Professional Documents
Culture Documents
Cisco SD-Access
Campus Wired and Wireless
Deployment using
Cisco Validated Designs
#CLUS
Agenda
• Introduction
• Cisco SD-Access Design
• Architecture and Components
• Cisco SD-Access Deployment
• Installation – Cisco DNA Center
• Integration – ISE, IPAM
• Network Infrastructure – Underlay
• Cisco SD-Access Deployment (Live Demonstration)
Design Policy Provision
• Summary
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
#CLUS © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Cisco’s Intent-Based Networking
Delivered by Software Defined Access
LEARNING
INTENT CONTEXT
Intent-Based
Network Infrastructure
SECURITY
Monday (June 10) Tuesday (June 11) Wednesday (June 12) Thursday (June 13)
08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00 08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00 08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00 08:00-11:00 11:00-13:00 13:00-15:00 15:00-18:00
BRKARC-2020 BRKARC-2009
Troubleshoot Why SDA
BRKCRS-3811
Policy
BRKEWN-2021 BRKEWN-2020
Live Setup Wireless
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco Validated Designs
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Cisco SD-Access
Fabric Roles & Terminology
Cisco DNA Cisco DNA Automation – provides simple
Automation GUI management and intent based
Identity automation (e.g. NCP) and context sharing
Services
ISE Cisco DNA Assurance – Data Collectors
Cisco Cisco DNA (e.g. NDP) analyze Endpoint to App flows
DNA Center Assurance and monitor fabric status
Identity Services – NAC & ID Systems
(e.g. ISE) for dynamic Endpoint to Group
Fabric Border Fabric Wireless mapping and Policy definition
Nodes Controller
B B Control-Plane Nodes – Map System that
manages Endpoint to Device relationships
Intermediate Control-Plane Fabric Border Nodes – A Fabric device
C Nodes
Nodes (Underlay) (e.g. Core) that connects External L3
network(s) to the SDA Fabric
Fabric Edge Nodes – A Fabric device
(e.g. Access or Distribution) that connects
Fabric Edge Wired Endpoints to the SDA Fabric
Nodes
Fabric Wireless Controller – A Fabric device
E E E E (WLC) that connects APs and Wireless
Endpoints to the SDA Fabric
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
SD-Access Hierarchical Network Segmentation
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Cisco Software-Defined Access
Cisco DNA Center™:
Simple workflows
DNA Center
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Cisco DNA Center Appliance
Hardware Appliance options
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Identity Service Engine
Hardware / Virtual Appliance
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
SD-Access
SD- Access Support
For more details: cs.co/sda- compatibility- matrix
Support For more details: cs.co/sda-compatibility-matrix
NEW
ASR- 1000- X
NEW
Catalyst 9200
NEW AIR- CT8540
ISR 4451
#CLUS
#CLUS BRKCRS- 1501 © 2019
2019 Cisco
Cisco and/or
and/or its
its affiliates.
affiliates. All
All rights
rights reserved.
reserved. Cisco
Cisco Public
Public 16
Connectivity Services
Where do I place Cisco DNA Center?
Local DC or Services Block Remote DC
Internet Internet
DC
Metro
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Cisco Identity Services Engine
Standalone or Distributed deployment
1:1 redundancy
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Cisco SD-Access Design options
Recommended Guidelines For more details: cs.co/sda-compatibility-matrix
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
SD-Access Multi-site Design Options Cisco DNA Center
Traditional
Campus LAN
SD-Access
Small Site
E B C
SD-Access
SD-Access
Medium Site
Large Site
E B C E B C
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Agenda
• Introduction
• Cisco SD-Access Design
• Architecture and Components
• Cisco SD-Access Deployment
• Installation – Cisco DNA Center
• Integration – ISE, IPAM
• Network Infrastructure – Underlay
• Cisco SD-Access Deployment (Live Demonstration)
Design Policy Provision
• Summary
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Cisco SD-Access Deployment – “How”
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Cisco DNA Center Appliance Connections
Physical Interface & Connections
• NTP, DNS is required • Service Subnet & Cluster Service Subnet is required (/21 subnet)
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Cisco DNA Center Appliance Connections
Physical Interface & Connections
• NTP, DNS is required • Service Subnet & Cluster Service Subnet is required (/21 subnet)
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Cisco DNA Center
Is the appliance is behind Firewall ?
Note: Refer to the Cisco DNA Installation guide for more specific details
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Cisco DNA Center
Is the appliance is behind proxy ?
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Cisco DNA Center Installation
Step 1 - 2
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Cisco DNA Center Installation
Step 3 - 4
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Cisco DNA Center Installation
Step 5
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Cisco DNA Center Installation
Step 6 - 7
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Cisco DNA Center Installation
Step 8 - 9
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Cisco DNA Center Installation
Step 10 - 11
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Cisco DNA Center Installation
Step 12 – 13 (First Time Setup)
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Cisco DNA Center Installation
Step 14 - 15
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Cisco DNAC Upgrade & Install Packages
Application: SD-Access
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Identity Services Engine
Requirements for Integration
Enable pxGrid on ISE Enable ERS on ISE
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Integrate ISE with Cisco DNA Center
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Integrate ISE with Cisco DNA Center
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Integrating IPAM with Cisco DNA Center
Optional
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
ISE Authentication and Authorization
Cisco SD-Access secure onboarding
Active Directory
ENTERPRISE SQL Server
NETWORK LDAP / SQL
LDAP Servers
Contractors IP Phone
SGT - 6 SGT - 18
Lights
IP Camera SGT - 10
SGT - 14
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Network Infrastructure – Underlay
Cisco SD-Access Underlay options
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
SD-Access Support
LAN Automation Platform
• Network Device should be enabled with Network Advantage + DNA Advantage License
• Catalyst 6800 Seed Device interface needs to be converted to Layer-2 Ports
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Agenda
• Introduction
• Cisco SD-Access Design
• Architecture and Components
• Cisco SD-Access Deployment
• Installation – Cisco DNA Center
• Integration – ISE, IPAM
• Network Infrastructure – Underlay
• Cisco SD-Access Deployment (Live Demonstration)
Design Policy Provision
• Summary
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Live
Demonstration
Demonstration Topology WLC
Cisco DNAC
Shared-Services
RTP Site – Cisco SD Access Network
DHCP
Scalable Group Virtual Network IP Address Pool DNS
NTP
Vending_Machine VN_IOT 10.4.217.0/24
Traditional Network ISE
IoT_Devices VN_IOT EIGRP
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
SD-Access Workflow
Design – Policy workflow
Network Hierarchy Network Settings – Network Settings Network Settings - Address Pools
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
SD-Access Workflow
LAN Automation workflow
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Cisco SD-Access
before Onboarding Endpoints – Fusion Configuration
Cisco DNA-Center
ISE
Traditional Network
GRT DHCP, DNS, AD
Fusion
Border Border
VN_Campus
10.4.212.0/24
10.4.214.0/24
VN_IoT
10.4.217.0/24
INFRA_VN
10.4.217.0/24 VN_Guest
10.4.215.0/24
DEFAULT_VN
Edge Edge
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Fusion Configuration
connecting Fabric to Traditional Infrastructure
Extend eBGP Route Leak iBGP
• Configure VRF • eBGP neighbors • Route-leak shared-services • iBGP neighbors for each
• Interfaces for for each VN between subnets to each VN VN between Border nodes
each VN Fusion and Border • Route-leak VN subnets into
matching Border Global
configuration
Shared-Services Fusion-1 Fusion-2
Fusion
Fusion
Fusion
VN_Campus
VN_Guest
INFRA_VN
VN_Campus
VN_Campus
VN_IoT
VN_Guest
INFRA_VN
VN_Guest
INFRA_VN
VN_IoT
VN_IoT
Border
Border-1 Border-2
Border Border
• If Border / Fusion network device is Routing platform, L3 sub-interfaces will be used to extend Virtual Networks
• If Border / Fusion network device is Switching platform, VLANs & Trunk will be used to extend Virtual Networks
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
SD-Access Workflow
Fabric Infrastructure
Provision
Fabric Provision – Transit Site Fabric Provision Host Onboarding
Fabric Site Default Authentication Template
Address Pool Assignment
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Fusion Configuration
Step 1 - Extend
• Examine the below configs on the Fabric Border(s)
• show running-config | section vrf definition
• show running-config | section interface Vlan
• show running-config | section interface <interface>
(OR)
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Fusion Configuration
Step 1: Extend - Fusion Node Configuration
• Step 1.1 – configure VRF • Step 1.2 – configure interface
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Fusion Configuration
Step 4: iBGP – Border(s) Node Configuration
• Create iBGP session for every VN between Border nodes
Create Interface (vlan / sub-interface)
Configure iBGP session between Border Node
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Agenda
• Introduction
• Cisco SD-Access Design
• Architecture and Components
• Cisco SD-Access Deployment
• Installation – Cisco DNA Center
• Integration – ISE, IPAM
• Network Infrastructure – Underlay
• Cisco SD-Access Deployment (Live Demonstration)
Design Policy Provision
• Summary
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Secure onboarding of users and devices
Segmentation and Access Control
Challenges
Workgroups IoT devices Software-defined
segmentation
Automated policy
Mobile Applications
management
Single network fabric
Mergers
network changes
95% performed manually Routers Switches Wireless
#CLUS © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
SD-Access Resources
Would you like to know more?
cisco.com/go/dnacenter
cisco.com/go/sdaccess • Cisco DNA Center At-A-Glance
• SD-Access At-A-Glance • Cisco DNA ROI Calculator
• SD-Access Ordering Guide • Cisco DNA Center Data Sheet
• SD-Access Solution Data Sheet • Cisco DNA Center 'How To' Video
• SD-Access Solution White Paper Resources
cisco.com/go/dna
cisco.com/go/cvd
• SD-Access Design Guide
• SD-Access Deployment Guide
• SD-Access Segmentation Guide
• https://cs.co/en-cvds
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Published design guides
It is very good for us to hear all of your
feedback!
Look for the feedback link in the guides:
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Complete your
online session • Please complete your session survey
evaluation after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live water bottle.
• All surveys can be taken in the Cisco Live
Mobile App or by logging in to the Session
Catalog on ciscolive.cisco.com/us.
Cisco Live sessions will be available for viewing
on demand after the event at ciscolive.cisco.com.
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Continue your education
Demos in the
Walk-in labs
Cisco campus
#CLUS BRKCRS-1501 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Thank you
#CLUS
#CLUS