cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2180
Views
3
Helpful
3
Replies

Cisco SD-Access Lab in EVE-NG

ikadisenj66
Level 1
Level 1

Hello,

I have a physical Cisco DNAC appliance, and I’ve set up EVE-NG on ESXi to practice SD-Access. I’m a bit confused about which Cisco switch IOS images are compatible with EVE-NG for SD-Access lab simulations.

I want to ensure I use the right images to replicate SD-Access features like LISP, ISIS, VXLAN, MTU, etc configurations.

Any recommendations for specific IOS versions or devices that work well for this setup

3 Replies 3

Not sure what is supported on this platform folks might know here https://www.eve-ng.net/forum/

Please mark this as helpful or solution accepted to help others
Connect with me https://bigevilbeard.github.io

vishalbhandari
Spotlight
Spotlight

For replicating Cisco SD-Access features in EVE-NG, you need switch images that support advanced features like LISP, IS-IS, VXLAN, and enhanced MTU configurations. Below are recommendations and considerations for selecting the right Cisco IOS images for your setup:


Recommended Cisco Images for SD-Access Lab Simulations

  1. Cisco Catalyst 9300v or 9500v (Virtual Switches):

    • These are the preferred switches for SD-Access environments, as they natively support features like VXLAN, LISP, and IS-IS.
    • Available through Cisco CML or on Cisco's software download platform (with appropriate licensing).
  2. IOS-XE 16.x+ for CSR1000v:

    • The CSR1000v virtual router supports many SD-Access features, including VXLAN and LISP.
    • While primarily a router, it can be configured to simulate some Layer 2/3 SD-Access functionalities.
  3. IOSvL2:

    • A lightweight image for Layer 2 switching, available in Cisco CML.
    • Limitations: It does not natively support VXLAN or advanced SD-Access protocols but can still be used for basic VLAN and trunk setups.

Compatibility and Considerations

  1. Licensing:

    • Ensure you have the proper licenses for Cisco virtual images. Licensing is often required to unlock advanced features like VXLAN and IS-IS.
  2. Hardware Resources:

    • SD-Access features like VXLAN are resource-intensive. Ensure your ESXi host and EVE-NG deployment are configured with sufficient CPU and memory.
  3. MTU Considerations:

    • VXLAN requires an MTU of at least 1550 bytes. Ensure the EVE-NG interfaces and underlying ESXi network configurations support jumbo frames.

Suggested Lab Setup for SD-Access

  • DNA Center Physical Appliance:
    • Use your DNAC to manage and orchestrate SD-Access simulations in EVE-NG.
  • Cisco Catalyst 9300v/9500v:
    • As border nodes, control plane nodes, or edge nodes.
  • CSR1000v:
    • Simulate WAN connections or data center interconnects.
  • ISE Virtual Appliance:
    • For authentication and policy integration.
  • Catalyst WLC (9800-CL):
    • To integrate wireless in SD-Access.

How to Obtain Images

  • Cisco CML (Cisco Modeling Labs):
    • Comes with a variety of Cisco images optimized for lab use, including IOSv, IOSvL2, CSR1000v, and NX-OS.
  • Cisco Software Download Portal:
    • Download images if you have the appropriate Smart Account and licensing.

Torbjørn
VIP
VIP

Hi @ikadisenj66

The only virtual Cisco switch image that supports LISP and VXLAN is the Catalyst 9000v. You will need to obtain this through a CML refplat if you wish to use it in EVE-ng. Installation instructions can be found here: https://www.eve-ng.net/index.php/documentation/howtos/catalyst-9000v/. These are very heavy nodes, make sure you have enough resources or you'll be facing a lot of instability.

Note: I don't believe it is permitted to use these images outside of CML, so it is probably a better idea to use CML for this instead. 

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev