
Explore Cisco sd-access for branches and campus networks, learn to orchestrate it with Cisco dna center, and use the net data platform for assurance and analytics.
Explore Cisco SD-Access, a fabric-based solution delivering identity-based macro and micro segmentation, host mobility with Lisp, and automated deployment and visibility via DNA Center, ISE, and the network data platform.
Describe the Cisco SD-Access architecture, with ISE handling endpoint mapping and policy, DNA Center enabling visibility, and control plane, border, and fabric edge nodes for VXLAN and anycast L3 gateways.
Explore border nodes in the fabric, including internal, external, and internal plus external borders, and how they advertise subnets, import non-subnets, and enable data transit.
Explore external border routing and fabric components, including internal and external borders, fabric enabled wireless controllers, vxlan data planes, and control plane separation for policies that regulate traffic.
Explore fabric components and terminology in SD-Access, including virtual networks, VXLAN, instance IDs, host pools, scalable groups, anycast gateways, and global routing table import and export for mobility.
Explore fabric operation in Cisco sd-access fabric, highlighting the lisp-based control plane, vxlan data plane, and Cisco Trustsec policy plane, with host mobility and virtual network IDs forming the overlay.
Explore how Lisp-based control plane for Cisco sd-access uses a central map database to locate endpoints, enabling on-demand routing, smaller local routing tables, and vxlan traffic across the fabric.
Learn how the data plane uses vxlan encapsulation to form layer 2 and layer 3 overlays, carrying the virtual network ID and group policy options for sd-access.
Explore policy plane based on Cisco Trust SEC and group based policies with vxlan gpo, macro and micro segmentation, and dynamic and static classification for wired and wireless traffic.
Explore Cisco DNA Center, a centralized platform for automating and assuring enterprise campus LAN, wireless LAN, and SD-Access fabric, with RBAC, APIs, and external orchestration.
Automate the underlay for deploying Cisco sd-access with DNA Center, replacing traditional l2 loops with a scalable l3 underlay and enabling rapid seed-device discovery and provisioning.
Plan underlay automation by defining seed and BNP agent device roles, ensuring DNA center reachability, L2 uplinks, and proper routing with ISIS or OSPF for discovery and provisioning.
Design underlay automation in DNA Center: build a network hierarchy with sites, buildings, and floor plans, and configure global network settings and a global IP pool for provisioning.
Configure underlay automation by discovering seed devices and onboarding catalyst switches through the DNA Center discovery, then inventory and manage devices.
Master underlay automation provisioning in DNA Center by discovering seed devices, assigning sites, and configuring LAN automation to convert L2 to L3 and deploy global network settings.
Integrate ICE with Cisco DNA Center to push and enforce group-based policies across the campus fabric via rest APIs, with configuration synchronized between DNA Center and ICE.
Learn to provision policies in Cisco SD-Access by creating skill level group tags, building virtual networks, and establishing group-based policies and contracts with explicit deny and allowed traffic.
Explore Cisco SD-Access deployment models, including fabric sites with border nodes and control planes, fabric-in-a-box, and campus transit networks with VXLAN, IP transit, and site tagging.
Compare ip-based transit and sd-access standard, and learn how control plane, data plane, and policy plane work with vxlan, remapping virtual networks and cities for campus interconnect.
Explore border deployment use cases in SD-Access, including external border for unknown networks, internal border for data centers, and anywhere border for known and unknown subnets via BGP handoff.
Explore fabric border packet flow through the internal border router, from external domain to fabric and back, using VXLAN encapsulation, BGP, and the control plane MAP database.
Analyze fabric border packet flow and the external border router’s handling of unknown subnets. See how map database lookups, vxlan encapsulation, and a default route steer traffic to external domains.
Explore the fabric border architecture with the anywhere border, combining internal and external routing. Understand importing external prefixes, map server lookups, and exporting fabric routes to the internet.
Learn how to connect shared services such as ice, dns, dcp, and netflow to an sd-access fabric via the global routing table underlay, using VRF-based route leaking and route-maps.
Troubleshoot Cisco sd-access fabric external domains by verifying border router connectivity and BGP adjacency, confirming map server learning on the control plane, and validating internet reachability through the proxy tunnel.
