Cisco SD-Access with ISE



Cisco SD-Access with ISE

Cisco SD-Access with ISE

Cisco SDA TME Kadin Stephens gives us an introduction to Software-Defined Access and how ISE plays a role in making it better for network segmentation.
00:00 Intro & Agenda
02:50 Poll: Are you familiar with Cisco’s SD-Access?
04:07 Cisco Catalyst Center – formerly Cisco Digital Network Architecture Center (DNAC)
05:00 What is SDA? Terminology & Roles
06:40 Underlay and Overlay
07:26 Why an Overlay?
08:10 SD Access Fabric Sites
09:55 Transit
11:00 SDA Roles
11:15 Border Node (BN)
11:55 Edge Node (EN)
12:58 Control Plane (CP) Node
13:56 Location ID Separation Protocol (LISP)?
16:03 Extended Nodes
16:32 Wireless Controllers and APs
16:49 Identity Services Engine (ISE)
17:11 Cisco ISE Integration and Use Cases with Catalyst Center (CC)
18:37 Demo: ISE Integration with CC/DNAC
20:29 Demo: Add ISE as a Policy Server with CC/DNAC
21:57 Demo: CC/DNAC Network Settings
23:08 Demo: Add ISE as the AAA Server
23:43 Virtual Networks in an SD-Access Fabric (L3VNs, L2VNs, VRFs, INFRA_VN, DEFAULT_VN)
26:14 SDA Segmentation : Macro and Micro
28:04 Security Group Tags (SGTs)
28:46 Demo: Macro & Micro Segmentation in CC/DNAC
29:37 Demo: Create a new Virtual Network (VN)
30:17 Demo: Assign SGTs to VNs
32:17 SDA Role Assignment and Capability: https://cs.co/sda-compatibility
33:23 Demo: Fabric Provisioning
34:29 Demo: Deploy a Fabric Site
35:40 Demo: Assign Virtual Networks to Fabric Site
37:25 Demo: Add IP Address Pools
38:45 Group Based Access Control: TrustSec vs SDA
41:40 Demo: Group Based Access Control in CC/DNAC
45:03 SDA Fabric Review
46:50 ISE to Multiple DNACs (mDNAC)
49:26 Questions

Resources
– Cisco Software-Defined Access (SDA) Resources: https://cs.co/sda-resources
– Cisco SDA YouTube Channel: https://cs.co/sda-youtube
– Cisco Validated Design: https://cs.co/sda-cvd
– Design Tool: https://cs.co/sda-design-tool
– Compatibility Matrix: https://cs.co/sda-compatibility