Brkewn 2026
Brkewn 2026
Brkewn 2026
BRKEWN-2026
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Introducing Cisco
DNA Center
Cisco DNA Center
Intent-based Automation & Assurance Platform
Cisco DNA Center
Intent based Platform
• Single pane of glass for all devices
• End-to-end health info in real time
Policy Design
• Granular visibility
• Simplified workflows
• Zero-touch deployment
• Device Lifecycle Management
• Policy enforcement
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Cisco DNA Automation
Existing Approach Cisco DNA Approach
Multiple tools for Automation and One Box Solution with closed loop
Assurance
Automation
CMX
DHCP EM
WAN
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
DNA Center Overview ..2
Architecture & Components
DNA Center Cisco AI Cloud
Cisco AI Network
Cisco DNA Automation Cisco DNA Assurance Analytics Engine
Assurance &
Design Provision Policy
Analytics
• Create the structure and Prepare and configure devices Create policies that reflect
• • • Provide proactive and
framework of the network organization's business
• Add devices to sites / site predictive actionable
• The Network settings to locations intent insights
discover your network The policy is translated into
• Assigning devices to the • • Performance and health of
infrastructure network or device specific
inventory the network infrastructure,
• Create device specific configurations applications, and end-user
profiles that can be applied • Deploying the required
• Policies vary based on clients.
throughout the network settings and policies
device types, makes,
• Adding new devices into the • Creating fabric domains, and models, operating systems,
network - Zero touch adding devices to the fabric roles, and resource
deployment constraints
Protocols & APIs (CLI,SNMP, NetConf, JSON, NetFlow, pxGrid...)
CMX
DHCP EM
WAN
DNA Center
Telemetry, alerts,
violations
Assurance and
Automation Analytics
Network inventory,
topology, and
configuration
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Agenda
• Introduction to Cisco DNA Center and C9800 Wireless Controller
• Wireless Automation Workflow with C9800 Wireless Controller
• Planning-Map Innovation (Planned AP/Ekahau Integration)
• Network Settings
• Design Workflow
• Provision Workflow (N+1 HA Provision)
• Day N Changes
• Deployment Models
• Embedded Wireless Controller (EWC) on Catalyst Access Points
• Key Takeaways
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Cisco DNA Center - Automation Principles
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Introduction to
Cisco Catalyst
9800 Series
Controller
Catalyst 9800 Series Wireless Controllers
Translate business intent into network policy and
DNA Center capture actionable insights with DNA Center
Managed by Digitized by
Cisco DNA Center Cisco DNA Spaces
Translate business intent into network policy Digitize people, spaces and things
and capture actionable insights
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Catalyst 9800 - Fastest Ramping Wireless Controller
ENCS
C
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Catalyst Wireless Stack Innovations
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Deploy It the Way You Want It
ENCS
250 APs 1000 APs 2000 APs 3000 APs 6000 APs
• Zero downtime with Software updates • Detect encrypted threats with • Enhanced analytics with
and upgrades Encrypted Traffic Analytics (ETA) Cisco DNA
• WLC SMU
• RF Snapshots, WPA3, • Programmable network processor
• AP Service and Device Pack Trustworthy systems and IOx infra support
• Intelligent Rolling AP Upgrade
• Automated macro and micro • Multi-lingual AP to enable
• Deterministic capacity at scale segmentation with SD-Access enterprise IoT
• Superior battery life for IoT and • Deploy in infrastructure of choice
mobile devices and cloud of choice
Reusability
Easy Provisioning Change Management
Config modularized as
With AP attribute Site based filtering
objects
Tagging
Rule-based Tagging
Simplicity For easy Day 1
No inheritance or configuration
containers
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
AireOS vs. Catalyst 9800 Config Model
Going towards a more Modularized and Reusable model with Logical decoupling of configuration entities Granular & simplified
What Policies on which Sites
with what RF characteristics
Remote Site
Wireless Security RF Parameters DCA, TPC, CHDM
Config
RF Profile
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Catalyst 9800 Config Model
Access Points
RF
Policy
Profile
Profile
5 GHz
Site Tag
AP Join
Profile
Flex
Profile
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Wireless Automation
Workflow with C9800
Wireless Controller
Scenario
A large enterprise is refreshing their wireless infrastructure to C9800 across
multiple sites/buildings. Site B
Business Intent
Site A
Site C
Campus Core
Site F Site H
Site E Site G
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Wireless Deployment Workflow
Profile Mapped to
Site SSIDs and RF
Parameters that
represent wireless
network
Site/Building
AP Mapped to Site
APs inherits the
properties of the Profile
associated to site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Plan
Site Hierarchy & Maps
Cisco CMX
Site
D
WAN/Internet Site I
Sites, buildings,
floors
Campus Core
WLCs
APs Site F Site H
Site E Site G
Switches
Routers
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Export Sites and Maps from Prime Infrastructure
Export Sites Step 2
Step 1
Site.CSV
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Export Sites and Maps from Prime Infrastructure
Export Maps
Step 2
Step 1
Maps.tar.gz
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Position APs on Map – Traditional Way
Critical Part of AP Onboarding Lifecyle
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Position APs on Map – Traditional Way
Critical Part of AP Onboarding Lifecyle
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Position APs on Map – New Way
How to resolve challenges from traditional way?
1. RF Planning - Real AP or Predictive Site Survey 1. RF Planning - Real AP or Predictive Site Survey
to plan AP positions via RF survey tools to plan AP positions via RF survey tools
2. Give a copy of floor plan with AP positions to 2. On Cisco DNA Center, plan AP positions natively
installers for installing APs or import AP position from Ekahau survey tool
3. Installers connect the cables and power on APs. 3. Give a copy of floor plan with AP positions to
installers for installing APs
4. APs join WLC and are discovered by NMS tools
4. Installers connect the cables and power on APs.
5. On NMS tools, network admin drags and drops
APs to positions on map based on the same floor 5. Cisco DNA Center claims APs to desired
plan in step 2. site/controller via PnP and they are shown on
map automatically in planned positions.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Position APs on Map – New Way
Critical Part of AP Onboarding Lifecyle
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Position APs on Map – New Way
Planned APs on Map – Under the Hood
Cisco DNA Center 1.3.1
• Users defined planned APs with name, model, antenna and positions on map.
• When real APs are added into inventory either via discovery or PnP claim,
Cisco DNA Center will match them against planned APs based on AP name,
model and antenna.
• When all matched, APs are put to planned AP positions automatically. The heatmap are
displayed accordingly.
• Otherwise, planned APs stay. Users can manually assign real APs to planned APs if required.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Position APs on Map – New Way
Planned APs on Map – Under the Hood
Cisco DNA Center 1.3.1
There are two options to define planned APs:
In 1.3.1 release, it only support creating planned APs with name, model, antennas and position. It is
NOT predictive RF planning with heatmap.
• Only Ekahau project created in planning mode, not site survey mode.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Position APs on Map – New Way
Planned APs on Map – Under the Hood Cisco DNA Center 1.3.1
To import Ekahau project successfully, follow the rules below:
• Define Network Hierarchy in Cisco DNA Center first.
• Match building and floor names in Cisco DNA Center what are defined in
Ekahau.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Demo - Network Hierarchy and Map with
Ekahau Integration
Design Network
Services
Site A
Site C
Site
D
WAN/Internet Site I
Campus Core
Site F Site H
Site E Site G
Network Services
• AAA (Network and Client)
• DNS, DHCP
• NTP
Monitoring Services
• Syslog
• Traps
• Netflow and Application Visibility
Credentials
• CLI
• SNMP
• HTTP
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Design Network
Configuring Network Settings
New
Infrastructure
Network
Hierarchy
Import Sites /
Maps
Design
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Challenges with Network Services & Credentials
▪ Vary by :
▪ Location
▪ Differences in Network Design
▪ Information often stored in Files - Error
Prone
▪ Day 2 Updates become a challenge
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
AAA/ISE Integration
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
AAA Server - ISE Integration
Objectives and Key Points
• Single pane of management for all AAA/policy administration between
network devices and ISE
• Automate RADIUS/TACACS configuration for network devices.
• Support only one ISE cluster.
