Software Defined Networking Flashcards
What is a network fabric?
A cohesive overlay network which obscures the physical underlay.
What is network assurance?
Monitoring and analytics of device health metrics, ip reachability, traffic patterns
What are the 5 layers of SD-ACcess?
1. Physical 2 underlay 3 overlay 4 controller 5 management
What are the 3 planes of SD-Access overlay network?
Data plane
Control plane
Policy plane
Describe the SD-Access data plane.
Uses VXLAN for transporting data between hosts.
Network is divided into Virtual networks (VNs) to segment routing and forwarding domains.
Describe the SD-Access Control plane.
Control plane uses LISP to reduce load on individual devices when layer 3 routing.
LISP creates a MR/MS to maintain routing forwarding information for the entire overlay.
Describe the SD-Access Policy plane.
The propriety VXLAN sgt tag is added upon port ingress to a VTEP (inline tagging)
The SGT tag is used to enforce QoS and is checked upon egress of a VTEP. SGTs usually correspond with a organisational role
What is the Cisco term for SGTs used for VXLAN/SD-Access?
Trustsec
What is the term for a VXLAN packet containing a SGT?
The packet is called a Group Policy ID and VXlAN is using the VXLAN-GPO format.
What is a fabric enabled network device?
Any device which participated in the underlay or overlay network and is controlled by a DNAC.
What are the 4 types of fabric enabled devices used in SD-Access?
Control plane node
Fabric Border node
Fabric edge node
Fabric WLAN controller
What is the purpose of the SD-Access control plane node?
Router or switch acting has the LISP MR/MS server.
The control plane node acts as a central IP routing and MAC address table for the overlay fabric.
It’s also responsible for mapping SGTs between Ethernet and VXLAN headers.
What is the purpose of the fabric edge node?
Hosts entry point into the VN.
Fabric edge is a LISP xTR but uses VXLAN encapsulation for building layer 2/3 tunnels.
They SGT tag Ingress traffic, authenticate with 802.1X and act as the GW for hosts.
What is a fabric end nodes anycast gateway?
ALL fabric edge nodes have matching SVI ip addressing and MAC address for any given VN.
This allows a host to connect to ANY fabric edge node and retain its GW information.
What purpose does the Fabric border node serve?
Provides connectivity for devices outside of the fabric.
Redistributes routes internally used by the fabric with outside networks.