BRKCRS 2825
BRKCRS 2825
BRKCRS 2825
Scott Hodgdon
Senior Technical Marketing Engineer
BRKCRS-2825
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Who is Scott ?
Personal
• Based in Raleigh, NC (US)
• 19-year-old daughter in university (she’s smarter than I)
Career
• 19 years as a Technical Marketing Engineer
• 13 Years focused on just Catalyst 6K Family
• 15 years as a Cisco Live Speaker
• 9 years as Cisco Live Session Group Manager for US and EMEA
• 2 Years as a Cisco Partner SE
• 2 Years Lead Network Engineer for 15-site Health Care network
in North Carolina
• No formal technology schooling … I have a Business Degree with
a Finance Concentration
Current Focus
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Session Goals
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Agenda
• Introduction to Cisco SD-Access
Fabric Roles and Constructs
• Scaling the fabric in a single site
Vertical scaling of fabric end points , Cisco DNA Center (for
automation and assurance) and Cisco ISE (for policy)
• Deploying Cisco SD-Access in small branches/sites
Collapsed fabric roles ( Border + edge + control plane + WLC )
• Scaling the fabric across multiple sites
Expanding the fabric across multiple metro/WAN regions
Horizontal scaling of fabric end points , Cisco DNA Center (for
automation and assurance) and Cisco ISE (for policy)
• Cisco SD-Access fabric across Geographical Locations ( Design Overivew)
• Conclusion
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Fabric Roles and
Constructs
Cisco SD-Access
Fabric Roles & Terminology
Cisco DNA Cisco DNA Automation – provides simple
GUI management and intent based
Identity NCP Automation
automation (e.g. NCP) and context sharing
Services
ISE NDP Cisco DNA Assurance – Data Collectors
Cisco DNA (e.g. NDP) analyze Endpoint to App flows
Cisco DNA
Center Assurance and monitor fabric status
Identity Services – NAC & ID Systems
(e.g. ISE) for dynamic Endpoint to Group
Fabric Border Fabric Wireless mapping and Policy definition
Nodes Controller
B B Control-Plane Nodes – Map System that
manages Endpoint to Device relationships
Intermediate Control-Plane
C Nodes Fabric Border Nodes – A Fabric device
Nodes (Underlay) (e.g. Core) that connects External L3
network(s) to the SDA Fabric
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Cisco SD-Access Fabric
Control-Plane Nodes – A Closer Look
B B
• Host Database supports multiple types of Endpoint
ID lookup types (IPv4, IPv6 or MAC)
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Cisco SD-Access Fabric
Control-Plane Nodes – Scale Considerations
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Cisco SD-Access Fabric
Edge Nodes – A Closer Look
Edge Node provides first-hop services for Users / Devices connected to a Fabric
B B
• Register specific Endpoint ID info (e.g. /32 or /128)
with the Control-Plane Node(s)
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Cisco SD-Access Fabric
Border Nodes
Border Node is an Entry & Exit point for data traffic going Into & Out of a Fabric
B B
• Rest of Company/Internal Border Used for
“Known” Routes inside your company
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Cisco SD-Access Fabric
Border Nodes – Rest of Company/Internal
B B
• Exports all internal IP Pools to outside (as
aggregate), using a traditional IP routing protocol(s).
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Cisco SD-Access Fabric
Border Nodes – Outside World/External
B B
• Exports all internal IP Pools outside (as aggregate)
into traditional IP routing protocol(s).
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Cisco SD-Access Fabric
Border Nodes – Outside World/External
Anywhere/ Internal + External Border is a “One all exit point” for any known
and unknown destinations
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Cisco SD-Access Fabric
Border Nodes – Scale Considerations
Border Node is an Entry and Exit point for data traffic going Into and Out of a
Fabric
• Each fabric site supports a maximum of four Outside
World / External Border nodes. C
Known Unknown
Networks Networks
• Each fabric site supports a maximum of four outside B B
Anywhere / Internal+ External Border nodes.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Scaling the fabric
in a single site
General Scaling Strategy for Network Designs
How do I achieve higher scale?
• Using larger capacity devices / platforms to • Using more devices to achieve higher scale.
achieve higher scale.
• Multiple devices can aggregately provide
• Larger capacity devices provide more control greater control and data plane scale.
plane as well as more data plane scale.
• Distributed model of scaling.
• Centralized model of scaling.
• Using multiple C9400’s as core platform or
• Using an C9600 as a core platform or an using C9300’s as BGP route reflector etc.
C9500 as a BGP route reflector etc.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Scaling Strategy for Cisco SD-Access Networks
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes and wireless
and wireless controller to achieve scale for controllers to achieve scale for the fabric
the fabric infrastructure. infrastructure.
• In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
• Using a larger Cisco DNA Center appliance to higher scale in this model we have to split a single fabric
achieve higher automation and assurance site into multiple sites.
scale for fabric.
• Using multiple clusters of Cisco DNA Center
• Using a larger ISE node to achieve higher appliances to achieve higher automation and
scale for authentications and policy. assurance scale for fabric.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Scaling Strategy for within a Fabric Site
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless control to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliance to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE Node’s and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Scaling Strategy for Cisco SD-Access Networks
CP redundancy for equivalency and not scale
Border
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Scaling Strategy for Fabric within a site
Design for a small size fabric site
Key Decision Points
Cisco DNAC
DC 1 NCP + NDP
Cluster
ISP
ISE
1 PAN + PXG
Internet
• Tends to be Building or Office
+ PSN
DDI
IP
with < 1000 endpoints and
1 DHCP + DNS
+ IPAM
• 1-2 Collocated CP +
CP EB CP EB
External Border (Single Exit)
Site
• Tends to be local WLC
connected to Border
+ SD-Access Wireless
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Scaling Strategy for Fabric within a site
Design for a medium size fabric site
Key Decision Points
Cisco DNAC
DC 3 NCP + NDP
Cluster
ISP
ISE
2 PAN + PXG
Internet
• Tends to be Multiple Buildings
2 PSN
DDI
1 DHCP + DNS
1 IPAM IP with < 10,000 endpoints and
< 250 IP Pools/Groups
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Scaling Strategy for Fabric within a site
Design for a Large size fabric site
DC
Cisco DNAC
5-7 NCP + NDP
Cluster
WAN ISP Key Decision Points
ISE
DDI
1 DHCP 1 DNS
1 IPAM Internal External with < 25,000 endpoints and
< 500 IP Pools/Groups
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Scaling Strategy for Fabric within a Site
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless controller to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
SD-Access Platforms
For more details: cs.co/sda-compatibility-matrix
The Channelco®
NEW
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
SD-Access Platforms
For more details: cs.co/sda-compatibility-matrix
NEW
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
SD-Access – CP Scale
ASR1K
Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Nexus or CSR1K
Scale
3850(XS) 9300 9400 9500 9500H 9600 6800 N7700 ISR4K V
Control- 200K
Plane (16GB)
3K 16K 80K (XL) 80K 150K 150K 50K N/A 200K
(LISP) 100K
Entries (8GB)
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
SD-Access – Border Scale
ASR1K
Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Nexus
Scale or CSR1KV
3850(XS) 9300 9300L 9400 9500 9500H 9600 6800 N7700
ISR4K
Virtual
64 256 256 256 256 256 1K 500 500 4K 4K
Networks
IPv4 Fabric 4M
1M (XL)
Routes (16GB)
8K 8K 8K 80K (XL) 48K 48K 200K 256K 500K 200K
(LPM 1M
(LE)
IP/mask) (8GB)
4M
IPv4 Host 1M (XL)
(16GB)
Entries 16K 16K 16K 80K (XL) 80K 150K 150K 512K 32K 100K
1M
(Host /32) (LE)
(8GB)
IPv4:SGT
12K 10K 10K 40K 40K 40K 200K 256K 200K 750K 750K
Bindings
SGT/DGT
4K 8K 8K 8K 8K 16K 32K 30K 16K 64K N/A
Policies
SGACEs
30K (XL)
(Contract 1500 5K 5K 18K 18K 13K IPv4 27K 128K 64K N/A
12K (LE)
Actions)
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
SD-Access – Edge Scale These are 1D numbers
Catalyst
Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst
Scale 4K
3650 3850 9200L 9200 9300 9300L 9400 9500
(Sup8/9E)
Virtual
64 64 1* 4* 256 256 64 256 256
Networks
Local End
2K 4K 2K 4K 4K 4K 4K 4K 4K
Points/Hosts
IPv4:SGT
12K 12K 8K 10K 10K 10K 128K 40K 40K
Bindings
SGT/DGT
4K 4K 2K 2K 8K 8K 2K 8K 8K
Policies
SGACEs
(Contract 1350 1350 1K 1K 5K 5K 64K 18K 18K
Actions)
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Scaling Strategy for Fabric within a site
