Cisco Secure Interconnection of Heterogeneous Fabrics (ACI and VXLAN EVPN)

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Cloud Networking Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Lukas Krattiger, Max Ardica

In this presentation, Lukas Krattiger and Max Ardica from Cisco’s Data Center Business Unit discuss new functionalities for Cisco Data Center networking. They focus on the secure interconnection of heterogeneous fabrics, specifically integrating ACI (Application Centric Infrastructure) and standard VXLAN EVPN (Ethernet VPN) fabrics.

Max introduces the concept of the ACI Border Gateway, which is a device that allows for controlled connectivity between different leaf-spine topologies, enabling the extension of layer 2 and layer 3 connectivity in a controlled manner. The ACI Border Gateway operates in a standard VXLAN EVPN fashion to interconnect with VXLAN EVPN border gateways of other fabrics. This allows for the expansion of a network using either ACI or VXLAN EVPN fabrics within the same multi-fabric domain.

They also introduce the VXLAN Group Policy Option (GPO), which provides secure group segmentation within a VXLAN EVPN fabric, similar to the concept of SGT (Security Group Tag) discussed in a previous session. GPO enables microsegmentation and service chaining, allowing administrators to direct traffic through firewalls or other network services as part of a security policy.

Lukas and Max emphasize the importance of using a control plane to exchange group information, allowing for optimal traffic flow by applying security policies at the ingress leaf. This approach is more efficient as it avoids sending unnecessary traffic across the network only to be dropped at the destination.

The discussion also touches on the need for policy authoring and enforcement, which will be facilitated by software tools like Nexus Dashboard or Ansible playbooks, allowing for consistent policy application across ACI and VXLAN EVPN fabrics.

Throughout the conversation, they address scalability, resource management, and the benefits of using border gateways to abstract network complexity and control inter-fabric connectivity. They also mention the possibility of synchronizing policy across different network domains and the potential integration with third-party security management tools.


NIS2 Compliance with Cisco Industrial Security

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Cloud Networking Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Andrew McPhee

Andrew McPhee, a solution manager for industrial security at Cisco, discusses how Cisco Cyber Vision and Cisco Secure Equipment Access can assist with NIS2 compliance. NIS2 is a European standard that mandates cybersecurity measures for critical industries. Andrew explains the importance of NIS2 as a forcing factor for industries to implement security measures, which apply to a wide range of industrial verticals.

He highlights the need to understand the risk profile of devices on a network, manage supply chain security, handle vulnerabilities, and implement access control policies, including multi-factor authentication. Andrew emphasizes the role of Cisco Cyber Vision for deep packet inspection and asset visibility in operational technology (OT) environments, which helps assess vulnerabilities and risks. He also discusses Cisco Secure Equipment Access for remote access, moving towards a Zero Trust Network Access (ZTNA) model.

Andrew demonstrates Cisco’s IoT Operations Dashboard, which facilitates secure remote access to network devices and systems. He explains how the dashboard can be used for both clientless and client-based access, with features like session recording and scheduled access for vendors. The demonstration includes an overview of Duo, Cisco’s multi-factor authentication platform, and how it integrates with Secure Equipment Access for identity verification and policy enforcement.

Next, Andrew presents Cisco Cyber Vision, which provides a risk analysis of OT networks through passive monitoring and deep packet inspection. Cyber Vision can detect changes in the network, create baselines, and generate security reports. It can also integrate with Cisco’s Identity Services Engine (ISE) to implement segmentation based on the zones and conduits model from the IEC 62443 standard. He explains how Cyber Vision can share information with ISE to assign devices to security groups and enforce policies.

Throughout the discussion, Andrew addresses questions from the audience regarding the capabilities, integrations, and potential applications of the technologies presented. He clarifies how Cisco’s solutions can be adapted to various network architectures and the benefits of implementing security group tags for macro and micro-segmentation in industrial networks.


IP Fabric and NetBox Cloud – Better Together Demo

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: IP Fabric and NetBox Labs Present at Tech Field Day Extra at Cisco Live EMEA

Company: IP Fabric, NetBox Labs

Video Links:

Personnel: Alex Gittings

Alex Gittings, a solution architect at IP Fabric, presents a demonstration of a plugin that integrates IP Fabric with NetBox, a source of truth database for network automation. The plugin allows for the automatic synchronization of observed network state data into NetBox, which can be used to maintain an up-to-date source of truth for network automation purposes. This functionality is available for both the open-source and cloud-based versions of NetBox.

During the demo, Alex shows how a network discovered by IP Fabric can be imported into NetBox, including devices, interfaces, VLANs, VRFs, prefixes, and IP addresses. He explains that IP Fabric supports both cloud and on-premises versions of NetBox and demonstrates how to create an ingestion process to synchronize data from IP Fabric into NetBox. The plugin translates data from IP Fabric’s model to NetBox’s model using transform maps.

Alex also addresses questions regarding the plugin’s capabilities and limitations, such as its focus on the underlay network rather than the overlay, its ability to support various technologies, and how it can be used for compliance and change tracking. He explains that while IP Fabric captures snapshots of network state periodically, it does not support real-time monitoring, which means out-of-band changes may not be immediately reflected.

The demo concludes with a discussion on the potential for integration with other tools like Terraform and the challenges of maintaining a single source of truth for network state. Alex emphasizes the importance of aligning tooling with processes to ensure that the network source of truth remains accurate and effective for automation purposes.


Network Assurance in the Automation Ecosystem with IP Fabric

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: IP Fabric and NetBox Labs Present at Tech Field Day Extra at Cisco Live EMEA

Company: IP Fabric, NetBox Labs

Video Links:

Personnel: Daren Fulwell

Daren Fulwell, the Product Evangelist for IP Fabric, presented on how IP Fabric’s Automated Network Assurance Platform can transform network management. The platform is designed to proactively manage and measure networks, replacing manual documentation with interactive tools and providing an API for network intelligence. It works in conjunction with NetBox Cloud to enrich the automation ecosystem.

Fulwell discussed the challenges network operators face, such as dealing with complex, multi-vendor environments and the need for up-to-date documentation. He emphasized that traditional tools like SNMP monitoring and manual documentation are insufficient for modern network demands.

IP Fabric’s platform addresses these issues by collecting data on inventory, configuration, and state to provide a comprehensive understanding of the network. It then creates visual topologies and simulates traffic flows to understand network behavior. The platform uses snapshots to track changes over time and can flag issues for remediation based on predefined intent checks.

Fulwell also highlighted the importance of integrating IP Fabric’s API with other systems like monitoring platforms, ticketing systems, CMDBs, chatbots, and network automation tools to ensure up-to-date information and to validate changes in the network.

The presentation included a Q&A session where Fulwell answered questions about integrating network components, defining good and bad configurations, and potential impact analysis for network changes. He concluded by mentioning that while a complete digital twin of the network is difficult to achieve, IP Fabric provides the necessary oversight and intelligence to manage complex networks effectively.


NetBox Cloud as Part of a Modern Network Automation Architecture with NetBox Labs

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: IP Fabric and NetBox Labs Present at Tech Field Day Extra at Cisco Live EMEA

Company: IP Fabric, NetBox Labs

Video Links:

Personnel: Rich Bibby

In this presentation, Rich Bibby, a technical advocate with NetBox Labs, introduces NetBox Cloud and discusses its importance in network automation architecture. NetBox Labs, founded in 2023 in New York, is the commercial steward of the open-source project NetBox and has developed NetBox Cloud, an enterprise-grade, software-as-a-service version of NetBox.

Rich explains that a network source of truth is a representation of the intended state of a network, including devices, configurations, connections, and services. This intended state is distinct from the actual operational state, which is reported by monitoring and assurance tools. NetBox serves as a structured and cohesive data model, which is essential for network automation at scale. It eliminates the need for spreadsheets and disparate data sources, providing a single source of truth and accelerating network automation through its REST API and GraphQL interface.

NetBox Cloud offers push-button lifecycle operations, automated backups, single sign-on, and simplified plugin management. It is designed to be secure and compliant, and it allows for easy upgrades and integration with other tools. Rich also briefly describes the customer journey from documenting networks to full automation and presents a modern network automation reference architecture with NetBox Cloud at its center. This architecture includes operations teams, automation tools, and observability tools that together maintain the feedback loop between intended and actual network states.

Throughout the presentation, Rich also demonstrates the NetBox UI, showing how users can view site details, rack elevations, device configurations, and connections. He clarifies that while NetBox does not actively poll devices for their state, it can integrate with plugins and tools like IP Fabric to reconcile intended and actual states. NetBox Cloud does not require direct connectivity to customer networks, as it primarily interacts with other management tools.

Rich concludes by addressing audience questions about compliance, data validation, integration with existing tools, and the process for updating the intended state in NetBox.


Cisco Routed Optical Networking Automation

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Service Provider Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Jochen van Guyse, Pedro Do Vale Brites

Jochen van Guyse and Pedro Do Vale Brites from the automation team present a demo on routed optical networking (RON) and its automation. They explain the benefits of RON, which include simplifying network architecture by eliminating the need for separate transponders and reducing power consumption, space, and overall operational costs. They discuss the need for automation in RON due to the challenges it poses, such as the management of wavelengths across different teams (optical and IP networking teams).

The hierarchical controller architecture, which facilitates RON automation, is introduced. This architecture includes the top-level hierarchical controller, domain controllers for IP and optical networks, and the potential for integration across multiple vendors.

Pedro then demonstrates the system, highlighting the ease of setting up end-to-end IP links, including the provisioning within optical networks, and how to troubleshoot faults. He shows how the system can help operations teams by providing a single pane of glass view, correlating IP links with their optical paths, and simplifying fault management. The demo also covers inventory management, proactive maintenance planning through failure impact analysis, and historical data analysis for identifying trends in hardware failures.

The system is designed to fix inventory issues by relying on discovered data rather than user input, thereby serving as a single source of truth. The goal is to simplify operations for first-level network operations center (NOC) personnel by providing easy correlation of faults across layers and offering predictive maintenance insights. Some functionalities, like cross-launching into different domain controllers, are still in progress, but the main features demonstrated are generally available (G.A.) and currently shipping.


Automated Assurance with Cisco Crosswork and Accedian

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Service Provider Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Rana El Desouky Kazamel, Tom Footit

Rana El Desouky Kazamel and Tom Footit discuss the collaboration between Cisco Crosswork and Accedian, which is now part of Cisco, focusing on automated assurance for mass scale networks. Their goal is to help network operators monitor services, monetize SLAs, and deliver enhanced digital experiences. They explain how their solution provides a single pane of glass across multi-vendor and multi-domain networks, mapping services to network operations and enabling enhanced services.

They cover the end-to-end automation framework necessary for simplifying mass scale networks, including workflow definition, service provisioning, visibility, assurance, planning, and optimization. They emphasize the importance of intent-based assurance, which starts with the service intent and SLA metrics.

Tom details Accedian’s capabilities, including the use of sensors (probes) to generate test traffic and collect data for analyzing network behavior, predicting issues, and identifying SLA compliance. They also discuss how issues like fiber cuts can be managed and correlated with affected services, and how policies can be adjusted in real-time based on various constraints, including energy consumption.

Rana and Tom touch on integrations with other Cisco tools like Thousand Eyes for end-to-end assurance, and they demonstrate how their platform allows operators to drill down from a high-level view of network health to specific issues and devices causing problems.

Overall, the collaboration aims to provide network operators with the tools to proactively manage their networks, ensure service quality, and respond to issues efficiently.


Cisco Catalyst 9000 Cloud Evolution: Born Meraki

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Enterprise Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Alex Burger, Nico Darrow

Alex Burger and Nico Darrow from the Meraki Product Organization discuss the expansion of the Catalyst 9300-M portfolio and its integration into the Meraki Dashboard. The Catalyst C9300-M is designed to bring together Cisco’s hardware capabilities with the cloud management features of the Meraki Dashboard, offering flexibility and a unified platform for various customer environments.

Nico elaborates on the benefits of using the Meraki Dashboard for configuration, visibility, and ecosystem integration. He highlights the ease of provisioning and management, including firmware upgrades and day-to-day operations. The discussion also covers the hardware announcement of 15 new switch models, including the 9300-X and 9300-L series, which offer features like 25 gig uplinks and UPOE+ (up to 90 watts per port).

They discuss the 9300-X as a new fiber aggregation switch with high port density and stack-wise capabilities. The 9300-L models are presented as a cost-effective alternative with similar features but targeted at smaller remote offices.

The conversation also touches on smart building convergence, with the 9300-X enabling the convergence of IT and OT networks through adaptive policy and smart power management. They explain how the Meraki Dashboard allows for monitoring and automating power usage and environmental conditions.

Finally, they address the ability to migrate existing Catalyst switches to Meraki management and vice versa, as well as simplified licensing options. The talk concludes with a discussion about adaptive policy for micro-segmentation, integration with Cisco security operations, and the potential for future developments in granular security controls.


