SD-Access Flashcards
What are the two main networks that the Cisco SD-Access Fabric consists of?
1) Underlay network – the physical topology for L2 and L3 connectivity, that can use any routing protocol.
2) Overlay network - runs on top of the overlay to create a virtualized network (a logical topology).
What is the role of an underlay network?
Establish physical connectivity from one edge device to another.
What is the role of the overlay network?
To create the logical topology on top of the underlay network, using encapsulation technology (e.g. GRE or IPSec)
What are some requirements and considerations when migrating an existing network to Cisco SD-Access?
1) There should be IP reachability within the network
2) Switches in the overlay are designated and configured as edge and border nodes
3) Ensure that there is connectivity between the devices in the underlay network
4) Recommended to use IS-IS as the routing protocol (easiest to automate using Cisco DNA Center, and does not have an IP address dependency for neighbors)
What are some advantages of using IS-IS with Cisco SD-Access in the underlay network?
1) Able to establish neighbors without IP dependencies
2) Can peer using loopback address
3) Agnostic treatment of IPv4, IPv6, and non-IP
What does Cisco SD-Access use to configure the overlay network for fabric data plane encapsulation?
VXLAN, which encapsulates complete L2 frames for transport in the underlay. Overlay networks are identified by the VXLAN network identifier (VNI), and carries the scalable group tags (SGTs)
What Cisco technology is the Cisco SD-Access fabric policy plane based on?
Cisco TrustSec
With Cisco TrustSec, what is used to enforce access policies for users, applications, and devices?
A classification group (scalable group or SGT)
Cisco TrustSec and scalable group tags classifies traffic according to…?
The contextual identity of the endpoint instead of the IP address
When is an SGT usually assigned to a user or device? When is it enforced?
Assigned at the ingress (inbound into the network). Enforced elsewhere in the infrastructure (e.g. a data center). Switches, routers, and firewalls use the SGT to make forwarding decisions.
What is driven by Cisco Identity Services Engine (ISE), and what orchestrates this?
ISE drives:
1) AAA services, groups, policy, endpoint profiling
These are orchestrated by Cisco DNA Center’s policy authoring workflows.
What two technologies allows ISE and DNA Center to integrate?
Cisco Platform Exchange Grid (pxGrid) and REST APIs
What is the minimum recommended nodes for ISE for redundancy?
2
What component of ISE do Cisco SD-Access fabric edge node switches send authentication requests to?
The Policy Services Node (PSN) persona running on ISE
In Cisco SD-Access, what is the role of the control plane node?
Acts as the LISP map server/map resolver (MS/MR) that manages EID to device relationships