Professional Documents
Culture Documents
BRKCRS 2812
BRKCRS 2812
Network
Software Defined Access
Meghna Muralinath
Technical Marketing Engineer
BRKCRS-2812
A little bit about me ……
I have been a TME with Cisco for 4 years with expertise on switching and
SD Access. Before this I was with Cisco TAC handling customer
escalations on Cisco Switching.
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
cs.co/ciscolivebot# BRKCRS-2812
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Agenda
• Introduction
• Migration strategies
• Prepare for migration
• Wireless network migration
• DNA Center upgrade
• Key takeaways
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Level set
• Today I am here to share a couple of
interesting snippets of what the Cisco DNA
Center automates so you will have the tools
to be able to plan your migration
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cis
co
DN
ISE AC
Ins Ins
tal
tal
l/ l
R e
Pre ad
pN y
etw
ork
Ad De
dd vic
ev es
ice
st
La oi
Wi nA nv
red uto en
ma tor
an Tr a tio y-
Vis d W de slan n or
Dis
co
ibi irel
lity es vic te Pn ve
s es net P ry
wo
rk
int
en
t to
So ne
ftw tw
are ork
Mi U pd
cro ate
Se (SW
gm IM
Ma en )&
cro tat
Se io n
Lic
en
SD gm se
Ac Fa
ce bri en mg
ss cP tat mt
rov ion
Fa isio
bri nin
c Cl i g
e
Vis nt a En
ibi nd dP
lity Ho oin
BRKCRS-2812
st tO
nb
oa
rdi
ng
Intent based networking journey Map
Security
Analytics
Threat
Containment
ETA
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Assurance
Automation
7
Not mandatory
Security / Policy
A brownfields migration philosophy
Source :https://medium.com/@ank.mahajan/value-vs-complexity-a-prioritisation-tool-4a2a1ba08eda
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Lowest complexity brownfields migration scenario
L3 switch /
(OTT) E Router
B
CP
Internet
eBGP
GRT GRT
or
eBGP
VRF VRF
• recommended code • One exit point out of the network • No network transit over fabric site
• Single fabric site • L3 Routed access Underlay • No redundancy
• OTT local mode wifi • One SDA VN • No inter-border iBGP
• < 20ms RTT (for wifi) • No inter-VN security • New IP ranges in SDA
• No end point authentication • No SGACLs • No L2 flooding in SDA
• No multicast • No SGTs • No SDA L2 border
• Jumbo MTU everywhere
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Layer on high business value features
New cable runs to create a new parallel May require a couple of cables from new
network access or distribution switches
Power and rack space to accommodate Incremental power and incremental rack
the parallel network space
Additional hardware required Existing hardware can be re-used
Clean slate, new configurations automated Will need to workaround and carry over
by Cisco DNA-Center existing configuration hacks
Plug and play users into the new network Move users one group at a time
Can be rolled back by moving end points Roll back will need re-configuration of the
network devices
BRKCRS-2812
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Hybrid of Parallel and Incremental when planning
a network re-fresh
• Backup configurations from the old network devices
• Replace network with new refreshed hardware, ensure they are upgraded
to software that is supported on a fabric
• Restore old configurations to the new switches.
---------- Ensure the network is restored and the end hosts can onboard ------------
Presentation © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Add B/CP to DNA Center inventory
• You can add the brownfield device chosen as B/CP to the Cisco DNA
Center inventory by running a discovery for it from the Cisco DNA Center
• Once device is discovered, Cisco DNA Center configures the switch with
IP device tracking on access ports (access PIDs like 9300, 9200,
3850,3650)
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Incremental Migration – High Level concept
Fabric network Traditional network Network
(new IP scope) (existing IP scope)
Route between
IP scopes
C B
Existing IP
distribution network
(underlay)
Edge Border/Control Rest of
Nodes Plane Node the
Network
• The virtual network connects to the existing/external network via the border
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Converting a brownfield switch to a fabric switch
Rebuild the switch:
1 2
LAN Automation
Manual Underlay
1. Default seed downlink
interface config 1. Configure the L3 underlay manually
2. Start Lan Automation 2. Modify the upstream links to routed links
3. Provision the device to site 3. Discover the device via the DNA Center
4. Add to fabric as an Edge 4. Provision device to site
5. Add the switch to fabric as an edge
switch
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Provisioning devices to site
• Once devices are added to Cisco DNA Center inventory, they have
to be provisioned.
• This step assigns the devices to a specific site in the hierarchy. This
step ensures all the network intent defined by the network
administrator is added to the network devices.
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Communication between fabric enabled and non
fabric hosts
Fusion • Traffic from the traditional network gets
routed up to the fusion router
Presentation © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Prepare for migration
New IP scopes for fabric
• Keep your underlay separated from your
overlay. Underlay can be ipV4 only
10.10.10.254/
10.10.10.253/32 • Dual stack support for overlay
32
192.168.1.2/32
10.10.10.0/30
• Limit on number of IP pools per fabric, leave
room to grow
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
LAN Automation
When building a parallel network for SD Access,
Lan Automation can be used to simplify building
Fusion
the underlay.
• having L2 in the underlay with spanning tree instability and STP blocked links
only makes the overlay more unstable – this is unsupported
• If you decide to use LAN automation to onboard edge switches, IS-IS routing
protocol must be configured
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Why is underlay MTU important ?
ICMP T3C4 to IP addr – 2 in GRT
Destination unreachable,
Fragmentation required
IP Addr=1
Lo0 IP Addr=22 IP Addr=2
Lo0 IP Addr=11
E10,
MTU1500
+VXLAN
• The T3C4 is sent in the underlay and never makes it back to the host
• Use TCP re-adjust MSS , this will not help with UDP packets
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Relocate point of application of features
User traffic will be encapsulated with VxLAN at the Edge/Broder
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Extend fabric subnets outside
• If there are IoT devices that cannot be re-ip when migrating to fabric
use L2 border to extended the subnet into the fabric
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Extend fabric subnets outside
VXLAN VLAN
DATA-PLANE
Layer 2
Border
Multi-chasis
B EtherChannel
Single or
SDA Fabric port-
channel*
Trunk Port
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Extend fabric subnets outside
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Extend fabric subnets outside
B STP ro
o t port
B STP
bloc
king
Layer 2
Border
SDA Fabric
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Extend fabric subnets outside
B
B
Layer 2
Border Single or
port-channel*
SDA Fabric Trunk Port
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
L3 VNs in Cisco SD Access
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Multi-VN border route peering scenarios
• 1:1
B GRT GRT B GRT Zone
Brownfields
VN1 VRF1 / fusion VN1 Zone
VN2 VRF2 VN2 Zone
• Capture connectivity and security requirements, they will dictate the ‘right’
answer. Define and agree on these early
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Firewall as fusion
• Comprehensive inter-VN policy, stateful inspection, AVC
Note: SGT can be derived from ACI EPG. Review latest BRKDCN-2489
• Rich reporting in FTD: Top blocks, top malwares top hosts effected by malware,
network risk, customized, etc.
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Firewall as fusion – other considerations
• Size appropriately:
• Max throughput
• Max connections per second
• Average packet sizes
• Interfaces
• Enable features (IPS, AMP, URL Filtering, IPSec)
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Border switch redundancy S
E
SVI or sub-int
eBGP+BFD
I iBGP+BFD
Physical
Could be a
Sub interface
Logical: GRT
Brownfields if it’s a router repeat per SDA VN
VRF VRF
S S E E S S
E E
S S S S
B B
VRF S S VRF
I
Only for VN, not GRT
• Per-VRF BGP recommended. Best route control features. Other protocols allowed but not recommended
• BFD optional, still recommended if other side capable. SVI can stay up when physical link fails. Configure
Manually on CLI or with template
• N-S and E-W port-channel optional/permitted as it reduces BGP peering to 5x per VRF
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Border router redundancy S
E
SVI or sub-int
eBGP+BFD
Physical
could be routed sub- Logical: GRT then
interface, depending repeat per SDA VN
Brownfields
on brownfields switch
model / router VRF VRF
S S E E S S
E E
B B Si Si Si Si
VRF Si Si VRF
I
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Border handoff Automation
• Cisco DNA Center Automates the configurations on the Border for the
North bound interface. Brownfield device connecting to it has to be
manually configured
• The automation vlan starts with VLAN 3001 and counts across all fabric
sites.
• If the VN handoff is deleted and re-added it does not get the same vlan
back. The brownfield device will need to be re-configured
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
L2 Broadcast
• In a fabric L2 broadcast is disabled by default. It can be selectively enabled
only for hosts that send/receive broadcast, also floods link local multicast in
the overlay
• Silent hosts need the broadcast (ARP) flooded to it, so they can respond
and in turn get registered in the edge’s lisp database
• Manually add hosts into the edge’s sisf table - ‘device tracking binding vlan
vlan_no ip_addr int gix/y mac_addr ’
• Wake On LAN with server and hosts in the same subnet is supported
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Native multicast
• Fabric supports propagating multicast in
CP RP
two ways
• Head end replication
B B • Native multicast
Multicast
Replicator
• Enabling native multicast distributes the
load of replication of multicast streams
(S,G)
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Native multicast
Native multicast uses SSM to transmit multicast in the underlay. It does not
require an RP in the underlay.
If any of these groups are being used in the intermediate network, this will
mix up the streams
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Integrating fabric multicast with traditional
network pre 1.3.3
• Fabric has to have its own RP
External RP
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Integrating fabric multicast with traditional
network pre 1.3.3
Fusion router
External RP-1
External RP-3
External RP-2
non Fabric
SD-Access Fabric • This will limit the number of MSDP peering needed
E E E on the Fabric RPs
ip msdp vrf <vrf_name> peer External_RP_ip
connect-source Loopback<lo_created_for_multicast_VN>
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Integrating fabric multicast with traditional
network post 1.3.3
• The fabric devices can directly peer with the external RP
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Software and hardware support for native
multicast
Platform Min IOS needed for Native Multicast
9k 16.9.1.s
3k 16.9.1.s
6k 15.5.(1)SY2
ASR1k,ISR4k,CSR 16.9.1.s
Cat4k,N7k No support
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Pick the right border
Router Switch
B B
Lower port density- Patch FEs to intermediate Higher port density - Patch FEs directly to
switches border switch
Higher scale. CP, SGT, SGACL, adjacency etc. L2 handoff support on C3K, C9K and C6K
Standalone Multi-chassis
Back-stack
Stackwise Virtual
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Test your configuration before production
• Routing convergence is dependent on correct
brownfields routing configuration
• Building 1-2 fabric edges does not impact Brownfields
existing network and can be used for testing of
endpoints
• Before adding critical production traffic, test
failure scenarios:
• Fabric endpoint PING to hosts external to fabric
• ECMP. Run multiple parallel PINGs B B
• Fail links
• Reload borders
• Fix anomalies
• Repeat tests
• Get a sampling of all the exotic endpoints and test
on this fabric edge – if it works here, it will work
99.999% elsewhere E
• Once the borders are right, the whole fabric can
leverage this. Correct border routing is the same
for fabric of 1x FE or 250x FE
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Extended node policy enforcement – IoTswitch
migration - pre 1.3.3
• SGT mapping for traffic originated from the
Extended node is done on the Edge Node.
C
B
B
B
B • Policy enforcement for traffic originated from
the Extended node is done on the Edge node
Host-2 Host-1
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Policy Extended node – 1.3.3 IoT switch
migration
ISE • Switches like the IE3400/IE3400H with release
17.1.1 are capable of inline SGT.
C
• Once the End Host connected to the Policy
B B
B
B extended node will be authenticated via ISE
Fabric SGT
Site • the ISE as an authorization result sends an
--------anycast gateway--------
SGT tag to the policy extended node
Inline tagging
• Policy extended node sends the SGT tag to
via CMD the edge node via CMD
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Policy
Integrating Cisco DNA Center with existing ISE
• Supplicants on endpoints don’t need to change
If you do decide to use a new ISE cluster for the fabric network for POC or
because the production ISE version cannot be upgraded, the policies can
be backed up from the old ISE and restored on the new ISE.
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Integrating Cisco DNA Center with Existing ISE
• The credentials used on Cisco DNA Center for ISE should the root
credentials. The ISE should have same root and UI password for the
integration to be successful.
• Post 1.3.1 when ISE is integrated with Cisco DNA Center via PxGrid the
integration is for both automation and assurance.
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Integrating Cisco DNA Center with Existing ISE
• If you have existing SGACL policies on the brownfield ISE consider using
Cisco DNA Center 1.3.1 or later
• The DNA Center now controls all the policy creation and definitions
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
DNA Center upgrade
SD-Access 1.3 Migration Matrix
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Challenge question
• When upgrading Cisco DNA Center for new feature support, should you
upgrade the fabric network devices be upgraded first or should the Cisco
DNA Center be upgraded first ?
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Migrating Cisco DNA Center appliance
DN2-HW-APL
DN2-HW-APL-L
(entry)
(mid-size)
44 Core DN2-HW-APL-XL
56K Core
25K endpoints (large)
40K endpoints
112 Core
100K endpoints
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Key takeaways
• Most traditional topologies can be migrated to SD Access architecture
• Double/triple check to make sure the software on ISE, Cisco DNA Center , network
elements are all compatible
• Keep in mind the max RTT between different fabric elements
• It will help to know your Network
• Traffic patterns and types
• Network devices connecting in
• Exotic end points
• Security policies
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
A special thank you to my colleagues
Jerome Dolphin
Jonathan Cuthbert
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
BRKCRS-2812 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Thank you