Wireless Controller Design
Active Standby
Scale remains same
Client updates
SSO pair
Control Plane redundancy is supported
in Active / Active configuration
C C
B
WLC is configured with two CP nodes
with information sync across both
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
SD-Access – WLC Scale
Number of end
Platform Number of AP’s SDA Design
points
3504 150 3000 Small
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Scaling Strategy for Fabric within a site
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless controller to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Scaling Strategy for Fabric within a site
Cisco DNA Center Scale
Parameters DN2-HW-APL DN2-HW-APL-L DN2-HW-APL-XL
Number of Devices 1000 2000 5000
(Switch/Stack, Router, WLC)
Number of Access Points 4000 6000 12000
Number of Endpoints (Concurrent) 25,000 40,000 100,000
Number of Endpoints (Unique/Transient) 75,000 120,000 250,000
over 14 days
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Scaling Strategy for Fabric within a site
Cisco DNA Center Scale – Cisco SD-Access Focus
Parameters DN2-HW-APL DN2-HW-APL-L DN2-HW-APL-XL
Number of Fabric Domains 10 20 20
* If any DNAC scale item (e.g. Endpoints) gets max out in single site, then it cannot be scaled more by adding another site.
** Cisco DNA Center Release 1.3.1.0 supports tracking upto only 1.2 million separate interfaces on the fabric devices.
Interfaces include physical and virtual interfaces, like switched virtual interface, loopback, Dot1Q, tunnel and so on.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Scaling Strategy for Fabric within a site
Cisco DNA Center Design- Where to Locate it ?
Internet Internet
DC
Metro
1 or 3 appliance HA Cluster
- Odd number to achieve quorum
of distributed system
- Scale does not change
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Scaling Strategy for Fabric within a site
Cisco DNA Center Design- Three Node High Availability
Users can choose to deploy Cisco DNA Center as a single node or 3-node cluster.
3-node cluster deployment is for redundancy and to mitigate the split-brain problem.
node
Things to Remember:
• 2-node DNAC cluster cannot withstand a node failure
• A one node crash will lead to a stall of the other node
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Scaling Strategy for Fabric within a site
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless controller to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Scaling Strategy for Fabric within a site
Cisco ISE Scale
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Scaling Strategy for Fabric within a site
Cisco ISE Scale
PSN
PXG
PSN PSN
Primary Secondary
PxGrid PXG PXG PxGrid
Controller Controller
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Scaling Strategy for Cisco SD-Access in a site
Summary
Vertical Scaling
• Higher Capacity control plane node can provide higher number of end points in a fabric
site.
• Corresponding higher capacity WLC controller needs to be used if wireless end points are
present in the fabric.
• Higher core Cisco DNAC appliance can provide higher scale for automation and assurance
in fabric.
• Larger ISE appliance/VM can provide policy and authentication for higher number of end
points in a fabric site.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Deploying Cisco
SD-Access in
small
branches/sites
Strategy for Cisco SD-Access in a small site
Design for a very small site
Cisco DNAC
DC 1 NCP + NDP
Cluster
ISP
ISE
1 PAN + PXG
+ PSN Internet
DDI
1 DHCP + DNS
+ IPAM IP Reduces cost to deploy
SDA for “mini” sites
Site
CP EB
FE + FB + CP + wireless on C9K
FE WLC
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Strategy for Cisco SD-Access in a small site
Design for a very small site
Catalyst Supported SKU
9300 All
9500 12Q, 24Q, 16X, 24X, 40X, 48X
Distributed
Enterprise
Campus
Branch
c c
Fabric Edge
c WAN Transit
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Strategy for Cisco SD-Access in a small site
Design for a very small site
Remote Site1 Remote Site 2 Remote Site N
DC 5-7 NCP +
NDP
Cluster
ISE
DDI
1 DHCP 1
DNS
1 IPAM
AB AB EB EB
Site HQ
CP CP
HQ Campus
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Scaling the fabric
across multiple
sites
Scaling Strategy across Multiple Sites
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless control to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
General Scaling Strategy for Network Designs
How do I achieve higher scale?
Basic Goal is for fewer, larger Fabric Sites Some Needs require split into Multiple Sites
S S
Large Transit
Medium M
Small L
S
S
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless control to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Scaling Strategy across Multiple Sites
Why multiple sites ?
Advantages:
Smaller or isolated Failure Domains
Cisco DNA Center provides Automation and Single View of entire system
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Scaling Strategy across Multiple Sites
Multi Site Design
Transit
C C
B B B B
Fabric Fabric
Site 1 Site 2
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Scaling Strategy for Fabric across Multiple Sites
Control Plane Scale
Transit B
B
B B WAN/Metro
B
C C C C
• This will help scale the number of end points in the network CP
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Scaling Strategy for Fabric within a site
Control Plane nodes scale
ASR1K or
Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Catalyst Nexus
Scale ISR4K CSR1KV
3850(XS) 9300 9400 9500 9500H 9600 6800 N7700
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Transit Connectivity
Why IP Based Transit?
Cloud
Data Center • Customers already using existing WAN
or have adopted SD-WAN
• Unable to carry VXLAN header in WAN
• Higher latencies because sites are in
LTE
different regions
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Scaling Strategy for Fabric across Multiple Sites
Design for a multi site with IP Transit
Remote Branch 1 Remote Branch 2 Remote Branch N Key Decision Points
Site BN
• Tends to be many remote
Site B1 Site B2
B E C
branch offices connected
via traditional IP WAN/MPLS or
SD-WAN
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Transit Connectivity
Why SD-Access Transit?
Cloud
Data Center • Customers have multiple sites connect
via “Dark Fiber” links or DWDM links
• WAN can transport VXLAN header
• Sites are in same Metropolitan area
Metro
HQ
Typical use cases
Metro Metro
o Consistent policy and end-to-end
segmentation using VRFs and SGTs
Campus 1 o Smaller and Isolated fault domains
Campus 2 Campus 3 o Resiliency and Scalability
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Scaling Strategy for Fabric across Multiple Sites
Design for a multi site with Cisco SD-Access Transit
Remote Building 1 Remote Building 2 Remote Building N Key Decision Points
• Tends to be like a Metro area
Site B1 Site B2 Site BN with multiple buildings or sites
DNAC
• 2 Transit CP
DC 5-7 NCP +
NDP
Cluster
ISE
DDI
(Multiple Exits)
1 DHCP 1
DNS
1 IPAM
AB AB EB EB
Site HQ
CP CP
HQ Campus
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Would you like to know more?
BRKCRS-2815
Cisco SD-Access – Connecting Multiple Sites in a
Single Fabric Domain
This session covers:
• How multiple Fabrics communicate
• Various Multi-Site design approaches
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Scaling Strategy for Fabric across Multiple Sites
Wireless Controller Scale
Transit B
B
B B WAN/Metro
B
C C C C
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Scaling Strategy for Fabric within a site
Wireless Controller Scale
Number of end
Platform Number of AP’s SDA Design
points
3504 150 3000 Small
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Scaling Strategy across Multiple Sites
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless control to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Scaling Strategy across Multiple Sites
Cisco DNA Center Scale
PSN PSN
Fabric Fabric
Site3 Site6
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Scaling Strategy across Multiple Sites
Cisco DNA Center Scale
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Scaling Strategy across Multiple Sites
Cisco DNA Center Scale
PSN PSN
PSN PSN
PSN
PSN
PSN
PSN
PSN
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Scaling Strategy across Multiple Sites
How do I achieve higher scale?
• Using a larger capacity control plane node • Using more control plane nodes to achieve
and wireless control to achieve scale for the scale for the fabric infrastructure.
fabric infrastructure. • In a given single site by increasing the control planes
nodes we cannot provide higher scale. To achieve
higher scale in this model we have to split a single fabric
• Using a larger Cisco DNA Center appliance to site into multiple sites.
achieve higher automation and assurance
scale for fabric. • Using multiple clusters of Cisco DNA Center
appliances to achieve higher automation and
• Using a larger ISE Node to achieve higher assurance scale for fabric.
scale for authentications and policy.
• Using multiple ISE nodes and with load
balancing can achieve higher scale for
authentications and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Scaling Strategy across Multiple Sites
Cisco ISE Scale
• 2 x Admin+Monitor
• Max 5 PSNs
PSN
• Max endpoints – Platform dependent
PSN
PSN
PSN
PSN
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Scaling Strategy across Multiple Sites
Cisco ISE Scale
Standalone ISE + HA Distributed ISE + HA
Admin (P) Admin (S) Policy Services
MnT (P) MnT (S) Cluster
Admin (P) PXG PXG
Admin
MnT (P) (S) PSN PSN PSN
PSN MnT (S)
PSN
AD / LDAP AD / LDAP
(External ID or (External ID or
Attribute Store) Attribute Store)
WLC WLC
802.1X 802.1X
Switch Switch
802.1X 802.1X
AP AP Small Site
AP
Small Site
WLC WLC
Switch
802.1X 802.1X
802.1X
Switch AP
802.1X
AP
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Scaling Strategy across Multiple Sites
Cisco ISE Scale
Admin (P) Admin (S) Policy Services
MnT (P) MnT (S) Cluster Distributed
Policy Services
PSN PSN
PSN PSN
HA Inline AD/LDAP
Posture Nodes (External ID/ AD/LDAP
Attribute Store) (External ID/
IPN
Data DC B Attribute Store)
IPN
Center A
WLC
Non-CoA 802.1X
ASA VPN
Switch
802.1X AP
WLC
802.1X Switch
AP 802.1X •Dedicated Management Appliances
•Primary Admin / Secondary MnT
Site B
•Primary MnT / Secondary Admin
Site A
•Dedicated Policy Service Nodes—Up to 5 PSNs
Switch Switch
802.1X 802.1X
AP AP
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Scaling Strategy across Multiple Sites
Cisco ISE Scale
MnT MnT
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Scaling Strategy across Multiple Sites
Cisco ISE Scale
• Only two PSN’s are allowed per Fabric device in Cisco SD-Access.
• Policy Service nodes can be configured in a cluster behind a load balancer (LB).
• Access Devices send RADIUS and TACACS+ AAA requests to LB virtual IP.
PSNs (RADIUS
PSN PSN PSN PSN PSN PSN PSN PSN PSN Servers)
Load
Virtual IP Balancers
Fabric
Devices
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Scaling Strategy across Multiple Sites
Cisco ISE Scale
DC 1 DC 2
PAN PAN
B
Load
Balancers Metro
B B B
C
B
C C C C
Horizontal Scaling
• Use multiple clusters of Cisco DNA Center appliances to achieve higher automation and
assurance scale for fabric.
• Use multiple ISE PSN nodes and with load balancing can achieve higher scale for authentications
and policy.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
High Level Design
for a Cisco SD-
Access across
Geographies
High Level Design Overview
Across Geographies
• Deploy Fabric Domains per Geo Locations like US , Europe , Asia Pac etc.
• A site is a fabric on its own with its own control plane and border nodes
• Different sites in Geo regions will be connected using Cisco SD-Access multi-site ( SDA
and / or IP Transit)
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
High Level Design Overview
Across Geographies
SD-Access
sites Australia
SD-Access
India Site
(Bangalore and
SD-WAN(Viptela)
Chennai)
SD-Access SD-Access
Sites USA Sites X
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
High Level Design Overview
Across Geographies
Hyderabad
Transit
Site 3
Bangalore
Hyderabad
SD-WAN
and Internet
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Conclusion
Session Summary
Cisco SD-
Access
Fabric
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
SD-Access Resources
Would you like to know more?
cs.co/sda-resources
cs.co/sda-community
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco SD-Access Resources
Would you like to know more?
cisco.com/go/dna
cisco.com/go/sdaccess cisco.com/go/dnacenter
cisco.com/go/cvd
• SD-Access At-A-Glance • Cisco DNA Center At-A-Glance
• SD-Access Ordering Guide • Cisco DNA ROI Calculator
• SD-Access Solution Data Sheet • Cisco DNA Center Data Sheet
• SD-Access Solution White Paper • SD-Access Design Guide • Cisco DNA Center 'How To' Video Resources
• SD-Access Deployment Guide
• SD-Access Segmentation Guide
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
BRKCRS-2825 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Thank you