Purpose of the document
This document describes the general recommendations or best practices when designing and deploying the Cisco SD-Access technology. The document assumes that the reader has a general overview of Cisco's SD-Access for Distributed Campus architecture, it's components and operation.
Best Practice
Transit Control Plane node is part of your underlay network and primarily only needs to have reachability in the transport network towards Border Nodes (Default and Anywhere) and Cisco DNA Center in the Cisco's SD-Access for Distributed Campus architecture. Transit Control Plane node does not need to install all known routes in the Enterprise Network into the Routing Information Base. It basically can leverage your Default Border Nodes for any connectivity towards Cisco DNAC and DDI resources. It also needs to have underlay connectivity towards your Border Nodes (Default and Anywhere RLOCs) in multiple fabric sites. It is running the control plane protocol to provide reachability to end devices like hosts etc between different fabric sites. It must not be in the data plane forwarding towards Centralized resources like above.
At the time of writing this document, Cisco DNA Center automates the overlay config for Transit Control Plane node and it would also set up eBGP sessions between Border Nodes and Transit Control Plane nodes (Cisco DNA Center picks up private AS 65540). One of the best practice recommendations here is to ensure that there is no misconfiguration done on the Transit Control Plane nodes where network operators could end up configuring the same BGP AS as Border Nodes if there is already a BGP AS configured (due to BGP AS was configured manually) and unfortunately, for example, worst-case scenario, it matched your Fabric Border Nodes AS. Then this would configure IBGP between Transit Control Plane nodes and Fabric Border Nodes. The implication is that this would result in routing issues for Cisco's SD-Access Network.
Conclusion
Please ensure that the underlying transport network is configured correctly so that the above best practices can be taken into consideration when planning to deploy Cisco's SD-Access for Distributed Campus architecture.
Additional Information
Please refer to below parent page and specific Cisco SD-Access for Distributed Campus with SD-Access Transit page for more information.
https://community.cisco.com/t5/networking-documents/sd-access-resources/ta-p/3812030
https://community.cisco.com/t5/networking-documents/cisco-sd-access-for-distributed-campus-with-cisco-sd-access-as-a/ta-p/3837269#toc-hId--1703369038