What’s Next for Cisco Meraki Switching in 2024

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Enterprise Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Alex Burger, Brennan Martin

Brennan Martin and Alex Burger from Cisco Meraki discussed the upcoming MS17 firmware release for Meraki Switching platforms. The key features they highlighted include:

  1. Device Health: MS17 will provide detailed information on CPU and memory utilization, as well as switch and environmental temperature for each individual switch. This will help in understanding if issues are related to device performance or environmental factors, such as a data center being too hot.
  2. Remote SPAN and VLAN-based SPAN: These features have been highly requested and will allow traffic to be mirrored from selected ports or VLANs across the network to another switch.
  3. Dynamic Port Profiles: MS17 will introduce the ability to create automations for configuring switch ports based on triggers like CDP, MAC OUIs, and RADIUS responses, which will automatically apply the appropriate port profile when a device is connected.
  4. Radius Configuration: This isn’t directly related to firmware but will allow consistent configurations to be managed at the organization level, simplifying the process of setting up RADIUS servers and policies.
  5. Cloud PCAP and Packet Analysis: MS17 will offer cloud-based packet capture and analysis, allowing users to store, share, download, and analyze packet captures directly from the Meraki dashboard.
  6. MAC Block List: This feature will enable users to quickly block misbehaving clients, integrating with the same APIs used for wireless and MX products.
  7. Adaptive Policy: Introduction of adaptive policy on compact switches, allowing for in-line SGTs and micro-segmentation controlled through the dashboard, interoperable with other Cisco TrustSec-capable devices.
  8. Digital Optical Monitoring: MS17 will provide health metrics for devices plugged into the switch, such as TX/RX power, temperature, voltage, and current, with Meraki and Cisco optics supported initially. This will help in predicting issues before module failure.

The release is expected to be in beta in the second quarter and stable GA in the third quarter. The goal is to maintain Meraki’s simplicity while improving integration with other products and adding more advanced features.


Cisco Meraki and Catalyst Wireless – Better Together

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Enterprise Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco, Meraki

Video Links:

Personnel: Scott Irey

Scott Irey presented the launch announcement of Cloud Monitoring for Catalyst Wireless, which is an extension of Cloud Monitoring for Catalyst Switching introduced about 18 months prior. Starting in April, users can access the early public beta release to onboard Catalyst wireless controllers. This release marks the first round of native integration with iOS XE, aiming to simplify network operations.

Scott discussed the primary goals of Cloud Monitoring, emphasizing simplification of operations, event monitoring, performance monitoring, and the introduction of new features such as configuration history and image upgrades for Catalyst devices. He also highlighted the ease of performing packet captures with the new system, which requires fewer steps compared to traditional methods.

Scott addressed the API-driven nature of the system, the plan to bring intelligent packet capture to the system, and the licensing structure, which includes Cloud Monitoring with DNA licenses, with the Advantage license offering additional client traffic analytics.

The presentation went into detail about the native integration of Meraki tunnel with iOS XE, the registration process for Catalyst devices, and the onboarding process, which involves claiming the device in the dashboard and deciding how to organize the APs. Scott also clarified that the APs only need to reach the dashboard during registration, after which all communication is through the controller.

Scott then demonstrated the onboarding process, showing how to claim a controller and add it to a network in the dashboard. He also discussed the limitations of the current system compared to native Meraki devices, the strategic positioning of the Meraki dashboard compared to DNA Center, and future capabilities like configuration management and software upgrades.

The presentation concluded with an overview of how the Meraki dashboard pulls data from iOS XE data stores and the possibility of integrating AI-driven solutions in the future.


Centralized Management Distributed Enforcement with Cisco Secure Connect

Event: Tech Field Day Extra at Cisco Live EMEA 2024

Appearance: Cisco Enterprise Presents at Tech Field Day Extra at Cisco Live EMEA

Company: Cisco

Video Links:

Personnel: Akshar Patel

Akshar Patel, a product manager for Cisco Secure Connect, presented information about Cisco’s Secure Connect and how it provides a true unified SASE (Secure Access Service Edge) experience at scale. He introduced the concept of SASE, which combines networking and security into a unified platform, and explained the evolution of SASE from disjointed components to integrated multi-vendor solutions, and finally to single-vendor unified solutions like Cisco Secure Connect.

Secure Connect is built on two platforms: Meraki SD-WAN and Umbrella SASE solution. The architecture is designed to connect and secure branches, remote access users, and ZTNA (Zero Trust Network Access) methods. It enables secure access to resources on the internet, on-premises, or in public/private clouds.

Akshar focused on branch connectivity and cloud security functionalities, emphasizing the firewall aspect. He highlighted the simplicity of onboarding branches to the Secure Connect platform and the ability to handle large numbers of sites quickly. The demo showed how Secure Connect integrates into the Meraki dashboard, allowing users to connect sites to regions and verify connectivity.

He addressed concerns about latency and bandwidth, explaining that Secure Connect optimizes traffic within the data center and between regions. The solution provides guaranteed bandwidth per uplink per site, and prioritizes traffic based on quality of service (QoS) policies.

Akshar also discussed cloud security functions, including DNS inspection, cloud firewall with IPS inspection, and Secure Web Gateway (SWG) for deeper inspection. He introduced a centralized management interface for global policy enforcement, allowing users to define rules once and apply them across multiple branches and the cloud.

Finally, he addressed questions about API access, licensing, egress charges, and traffic analytics, indicating that Secure Connect offers detailed reporting and control over traffic and policies.


Broadcom Thor 2: High Performance Ethernet NIC for AI/ML

Event: Cloud Field Day 19

Appearance: Broadcom Presents at Cloud Field Day 19

Company: Broadcom

Video Links:

Personnel: Hemal Shah

The large scale of AI/ML cluster requires high-performance networking solutions. In this talk, we will provide an overview of Broadcom’s high-performance Ethernet NIC for AI/ML clusters. Hemal Shah, Distinguished Engineer and Architect, will describe RoCE and congestion control features of the NIC, a reference AI/ML cluster architecture based on Broadcom switches and NICs, and benefits of end-2-end networking.

Shah begins with a discussion of the importance of high-performance networking for AI/ML clusters. He emphasizes that as AI/ML workloads increase in complexity and scale, networking becomes crucial for efficient job completion times. Shah provides an overview of Broadcom’s Ethernet NIC (Network Interface Card), which is designed to meet the demands of AI/ML clusters.

He explains that AI/ML clusters require networking that can handle large amounts of data and support high-speed, low-latency communication between nodes. Broadcom’s NICs and switches are designed to work together to provide end-to-end networking solutions that address these needs.

Shah outlines the key features of Broadcom’s 400 gig NIC, including:
– Support for RDMA over Converged Ethernet (RoCE) and congestion control, which are important for AI/ML workloads.
– The ability to handle 400 gig bi-directional line rates with low latency to ensure rapid data transfer.
– PCIe Gen 5 by 16 host interface compatibility to maintain high throughput.
– Advanced congestion control mechanisms that react to network congestion and optimize traffic flow.
– Security features like hardware root of trust to ensure only authenticated firmware runs on the NIC.

Shah also discusses the reference architecture for an AI/ML cluster that incorporates Broadcom switches and NICs, designed to scale to thousands of GPUs and provide robust networking capabilities. He concludes by highlighting the importance of end-to-end fabric management for operating large-scale networks effectively, which includes automation, performance monitoring, and diagnostic capabilities.


Broadcom Qumran3D: The Industry’s First 5nm 25.6T Router

Event: Cloud Field Day 19

Appearance: Broadcom Presents at Cloud Field Day 19

Company: Broadcom

Video Links:

Personnel: Sharon Nagar

Sharon Nagar, Principal PLM, gives a review of the latest Broadcom innovations in the WAN space and the world’s first 5nm, 25T router on a single chip. The presentation will cover the phenomenal level of integration that went into the Qumran3D shrinking what used to be a multi RU chassis into a single chip solution, significantly reducing the space and power needed to operate high end routers.

Nagar highlights Broadcom’s work in switching and routing, noting the three main product lines: Trident, Tomahawk, and Jericho, each optimized for different market segments and use cases. These devices share common infrastructure, including connectivity, enhanced telemetry features, and the software core known as the SDK.

The Qumran 3D is a 25 terabit router that is a full carrier-grade router with deep buffers, large routing databases capable of holding the entire internet routing table, and an encryption engine for all its throughput. The Qumran 3D represents a significant advancement in integration, shrinking what used to be a multi-RU (rack unit) chassis into a single chip solution, which reduces space and power requirements for high-end routers.

Sharon explains that the Qumran 3D is part of the Qumran product line, which has been around for ten years and is a parallel line to the Jericho series. The Qumran 3D offers a 100-fold speed increase and 95% power efficiency improvement over the technology from ten years ago. The device has 256 100G PAM4 SerDes, allowing for various port speeds and configurations, and integrates advanced features such as hierarchical traffic management, encryption, and a large number of access control lists (ACLs) and counters.

