
Explore Cisco SDA architecture, VXLAN, LISP, and anycast gateways, and build the SDA fabric through theory and hands-on labs with DNAC and ISE.
Explore the control plane, data plane, and management plane of traditional networking, and examine software defined networking, APIs, and Cisco SDA solutions.
Explore the control plane, data plane, and management plane in traditional networking and how OSPF, IGP, BGP, and LISP shape routing tables and forwarding decisions.
The data plane, or forwarding plane, forwards packets based on control plane routing knowledge, matches IP destinations in the routing table, and encapsulates with 802.1Q tags, supporting VXLAN in SDA.
Understand the management plane as the access and monitoring layer for networking devices. It uses protocols like SNMP, Telnet, SSH, NetFlow, XML, and TFTP for management and automation.
Explore software defined networking (SDN) and its centralized controller, which decouples the control plane from the data plane to configure devices via APIs for scalable network management.
Learn how the SDA controller centralizes control and management planes, pushes forwarding policies via API to switches, and enables automation, policy enforcement, and security across physical and virtual networks.
Examine the benefits of software defined networking, including centralized provisioning and zero-touch, scalable policy deployment, and reduced human error, alongside the single point of failure risk mitigated by controller clustering.
Learn how application programming interfaces enable admin, controller, and switches to communicate in software defined networking, using northbound and southbound APIs and rest APIs for automation.
Compare Cisco SDN solutions, including ACI for data centers, SD-WAN for wide area networks, and software defined access for campus networks, featuring spine-leaf, VXLAN, and epic.
Explore the section three SDA architecture, define Cisco SDA and intent-based networking (IBM), and outline the four operational planes and the four layers of software-defined access.
Cisco SDA transforms campus LANs into intent-driven, programmable networks using intent-based networking, translation, activation, and assurance across fabric and non-fabric components.
Explore the four planes of SDA, including a Lisp-based control plane. See how map server RMS supports identity-location mapping, VXLAN data forwarding, and CTAS-driven SGD tagging for policy.
Explore Cisco SDA's four layers—physical, network, controller, and management—highlighting Lisp-based control, VXLAN data plane, Cisco TrustSec policy plane, and deployment via DNA Center and ISE.
Explore the Anycast gateway concept and its role in Cisco SDA, as introduced in section four.
Anycast gateway places the same svi on all fabric edge switches to keep traffic local, eliminating inefficient underlay routing and avoiding duplicate ip issues.
Explore the locator/identifier separation protocol (LISP) and its control planes, message types, data plane, and how Lisp works within Cisco SDA.
Explore how Lisp separates endpoint identifiers from routing locations, using map servers to map eid to rloc and enable mapping and encapsulation in SDA networks.
Explore LISP control plane concepts, including map server and map resolver roles, map cache sharing among routers, and how LISP encapsulation enables scalable underlay routing.
Explores lisp five message types, how map servers update id to rloc mappings, and how map requests and replies establish routes, with proxy routers bridging lisp and non-lisp domains.
Explore the lisp data plane, using l3 tunneling and UDP 4341, with idr, etr, and proxy routers managing map lookups and traffic, and compare it to SDA's VXLAN data plane.
Explore how LISP operates in software defined access, renaming tunnel routers to fabric edge nodes and map server/resolver to control plane nodes, with VXLAN handling data forwarding.
Explore why VXLAN is required in SDA, define VXLAN, and explain how it works within Cisco SDA.
Harness VXLAN to create layer two overlays over a layer three underlay, enabling same-subnet hosts to communicate across multi-switch fabrics while avoiding STP limits and expanding VLAN scale.
Explore how VXLAN creates layer-two overlays over layer-three networks to extend VLANs in software-defined access, using UDP-based tunneling (port 4789) between fabric edge nodes.
Explore how vxlan operates in software defined access, detailing fabric edge nodes, layer two vxlan tunnels, and vxlan gpo with scalable group tags managed by Cisco Trust.
Explore Cisco risk (CTAs) and Cisco trust, then examine virtual network and scalable group tax, and learn how these concepts work in software-defined access.
