Course Objectives
Upon completing this course, the learner will be able to meet these overall objectives:
- Explain the role that ISE plays as part of the solution Configure AAA services and TrustSec Policy in ISE Explain ISE Integration with DNA Center for Policy enforcement Know and understand Cisco’s SD
- Access concepts, features, benefits, terminology and the way this approach innovates common administrative tasks on today’s networks. Differentiate and explain each of the building blocks of SD
- Access Solution Explain the concept of “Fabric” and the different node types that conform it (Fabric Edge Nodes, Control Plane Nodes, Border Nodes) Describe the role of LISP in Control Plane and VXLAN in Data Plane for SD
- Access Solution Understand TrustSec concepts, deployment details and the way it is used as part of SD
- Access Solution for segmentation and Policy Enforcement Understand the role of DNA Center as solution orchestrator and Intelligent GUI Be familiar with workflow approach in DNA Center Design, Policy, Provision and Assurance
Agenda
- Introduction to Cisco ISE
- Using Cisco ISE as a Network Access Policy Engine
- Introducing Cisco ISE Deployment Models
- Introducing 802.1x and MAB Access: Wired and Wireless
- Introducing Identity Management
- Configuring Certificate Service
- Introducing Cisco ISE Policy
- Configuring Cisco ISE Policy Sets
- Introduction to Cisco TrustSec for segmentation
- The Concept of Security Group (SG) and Security Group Tag (SGT)
- Cisco TrustSec Phases
- Classification
- Propagation
- Enforcement
- Methods for Classification
- Static Classification
- Dynamic Classification
- Methods for SGT tag propagation
- Inline Tagging
- SGT Exchange Protocol (SXP)
- SD-Access Overview
- SD-Access Benefits
- SD-Access Key Concepts
- SD-Access Main Components
- Campus Fabric
- Wired
- Wireless
- Nodes
- Edge
- Border
- Control Plane
- DNA Controller (APIC-EM Controller)
- Introducing Cisco ISE 2.x px
- 2-level Hierarchy
- Macro Level: Virtual Network (VN)
- Micro Level: Scalable Group (SG)
- DNA Center Refresher
- Creating Enterprise and Sites Hierarchy
- Configuring General Network Settings
- Loading maps into the GUI
- IP Address Management
- Software Image Management
- Network Device Profiles
- Introduction to Analytics
- NDP Fundamentals
- Overview of DNA Assurance
- The concept of Fabric
- Node types (Breakdown)
- LISP as protocol for Control Plane
- VXLAN as protocol for Data Plane
- Enterprise Sample Topology for SD-Access
- Role of Border Nodes
- Types of Border Nodes
- Border
- Default Border
- Single Border vs. Multiple Border Designs
- Collocated Border and Control Plane Nodes
- Distributed (separated) Border and Control Plane Nodes
- WLAN Integration Strategies in SD-Access Fabric
- Fabric CUWN
- SD-Access Wireless (Fabric enabled WLC and AP)
- SD-Access Wireless Architecture
- Control Plane: LISP and WLC
- Data Plane: VXLAN
- Policy Plane and Segmentation: VN and SGT
- Sample Design for SD-Access Wireless
FREE
Interested in course?
Course Type: Instructor Led