BRKNMS 2031
BRKNMS 2031
BRKNMS 2031
BRKNMS-2031
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda BRKNMS-2031
• Why an Intent Based solution
• Traditional Management vs. Intent Based Networking
• What is Cisco DNA Center
• Cisco DNA Center Automation- Use Cases Examples
• DAY0: Onboarding new devices using Zero Touch Deployment
• DAY1: Configurations using Templates
• DAYN: Security Advisories based on Machine Reasoning Engine
Demo
• DAYN: Simplified Software Management based on Golden Images &
• DAYN: Defective Device Replacement - RMA
Lecture
• Cisco DNA Center Assurance- Use Cases Examples
• Network Health & Device 360
• Client Health & Client 360
• Application Health & Application 360
• Proactive troubleshooting using Sensors
The What
The What “QoS Policy for Admin
Branches A-N” Driven
“QoS Policy for
Branches A-N”
Admin
Driven The How
The How
“Change QoS System
config in the “Change QoS
Config in the Driven
following elements”
following flements”
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Feature Configuration vs. Intent Based
Networking
FEATURE CONFIGURATION
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Feature Configuration vs. Intent Based
Networking INTENT BASED NETWORKING
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
What is Cisco DNA Center?
Cisco DNA Center: Design, Policy, Provision, Assurance
Intent Based Driven Management
Logical workflow to design, Monitor end-to-end Pinpoint problems faster Manage hardware and
provision, set policy network performance Reduce downtime with an software lifecycles
Respond to changes faster Predict and act on problems end-to-end view instead of Keep up to date, meet
before they happen hop by hop compliance and plan for refresh
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Pillars of Cisco DNA Center Covered in this
session
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Pillars of Cisco DNA Center Might come up in
Q&A
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Cisco DNA Center
Automation:
• Software upgrade
• Greenfield switch on- • Device Provisioning • MRE based Security using SWIM
boarding • Wireless Rogue Advisory
• Application Policy
• WiFi site planning & detection* • Netflow/ETA enablement
deployment w/ Stealthwatch • Bonjour
• StackWise Virtual (SVL)*
• AP Refresh • RMA
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Automation Use Cases covered in this session
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Preparing Cisco DNA Center
Demo
Preparing Cisco DNA Center For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
New device onboarding –
Network Plug and Play
Use Case Example
Device Deployment in Campus
Cisco DNA Center
DHCP Server (PnP Server)
IP Address
10.11.11.11
Day 0
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Use Case Example
Device Deployment in Campus Device validates server’s location and
establishes a communication with the server
Cisco DNA Center
DHCP Server
(PnP Server)
Cisco
IOS-XE®
Config IP Address
<..snip..>
file…. 10.11.11.11
CISCO_PNP.pnpserver
"5A;B2;K4;I10.11.11.11;J80"; Switch running
<..snip..> PnP Agent
Day 1
Remote Installer
Day 1 • Mount and cable
devices
• Power-on
Network Admin remotely
monitors status of install
while in progress.
Installer
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
New device onboarding – Network Plug
and Play
Demo
PnP Server Discovery Options For your
reference
Routers
DHCP with options 60 and 43 (ASR, ISR)
1 PnP string: 5A1D;B2;K4;I172.19.45.222;J80 added to DHCP Server
Wireless
Automated
Access Points
DNS lookup
2
pnpserver.localdomain resolves to Cisco DNA Center IP Address
Switches
(Catalyst®)
Manual discovery
not supported for
USB-based bootstrapping Access Points
4 router-confg/router.cfg/ciscortr.cfg
Manual
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Day-0 deployment using PnP For your
reference
Connect
Cisco® Customer Smart
supply chain Device SN Account Device SN
PnP Connect
Cloud-based device
discovery
Label
2 3
Cisco DNA Center downloads SN
Device SN added SN per Smart 5 from PnP Connect
into customer Account available in
Smart Account PnP Connect Device SN
SSL
4 SSL
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Plug & Play Stack Support
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Plug & Play Stack Support
Software
Upgrade to
whole stack
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Starting with Cisco DNA
Stack Switch Numbering Issue Center1.2
Port # tied to
Before Stack switch Configuration
stack Member ID
SR#A
!
1 1 SR#C
SR#B
2 2 SR#B
4 4
SR#D SR#D
Demo
How do Variables Work For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Velocity Template Language For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Variables & Bind to Source For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Variables & Bind to Source For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Bind to Source For your
reference
What information can I access?