Learn how Cisco TrustSec enables security in SDA by network segmentation, tagging traffic with scalable group tags, and policy-driven macro and micro segmentation across virtual networks.
Understand virtual networks with unique identifiers and scalable group tags, including VRF in traditional networking, VXLAN GPO, and NAC and ISE integration driving policy application.
Explain how security group tags (SGT) and SGD work in SDA, authenticating and authorizing clients with ISE, pushing policies to fabric edge nodes, and enforcing cross-network access via the fabric.
Explore section eight protocols used in Cisco SDA, identify the types of protocols, and examine the routing protocols for underlay in Cisco SD.
Explore protocols powering Cisco SDA: underlay routing with IS-IS (or OSPF), control plane with LISP, data plane via VXLAN, anycast, and Cisco TrustSec using VLAN IDs and scalable group tags.
Explore underlay routing in SDA, using IS-IS or OSPF IGPs to establish loopback reachability for fabric edge nodes and support VXLAN with LISP, while client subnets stay unadvertised.
Explore Cisco SDA fabric components, including underlay, overlay, node fabric, border and control plane nodes, fusion, router, shared services, and the roles of Cisco DNAC, Cisco ISE, and DHCP.
Cisco SDA campus fabric creates an overlay over underlay devices to form a logical full-mesh topology that virtually connects fabric components across an arbitrary underlay.
Define the underlay with physical switches and routers, enabling IP connectivity via IGP such as ISIS or OSPF, then build an overlay of layer-2 tunnels that carries end-user subnets only.
Fabric edge node, or fen, acts as the SDA fabric access layer. It handles endpoint registration, ID-to-IP mappings, and VXLAN data plane communication.
Explore fabric border nodes (FBN) in the SDA fabric as gateways to external networks, advertising endpoint prefixes and enabling vxlan encapsulation and diverse border node types.
Describe how the control plane node acts as map server and map resolver, managing the host tracking database and id to log mappings for edge, border, and wireless controller nodes.
Fusion routers provide access to shared services and enable inter-vrf communication in the SDA fabric, connecting clients to DHCP, DNS, IP, SNMP, NAC and ISE.
Explore shared services in the SDA environment, including how the fusion router advertises DHCP, DNS, NTP, and SNMP to all SDA fabric clients.
Explore fabric wireless controller concepts in SDA, where fabric-enabled access points connect to the fabric edge node, traffic stays local, and hybrid fabric-enabled and traditional SSIDs are supported.
Explore the digital network architecture center controller (NEC) for SDA, enabling automatic provisioning, device discovery, and centralized configuration across the SDA fabric with design, provision, and assurance functions.
Explore ISE in the SDA environment, including dynamic mapping of users and devices to scalable groups. Learn policy enforcement, authentication, authorization, and DNA Center integration with REST API and pxGrid.
Explore fabric in a box where border, CP node, and edge node reside in one device or stack, reducing underlay needs, and learn how intermediate nodes route IP traffic.
Explains dhcp in sda: after ise authenticates endpoints, edge nodes assign vlan and sgd, relay dhcp using option 82 on an anycast gateway svi, and deliver replies to the edge.
Use the Cisco SDA compatibility matrix to verify OS version compatibility across controllers and fabric devices for a new deployment, referencing release 2.2.3.6 and Catalyst 3650 iOS versions.
Explore traffic flow for endpoints in the same subnet, across subnets behind the known border router, to unknown destinations, and to shared services.
Explore how SDA handles end-to-end communication between hosts in the same subnet using ARP, Lisp, map servers, VXLAN tunneling, and macro and micro-segmentation policies.
Explore how in a SDA environment endpoints on different subnets communicate via an anycast gateway and border router, using VXLAN encapsulation, ip-to-loc mapping, and macro segmentation checks.
Learners explore SDA packet flows to an unknown destination behind a border node. It covers ARP to an anycast gateway, map requests, negative map replies, and VXLAN encapsulation and decapsulation.
Explore how endpoints reach shared subnets and services (dhcp, dns, ntp, snmp, ise) through fusion routers, edge and border nodes, using vxlan tunnels and vrf-based mp-bgp routing.