Explore how sd-access wireless architecture simplifies the control plane, optimizes the data plane with vxlan, and integrates policy and segmentation across the fabric.
Configure fabric enabled wireless societies in SD-Access via DNA Center, creating enterprise wireless networks with data or voice and data, selecting security, and applying a fabric enabled profile across sites.
Configure a guest ssid for sd-access wireless by creating the guest network, selecting the sd-access wireless profile, and building a guest portal with ICE authentication for centralized access.
Discover fabric wireless controllers using a defined IP range and add them to the Cisco DNA Center inventory for SD-Access management.
Log in to Cisco DNA Center and configure a wlc ha sso pair via the provision and inventory menus, selecting the primary and secondary wlc and monitoring sync status.
Provision the wireless LAN controller for SD-Access fabric by selecting the device from inventory, assign it to a site, and push the design's global settings to the WLC.
Learn how to add the wireless LAN controller to the SD-Access fabric via the Cisco DNA Center dashboard, then save, apply, and verify the control plane on the controller.
Onboard access points into the wireless fabric by connecting APs to the fabric edge and using the DNA Center host onboarding, with an infra virtual network and RF profile.
Verify an access point in an SD-Access network by checking the VXLAN tunnel to the first hop switch using DNA Center, confirming the AP is joined to the fabric.
Learn wireless client onboarding in the Cisco SD-Access fabric by creating wireless pools, enabling L2 Lisp, and mapping pools to a virtual network and fabric.
Discover how Cisco sd-access enables seamless wireless client roaming, as access points update the wlc fabric and control plane about the client's location via vxlan, with l2 roaming.
Learn Cisco sd-access wireless design and deployment principles, meet latency thresholds across access points, control plane, and border nodes, and apply mix-mode or over-the-top deployments.
Discover how Cisco DNA Center Assurance provides a 360 view of SD-Access network health, from device and client health dashboards to top issues and location-based drill-downs for troubleshooting.
Explore how Cisco SD-Access analyzes client health on wired and wireless networks using the client health dashboard, onboarded counts, health scores, and trends to troubleshoot and optimize access.
Explore Cisco SD-Access assurance's application health dashboard, categorize apps by business relevance, and analyze 24-hour health scores, latency, jitter, and losses to troubleshoot issues.
Explore how Cisco DNA Center Assurance delivers operational insights to troubleshoot day-to-day SD-Access issues using guided actions, run commands, verify ICE server connectivity, and streamline support.
Explore how Cisco DNA Center enables SD-Access assurance and operational insight by centralizing user data, a user 360 view, and application experience to diagnose and resolve daily network issues quickly.
The Deploying Cisco SD-Access (ENSDA) v1.1 course teaches you how to successfully deploy the Cisco® Software-Defined Access (SD-Access) solution in your enterprise network. This advanced-level, instructor-led, lab-based, hands-on course covers SD-Access fundamentals, provisioning, policies, wireless integration, border operations, and migration strategies. The course also discusses how Cisco SD-Access fits into the Cisco Digital Network Architecture (Cisco DNA).
Objectives
Upon completion of this course, you should be able to:
Describe Cisco SD-Access and how it relates to Cisco DNA
Orchestrate a Cisco SD-Access solution using the Cisco DNA Center™ orchestration platform
Use the Network Data Platform to demonstrate the assurance and analytics capabilities of SD-Access
Prerequisites
Before taking this course:
You should have an understanding of network routing and switching principles equivalent to the Cisco CCNA® certification level.
Outline
Cisco SD-Access Overview
Exploring Cisco SD-Access
Describing the Cisco SD-Access Architecture
Exploring Cisco DNA Center
Configuring Underlay Automation
Cisco SD-Access Implementation
ISE Integration in Cisco DNA Center
Policy Provisioning Basics
Navigating and Managing the Policy Application Workflows
Cisco SD-Access Border Operations
Cisco SD-Access Deployment Models
Connecting the Fabric to External Domains
Wireless Integration Orchestration
Integrating Wireless with the Cisco SD-Access Solution
Workflow of Cisco SD-Access Wireless
Cisco SD-Access Wireless Network Design
Cisco SD-Access Wireless Basic Operation
Cisco SD-Access Assurance and Migration
Cisco Network Data Platform
Cisco SD-Access Migration Strategies