<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNA Fusion Router - Device Model in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753073#M490</link>
    <description>I see the explanation is for the control plane node. However, I am looking for compute requirements of the fusion router.&lt;BR /&gt;&lt;BR /&gt;Is there any documentation available for that?&lt;BR /&gt;</description>
    <pubDate>Mon, 26 Nov 2018 20:58:29 GMT</pubDate>
    <dc:creator>devnetdan</dc:creator>
    <dc:date>2018-11-26T20:58:29Z</dc:date>
    <item>
      <title>DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3752468#M483</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've looked over the official list of DNA compatible devices. However, I have not found a document outlining the requirements for a device to be considered for the role of the Fusion router. From reading through documentation, I can gather the Fusion will need to perform the following:&lt;/P&gt;
&lt;P&gt;- IP routing&lt;/P&gt;
&lt;P&gt;- Support for dynamic routing protocols (ISIS, BGP, EIGRP, etc.)&lt;/P&gt;
&lt;P&gt;- VRF support&lt;/P&gt;
&lt;P&gt;- Route redistribution&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since these requirements can be met using a true router (ISR/ASR) or a L3 switch (Catalyst), what devices have been used in environments (lab/prod)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just looking to see what devices have been tested and are viable options...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3752468#M483</guid>
      <dc:creator>devnetdan</dc:creator>
      <dc:date>2019-03-09T01:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3752996#M487</link>
      <description>&lt;H3 id="toc-hId--695419912"&gt;DNA-SDA solution requires Fusion router.&lt;/H3&gt;
&lt;P&gt;Today the Dynamic Network Architecture Software Defined Access (DNA-SDA) solution requires a fusion router to perform VRF route leaking between user VRFs and Shared-Services, which may be in the Global routing table (GRT) or another VRF.&amp;nbsp;Shared Services may consist of DHCP, &lt;SPAN&gt;Domain Name System (&lt;/SPAN&gt;DNS), &lt;SPAN&gt;Network Time Protocol (&lt;/SPAN&gt;NTP), &lt;SPAN&gt;Wireless LAN Controller (&lt;/SPAN&gt;WLC), &lt;SPAN&gt;&amp;nbsp;Identity Services Engine&amp;nbsp;(&lt;/SPAN&gt;ISE), DNAC components which must be made available to other virtual networks (VN’s) in the Campus. Thus by creating&amp;nbsp;&lt;SPAN&gt;Border Gateway Protocol (&lt;/SPAN&gt;BGP) peerings from the Border Routers to the Fusion Routers, on the Fusion Router the fabric VRF’s subnets which need access to these shared services will be leaked into GRT, and vice-versa. Route maps can be used to help contain routing tables to subnets specific to SDA Fabric.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 19:12:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3752996#M487</guid>
      <dc:creator>kumaamit</dc:creator>
      <dc:date>2018-11-26T19:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3752999#M488</link>
      <description>Thank you. On top of the logical requirements, are there any compute or memory requirements? Does the certain Fusion device need a certain amount of memory or CPU in order to handle all the processes taking place?&lt;BR /&gt;</description>
      <pubDate>Mon, 26 Nov 2018 19:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3752999#M488</guid>
      <dc:creator>devnetdan</dc:creator>
      <dc:date>2018-11-26T19:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753063#M489</link>
      <description>&lt;P&gt;The memory and processing requirements are load balanced as the control plane functionality is automated.&lt;BR /&gt;DNA Center automates the configuration of the control plane functionality. For redundancy, you should deploy two control plane nodes to ensure high availability of the fabric, as a result of each node containing a duplicate copy of control plane information. The devices supporting the control plane should be chosen to support the HTDB, CPU, and memory needs for an organization based on fabric endpoints.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 20:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753063#M489</guid>
      <dc:creator>kumaamit</dc:creator>
      <dc:date>2018-11-26T20:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753073#M490</link>
      <description>I see the explanation is for the control plane node. However, I am looking for compute requirements of the fusion router.&lt;BR /&gt;&lt;BR /&gt;Is there any documentation available for that?&lt;BR /&gt;</description>
      <pubDate>Mon, 26 Nov 2018 20:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753073#M490</guid>
      <dc:creator>devnetdan</dc:creator>
      <dc:date>2018-11-26T20:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753840#M495</link>
      <description>&lt;P&gt;we don't have a documentation for compute requirements of fusion router. we only have the configuration guide. link to it is following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 20:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3753840#M495</guid>
      <dc:creator>kumaamit</dc:creator>
      <dc:date>2018-11-27T20:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3754338#M497</link>
      <description>&lt;P&gt;Thank you. For the future, I would recommend providing a document on compute requirements or, at the minimum, a list of recommended devices that can be used as the Fusion router role. I know the Fusion router isn't necessary part of the fabric, but it plays a vital role&amp;nbsp;during the planning phases of rolling out DNA.&lt;U&gt;&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 13:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3754338#M497</guid>
      <dc:creator>devnetdan</dc:creator>
      <dc:date>2018-11-28T13:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3759866#M514</link>
      <description>&lt;P&gt;Is this for a lab or production network? If the latter, then a Cisco firewall makes more sense than fusion router, cost permitting. Better to punt inter-VRF traffic up to the firewalls, thereby properly securing the networks from one another, which is presumably the aim of separate VRFs in the first place. You only need to factor in the stateful performance hit on the firewall - i.e. not IPS. Try to keep VRFs to a minimum and rely more on TrustSec.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 23:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/3759866#M514</guid>
      <dc:creator>shillings</dc:creator>
      <dc:date>2018-12-07T23:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/4107174#M2310</link>
      <description>&lt;P&gt;Hi can you do SDA without the fusion device and still achieve full segmentation using SGTs? Or do you at least require a fusion router to access shared services or can shared services be placed in the same VN as all other traffic and just rely on SGTs for segmentation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 09:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/4107174#M2310</guid>
      <dc:creator>rays</dc:creator>
      <dc:date>2020-06-22T09:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNA Fusion Router - Device Model</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/4107188#M2311</link>
      <description>&lt;P&gt;Not 100% sure what you're asking so I've covered a few angles.&lt;/P&gt;&lt;P&gt;Yes, you can place all your corporate endpoints into a single VN and leverage micro segmentation. Better to minimise the number of VNs anyway although a single VN won't work for everyone. Typically, you'd also want a separate VN for Guest traffic as well.&lt;/P&gt;&lt;P&gt;As for the SDA fusion firewall requirement, it's only really necessary in order to secure endpoint-to-endpoint traffic flows where both endpoints reside within the SDA fabric but they exist within a different VN to one another. Otherwise, the amount of route leaking required undermines the whole point of applying marco segmentation in the first place.&lt;/P&gt;&lt;P&gt;I don't see a need for a SDA fusion firewallI for traffic flows between a fabric endpoint and server located in your DC, assuming the fabric endpoint traffic feeds into the same VRF as the server or both client and server reside in the global table. Of course, you'd still have some specific route leaking so that traffic in each VRF can reach your DHCP server, for example.&lt;/P&gt;&lt;P&gt;There's nothing to stop you punting all fabric endpoint-to-server traffic through a firewall anyway but that's down to your security policy. You have to consider if a L3 stateful firewall will break any of your client-server traffic flows though.&lt;/P&gt;&lt;P&gt;Lastly, your shared services such as DNAC and ISE will typically reside in the global table but you can put them in a dedicated VRF if you want to.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 13:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-fusion-router-device-model/m-p/4107188#M2311</guid>
      <dc:creator>shillings</dc:creator>
      <dc:date>2020-06-22T13:59:40Z</dc:date>
    </item>
  </channel>
</rss>

