0% found this document useful (0 votes)
4 views105 pages

Module - 1 SDA Introduction

The document provides a comprehensive overview of Cisco's Software-Defined Access (SD-Access) and its key components, including the DNA Center and various workflows for design, policy, and provisioning. It details the roles of different nodes within the SD-Access fabric, such as edge, border, and control-plane nodes, as well as the integration with Cisco Identity Services Engine (ISE) for policy enforcement. Additionally, it outlines deployment strategies for ISE and the importance of network automation and assurance in managing access and security across wired and wireless networks.

Uploaded by

mofo1842
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views105 pages

Module - 1 SDA Introduction

The document provides a comprehensive overview of Cisco's Software-Defined Access (SD-Access) and its key components, including the DNA Center and various workflows for design, policy, and provisioning. It details the roles of different nodes within the SD-Access fabric, such as edge, border, and control-plane nodes, as well as the integration with Cisco Identity Services Engine (ISE) for policy enforcement. Additionally, it outlines deployment strategies for ISE and the importance of network automation and assurance in managing access and security across wired and wireless networks.

Uploaded by

mofo1842
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Cisco SD-Access

Deep Dive

Parthiban Manickam
CCSI # 35410
Module 1: Introduction to Cisco’s Software Module 3: DNA Center and Workflow for SD-
Defined Access (SD-Access) Access
SD-Access Overview Introduction to DNA Center
SD-Access Benefits Workflow for SD-Access in DNA Center
SD-Access Key Concepts Design Step overview
SD-Access Main Components Policy Step overview
Campus Fabric Provision Step overview
Wired Assurance Step overview
Wireless Integration with Cisco ISE for Policy Enforcement
Nodes
Edge
Border Module 4: DNA Center Workflow First Step –
Control Plane Design
DNA Controller
Creating Enterprise and Sites Hierarchy
ISE (Policy)
Discuss and Demonstrate General Network Settings
Module 2: SD-Access Campus Fabric Loading maps into the GUI
The concept of Fabric IP Address Administration
Node types Administering Software Images
Fabric Edge Nodes Network Device Profiles
Control Plane Nodes
Border Nodes
Module 5: DNA Center Workflow Second Step Module 7: Campus Fabric External
– Policy Connectivity for SD-Access
2-level Hierarchy Enterprise Sample Topology for SD-Access
Macro Level: Virtual Network (VN) Role of Border Nodes
Micro Level: Scalable Group (SG) Types of Border Nodes
Policy Types Border
Access Policy Default Border
Access Control Policy Single Border vs. Multiple Border Designs
Traffic Copy Policy
ISE Integration with DNA Center
Module 6: DNA Center Workflow Third Step -
Module 8: Implementing WLAN in SD-
Provision Access Solution
Devices Onboarding WLAN Integration Strategies in SD-Access Fabric
Discovering Devices •CUWN Wireless Over The Top (OTT)
Assigning Devices to a site •SD-Access Wireless (Fabric enabled WLC and AP)
Provisioning device with profiles SD-Access Wireless Architecture
Fabric Domains •Control Plane: LISP and WLC
Understanding Fabric Domains •Data Plane: VXLAN
Using Default LAN Fabric Domain •Policy Plane and Segmentation: VN and SGT
Creating Additional Fabric Domains Sample Design for SD-Access Wireless
Adding Nodes
Adding Fabric Edge Nodes
Adding Control Plane Nodes
Adding Border Nodes
Software Defined Access
Overview
• Software Defined Access Overview

• SD-Access Key Concepts

• Fabric Fundamentals

• Controller Fundamentals
Software Defined Access
Overview
Software Defined Access
Networking at the speed of Software!
Cisco DNA
Center
Identity-Based
Policy & Segmentation
Policy Automation Analytics
Decoupled security policy from
VLAN and IP Address

B B
C Outside Automated
Network Fabric
Single Fabric for Wired & Wireless
with workflow Automation

