Module - 1 SDA Introduction
Module - 1 SDA Introduction
Deep Dive
Parthiban Manickam
CCSI # 35410
Module 1: Introduction to Cisco’s Software Module 3: DNA Center and Workflow for SD-
Defined Access (SD-Access) Access
SD-Access Overview Introduction to DNA Center
SD-Access Benefits Workflow for SD-Access in DNA Center
SD-Access Key Concepts Design Step overview
SD-Access Main Components Policy Step overview
Campus Fabric Provision Step overview
Wired Assurance Step overview
Wireless Integration with Cisco ISE for Policy Enforcement
Nodes
Edge
Border Module 4: DNA Center Workflow First Step –
Control Plane Design
DNA Controller
Creating Enterprise and Sites Hierarchy
ISE (Policy)
Discuss and Demonstrate General Network Settings
Module 2: SD-Access Campus Fabric Loading maps into the GUI
The concept of Fabric IP Address Administration
Node types Administering Software Images
Fabric Edge Nodes Network Device Profiles
Control Plane Nodes
Border Nodes
Module 5: DNA Center Workflow Second Step Module 7: Campus Fabric External
– Policy Connectivity for SD-Access
2-level Hierarchy Enterprise Sample Topology for SD-Access
Macro Level: Virtual Network (VN) Role of Border Nodes
Micro Level: Scalable Group (SG) Types of Border Nodes
Policy Types Border
Access Policy Default Border
Access Control Policy Single Border vs. Multiple Border Designs
Traffic Copy Policy
ISE Integration with DNA Center
Module 6: DNA Center Workflow Third Step -
Module 8: Implementing WLAN in SD-
Provision Access Solution
Devices Onboarding WLAN Integration Strategies in SD-Access Fabric
Discovering Devices •CUWN Wireless Over The Top (OTT)
Assigning Devices to a site •SD-Access Wireless (Fabric enabled WLC and AP)
Provisioning device with profiles SD-Access Wireless Architecture
Fabric Domains •Control Plane: LISP and WLC
Understanding Fabric Domains •Data Plane: VXLAN
Using Default LAN Fabric Domain •Policy Plane and Segmentation: VN and SGT
Creating Additional Fabric Domains Sample Design for SD-Access Wireless
Adding Nodes
Adding Fabric Edge Nodes
Adding Control Plane Nodes
Adding Border Nodes
Software Defined Access
Overview
• Software Defined Access Overview
• Fabric Fundamentals
• Controller Fundamentals
Software Defined Access
Overview
Software Defined Access
Networking at the speed of Software!
Cisco DNA
Center
Identity-Based
Policy & Segmentation
Policy Automation Analytics
Decoupled security policy from
VLAN and IP Address
B B
C Outside Automated
Network Fabric
Single Fabric for Wired & Wireless
with workflow Automation
Insights
SDA
Extension
& Telemetry
User Mobility
Policy stays
Analytics and Insights into
with user User and Application behavior
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
IoT Network Employee Network
Cisco SD-Access Network Automation – Simple GUI
Fabric Roles & Terminology and APIs for intent-based Automation
of wired and wireless fabric devices
Automation
Identity Network Assurance – Data Collectors
Cisco ISE Cisco DNA Center
Services analyze Endpoint to Application flows
and monitor fabric network status
Assurance Identity Services – NAC & ID Services
(e.g. ISE) for dynamic Endpoint to Group
mapping and Policy definition
Fabric Border IP Fabric Wireless
Nodes Controllers Fabric Edge Nodes – A fabric device
B
(e.g. Access or Distribution) that connects
B
Wired Endpoints to the SD-Access fabric
Control- Plane
Intermediate Nodes Fabric Border Nodes – A fabric
C
Nodes (Underlay) device (e.g. Core) that connects
External L3 network(s) to the SD-
Access fabric
SD-Access
Fabric Edge Fabric Wireless Controller – A fabric device
Nodes Fabric Fabric Wireless
Access Points (WLC) that connects Fabric APs and
Wireless Endpoints to the SD-Access fabric
DNA Center
Identity Services Engine APIC-EM Network Data Platform
API
NETCONF
SNMP
SSH
AAA
RADIUS
EAPoL
Campus Fabric HTTPS
NetFlow
Syslogs
Cisco ISE can reach deep into the network to deliver superior visibility into who and what is
Asset Visibility accessing resources.
