Beruflich Dokumente
Kultur Dokumente
Your Guides
Yousuf Hatami Syed F. Ahmed
• Systems Engineer • Systems Engineer
supporting Cisco supporting Cisco
Federal Federal
• Hobby • Hobby
• Soccer/Volleyball • Bowling/Swimming
• 2 Kids • 1 Kid
• Hiking • Biking
• Vacation Spots: Italy, • Vacation Spots: Tampa, Fl,
Greece, Morocco Cancun, Barcelona
yohatami@cisco.com syedah2@cisco.com
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
SD-Access
Deployment Gotchas and Lessons
Learned
Yousuf Hatami, Systems Engineer
Syed F. Ahmed, Systems Engineer
BRKARC-1003
#CLUS
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Vacation Itinerary
• Plan, Plan, and Plan…
• Give yourself more time
• Open minded
• Don’t over think or over pack
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Cisco WebEx Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
#CLUS © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Agenda
• Introduction
o SDA
• Our Story
o Customer Engagement
o SDA Education & Learning
o SDA Deployment Scenario’s
Lessons Learned and Tips & Tricks
• Conclusion
• Wave I, II & III benefits
• Way Forward
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Introduction
2019 Out with the Old, In with the New
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
2019 Out with the Old, In with the New
SolarWinds, Prime Infrastructure, DNA Center
OpManager, PRTG. WhatsUp
B B
C
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Customer
Engagement
Customer Engagement
ISE + AD/Other
PCIe 1 PCIe 2
SS
1 2
770W AC 770W AC
1 10G 2
Cisco DNS/DHCP
DNA Center
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Customer Engagement
ISE
ISE ISE
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Customer Engagement
Testing
(Wired/Wireless) Limited-Production Production
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Education &
Learning
Nothing Like Hands-On Experience
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Demo
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Journey
Journey Begins Today
Fabric Enabled & Microsegmentation
Macrosegmentation
(Wave III)
(Wave I)
Network Access
(Wave II)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Fabric Enabled &
Macrosegmentation
(Wave I)
Small Details Matter!!!
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Fabric Enabled & Macrosegmentation (Wave I)
Integrate ISE
Shared Services Bring Up DNAC Integrate ISE
with DNAC
(AD/ISE/DHCP/NTP/DNS…) with AD
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Fabric Enabled & Macrosegmentation (Wave I)
Test/Validate
Provisioning Connect to the Host Onboarding
Wireless Outside World
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Shared Services (Tips & Tricks)
DHCP
AD Integration with ISE DNS Forward/Reverse Lookup (Windows Conflict Detection Attempts value 4)
(NTP) (ISE)
BRKARC-1003 29
#CLUS © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
DNA Center (Tips & Tricks)
Bootable USB
(Etcher Tool)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Integrate ISE with AD (Lessons Learned)
Microsoft Domain
NTP (Trust)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Integrate ISE with DNA Center (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Site Design with DNA Center (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Wired Design (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Wired Design (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Provision Wired (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Provision Wireless (Tips & Tricks)
DHCP Scope
APs not Registering Switch Port (POE) Option 43
(WLC License) (F104, F108)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Multicast (Tips & Tricks)
Order of Implementation
(Underlay Fabric VN) Remote RP
(MSDP)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Connect to the Outside World (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Host Onboarding (Tips & Tricks)
Authentication
Templates Port Provision Port Provision Port Provision
(Closed/Open/Easy/No (No AUTH, Manual) (Open AUTH, Manual) (Closed Auth, Automatic)
AUTH)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Test and Validate Fabric Enabled (Lessons Learned)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Network Access
(Wave II)
Network Access (Wave II)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
ISE Monitor Mode (Wave A) (Tips & Tricks)
Network Access 802.1x -> MAB -> Access Monitor Mode VN ISE Logs
not Impacted
Auditing/Monitoring
Network
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
ISE Closed Mode (Wave B) (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
ISE Closed Mode (Wave B) (Tips & Tricks)
Cisco Support Forums Lab Minutes Web Proof of Value On site Test
and Communities Site (POV) Deployment
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Testing/Validating Port Security (Lessons Learned)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Fine Tuning Policies (Tips & Tricks)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Microsegmentation
(Wave III)
Microsegmentation (Wave III)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Microsegmentation (Tips & Tricks)
Learn ISE
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Benefits of Fabric Enabled & Macrosegmentation
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Benefits Network Access Phase
Visibility Control
(Users/Groups, Devices) (Who, What, When & How)
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Benefits Microsegmentation Phase
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Change
SDA
Bridge
1990
1981
HUB
1980s
Router
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Change
2012
2010
1885 - 1886
1885
1817
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Forward Thinking
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Are you ready to bring change?
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
SD-Access Resources
Would you like to know more?
cisco.com/go/dna
cisco.com/go/sdaccess cisco.com/go/dnacenter
• SD-Access At-A-Glance • Cisco DNA Center At-A-Glance
•
•
SD-Access Ordering Guide
SD-Access Solution Data Sheet
cisco.com/go/cvd •
•
Cisco DNA ROI Calculator
Cisco DNA Center Data Sheet
• SD-Access Solution White Paper • SD-Access Design Guide • Cisco DNA Center 'How To' Video Resources
• SD-Access Deployment Guide
• SD-Access Segmentation Guide
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Complete your
online session • Please complete your session survey
evaluation after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live water bottle.
• All surveys can be taken in the Cisco Live
Mobile App or by logging in to the Session
Catalog on ciscolive.cisco.com/us.
Cisco Live sessions will be available for viewing
on demand after the event at ciscolive.cisco.com.
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Continue your education
Demos in the
Walk-in labs
Cisco campus
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
NDA Roadmap Sessions at Cisco Live
Customer Connection Member Exclusive
Join Cisco’s online user group to …
Connect online with 29,000 peer and Cisco NETWORKING ROADMAPS SESSION ID DAY / TIME
experts in private community forums
Roadmap: SD-WAN and Routing CCP-1200 Mon 8:30 – 10:00
Give feedback to Cisco product teams Join at the Customer Connection Booth
(in the Cisco Showcase)
Product enhancement ideas
Early adopter trials Member Perks at Cisco Live
User experience insights • Attend NDA Roadmap Sessions
• Customer Connection Jacket
Join online: www.cisco.com/go/ccp • Member Lounge
#CLUS BRKARC-1003 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Thank you
#CLUS
#CLUS