The Qumran 3D is designed to be flexible and modular, supporting virtualization and multi-tenancy for cloud environments. It comes with tens of thousands of virtual routes and thousands of tunnels, allowing for a large number of services and customers. The routing table has ample capacity to accommodate internet routing table growth until 2030, and the device has over one million ACL rules for policies and security. The encryption engine provides the option to encrypt all traffic without limitations, and the counters on the device help monitor and manage traffic flow and subscriber usage.

The device’s SerDes exceed industry standards, allowing for various optical and copper connection solutions, including linear drive optics, coherent optics, co-packaged optics, and extended reach copper cables. This flexibility offers cost and power savings for operators.

The Qumran 3D’s capabilities make it suitable for various network applications beyond cloud settings, including service provider environments. It can replace larger, more complex systems with multiple chips, simplifying software control and reducing power and space requirements.


Broadcom Trident5-X12: Smarter Cloud Infrastructure

Event: Cloud Field Day 19

Appearance: Broadcom Presents at Cloud Field Day 19

Company: Broadcom

Video Links:

Personnel: Robin Grindley

Network infrastructure for the cloud is undergoing a phase change. Robin Grindley Principal PLM, presents Broadcom’s new Trident5-X12 chip introduces new capabilities to enhance performance and security, aided by a the introduction of a novel line-rate, packet-processing inference engine called NetGNT.

In this presentation, Robin Grindley from Broadcom introduces the new Trident5-X12 chip, which is designed to upgrade cloud infrastructure by enhancing performance and security. The chip features a line-rate packet-processing inference engine called NetGNT, which allows for real-time analysis of network traffic to identify patterns and potential security threats without software intervention.

The Trident5-X12 chip offers various capabilities, including support for 800 gigabit Ethernet ports, cognitive routing, and programmable packet processing pipelines using Broadcom’s Network Programming Language (NPL). The NetGNT engine is a key innovation that can be trained to recognize specific traffic patterns, such as those associated with denial-of-service attacks, and take appropriate actions at line rate.

Grindley emphasizes that the cloud is evolving with new demands, particularly due to AI and ML workloads, which require advanced networking solutions capable of handling high bandwidth and providing security at scale. The Trident5-X12 chip is positioned to address these needs by offering powerful, programmable hardware that operates at the speeds required by modern cloud infrastructures.


Dell Technologies APEX Cloud Platform Deep Dive

Event: Cloud Field Day 19

Appearance: Dell Technologies Presents at Cloud Field Day 19

Company: Dell Technologies

Video Links:

Personnel: Samuel Niemi

If data is the fuel then applications are the engine for innovation in the digital age. Applications teams need a consistent environment across multicloud infrastructure to enable seamless workload compatibility for VMs and Containers, as well as streamlined operations between private and public cloud locations. Sam Niemi, Product Manager, will lay out Dell’s strategy for multicloud platforms and overview the key features of Dell’s APEX Cloud Platforms, that bring native cloud ecosystems on premises in a turnkey package.

Sam Niemi presents an overview of Dell’s APEX Cloud Platforms, which aim to address challenges in deploying multicloud infrastructure. These challenges include unpredictable costs, management complexity due to multiple cloud vendors, inconsistencies across clouds, skills gaps, and limited visibility.

The APEX Cloud Platforms are designed to provide a consistent environment across multicloud infrastructures, enabling seamless workload compatibility for VMs and Containers and streamlined operations between private and public cloud locations. They offer a “cloud to ground” approach by bringing native cloud ecosystems on-premises in a turnkey package.

APEX Cloud Platforms focus on the “three Cs”: Choice, Consistency, and Control. They offer a choice of vendors, consistent management across different cloud platforms, and control that simplifies operations.

Key features of APEX Cloud Platforms include:

– Foundation software for consistent management regardless of the cloud platform (Azure, Red Hat OpenShift, VMware).
– Integration with Dell Enterprise SDS (Software-Defined Storage), specifically PowerFlex, for storage scalability and performance.
– Utilization of PowerEdge servers with the latest generation Intel Xeon processors for hardware resilience.

Sam emphasizes the importance of common building blocks in APEX Cloud Platforms, which ensure consistent management and operations (MNO), flexibility in deployment, shared storage capabilities, embedded security features, and uniform support services.

He also discusses the Cloud Platform Foundation software, which provides lifecycle management, fleet management, integrated support, and other functionalities built into the vendor’s control plane. The platform supports continuous validation and patching, ensuring systems remain up-to-date without requiring extensive testing from the customer.

In summary, APEX Cloud Platforms offer a standardized, integrated solution for multicloud environments, enabling customers to manage various cloud services with greater ease and efficiency.