Insights
SDA
Extension
& Telemetry
User Mobility

Policy stays
Analytics and Insights into
with user User and Application behavior
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
IoT Network Employee Network
Cisco SD-Access  Network Automation – Simple GUI
Fabric Roles & Terminology and APIs for intent-based Automation
of wired and wireless fabric devices
Automation
Identity  Network Assurance – Data Collectors
Cisco ISE Cisco DNA Center
Services analyze Endpoint to Application flows
and monitor fabric network status
Assurance  Identity Services – NAC & ID Services
(e.g. ISE) for dynamic Endpoint to Group
mapping and Policy definition
Fabric Border IP Fabric Wireless
Nodes Controllers  Fabric Edge Nodes – A fabric device
B
(e.g. Access or Distribution) that connects
B
Wired Endpoints to the SD-Access fabric
Control- Plane
Intermediate Nodes  Fabric Border Nodes – A fabric
C
Nodes (Underlay) device (e.g. Core) that connects
External L3 network(s) to the SD-
Access fabric
SD-Access
Fabric Edge  Fabric Wireless Controller – A fabric device
Nodes Fabric Fabric Wireless
Access Points (WLC) that connects Fabric APs and
Wireless Endpoints to the SD-Access fabric

 Control-Plane Nodes – Map System that


manages Endpoint to Device relationships
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
DNA Solution DNA Center
Cisco Enterprise Portfolio
Simple Workflows

DESIGN PROVISION POLICY ASSURANCE

DNA Center
Identity Services Engine APIC-EM Network Data Platform

Routers Switches Wireless Controllers Wireless APs


SD-Access
DNA Center – Service Components

API DNA Center 1.0 API

Design | Provision | Policy | Assurance

API

Cisco ISE 2.3 API


Cisco APIC-EM 2.0 API
Cisco NDP 1.0
Identity Services Engine App Policy Infra Controller – EN Module Network Data Platform

NETCONF
SNMP
SSH

AAA
RADIUS
EAPoL
Campus Fabric HTTPS
NetFlow
Syslogs

Cisco Switches | Cisco Routers | Cisco Wireless


© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco
ISE
Understand the Business Objectives
What is the business trying to accomplish with ISE?

Cisco ISE can reach deep into the network to deliver superior visibility into who and what is
Asset Visibility accessing resources.

Consistent access control across wired, wireless and VPN Networks. 802.1X, MAC, Web
Access Control Authentication and Easy connect for admission control.

Fully customizable branded mobile and desktop guest portals, with dynamic visual workflows to
Guest Access easily manage guest user experience.

Simplified BYOD management with built-in CA and 3rd party MDM integration for on boarding
BYOD Access and self-service of personal mobile devices

Segmentation Topology independent Software-defined segmentation policy to contain network threats.

Context sharing with partner eco-system to improve their overall efficacy and accelerate time
Context Exchange to containment of network threats.

Protection against threats across the attack continuum, before, during and after an attack.
Threat Control Reduce time-to-detection from days to hours.

Cisco ISE supports device administration using the TACACS+ security protocol to control and
Device Admin audit the configuration of network devices
Cisco ISE and Anyconnect
Cisco ISE CISCO ISE SIEM, MDM, NBA, IPS, IPAM, etc.
WHO WHEN
Context aware policy service, to WHAT WHERE PxGRID
control access and threat across & APIs
wired, wireless and VPN HOW HEALTH
networks THREATS CVSS
Partner Eco System
ACCESS POLICY

Dot 1x FOR ENDPOINTS FOR NETWORK


WIRED WIRELESS VPN
Supplicant for wired and wireless
access. Services

Cisco Anyconnect
Supplicant for wired, wireless
and VPN access. Services
include: Posture assessment,
Malware protection, Web Role-based Access Control | Guest Access | BYOD | Secure Access
security, MAC Security, Network
visibility and more.
Nodes and Personas
 Policy Administration Node (PAN)
– Interface to configure policies and manage ISE deployment
– Writeable access to the database
Can run in a
 Monitoring & Troubleshooting Node (MnT)
– Interface to reporting and logging
single host
– Destination for syslog from other ISE nodes and NADs

 Policy Service Node (PSN)