In this Course we will learn below topics and perform below labs
Section1 Course Introduction
Course Introduction
Section2 Introduction to Cisco SDA
Control Plane in Traditional Networking
Data Plane in Traditional Networking
Management Plane in Traditional Networking
What is SDN (Software Defined Networking)
SDN Controller
SDN Benefits and Drawback
Application Programming Interface (API)
SDN Solutions Offered by Cisco (ACI vs SDWAN vs SDA)
Section3 SDA Architecture
What is Cisco SDA and Intent Based Networking (IBN)
SDA Operational Planes
SDA Layers
Section4 AnyCast Gateway
AnyCast Gateway
Section5 Locator Identifier Separation Protocol(LISP)
Locator Identifier Separation Protocol(LISP)
LISP Control Plane
LISP Message Type
LISP Data Plane
LISP in SDA
Section6 Virtual Extensible LAN(VXLAN)
Why Virtual Extensible LAN (VXLAN) is Required in SDA
Virtual Extensible LAN(VXLAN)
VXLAN in SDA
Section7 Cisco TrustSec (CTS)
Cisco TrustSec (CTS)
Virtual Network (VN) and Scalable Group Tags (SGT)
How SGT Works in SDA
Section8 Protocols used in SDA
Protocols Used in SDA
Routing Protocols for Underlay in SDA
Section9 SDA Components
Cisco SDA Fabric
Underlay & Overlay (Network & Devices)
Fabric Edge Node (FEN)
Fabric Border Node (FBN)
Control Plane Node (CPN)
Fusion Router
Shared Services
Fabric WLC
Digital Network Architecture Center Controller (DNAC)
Identity Services Engine (ISE)
Miscellaneous Components (Fabric In A BOX & Intermediate Nodes)
DHCP in SDA
Cisco SDA Compatibility Matrix
Section10 SDA Traffic Flow
SDA Traffic Flow Endpoints Belong To Same Subnet
SDA Traffic Flow Endpoints Belong To Different Subnet & Subnets Behind Known Border Router
SDA Traffic Flow Endpoints Communication With Unknown Destination
SDA Traffic Flow Endpoints Communication With Shared Subnets
Section11 Lab IP Pool & Lab Topology Overview
IP Pools Overview
Cisco SDA Lab Topology Overview
Section12 Lab Cisco DNAC Introduction
DNAC GUI Overview
Cisco DNAC Integration with Cisco ISE
Section13 Lab Cisco DNAC Design
Network Hierarchy Design
Network Settings Configuration
Device Credentials Configuration
IP Address Pools Configuration
Network Profiles Configuration
SSID Configuration
Section14 Lab Cisco DNAC Discovery
Discovery Tool for Discovery of Fusion, Border and Edge Node
Manual Discovery of Wireless Controller
Assign Devices to the Site
Device Provisioning BORDER and EDGE Node
Device Provisioning Wireless Controller
Discover & Configure Fabric Edge Underlay Using LAN Automation
Section15 Lab SD Access Fabric
Configure Virtual Networks (VN)
Configure Security Group Tags (SGT)
Assign Security Group Tags (SGT) to Virtual Networks (VN)
Configure SDA Fabric Site
Configure SDA Fabric Role
Section16 Lab Host Onboarding
Host Onboarding Part1 (Configure Authentication Template)
Host Onboarding Part2 (Assign IP Pool to VN)
Host Onboarding Part3 (Assign IP Pool to SSID)
Host Onboarding Part4 (Configure FEN Ports)
Section17 Lab Internet Transit BGP HandOff
Internet Transit BGP Handoff Configuration
Section18 Lab Client Verification
Wired client connectivity verification
Wireless client connectivity verification
Section19 Lab Fabric In A Box (FIAB)
Fabric In A Box (FIAB)
Build Second Fabric Site
Configure and Deploy FIAB
SDA Transit Configuration For Second Fabric Site
Section20 Lab Traffic Segmentation
Macro Segmentation & Micro Segmentation
Policy Configuration
Contract Configuration
Section21 Lab Cisco DNAC Assurance
DNAC Assurance Network & Client Health
DNAC Assurance Platform Assurance
DNAC Assurance Audit Logs
Section22 Lab Miscellaneous
Run Commands from DNAC