Cisco SD-Access Lab in EVE-NG
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-17-2024
05:18 AM
- last edited on
11-17-2024
06:13 AM
by
shaiksh
Hello,
I have a physical Cisco DNAC appliance, and I’ve set up EVE-NG on ESXi to practice SD-Access. I’m a bit confused about which Cisco switch IOS images are compatible with EVE-NG for SD-Access lab simulations.
I want to ensure I use the right images to replicate SD-Access features like LISP, ISIS, VXLAN, MTU, etc configurations.
Any recommendations for specific IOS versions or devices that work well for this setup
- Labels:
-
SD-Access

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-17-2024 05:21 AM - edited 11-17-2024 05:22 AM
Not sure what is supported on this platform folks might know here https://www.eve-ng.net/forum/
Connect with me https://bigevilbeard.github.io
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-17-2024 07:44 AM
For replicating Cisco SD-Access features in EVE-NG, you need switch images that support advanced features like LISP, IS-IS, VXLAN, and enhanced MTU configurations. Below are recommendations and considerations for selecting the right Cisco IOS images for your setup:
Recommended Cisco Images for SD-Access Lab Simulations
Cisco Catalyst 9300v or 9500v (Virtual Switches):
- These are the preferred switches for SD-Access environments, as they natively support features like VXLAN, LISP, and IS-IS.
- Available through Cisco CML or on Cisco's software download platform (with appropriate licensing).
IOS-XE 16.x+ for CSR1000v:
- The CSR1000v virtual router supports many SD-Access features, including VXLAN and LISP.
- While primarily a router, it can be configured to simulate some Layer 2/3 SD-Access functionalities.
IOSvL2:
- A lightweight image for Layer 2 switching, available in Cisco CML.
- Limitations: It does not natively support VXLAN or advanced SD-Access protocols but can still be used for basic VLAN and trunk setups.
Compatibility and Considerations
Licensing:
- Ensure you have the proper licenses for Cisco virtual images. Licensing is often required to unlock advanced features like VXLAN and IS-IS.
Hardware Resources:
- SD-Access features like VXLAN are resource-intensive. Ensure your ESXi host and EVE-NG deployment are configured with sufficient CPU and memory.
MTU Considerations:
- VXLAN requires an MTU of at least 1550 bytes. Ensure the EVE-NG interfaces and underlying ESXi network configurations support jumbo frames.
Suggested Lab Setup for SD-Access
- DNA Center Physical Appliance:
- Use your DNAC to manage and orchestrate SD-Access simulations in EVE-NG.
- Cisco Catalyst 9300v/9500v:
- As border nodes, control plane nodes, or edge nodes.
- CSR1000v:
- Simulate WAN connections or data center interconnects.
- ISE Virtual Appliance:
- For authentication and policy integration.
- Catalyst WLC (9800-CL):
- To integrate wireless in SD-Access.
How to Obtain Images
- Cisco CML (Cisco Modeling Labs):
- Comes with a variety of Cisco images optimized for lab use, including IOSv, IOSvL2, CSR1000v, and NX-OS.
- Cisco Software Download Portal:
- Download images if you have the appropriate Smart Account and licensing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-17-2024 11:30 PM
Hi @ikadisenj66,
The only virtual Cisco switch image that supports LISP and VXLAN is the Catalyst 9000v. You will need to obtain this through a CML refplat if you wish to use it in EVE-ng. Installation instructions can be found here: https://www.eve-ng.net/index.php/documentation/howtos/catalyst-9000v/. These are very heavy nodes, make sure you have enough resources or you'll be facing a lot of instability.
Note: I don't believe it is permitted to use these images outside of CML, so it is probably a better idea to use CML for this instead.
Get in touch: https://torbjorn.dev
