sd access ise Flashcards
(33 cards)
over lay tunnels
GRE-vxlan
mpls - bgp evpn
ipsec - sd-wan
capwap -ACI
LISP - OTV
GRE
VXLAN
MPLS
BGP EVPN
IPSEC
SD-WAN
CAPWAP
ACI
LISP
OTV
diffrent fabrics are connected trhough what
transit controller access node TC ip based vrf lite mpls or
sd-access
SD access roles
cattalyst center GUI and API for intent based automation of fabric devices
Fabric Border Nodes
a fabric device that connects external L3 and l2 networks to the cisco SD-ACCESS fabric
Edge nodes
A fabric device that connects wired endpoinst to the cisco SD-Aess fabric and optionally enforces microsegmentation policy
control plane node
Map system that tracks endpoint to tfrabric node relatiossip
SD access roles
Catalyst Center - GUI API
Fabric Border Nodes - ASBR for l2 l3
Edge Nodes - Endpoint connections
Controler Plane Node - Maps endpoint to fabric node
Border node
usually the “default gateway”
Edge node
Authenticate and aauthorize endpoints with ISE 801.x ISE = Radius tacas
Register endpoint IDS EID . IPV4 mac address to control plane node
Encapsulation Decapsulation.
control plane node.
maintains host tracking dataabase
receibed EID reigstrations from border node and edge nodes
Performs lisp lookups endpoint and border node subscribes to CP
Basically RR .
what is LISP
Location id separation protocol
routing protocol in control point of sd access
decopuples endpoint idfrom ip location .
Assigns RLOC (routing locator ) to all network devices at different locations within fabric.
LISP example
ip to rloc: 1.2.3.4/32 -> en1
mac to rloc AA:BB:CC:DD -> en1
address resolution 1.2.3.4 -> AA:BB:CC:DD
if user changes destionation RLOC keeps track of endoint of user
RLOC = endpoint EID = user
user does not have to know where other users physical location is (rloc) is only need to know eid ask control plane for rloc
optional components
Extended node a l2 only switch extends fabcric connectivity and optionaly enforces micro segmentatoin.
Fabric wireless controller and fabric APS
connects wirteslls endpoints ot the sd-access fabric
intermediate nodes
moves data between fabric nodes can be one or many hops
IS ISE required to perform micro segmentation in an SD-ACCESS fabric
yes
what 2 types of virtual networks exists
l2 eqvivlent to vlan and l3 eqvivelent for VRF
all endpoints which conntect to sd-access fabric have to do what
connect in to an virtual network