– Makes policy decisions
– RADIUS server & provides endpoint/user services

 pxGrid Controller
#CLMEL

– Facilitates sharing of information between network systems


– Context In/Context-Out information exchange
Policy Synchronization
• Changes made via Primary PAN DB are automatically synced to
Secondary PAN and all PSNs. PAN
(Secondary)

PSN
Policy Sync

Policy Change Policy Sync


Admin PSN
User
PAN
(Primary)
PSN
• Guest account creation
Policy Sync
• Device Profile update

PSN
ISE Design and Deployment Terms
• Persona Deployment
Standalone = All personas (Admin/MnT/pxGrid/Policy Service) located on same node
Distributed = Separation of one or more personas on different nodes

• Topological Deployment
Centralized = All nodes located in the same LAN/campus network
Distributed = One or more nodes located in different LANs/campus networks
separated by a WAN 20
Standalone Deployment
All Personas on a Single Node: PAN, PSN, MnT, pxGrid

• Maximum sessions – Platform dependent


 7,500 for 3515
ISE Node
 10,000 for 3615
 20,000 for 3595 Policy Administration Node
 25,000 for 3655
 50,000 for 3695 Monitoring and Troubleshooting Node

Policy Service Node


21

pxGrid Node
Basic 2-Node ISE Deployment (Redundant)
• Maximum sessions– 50,000 (platform dependent—same as standalone)
• Redundant sizing – 50,000 (platform dependent—same as standalone)

ISE Node ISE Node


Primary Secondary
Admin Admin

Primary Secondary
Monitoring Monitoring

22

Primary Secondary
pxGrid pxGrid
Controller Controller
Basic 2-Node ISE Deployment (Redundant)
Maximum Sessions = 50,000 (Platform dependent) Centralized

Admin (P) PXG PXG


Admin (S)
MnT (P) MnT (S)
PSN PSN

• All Services run on both ISE Nodes


AD/LDAP
(External ID/ • Set one for Primary Admin / Primary MnT
Attribute Store) • Set other for Secondary Monitoring / Secondary Admin
Campus A
• Max Sessions is platform dependent:
ASA VPN • 3515 = Max 7.5k sessions
w/ CoA
• 3615 = Max 10k sessions
WLC • 3595 = Max 20k sessions
802.1X Switch
AP 802.1X • 3655 = Max 25k sessions
• 3695 = Max 50k sessions
23

Branch B
Branch A

Switch Switch
AP 802.1X AP 802.1X
Hybrid-Distributed Deployment
Admin + MnT on Same Appliance; Policy Service on Dedicated
Appliance

• 2 x Admin+Monitor+pxGRID
PAN PAN
• Max 5 PSNs MnT
MnT
• Optional: Dedicate 2 of the 5 for pxGrid PXG PXG

• Max sessions – Platform dependent


 7,500 for 3515 as PAN+MnT
 10,000 for 3615 as PAN+MnT
24

 20,000 for 3595 as PAN+MNT PSN PSN PSN PSN PSN


 25,000 for 3655 as PAN+MnT
 50,000 for 3695 as PAN+MnT
Dedicated-Distributed Persona Deployment
Dedicated Appliance for Each Persona: Admin, Monitoring, pxGrid, Policy
• 2 x Admin and 2 x Monitoring and up to 4 x pxGrid
Optional
• Max PSNs (Platform dependent)
 50 using 3595/3655/3695 as PAN and MnT
• Max sessions (Platform dependent) PAN MnT PXG
 500k using 3595/3655/3695 as PAN and MnT
 2M - 3695 as PAN/MNT on ISE 2.6 (DOT1X/MAB
only)

25

PSNs
Putting It All Together…
Network Access Device Monitoring and Policy Service Node Policy Administration
Access-Layer Devices Troubleshooting The “Work-Horse”: RADIUS, Node: All Management UI Admin
Enforcement Point for all Logging and Profiling, WebAuth, Posture, Activities & synchronizing
Policy Reporting Data Sponsor Portal Client all ISE Nodes
Provisioning
NAD MnT PSN PAN PXG

Policy Sync
RADIUS from NAD to PSN Platform
eXchange Grid
Node: Share
RADIUS response from PSN to NAD
#CLMEL
PSN queries context in/out
User external database
RADIUS Accounting directly
Publish
syslog Config
Publish Sessions
ISE Node Communication
SD-Access Components

Cisco APIC-EM + Cisco


ISE NDP
SD-Access Fabric: Roles

Control-Plane Node

Edge Node

Fabric Border Node

Default Border Node

Fabric-Enabled WLC
SD-Access Fabric: Edge Nodes
SD-Access Fabric
Edge Nodes – A Closer Look

Edge Node provides first-hop services for Users / Devices connected to a Fabric
IP to RLOC M A C to RLOC Address Resolution
[Link]/32  FE1 AA:BB:CC:DD  FE1 [Link]  AA:BB:CC:DD

• Responsible for Identifying and Authenticating C


Endpoints (e.g. Static, 802.1X, Active Directory)
B B
• Register specific Endpoint ID info (e.g. /32 or /128)
with the Control-Plane Node(s)

• Provide an Anycast L3 Gateway for the connected


Endpoints (same IP address on all Edge nodes) 33

• Performs encapsulation / de- encapsulation of data FE1

traffic to and from all connected Endpoints IP - [Link]/32


MAC – AA:BB:CC:DD
SD-Access Fabric: Edge Nodes Platform
Support
SD-Access Fabric: Border Nodes
SD-Access Fabric
Border Nodes
Border Node is an Entry & Exit point for data traffic going Into & Out of a Fabric

There are 3 Types of Border Node!

• Internal Border (Rest of Company)


• connects ONLY to the known areas of the company

• External Border (Outside)


• connects ONLY to unknown areas outside the company
36

• Internal + External (Anywhere)


• connects transit areas AN D known areas of the company
SD-Access Fabric
Border Nodes - Internal

Internal Border advertises Endpoints to outside, and known Subnets to inside


IP to RLOC
[Link]/24  FB1
IP - [Link]/24
• Connects to any “known” IP subnets available from C
the outside network (e.g. DC, WLC, FW, etc.) Known
Networks
Unknown
Networks

B B
FB1
• Exports all internal IP Pools to outside (as aggregate),
using a traditional IP routing protocol(s).

• Imports and registers (known) IP subnets from


outside, into the Control-Plane Map System

• Hand- off requires mapping the context (VRF & S GT)


from one domain to another. IP - [Link]/32
MAC – AA:BB:CC:DD
SD-Access Fabric
Border Nodes - External

External Border is a “Gateway of Last Resort” for any unknown destinations


IP to RLOC
? ? ?  FB2
IP - [Link]/32
• Connects to any “unknown” IP subnets, outside of C
the network (e.g. Internet, Public Cloud) Known
Networks
Unknown
Networks

B B
• Exports all internal IP Pools outside (as aggregate) FB2

into traditional IP routing protocol(s).

• Does NOT import unknown routes! It is a “default”


exit, if no entry is available in C ontrol- Plane. 38

• Hand- off requires mapping the context (VRF & S GT)


from one domain to another. IP - [Link]/32
MAC – AA:BB:CC:DD
SD-Access Fabric: Border Node Platform
Support
SD-Access Fabric: Control-Plane Nodes
SD-Access Fabric
Control-Plane Nodes – A Closer Look

Control-Plane Node runs a Host Tracking Database to map location information


IP to RLOC M A C to RLOC Address Resolution
[Link]/32  FE1 AA:BB:CC:DD  FE1 [Link]  AA:BB:CC:DD

• A simple Host Database that maps Endpoint IDs to its C


current Location, along with other attributes
B B
• Host Database supports multiple types of Endpoint ID
lookup types (IPv4, IPv6 or MAC)

• Receives Endpoint ID map registrations from Edge


and/or Border Nodes for “known” IP prefixes RLOC- Loopback0 IP Address

• Resolves lookup requests from Edge and/or Border FE1

Nodes, to locate destination Endpoint IDs IP - [Link]/32


MAC – AA:BB:CC:DD
SD-Access Fabric: Control-Plane Platform
Support
SD-Access Fabric
Fabric Enabled Wireless – A Closer Look

Fabric Enabled WLC is integrated into Fabric for S D - A c c e s s Wireless clients


Ctrl: C A PWA P
MAC – AA:BB:CC:DD
Data: VXLA N

• Connects to Fabric via Border (Underlay) C


Known Unknown

• Fabric Enabled APs connect to the WLC (CAPWAP) Networks Networks

B B
using a dedicated Host Pool (Overlay)

• Fabric Enabled APs connect to the Edge via VXLAN

• Wireless Clients (SSIDs) use regular Host Pools for 53

data traffic and policy (same as Wired)


IP - [Link]/32
• Fabric Enabled WLC registers Clients with the
Control-Plane (as located on local Edge + AP)
SD-Access Fabric: Fabric-Enabled WLC
Platform Support
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Fabric Site
A Closer Look

Fabric sites are an independent fabric area with a unique set of network devices

CP
• Contains Control Plane Node, Border Node, and Edge Node Control Plane Node

• Contains WLC and ISE Policy Service Node (PSN) BN


Border Node

• Fabric Border Node is the ingress and egress device for the FE
site DHCP/DNS Edge Node ISE

• A Fabric Site may cover a single physical location, multiple © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66

locations, or just a subset of a location Fabric WLC


• Single Location  Branch, Campus, or Metro Campus
• Multiple Locations  Metro Campus + Multiple Branches Fabric Site
• Subset of a Location  Building or Area within a Campus
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Fabric Domain
A Closer Look

Fabric Domains are an Administrative Construct


Fabric Domain
Known and
Unknown

AB
Known Unknown
• Consist of one or more fabric sites and IB EB

associated transits CP CP
Fabric Site
FE FE FE
• Cisco DNA Center GUI construct

• Used to create an administrative grouping of Known and Known and


Unknown
multiple fabric sites
Unknown

AB AB
Known Known Unknown
Unknown EB
IB EB IB

CP CP CP CP
Fabric Site Fabric Site
FE FE FE FE FE FE

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Fabric Domain
A Closer Look

Transit
CP
CP

BN
BN

BN BN Fabric Site 2
Fabric Site 1

Fabric Domain

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SD-Access Fabric
Architecture
DHCP in an anycast Gateway environment
Anycast GW provides a single L3 Default Gateway for IP capable endpoints

• The same Switch Virtual Interface (SVI) is present C


on EVERY Edge with the SAME Virtual IP and MAC Known Unknown
Networks Networks

B B
• When a Host moves from Edge 1 to Edge 2, it does
not need to change its Default Gateway 

• The SVI is also configured with an IP helper address


for DHCP.

GW GW GW GW GW

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
4
SD-Access Fabric Architecture
DHCP in an anycast Gateway environment

DHCP reply needs to come to the right edge node switch.

• But “we do not know on which edge node a host is C


located” as we don’t have an IP address for it yet. Known Unknown
Networks Networks

B B
• Once an IP address is assigned to the host, the
control plane node learns where the host is located.

• The Control-Plane maintains the Host to Edge


relationship (Fabric Dynamic EID mapping)

GW GW GW GW GW

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
5
SD-Access Fabric Architecture
DHCP in Fabric – Enable LISP lookups for DHCP
requests
[Link]/24 [Link]/32 [Link]/32 [Link]/24

IP Network
[Link]/24 [Link]

Host Pool 10 Edge Node 1 Border and Shared Services


Control Plane (DHCP Server)
Node
• The Edge node needs to be
router lisp
configured as a “proxy-itr” to avoid
instance-id 4098
source EID validation. The source of dynamic-eid user
the DHCP request doesn’t have an database-mapping [Link]/24 locator-set edge1
IP address yet. exit-dynamic-eid
!
• We also need a 0/0 map-cache service ipv4
eid-table vrf User
that triggers a LISP lookup for the
map-cache [Link]/0 map-request
DHCP helper address so that the itr map-resolver [Link]
DHCP request is sent in the overlay. proxy-itr [Link]
etr map-server [Link] key uci
etr
use-petr [Link]
exit-service-ipv4
!
exit-instance-id
!
exit-router-lisp

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
6
SD-Access Fabric
Architecture
DHCP in Fabric – Option 82 plus Snooping

[Link]/24 [Link]/32 [Link]/32 [Link]/24

IP Network
[Link]/24 [Link]

Host Pool 10 Edge Node 1 Border and Shared Services


Control Plane (DHCP Server)
Node
• The Edge node needs to enable option 82 in
ip dhcp relay information option
the DHCP request.
ip dhcp snooping vlan 1022
• Option 82 will carry the VNID and ip dhcp snooping
RLOC.
interface Vlan1022
ip vrf forwarding User
ip address [Link] [Link]
• DHCP snooping needs to be enabled on all ip helper-address [Link]
lisp mobility user
the VLANs in fabric.

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
SD-Access Fabric Architecture
DHCP in Fabric – “Pre-advertise” IP pools outside the
fabric
[Link]/24 [Link]/32 [Link]/32 [Link]/24

IP Network
[Link]/24 [Link]

Host Pool 10 Edge Node 1 Border and Shared Services


Control Plane (DHCP Server)
• The Border will only advertise the “Aggregate Node
route([Link]/24) when there is a more
specific prefix(host route)for that subnet in RIB” router bgp 65002
bgp log-neighbor-changes
!
address-family ipv4 vrf USER
• For the DHCP server to send the DHCP reply aggregate-address [Link] [Link] summary-only
back we need a route to [Link]/24 at the redistribute lisp metric 10
DCHP server side. neighbor x.x.x.x remote-as xxxxx
exit-address-family

interface Loopback1022
• This will not happen until we have a HOST in vrf forwarding User
the subnet [Link]/24 registered with LISP ip address [Link] [Link]
HTDB. This needs DHCP to happen first.

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
8
SD-Access Fabric Architecture
DHCP in Fabric – Include RLOC in DHCP request
Option 82:
-VNID
[Link]/24
E
• Unicast DHCP request sent to Border with Option 82/Circuit ID
• Option 82 = “[Link]”(RLOC loopback) and “10”VN-ID B 3 -RLOC for Relaying xTR
• Set in DHCP request GIADDR= [Link] ( SVI address)

2 DHCP request
C sent to server through
fusion router
1 DHCP
Request B
DHCP [Link]
SERVER
Fusion Router
Shared Services
[Link]

[Link] [Link]

SVI SVI
[Link] [Link]
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
9
SD-Access Fabric
Architecture
DHCP in Fabric – DHCP Reply
E B 4

DHCP reply is sent to GIADDR-[Link] via border


C Option 82 ”reflected” back unaltered

B
DHCP [Link]
SERVER
Fusion Router
Shared Services
[Link]

[Link] [Link] Option 82:


VNID + RLOC

SVI SVI
[Link] [Link]

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
0
SD-Access Fabric
Architecture
DHCP in Fabric – Snoop and encapsulate DHCP reply at the Border

E Encapsulate DHCP B 5
Snoop Option 82:
Reply to Snooped VNID + RLOC
RLOC/VNID
C • DHCP reply comes to the Border
where it is punted to CPU.

B • Relay xTR RLOC + VNI is extracted


from Option82 / Circuit ID

• Border encapsulates DHCP reply in


[Link]
VXLAN with destination RLOC =
[Link] and VNI = 10

[Link] [Link]

SVI SVI
[Link] [Link]

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
1
SD-Access Fabric
Architecture
DHCP in Fabric – Complete DHCP reply
[Link]/24 DHPC reply sent from Border to Edge switch
E with VNI=10 to RLOC =[Link]
B

6
C
7 DHCP
Reply B
DHCP [Link]
SERVER
Fusion Router
Shared Services
[Link]

[Link] [Link]

SVI SVI
[Link] [Link]

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
2
SD-Access Fabric: Constructs

Virtual Network

Scalable Group

Host Pool

Anycast GW

Stretched Subnets

Layer 2 Overlays
SD-Access
Fabric
How VNs work in SD-Access ip vrf USERS
rd 1:4099
route-target export 1:4099
route-target import 1:4099

SD-Access Designs connecting to existing Global Routing Table !


route-target import

ip vrf DEFAULT_VN
1:4097

should use a “Fusion” router with MP-BGP & VRF import/export. rd 1:4098
route-target export 1:4098
route-target import 1:4098
route-target import 1:4097

ip vrf GLOBAL
Control Plane rd 1:4097
route-target export 1:4097

C route-target
route-target
import
export
1:4097
1:4099
VRF B route-target export 1:4098
T5/1
SVI B
SVI B AF VRF B G0/0/0.B
ISIS BGP
GRT
T5/2
B SVI A
AF VRF A G0/0/0.A

T5/8 G0/0/0 G0/0/3


T1/0/1 T5/1
AF IPv4
MP-BGP
Edge Node Border Node Fusion Router Switch
VRF A Shared
SVI A Services

BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
SD-Access
Fabric
Virtual Network– A Closer Look
Virtual Network maintains a separate Routing & Switching table for each instance

• Control-Plane uses Instance ID to maintain separate C


VRF topologies (“Default” VRF is Instance ID “4098”) Known
Networks
Unknown
Networks

B B
• Nodes add a VNID to the Fabric encapsulation

• Endpoint ID prefixes (Host Pools) are routed and VN VN VN


advertised within a Virtual Network Campus IOT Gues t

• Uses standard “vrf definition” configuration, along with


RD & RT for remote advertisement (Border Node)

#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
SD-Access Fabric: Virtual Network
SD-Access Policy
Two Level Hierarchy - Macro Level

Known Unknown
Networks Networks

VN
“A”
VN
“B”
VN
“C”
SD- Access
Fabric
Virtual Network (VN)
First level Segmentation ensures zero
communication between forwarding
domains. Ability to consolidate multiple
networks into one management plane.

Building Management Campus Users


VN VN

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
SD-Access
Fabric
How VNs work in SD-Access

• Fabric Devices (Underlay) connectivity


is in the Global Routing Table
Scope of Fabric

• INFRA_VN is only for Access Points User-Defined VN(s)


and Extended Nodes in GRT
User VN (for Default)
Border
• DEFAULT_VN is an actual “User VN”
provided by default VN (for APs, Extended Nodes)
USER VRF(s)
DEFAULT_VN

User-Defined VNs can be added or


INFRA_VN

Devices (Underlay) GRT
removed on-demand 88
SD-Access Policy
Two Level Hierarchy - Micro Level

Known Unknown
Networks Networks

SD-Access
SG
SG
1
SG SG
SG
4
SG SG
SG
7
SG
Fabric
Scalable Group (SG)
2 3 5 6 8 9

Second level Segmentation ensures


role based access control between
two groups within a Virtual Network.
Provides the ability to segment the
network into either line of businesses
or functional blocks.

Building Management Campus Users


VN VN

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
SD-Access Fabric
Scalable Groups – A Closer Look

Scalable Group is a logical policy object to “group” Users and/or Devices

• Nodes use “Scalable Groups” to ID and assign a C


unique Scalable Group Tag (SGT) to Endpoints Known Unknown
Networks Networks

B B
• Nodes add a SGT to the Fabric encapsulation
SGT
SGT
• SGTs are used to manage address-independent SGT
17
4 SGT
8 25
SGT
“Group-Based Policies” SGT SGT
SGT 19 SGT
3 11 12
23

• Edge or Border Nodes use SGT to enforce local


Scalable Group ACLs (SGACLs)

90
SD-Access Fabric: Scalable Group
SD-Access @ Cisco DNA Center
Scalable Groups
SD-Access Fabric
Host Pools – A Closer Look

Host Pool provides basic IP functions necessary for attached Endpoints

• Edge Nodes use a Switch Virtual Interface (SVI), with C


IP Address /Mask, etc. per Host Pool Known
Networks
Unknown
Networks

B B
• Fabric uses Dynamic EID mapping to advertise each
Host Pool (per Instance ID) Pool
Pool
Pool .4 Pool
.17 .8 .25
Pool
• Fabric Dynamic EID allows Host-specific (/32, /128 Pool Pool Pool .19 Pool
.13 .11 .12
or MAC) advertisement and mobility .23

• Host Pools can be assigned Dynamically (via Host


Authentication) and/or Statically (per port)

93
SD-Access Fabric
Anycast Gateway – A Closer Look

Anycast GW provides a single L3 Default Gateway for IP capable endpoints

C
• Similar principle and behavior to HSRP /VRRP with a Known Unknown
shared “Virtual” IP and M A C address Networks Networks

B B
• The same Switch Virtual Interface (SVI) is present on
EVERY Edge with the SAME Virtual IP and M A C

• Control-Plane with Fabric Dynamic EID mapping


maintains the Host to Edge relationship

• When a Host moves from Edge 1 to Edge 2, it does GW GW GW GW GW

not need to change its Default Gateway  [Link]/24 [Link]/24 [Link]/24 [Link]/24 [Link]/24

94
SD-Access Fabric
Layer 3 Overlay – A Closer Look

Stretched Subnets allow an IP subnet to be “stretched” via the Overlay

• Host IP based traffic arrives on the local Fabric Edge C


(SVI) and is then transferred by the Fabric
Known Unknown
Networks Networks

B B
• Fabric Dynamic EID mapping allows Host-specific
(/32, /128, MAC) advertisement and mobility
Dynamic
EID
• Host 1 connected to Edge A can now use the same
IP subnet to communicate with Host 2 on Edge B

• No longer need a VLAN to connect Host 1 and 2  GW GW GW GW GW

95
SD-Access @ Cisco DNA Center
Host Pools & Layer- 2 Extension

96
Fabric Edge @ CLI
VN & Pool C onfiguration
Edge-1# show vrf
Name Default RD Protocols Interfaces
DEFAULT_VN 1:4098 ipv4 LI0.4098
GUEST 1:4100 ipv4 LI0.4100
Mgmt-vrf <not set> ipv4,ipv6 Gi0/0
USERS 1:4099 ipv4 LI0.4099
Vl1021
Edge-1# show interface vlan1021
Building configuration...
Current configuration : 315 bytes
!
interface Vlan1021
description Configured from apic-em
mac-address 0000.0c9f.f45c
vrf forwarding USERS
ip address [Link] [Link]
ip helper-address [Link]
no ip redirects
ip local-proxy-arp
ip route-cache same-interface
no lisp mobility liveness test
lisp mobility 10_111_0_0-USERS

#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Fabric Edge & CP @
CLI Registration
Endpoint

CP_Border-1# show lisp site instance 4099


LISP Site Registration Information
* = Some locators are down or unreachable
# = Some registrations are sourced by reliable transport
Site Name Last Up Who Last Inst EID Prefix
Register Registered ID
site_sda never no -- 4099 [Link]/0
17:32:21 yes# [Link] 4099 [Link]/16
01:40:00 yes# [Link] 4099 [Link]/32

Edge-1# show lisp instance 4099 dynamic-eid summary


LISP Dynamic EID Summary for VRF "USERS"
^ = Dyn-EID learned by EID Notify
* = Dyn-EID learned by Site-Based Map-Notify
Dyn-EID Name Dynamic-EID Interface Uptime Last Pending
Packet Ping Count
10_111_0_0-USERS [Link] Vl1021 01:38:42 01:38:42 0

#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
SD-Access Fabric
Layer 2 Overlay – A Closer Look

Layer 2 Overlay allows Non-IP endpoints to use Broadcast & L2 Multicast

• Similar principle and behavior as Virtual Private LAN C


Services (VPLS) P2MP Overlay Known Unknown
Networks Networks

B B
• Uses a pre-built Multicast Underlay to setup a P2MP
tunnel between all Fabric Nodes.
L2
Overlay
• L2 Broadcast and Multicast traffic will be distributed
to all connected Fabric Nodes.
VLAN VLAN VLAN
• Can be enabled for specific Host Pools that require
L2 services (use Stretched Subnets for L3)
NOTE: L3 Integrated Routing and Bridging (IRB) is not supported at this time.

#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
SD-Access @ Cisco DNA
Center
Layer-2 Flooding

#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
0
Controller Fundamentals
ISE and DNA Center Integration
Cisco® pxGrid
NDP and DNA Center Interaction

You might also like