Showing results for 
Search instead for 
Did you mean: 

Design Recommendation


To briefly describe this company has this main product, drones, who is revolving around in testing, management and mass produce 

HQ/Branches* 200 sites, different sizes between 10 to
1500 Employees
Drone Landing/Staging Ports800 sites
LABS30 sites, hardware close development
Test Benches30 sites, custom IT set-ups
Production Sites15 sites, custom IT set-ups

*Scenario: We will have multiple IoT Devices, 3 Devices per Employee, yet a bit unclear

1. How would you architect and template the network?

2. How specific would you create the production network?

FYI It's asking for a very modern approach.


Ok so far I came up with this very high level Architecture,

  • Aside from a primary On-Prem location, HQ will be having an extra backup site for incident recovery deployed in the cloud connected with ACI multisite orchestrator, also cross-connected to all branches over L3OUT via SDWAN technology
  • Using Cisco Firepower 41xx for the N/S E/W Traffic in HQ and FTDv in the HQ backup site, Also Cisco Secure Endpoint security and SecureX for End User Control/Policing
  • Using ACI also for the rest of those sites

I don't know how different those other environments(i.e. Landing/Staging Ports, Labs, Test benches, production) should be connected/designed? specifically production..

these are all I know about this project requirements and that's the catch!, please guess work the design as much possible...

Thanks Folks

9 Replies 9

Kasun Bandara
VIP Advocate VIP Advocate
VIP Advocate

is this real scenario or assignment?

Please rate this and mark as solution/answer, if this resolved your issue
Good luck

No a real one...

Leo Laohoo
VIP Community Legend VIP Community Legend
VIP Community Legend
  1. If you want this done right, get a reputable systems integrator involved. 
  2. If you want to "learn", do number 1.  

Georg Pauwen
VIP Master VIP Master
VIP Master


highly interesting and challenging project ! Based on the information you have provided, you are dealing with about 1100 sites. Which would suggest some sort of DMVPN approach. Does this company already have an existing infrastructure in place ?

well for the sake of simplicity, let's just say this going to be a greenfield....

Leo Laohoo
VIP Community Legend VIP Community Legend
VIP Community Legend

What is the budget for this work?


Leo Laohoo
VIP Community Legend VIP Community Legend
VIP Community Legend

@Aaron_un wrote:

Infinite budget but cannot pay for a reputable systems integrator?

HAHAHAHAHA ... Busted -- This is homework!


you have plenty of options: for the HQ and larger branch sites, you could use ASR-100x routers (there are numerous models). For all other sites, keeping the DMVPN in mind, you could use e.g. the ISR 921 routers. That would be the routers only, you need switches as well.

There is a tool on the Cisco website that lets you select routers based on business requirements:

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers