Software Defined Networking Flashcards

1
Q

What is a network fabric?

A

A cohesive overlay network which obscures the physical underlay.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is network assurance?

A

Monitoring and analytics of device health metrics, ip reachability, traffic patterns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 5 layers of SD-ACcess?

A
1. Physical
2 underlay
3 overlay 
4 controller
5 management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 planes of SD-Access overlay network?

A

Data plane
Control plane
Policy plane

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe the SD-Access data plane.

A

Uses VXLAN for transporting data between hosts.

Network is divided into Virtual networks (VNs) to segment routing and forwarding domains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe the SD-Access Control plane.

A

Control plane uses LISP to reduce load on individual devices when layer 3 routing.

LISP creates a MR/MS to maintain routing forwarding information for the entire overlay.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe the SD-Access Policy plane.

A

The propriety VXLAN sgt tag is added upon port ingress to a VTEP (inline tagging)

The SGT tag is used to enforce QoS and is checked upon egress of a VTEP. SGTs usually correspond with a organisational role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Cisco term for SGTs used for VXLAN/SD-Access?

A

Trustsec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the term for a VXLAN packet containing a SGT?

A

The packet is called a Group Policy ID and VXlAN is using the VXLAN-GPO format.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a fabric enabled network device?

A

Any device which participated in the underlay or overlay network and is controlled by a DNAC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 4 types of fabric enabled devices used in SD-Access?

A

Control plane node
Fabric Border node
Fabric edge node
Fabric WLAN controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of the SD-Access control plane node?

A

Router or switch acting has the LISP MR/MS server.

The control plane node acts as a central IP routing and MAC address table for the overlay fabric.

It’s also responsible for mapping SGTs between Ethernet and VXLAN headers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of the fabric edge node?

A

Hosts entry point into the VN.
Fabric edge is a LISP xTR but uses VXLAN encapsulation for building layer 2/3 tunnels.

They SGT tag Ingress traffic, authenticate with 802.1X and act as the GW for hosts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a fabric end nodes anycast gateway?

A

ALL fabric edge nodes have matching SVI ip addressing and MAC address for any given VN.

This allows a host to connect to ANY fabric edge node and retain its GW information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What purpose does the Fabric border node serve?

A

Provides connectivity for devices outside of the fabric.

Redistributes routes internally used by the fabric with outside networks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a Default Fabric border node?

A

A simple border node adverting a default route out of the fabric.

17
Q

What is the purpose of the Fabric WLC node?

A

Used for connecting and managing APs CONTROL plane data only (CAPWAP)

18
Q

How is APs data traffic handled in a SD-access fabric?

A

All data traffic flows through the fabric edge VXLAN tunnel, applying SGTs and enforcing egress policy’s

Removing the WLC allows wireless clients to be treated similar to physical hosts.

19
Q

What are the 3 components of the SD-Access Controller layer?

A

Network controller platform (NCP) : Automation

Network Data Platform (NDP): assurance

Identity services engine (ISE): identity and policy

20
Q

What services run on the Network Controller Platform?

A

DNA Provision and DNA design use NETCONF and YANG to push automation tasks to fabric devices.

21
Q

What services run on the Network Data platform?

A

Collects metrics using SPAN, SNMP and NETflow for traffic analysis and health analytics

22
Q

What services run on ISE?

A

Controls network access via TACACs, RADIUS, MAB, 802.1.X and webauth