Dell Technologies APEX Navigator for Managing Multicloud Storage

Event: Cloud Field Day 19

Appearance: Dell Technologies Presents at Cloud Field Day 19

Company: Dell Technologies

Video Links:

Personnel: Kiruthika Gopal, Prateesh Sharma

With IT infrastructure distributed across multiple cloud environments, centralized management becomes a key element for multicloud operations. Prateesh Sharma, Product Manager, will highlight key capabilities of Dell Navigator for Multicloud Storage, including security, deployment, management, monitoring and data mobility across multicloud infrastructure.

Sharma presents the capabilities of Dell Apex Navigator for Multicloud Storage, which is a centralized management console designed to manage IT infrastructure across multiple cloud environments. He outlines five key capabilities of the tool:

1. Security: Apex Navigator emphasizes security with an API-first approach, federation, identity provider support, and single sign-on (SSO) to align with zero trust policies.
2. Deployment: It simplifies deployment to the cloud with four configuration steps, automating the provisioning of AWS resources.
3. Management: The tool offers in-context navigation to storage management tools for a seamless management experience.
4. Monitoring: Apex Navigator provides a single view for monitoring capacity and inventory, aiming to save time for users.
5. Data Mobility: It supports data movement across multicloud infrastructure, reducing manual interventions and custom processes.

Apex Navigator is built to accommodate different operating models, whether users prefer a graphical interface or API integration for automation. It can also be integrated with tools like Terraform.

The tool is offered as a SaaS-based solution, hosted on the web, and comes with a separate cost due to the value it provides in terms of automation, management, and complexity reduction. The presentation also touches on the future vision and strategy for Apex Navigator, including its support for deployments on Azure and other hyperscalers, as well as data mobility across different cloud providers.


A Strategy for Multicloud by Design with Dell Technologies

Event: Cloud Field Day 19

Appearance: Dell Technologies Presents at Cloud Field Day 19

Company: Dell Technologies

Video Links:

Personnel: Prateesh Sharma

How can organizations architect their IT infrastructure to maximize advantage of using multiple cloud platforms? Damon will provide an overview of Dell’s approach to helping customers optimize multicloud infrastructure and set the context for the rest of the sessions.

Prateesh Sharma, a Product Manager at Dell Technologies, discusses the concept of “multicloud by design” and how Dell is assisting customers in managing their multicloud infrastructure. He highlights the common scenario where organizations use both public cloud services for their scalability and innovative features, and on-premises infrastructure for business-critical workloads. Sharma points out the challenges of using multiple clouds, such as experience inconsistencies, unpredictable costs, management complexity, skill gaps, and visibility issues.

To address these challenges, Dell proposes a universal storage layer that acts as a foundation for multicloud by design. This layer offers a consistent set of storage services that are software-defined and behave like cloud services, supporting both VMs and containers with Kubernetes. These services are designed to be automated through standardized, open APIs and to provide a consistent application environment across different cloud ecosystems.

Dell’s solution includes a centralized management portal to enhance visibility and automation across the multicloud landscape. The company’s approach, termed “ground to Cloud strategy,” ensures that the same enterprise storage infrastructure available on-premises is also offered in the cloud, behaving like native cloud services. Furthermore, Dell’s Apex Cloud platform brings cloud applications to the ground, creating a seamless experience for customers.

Sharma emphasizes that Dell not only provides a unified environment but also facilitates the orchestration of data mobility and workload management between on-premises and cloud environments, ensuring a seamless and efficient customer experience.


Platform9 EMP Cost Analyzer and EKS Cluster Management Demo

Event: Cloud Field Day 19

Appearance: Platform9 Presents at Cloud Field Day 19

Company: Platform9

Video Links:

Personnel: Madhura Maskasky, Peter Fray

Platform9 Systems demonstrates Elastic Machine Pool (EMP) Cost Analyzer and their approach to managing Amazon EKS clusters. Peter Fray, Field CTO, and Madhura Maskasky, VP of Product, showcase how their tool can calculate potential savings for AWS EKS clusters by analyzing current costs and projecting savings and explain how EMP serves as an alternative to AWS Fargate by managing worker nodes and potentially reducing costs.