• Enable secure services between Cisco DNAC and ISE:
o pxGrid Service to pull the info out of ISE (Uni-Directional)
Obtain TrustSec metadata such as SGT, IP-SGT mappings & TrustSec policy.
o ERS (External RESTful Services) APIs - Bi-Directional Communication
▪ Fetch deployment model from ISE, such as PAN and PSN info
▪ Add devices to ISE as network devices
▪ Create SGT, IP-SGT mappings & TrustSec policy on ISE
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
AAA Server - ISE Integration
Pre-Requisites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
AAA Server - ISE Integration
Add ISE in DNA-C
Shared secret
between ISE and
devices for TACACS
or Radius
Policy Preview
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
AAA Server - (Non-ISE) Integration
Key Points:
• Non-ISE server definition:
• ISE running 2.2 or below
• ACS or any third-party AAA Server
• Only automate RADIUS/TACACS
configuration for network devices
• Require to add network devices to AAA
clients manually.
• Can have multiples non-ISE AAA servers
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Network Settings
AAA Settings
TACACS
Policy Service
Node
Policy Admin
Node
RADIUS
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Demo - Network Settings
What did we do so far?
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Design Network
Profile for Wireless
Associate AP to AP Groups
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Problem with this approach
Need to manually manage the mapping of AP to AP
Groups
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Network Deployment using Profiles
WAN/Internet
Site D Site I
Campus Core
Site H
Site E Site F Site G
Services
• SSID
• Guest Network 70%-80% of the WLC
• RF Profiles Config or more
• Deployment mode
Services
(Intent)
Named Capabilities
• Clean Air
• 11k
• 11v
Advanced 20%-30% of the
Capabilities WLC Config or less
CLI Templates
• Customized Features
• Cisco Best Practice Out of the
box
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Wireless Network Profile - Composition View
• Device Credentials
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Wireless Profile - Design Workflow
Assign
Define
Define Define Create CLI Wireless
Create Wireless
Network Wireless Templates Network
Sites Network
Settings Settings (Optional) Profile to
Profile
Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Design- Wireless Settings
SSIDs
Based on best practices
Wireless Interfaces
Map dynamic interface
to VLAN
RF Profiles
Based on best Practices
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Design- Define Wireless Settings
Create Sites
Define Network
Settings
Define Wireless
3 Settings
Create
Create Templates Enterprise
(Optional)
Wireless SSID
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Design- Wireless Settings
Advanced Parameters in SSID Supported in Cisco DNAC 1.3
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Design - Define Wireless Settings
Create Sites
Create
Define Network Wireless
Settings Interfaces
Define Wireless
3 Settings
Create Templates
(Optional)
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Design - Define Wireless Settings
Create Sites
Define Network
Settings
Define Wireless
3 Settings
Create RF
Create Templates
(Optional) Profile
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Design - Create Templates
Create Sites
Define Network
Settings
Create Project
Define Wireless
Settings
and Template in
“Template Editor”
Create Templates
4 (Optional)
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Design - Create Templates
Create Sites
• Cool programming-like template view for copy/paste and editing.
• Template engine is based on Apache Velocity engine.
Define Network • Use “$” sign to define variable.
Settings
Define Wireless
Network Profile
variable
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Design - Create Templates
Form View
Create Sites
• Define detailed info of variable in “Input Form” view.
• Default value of variable will auto populate for user during provisioning.
Define Network
Settings
Define Wireless
Settings
Create Templates
4 (Optional)
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Design - Create Templates
Create Sites
4
Create Templates • Save
(Optional)
• Writable version of template on Cisco DNA Center
• Can not be used for provisioning
Define Wireless
Network Profile
• Commit
• Once committed, it becomes read-only
Assign Wireless
Network Profile to Sites • Can commit multiple times to create multiple versions of template
• Only latest commit version can be used for provisioning
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Design - Define Wireless Network Profile
Create Sites
Define Network
Settings
Define Wireless
Settings
Create Templates
(Optional)
Define Wireless
5 Network Profile
Assign Wireless
Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Design - Assign Wireless Network Profile to Sites
Create Sites
Define Network
Settings
Define Wireless
Settings
Create Day-N
Templates (Optional)
Define Wireless
Network Profile
Assign Wireless
6 Network Profile to Sites
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Demo – Design
1. Create Wireless Profile with Enterprise SSID
2. Assign Wireless Profile to Site
What did we do so far?