Consistent access control across wired, wireless and VPN Networks. 802.1X, MAC, Web
Access Control Authentication and Easy connect for admission control.
Fully customizable branded mobile and desktop guest portals, with dynamic visual workflows to
Guest Access easily manage guest user experience.
Simplified BYOD management with built-in CA and 3rd party MDM integration for on boarding
BYOD Access and self-service of personal mobile devices
Context sharing with partner eco-system to improve their overall efficacy and accelerate time
Context Exchange to containment of network threats.
Protection against threats across the attack continuum, before, during and after an attack.
Threat Control Reduce time-to-detection from days to hours.
Cisco ISE supports device administration using the TACACS+ security protocol to control and
Device Admin audit the configuration of network devices
Cisco ISE and Anyconnect
Cisco ISE CISCO ISE SIEM, MDM, NBA, IPS, IPAM, etc.
WHO WHEN
Context aware policy service, to WHAT WHERE PxGRID
control access and threat across & APIs
wired, wireless and VPN HOW HEALTH
networks THREATS CVSS
Partner Eco System
ACCESS POLICY
Cisco Anyconnect
Supplicant for wired, wireless
and VPN access. Services
include: Posture assessment,
Malware protection, Web Role-based Access Control | Guest Access | BYOD | Secure Access
security, MAC Security, Network
visibility and more.
Nodes and Personas
Policy Administration Node (PAN)
– Interface to configure policies and manage ISE deployment
– Writeable access to the database
Can run in a
Monitoring & Troubleshooting Node (MnT)
– Interface to reporting and logging
single host
– Destination for syslog from other ISE nodes and NADs
pxGrid Controller
#CLMEL
PSN
Policy Sync
PSN
ISE Design and Deployment Terms
• Persona Deployment
Standalone = All personas (Admin/MnT/pxGrid/Policy Service) located on same node
Distributed = Separation of one or more personas on different nodes
• Topological Deployment
Centralized = All nodes located in the same LAN/campus network
Distributed = One or more nodes located in different LANs/campus networks
separated by a WAN 20
Standalone Deployment
All Personas on a Single Node: PAN, PSN, MnT, pxGrid
pxGrid Node
Basic 2-Node ISE Deployment (Redundant)
• Maximum sessions– 50,000 (platform dependent—same as standalone)
• Redundant sizing – 50,000 (platform dependent—same as standalone)
Primary Secondary
Monitoring Monitoring
22
Primary Secondary
pxGrid pxGrid
Controller Controller
Basic 2-Node ISE Deployment (Redundant)
Maximum Sessions = 50,000 (Platform dependent) Centralized
Branch B
Branch A
Switch Switch
AP 802.1X AP 802.1X
Hybrid-Distributed Deployment
Admin + MnT on Same Appliance; Policy Service on Dedicated
Appliance
• 2 x Admin+Monitor+pxGRID
PAN PAN
• Max 5 PSNs MnT
MnT
• Optional: Dedicate 2 of the 5 for pxGrid PXG PXG
25
PSNs
Putting It All Together…
Network Access Device Monitoring and Policy Service Node Policy Administration
Access-Layer Devices Troubleshooting The “Work-Horse”: RADIUS, Node: All Management UI Admin
Enforcement Point for all Logging and Profiling, WebAuth, Posture, Activities & synchronizing
Policy Reporting Data Sponsor Portal Client all ISE Nodes
Provisioning
NAD MnT PSN PAN PXG
Policy Sync
RADIUS from NAD to PSN Platform
eXchange Grid
Node: Share
RADIUS response from PSN to NAD
#CLMEL
PSN queries context in/out
User external database
RADIUS Accounting directly
Publish
syslog Config
Publish Sessions
ISE Node Communication
SD-Access Components
Control-Plane Node
Edge Node
Fabric-Enabled WLC
SD-Access Fabric: Edge Nodes
SD-Access Fabric
Edge Nodes – A Closer Look
Edge Node provides first-hop services for Users / Devices connected to a Fabric
IP to RLOC M A C to RLOC Address Resolution
[Link]/32 FE1 AA:BB:CC:DD FE1 [Link] AA:BB:CC:DD
B B
FB1
• Exports all internal IP Pools to outside (as aggregate),
using a traditional IP routing protocol(s).
B B
• Exports all internal IP Pools outside (as aggregate) FB2
B B
using a dedicated Host Pool (Overlay)
Fabric sites are an independent fabric area with a unique set of network devices
CP
• Contains Control Plane Node, Border Node, and Edge Node Control Plane Node
• Fabric Border Node is the ingress and egress device for the FE
site DHCP/DNS Edge Node ISE
• A Fabric Site may cover a single physical location, multiple © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
AB
Known Unknown
• Consist of one or more fabric sites and IB EB
associated transits CP CP
Fabric Site
FE FE FE
• Cisco DNA Center GUI construct
AB AB
Known Known Unknown
Unknown EB
IB EB IB
CP CP CP CP
Fabric Site Fabric Site
FE FE FE FE FE FE
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Fabric Domain
A Closer Look
Transit
CP
CP
BN
BN
BN BN Fabric Site 2
Fabric Site 1
Fabric Domain
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
SD-Access Fabric
Architecture
DHCP in an anycast Gateway environment
Anycast GW provides a single L3 Default Gateway for IP capable endpoints
B B
• When a Host moves from Edge 1 to Edge 2, it does
not need to change its Default Gateway
GW GW GW GW GW
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
4
SD-Access Fabric Architecture
DHCP in an anycast Gateway environment
B B
• Once an IP address is assigned to the host, the
control plane node learns where the host is located.
GW GW GW GW GW
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
5
SD-Access Fabric Architecture
DHCP in Fabric – Enable LISP lookups for DHCP
requests
[Link]/24 [Link]/32 [Link]/32 [Link]/24
IP Network
[Link]/24 [Link]
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
6
SD-Access Fabric
Architecture
DHCP in Fabric – Option 82 plus Snooping
IP Network
[Link]/24 [Link]
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
SD-Access Fabric Architecture
DHCP in Fabric – “Pre-advertise” IP pools outside the
fabric
[Link]/24 [Link]/32 [Link]/32 [Link]/24
IP Network
[Link]/24 [Link]
interface Loopback1022
• This will not happen until we have a HOST in vrf forwarding User
the subnet [Link]/24 registered with LISP ip address [Link] [Link]
HTDB. This needs DHCP to happen first.
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
8
SD-Access Fabric Architecture
DHCP in Fabric – Include RLOC in DHCP request
Option 82:
-VNID
[Link]/24
E
• Unicast DHCP request sent to Border with Option 82/Circuit ID
• Option 82 = “[Link]”(RLOC loopback) and “10”VN-ID B 3 -RLOC for Relaying xTR
• Set in DHCP request GIADDR= [Link] ( SVI address)
2 DHCP request
C sent to server through
fusion router
1 DHCP
Request B
DHCP [Link]
SERVER
Fusion Router
Shared Services
[Link]
[Link] [Link]
SVI SVI
[Link] [Link]
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
9
SD-Access Fabric
Architecture
DHCP in Fabric – DHCP Reply
E B 4
B
DHCP [Link]
SERVER
Fusion Router
Shared Services
[Link]
SVI SVI
[Link] [Link]
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
0
SD-Access Fabric
Architecture
DHCP in Fabric – Snoop and encapsulate DHCP reply at the Border
E Encapsulate DHCP B 5
Snoop Option 82:
Reply to Snooped VNID + RLOC
RLOC/VNID
C • DHCP reply comes to the Border
where it is punted to CPU.
[Link] [Link]
SVI SVI
[Link] [Link]
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
1
SD-Access Fabric
Architecture
DHCP in Fabric – Complete DHCP reply
[Link]/24 DHPC reply sent from Border to Edge switch
E with VNI=10 to RLOC =[Link]
B
6
C
7 DHCP
Reply B
DHCP [Link]
SERVER
Fusion Router
Shared Services
[Link]
[Link] [Link]
SVI SVI
[Link] [Link]
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
2
SD-Access Fabric: Constructs
Virtual Network
Scalable Group
Host Pool
Anycast GW
Stretched Subnets
Layer 2 Overlays
SD-Access
Fabric
How VNs work in SD-Access ip vrf USERS
rd 1:4099
route-target export 1:4099
route-target import 1:4099
ip vrf DEFAULT_VN
1:4097
should use a “Fusion” router with MP-BGP & VRF import/export. rd 1:4098
route-target export 1:4098
route-target import 1:4098
route-target import 1:4097
ip vrf GLOBAL
Control Plane rd 1:4097
route-target export 1:4097
C route-target
route-target
import
export
1:4097
1:4099
VRF B route-target export 1:4098
T5/1
SVI B
SVI B AF VRF B G0/0/0.B
ISIS BGP
GRT
T5/2
B SVI A
AF VRF A G0/0/0.A
BRKCRS- 3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
SD-Access
Fabric
Virtual Network– A Closer Look
Virtual Network maintains a separate Routing & Switching table for each instance
B B
• Nodes add a VNID to the Fabric encapsulation
#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
SD-Access Fabric: Virtual Network
SD-Access Policy
Two Level Hierarchy - Macro Level
Known Unknown
Networks Networks
VN
“A”
VN
“B”
VN
“C”
SD- Access
Fabric
Virtual Network (VN)
First level Segmentation ensures zero
communication between forwarding
domains. Ability to consolidate multiple
networks into one management plane.
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
SD-Access
Fabric
How VNs work in SD-Access
Known Unknown
Networks Networks
SD-Access
SG
SG
1
SG SG
SG
4
SG SG
SG
7
SG
Fabric
Scalable Group (SG)
2 3 5 6 8 9
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
SD-Access Fabric
Scalable Groups – A Closer Look
B B
• Nodes add a SGT to the Fabric encapsulation
SGT
SGT
• SGTs are used to manage address-independent SGT
17
4 SGT
8 25
SGT
“Group-Based Policies” SGT SGT
SGT 19 SGT
3 11 12
23
90
SD-Access Fabric: Scalable Group
SD-Access @ Cisco DNA Center
Scalable Groups
SD-Access Fabric
Host Pools – A Closer Look
B B
• Fabric uses Dynamic EID mapping to advertise each
Host Pool (per Instance ID) Pool
Pool
Pool .4 Pool
.17 .8 .25
Pool
• Fabric Dynamic EID allows Host-specific (/32, /128 Pool Pool Pool .19 Pool
.13 .11 .12
or MAC) advertisement and mobility .23
93
SD-Access Fabric
Anycast Gateway – A Closer Look
C
• Similar principle and behavior to HSRP /VRRP with a Known Unknown
shared “Virtual” IP and M A C address Networks Networks
B B
• The same Switch Virtual Interface (SVI) is present on
EVERY Edge with the SAME Virtual IP and M A C
not need to change its Default Gateway [Link]/24 [Link]/24 [Link]/24 [Link]/24 [Link]/24
94
SD-Access Fabric
Layer 3 Overlay – A Closer Look
B B
• Fabric Dynamic EID mapping allows Host-specific
(/32, /128, MAC) advertisement and mobility
Dynamic
EID
• Host 1 connected to Edge A can now use the same
IP subnet to communicate with Host 2 on Edge B
95
SD-Access @ Cisco DNA Center
Host Pools & Layer- 2 Extension
96
Fabric Edge @ CLI
VN & Pool C onfiguration
Edge-1# show vrf
Name Default RD Protocols Interfaces
DEFAULT_VN 1:4098 ipv4 LI0.4098
GUEST 1:4100 ipv4 LI0.4100
Mgmt-vrf <not set> ipv4,ipv6 Gi0/0
USERS 1:4099 ipv4 LI0.4099
Vl1021
Edge-1# show interface vlan1021
Building configuration...
Current configuration : 315 bytes
!
interface Vlan1021
description Configured from apic-em
mac-address 0000.0c9f.f45c
vrf forwarding USERS
ip address [Link] [Link]
ip helper-address [Link]
no ip redirects
ip local-proxy-arp
ip route-cache same-interface
no lisp mobility liveness test
lisp mobility 10_111_0_0-USERS
#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Fabric Edge & CP @
CLI Registration
Endpoint
#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
SD-Access Fabric
Layer 2 Overlay – A Closer Look
B B
• Uses a pre-built Multicast Underlay to setup a P2MP
tunnel between all Fabric Nodes.
L2
Overlay
• L2 Broadcast and Multicast traffic will be distributed
to all connected Fabric Nodes.
VLAN VLAN VLAN
• Can be enabled for specific Host Pools that require
L2 services (use Stretched Subnets for L3)
NOTE: L3 Integrated Routing and Bridging (IRB) is not supported at this time.
#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
SD-Access @ Cisco DNA
Center
Layer-2 Flooding
#CiscoLive DGTL-BRKCRS-2810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
0
Controller Fundamentals
ISE and DNA Center Integration
Cisco® pxGrid
NDP and DNA Center Interaction