With Cisco Catalyst SD-WAN multitenancy, a service provider can manage multiple customers, called tenants, from Cisco SD-WAN Manager.
The tenants share the same set of underlying Cisco SD-WAN Control Components:
-
Cisco SD-WAN Manager
-
Cisco SD-WAN Validator
-
Cisco SD-WAN Controller
The tenant data is logically isolated on these shared control components.
Access to multitenancy
The service provider accesses Cisco SD-WAN Manager using a domain name mapped to the IP address of a Cisco SD-WAN Manager cluster and manages the multitenant deployment.
Each tenant is provided a subdomain to access a tenant-specific Cisco SD-WAN Manager view and manage the tenant deployment.
A service provider using the domain name managed-sp.com can assign tenants Customer1 and Customer2 the subdomains:
-
customer1.managed-sp.com
-
customer2.managed-sp.com
This allows the service provider to manage multiple tenants on the same set of SD-WAN Controllers instead of providing each customer a single-tenant setup with a dedicated set of SD-WAN Controllers.
Full enterprise multitenancy
Cisco Catalyst SD-WAN supports multitenancy and offers enterprises the flexibility of segregated roles such as service provider and tenants. Service
providers can use multitenancy to provide Cisco Catalyst SD-WAN service offerings to their customers.
Security
Send and receive AAA traffic over management VPN 512 from Cisco IOS XE Catalyst SD-WAN Release 17.16.1a.
Overlapping VPN numbers
A particular VPN or a set of common VPNs is assigned to a specific tenant, with their own configurations and monitoring dashboard
environment. These VPN numbers can overlap where they are used by other tenants.
On-prem and cloud deployment models
Cisco Catalyst SD-WAN controllers can be deployed in:
-
An organization data center on servers running VMware ESXi 6.7 or later, or the Kernel-based Virtual Machine (KVM) hypervisor.
-
Amazon Web Services (AWS) servers hosted by Cisco CloudOps.
Tenant-specific Cisco SD-WAN Analytics
Cisco SD-WAN Analytics is a cloud-based service that offers insights into the performance of applications and the underlying
SD-WAN network infrastructure.
Each tenant can obtain Cisco SD-WAN Analytics insights for their overlay network by:
The service provider must enable cloud services on SD-WAN Manager in the provider view to facilitate the onboarding of the Cisco SD-WAN Analytics instance for the tenant overlay network.
Single tenant environments
A single tenant environment exclusively manages, and is responsible for, its own Cisco Catalyst SD-WAN Control Components
and devices. All configured resources are visible to the single tenant administrator in the Cisco SD-WAN Manager interface.
Cloud-delivered Catalyst SD-WAN
Cloud-delivered Catalyst SD-WAN operates as a tenant within a multitenant environment rather than as a single tenant. Cloud-delivered
Catalyst SD-WAN users do not see controller infrastructure settings in Cisco SD-WAN Manager. Their available information is
limited to their own components and WAN edge devices.
For more information on Cloud-delivered Catalyst SD-WAN, see Cloud-delivered Cisco SD-WAN Getting Started Guide.
Multitenancy
-
Multitenant Cisco SD-WAN Manager
-
Multitenant Cisco SD-WAN Validator
-
Multitenant Cisco SD-WAN Controller
-
Tenant-specific WAN edge devices