Tecccde 3005

Download as pdf or txt
Download as pdf or txt
You are on page 1of 144

The Cisco Certified Design Expert

Elaine Lopes - CCDE and CCAr Exam Product Manager, Cisco - CCIE#4478
Russ White - Network Architect, LinkedIn – CCIE#2635, CCDE#2007:1, CCAr
Yuri Lukin – Solutions Integration Architect - Cisco - CCIE#22899, CCDE#2012:4
TECCCDE-3005
Agenda

• CCDE Overview
• Network Design Domain
• CCDE Written Examples
• CCDE Practical Example
• Study and Exam Tips
• CCIE/CCDE Program Updates
• Learning and Enablement
• Q&A
CCDE Overview
Why CCDE?
• Design is not widely taught, or practiced
• Misconceptions: design is easy, it’s not new and exciting, it’s just
plumbing
• Cool, exciting technologies don’t work without a solid routing design
• Basic design problems happen every day: a lot of time and money is
spent fixing failures caused by poor design
• CCDE assesses design principles to deliver robust network designs
• Cost-effective, scalable, fast, available, secure and manageable networks
• But mainly, network designs which meet the business requirements!

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
What CCDE Is and What It Is Not
What CCDE “IS” What CCDE “IS NOT”
• Focus on how and where to deploy • Implementation/configuration,
which technologies, and why troubleshooting or operations
• Vendor-agnostic • Data sheets
• Translates business and technical • Product specifics
requirements into technical designs
• Software release specifics
ARCHITECT • Business test
EXPERT

PROFESSIONAL

ASSOCIATE

ENTRY
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Mindset
CCIE mindset CCDE mindset
• Assesses implementation, operations • Assesses network design skills
and troubleshooting skills
• Focus on Why
• Focus on How
• Take the time to read and comprehend
• Make decisions fast the situation at hand (time is not an issue)
• Context is established by provided • Context is established by exhibits on a
parameters scenario which looks like RPG
• Requires understanding of • Requires understanding of design
technologies principles employing technologies
• End state is a CLI configuration set • End state is a set of network design
decisions
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Certification Process
Overview

CCDE Practical Exam


352-011
Section One
CCDE
Written pass Section Two pass
Exam Lunch
352-001
Section Three

Section Four

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
CCDE Written Exam
352-001 Exam Information
• Location: Pearson VUE Test • Pre-requisite: None, though
Centers following is recommended:
• minimum of seven (7) years job
• Duration: 2 hours experience in network engineering
• Format: 90-110 questions • thorough understanding of networking
• Multiple Choice infrastructure principles
• Drag & Drop • in-depth understanding of the topics in
the exam topics on CLN
• Scored & non-scored items
• NO “skip question”, NO “go back” • Focus: Design aspects of the
technologies

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
CCDE Practical Exam
352-011 Exam Information
• Location: Pearson VUE • Format:
Professional Test Centers; event • 4 distinct scenario-based sections
based (only offered on specific • Approximately 20-35 items per scenario
dates and now available WW) • Scored & non-scored items
• NO “skip question”, NO “go back”
• Duration: 9 hours (8 hour exam • A 24 inch monitor
plus 1 hour lunch break *) • Auto-scored
• Scenario section: Uses a • Pre-requisite: CCDE Written
hypothetical story to set the context • Upcoming Dates:
of a complex design test that is • February 22, 2017 (yes, in 2 days!)
credible, real-life, and covers • May 11, 2017
multiple steps • August 29, 2017
• November 9, 2017
* Lunch is not provided

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Domains
Analyze

Design Lifecycle
Design
Implementation Plan

Validate
Use Case
Merge/Divest Optimize
Design Failure
Replace Technology/Service
Scaling
Add Technology/Service

Technology
Vendor Agnostic
Layer 3
Virtualization
Layer 2
Security
QoS Network Management

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Focus: Domains
• Use Cases
• What is the problem I’m solving?
• Design Lifecycle
• What is the process I should use to
solve this problem?
• Technology
• What technology (or technologies) I TECHNOLOGY
should use to solve this problem?
The CCDE is at the intersection of
these three

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
CCDE Practical Exam

Exhibits—look for Questions—


• Business objective • What would you ask
• Project objective • What would you choose
• Current design • Why would you choose this
• Skills • How do these compare
• Business constraints • How would you deploy this
• Technical constraints
• Special situations
• Questions answered
• Changes in direction/solution
• Technology selection

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
CCDE Practical Exam
Option A Option A Option A 1 2 3 Options Set 1
Option B Option B Option B A x x A B
Option C Option C B x x B E
Option D Option D C x C
D Set 2
Option A E C
Option B
Option C
Option D

Multiple Branching Table Drag & Drop


Choice
Make a decision on the parent Compare and contrast different Used to match,select, order
Justify your decision on the child design and technology options or categorize options
There may be more than 1 solution
There may be optimal and
suboptimal solutions
Only 1 level deep
Next question level sets: may or may
not be a good decision
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
CCDE Practical Exam
• Simulation
• Hotspot
• Complex interactive
question types
• Generally worth
multiple points
• Detailed instructions
provided with the
question

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
CCDE Practical Exam
Scoring
• Exam is auto-scored
• Multiple valid solutions are taken into consideration for scoring
• Optimal and suboptimal
• Some items are worth multiple points, with partial scoring
• Some items are unscored
• Must achieve minimum score to pass on the entire exam
• The cutscore is unique for each administration, depending on which 4 scenarios are on the
exam
• Based on statistical analysis
• Cutscore varies to guarantee exams are balanced
• Assures all exams are in the same difficulty level
• All candidates are submitted to the same passing standards since the inception of the program
• Candidates receive score report at the end of the exam, which indicates broad areas
where additional preparation may be useful; score report mapped to exam blueprint

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Network Design Domain
Design Lifecycle
• The practical blueprint is built on ANALYZE
four specific candidate tasks
• Each scenario may have multiple
cycles of this type
VALIDATE
• A cycle is normally initiated with a
“focus change” exhibit
• These tasks should shape how you DESIGN
approach the practical

PLAN

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Design Lifecycle versus Mental Process
Validate
WHAT Analyze

WORK

WHY

Plan WHAT
Design

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Mental Process • How is the network
configured today?
• Modularity
WHAT • Failure Domains
• Resilience
• Deploy the solution • Policies
• Evaluate the results • Security
WORK
• Monitor and manage • Quality of service
the network
• Why is the network
WHY configured this way?
• Compare and contrast • Business drivers
options (technologies • Technology constraints
and designs)
• Culture constraints
WHAT • Decide which
technology or set of • Business constraints
technologies will meet
the requirements

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
What (Observe)
Two regional
Similar site rings: modularity
configurations:
modularity

Packet Filters:
security & policy

Redundant
connections:
resilience Aggregation:
failure domains

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Why (Orient)
Modular regions
& sites promote
reduced OPEX
& CAPEX

Single
connection from
each server:
technology
constraint

Resilience Failure domains


required for contain network
business outages to
regions

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
What (Decide)
• Determine which technology fits

Technology 1

Technology 2

Technology 3

Technology 4
which business requirement
• Take the entire scenario into
account

Requirement 1 x x
Requirement 2 x x
Requirement 3 x x
Requirement 4 x x

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Work (Act)
• Technology 1
• Technology 1
• Technology 2
• Technology 2
• Technology 3
• Technology 3

• Technology 1
• Technology 2
• Technology 3

• Technology 1
• Technology 1
• Technology 2
• Technology 2
• Technology 3
• Technology 3

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Important Design Concepts
• Hiding Information
• Topology and reachability
• Failure Domains
• Finding and creating failure domains
• Resilience
• Redundant is not always resilient
• Mean Time Between Failures (MTBF)
• Mean Time to Repair (MTTR)
• Mean Time Between Mistakes (MTBM)
• Shared Risk Link Groups (SRLG)

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Important Design Concepts
• Hierarchy
• Policy to the edge
• Aggregation in the middle
• Forwarding to the core
• Two and three layer
• Layers with layers
• Modularity
• Split complexity from complexity
• Design lifecycle
• Deployment process

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Important Design Concepts
• Convergence
• Discover, Report, Calculate, Install
• Positive feedback loops and convergence failure
• Virtualization
• Network
• Compute
• Storage
• Tunneling
• Control plane
• Forwarding plane

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Important Design Concepts
• Quality of Service
• Classification
• Queuing
• Hierarchical QoS
• Management
• Fault reporting
• What to measure where
• Security
• Domains: device, system, data
• Microsegmentation
• Attack vectors/surfaces

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Remember to Manage Complexity
• We cannot get to the lower left hand
corner
• Instances –
• Robust Yet Fragile (RYF)
• Consistent/Accessible/Partitionable
(CAP)
• Quality/Speed/Cost (QSC)
• Just the way the world is built

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
CCDE Written Examples
OSPF Deployment
In a large enterprise network with multiple data centers and thousands of access
devices, OSPF is becoming unstable due to link flapping. The current design has
the access devices multihomed to large aggregation routers at each of the data
centers. How can this network be redesigned to improve stability?
1. Add a layer of regional Layer 3 aggregation devices, but leave the ABR
function on the data center aggregation routers.
2. Add a layer of regional Layer 2 aggregation devices, but leave the ABR
function on the data center aggregation routers.
3. Add a layer of regional Layer 3 aggregation devices and move the ABR
function to the regional aggregation device.
4. Add a layer of regional Layer 2 aggregation devices and move the ABR
function to the regional aggregation device.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
OSPF Deployment
In a large enterprise network with multiple data centers and thousands of access
devices, OSPF is becoming unstable due to link flapping. The current design has
the access devices multihomed to large aggregation routers at each of the data
centers. How can this network be redesigned to improve stability?
1. Add a layer of regional Layer 3 aggregation devices, but leave the ABR
function on the data center aggregation routers.
2. Add a layer of regional Layer 2 aggregation devices, but leave the ABR
function on the data center aggregation routers.
3. Add a layer of regional Layer 3 aggregation devices and move the ABR
function to the regional aggregation device.
4. Add a layer of regional Layer 2 aggregation devices and move the ABR
function to the regional aggregation device.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
IPv6 Integration
You are designing an IPv6 integration, and decided to use stateless encapsulation
of IPv6 packets into IPv4 tunnels between subscriber CPEs and a border relay.
Which deployment technique allows for this functionality?
1. 4rd
2. Dual-stack lite
3. 6rd
4. DTSM

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
IPv6 Integration
You are designing an IPv6 integration, and decided to use stateless encapsulation
of IPv6 packets into IPv4 tunnels between subscriber CPEs and a border relay.
Which deployment technique allows for this functionality?
1. 4rd
2. Dual-stack lite
3. 6rd
4. DTSM

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
MPLS Deployment
A healthcare company currently uses a MPLS Layer 3 VPN service to connect
2000 remote sites to two data centers. It has been decided that they must encrypt
their traffic across this service to meet tight regulatory requirements. Which is the
simplest method to accomplish this task?
1. DMVPN
2. L2TPv3
3. Point-to-Point GRE over IPSec
4. Multi-Point GRE Tunnels
5. GETVPN

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
MPLS Deployment
A healthcare company currently uses a MPLS Layer 3 VPN service to connect
2000 remote sites to two data centers. It has been decided that they must encrypt
their traffic across this service to meet tight regulatory requirements. Which is the
simplest method to accomplish this task?
1. DMVPN
2. L2TPv3
3. Point-to-Point GRE over IPSec
4. Multi-Point GRE Tunnels
5. GETVPN

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
VRF Extension
Which two features can be used to extend VRFs across a campus? (Choose
two.)
1. 802.1q trunk
2. LDP
3. MPLS TE
4. GRE
5. Port-Channel

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
VRF Extension
Which two features can be used to extend VRFs across a campus? (Choose
two.)
1. 802.1q trunk
2. LDP
3. MPLS TE
4. GRE
5. Port-Channel

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Quality of Service
When designing a WAN network which will carry real-time traffic, what are two
design considerations about serialization delays? (Choose two.)
1. packet type
2. interface line rate
3. physical media
4. packet size
5. distance
6. end-to-end latency

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Quality of Service
When designing a WAN network which will carry real-time traffic, what are two
design considerations about serialization delays? (Choose two.)
1. packet type being serialized
2. interface line rate
3. physical media
4. packet size being serialized
5. distance
6. end-to-end latency

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
CCDE Practical Example
Exhibit 1: Introduction Information
• During this section of the test, you will be on the IT Engineering team tasked to
design the replacement of the insurance company So-Sure’s dated
technologies.
• Information on
• Question Navigation
• Documents
• Exam displays
• Task time
• Notes
• Comments

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Background
So-Sure Co. (So-Sure) is an insurance company with more than 95 years in business, with
headquarters in Boston, MA. Their portfolio includes Life insurance (Mortgage life,
Permanent life, Term life, Universal life, and Whole life), Residential insurance (Contents,
Earthquake, Flood, Home, Landlord, Mortgage, Property, Renters and Title), and Vehicle
insurance. So-Sure is proud of their wide portfolio of insurance products and of their footprint
(currently So-Sure has 531 small branches across the US), where their well-trained field
agents give advice and build relationship with their end-clients.
So-Sure wants to make it easier and faster for the field agents to get insurance quotes to the
end-clients. A mobility initiative has been launched and will use BYOD and new applications
to support it. This has highlighted the importance of updating their dated WAN solution. So-
Sure has had outages in the past which have impacted the agents servicing their end-
clients, and therefore So-Sure wants to investigate a move from a single SP to a dual SP
network to increase redundancy.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Background
So-Sure Co. (So-Sure) is an insurance company with more than 95 years in business, with
headquarters in Boston, MA. Their portfolio includes Life insurance (Mortgage life,
Permanent life, Term life, Universal life, and Whole life), Residential insurance (Contents,
Earthquake, Flood, Home, Landlord, Mortgage, Property, Renters and Title), and Vehicle
insurance. So-Sure is proud of their wide portfolio of insurance products and of their footprint
(currently So-Sure has 531 small branches across the US), where their well-trained field
agents give advice and build relationship with their end-clients.
So-Sure wants to make it easier and faster for the field agents to get insurance quotes to the
end-clients. A mobility initiative has been launched and will use BYOD and new applications
to support it. This has highlighted the importance of updating their dated WAN solution. So-
Sure has had outages in the past which have impacted the agents servicing their end-
clients, and therefore So-Sure wants to investigate a move from a single SP to a dual SP
network to increase redundancy.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Background
The current CIO is retiring after 35 years with the company. His replacement has been hired
from outside of the company, is young and more knowledgeable of industry and technology
trends. The new CIO is more focused on outcome-based IT decisions which are in direct
response to business needs. Therefore he is willing to invest in technology where it makes
sense. Even though he is willing to invest, he is still under constant pressure to cut OPEX.
Any expenditure must have strong justification which is why he wants everything to tie into
the bottom line for the business units.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Background
The current CIO is retiring after 35 years with the company. His replacement has been hired
from outside of the company, is young and more knowledgeable of industry and technology
trends. The new CIO is more focused on outcome-based IT decisions which are in direct
response to business needs. Therefore he is willing to invest in technology where it makes
sense. Even though he is willing to invest, he is still under constant pressure to cut OPEX.
Any expenditure must have strong justification which is why he wants everything to tie into
the bottom line for the business units.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Current Network
Atlanta, GA
Atlanta, GA Secondary Data Center

New York, NY Andover, MA


Primary Data Center
Call Center
Chicago, IL

L3VPN

Seattle, WA
Boston, MA
Headquarters
San Francisco, CA
531 Remote Sites
...
Dallas, TX
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Current Network
• WAN Topology
• All sites are connected to a MPLS/Layer 3 VPN service from a single provider.
• 5 years ago the WAN was upgraded from ATM to MPLS/Layer 3 VPN, which was the
last thing really done on the WAN.
• Much of the branch locations equipment (routers and switches) is now End-of-Life and
the MPLS/Layer 3 VPN contracts are being reviewed for renewal.
• Internet and Extranet
• Internet is handled via a single provider and Internet usage is not an issue at this point.
The DMZ has just gotten upgraded and is working fairly well. However, there was a
recent outage that disrupted service to their field agents and is an increasing concern.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Current Network
• WAN Topology
• All sites are connected to a MPLS/Layer 3 VPN service from a single provider.
• 5 years ago the WAN was upgraded from ATM to MPLS/Layer 3 VPN, which was the
last thing really done on the WAN.
• Much of the branch locations equipment (routers and switches) is now End-of-Life and
the MPLS/Layer 3 VPN contracts are being reviewed for renewal.
• Internet and Extranet
• Internet is handled via a single provider and Internet usage is not an issue at this point.
The DMZ has just gotten upgraded and is working fairly well. However, there was a
recent outage that disrupted service to their field agents and is an increasing concern.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Current Network
• Andover, MA data center is So-Sure’s original data center and cannot be expanded any
longer
• Atlanta, GA data center is newer and has room to expand with available space for
approximately 36 new additional compute racks
• Call center co-located with the data center in Andover, MA has worked out well
• The data centers are currently connected together with two point-to-point MPLS circuits
which are loaded around 50% utilization

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Current Network
• Andover, MA data center is So-Sure’s original data center and cannot be expanded any
longer
• Atlanta, GA data center is newer and has room to expand with available space for
approximately 36 new additional compute racks
• Call center co-located with the data center in Andover, MA has worked out well
• The data centers are currently connected together with two point-to-point MPLS circuits
which are loaded around 50% utilization

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Branch Site
3 connections to
the L3VPN
1 or 2 switches,
depending on size

L3VPN

Internet

Remote User

Multiple manufacturers
and ages

Inconsistent deployment

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Branch Site
• The small branch networks are inconsistent and outdated; much of the equipment is end-
of-life
• Not all branches have wireless; multiple vendors are in use
• Each branch can support between 20 and 150 agents, some of them remote
• They have seen a decline in physical branch occupancy from 80% 10 years ago to 20%
last year
• The applications currently in use in the branch locations are
• Email
• Get insurance quotes for end-clients based on statistical data
• Access to the customer database

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Branch Site
• The small branch networks are inconsistent and outdated; much of the equipment is end-
of-life
• Not all branches have wireless; multiple vendors are in use
• Each branch can support between 20 and 150 agents, some of them remote
• They have seen a decline in physical branch occupancy from 80% 10 years ago to 20%
last year
• The applications currently in use in the branch locations are
• Email
• Get insurance quotes for end-clients based on statistical data
• Access to the customer database

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Bring Your Own Device
Employees are increasingly trying to connect new personally owned mobile devices to the
company network and are complaining about the complex process of getting connected, and
in many cases there is inconsistent service availability across the branches. The business
has requested that a robust BYOD program be a focus of IT. This would allow the field
agents to better serve the customer base by enabling them to do adjustments and claim
processing without visiting a So-Sure office. This initiative would also allow them to move to
a 80% wireless / 20% wired connectivity model.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Bring Your Own Device
Employees are increasingly trying to connect new personally owned mobile devices to the
company network and are complaining about the complex process of getting connected, and
in many cases there is inconsistent service availability across the branches. The business
has requested that a robust BYOD program be a focus of IT. This would allow the field
agents to better serve the customer base by enabling them to do adjustments and claim
processing without visiting a So-Sure office. This initiative would also allow them to move to
a 80% wireless / 20% wired connectivity model.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Leasing Challenge Memo
So-Sure has been on the practice of leasing equipment over a three year period where
appropriate. This has served So-Sure well in the past and had been done for all their branch
locations. One of the issues that the new CIO needs to tackle is that the majority of
equipment (routers, switches, access points) at the branch locations was leased. However,
due to several reasons, the leases expired and transitioned to month-to-month leases one
year ago. These month-to-month leases have resulted in higher OPEX expenses. This issue
has been raised in several budget meetings with executive management and needs to be
addressed.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Leasing Challenge Memo
So-Sure has been on the practice of leasing equipment over a three year period where
appropriate. This has served So-Sure well in the past and had been done for all their branch
locations. One of the issues that the new CIO needs to tackle is that the majority of
equipment (routers, switches, access points) at the branch locations was leased. However,
due to several reasons, the leases expired and transitioned to month-to-month leases one
year ago. These month-to-month leases have resulted in higher OPEX expenses. This issue
has been raised in several budget meetings with executive management and needs to be
addressed.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
1: Initial Solution Evaluation
Provides optimal Optimal support for Provides required
support for BYOD Reduces branch call center resilience and
and mobility office OPEX operations business continuity
Move applications to
a public cloud
Deploy an SD-WAN
solution for branch
connectivity
Modernize branches,
add a second MPLS
provider

Assume this is over plain IP,


instead of MPLS

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
1: Initial Solution Evaluation
Provides optimal Optimal support for Provides required
support for BYOD Reduces branch call center resilience and
and mobility office OPEX operations business continuity
Move applications to
a public cloud
Deploy an SD-WAN
solution for branch
connectivity
Modernize branches,
add a second MPLS
provider

1 Point 1 Point 1 Point

• Chart questions are graded by either rows or columns


• The value of each column or row is determined by the difficulty,
the relation to the scenario, and other factors

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
1: Initial Solution Evaluation
Provides optimal Optimal support for Provides required
support for BYOD Reduces branch call center resilience and
and mobility office OPEX operations business continuity
Move applications to
X X X
a public cloud
Deploy an SD-WAN
solution for branch X X X
connectivity
Modernize branches,
add a second MPLS X X
provider

Once these applications are in a While mobility can be supported


public cloud, they can be alongside the solutions, it’s not
accessed by anyone, anytime, going to be a “native” part of
anywhere either of them

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
1: Initial Solution Evaluation
Provides optimal Optimal support for Provides required
support for BYOD Reduces branch call center resilience and
and mobility office OPEX operations business continuity
Move applications to
X X X
a public cloud
Deploy an SD-WAN
solution for branch X X X
connectivity
Modernize branches,
add a second MPLS X X
provider

Moving to a public cloud eliminates both the local


MPLS circuit and remote user access equipment

Moving to an SD-WAN solution eliminates This solution may reduce branch office
the local MPLS circuit, this may be OPEX somewhat, but it’s not going to
considered “minimal,” or not, so this option “minimize” it, especially in comparison with
can be marked either way (no points) the other two options
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
1: Initial Solution Evaluation
Provides optimal Optimal support for Provides required
support for BYOD Reduces branch call center resilience and
and mobility office OPEX operations business continuity
Move applications to
X X X
a public cloud
Deploy an SD-WAN
solution for branch X X X
connectivity
Modernize branches,
add a second MPLS X X
provider

Pushing the applications to the


cloud would move the primary
data and applications out of the These two solutions leave the colocation
call centers of the data and call centers in place, which
was noted as being a “good thing” in the
documentation
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
1: Initial Solution Evaluation
Provides optimal Optimal support for Provides required
support for BYOD Reduces branch call center resilience and
and mobility office OPEX operations business continuity
Move applications to
X X X
a public cloud
Deploy an SD-WAN
solution for branch X X X
connectivity
Modernize branches,
add a second MPLS X X
provider

Any one of these three solutions could provide the required resilience and business
continuity if deployed properly

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
2: Cloud Evaluation
Do you recommend So-Sure move their two
custom applications to a public cloud to
support their requirements?
1. Yes
2. No

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
2: Cloud Evaluation
Do you recommend So-Sure move their two
custom applications to a public cloud to
support their requirements?
1. Yes
2. No

• Either answer here can be correct, it just


depends on your perspective
• This is the “guard” question for a pair of
equal weight branch questions
• The point is not “do you know the right
solution,” but rather, “ can you justify your
choice”

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
2.1: Cloud Evaluation
What justification would you give for moving
So-Sure’s custom applications to a public
cloud?
1. Overall operational costs would be
greatly reduced
2. “Native” support for remote and BYOD
personnel
3. Cloud environments are more secure
than the locally managed data center

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
2.1: Cloud Evaluation
What justification would you give for moving
So-Sure’s custom applications to a public
cloud?
1. Overall operational costs would be
• We don’t know if (1) is true or not—branch
greatly reduced OPEX would be reduced, but we don’t have
2. “Native” support for remote and BYOD any information about total OPEX
• Public clouds are not necessarily more or
personnel less secure than a local data center—it all
depends on your operational skill—so (3)
3. Cloud environments are more secure
isn’t a viable answer
than the locally managed data center • The only strong answer in this set is (2), the
native support for remote and BYOD clients
• There could be other strong answers, but
they’re not available, so…

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
2.2: Cloud Evaluation
What justification would you give not to
move So-Sure’s custom applications to a
public cloud?
1. The cost of moving the applications
would outweigh OPEX savings
2. Public clouds are not secure enough for
financial information
3. Colocation of the applications and the
call center is an operational advantage

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
2.2: Cloud Evaluation
What justification would you give not to
move So-Sure’s custom applications to a
public cloud?
1. The cost of moving the applications • We don’t know if (1) is true or not—branch
OPEX would be reduced, but we don’t have
would outweigh OPEX savings any information about total OPEX
2. Public clouds are not secure enough for • Public clouds are not necessarily more or
less secure than a local data center—it all
financial information depends on your operational skill—so (2)
isn’t a viable answer
3. Colocation of the applications and the
• The only strong answer in this set is (3), the
call center is an operational advantage colocation of the application and the call
center
• There could be other strong answers, but
they’re not available, so…

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Cloud Solution Memo
So-Sure management has met and
discussed the concept of moving our
custom applications to a public cloud. So-
Sure will not be moving in this direction
because of security concerns… Given this,
we would like to evaluate our options for
replacing the branch sites with a lower cost
solution that provides flexibility until we • Reaching a point like this doesn’t mean
you’ve chosen the wrong answer!
believe public cloud based solutions
• The customer has made a decision,
become a viable option regardless of whether or not you agree with
them
• Move forward from this point; don’t think and
rethink your previous answers in light of this
new information

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Cloud Solution Memo
So-Sure management has met and
discussed the concept of moving our
custom applications to a public cloud. So-
Sure will not be moving in this direction
because of security concerns… Given this,
we would like to evaluate our options for
replacing the branch sites with a lower cost
solution that provides flexibility until we
• Make certain you read additional information
believe public cloud based solutions
provided during the test for new or clarified
become a viable option requirements
• These might not relate to the actual segue
between sections, but might seem like “off
handed” comments embedded in a larger
document

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
3: Branch WAN Evaluation
What of the following factors would you
argue is not important in considering the
branch WAN connectivity?
1. Changes in the user population
2. Minimized OPEX
3. Quality of Service requirements
4. Application security
5. Simplified management
6. Connectivity resilience

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
3: Branch WAN Evaluation
What of the following factors would you
argue is not important in considering the
• Note the NOT
branch WAN connectivity? • Branch utilization is clearly changing; (1) is
1. Changes in the user population incorrect
• Minimized OPEX is explicitly called out in the
2. Minimized OPEX documentation; (2) is incorrect
• Financial information must be secure; (4) is
3. Quality of Service requirements incorrect
• Simplified management is related to OPEX;
4. Application security (5) is incorrect
• Connectivity resilience is explicitly called out
5. Simplified management in the documentation; (6) is incorrect
• QoS doesn’t seem to be a pressing issue;
6. Connectivity resilience there is no “real time” or high bandwidth
traffic noted; (3) is correct

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
WAN Connectivity Email
From: [email protected]
To: [email protected] (mailer list)
Subject: WAN connectivity

I’ve spent some time looking at our options for branch office connectivity. Based on my research, I would
say there are four options we should be looking at:

Continue with a single MPLS connection


Build out a second MPLS circuit to each branch office
Switch to an SD-WAN solution across the a plain vanilla Internet connection at each branch
Switch to an SD-WAN solution and build out a second Internet connection at each branch

Regards,
Elliott Jackman
So-Sure IT Engineering manager

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
4: Branch WAN Evaluation
Which two of the following pieces of
additional information would you want
before evaluating the four solutions
presented (Choose two.)?
1. MPLS circuit quality of service support
2. MPLS circuit cost
3. Internet connection cost
4. SD-WAN quality of service support
5. MPLS circuit bandwidth
6. SD-WAN virtual circuit bandwidth

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
4: Branch WAN Evaluation
Which two of the following pieces of
additional information would you want
before evaluating the four solutions
presented (Choose two.)?
1. MPLS circuit quality of service support
2. MPLS circuit cost
• QoS doesn’t seem to be a pressing issue;
3. Internet connection cost (1) and (4) are incorrect
• There’s no fixed bandwidth for either the
4. SD-WAN quality of service support MPLS or SD-WAN solutions; (5) and (6) are
incorrect
5. MPLS circuit bandwidth • The costs of the two options are going to be
the primary drivers; hence (2) and (3) are the
6. SD-WAN virtual circuit bandwidth correct answers

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
WAN Cost Email
From: [email protected]
To: [email protected] (mailer list)
Subject: WAN connectivity

You asked for more information about each option? This is what I found out:

QoS Support Cost Cost Basis


MPLS Four queues of support, Current costs Cost increment on a yearly
provider accepts packet basis (contract)
markings from customer
network
SD-WAN over Internet Four queues of support, About 40% of the cost of Cost on base bandwidth +
solution attempts to detect an MPLS circuit (average incremental bandwidth
classes, but will accept across all branch sites) usage
markings from customer
network

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
• The test will often provide all the information
WAN Cost Email from the last question, rather than what you
asked for

From: [email protected] • This helps keep cheating down…


To: [email protected] (mailer list) • More information that might be useful later is
Subject: WAN connectivity again buried in the additional documents

You asked for more information about each option? This is what I found out:

QoS Support Cost Cost Basis


MPLS Four queues of support, Current costs Cost increment on a yearly
provider accepts packet basis (contract)
markings from customer
network
SD-WAN over Internet Four queues of support, About 60% of the cost of Cost on base bandwidth +
solution attempts to detect an MPLS circuit incremental bandwidth
classes, but will accept usage
markings from customer
network

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
5: Branch WAN Evaluation
Based on the information you have, which
solution would you recommend to So-Sure
for branch connectivity?
1. Keep the existing single MPLS circuit
2. Add an additional MPLS circuit to each
branch
3. Replace the MPLS circuit with SD-WAN
over the existing Internet link
4. Replace the MPLS circuit with SD-WAN
and add an Internet link at each branch

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
5: Branch WAN Evaluation
Based on the information you have, which
solution would you recommend to So-Sure
for branch connectivity?
1. Keep the existing single MPLS circuit • This is the top level question of a branch
(though you wouldn’t know that when taking
2. Add an additional MPLS circuit to each the test)
branch • (1) doesn’t modify resilience or cost;
receives 0 points
3. Replace the MPLS circuit with SD-WAN • (2) increases resilience while increasing
cost; receives 1 point
over the existing Internet link
• (3) reduces cost without increasing
4. Replace the MPLS circuit with SD-WAN resilience; receives 1 point and leads to
branch 5.3
and add an Internet link at each branch
• (4) reduces cost and increases resilience;
receives 2 points and leads to branch 5.4

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
5.3: Branch WAN Evaluation
Which requirement will deploying SD-WAN
over a single Internet connection not fulfill?
1. Quality of Service
2. Minimizing branch OPEX
3. Resilience

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
5.3: Branch WAN Evaluation
Which requirement will deploying SD-WAN
over a single Internet connection not fulfill?
1. Quality of Service • This gives you the chance to catch your
suboptimal answer and recover a point—the
2. Minimizing branch OPEX real test may, or may not, have this type of
question
3. Resilience • (1) QoS is not an issue for the applications in
use, so this is incorrect
• (2) This does minimize branch OPEX, so this
is a requirement that is fulfilled, rather than
one that is not fulfilled
• (3) Resilience is the one that’s not taken into
account—this was mentioned explicitly in the
documentation, so it’s something you should
be watching for

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
5.4: Branch WAN Evaluation
Deploying an SD-WAN solution over dual
providers saves around 20% on the OPEX,
rather than a potential savings of 60%. How
would you justify the reduced savings?
1. The size of the branch offices indicates
they need more bandwidth
2. Dual connections will offer protection
against a single provider failing or
browning out
3. The two connections are required for
adequate QoS controls for all SD-WAN
solutions

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
5.4: Branch WAN Evaluation
Deploying an SD-WAN solution over dual
providers saves around 20% on the OPEX,
• This is an additional point opportunity on the
rather than a potential savings of 60%. How best answer if you can back your choice up
would you justify the reduced savings? with a solid reason
• There is no indication of (1) anyplace in the
1. The size of the branch offices indicates documentation
they need more bandwidth • If you choose (3), then you don’t know SD-
WAN technology very well
2. Dual connections will offer protection • Resilience has been mentioned in the
against a single provider failing or documentation, specifically for the branch
browning out offices; (2) is the correct answer
• Further, going to SD-WAN leaves the branch
3. The two connections are required for more vulnerable to outages than an MPLS
adequate QoS controls for all SD-WAN provider managed solution; this provides a
solutions second justification for (2)

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
6: Branch OPEX Evaluation
Other than replacing the WAN link, what
other actions should So-Sure consider to
reduce branch OPEX (Choose two.)?
1. Return to a long term leasing option for
branch equipment
2. Eliminate the branch offices in favor of
an all mobile work force
3. Unify branch network equipment in a
single type of device
4. Reduce application traffic levels to
minimize bandwidth requirements

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
6: Branch OPEX Evaluation
Other than replacing the WAN link, what
other actions should So-Sure consider to • You might have thought we’d forgotten about
those leasing costs—but test writers never
reduce branch OPEX (Choose two.)? forget!
1. Return to a long term leasing option for • The answers here are all “good,” you must
choose ones that are realistic within the
branch equipment scenario
2. Eliminate the branch offices in favor of • (1) is definitely true; correct answer
• (2) is orthogonal to (1), hasn’t been
an all mobile work force mentioned before, and is a business
decision rather than a technology decision
3. Unify branch network equipment in a
• (3) is true if it can be done; correct answer
single type of device • (4) might be true if it can be done, but this
isn’t something that’s been mentioned
4. Reduce application traffic levels to
before; there’s no information on which to
minimize bandwidth requirements choose this option

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
7: Branch Migration Plan
Drag these steps into the proper order to
achieve a successful migration to the SD-
WAN solution
Install and configure SD-WAN
Step 1
solution at all branches
Check for proper routing • Once a solution is selected, you may
Step 2 sometimes be presented with an ordering
information
question like this
Install and configure SD-WAN
hub
Step 3 • The objective is to make certain you know
how to deploy a technology
Failover testing for a small
Step 4 • Make certain you consider a solution that will
subset of branch locations
not break the existing network (where
Shut down MPLS connections possible)
Step 5
• Make certain you consider backout options
Create routing policy to prefer in the case of failure (where possible)
Step 6
SD-WAN connection

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
7: Branch Migration Plan
Drag these steps into the proper order to
achieve a successful migration to the SD-
WAN solution
Install and configure SD-WAN Create routing policy to prefer
solution at all branches SD-WAN connection
Check for proper routing Install and configure SD-WAN • In most of these types of questions there are
information hub actually “groups of options”
• It doesn’t matter what order you place things
Step 3 within each “group,” so long as you get the
group ordering right
Failover testing for a small
Step 4 • In this case, creating a policy and installing
subset of branch locations
the hub could be done at the same time or in
Shut down MPLS connections any order
Step 5
• But they must be done before any of the
Step 6 other steps are taken

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
7: Branch Migration Plan
Drag these steps into the proper order to
achieve a successful migration to the SD-
WAN solution
Install and configure SD-WAN Create routing policy to prefer
solution at all branches SD-WAN connection
Check for proper routing Install and configure SD-WAN
information hub
Failover testing for a small
subset of branch locations

Step 4 • You should always test before performing a


larger scale rollout of any solution
Shut down MPLS connections • This gives you a “break point” where you can
Step 5
roll back or resolve issues before the
Step 6 solution is pressed into service

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
7: Branch Migration Plan
Drag these steps into the proper order to
achieve a successful migration to the SD-
WAN solution
Create routing policy to prefer
SD-WAN connection
Install and configure SD-WAN
hub
Failover testing for a small
subset of branch locations • This is another “group” of items
• You could perform the routing check while
Install and configure SD-WAN
installing the new solution at each branch, or
solution at all branches
all at once
Check for proper routing • Which way you do things doesn’t matter, just
Shut down MPLS connections
information
so long as they’re both done before taking
Step 6 the next step

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
7: Branch Migration Plan
Drag these steps into the proper order to
achieve a successful migration to the SD-
WAN solution
Create routing policy to prefer
SD-WAN connection
Install and configure SD-WAN
hub
Failover testing for a small
subset of branch locations
Install and configure SD-WAN
solution at all branches
Check for proper routing • Make before break is always ideal
information
• This provides you with a final roll back point
Shut down MPLS connections before you commit to the solution

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Application Performance
From: [email protected]
To: [email protected] (mailer list)
Subject: Application performance issues

There are times when the quoting and customer


information applications are performing poorly. We
know this happens when system updates and other
large transfers are occurring over the links between
the data centers. We need to come up with a
solution so that these business critical applications
are not impacted.

I know we are facing many changes right now. Let's


focus on a solution that will work with our existing
connectivity.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Application Performance
From: [email protected]
To: [email protected] (mailer list)
Subject: Application performance issues

There are times when the quoting and customer


information applications are performing poorly. We
know this happens when system updates and other
large transfers are occurring over the links between
• This is a “focus shifting” exhibit
the data centers. We need to come up with a
• Each scenario can have multiple embedded
solution so that these business critical applications
areas of work
are not impacted.
• As you pass through the scenario, you may
(or may not) pass through these areas
I know we are facing many changes right now. Let's
• Information must be drawn from these new
focus on a solution that will work with our existing
exhibits and merged with existing information
connectivity.
to draw a complete picture of the problem
set, requirements, constraints, etc.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Application Performance
From: [email protected]
To: [email protected] (mailer list)
Subject: Application performance issues

There are times when the quoting and customer


information applications are performing poorly. We
know this happens when system updates and other
large transfers are occurring over the links between
the data centers. We need to come up with a
solution so that these business critical applications
are not impacted.

I know we are facing many changes right now. Let's


focus on a solution that will work with our existing
connectivity.

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
8: Application Performance Investigation
What further information would you want
about the So-Sure network before
evaluating solutions to resolve this
problem?
1. The type of devices the inter-DC link is
connected to
2. The maximum MPLS link bandwidth
available from the provider
3. Detailed link utilization between the two
data centers

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
8: Application Performance Investigation
What further information would you want
about the So-Sure network before
evaluating solutions to resolve this
problem?
• (1) might matter, but it’s a long shot; QoS
1. The type of devices the inter-DC link is configuration or link utilization are more likely
connected to culprits
• Further, remember the CCDE doesn’t get
2. The maximum MPLS link bandwidth into specific equipment types, so this answer
available from the provider should feel out of place here
• (2) is premature; you’ve not yet decided that
3. Detailed link utilization between the two a link upgrade is the best solution
data centers • (3) would provide you with the information
needed to decide if a link upgrade is in order,
or some other solution is possible

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
InterDC WAN Utilization
From: [email protected]
To: [email protected] (mailer list)
Subject: Application performance issues

The maximum bandwidth we can get along the inter-DC link is 100G—which is probably far more than
we’ll ever need. I’ve included a utilization chart below from a couple of days last week.

80%

60%

40%

20%

4 hour increments

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
9: Application Performance Investigation
With the information you now have, what
type of solution would you recommend to
So-Sure?
1. Increasing the bandwidth on the inter-
DC link
2. Deploying Quality of Service to manage
link loading

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
9: Application Performance Investigation
With the information you now have, what
type of solution would you recommend to
So-Sure?
1. Increasing the bandwidth on the inter-
• This is the top of another branch (though you
DC link couldn’t tell this while taking the test)
2. Deploying Quality of Service to manage • The overall utilization of the link looks pretty
reasonable
link loading • But—there are spikes of utilization that
indicate some combination of applications
working together can overrun the link
• This indicates a QoS solution, rather than
adding more bandwidth
• The difficulty of this question would indicate
it should earn at least one point

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
9.2: Application Performance Investigation
Why would you argue deploying QoS is the
correct solution for the problem as
observed?
1. The overall link utilization appears to be
less than 30%, far below the threshold
needed to upgrade a link
2. The spikes in utilization indicate
transitory/interacting application usage
that should be controlled through QoS
3. The spikes in the utilization a set of
interacting processes that need to be
modified

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
9.2: Application Performance Investigation
Why would you argue deploying QoS is the
correct solution for the problem as
observed?
1. The overall link utilization appears to be
less than 30%, far below the threshold
needed to upgrade a link
2. The spikes in utilization indicate
transitory/interacting application usage
that should be controlled through QoS • (1) is a “trick;” the overall utilization isn’t
enough to demand an upgrade, but it’s also
3. The spikes in the utilization a set of not under 30%
interacting processes that need to be • (3) What? Seriously?
modified • (2) is the correct reason here

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Provider QoS information email
From: [email protected]
To: [email protected] (mailer list)
Subject: Provider QoS information

I just attended a presentation with the MPLS provider. They said we can allocate bandwidth for certain
applications by using DSCP markings. They support 3 different classes, marked as default (Best Effort),
AF21 (Critical Data) and EF (Realtime). They have a bunch of different queuing profiles, but they said
what we pick would be application dependent.

Regards,
Elliott Jackman
So-Sure IT Engineering manager

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Provider QoS information email
From: [email protected]
To: [email protected] (mailer list)
Subject: Provider QoS information

I just attended a presentation with the MPLS provider. They said we can allocate bandwidth for certain
applications by using DSCP markings. They support 3 different classes, marked as default (Best Effort),
AF21 (Critical Data) and EF (Realtime). They have a bunch of different queuing profiles, but they said
what we pick would be application dependent.

Regards,
Elliott Jackman
So-Sure IT Engineering manager

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
10: Application Performance QoS
Which two actions, when combined, should
be taken to resolve the application
performance problems caused by the inter-
DC link (Choose two.)?
1. Classify and mark business critical
traffic
2. Reserve bandwidth for the business
critical applications
3. Reserve bandwidth for the remaining
traffic

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
10: Application Performance QoS
Which two actions, when combined, should
be taken to resolve the application
performance problems caused by the inter-
DC link (Choose two.)?
1. Classify and mark business critical
traffic
2. Reserve bandwidth for the business • (2) is the actual “bottom line” solution here,
critical applications as it will force the applications to co-exist on
the single link better
3. Reserve bandwidth for the remaining
• (2) is pretty useless without (1), though
traffic • (3) isn’t necessary in this situation; best
effort over the remaining bandwidth should
do, so long as the reserved bandwidth in (2)
isn’t 100% 

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
11: Application Performance QoS
How would you mark the application traffic
at the interfaces connected to the inter-DC
link?
1. Default (Best Effort)
2. AF21 (Critical Data)
3. EF (Real Time)

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
11: Application Performance QoS
How would you mark the application traffic
at the interfaces connected to the inter-DC
link?
1. Default (Best Effort)
2. AF21 (Critical Data)
3. EF (Real Time)

• (1) doesn’t help


• (3) – the EF queue should be reserved for
voice or streaming traffic of some type
• (2) is the correct answer

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Application Performance (2)
From: [email protected]
To: [email protected] (mailer list)
Subject: Increase data center capacity

Congrats all around on completing the SD-WAN migration!

Implementing QoS on the inter-DC link appeared to have


resolved our application performance issues, but this last
week we ran into problem again. The inter-DC link doesn’t
appear to be overloaded now, and the applications aren’t
reporting a lot of dropped packets, so the problem seems to
be elsewhere.

This is the highest seasonal rate we’ve had for transactions,


however; in a few weeks we should be past our peak season
for the year. Can someone investigate and get back to me?

Regards,
Elliott Jackman
So-Sure IT Engineering manager TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Application Performance (2)
From: [email protected]
To: [email protected] (mailer list)
Subject: Increase data center capacity

Congrats all around on completing the SD-WAN migration!

Implementing QoS on the inter-DC link appeared to have


resolved our application performance issues, but this last
week we ran into problem again. The inter-DC link doesn’t
appear to be overloaded now, and the applications aren’t
reporting a lot of dropped packets, so the problem seems to • Once again we have a focus shifting email
be elsewhere. • Don’t let cognitive dissonance set in through
these shifts; they’re necessary to cover the
This is the highest seasonal rate we’ve had for transactions, various technology domains in the blueprint
however; in a few weeks we should be past our peak season • Tests are from components that ensure a
for the year. Can someone investigate and get back to me? wide spread of technology domains are
sufficiently covered
Regards,
Elliott Jackman
So-Sure IT Engineering manager TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Application Performance (2)
From: [email protected]
To: [email protected] (mailer list)
Subject: Increase data center capacity

Congrats all around on completing the SD-WAN migration!

Implementing QoS on the inter-DC link appeared to have


resolved our application performance issues, but this last
week we ran into problem again. The inter-DC link doesn’t
appear to be overloaded now, and the applications aren’t
reporting a lot of dropped packets, so the problem seems to
be elsewhere.

This is the highest seasonal rate we’ve had for transactions,


however; in a few weeks we should be past our peak season
for the year. Can someone investigate and get back to me?

Regards,
Elliott Jackman
So-Sure IT Engineering manager TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
12: Application Performance
Given the information you have so far,
which of the following would you want to
investigate further to resolve this problem?
1. Link utilization towards the branch
offices
2. Queue depths, jitter, and delay across
the inter-DC link
3. Server utilization levels in the data
centers
4. Processor utilization levels on the
routers connected to the inter-DC link

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
12: Application Performance
Given the information you have so far,
which of the following would you want to
investigate further to resolve this problem?
1. Link utilization towards the branch
offices
• (1) should be ruled out; the SD-WAN
2. Queue depths, jitter, and delay across implementation is complete, and there are
the inter-DC link no signs problems from that end
3. Server utilization levels in the data • (2) should be ruled out, as the email states
the applications aren’t reporting drops or
centers problems on the transport side of things
4. Processor utilization levels on the • (4) doesn’t seem to relate to anything
routers connected to the inter-DC link • (3) is the correct answer; there is no network
side reason for a problem, and there is some
sort of issue with seasonal workload

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Application Performance (2)
From: [email protected]
To: [email protected] (mailer list)
Subject: Increase data center capacity

After checking the logs, it appears what has happened is the pre-QoS configuration was choking down the
processing on the existing servers, which was holding down their utilization levels. With the current
configuration on the network side, the servers are now running hot to the point that it’s impacting peak
processing.

We need to add new servers, but capacity is an issue, so we’re going to need to move some processing
into a public cloud provider to carry the peak load until we sort out how to handle this long term. We’ve
contracted with a provider for the processing we need, but we need to figure out how to connect their
compute seamlessly to our existing data centers in a way that will have comparable performance and
privacy to our existing on-premises servers…

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Application Performance (2)
From: [email protected]
To: [email protected] (mailer list)
Subject: Increase data center capacity

After checking the logs, it appears what has happened is the pre-QoS configuration was choking down the
processing on the existing servers, which was holding down their utilization levels. With the current
configuration on the network side, the servers are now running hot to the point that it’s impacting peak
processing.

We need to add new servers, but capacity is an issue, so we’re going to need to move some processing
into a public cloud provider to carry the peak load until we sort out how to handle this long term. We’ve
contracted with a provider for the processing we need, but we need to figure out how to connect their
compute seamlessly to our existing data centers in a way that will have comparable performance and
privacy to our existing on-premises servers…

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
13: Application Performance
Select the level of concern for each option to
connect So-Sure to the cloud provider for hybrid
processing.
Latency Security Cost
Direct link to the cloud
provider
Link to an
interconnect provider
(IXP) which has the
cloud provider on their
fabric • Each cell has three options: high, medium,
Tunnel over an or low
existing plain IP • You will need to select a particular level of
Internet connection concern in each cell to complete the
question

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
13: Application Performance
Select the level of concern for each option to connect
So-Sure to the cloud provider for hybrid processing.
• Direct Link—latency is going to be a matter
of circuit length (geography), queuing, and
Latency Security Cost quality of service; these are knowable, and
Direct link to the cloud probably manageable
LOW • IXP—latency is going to be a matter of circuit
provider
Link to an
length (geography), queuing, quality of
interconnect provider service, and the interconnect service itself; a
(IXP) which has the MEDIUM third party is in the mix, so managing latency
cloud provider on their is a little more difficult
fabric • Over-the-top—there’s almost no way to
Tunnel over an control latency in this situation, although
existing plain IP HIGH many SD-WAN solutions work hard at it;
Internet connection local brownouts and other problems could
shut the entire application down

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
13: Application Performance
Select the level of concern for each option to connect
So-Sure to the cloud provider for hybrid processing.

• Direct Link—security can be directly


Latency Security Cost managed on both ends of the link; traffic can
Direct link to the cloud be encrypted to ensure security
LOW LOW • IXP—traffic probably can’t be encrypted
provider
Link to an
because it needs to be carried through the
interconnect provider IX’s fabric; there is a third party in the mix,
(IXP) which has the MEDIUM MEDIUM but the fabric is (probably) private
cloud provider on their • Over-the-top—traffic can be encrypted, but
fabric there is still the possibility of directed attacks
Tunnel over an taking the virtual link down, or a third party
existing plain IP HIGH HIGH performing a man-in-the-middle attack
Internet connection • This could probably be marked either
medium or high

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
13: Application Performance
Select the level of concern for each option to connect
So-Sure to the cloud provider for hybrid processing.

Latency Security Cost


Direct link to the cloud • Direct Link—is probably the most expensive
LOW LOW HIGH option, as a new circuit must be established,
provider
Link to an
and the cloud provider needs to eat some
interconnect provider local resources
(IXP) which has the MEDIUM MEDIUM MEDIUM • IXP—this is probably a moderate cost
cloud provider on their option, as it does require a new link, but the
fabric link is likely to be a shorter run (within the
Tunnel over an metro area, for instance)
existing plain IP HIGH HIGH LOW • Over-the-top—this is going to be cheap,
Internet connection mostly just a matter of adding any necessary
bandwidth onto the existing connection

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
14: Application Performance
Given the information you have, which
solution would you recommend to So-Sure
for connecting to the public cloud provider?
1. Direct link to the cloud provider
2. Link to an interconnect provider (IXP)
which has the cloud provider on their
fabric
3. Tunnel over an existing plain IP Internet
connection
• In a more complex scenario, this may be the
top of a branching question, followed by a
set of “why” questions to justify your answer
• To simplify, we’re not going to branch here

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
14: Application Performance
Given the information you have, which
solution would you recommend to So-Sure
for connecting to the public cloud provider?
1. Direct link to the cloud provider
2. Link to an interconnect provider (IXP)
which has the cloud provider on their
fabric
3. Tunnel over an existing plain IP Internet
connection
• The least cost solution with the best latency
and security is a connection to a local IXP
with an on fabric connection to the cloud
services provider

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
15: Remote & BYOD
So-Sure has decided that supporting
remote workers out of the branch offices is
adding traffic load and management
complexity. They would like to centralize
their support for remote workers, and bring
in support for BYOD at the same time. On
the following diagram, note where you
would deploy the necessary concentrators
for this support.
• Sometimes new information or a focus
switch can be contained in a question stem
• Don’t always count on getting new
information as exhibits
• Make certain to incorporate information from
stems into your thinking

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 123
15: Remote & BYOD
Atlanta, GA
Atlanta, GA Secondary Data Center

Cloud
New York, NY Based Andover, MA
Primary Data Center
Call Center
Chicago, IL

L3VPN

Seattle, WA SD-
WAN Boston, MA
Headquarters
San Francisco, CA
531 Remote Sites
...
Dallas, TX
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 124
15: Remote & BYOD 1 point
Atlanta, GA
Atlanta, GA 2 points Secondary Data Center

Cloud
New York, NY Based Andover, MA
Primary Data Center
Call Center
Chicago, IL

L3VPN

Seattle, WA SD-
WAN Boston, MA
Headquarters
San Francisco, CA
531 Remote Sites
...
Dallas, TX
TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 125
15: Remote & BYOD
• Chicago
• Large central location, but no data center facilities seem to be located here

• Atlanta Data Center


• A possible location, but not optimal because the data centers are already struggling with capacity
• We just went out to hybrid cloud as a temporary solution for capacity issues

• Boston
• This is the company headquarters, and hence probably the largest office
• But there’s no data center here

• Cloud based
• Allows the best flexibility and reachability
• Could be brought in house if capacity issues are sorted out

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 126
16: BYOD
What further considerations should So-Sure
examine when deploying BYOD (Choose
three.)?
1. Density of wireless devices
2. Device security and policy
3. On-boarding of new devices
4. Additional cost of devices
5. Type of devices supported (laptop,
phone, etc.)

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 127
16: BYOD
What further considerations should So-Sure
examine when deploying BYOD (Choose
three.)?
1. Density of wireless devices
2. Device security and policy
3. On-boarding of new devices
4. Additional cost of devices
• (1) doesn’t make any sense
5. Type of devices supported (laptop, • (2) is the major issue in deploying BYOD
phone, etc.) • (3) is a process that does need to be
handled, whether outsourced or insourced
• (4) What’s the point of BYOD again?
• (5) The company does need to decide if it
will support all devices, or just a subset

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 128
Study and Exam Tips
CCDE Study Tips
• Honestly assess your strengths in • Design Mindset
all technologies and blueprint • Focus on design chapters of
domains recommended books
• Prioritize your studies based on • Don’t worry about configuration
weaknesses unless it helps solidify your
understanding of the technology
• Design experience is key
• Evaluate past work projects
• Read as many case studies and
design reviews as possible
• Join a study group that shares real
world design challenges

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 130
Interacting With the CCDE Practical Exam
Understand
• Don’t get overwhelmed by the
amount of information provided
• Take the time to comprehend and
absorb the question
• Don’t be so fast on your decision Connect
• Don’t make false assumptions
• Real-life: will have to work around • Always consider the provided
constraints and bad decisions customer requirements and
constraints
Take action • Connect the question with
• Apply the best design strategy previous questions and
to answer the questions scenario information
• Consolidate the information to • Look at the bigger picture
support your answer – look
again and you’ll find it TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 131
CCDE Preparation Resources
• CCDE Written exam blueprint:
https://learningnetwork.cisco.com/community/certifications/ccde/written_exam/
exam-topics
• CCDE Written exam study/learn:
https://learningnetwork.cisco.com/community/certifications/ccde/written_exam/
study-material

• CCDE Practical exam blueprint:


https://learningnetwork.cisco.com/community/certifications/ccde/practical_exa
m/exam-topics
• CCDE Practical exam study/learn:
https://learningnetwork.cisco.com/community/certifications/ccde/practical_exa
m/study-material

• CCDE Study Group: https://learningnetwork.cisco.com/groups/ccde-study-


group
• Unleashing CCDE Blog: https://learningnetwork.cisco.com/blogs/unleashing-
ccde
• Follow us on Twitter to be in the loop: @elopes01, @rtggeek and @ylukin00

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 132
CCIE/CCDE Program Update
CCIE/CCDE NextGen
Focus targeted towards revamp of Qualification Exams and Blueprints

Transition Written
Combine Add Add Evolving
(Qualification) Exam
Track-specific Blueprint Networking Technologies section
to new secure
(Unified Blueprint Fundamentals baseline to all tracks
delivery model
= Written + Lab) (L2 & L3) (SDN, IoT, Cloud)
(IBT)

to be continued..

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 134
CCIE/CCDE Blueprint Framework
• New Evolving Technologies section across all CCIE tracks (July 2016)
• Future proofing IT professional skills
Blueprint Weights
• Holistic assessment of each learning domain
WRT% LAB%
NEW EXAM TOPIC Evolving Technologies (Common across all Tracks)
REST Automation and NFV/ 10% N/A
SDN IoT DevOps XaaS OpenStack Cloud
API Orchestration AFV

CCIE Data CCIE CCIE CCIE CCIE CCIE CCDE


Center v2.0 SP Security v5.0 Wireless Collaboration R&S Current BP
Consolidated/ Current Consolidated/ Current BP Current BP Current BP per track 90% 100%
Unified BP Unified per track per track per track
Blueprint per track Blueprint

100% 100%
Reference Material: https://learningnetwork.cisco.com/docs/DOC-29253

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 135
Learning and Enablement
CCIE Community
Live Virtual Events • Interactive online events

• Learning@Cisco leaders discuss


state of the industry, program
updates, and
items that are top of mind
to community

• Events held twice a year


and are invite-only

https://learningnetwork.cisco.com/community/a
rchived_events/ccie-community-events

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 137
CCIE Technical Webinar Series
Technical Sessions delivered by Cisco Distinguished Engineers—
focused on new technologies
CISCO NETFLOW AND BIG DATA
OPENSTACK FOG ARCHITECTURE ANALYTICS FOR CYBERSECURITY

OPENSTACK NEUTRON DEEP DIVE


CISCO DNA DEEP DIVE
DO IT WITH DEVOPS
STEALTHWATCH LEARNING NETWORKS

https://learningnetwork.cisco.com/community/archived_events/ccie-community-events

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 138
Stay
Connected!
Opt-In for CCIE
Specific Information
cisco.com/go/ccie-comms

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 139
Cisco Certifications SME Recruitment Program
Collaborate and network Directly influence Cisco Career
with other engineers Certifications (Design, Author, Review)

Use and sharpen


Give back to community
technical expertise

Join creativity with experience, Experience with


knowledge and skills assessment techniques

cisco.com/go/certsme SME= Subject Matter Expert

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 140
Q&A
Complete Your Online Session Evaluation
• Please complete your Online
Session Evaluations after each
session
• Complete 4 Session Evaluations &
the Overall Conference Evaluation
(available from Thursday) to receive
your Cisco Live T-shirt
• All surveys can be completed via
the Cisco Live Mobile App or the
Don’t forget: Cisco Live sessions will be available
Communication Stations for viewing on-demand after the event at
CiscoLive.com/Online

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 142
Continue Your Education
• Demos in the Cisco campus
• Walk-in Self-Paced Labs
• Lunch & Learn CCDE: Insights from the trenches Tuesday at noon
• Meet the Engineer 1:1 meetings
• Related session (duplicate): CCDE Lab – LTRCCDE-3006
• Wednesday at 9 AM
• Friday at 9 AM

TECCCDE-3005 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 143
Thank You

You might also like