01-23-2018 11:34 PM - edited 03-08-2019 05:25 PM
Hello, all!
I have read a lot of documentation about DNA but still have some questions.
1) What is the purpose of using underlay/overlay conception in SD-ACCESS? The only reason i see is to allow any devices not change its IP if they change their location. But may be there are some other reasons?
2) Does anyone know something about Virtual DNA Controller?
01-25-2018 12:26 AM
Hello Evgeniy,
1)The overlay is the main idea behind the fabric, once you have built the fabric, having the DNA controller, you don't need to define and configure vlans, trunks, spanning tree, SVIs and routing within the enterprise, which is really cool and reduces the overhead of operating an enterprise network, also the security part is more simple and more automated, as you can build the policies based on the SGT/Identity, not based on the IP.
so overall concept of operating a network is different, more simple and more automated.
compared to WLC/AP once AP joins the controller, you don't think much of the capwap traffic flow, you think only of the wireless part, and user traffic going out from the controller, and so in the fabric, you will think of the end point, and how traffic is going out of the border.
i hope that helps.
2)for the virtual DNA center, it is not officially available as a product, not even for partners to do PoC or Labs.
01-28-2018 07:34 PM
You wrote
1)The overlay is the main idea behind the fabric, once you have built the fabric, having the DNA controller, you don't need to define and configure vlans, trunks, spanning tree, SVIs and routing within the enterprise, which is really cool and reduces the overhead of operating an enterprise network, also the security part is more simple and more automated, as you can build the policies based on the SGT/Identity, not based on the IP.
These are advantages of overlay network WITH DNA controller. But i am asking about only underlay/overlay.From my point of view, It gives me cool ability for roaming users to move from one part of network to another.
Anything else?
07-13-2018 06:30 AM
04-28-2018 05:13 AM - edited 05-01-2018 01:10 PM
Please refer to the below mentioned URL:
https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/software-defined-access/white-paper-c11-739642.html
DNA Center appliance is only available as a physical appliance.
VM for it is not supported.
05-07-2018 11:16 AM
08-15-2018 03:42 AM
Hi Evgeniy,
The reason for an overlay and underlay is to have an abstract level of carrying and segmenting data which runs through the network. With the use of an overlay we are able to keep specific information about the end-host such as source/destination MAC and IP, QoS, SGT and VNI, which is used by our Leafs and Borders to make right forwarding and security decisions. Furthermore, we are removing the need for Spanning-tree within the fabric because all traffic is routed, and we make good use of uplinks as ECMP preferably is part of the underlay.
It's easier to expand the underlay as intermediate devices doesn't have end-host information. They only care about forwarding traffic between VTEP's.
/Anders
09-04-2018 05:46 AM
2.DNA center is only available on the DN1-HW-APL (DNA Center appliance) by Cisco
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide