Cisco DNA Software For SD-WAN and Routing Ordering Guide - Guide-C07-740642
Cisco DNA Software For SD-WAN and Routing Ordering Guide - Guide-C07-740642
Cisco public
Cisco SD-WAN and Routing subscription gives the flexibility to consume the latest technology, either on the Cloud or
On-Premises across the entire routing stack. The Cisco DNA subscription license tiers include 3Y and 5Y term options. All
available tiers include Cisco Software Support Service.
Cisco DNA Subscription PID nomenclature To begin ordering Cisco DNA Software Subscriptions for SD-WAN and
Routing, please follow the below steps:
The Cisco DNA Subscription Product part codes have a built-in structure
that indicates the following: Step 1: Platforms
© 2020 Cisco
© 2020and/or
Ciscoitsand/or
affiliates. All rightsAll
its affiliates. reserved.
rights reserved.
Ordering guide
Cisco public
Modular chassis Branch Routers Cisco 4000 Series Integrated Services Routers
Step 4: S
mart account and
Virtual account Cisco vEdge Router (vEdge-2000 and
vEdge-5000)
Step 5: Services Aggregation Services Routers Cisco 1000 Series Aggregation Services Routers
The platforms in Table-1 above can be ordered either for Cisco SD-WAN deployment or for Traditional
Routing along with Cisco DNA Software Subscriptions.
Table-2 below shows all the Cisco DNA bundles that can be specifically ordered for Cisco SD-WAN deployments.
Table 2. Platform Product IDs for Cisco SD-WAN DNA Bundles
1
ISR4421X-DNA and ISR4461-DNA bundle is targeted for second half of CY2020, however both these platforms are orderable as ala-carte hardware + L-LIC-DNA-ADD
The platforms in Table-3 below can be ordered as a la-carte, either for Cisco SD-WAN deployment or for Traditional Routing along with Cisco DNA Software
Subscriptions through L-LIC-DNA-ADD
Table 3. Cisco WAN platform Product IDs supported with Cisco DNA Software Subscriptions
W* - Refer to the ISR1000 ordering guide for more information on various Wireless-domain SKU’s: https://www.cisco.com/c/en/us/products/collateral/routers/1000-series-integrated-services-
routers-isr/guide-c07-740009.html
The platforms in Table-4 below lists the Software WAN platforms that can be deployed on Private or Public cloud and can be ordered only using
L-LIC-DNA-ADD
Table 4. Software WAN platform Product IDs for new deployments
Understanding the Cisco DNA and Cisco IOS product part codes
The Cisco IOS and subscription product part codes have a built-in structure as described below.
Structure of product ID for Cisco IOS XE image
CM = SDWAN Image
Image for ISR4300 Series
Selecting a Cisco IOS type for the router (Cisco IOS XE-SDWAN)
For any router with a Cisco DNA Bundle (for example, ISR4331-DNA or ASR1001-HX-DNA), the choice of Cisco IOS type is limited only to
Cisco IOS XE-SDWAN (which will be pre-installed at factory) and is chosen as below:
• Choose the desired Cisco DNA bundle and select Cisco IOS type under the Option class “IOS Software and Version Type”
• Choose from available IOS XE SD-WAN image versions under the Option subclass “SD-WAN Image with Payload Encryption”
Selecting a Cisco IOS type for the router (Cisco IOS XE-SDWAN)
For any ISR/ASR series router (for example, ISR4331/K9 or ASR1001-X), the Cisco IOS type is chosen as below:
• The customer selects the Cisco IOS type under the Option class “IOS Software and Version Type”
• If the customer prefers the IOS XE SD-WAN image, they will choose from the available versions under the Option subclass “SDWAN Image with
Payload Encryption.”
• If the customer prefers the Cisco IOS XE image, they will choose from the available versions under the Option subclass “Image with Payload Encryption”
or “Image with No Payload Encryption”
Management option:
Cisco SD-WAN and Routing subscriptions offer maximum flexibility through cloud or on-premises management options. Cloud management through the
vManage console is the recommended option for customers wishing to simplify WAN deployments, accelerate digital transformation, and move toward
intent-based networking.
Table 5. Management options
Cloud management Provides simplicity of management with Cisco vManage Cloud management software part numbers follow the
DNA-C-<>-<>-<> construct (For eg: DNA-C-25M-E-3Y)
On-premises management Manages WAN using Cisco DNA Center or vManage on-premises. On-premises management software part
numbers follow the DNA-P-<>-<>-<> construct (For eg: DNA-P-25M-E-3Y). Cisco DNA Center requires an additional
appliance purchase
Cisco DNA licenses for WAN provide you flexibility to move from on-premises to cloud management, and across hardware and software platforms. There is
no charge for porting licenses within the same bandwidth tier. Device family classifications for Cisco ONE Software are available in the Cisco ONE Software
Device Tiering Guide.
So let’s work through the example in the figure below. Aggregate all of your bandwidth together. Upstream. Downstream. Across all circuits. That’s your
Aggregate bandwidth. In this example it’s 143 Mb/s. Now divide that by two to get to a Nominal bandwidth to determine which PID is needed. In this case,
you need a PID that can handle greater than 71.5 Mb/s. That’s the 100 Mb/s PID.
What causes some confusion is highly asymmetrical usage. In this example, if you look at the sum of the downstream bandwidth, you’ll see that it alone is
over 100 Mb/s. One might think that the 100 Mb/s license would not be enough. But it is. The 100 Mb/s PID enables 200 Mb/s of aggregate bandwidth,
which can be used in any upload / download ratio.
1 2 3
Table 6 below gives the range of Bandwidth entitlement and Subscription term options available with Cisco DNA Software Subscriptions
Table 6. Cisco DNA Cloud and On Premise Software subscription Product IDs
Note: The numbers in the Product IDs column are not aggregated throughput number.
Subscription tiers:
Three software subscription tiers offer feature combinations tailored to your needs. Depending on the platform and deployment needs, the following offers
can be chosen across all the platforms mentioned in Step-1
Subscription term:
With any of the Cisco Software Subscription offers, there is a choice of 3Y and 5Y Subscription terms
A. If you are choosing a Cisco DNA Bundle (For eg: ISR4331-DNA OR any platform from Table-2 in Step-1:Platforms Section), you can complete the
ordering process along with built-in Cisco DNA subscription SKUs. You can skip STEP-2.
B. If you are choosing an ala-carte Router hardware platform (For eg: ISR4221/K9 or ASR1002-X), complete the ala-carte ordering process by selecting
the suitable Cisco IOS type, Network Modules and add L-LIC-DNA-ADD SKU at the end.
-- When purchasing a new router, if the intended use is to deploy the subscription through Cisco DNA Center, no additional Technology Package license
needs to be purchased (exception: ASR 1000 platforms require selection of IP Base, which acts as the OS). All necessary feature licenses required for
a subscription are included when Cisco DNA Essentials or Cisco DNA Advantage licenses are procured (through Step-2).
-- Similarly, all Performance or Boost licenses are included when Cisco DNA Essentials or Cisco DNA Advantage licenses are procured (through Step-2).
-- Refer to “Working with L-LIC-DNA-ADD” section in Step-2 below for completing the Cisco DNA Software subscriptions ordering
Step-2: Select the L-LIC-DNA-ADD SKU:
In these scenarios, the customer will configure the router and the subscription independently. The customer configures the router (for example, the ISR4321/
K9, ISR4351, or ASR1002-X) and selects the relevant Cisco IOS type as described in the section “Step-2: Software”. Finally, the customer chooses
L-LIC-DNA-ADD, which provides various subscription options for each platform family as described below.
If the choice is a cloud platform or a subscription on existing hardware, the product ID shown in Table 7 is applicable.
Table 7. WAN platform Product ID for cloud or existing deployments
Product ID Description
Once you have selected the above product ID, select the platform for which you need to order the Cisco DNA Subscription (See Table 8 below)
Table 8. Platform licenses for L-LIC-DNA-ADD for cloud or existing deployments
vEdge Cisco DNA VEDGE-100B-DNA vEdge 100B platform for Cisco DNA
ISR 1000 C1100-8P-DNA 1100 ISR 8-port platform for Cisco DNA
C1100SV-8P-DNA ISR1100 SV 8 Port 1121, 1126, 1127, 1161 platforms for DNA
ISR 1100 (Viptela OS) ISR1100-4G-DNA ISR1100 platform for Cisco DNA for ISR1100-4G
ENCS 5000
Example of Virtual Router
VEDGE CISCO DNA
Platform Family
ISR1100
ISR4220
ISR4300
ISR4400
Example of Physical Router
ASR1001X
Platform Family
ASR1002HX
• The warnings indicate the supported bandwidths for the chosen platform family
• Select the intended subscription reason for SD-WAN or for Cisco DNA Center deployment. This helps Cisco manufacturing prepare the infrastructure for
cloud or for on-premises deployment
-- When selecting SDWAN-ONPREM, the intended reason is for on-premises implementation of SD-WAN functionality
-- When selecting SDWAN-CLOUD, the intended reason is for cloud implementation and management of SD-WAN functionality
-- When selecting DNACENTER-ONPREM the intended reason is for on-premises implementation and management using Cisco DNA Center functionality
• Select the appropriate bandwidth for the product family chosen. Refer to Table-9 for the appropriate Bandwidth selections
Table 9 below lists the bandwidths available for each platform. For example, for the 4331 ISR, you can choose from 25M, 50M, 100M and 250M
Table 9. Cisco DNA Subscription Bandwidth tiers by platform
*Only fixed chassis of ASR1000 family supports Cisco SD-WAN DNA subscriptions
Scenario 1: Purchasing subscription in conjunction with the platform using the Cisco DNA bundles (eg: ISR4331-DNA, C1111-8P-DNA)
Scenario 2: Purchasing subscription for an existing Router using the L-LIC-DNA-ADD top level SKU (eg: ISR4221/K9, C1117-4P and a subscription using
L-LIC-DNA-ADD)
In Scenario 1, the HSEC license is auto included with each Cisco DNA bundle where the chosen subscription exceeds 250Mbps.
In Scenario 2, the customer is entitled to a HSEC license at $0 where the chosen subscription throughput exceeds 250Mbps. The entitled HSEC maybe
procured by choosing the appropriate product SKU.
The following advanced security features require a minimum of 8-GB memory and 8-GB boot flash on all platforms:
1. Intrusion prevention system
2. URL filtering
3. Advanced Malware Protection (AMP and ThreatGrid)
Platforms/Features Ent FW Ent FW App IPS URL AMP and DNS/weblayer security
Awareness Filtering TG
vEdge - (100, 1000, 2000 and 5000) Y N/A N/A N/A N/A Y
CSR 1000V Y Y Y Y Y Y
ISRv (ENCS) Y Y Y Y Y Y
ISR 4000 (4461, 4451, 4431, 4351, 4331,
4321, 4221x) Y Y Y Y Y Y
Notes:
1. CSR 1000V supports URL Filtering, AMP and DNS Security only in on-premise deployment. The Cisco ISRv and Cisco CSR 1000V need four vCPU and a minimum of 8GB RAM and 8GB bootflash.
2. URL filtering is supported with cloud lookup only with 8GB. 16GB is required for on-box URL database download and lookup.
Step 4: Smart account and Virtual account -- Don’t use email addresses in the Virtual Account name. A Virtual
Account name can have A-Z, a-z, 0-9, and _. Virtual Account names
An end-user smart account and virtual account are mandatory for the Cisco can be a maximum of 32 characters
SD-WAN ordering process. Cisco SD-WAN requires a unique identifier to
-- The Virtual Account name is the Org ID. The Org ID is used in the
auto-provision hardware devices for end customers. Since Smart Accounts
certificate Org Name
and Virtual Accounts are both unique and partner-enabled, they provide a
convenient mechanism for provisioning the Cisco SD-WAN solution. (Note: -- Example Virtual Account format: For an MSP tenant,
SD-WAN will be provisioned on Cisco routers using Smart Accounts.) <END-CUSTOMER>_PROD
For the Cisco SD-WAN solution, Virtual Accounts are aligned to a • Step 3: Go to CCW and start ordering
customer overlay and the devices that should be associated with the overlay. -- https://apps.cisco.com/ccw/cpc/estimate/create
Failure to provide a Virtual Account during ordering will result in a delay in -- Ensure that the Smart Account and Virtual Account details are
device provisioning. populated via “Assign Smart Account”
Each Smart Account can have multiple Virtual Accounts. If the customer When ordering in Cisco Commerce Workspace (CCW), the end customer’s
has two customer overlays, they would have two different Virtual Accounts. Smart Account and Virtual Account can be added at the line level or at the
Managed Services Providers (MSPs) will create a Smart Account and be the header level and applied to all applicable Smart items on the order.
Smart Account owner. The MSP would then need to create a Virtual Account
for every end customer (or tenant), assuming that each end customer has a
specific overlay.
Cisco Embedded Support is included with the purchase of the Cisco SD-
WAN software subscription. Cisco Embedded Support provides access to
Cisco technical support online or by phone.
Cisco Embedded Support includes:
• Access to support and troubleshooting via online tools and web case
submission. Case severity or escalation guidelines are not applicable
• Cisco Technical Assistance Center (TAC) access 24 hours per day, 7 days
per week to assist by telephone, or web case submission and online tools
with application software use and troubleshooting issues
• Entitlement to maintenance releases and software updates for SD-WAN
software only. The Support for the hardware platform OS, along with OS
updates, is covered by the support contract on the hardware.
• Access to www.cisco.com This system provides the customer with
The end customer’s email address is essential for Cisco SD-WAN orders. helpful technical and general information on Cisco products, as well as
In the case of cloud deployments, details on vManage will be sent to this access to Cisco’s online Software Center library
email address. No additional products or fees are required to receive these services with a
software subscription. Hardware support must be purchased separately and
is not covered as part of the embedded SW support contract.
Steps for ordering a WAN subscription on the Cisco Enterprise Network Compute System (ENCS)
In this section we will go over the subscription ordering process for the ENCS. The Enterprise NFV solution is ordered through term-based subscription
licenses that may be purchased with a 3- or 5-year duration. At the time of ordering, you may choose a Cisco DNA Licensing for SD-WAN and Routing start
date that is independent of the hardware ship date.
The ordering process for routing subscriptions on the ENCS hardware is structured using a multiline bundle. This bundle provides the flexibility to choose the
appropriate software stack and the corresponding hardware stack to run it on.
To order the SD-Branch solution, use the NFV-BRANCH-MLB top-level part number, as shown in Table 10.
Table 10. Enterprise NFV solution top-level Product ID
Product ID Description
NFV-BRANCH-MLB is the top-level multiline part number and can be used as the starting point for both the software subscription licenses and the Cisco
ENCS hardware options. Table 11 covers the sub options under NFV-BRANCH-MLB.
Table 11. Sub options under NFV-BRANCH-MLB
Software licenses
Hardware
ENCS5412/K9 5412 Enterprise Network Compute System (12-core, 1.5 GHz Intel® CPU, 16 GB DRAM)
ENCS5408/K9 5408 Enterprise Network Compute System (8-core, 2.0 GHz Intel CPU, 16 GB DRAM)
ENCS5406/K9 5406 Enterprise Network Compute System (6-core, 1.9 GHz Intel CPU, 16 GB DRAM)
ENCS5104-400/K9 5104 Enterprise Network Compute System (4-core, 3.4 GHz AMD CPU, 16 GB DRAM, 400G SSD)
ENCS5104-200/K9 5104 Enterprise Network Compute System (4-core, 3.4 GHz AMD CPU, 16 GB DRAM, 200G SSD)
ENCS5104-64/K9 5104 Enterprise Network Compute System (4-core, 3.4 GHz AMD CPU, 16 GB DRAM, 64G SSD)
Ordering software subscription licenses for the Cisco 5000 The ordering tool does not verify the VNF requirements at this time. For the
Series ENCS purposes of sizing in this document, the terms “core,” “vCPU,” and “physical
CPU core” are considered equivalent.
L-LIC-DNA-ADD is a container for all of the term subscription licenses for
the 5000 Series ENCS solution. These software licenses are common to all
ENCS platforms. The ENCS platforms have been grouped together under the Software selection choices on the ENCS
Hardware category. Software subscription licenses are ordered via L-LIC-DNA-ADD, as described
in the previous section. On the ENCS hardware you will have to select either
The WAN licenses include choices along four main dimensions: preferred
the ISRv (non-SD-WAN) or ISRv XE SD-WAN image binary and version.
choice of management, performance, term, and feature tiers.
Note:
For ENCS deployments, choosing on-premises or cloud SKUs will entitle the
end user to Cisco DNA Center licenses, as the instantiation of virtual network 1. Selecting this instance does not license the VNF. This ensures only that the right code is
functions on the ENCS is orchestrated via Cisco DNA Center. loaded onto the hardware
Performance options on the ENCS range from 25 Mbps to 500 Mbps. 2. ISRv XE SD-WAN is supported on all 5400 ENCS platforms
This selection maps to the Cisco Integrated Services Virtual Router (ISRv) Table 13 lists the supported ENCS platforms.
and IOS XE SD-WAN throughput licenses. When using L-LIC-DNA-ADD,
Table 13. Hardware platforms supported on the ISRv 16.9 – SD-WAN XE
you must choose the platform license. The platform license determines
the throughputs supported on the underlying hardware. Table 12 lists the
Model Description
throughput licenses supported on the ENCS platforms.
Table 12. Throughputs supported on the ENCS platforms ENCS 5412/K9 5412 Enterprise Network Compute System
(12-core, 1.5 GHz Intel CPU, 16 GB DRAM)
Platform Throughputs supported
ENCS 5408/K9 5408 Enterprise Network Compute System
5400ENCS 25, 50, 100, 250 and 500 Mbps (8-core, 2.0 GHz Intel CPU, 16 GB DRAM)
Table 14. NIMs supported with ISRv XE SD-WAN 16.9 on the 5400 ENCS Further, additional NIMs are supported with ISRv 16.9 (non-SD-WAN), as
shown in Table 16.
Type of Interface NIMs
Table 16. NIMs supported with ISRv 16.9 on the 5400 ENCS
4G-LTE NIM-LTEA-EA
Type of Interface NIMs NIM-4G-
NIM-LTEA-LA
4G-LTE LTE-NA NIM-4G-
T1/E1 NIM-1MFT-T1/E1
LTE-VZ NIM-4G-
NIM-2MFT-T1/E1
NIM-4MFT-T1/E1 LTE-GA NIM-
NIM-8MFT-T1/E1 4G-LTE-ST
NIM-4G-LTE-LA
ISRv 16.9.1 (non-SD-WAN) is supported on all ENCS platforms. Table 15
lists the supported ENCS platforms. NIM-LTEA-EA
Table 15. Hardware platforms supported on the ISRv 16.9.1 NIM-LTEA-LA
• Under the Cisco DNA hardware bundle, select the Option class “DNA OPT OUT” and select one of the below appropriate opt-out SKU’s
PID Description
The following crypto modules are required for the ASR 1000 Series routers:
APPENDIX-C: Cisco DNA ordering and license management on the 4000 Series ISRs
When the customer wishes to subscribe to a Cisco DNA Center and orders.
• Cisco DNA Essentials, Advantage, or Premier with bandwidth less than or equal to the factory default2 of the platform, no performance license need to be
ordered for the platform
• Cisco DNA Essentials, Advantage, or Premier with bandwidth greater than the factory default but less than the bandwidth provided by the High-
Performance license³ of the platform, a performance license is automatically added at the time of order and the customer does not need to order it.
Additionally, if the bandwidth (post-encryption) is greater than 250 Mbps, the HSEC license for the relevant platform is automatically added
• Cisco DNA Essentials, Advantage, or Premier with bandwidth greater than the High-Performance license4 of the platform, but less than or equal to the
maximum subscription bandwidth permitted for the platform, a BOOST license is automatically added to the order and the customer does not need to
order it. Additionally, if the bandwidth (post-encryption) is greater than 250 Mbps, the HSEC license for the relevant platform is automatically added.
• Cisco DNA Essentials, Advantage, or Premier with bandwidth, no additional Technology Packages need to be ordered
• Unified Communications is now packaged into the Cisco DNA Essentials and Cisco DNA Advantage. Voice Optimization is supported in Essentials
whereas Rich voice services and integration with SRST /FXO/FXS are the prime focus on the Cisco DNA Advantage package
When the customer wishes to subscribe to Cisco DNA for Enterprise Routing and SD-WAN and orders.
• Cisco DNA Essentials, Advantage, or Premier with bandwidth less than or equal to the factory default⁵ of the platform, no performance license need to be
ordered for the platform. No IP Base license or Technology Packages (or add-on licenses) need to be purchased
• Cisco DNA Essentials, Advantage, or Premier with bandwidth greater than the factory default but less than the bandwidth provided by the High-
Performance license6 of the platform, a performance license is automatically added at the time of order and the customer does not need to order it.
Additionally, if the bandwidth (post-encryption) is greater than 250 Mbps, the HSEC license for the relevant platform is automatically added. No IP Base
license or Technology Packages (or add-on licenses) need to be purchased
• Cisco DNA Essentials, Advantage, or Premier with bandwidth greater than the High-Performance license7 of the platform, but less than or equal to the
maximum subscription bandwidth permitted for the platform, a BOOST license is automatically added to the order and the customer does not need to
order it. Additionally, if the bandwidth (post-encryption) is greater than 250 Mbps, the HSEC license for the relevant platform is automatically added. No IP
Base license or Technology Packages (or add-on licenses) need to be purchased
2
For platform positioning, please refer to https://www.cisco.com/c/en/us/products/collateral/routers/4000-series-integrated-services-routers-isr/white-paper-c11-734550.html
(Table 1) ISR 4000 Performance Levels.
4
The 4331 ISR provides up to 250 Mbps of encrypted performance per direction (incoming and outgoing), aggregating to 500 Mbps of platform performance.
6
As an example, for the 4331 ISR, the High-Performance license allows a customer to go up to a bandwidth of not more than 300 Mbps. Hence (as an SD-WAN subscription license provides a
customer with an entitlement for the purchased bandwidth in each direction), the 4331 ISR supports a bandwidth of 100 Mbps (allowing for 100 Mbps up and 100 Mbps down).
7
The SD-WAN software on the 4331 ISR can provide for 250 Mbps of performance in each direction.
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/go/trademarks.
Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) C07-740642-08 08/20