Beruflich Dokumente
Kultur Dokumente
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Key Benefits
Why do I care?
CONNECTIVITY
CONSISTENCY SEGMENTATION
POLICING
MOBILITY AUTOMATION
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
What is SD-Access?
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
SD-Access
Campus Fabric + DNA Center (Automation & Assurance)
§ SD-Access
GUI approach provides automation &
assurance of all Fabric configuration,
Identity Services Engine
management and group-based policy
Network Control Platform
§ Campus Fabric
CLI or API approach to build a LISP + VXLAN
+ CTS Fabric overlay for your enterprise
Campus networks
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
SD-Access
What exactly is a Fabric?
A Fabric is an Overlay
An Overlay network is a logical topology used to virtually connect devices, built on top
of a simple physical Underlay network.
An Overlay network often uses alternate forwarding attributes to provide additional
services, not provided by the Underlay.
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
SD-Access
What exactly is a Fabric?
A Fabric is an Overlay
An Overlay network is a logical topology used to virtually connect devices, built on top
of a simple physical Underlay network.
An Overlay network often uses alternate forwarding attributes to provide additional
services, not provided by the Underlay.
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
SD-Access
Fabric Terminology
Hosts
(End-Points)
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
SD-Access
Fabric Terminology
Encapsulation
Hosts
(End-Points)
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
SD-Access
Fabric Terminology
Manual Underlay
You can reuse your existing IP network
as the Fabric Underlay!
• Key Requirements
• IP reach from Edge to Edge/Border/CP
• Can be L2 or L3 – We recommend L3
• Can be any IGP – We recommend ISIS
• Key Considerations
• MTU (Fabric Header adds 50B)
• Latency (max RTT =/< 100ms)
Underlay Network
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
SD-Access
Fabric Terminology
Underlay Network
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Fabric Roles & Terminology
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
SD-Access
Fabric Roles & Terminology
§ DNA Center – provides simple GUI
management and intent based automation
(e.g. NCP) and context sharing
§ Identity Services – NAC & ID Systems
(e.g. ISE) for dynamic Endpoint to Group
mapping and Policy definition
§ Analytics Engine – Data Collectors
(e.g. NDP) analyze Endpoint to App flows
and monitor fabric status
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
What is SD-Access?
Overlay Terminology
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
What is SD-Access?
Fabric Segmentation
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
SD-Access Fabric
Control-Plane Nodes – A Closer Look
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
SD-Access Fabric
Edge Nodes– A Closer Look
Edge Node provides first-hop services for Users / Devices connected to a Fabric
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
SD-Access Fabric
Border Nodes– A Closer Look
Border Node is an Entry & Exit point for data traffic going Into & Out of a Fabric
• Internal Border
• Used for “Known” Routes inside your company
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
SD-Access Fabric
Fabric Enabled WLC– A Closer Look
Fabric Enabled WLC is integrated into Fabric for SDA Wireless clients
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
SD-Access Fabric
Virtual Network– A Closer Look
Virtual Network maintains a separate Routing & Switching table for each instance
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
SD-Access Fabric
Scalable Groups – A Closer Look
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
SD-Access Fabric
Anycast Gateway– A Closer Look
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
SD-Access
Campus Fabric - LISP
BEFORE
IP Address = Location + Identity
Prefix Next-hop
189.16.17.89 ….....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 …....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
192.58.28.128 ….....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
192.58.28.128 …......171.68.228.121
189.16.17.89 ….....171.68.226.120
22.78.190.64 …......171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121
Prefix Next-hop
189.16.17.89 …......171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 …....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
192.58.28.128 ….....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
192.58.28.128 ….....171.68.228.121
189.16.17.89 ….....171.68.226.120
22.78.190.64 …......171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121
Prefix Next-hop
189.16.17.89 ….....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 …....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
192.58.28.128 ….....171.68.228.121
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
SD-Access
Campus Fabric - LISP
Routing Protocols = Big Tables & More CPU LISP DB + Cache = Small Tables & Less CPU
with Local L3 Gateway with Anycast L3 Gateway
BEFORE AFTER
IP Address = Location + Identity Separate Identity from Location
Prefix RLOC
192.58.28.128 ….....171.68.228.121
Prefix Next-hop 189.16.17.89
22.78.190.64
….....171.68.226.120
….....171.68.226.121
189.16.17.89 ….....171.68.226.120 172.16.19.90 ….....171.68.226.120
22.78.190.64 ….....171.68.226.121 192.58.28.128 ….....171.68.228.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121
192.58.28.128 …....171.68.228.121 Prefix Next-hop 189.16.17.89 ….....171.68.226.120
Mapping
189.16.17.89 …....171.68.226.120 22.78.190.64 ….....171.68.226.121
189.16.17.89 ….....171.68.226.120
Endpoint
22.78.190.64 ….....171.68.226.121 22.78.190.64 ….....171.68.226.121 172.16.19.90 ….....171.68.226.120
172.16.19.90 …......171.68.226.120 172.16.19.90 ….....171.68.226.120 192.58.28.128 ….....171.68.228.121
192.58.28.128 ….....171.68.228.121
192.58.28.128 …....171.68.228.121
Database
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
Routes are
192.58.28.128 …......171.68.228.121
189.16.17.89 ….....171.68.226.120
22.78.190.64 …......171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121
Consolidated
Prefix
189.16.17.89
22.78.190.64
172.16.19.90
Next-hop
…......171.68.226.120
….....171.68.226.121
….....171.68.226.120
to LISP DB
192.58.28.128 …....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121 Prefix Next-hop
172.16.19.90 …......171.68.226.120 189.16.17.89 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121 22.78.190.64 ….....171.68.226.121
189.16.17.89 …....171.68.226.120 172.16.19.90 ….....171.68.226.120
22.78.190.64 ….....171.68.226.121 192.58.28.128 …....171.68.228.121
172.16.19.90 …......171.68.226.120
192.58.28.128 ….....171.68.228.121
189.16.17.89 ….....171.68.226.120
22.78.190.64 …......171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121
Prefix Next-hop
Prefix Next-hop 189.16.17.89 ….....171.68.226.120
189.16.17.89 ….....171.68.226.120 22.78.190.64 ….....171.68.226.121
22.78.190.64 ….....171.68.226.121 172.16.19.90 ….....171.68.226.120
172.16.19.90 ….....171.68.226.120 192.58.28.128 …....171.68.228.121
192.58.28.128 …....171.68.228.121
189.16.17.89 …....171.68.226.120
22.78.190.64 ….....171.68.226.121
172.16.19.90 …......171.68.226.120
192.58.28.128 ….....171.68.228.121
Topology Routes
192.58.28.128 ….....171.68.228.121
189.16.17.89 ….....171.68.226.120
22.78.190.64 …......171.68.226.121
172.16.19.90 ….....171.68.226.120
192.58.28.128 ….....171.68.228.121
Endpoint Routes
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
SD-Access
Campus Fabric - VXLAN
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
SD-Access
Campus Fabric - CTS
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Thank you