Common Settings
Inventory
Network Profile
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Flexible Deployment Options For your
reference
Key-Value Pairs
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Flexible Deployment Options For your
reference
Min-Max Values
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Security Advisories based on
Machine Reasoning Engine
Identifying and fixing vulnerabilities is challenging
and ongoing
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Machine Reasoning Engine
Cisco Cloud
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Security Advisories based on Machine
Reasoning Engine
Demo
Security Advisories For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Security Advisories For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Security Advisories For your
reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Software and Image
Management
But wait! Indicates ITSM Process Steps
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
But wait! Doesn’t PI have Image Management?
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Selecting Golden Image
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Identify Devices to Upgrade
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Image Update Readiness Checks
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Out of box Pre-Checks and Post-Checks
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Software Upgrade – Integrity Verification
Software Is the software used by the device authentic? Includes checks of the
software files (Known Good Value) and in-memory (Imprint Value) contents. Also
includes shell access attempts (Event Occurrence)
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Software Upgrade – Integrity Verification
• To provide a level of security integrity devices must run authentic and valid software
• Cisco DNA Center Integrity Verification uses a system to compare collected image
integrity data to Known Good Values (KGV) for Cisco software.
• The MD5 or SHA values of the images are validated against KGV’s.
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Software Upgrade – Integrity Verification
• To provide a level of security integrity devices must run authentic and valid software
• Cisco DNA Center Integrity Verification uses a system to compare collected image
integrity data to Known Good Values (KGV) for Cisco software.
• The MD5 or SHA values of the images are validated against KGV’s.
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Software and Image Management
Demo
What you need to know …
• Both BUNDLE mode and INSTALL mode are supported
• We don’t support BUNDLE/INSTALL mode conversion
• INSTALL mode doesn’t allow to import image directly from the device
• To upgrade image during PnP the device has to be in INSTALL mode
Bundle Mode
Install Mode
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
N+1 rolling AP upgrades For your
reference
Zero client downtime during image upgrades
Unified management
with Cisco DNA Center Key highlights
Policy Automation Assurance
No more manual
intervention to create
groups in Cisco Prime®
Infrastructure
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
N+1 Rolling AP Upgrade - Process AP
Trigger Rolling
Upgrade
X
Version : X+1 Mobility Group Version: X+1
Primary 1. Device auto selects candidate APs based on selected Upgraded N+1
% and RRM AP Neighbor Map
2. The primary controller selects a set of APs as part of
iteration and configures their primary controller to point to
the N+1 controller and does a swap and reboot of APs.
4. After all the APs are upgraded and moved to the N+1
controller, the primary controller is rebooted to activate
the new image.
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Defective Device
Replacement - RMA
Why Defective device replacement
(RMA) in Cisco DNA Center?
• RMA is a critical part of device lifecycle management.
• Existing RMA procedure is manual and time consuming.
• RMA in Cisco DNA Center provides users the ease of
automation to recover failed device quickly, thus
improving productivity and reducing Opex.
Replace Revoke
Device in Replace
Deploy PKI
Restore Deploy DNAC Device in
Archived trustpoint
Image License (Inventory, ISE
Config from faulty
Assurance
device
SDA)
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Return Material Authorization (RMA) workflow
Cisco DNA Center
SW1 Failed
Device
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Return Material Authorization (RMA) workflow
Cisco DNA Center
SW1 Failed
Device
SW2 Replacement
Device
Installer
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Benefits of DNA Center RMA Workflow
DNA Center RMA
Replace
Revoke
Device in Replace
Deploy PKI
Restore Deploy DNAC Device in
Archived trustpoint
Image License (Inventory, ISE
Config from faulty
Assurance
device
SDA)
Traditional NMS/Manual
Manual Deploy Manual
Archived
Config
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Defective Device Replacement - RMA
Demo
Cisco DNA Center 1.3.1: RMA For your
reference
What you need to know …
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Checklist before proceeding with For your
RMA in production reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Cisco DNA Center
Assurance:
Traceroute 001110101100110
Complex
1010110010 Clients Baseline
Syslog Netflow correlation
00101101
AAA Router DHCP Metadata
0110100 extraction
Telnet Wireless CLI
1101101
DNS
OID IPSLA Ping 00101101 Steam
SNMP MIB 10101100110 Processing Application Network
IPAM
AppD 101011000110011
CMX
Everything as a Sensor
170+ Actionable Insights
Client | Applications | Wireless | Switching | Routing
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Assurance Use Cases covered in this session
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Assurance & Analytics
Demo
What about Prime
Infrastructure?
Deployment with Prime and Cisco DNA Center
There is only one system that will make changes to the network
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Migration Scenarios
Full Migration from Prime to DNAC
There is only one system that will make changes to the network
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Assurance in Cisco DNA Center and Config in
Prime
1 Prime DNA Center
Devices Devices
WLC is RO in DNAC
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Co-Existence Overview
• Sites
• Buildings
• Floors with floor
plan
• Floor elements –
Inclusion/Exclusion
Areas, Obstacles
etc
• WLCs
• APs
• Routers
• Switches
• CMX Servers
Prime Infrastructure Cisco DNA Center –
3.5 Update 2 1.2.6,1.2.8,1.2.10, 1.3
Jump start with DNA Center with a readily available site layout
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Co-existence Overview
Prime DNA Center
California California
♻ Site
♻ Buildings
Denver
♻ Floors along with floor plan
New York ♻ Routers
Seattle ♻ Switches
♻ WLC
Florida
♻ AP’s
♻ AP Position on the floor maps
♻ Floor Elements like
Exclusion/Inclusion Regions,
Obstacles etc
Jump start with DNA Center with a readily ♻ CMX Servers
available site layout
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Co-existence Workflow
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Co-existence Workflow
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Co-existence Workflow
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Co-existence Workflow
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Co-existence Workflow
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Co-existence Workflow
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Cisco DNAC vs Prime - Lifecycle Mgmt for IOS-XE Based
Infrastructure
Cisco DNAC Prime Comments For your
Discovery/Inventory/Sites/Topology reference
Day 0
Device Onboarding/PnP
Sensor Onboarding
StealthWatch/ETA Integration
Day 1
App Policy
Intelligent Capture
Day N
Compliance
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Cisco DNAC vs Prime - Lifecycle Mgmt for IOS-XE Based
Infrastructure
Cisco DNAC Prime Comments For your
reference
Defective device replacement
Telemetry profile enhancements 1.3.1: support for the Application Visibility profile
Wide Area Bonjour application Provides you with centralized access control and
monitoring capabilities for large-scale Bonjour services
Stealthwatch Security Analytics Service 1.3.1: 1st phase
Ekahau Integration
Embedded Wireless Support: Fabric Edge Support for Cisco Catalyst 9300/9400/9500 Series
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Key Takeaways
Key Takeaways
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Check out my blogs
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Thank you
Reference Slides
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Cisco DNA Center 1.3.3 Supported Devices
https://www.cisco.com/c/en/us/support/cloud-systems-management/dna-
center/products-device-support-tables-list.html
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Reference Slides
Sensor Tests
Cisco DNA Center Sensor Tests
Network Tests
• Wireless Onboard Tests: Connects to the SSID with credentials and gets the IP address
through DHCP. It then verifies the gateway and DNS server received through DHCP.
• RF Assessment Test: Cisco DNA Center collects various RF performance measurements
like Tx/Rx Data rate and SNR during the active sensor testing and assesses the quality of
the RF environment during that sensor test.
• DNS Tests: Resolves IP address for the domain name.
• Host Reachability Tests: Verifies reachability using the Internet Control Message Protocol
(ICMP) echo request.
• RADIUS Tests: The sensor acts as a RADIUS authenticator and authenticates through
wireless. Sensors can test RADIUS Server using Password Authentication Protocol (PAP)
or the Microsoft version of the Challenge-Handshake Authentication Protocol (MS-CHAP).
*if the network administrator is already using the Wi-Fi Onboarding test that includes
802.1x/EAP Authentication, then this RADIUS test is essentially already covered as part of
the onboarding test.
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Cisco DNA Center Sensor Tests
Performance Tests
• Speed Test: Performs tests against NDT servers in the internet to obtain to the
downlink & uplink throughput and latency. Here is test sequence
• Sensor will send http query to M-Lab Server to get nearest M-lab Server info.
• Then Sensor will use returned NDT server cluster info
• Sensor will access NDT server using TCP Port 3001
• IP SLA Test: Sensor sends an UDP probe to the AP that acts as a responder to
determine the Jitter, Latency, Packet Loss and Round Trip time of the last hop
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Cisco DNA Center Sensor Tests
Application Tests
• File Transfer Tests: Tests for upload or download file operation using FTP protocol
• Web Tests (http, https): Tests for access to the provided URL and verifies the
response data.
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Reference Slides
There is only one system that will make changes to the network
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Scenario 1 For your
Full Migration: Prime to DNA Center reference
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Co-Existence: Scenario - 1 For your
reference
Assurance in DNA Center and Config in Prime
Devices Devices
WLC is RO in DNAC
WLC is RO in Prime
WLC is RO in Prime
BRKNMS-2031 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 107