Shai Silberman, Product Manager
Prabhjit Singh Bagga, Technical Marketing Engineer, Tech Lead
Physical or Virtual on AWS or VMware ESXi
Revolutionize Your Network
Management with Cisco
Catalyst Center
BRKOPS-2521
http://cs.co/catalyst-center-youtube
Agenda
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
How do I manage my complex, hybrid
networks with Catalyst Center?
Is there any new Catalyst Center Physical
Appliance?
How do I easily deploy Catalyst Center on
AWS and ESXi?
How do I secure and manage my
deployments on AWS and ESXi?
How does HA work with Catalyst Center on
AWS and ESXi?
How do I migrate from Physical Appliance
to Catalyst Center on AWS?
How do I backup my Catalyst Center and
restore if needed?
BRKOPS-2521
3
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
About Shai..
BRKOPS-2521
Was a DJ
I am a twin
Coached football (not the American one)
20+ years of industry experience
Catalyst Center Product Manager
Previously, I was a customer
EX-Cisco Champion
MBA+MSSE
Lecturer @SJSU
Two truths and a lie
4
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
About Prabhjit..
BRKOPS-2521
12+ Years with Cisco
3+ Years in TAC
3+ Years in Solution Testing (4G/LTE,
VoLTE)
3+ Years as Cloud Engineer
5+ Years as a TME in SDA and Catalyst
Center
I started school when I was 2 years old
I can ride a scooter with 5 people on it
Two truths and a lie
5
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Catalyst Center adoption continues to grow
11K Devices added per day in last 12 months
6
BRKOPS-2521
12M
Network Devices Managed
8M APs | 3M Switches | 200k Routers | 89k WLCs
50% Y/Y
200 Million
Unique Monthly Clients
31k
Monthly Active Users
25% Y/Y
includes 72% of Fortune 100!
6 Billion
Network Events analyzed weekly
with AI Network Analytics
2 Billion
API Calls performed annually
by customers
Population of Brazil
203 Million 2.5% of global population
Nearly 10 million events per
second
Nearly 64 calls per second
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
7
Virtual Appliance (VA) Accomplishments
BRKOPS-2521
130
Active Deployments
19,440
Total Devices
Total Wireless
WLC: 265
AP: 13,361
Total Clients
139,279
75
Active Deployments
10,406
Total Devices
Total Wireless
WLC: 213
AP: 7667
Total Clients
65,753
Catalyst Center
on AWS
Catalyst Center
on ESXi
Catalyst Center
Options
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Catalyst Center Virtual Appliances
The new cool kids on the block!
9
BRKOPS-2521
Supported Worldwide
15 AWS regions supported;
with more coming!
Take advantage of your EDP
Customer-supplied on-premises
server
Customer-supplied VMware
license
VM Requirement:
32vCPU, 256GB Ram, 3TB Storage
*Check datasheet for additional
requirements
No cost for software ($0 PID)
Optional support can be purchased
Quicker time to value
Deploy in 90 min
Scale parity
with DN2-HW-APL(44 core
appliance):
25,000 End points
1,000 switches
4,000 access points
1,500 sites
Clustering instances not supported
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Virtual appliances
3-XL
M
L
XL
M
L
XL
Catalyst Center operational evolution
Scaling to meet your enterprise needs
Single
appliance
HA cluster 3x scale
With XL
Appliances
Virtual Appliance Scale parity with DNx-HW-
APL(44 core appliance)
Scale
Down
Scale Up
VA Vertical Scale
Physical appliances Manager of Managers
**Future
GA
GA
There is no scale
difference between
DN2 & DN3 appliances
**Future
**Future
**Future plans subject to change
BRKOPS-2521
10
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Catalyst Center platform system scale
Description
Medium appliance
DN2-HW-APL
Large appliance
DN2-HW-APL-L
Extra large appliance
DN2-HW-APL-XL
3 XL cluster Virtual appliance
Endpoints (concurrent) 25,000 40,000 100,000 300,000 25,000
Network devices 5,000 8,000 25,000 35,000 5,000
APs 4,000 6,000 13,000 25,000 4,000
Sites 1,500 5,000 10,000 10,000 1,500
Access control policies 25,000 25,000 25,000 25,000 25,000
Access contracts 500 500 500 500 500
Per fabric site scale
Fabric nodes 500 600 1,200 1,200 500
VNs 64 128 256 256 64
IP pools 100 300 1,000 1,000 100
Latency between DNAC to device: 200ms (RTT)
As of 2.3.7.x
BRKOPS-2521
11
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Appliance Licensing and Support Requirements
Physical
ESXi
AWS
Appliance
License
Perpetual
Perpetual
perpetual
Support
Term
Term
Term
SNTC Support
Requirement
Mandatory
Recommended
Recommended
Subscription Licenses are only attached to network devices (Switch, Router, AP, WLC) and
cover feature support on Catalyst Center. (PnP, Swim, Assurance…)
Support for Physical appliances (SNTC) is mandatory at the time of purchase
Support for VA appliances (SNTC) is recommended at the time of purchase (Infra Support)
BRKOPS-2521
12
Physical Appliance
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Appliance Roadmap and Migration
14
BRKOPS-2521
DN1-LDOS
DN2-EoS
DN2-Last Ship
date
DN3-FCS
DN3-Ship
DN3
DN2
DN1
DN1-last SW
release
CY24Q1 CY24Q2 CY24Q3 CY24Q4
CY23Q4
2.3.7.5
Catalyst
Center SW
release
June Release2.3.7.4
ROADMAPS AND TIMELINES SUBJECT TO CHANGE
ALL FUTURE DATES ARE FCS RELEASES AND SUBJECT TO CHANGE
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
DN3-HW-APL (32C) ~1.1KW 1,428.31 BTU/hr
i6326 2x16C @2.8/4Ghz, 2x185W, 256G RAM
DN3-HW_APL-L (56C) ~1.3KW 2,159.40 BTU/hr
i6348 2x28C@2.7/4Ghz, 2x235W, 384G RAM
DN2-HW-APL-XL(112C) ~2KW 2,573.32 BTU/hr
i8276 4x 28C@2.2/4Ghz, 4x165W, 768G RAM
DN2-HW-APL (44C) ~1KW 1,236.10BTU/hr
i6238 2x22C @2.1/3.7Ghz, 2x140W, 256G RAM
DN2-HW-APL-L (56C) ~1.2KW 1,485.35BTU/hr
I8280 2x28C@2.7/4Ghz, 2x205W, 384 RAM
4U
2U
DN3-HW-APL-XL (80C) ~1.9KW 2,107.36BTU/hr
i8380 2x40C @2.3/4Ghz, 2x270W, 768G RAM
Note: There is no scale difference between DN2 & DN3 appliances
Power, BTU and space savings
DN2/DN3 appliance comparison
15
BRKOPS-2521
Deployment Steps
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Bring-up Cisco Catalyst Center On-premises
17
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Order and Wait for the Lead Time
18
BRKOPS-2521
DCOps
Lab Admin
IT/NetOps
Order Supply
Chain
Shipping Datacenter
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Rack/Stack/Cable
19
BRKOPS-2521
Enterprise Port
10Gbps Interface
Network Adapter 1
OS Label# enp94s0f0
Intracluster Port
10Gbps Interface
Network Adapter 4
OS Label# enp94s0f1
Management Port
1Gbps Interface
Network Adapter 1
OS Label# eno1
Internet Port
1Gbps Interface
Network Adapter 2
OS Label# eno2
CIMC Port
1Gbps Interface
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Switch Configuration for Cisco Catalyst Center
20
BRKOPS-2521
Cisco Catalyst CenterSwitch
TenGi
g1/1/3
Enterprise
Port
dist-dc-01#config terminal
dist-dc-01(config)#interface tenGigabitEthernet 1/1/3
dist-dc-01(config-if)#switchport mode access
dist-dc-01(config-if)#switchport access vlan 99
dist-dc-01(config-if)#speed auto
dist-dc-01(config-if)#duplex full
dist-dc-01(config-if)#mtu 1500
dist-dc-01(config-if)#no shut
dist-dc-01(config-if)#end
dist-dc-01#copy running-config startup-config
Access VLAN
Speed Auto
Duplex Full
MTU 1500
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
21
Maglev Config Wizard Steps
BRKOPS-2521
Catalyst Center
Virtual Appliance
(VA) on ESXi
Why Deploy on ESxi
Modes of Deployment
Demo
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why Deploy Catalyst Center on ESXi
Quicker time to value from weeks to 2 hours
Operational flexibility and choice for customers
No additional CAPEX associated w/ physical appliance
Drive Sustainability
Using AWS and VMware’s native HA functionality
BRKOPS-2521
23
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Specifications of
DNAC VM
Specifications of Server Device Scale
Catalyst
Center (CC)
VA on ESXi
Type: OVA
CPU: 32vCPU
Mem: 256GB
Storage: 3TB
Storage Bandwidth: 180Mbps (Bi
-
directional)
IOPS: 2000-2500
vCenter and ESXi: 7.0.x
Intel CPU 2.1Ghz and above
Hyperthreading enabled
RAM: 256 GB for VA
RAID: Any as long as bandwidth
and IOPS
25K End-points
1K Devices
4K APs
2500 site elements
Specifications, Features, and Scale
BRKOPS-2521
Note: Make sure to reserve additional 8GB RAM for ESXi
24
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Things to Consider When Planning your
Deployment
BRKOPS-2521
Ease of Deploying Resources on ESXi HA with DRS
Headless Install of
Catalyst Center
Multiple Catalyst
Centers
Am I going to fired for this?
25
How many of you
Bring up/Manage
VMware and ESXi
environment by
yourself?
Show of Hands
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Two Methods
Download OVA and
Launcher Script
Verification of Resources
Headless Install
Auto Mode
Cisco Launcher App
Manual Mode
Deploy OVA on ESXi or
vCenter
Download OVA
Deploy using OVF Template
Configure using Maglev
Wizard
Deploy on multiple ESXi
Hosts
BRKOPS-2521
27
Auto Mode
Cisco Launcher
App
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why do I need Launcher App?
Verification of ESXi Resources
Headless Install
29
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why do I need Launcher App?
BRKOPS-2521
Verification of ESXi Resources
Headless Install
Central Location to Deploy multiple
Catalyst Centers
vCenter/ESXi Hosts
Datacenter 2
Launcher
App
Datacenter 1
ESXi-01
10.10.10.1
20.20.20.1
ESXi-02
30
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Pre-requisites to Auto Mode using Cisco Launcher
VMware Launcher App
Download OVA and Launcher App from Cisco.com
vCenter or ESXi
Create one or two networks (optional) for Catalyst Center
Create Resources 32 vCPU, 256GB RAM, 3TB Storage
Decide to use Thick or Think Provisioning
Note IP Address of vCenter or ESXi to configure config.json file
Note IP Address for Catalyst Center, NTP IP, DNS IP
Note Proxy IP/URL to configure config.json file
BRKOPS-2521
31
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
How does Launcher work?
BRKOPS-2521
Download Launcher Script on Linux,
Windows, or Mac
Configure json file
vCenter/ESXi Host IP, Datacenter
Name, Datastore Name, Cluster Name
Launcher
App
Path of Catalyst Center OVA
Catalyst Center IP, DNS IP, NTP IP,
Proxy IP/URL
Deploy OVA and Headless Install of
Catalyst Center
config.json
vCenter/ESXi
vCenter/ESXi Host IP
Datacenter Name
Path of CC OVA
CC IP, DNS, NTP, Proxy
32
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Catalyst Center Accessible!
BRKOPS-2521
33
Demo
Launcher App
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
35
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Time Estimate for Auto Mode Deployment
~30 mins ~ 40 mins
Config File
Run the
Launcher Install
Script
VA Ready
~ 60-90 mins
BRKOPS-2521
Note: Values are approximate and may vary due to factors like network speed, EXSi
resources, and connectivity
36
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Pre-requisites to Deploy using Manual Mode
VMware Catalyst Center
Download OVA from Cisco.com
vCenter or ESXi
Create one or two networks (optional) for Catalyst Center
Resources 32 vCPU, 256GB RAM, 3TB Storage
Decide to use Thick or Thick Provisioning
Reserve IP Address for Catalyst Center
Note DNS IP Address, NTP IP Address, Proxy IP Address/URL
Catalyst Center CLI Maglev Password
BRKOPS-2521
37
Demo
Manual Mode
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Time Estimate for Manual Mode Deployment
~30 mins ~10 mins ~5 mins ~45 mins
Deploy OVA
Maglev CLI Inputs
Maglev CLI
Available
Install/Pre-
manufacture VA
Ready
~ 60-90 mins
BRKOPS-2521
Note: Values are approximate and may vary due to factors like network speed, EXSi
resources, and connectivity
40
Catalyst Center on AWS
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Enterprise
Tunnel
Subnets
Cisco
Catalyst
Center AMI
EC2
Cisco Catalyst Center VA
Security
Group
VPN-GW/TGW
IPsec Tunnel
Internet
Deployment Overview
42
BRKOPS-2521
CGW
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploy
Anywhere
Sustainable
HA Native
AWS Features
Quicker
Time to Value
BRKOPS-2521
43
How many of you
Bring up/Manage AWS
environment by
yourself?
Show of Hands
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Things to Consider When Planning your
Deployment
BRKOPS-2521
Ease of Deploying Security Single Pane of Glass
Observability Serviceability
45
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Three Modes to Deploy CC VA on AWS
Auto Mode
(Cisco Launchpad
App)
Manual Mode
(CloudFormation
Template)
Manual Mode
(AWS
Marketplace)
BRKOPS-2521
46
Auto Mode
Cisco Launchpad App
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploy AWS across the globe, VPC, Security Groups, VPN-GW, IPSec
Tunnel, GP3, SSD, S3, EBS, Deploy of CC Globally
Ease of Deploying
AWS + CC
Why Deploy CC Using Launchpad?
48
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
No Internet Gateway, Changes only by admin, IPSec or TGW attachments
Security
Security Group
Why Deploy CC Using Launchpad?
49
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why Deploy CC Using Launchpad?
50
BRKOPS-2521
Single Pane of Glass
Manage AWS and Catalyst Center globally view dashboard
Concurrently
deploy around
the world in ~
75 mins
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
CloudWatch to observe any changes/misconfigurations/alerts
Observability
Why Deploy CC Using Launchpad?
51
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Monitoring Global Alerts, Get SNS notification, Create RCA Bundles
Serviceability
Why Deploy CC Using Launchpad?
52
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Where is it available?
Log into Launchpad via Cisco hosted
or Customer hosted container app
Cisco Hosted
Container App
53
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
How Does it work?
Log into Launchpad via Cisco hosted
or Customer hosted container app
Launchpad creates a VPC in your
AWS with security hardening
Launchpad
App
Internet
VPC-1 VPC-2 VPC-3
VPC-CC
Security Groups
Admin User
No Internet Gateway
Security Hardening
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
55
How Does it work?
BRKOPS-2521
Log into Launchpad via Cisco hosted
or Customer hosted container app
Launchpad creates a VPC in your
AWS
Launchpad helps you Configure IPsec
Tunnel / connect to TGW
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
IPsec VPN Configuration
56
BRKOPS-2521
crypto ikev1 enable <outside_interface>
crypto ikev1 policy 200
crypto ipsec ikev1 transform-set ipsec-prop-vpn-06c14b5f0791af2f8-0 esp-aes esp-sha-hmac
crypto ipsec df-bit clear-df <outside_interface>
sysopt connection tcpmss 1379
crypto ipsec security-association replay window-size 128
crypto ipsec fragmentation before-encryption outside
tunnel-group 3.109.140.185 type ipsec-l2l
tunnel-group 3.109.140.185 ipsec-attributes
ikev1 pre-shared-key jK8CORoyB3QPnr5GsPKvSdYbj.YP_oIu
route Tunnel-int-vpn-06c14b5f0791af2f8-0 172.16.2.0 255.255.255.0 169.254.39.245 100
Enable Internet Key Exchange (IKE) Configuration
A policy is established for the supported ISAKMP encryption,
Change the <outside_interface> to
the name of your public-facing
interface
Tunnel Interface
Configuration
Static Route Configuration
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
57
Choose Your Connection from AWS to On-premises!
BRKOPS-2521
VPN GW
New VPN GW + New TGW
Existing TGW
EC2
Tunnel
EC2
EC2
EC2
Customer Gateway
EC2
Note:
Existing TGW can have
attachments like IPSec
Tunnel, Direct Connect,
etc.
VPN GW
TGW
VPN GW
VPN GW VPN GW
VPN GW
TGW
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Supported Customer Gateway (CGW) Devices
58
BRKOPS-2521
Vendor Platform Software
Checkpoint Gaia R80.10+
Cisco Meraki MX Series 15.12+
(WebUI)
Cisco
Systems, Inc.
ASA 5500
Series
ASA 9.7+ VTI
Cisco
Systems, Inc.
CSRv AMI IOS 12.4+
Juniper
Networks,
Inc.
J-Series
Routers
JunOS 9.5+
Juniper
Networks,
Inc.
SRX
Routers
JunOS 11.0+
Vendor Platform Software
Mikrotik RouterOS 6.44.3
Fortinet Fortigate
40+ Series
FortiOS 6.4.4+ (GUI)
Palo Alto
Networks
PA Series PANOS 7.0+
SonicWall NSA, TZ OS 6.5
Sophos Sophos
Firewall
v19+
Strongswan Ubuntu
16.04
Strongswan 5.5.1+
Yamaha RTX
Routers
Rev.10.01.16+
Note:
Link: https://docs.aws.amazon.com/vpn/latest/s2svpn/your-cgw.html
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
How Does it work?
59
BRKOPS-2521
Log into Launchpad via Cisco hosted
or Customer hosted container app
Launchpad creates a VPC in your
AWS
Launchpad helps you Configure IPsec
Tunnel / connect to TGW
Launchpad deploys CC VA in the VPC
Launchpad
App
Internet
VPC-1 VPC-2 VPC-3
VPC-CC
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
60
Cisco Catalyst Center is UP !!
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Time Taken From 0 to 100…
BRKOPS-2521
5-7
mins
1-2
mins
~5 mins ~ 40 mins
~10 mins +
VA Pod
Open
Firewall
Cloud
Backup
VM
VA
Platform
VA Ready
60-75 mins
Note: Values are approximate and may vary due to factors like network speed, EXSi
resources, and connectivity
61
Demo
Auto Mode
Launchpad App
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
63
Manual Mode
CloudFormation
Template
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Download
CloudFormation
Template
+
AWS Account
Steps to Deploy using Manual Mode
CloudFormation Template
BRKOPS-2521
65
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
VPC
Subnet for
VA
Security
Group
Keypair
Connectivity
to On-prem
Steps to Deploy using Manual Mode
CloudFormation Template
VPC
BRKOPS-2521
66
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
VPC
Subnet for
VA
Security
Group
Keypair
Connectivity
to On-prem
Steps to Deploy using Manual Mode
CloudFormation Template
Subnet for VA
BRKOPS-2521
67
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
VPC
Subnet for
VA
Security
Group
Keypair
Connectivity
to On-prem
Steps to Deploy using Manual Mode
CloudFormation Template
Security Group
BRKOPS-2521
68
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
VPC
Subnet for
VA
Security
Group
Keypair
Connectivity
to On-prem
Steps to Deploy using Manual Mode
CloudFormation Template
Keypair
BRKOPS-2521
69
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
VPC
Subnet for
VA
Security
Group
Keypair
Connectivity
to On-prem
Steps to Deploy using Manual Mode
CloudFormation Template
Connectivity to On-prem
Note: Connectivity types includes IPsec Tunnel, SD-WAN, Direct Connect, Co-lo, etc.
BRKOPS-2521
70
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Open the
required ports
on Enterprise
Firewall/Router
Steps to Deploy using Manual Mode
CloudFormation Template
Type Protocol Port Description
TCP Netconf 830 Cisco Catalyst Center uses NETCONF for device
inventory, discovery, and configuration.
TCP SSH 22 Cisco Catalyst Center to ssh to network devices
UDP DNS 53 Cisco Catalyst Center uses DNS to resolve
hostnames.
UDP SNMP 161 Network device management and discovery.
TCP HTTPS 443 Cisco Catalyst Center uses HTTPS for cloud-
tethered upgrades
UDP RADIUS 1645,1812 Using external authentication with a RADIUS server.
TCP Cisco ISE 5222,8910 Cisco Catalyst Center uses Cisco ISE XMP for
PxGrid.
TCP Cisco ISE 9060 Cisco Catalyst Center uses Cisco ISE ERS API traffic.
Note: These are a subset of all ports needed. Check the entire list from this link.
BRKOPS-2521
71
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploy
CloudFormation
Template
Steps to Deploy using Manual Mode
CloudFormation Template
BRKOPS-2521
4
72
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploy
CloudFormation
Template
Steps to Deploy using Manual Mode
CloudFormation Template
BRKOPS-2521
4
73
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst Center is UP !!
BRKOPS-2521
74
Catalyst Center
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Demo
Manual mode
75
BRKOPS-2521
Demo
Manual Mode
CloudFormation
Template
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
BRKOPS-2521
77
Catalyst Center
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Manual Mode with
AWS Marketplace
78
BRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Deploy using Manual Mode
AWS Marketplace
AWS Marketplace Cisco DNA Center
Subscribe
VPC, Security Groups, VPN-GW, IPSec
Tunnel/Connectivity
AWS Infrastructure
Select VPC, Security Groups, Keypair, IP Address
Launch with EC2
Catalyst Center IP, DNS, NTP, Proxy
Inject Cloud Config
in EC2
BRKOPS-2521
79
Demo
AWS
Marketplace
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
81
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
How to Deploy Catalyst Center on AWS
Cisco Launchpad
App
(Auto Mode)
Ease of Deploying
AWS + CC
CloudFormation
Template
(Manual Mode)
AWS Marketplace
(Manual Mode)
Single Pane of
Glass
Security
Observability/
Serviceability
Time Taken
Launchpad creates AWS Infra
Launchpad Installs Catalyst Center
Launchpad Creates CloudWatch
Launchpad - RCA - AWS and CC
Launchpad helps Deploy Globally
Launchpad helps Manage Globally
Launchpad creates Security Groups
Launchpad creates Audit Role
Quick Time to Value
75 mins + Firewall Ports
Manual Creation of AWS Infra
Manual Creation - Catalyst Center
Manual creation of Alerts
Manual Troubleshooting of AWS
Does not exist
Through AWS Console
Manual creation of Tunnel
Manual creation of Security Group
Days to weeks
NFS Server
Launchpad brings up Cloud NFS
VM
Manual creation of NFS Server
Manual Creation of AWS Infra
Manual Creation - Catalyst Center
Insert Cloud Init Config
Manual creation of Alerts
Manual Troubleshooting of AWS
Does not exist
Through AWS Console
Manual creation of Tunnel
Manual creation of Security Group
Days to weeks
Manual creation of NFS Server
BRKOPS-2521
82
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco on AWS End to End Possible!
us-west-1
Cisco ISE VPC
Cisco ISE
C9800-CL C9800-CL
Controller VPC
Cisco Spaces Connector
Cisco Spaces VPC
Catalyst Center
Catalyst Center VPC
Transit
Gateway
TG Route Table
C8000v / vMX
Meraki/C8K SD-WAN
Corporate
Network
Transit Gateway Attachment
FW/Router
Connection Types: IPsec
Tunnel, SD-WAN
BRKOPS-2521
83
How many of you
would like to deploy
multiple Cisco
Products as a solution
stack on AWS?
Show of Hands
Enterprise
Readiness
Backup & Restore
High Availability (HA)
Backup/Restore
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Backup & Restore across all Form Factors
Need to be same Catalyst Center version for Backup & Restore
Same method
Backup on NFS Server
Restore on Physical
Appliance
Physical
Appliance
Same as Physical Appliance
NFS can be on AWS Cloud or
On-premises
VA on AWS
Using Physical Disk of ESXi
server
Data Retention
NFS Server also supported
VA on ESXi
New
87
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore on ESXi
Select Hard Disk as
New Device
1
This is the Disk where
Backup will be stored
88
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
Allocate Space for
this new Disk
2
89
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
Mount Path is Empty
before Creating New
Disk
3
90
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
Mount Path Shows
the New Disk
4
91
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
Create Existing disk
5
92
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
New disk added
6
93
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
Before rebooting VA
7
94
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
After rebooting
8
95
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create Backup/Restore
Back files from other
VA
9
96
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
High Availability (HA)
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Refer pre-requisites here: http://cs.co/9006ztlXG
How does HA work in Physical Appliance?
Catalyst Center Cluster
Maglev
Service A
Cisco Catalyst Center
Services
Catalyst
Center 1
Service B
Maglev
Service A
Cisco Catalyst Center
Services
Catalyst
Center 2
Service C
Service B
Maglev
Service A
Cisco Catalyst Center
Services
Catalyst
Center 3
Service B
Service B
Service C
When a service fails on
one node, Cisco
Catalyst Center starts
the service on one of the
other two cluster nodes
BRKOPS-2521
98
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Infrastructure availability from 99% to 99.99%.
Multiple DCs
Redundant Infrastructure
Low Latency
How does HA work in AWS?
BRKOPS-2521
Region
AZ-1
DC1 DC2
EC2
Using AWS’s Native HA Capabilities
99
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
How does High Availability work in ESXi?
Cluster ESXi Hosts
Shared Storage
vSphere’s Distributed Resource Scheduler
(DRS)
Enabled enabled on vCenter
vCenter/ESXi
vCenter/ESXi
vCenter/ESXi
vCenter/ESXi
vCenter/ESXi
vCenter/ESXi
VMDK
Resources Check
vMotion
Migration Options
BRKOPS-2521
100
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create HA for VA on ESXi
Creating New Cluster
1
101
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create HA for VA on ESXi
Add ESXi hosts to the cluster
2
102
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create HA for VA on ESXi
Setup HA vSphere
3
103
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create HA for VA on ESXi
Enabling the vSphere HA
4
104
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create HA for VA on ESXi
Host Failure Response
Response for Host Isolation
5
Datastore with PDL
Datastore with APD
VM Monitoring
105
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Steps to Create HA for VA on ESXi
vSphere HA is On
6
106
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco PublicBRKOPS-2521
Resources
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Catalyst Center Resources
BRKOPS-2521
Guides Release
Notes
FAQ YouTube
Community
Page
Physical
Installation Guide 2.3.5,
2.3.7
Admin Guide 2.3.5, 2.3.7
User Guide 2.3.5, 2.3.7
RN 2.3.5
RN 2.3.7.4
FAQ http://cs.co/catalyst-center-
youtube
Deployment Guide 2.3.5
Admin Guide 2.3.5
Ordering Guide
RN 2.3.5 FAQ http://cs.co/va-launchpad
http://cs.co/va-manual
http://cs.co/va-landingpage
http://cs.co/va-blog1
Deployment Guide 2.3.7.3
Admin Guide 2.3.7.4
RN 2.3.7.4 FAQ http://cs.co/catalyst-center-
youtube
108
© 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Catalyst Center on YouTube
Communities
GitHub
Salesconnect
Cisco DNA Community
DevNet
Playlists
~ 82 videos
6.88K
Subscribers
http://cs.co/catalyst-center-youtube
Want to ask Questions?
Want to Present?
Want to Learn?
Want to Automate?
109
Collaterals, Videos, and other Resources
BRKOPS-2521
Thank youThank you