16.1 release
per@cisco.com
Technical Capabilities
Distributed
Database
Maximizes Scale,
Separation of state
Information from process
Object/Eve
nt Tracing
Easier Troubleshooting &
Debugging
Application
Platform
Deploy Containers, Run
on X86,
Developer/Operator
Views
Polaris Architecture
Control &
Data Plane
Separation
Enables Scale & Best of
Breed Deployment
Selective
Sensors
Pervasive Security
Across the Network
Object/Event Tracing
Conditional
Debugging based on
IP or MAC generates
a UUID
Filtering Logs with
UUID reveals only
relevant debug
messages
Polaris#debug platform condition ?
both
Simultaneous ingress and egress debug
egress
Egress only debug
feature
For a specific feature
ingress
Ingress only debug
interface Set interface for conditional debug
ipv4
Debug IPv4 conditions
ipv6
Debug IPv6 conditions
mac
Debug MAC conditions
mpls
Debug MPLS conditions
start
Start conditional debug
stop
Stop conditional debug
Polaris#debug platform condition
Application Platform
Network
Analytics
Configuration
Management
Network
Monitoring
Kernel Support for Multiple Containers
exist in Polaris Phase-I
Depending on the Platform Capabilities,
Apps can run in Containers
Cisco Signed apps
“Open Packages”
Cisco + 3rd-party packages
netconf/restconf/yang/rest-api Interfaces
IOS
Life Cycle Management
Container
OS/Linux
NW Devices
IOS
Container
OS/Linux
NW Devices
AVC will be available
for
Wired & Wireless
Different Levels
of Application
Recognition
Application Recognition Techniques
2
1
DNS-AS &
Server
Based
Signaling
NBAR2 with
Socket
Caching
(Performance
Optimized)
Full NBAR2
with
DPI
1500 Apps – initial
few packets
1500 Apps
Pre Defined Apps
on
DNS-AS Server
Jabber, Lync,
Cisco Telepresence, etc.
Leveraging the
work from Routing
Platforms
Mostly on Routers,
Deep Packet
Inspection
Using DNS as an Authoritative Source (DNSAS)
DNS is pervasively used - why not have those servers provide App Metadata?
• Use the TXT record of DNS servers for police metadata and then let router or switches
snoop client DNS request and request an Authoritative Answer from the DNS server
•
DNS Server
BR
AVC Framework & CLI
AVC Technique can vary
from platform to platform,
depending on the system
capabilities. However,
Framework and CLI
remains the same
What do we have in Polaris Phase 1 (16.1)?
Sub Package Upgrade
for WCM
WebUI
Day0, Day1
Radioactive Tracing for
Wired & Wireless
Smart Licensing
Faster Device Onboarding
Cisco Support
Administrator
Traces
Path
Quickly
Feature Parity with 3.7*
Targeted for 16.2
MACSEC
CISP/NEAT
SGT over FNF
Targeted for 16.3
CTS Dot1X
Critical Auth
Deprectated
Medianet
Flexlink
License
Service
© 2013-2014 Cisco and/or its affiliates. All rights reserved.
Cisco Confidential
11