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Provision
Site A
Cisco Site C
DNA Center
Wireless
LAN Site
controller D
WAN/Internet Site I
Access
Points Campus Core
Site F Site H
Site E Site G
APs Discover
Provision
Discover WLC Cisco DNAC Provision APs
WLC to Site
via PnP
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Provision - Discover WLC
Provision WLC to
• SSH and NETCONF are enabled
Site
• CLI Login Credentials
• Wireless Management Interface
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Provision - Discover WLC
Provision WLC to
Site
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Provision - Discover WLC
Provision APs to
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Provision - N+1 HA WLCs
• Ensure APs are provisioned with correct primary and secondary WLCs.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Provision - N+1 HA WLCs
▪ The same wireless profile is applied to both primary and secondary WLCs.
▪ “Secondary Managed AP Locations” concept is introduced during WLC provision in 1.3.
▪ WLC that assigned to be sites with “Secondary Managed AP Locations” acts as
secondary WLC for all APs on that site.
▪ Can not provision secondary WLC to a site if there is no primary WLC assigned to it.
▪ Claiming APs to a site will provision APs with primary and secondary WLC automatically.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Provision - Provision WLC to Site Define Primary and
Secondary WLCs
Primary WLC for BLDG3
Discover WLC
Provision WLC to
2
Site
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site Secondary WLC for BLDG3
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Provision - Provision WLC to Site Define Mobility, RF
Groups
Discover WLC
Provision WLC to
2
Site
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site Note that you only need to define mobility and RF groups, and mobility peers on primary WLC. Cisco DNA
Center will configure mobility peering automatically between mobility peers. Also set the same mobility and
RF groups between them.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Provision - Provision WLC to Site
Discover WLC
Provision WLC to
2
Site
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Provision - Provision WLC to Site On C9800 Wireless Controller
• Country Code
• WLAN and Policy Profiles
• Network Settings: • Mobility and RF Groups
TACACS, Radius, SNMP,
Syslog, DHCP, DNS, NTP
and etc.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Provision - Provision WLC to Site
On C9800 Wireless Controller
WLAN
Profile
Policy
Profile
wlan profile
name and
policy profile
name are the
same
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Provision - Provision WLC to Site
On C9800 Wireless Controller
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Provision - Provision WLC to Site
On ISE
Discover WLC
Provision WLC
2 to Site
Provision APs
to Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Demo- WLC Provisioning
What did we do so far?
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Provision Workflows
APs Discover
Discover Provision Provision
Cisco DNAC
WLC WLC to Site APs
via PnP
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Provision Workflow - AP
Option 1- Unclaimed Workflow Option - 2
Provision AP
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Provision Workflow - AP PnP Discovery
Cisco
DNAC IP Cisco DNA Center
Option 43
5A1D;B2;K4;I192.168.139.151;J80
SSL
AP
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
PnP Server Discovery Options
Routers
DHCP with option 43 (ASR, ISR)
1 PnP string: 5A1D;B2;K4;I172.19.45.222;J80 added to DHCP Server
Wireless
Automated
Access Points
DNS lookup
2
pnpserver.localdomain resolves to DNA Center IP Address
Switches
(Catalyst®)
3 Redirect
Cloud re-direction https://devicehelper.cisco.com/device-helper
Cisco hosted cloud, re-directs to on-prem DNA Center IP Address
USB-based bootstrapping*
4 router-confg/router.cfg/ciscortr.cfg Manual discovery
Manual
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Provision- Provision APs to Site
Option -1
Discover WLC
Provision WLC to
Site
Provision APs to
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Provision- Provision APs to Site
Option -1
Discover WLC
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Provision- Provision APs to Site
Option -1
Discover WLC
Provision WLC to
Site
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Provision- Provision APs to Site
Provision WLC to
Site
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Provision- Provision APs to Site
Sample AP Console Log
Discover WLC
Provision WLC to
Site
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Provision- Provision APs to Site
Provision WLC to
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Provision- Provision APs to Site
Provision WLC to
Site
Provision APs to
4
Site
AP is added to inventory and assigned to the desired floor.
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Provision- Provision APs to Site
Cisco DNA Center
Map
Discover WLC
Provision WLC to
Site
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Provision- Provision APs to Site
On C9800 Wireless Controller
Discover WLC
Provision WLC to
Site
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Provision- Provision APs to Site
Provision APs to
4
Site
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Option - 2 : Bulk AP Deployment
1 Import APs
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Option - 2 : Bulk AP Deployment
2 Prepare AP Bulk Import CSV and Upload
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
Option - 2 : Bulk AP Deployment
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Demo - AP Provisioning
What did we do so far?
Planned the Sites & Hierarchy
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
• Network Profiles are mapped to Sites and
Site becomes the glue for Automation
• Configuration Standardization & Compliance
Summary using Network Profiles
• Automated Policy, Site and RF tags creation
for AP Onboarding.
• APs are placed to planned position
automatically. No more waiting!
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Day 2 Changes
Configuration
Changes
Scenario – Day N Configuration Changes
Provision wireless LAN controllers and access points across sites
Site B
Site A
Site C
Site
D
WAN/Internet Site I
Campus Core
Site F Site H
Site E Site G
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Network Profile Lifecycle
1
UPDATE
PROFILE (v1) PROFILE (v2)
Mismatch
with Profile
2
3
Compliance mismatch
of v1 and v2
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Wireless Profile - Day 2 Changes
V1 of the
Profile
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
IRCM for Guest Anchoring
User Case:
Inter-Release Controller Mobility (IRCM) is critical for mobility roaming and guest
anchoring. With introduction of C9800 IOS-XE WLC, Cisco DNA Center can simplify
both green-field deployment and integration with AireOS WLC, starting guest
anchoring support from 1.3 release.
Foreign Anchor Cisco DNA Center Support
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
IRCM for Guest Anchoring
Key Points
• Only one wireless profile required for both Foreign and Anchor WLCs
• In wireless profile, there is at least one SSID required to be specified as guest anchoring
• For Foreign WLC, Cisco DNA Center provision all SSIDs in the profile
• For Anchor WLC, Cisco DNA Center will deploy only guest anchor SSID in profile based
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
IRCM for Guest Anchoring
Workflow
Design Provision
Provision
Design Guest Provision Anchor
SSID Foreign WLC WLC
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Day 2 Example- IRCM Guest Anchoring
Design Guest SSID C9800s as both
Foreign and Anchor
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 123
Day 2 Example - IRCM Guest Anchoring
Design Guest SSID C9800s as both
Foreign and Anchor
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 124
Day 2 Example - IRCM Guest Anchoring
Provision Foreign WLC(s) C9800s as both
Foreign and Anchor
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 125
Day 2 Example - IRCM Guest Anchoring
Provision Foreign WLC(s) C9800s as both
Foreign and Anchor
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 126
Day 2 Example - IRCM Guest Anchoring C9800s as
Provision Anchor WLC(s) both Foreign
and Anchor
Wireless interface
created on anchor WLC
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 127
Day 2 Example- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 128
Day 2 Example - IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
Why?
• Enable guest WLAN and
create anchor
configuration on foreign
WLC
• Create guest WLAN and
anchor configuration
• Create mobility peers on
both foreign and anchor
WLCs
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 129
Day 2 Example- IRCM Guest Anchoring
Provision Anchor WLC(s)
C9800s as both
Foreign and Anchor
On Anchor
What else in WLAN?
• Webauth Parameter Map
• Authentication List
• Preauthentication ACL
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 130
Day 2 Example - IRCM Guest Anchoring
Provision Anchor WLC(s)
C9800s as both
Foreign and Anchor
On Anchor
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 131
Day 2 Example - IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
it is enabled now.
On Foreign
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 132
Day 2 Example - IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
Anchor to Anchor
C9800
On Foreign
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 133
Day 2 Example - IRCM Guest Anchoring
Provision Mobility Peers C9800s as both
Foreign and Anchor
On Anchor
Foreign WLCs
Anchor WLC
On Foreign
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 134
Demo- Day 2
Implement Foreign and Anchor Guest Solution
Deployment
Models
Same Workflows for Different Wireless Branch
Deployments
Configure
Centralized
Set up
Flex Connect EWC/ME
Operate Catalyst 9800
From a web
browser or Cisco Controller Next Gen Wireless
Eliminate the need
Ease of Deployment
wireless app, useand Functionality Stack
for a Controller at
management
the setup wizard Embedded in the
every Site
to enable multiple Access Point
APs
simultaneously
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 137
Embedded Wireless
Controller on
Catalyst Access
Points
EWC on Cisco Catalyst Access Points
Ready for enterprise deployments
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 139
EWC on Cisco Catalyst 9100 Access Points
Ideal for single or multisite small to medium- Mission critical Best in class
sized enterprise deployments Best suited for high-density enterprise branch deployments
Powered by Powered by
Cisco RF ASIC Cisco RF ASIC
Software feature parity Supports up to 100 APs, Supports Wave 2 APs as Cisco DNA Assurance
across APs 2000 clients client serving with ICAP
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 140
EWC Automation Key Points
• EWC Release 16.12.2 and above • EWC Day-0 templates via PnP
• Cisco DNA Center Release 1.3.3 • EWC Image upgrade via PnP
• Profile-based Design and Provision
• For PnP, support only EWC APs
running on the same AP base
image
• Only Day-N CLI Templates
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 141
EWC Design Workflow
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 142
EWC Onboarding Workflow
• DHCP Option 43 or DNS • Part 1- PnP Claim • Provision Day-N CLI On EWC:
for EWC to discover Cisco Device Credentials of Profile Template(s) (Optional)
• • Create native VLAN and
DNA Center
• Management IP and Default WLAN to VLAN mappings
• Switch port connecting to GW in default flex profile
EWC should be trunk with Hostname
• • Create policy and RF tags
management VLAN of
EWC as native VLAN • Part 2- Add to Inventory • Assign policy and RF tags
• Network Settings of Profile to APs
• Only master EWC AP will
call home to Cisco DNA • Enable wireless assurance
Center in case of multiple Remove day-0 default EWC
• On Cisco DNA Center:
EWCs config (e.g. day-0 banner,
webui login, • Place EWC APs on map
CiscoAirProvision SSID)
• SSIDs of Profile
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 143
Software Image
Upgrade (SWIM)
Core Principles of Software
Upgrade with DNA Center
1 2 3
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 145
Software Upgrade Process
Request
Software
Update
Identify
Close CR Golden
Image
Post Select
Deploy Devices
Validations
Activate Create
Software CR
DNA Center
NMS Software
Distribute Approve
Software CR
PreCheck
Validations
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 146
DNA Center - Software Update Workflow
System
Define Golden Pre-Check
Identifies Software Post Upgrade
Image by Validation for
Devices not in Upgrade Validation
Device Family Disk/Memory
compliance
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 147
Defining Golden Image
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 148
SMU (Software Maintenance Upgrade)
What is SMU ?
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 149
Use Case: Upgrading AP’s in a
Staggered way to achieve Zero Down
Time of the Network.
Rolling AP Upgrade
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 150
Rolling AP Upgrade – RRM Based Candidate AP
Selection
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 152
N+1 Rolling AP Upgrade AP
Trigger Rolling
Upgrade
X
Version : X+1 Mobility Group Version: X+1
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 153
Rolling AP Upgrade Workflow prerequisites
▪ Making N+1 WLC is Ready : The N+1 WLC should be running the same configuration as the
Primary WLC in terms of the WLANs and policies. For this reason, the config design of
primary WLC should be replicated on the N+1 WLC as a first step.
▪ Mobility Tunnel : The Primary WLC and N+1 WLC should be part of same Mobility Group and
the Mobility Tunnel should be UP between the two before initiating the Rolling AP upgrade
process
▪ N+1 WLC should be running on Golden image before starting the Rolling AP upgrade.
▪ The Rolling AP Upgrade workflow is Only Supported with Catalyst 9800 Wireless Controller
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 154
Rolling AP Upgrade Workflow
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 155
Rolling AP Upgrade Workflow
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 156
Rolling AP Upgrade Workflow
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 157
Rolling AP Upgrade Workflow
▪ Once the upgrade process started,
Rolling AP Upgrade will get triggered and
AP’s will be upgraded In a staggered way
based on the AP reboot percentage
provided.
