancements spanning virtualization, networking, storage, user experience, cloud computing, automation, and more.” Earlier Cisco blog posts discussed how Cisco has collaborated with Microsoft to achieve Windows 2012 certification for our UCS servers, as well as integrating our management tools into Microsoft System Center and PowerShell.
In this post, I’d like to highlight the integration of the Nexus 1000V virtual switch into the Windows Server 2012 platform, and particularly the Hyper-V hypervisor. We have been working closely with the Windows Server 2012 team for the past few years towards this goal, and announced Nexus 1000V and VM-FEX support for it at the Microsoft BUILD conference last year. Read More »
VNMC 2.0 is a template-driven policy management tool that is now bundled with Cisco Virtual Security Gateway (VSG) and Cisco ASA 1000V Cloud Firewall. This new release now has expanded capabilities to configure the security of your virtual cloud environment. Because VNMC 2.0 is such a step up from prior releases, and fewer people are familiar with its functionality, this is going to be a bit longer of a post than usual (but with lots of screen shots).
Let’s take a look at some of the key VNMC features and how it works with the two virtual firewalls:
Resource Objects for ASA 1000V
Cisco VNMC abstracts the devices it manages. As part of provisioning, devices are configured to point to Cisco VNMC for policy management. Cisco VNMC discovers all devices and lists them under the Resources pane. In addition to the ASA 1000V, the Resources pane has other resources such as Cisco VSGs, VSMs, and VMs.
Virtualization news continues to move to the forefront as we head towards the start of VMworld in San Francisco. Last week we unveiled the upcoming Nexus 1000V 2.1 major release here. Perhaps the biggest news on the virtual security front is the availability last week of the ASA 1000V Cloud Firewall (download a free trial here). We’re also announcing special introductory pricing on the ASA 1000V of 50% off the list price, which also includes our new Virtual Network Management Center (VNMC) 2.0. Other promotional pricing bundles are available as well.
We’re excited about the ASA 1000V because it brings virtually all the features of our physical ASA appliances to virtual environments, providing greater consistency across the physical, virtual and cloud domains, however your applications are deployed. The ASA 1000V will primarily be deployed to protect tenants in a multi-tenant cloud environment with traditional edge security services including VPN, NAT, attack prevention and DHCP. This will complement our Virtual Security Gateway (VSG) firewall which has greater visibility to VM-specific policy attributes, and will be used to isolate VM-VM traffic within a tenant.
Both ASA 1000V and VSG use vPath 2.0 in the new Nexus 1000V to steer appropriate traffic to the right firewall, or other virtual service nodes, in the right sequence, while automatically keeping policies consistent and the service paths properly configured after vMotion events. And the ASA 1000V comes bundled with the new Virtual Network Management Center (VNMC) 2.0 that we announced this week as well, for easy management and deployment of virtual security policies.
But since there’s still a lot to do prepping for this week’s activities, like #v0dgeball, I’ll wrap up here and let Jimmy Ray from TechWiseTV share some of his thoughts on ASA 1000V and VSG (and remember, if you are around #VMworld this week, give us a shout out on twitter using Cisco hash tag #ciscovmw or to me @gkinghorn).: