k12 reference architecture - cisco · cisco cloud services metro-area provider network catalyst...

1
K12 Reference Architecture Converged Wired + Wireless Access Mobility Agent Mobility Controller Wireless IPS (WIPS) Application Visibility and Control (AVC) High Density Experience (HDX) ClientLink 3.0 Optimized AP Roaming Cross AP Noise Reduction Highly secure web-based video surveillance control system Scalable camera count in a single manager Distributed processing of all video/audio Standard video codecs in single media server Integration with advanced video analytics View live secure video from mobile devices, inside or outside school Next-generation intrustion protection Before, During, and After Attack solutions Detect and block exploit attempts Correlate discrete events into coordinated attacks Cisco Talos threat intelligence Data Loss Prevention (DLP) Track malware's spread and communication Roaming laptop user protection Cisco TrustSEC Content Filtering Identity-based Filtering and Access Control Block Encrypted Search Auto VPN Cisco Prime Infrastructure Converged Wired & Wireless Management User access visibility, inventory Radio frequency planning End-to-End application and service assurance visibility Medianet performance monitor Prime 360 Experience Cisco Prime Assurance Manager Network Control System + LAN Management Policy Management WAN bandwidth savings, lower cost to upgrade Scale application usage to available bandwidth Akamai Connect intelligent object caching WAN compression and optimization SWITCHING, WIRELESS Converged Wired Plus Wireless Access Mobility Agent Mobility Controller Modular QoS (per AP, radio, SSID, user) AutoQoS Policy Names from ISE RSPAN RMON Agent Application Visibility and Control (AVC) Flexible Netflow v9 Medianet Catalyst Smart Operations UADP ASIC hierarchical bandwidth management at line rate Virtual Desktop Consolidate desktop compute resources to data center Lightweight desktop client or remote view software Access powerful desktop compute resources from anywhere Simplify software licensing Centralize software upgrades Run fully virtualized applications in scalable data center FlexPod Unified voice and video capabilities, with IM and Presence URI dialing Extension mobility IP Multimedia Subsystem (IMS) Cisco Jabber integration (instant messaging) CUCM virtual machine Cisco Virtualization Experience clients Cisco TelePresence Conductor integration UCS compute blade module inside school router for remote compute services Processors, storage, network interfaces, memory on-board Host network, UC, security, WAAS, and compatible school applications ISR 4400 and 4500 platforms Services Ready Engine (SRE) module for ISR G2 platforms Full classroom immersive video Screen sharing with tablets and laptops using proximity Desktop video endpoint 1080p video bridging Video services in VM (virtual machine) WebEx content sharing Mobile device collaboration (Spark) Speaker Track (dual-camera tracking) Persistent chat E911 support Cisco Collaboration Prime Standard Cisco Collaboration Prime Advanced Cisco MediaSense call recording integration IP Phones, wired and wireless Cisco Jabber mobile unified client Remote video connections without VPN Optimized AP Roaming DFS Support Cross AP Noise Reduction Historical Interference Information Spectrum Expert Connect IWAN IWAN Transport DMVPN Application Visibility and Control (AVC) NBAR2 QoS PfR (Performance Routing) Path Optimization PKI Automation PnP Provisioning Intelligent Path Control Application Experience SWITCHING Chassis: 1+1 redundant supervisor, NSF/ SSO, ISSU Cisco TrustSEC IPv6 Per-port power management IOS Modular Open Application Platform Network virtualization through Multi-VRF Embedded Events Manager (EEM) Smart Call Home AutoQOS Auto SmartPorts Flexible NetFlow Mediatrace IP SLA Agent Cisco Energywise District Internet Edge ISR 4400 Series 4451 4451-AX ASR 9900 Series ASR 9904 ASR 1000 Series ASR 1001X ASR 1002 ASR 1006 Network Security ASA 5500 Series ASA 5545 ASA 5585-S40 ASA 5585-S60 ASA with FirePOWER Identity Management Identity Services Engine ISE 3355 Secure Access Control System Advanced Malware Protection (AMP) AMP for Endpoints AMP for Networks AMP for Content Security AMP Threat Grid Email Security Virtual Appliance (ESAV) Web Security Virtual Appliance (WSAV) Cisco AnyConnect Secure Mobility (VPN) Meraki MX Series MX400-HW MX600-HW Cisco Cloud Services Metro-Area Provider Network Catalyst 4500 Series District Office or Regional Data Center Compute, Services, Management Catalyst 6807XL Nexus 9500 Series Nexus 9504 Nexus 9508 Nexus 7700 Series Nexus 7706 Nexus 7710 Wireless Management 5760 Controller 8510 Controller 7510 Controller Unified Computing System (UCS) UCS C-Series UCS B-Series Cisco Desktop Virtualization Solutions Unified Communications Unified Communications Manager Business Edition 6000 Business Edition 7000 Jabber TelePresence TelePresence Server Multiparty Media 310/320 Multiparty Media 400v TelePresence Content Server (TCS) TelePresence Conductor TelePresence Management Suite (TMS) Expressway-E Expressway-C ISR 4400 Series 4451 4451-AX ASR 1000 Series ASR 1001 ASR 1002 ASR 1006 ASR 9900 Series ASR 9904 Metro Ethernet Series ME 3600-X ME 3800-X WAN Optimization WAVE 7541, WAVE 7571, WAAS Central Manager with Akamai Connect District MAN Edge School Building ISR 4300 Series 4331 4331-AX 4351 4351-AX Building Edge ISR 4400 Series 4431 4431-AX 4451-X 4451-AS ASR 1000 Series ASR 1001 Metro Ethernet Series ME 2600-X ME 3600-X WAN Optimization WAVE 594 WAVE 694 vWAAS on UCS-E blade Akamai Connect WAAS on Service Ready Engine (SRE) Catalyst 3850 Series Catalyst 4500-X Series Meraki MS Series MS-320 MS-420 Catalyst 4500 Series Catalyst 6800 Series 6807 6880 Catalyst 3850 Series Catalyst 3650 Series Catalyst 2960-X Series Meraki MS Series MS-220 Aironet 3700 Series Aironet 2700 Series Aironet 1700 Series Meraki MR34 Meraki MR32 IP Phones 7800 Series 8800 Series 8900 Series 9300 Series Collaboration Desk Endpoints DX650 DX70 DX80 Collaboration Room Endpoints SX 10/20/80 Series MX 200/300/700/800 Series IX 5000 Series TX 9000 Series Nexus 9300 Series Building Backbone (MDF Closet) Building Closet (IDF Closet) Classroom & Building Wireless Mobile Device Management Meraki Systems Manager with Enterprise Mobile Management Compact Switches 3650-CX 2960-CS Notifi-ED Security SchoolMessenger Singlewire InformaCast ObjectVideo Proximex Augusta Systems Video Surveillance IP Video Cameras Video Surveillance Manager Video Analytics Incident Response IPICS Meraki MR72 Aironet 1570 Series Outdoor Wireless Mobile Device Management (MDM) Auto RF Air Marshall Integrated Bluetooth Low-Energy Asset monitoring and tracking Active Directory enrollment integration BYOD Self-deployment IP Source Guard Unicast RPF Bi-directional SPAN for IDS 802.1X authentication Dynamic ARP inspection Port security based upon MAC address Limited MAC address learning to prevent flooding VLAN ACLs Private VLAN edge Port-based ACLs for Layer 2 Wireless end-to-end security through DTLS encryption School-wide alert systems through Singlewire partnership IP-based HD video cameras, single infrastructure Wired and wireless cameras Provider-based Direct Internet Access Leased Fiber MAN/WAN Metro Ethernet Provider Provider-based SONET, Circuit Network Systems Management Prime Infrastructure Prime Collaboration Catalyst 3850/3650 Series Meraki MS 220/320 Aironet Series Meraki MR Series District Office Staff Cabling Infrastructure - Category 5e/6/6a Copper Cabling Infrastructure - Category 5e/6/6a Copper or MM/SM Fiber Cabling Infrastructure - MM/SM Fiber Connected Learning Information Security Professional Development School Safety Learning and Curriculum Student Assessment and Data Analytics INTERNET Wireless IWAN, Switching, IOS Network Management Collaboration Cybersecurity Physical Security Compute CLOUD LEARNING APPLICATION PARTNERS Desire2Learn: WebEx into LMS/ CirQLive Pearson: WebEx into LearningStudio LMS/CirQLive Pearson: PowerSchool on UCS CLOUD-BASED NETWORK MANAGEMENT Meraki Systems Manager with Enterprise Mobility Management Cisco Active Advisor COLLABORATION MEETING ROOM (CMR) CLOUD Converged video bridging and WebEx web conferencing Join from anywhere Superior scale All video resources in cloud ENERGY MANAGEMENT CLOUD Cost-effective energy monitoring Specific recommendations to optimize energy usage Active power management ROI tools, identify best practices Quick deployment Budget predictability CLOUD WEB SECURITY / CLOUD EMAIL SECURITY Near real-time web protection Advanced malware protection Flexible network connectors to cloud Dedicated email security instance Cloud capacity assurance HOSTED COLLABORATION SOLUTION (HCS) Voice & Video As a Service Voicemail and Integrated Messaging Instant Messaging Video As a Service Mobility As a Service CLOUD COMPUTE SERVICES Dimension Data Cloud Services IaaS, CaaS (Partner) Private Cloud Vblock Infrastructure Platform Intelligent Automation for Cloud Catalyst 6800IA Cisco FirePOWER Appliances FirePower 7000 Series FirePower 8000 Series Nexus 2000 Series Catalyst 4500-X, 6880 Meraki MS Series MS-320 MS-420 © 2015 Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) C82-734320-00 04/15

Upload: others

Post on 23-Sep-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: K12 Reference Architecture - Cisco · Cisco Cloud Services Metro-Area Provider Network Catalyst 4500 Series District O˜ce or Regional Data Center Compute, Services, Management Catalyst

K12 Reference Architecture

Converged Wired +Wireless Access

Mobility AgentMobility Controller

Wireless IPS (WIPS)

Application Visibilityand Control (AVC)

High DensityExperience (HDX)

ClientLink 3.0

Optimized APRoaming

Cross AP NoiseReduction

Highly secure web-basedvideo surveillance control system

Scalable camera count in a single manager

Distributedprocessing of allvideo/audio

Standard videocodecs in singlemedia server

Integration with advanced video analytics

View live secure video from mobile devices, inside or outside school

Next-generationintrustion protection

Before, During, andAfter Attack solutions

Detect and blockexploit attempts

Correlate discreteevents intocoordinated attacks

Cisco Talos threatintelligence

Data LossPrevention (DLP)

Track malware'sspread andcommunication

Roaming laptopuser protection

Cisco TrustSEC

Content Filtering

Identity-based Filtering and Access Control

Block Encrypted Search

Auto VPN

Cisco PrimeInfrastructure

Converged Wired & WirelessManagement

User accessvisibility, inventory

Radio frequencyplanning

End-to-Endapplication andservice assurancevisibility

Medianetperformancemonitor

Prime 360Experience

Cisco PrimeAssurance Manager

Network ControlSystem + LANManagement

Policy Management

WAN bandwidthsavings, lower costto upgrade

Scale applicationusage to availablebandwidth

Akamai Connectintelligent objectcaching

WAN compressionand optimization

SWITCHING, WIRELESSConverged WiredPlus WirelessAccess

Mobility AgentMobility Controller

Modular QoS(per AP, radio,SSID, user)

AutoQoS

Policy Names from ISE

RSPAN

RMON Agent

Application Visibilityand Control (AVC)

Flexible Net�ow v9

Medianet

Catalyst SmartOperations

UADP ASIC hierarchical bandwidth management at line rate

Virtual Desktop

Consolidate desktopcompute resourcesto data center

Lightweight desktopclient or remoteview software

Access powerfuldesktop computeresources fromanywhere

Simplify softwarelicensing

Centralize softwareupgrades

Run fully virtualizedapplications inscalable data center

FlexPod

Uni�ed voice andvideo capabilities, with IM and Presence

URI dialing

Extension mobility

IP MultimediaSubsystem (IMS)

Cisco Jabberintegration (instant messaging)

CUCM virtualmachine

Cisco VirtualizationExperience clients

Cisco TelePresence

Conductor integration

UCS compute blademodule inside schoolrouter for remotecompute services

Processors, storage,network interfaces,memory on-board

Host network, UC,security, WAAS, andcompatible schoolapplications

ISR 4400 and 4500platforms

Services Ready Engine(SRE) module for ISRG2 platforms

Full classroom immersive video

Screen sharing with tablets and laptops using proximity

Desktop video endpoint

1080p video bridging

Video services in VM (virtual machine)

WebEx content sharing

Mobile device collaboration (Spark)

Speaker Track (dual-camera tracking)

Persistent chat

E911 support

Cisco CollaborationPrime Standard

Cisco CollaborationPrime Advanced

Cisco MediaSensecall recordingintegration

IP Phones, wiredand wireless

Cisco Jabber mobileuni�ed client

Remote video connections without VPN

Optimized AP Roaming

DFS Support

Cross AP Noise Reduction

Historical Interference Information

Spectrum Expert Connect

IWANIWAN TransportDMVPN

Application Visibilityand Control (AVC)

NBAR2

QoS

PfR (PerformanceRouting)Path Optimization

PKI Automation

PnP Provisioning

Intelligent PathControl

ApplicationExperience

SWITCHINGChassis: 1+1redundantsupervisor, NSF/SSO, ISSU

Cisco TrustSEC

IPv6

Per-port powermanagement

IOSModular OpenApplicationPlatform

Networkvirtualizationthrough Multi-VRF

Embedded Events

Manager (EEM)

Smart Call Home

AutoQOS

Auto SmartPorts

Flexible NetFlow

Mediatrace

IP SLA Agent

Cisco Energywise

District Internet Edge

ISR 4400 Series44514451-AX

ASR 9900 SeriesASR 9904

ASR 1000 SeriesASR 1001XASR 1002ASR 1006

Network Security

ASA 5500 SeriesASA 5545ASA 5585-S40ASA 5585-S60ASA with FirePOWER

Identity ManagementIdentity Services Engine ISE 3355Secure Access Control System

Advanced Malware Protection (AMP)AMP for EndpointsAMP for NetworksAMP for Content SecurityAMP Threat Grid

Email Security Virtual Appliance (ESAV)

Web Security Virtual Appliance (WSAV)

Cisco AnyConnect Secure Mobility (VPN)

Meraki MX SeriesMX400-HWMX600-HW

Cisco Cloud Services

Metro-AreaProvider Network

Catalyst 4500 Series

District O�ceor RegionalData Center

Compute, Services, Management

Catalyst 6807XL

Nexus 9500 SeriesNexus 9504Nexus 9508

Nexus 7700 SeriesNexus 7706Nexus 7710

Wireless Management5760 Controller8510 Controller7510 Controller

Uni�ed Computing System (UCS)UCS C-SeriesUCS B-SeriesCisco Desktop Virtualization Solutions

Uni�ed CommunicationsUni�ed Communications ManagerBusiness Edition 6000Business Edition 7000Jabber

TelePresenceTelePresence ServerMultiparty Media 310/320Multiparty Media 400vTelePresence Content Server (TCS)TelePresence ConductorTelePresence Management Suite (TMS)Expressway-EExpressway-C

ISR 4400 Series44514451-AX

ASR 1000 SeriesASR 1001ASR 1002

ASR 1006 ASR 9900 SeriesASR 9904

Metro Ethernet SeriesME 3600-XME 3800-X

WAN OptimizationWAVE 7541, WAVE 7571, WAAS Central Manager with Akamai Connect

District MAN Edge

SchoolBuilding

ISR 4300 Series43314331-AX43514351-AX

Building Edge ISR 4400 Series44314431-AX4451-X4451-AS

ASR 1000 SeriesASR 1001

Metro Ethernet SeriesME 2600-XME 3600-X

WAN OptimizationWAVE 594WAVE 694vWAAS on UCS-E bladeAkamai ConnectWAAS on Service Ready Engine (SRE)

Catalyst 3850 Series Catalyst 4500-X Series Meraki MS SeriesMS-320MS-420

Catalyst 4500 Series Catalyst 6800 Series68076880

Catalyst 3850 SeriesCatalyst 3650 Series

Catalyst 2960-X Series Meraki MS SeriesMS-220

Aironet 3700 SeriesAironet 2700 SeriesAironet 1700 Series

Meraki MR34Meraki MR32

IP Phones7800 Series8800 Series8900 Series9300 Series

Collaboration Desk EndpointsDX650DX70DX80

Collaboration Room EndpointsSX 10/20/80 SeriesMX 200/300/700/800 SeriesIX 5000 SeriesTX 9000 Series

Nexus 9300 Series

Building Backbone(MDF Closet)

Building Closet(IDF Closet)

Classroom& BuildingWireless

Mobile Device ManagementMeraki Systems Managerwith Enterprise Mobile Management

Compact Switches3650-CX2960-CS

Noti�-ED SecuritySchoolMessengerSinglewire InformaCastObjectVideoProximexAugusta Systems

Video SurveillanceIP Video CamerasVideo Surveillance ManagerVideo Analytics

Incident ResponseIPICS

Meraki MR72

Aironet 1570 Series

OutdoorWireless

Mobile Device Management (MDM)

Auto RF

Air Marshall

Integrated Bluetooth Low-Energy

Asset monitoring and tracking

Active Directory enrollment integration

BYOD Self-deployment

IP Source Guard

Unicast RPF

Bi-directional SPANfor IDS

802.1Xauthentication

Dynamic ARP inspection

Port security based upon MAC address

Limited MAC address learning to prevent �ooding

VLAN ACLs

Private VLAN edge

Port-based ACLs for Layer 2

Wireless end-to-end security through DTLS encryption

School-wide alertsystems throughSinglewirepartnership

IP-based HD videocameras, singleinfrastructure

Wired and wirelesscameras

Provider-basedDirect Internet

Access

LeasedFiber MAN/WAN

Metro EthernetProvider

Provider-basedSONET, Circuit

Network SystemsManagementPrime InfrastructurePrime Collaboration

Catalyst 3850/3650 Series

Meraki MS 220/320

AironetSeries

Meraki MRSeries

District O�ce Sta�

Cabling Infrastructure - Category 5e/6/6a Copper Cabling Infrastructure - Category 5e/6/6a Copper or MM/SM Fiber

Cabling Infrastructure - MM/SM Fiber

Connected Learning

Information Security

Professional Development

School Safety

Learning and Curriculum

Student Assessment and Data AnalyticsINTERNET

Wireless IWAN,Switching, IOS

Network Management Collaboration Cybersecurity Physical

Security Compute

CLOUD LEARNINGAPPLICATIONPARTNERS

Desire2Learn:WebEx into LMS/CirQLive

Pearson:WebEx intoLearningStudioLMS/CirQLive

Pearson:PowerSchool onUCS

CLOUD-BASEDNETWORKMANAGEMENT

Meraki Systems Manager with Enterprise Mobility Management

Cisco ActiveAdvisor

COLLABORATIONMEETING ROOM(CMR) CLOUD

Converged videobridging andWebEx webconferencing

Join fromanywhere

Superior scale

All videoresources incloud

ENERGYMANAGEMENTCLOUD

Cost-e�ectiveenergy monitoring

Speci�crecommendationsto optimizeenergy usage

Active powermanagement

ROI tools, identifybest practices

Quick deployment

Budgetpredictability

CLOUD WEBSECURITY / CLOUD EMAIL SECURITY

Near real-timeweb protection

Advancedmalwareprotection

Flexible networkconnectors tocloud

Dedicated emailsecurity instance

Cloud capacityassurance

HOSTEDCOLLABORATIONSOLUTION (HCS)

Voice & Video As a Service

Voicemail andIntegratedMessaging

InstantMessaging

Video As aService

Mobility As aService

CLOUDCOMPUTESERVICES

Dimension DataCloud ServicesIaaS, CaaS(Partner)

Private CloudVblockInfrastructurePlatform

IntelligentAutomation forCloud

Catalyst 6800IA

ID

2

1

ID

1 2

ID

1 2

ID

1 2

ID

1 2

ID

1 2

Cisco FirePOWER AppliancesFirePower 7000 SeriesFirePower 8000 Series

Nexus 2000 Series

Catalyst 4500-X, 6880

Restore

Management

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

Fan Power

Restore

Management

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

37

38

39

40

41

42

43

44

45

46

47

48

Fan Power

ENS

LSFP

S LS

S L

0

1

MGMT

S GE 0 L

EN ENCONSOLE

AUXPOE GE /0/0/0

POE GE /0/0/1 GE /0/0/3

GE /0/0/2

0

ENS

1

ENS

SFP

2

ENS

3

LCisco 4000 Series

EN

EN

AUX

MGMT

S GE 0 L

CONSOLE

POE0 FLASH TEMP PWR

SSD ISC FAN STAT

PSU0 GE

POE

FLASH TEMP PWR

POE0 SSD ISC FAN STAT

Cisco 4000 Series

Meraki MS SeriesMS-320MS-420

© 2015 Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its a�liates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) C82-734320-00 04/15