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Demo - SWIM
Manage Software Images
❖ Import Images/SMU
from :
▪ URL(http/ftp)
▪ Local PC
▪ cisco.com
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 160
Image Standardization - “Golden Images”
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 161
Devices not Compliant with Golden Image
Built-in
Compliancy
checks to
Automatically
flag devices
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 162
SMU (Software Maintenance Upgrade)
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 163
SWIM/SMU Workflow Experience with DNA Center
1
Select device/(s) to
1 update Image/SMU
▪ Automatic Pre-
2 Checks done for
RAM & Flash
▪ Abort if Pre-Check
Fails
2
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 164
SWIM/SMU Workflow Experience with DNA Center
3
3 ▪ Detailed status information
regarding the Upgrade
Process
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 165
DNA Automation / Assurance driven events or
issues translate into ITSM events
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 166
ITSM Event spawns off a problem depending on
impact and user defined criteria
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 168
▪ Software Images are mapped to Sites
▪ Extremely simplified upgrade process
▪ Upgrade with Confidence - Integrate with
YOUR Pre-Check/Post-Check scripts
▪ Closed Loop Automation for Software
Images Upgrades
Summary
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 169
Key Takeaways
Key Takeaways
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 171
Opening Keynote 09:00 MOB
Mobility Track
BRKWEN-2028
Meraki Wireless 11:15
under the hood
BRKEWN-2006
Advancements in 14:30 BRKEWN-2014
Wireless Security Be my guest! - 14:45
Design and Deploy
Wireless Guest
Access that Works
BRKEWN-2005 Guest Keynote 17:00
Securely Designing 17:00
Your Wireless LAN Cisco Live
for Threat Mitigation, Celebration 18:30
Policy and BYOD
Security
#CLEMEA
TUESDAY WEDNESDAY THURSDAY FRIDAY
Keynote 09:30
08:30
08:30
11:00 BRKWEN-2028
Meraki Wireless 11:15
under the hood
11:00
09:00
BRKEWN-2006 14:45
Advancements in 14:30 BRKEWN-2014
Wireless Security Be my guest! - 14:45
Design and Deploy
Wireless Guest 16:45
Access that Works 11:30
BRKEWN-2005 16:45 Keynote 17:00
Securely Designing 17:00
Your Wireless LAN Customer
for Threat Mitigation,
MOB
Appreciation 19:00
Policy and BYOD
Security #CLEMEA
Mobility Track
Opening Keynote 09:00
MOB
BRKEWN-3010
BRKEWN-3010
Cisco Catalyst RF 08:30
Mobility Track
Cisco Catalyst RF 11:00 Innovations, WiFi6 and
Innovations, WiFi6 Beyond!
and Beyond!
BRKEWN-2017
BRKEWN-2017 RF Fundamentals 14:45
RF Fundamentals 14:30 from WiFi to WiFi6
from WiFi to WiFi6 (11ax) Wireless
(11ax) Wireless Networks
Networks
BRKEWN-2439
7 New ways to Fail as 16:45 Guest Keynote 17:00
a Wireless Expert...
Cisco Live
Celebration 18:30
RF
Optimization
#CLEMEA
TUESDAY WEDNESDAY THURSDAY FRIDAY
Keynote 09:30
08:30
BRKEWN-3010
BRKEWN-3010 Cisco Catalyst RF 08:30
Cisco Catalyst RF 11:00 Innovations, WiFi6 and
Innovations, WiFi6 Beyond! 11:00
and Beyond!
11:00
BRKEWN-2017 09:00
BRKEWN-2017 RF Fundamentals 14:45
RF Fundamentals 14:30 from WiFi to WiFi6
from WiFi to WiFi6 (11ax) Wireless
(11ax) Wireless
14:45
Networks BRKEWN-2013
High Density Wi-Fi
Networks 16:45
Design, Deployment, 11:30
BRKEWN-2439 and Optimization
7 New ways to Fail as 16:45 Keynote 17:00
17:00 a Wireless Expert...
Customer
Appreciation 19:00
MOB
RF Optimization Mobility Track
#CLEMEA
Opening Keynote 09:00 MOB
LTREWN-2673
Lab: Build your 09:30 BRKEWN-2026
Mobility Track
Wireless Network Wireless Network 11:15
Programmability & Automation with
Telemetry solution Cisco DNA Center
from scratch! BRKEWN-2033
Next generation Wifi 14:45
Networks enhanced
with Cisco DNA
Analytics and
Machine Learning
BRKEWN-2034
Cisco DNA Wireless 16:45
BRKEWN-2050 Assurance: Isolate Guest Keynote 17:00
Telemetry and 17:00
problems for faster
Programmability in Cisco Live
troubleshooting
the Next Generation Celebration 18:30
Wireless Stack
Management,
Analytics &
Assurance
#CLEMEA
TUESDAY WEDNESDAY THURSDAY FRIDAY
Keynote 09:30
08:30
LTREWN-2673
Lab: Build your 09:30 BRKEWN-2026
Wireless Network Wireless Network 11:15
Programmability & Automation with
Telemetry solution Cisco DNA Center
from scratch! BRKEWN-2033 09:00
Next generation Wifi 14:45
Networks enhanced 14:45
14:30 with Cisco DNA
Analytics and
Machine Learning
16:45
BRKEWN-2034 11:30
Cisco DNA Wireless 16:45
BRKEWN-2050 Assurance: Isolate Keynote 17:00
Telemetry and 17:00
problems for faster
Programmability in Customer
MOB
troubleshooting
the Next Generation Appreciation 19:00
Wireless Stack
Services
#CLEMEA
MONDAY TUESDAY WEDNESDAY
Keynote 09:30
08:30
LABEWN-2127
Walk in Lab: Every day
11:00 Integration of DNA
Spaces with Aironet 11:00
and Catalyst Based
wireless networks
MOB
Services Mobility Track
#CLEMEA
Opening Keynote 09:00 BRKEWN-2003
Optimize your WLANs 08:30
MOB
LABEWN-1098
Walk in Lab: IOS-XE
BRKEWN-2670
Every day Introduction to Cisco 08:30
for Small and Mobile
Devices (Phones,
Mobility Track
Embedded WLC on Catalyst 9800 Tablets and alike)
AP 9100 series Wireless Controller
LABEWN-1038 BRKEWN-2020
Walk in Lab: Migrate Every day Cisco SD-Access 11:00 BRKEWN-2027
from AireOS to Wireless Integration Design and 09:00
Cat9800 (IOS-XE) Deployment of
Outdoor Wireless
BRKEWN-2016 Networks
BRKEWN-2010 Design and Deployment 14:45
Introduction to Next 11:00 of Wireless for Branch
Generation Wireless and Remote Offices
Stack
MOB
Lab on Catalyst
Wireless 9800 18:30 Appreciation 19:00
Controllers
BRKEWN-2480
Plan, design and 16:45
troubleshoot your Cisco
DNA driven 9800 WLC
wireless network: Best Guest Keynote 17:00
Practices and lessons
Cisco Live
learnt from the field
Celebration 18:30
Troubleshooting
#CLEMEA
TUESDAY WEDNESDAY THURSDAY FRIDAY
Keynote 09:30
08:30
LABEWN-1505 08:30
Cisco 9800 Controllers Every day
- Understanding, 11:00
deploying and BRKEWN-3011 BRKEWN-3013
troubleshooting Advanced 11:00 Advanced Troubleshooting
Troubleshooting of BRKEWN-2809 of Cisco Catalyst 9800 09:00
Wireless LANs The Final Fails. 6 for 14:45 Wireless Controller
14:30 (WiFi) 6
BRKEWN-2480
Plan, design and 16:45 16:45
troubleshoot your Cisco 11:30
DNA driven 9800 WLC
wireless network: Best Keynote 17:00
17:00
Practices and lessons
Customer
MOB
learnt from the field
Appreciation 19:00
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 184
Continue your education
Demos in the
Walk-in labs
Cisco campus
BRKEWN-2026 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 185
Thank you