The demo includes the following:
1. An overview of the existing AWS environment with EC2 worker nodes.
2. A live demo of the EMP Cost Analyzer, projecting significant cost savings by running multiple EC2 instances on a single bare metal node.
3. A discussion on how EMP compares to AWS serverless offerings like Lambda and Fargate, emphasizing cost savings and management benefits.
4. An explanation of how to install the cost analyzer using a Helm chart and how it integrates with AWS.
5. A demonstration of how to create and manage EVM pools, configure overcommitment, and scale bare metal nodes according to workload demand.
6. An outline of the process for migrating from a traditional EKS cluster to one managed by EMP.
7. A discussion on the future expansion of EMP beyond AWS EKS to other Kubernetes offerings and possibly EC2.
8. A Q&A session addressing technical details, automation capabilities, and go-to-market strategies, including the AWS marketplace presence.

The demo illustrates the potential for significant cost savings and simplified cluster management for AWS EKS users through the use of Platform9’s EMP.


Introduction to Platform9 Elastic Machine Pool

Event: Cloud Field Day 19

Appearance: Platform9 Presents at Cloud Field Day 19

Company: Platform9

Video Links:

Personnel: Madhura Maskasky

In this presentation, Madhura Maskasky, the Co-Founder and VP of Product at Platform9 Systems, introduces their new product called Elastic Machine Pool (EMP). EMP aims to optimize compute utilization and reduce costs for Kubernetes in public clouds by at least 50%. EMP is unique in the market because it addresses the inefficiency of Kubernetes, which often uses only around 30% of its allocated resources.

EMP works by provisioning bare metal nodes and deploying optimized virtual machines on top of them, called elastic virtual machines (EVMs). A rebalancer component ensures even distribution of resources across the pool of bare metal nodes and can live-migrate VMs without disrupting applications. This allows for over-provisioning and better bin packing without compromising application SLAs.

The product targets DevOps, FinOps, and PlatformOps users and fits into the FinOps landscape by potentially reducing EKS costs significantly. EMP is complementary to other tools that provide cost visibility but differentiates itself by improving utilization and eliminating the need to constantly adjust app configurations for cost optimization.

EMP is licensed on a risk-reward model, charging a percentage of the actual savings it generates for customers. The discussion also covers the importance of feedback loops for engineers to understand resource usage better and the potential expansion of EMP to other clouds beyond AWS.

The presentation concludes with an emphasis on the significant potential cost savings that EMP can offer and its ability to operate seamlessly within existing Kubernetes clusters without requiring fundamental changes or app disruptions.


Democratizing Cloud Computing with Platform9

Event: Cloud Field Day 19

Appearance: Platform9 Presents at Cloud Field Day 19

Company: Platform9

Video Links:

Personnel: Madhura Maskasky

Madhura Maskasky, Co-Founder and VP of Product at Platform9 Systems, introduces Platform9, the main offerings of the company, and a discussion about the “cloud engine” which forms the unique IP that wraps around open-source software to simplify operations with “Always-On Assurance”. The session will further outline the proactive operations methodology, which includes Comprehensive Monitoring, Proactive Issue Identification, Automated Alerting and Ticket Generation, Enhanced System Reliability. The session will end with a review of how a full stack is deployed across 1000s of location in an automated and repeatable way.

The session covers an overview of Platform9, its mission to democratize cloud computing, and the unique services it offers to enterprises. Platform9’s approach involves using open-source software like Kubernetes, OpenStack, and other components, which are then packaged and deployed through a SaaS model. This is coupled with their “Always-On Assurance” guarantee, which ensures high operational efficiency and reliability for cloud infrastructures at scale.

The proactive operations methodology includes comprehensive monitoring, proactive issue identification, automated alerting, and ticket generation. This methodology is powered by a “hidden product” that operates 24/7, monitoring infrastructure, collecting metrics, and analyzing data to maintain a 99.9% SLA for enterprise customers.

During the session, Madhura explains how Platform9 manages customers’ infrastructure remotely, configuring hardware, installing operating systems, deploying Kubernetes or OpenStack, and providing a layer of PaaS services for applications. The discussion also touches on technical aspects such as the use of Prometheus for metrics, Loki and ELK for log aggregation, and Vault for secret management.

Questions from the audience address the intervals at which data is collected, the use of other tools like Splunk and Dynatrace, and the role of Platform9’s support team in application-level monitoring. It is clarified that while Platform9 is responsible for platform-level SLAs, customers can still use their own tools for application-level monitoring and can request access to Platform9’s collected data if needed.

The session concludes with Madhura mentioning some of Platform9’s customers, such as Juniper Networks, Rackspace, Cloudera, and SambaNova, and noting that they manage over 15,000 active nodes worldwide. An attendee inquires about HPE’s use of Platform9, and Madhura confirms that an HPE team uses their OpenStack product for DevTest private cloud purposes.