Module 1 Slides
Module 1 Slides
Enterprise Architecture
ENCOR (350-401) Topics RID: 1.1.1.1
R1
Gig 0/1
.1
172.16.1.0 /24
.2
•Enterprise Architecture Gig 0/1
AS 65001
RID: 2.2.2.2
R2
•Virtualization Technologies Gig 0/2
.2
10.1.1.0 /24
•Infrastructure Technologies
.1 Lo1:
Gig 0/1 2000:1::1/64
RID: 3.3.3.3
R3
•Network Management
.5
0/ 1
Gig
.
2
20
0/
00
Gig
3
:2::
19
30
1/6
8.5
.0 /
100
•Network Security
1.1
00
ps
00
Mb 0:2::
1.1
Mb
.4 / Gig 0
ps
8.5
20
10
30
0
19
•Network Automation
/1
2/6
0
AS 65002
.6
.2
Gig
AS 65004
/1
RID: 4.4.4.4 RID: 6.6.6.6
ISP1 ISP2
•Exam Preparation
Gi
.1 g 0/ 0 /2
g .6
2 Gi
20 Gi 2 30
2000:3::1/64
Lo1:
3.0 RID: 5.5.5.5 /
g0
/1 g 0/ .4
.11 Gi 13
3.0 .2 .5 .1
/3 3.0
0 INET 20
AS 65003
Your Instructor
• Kevin Wallace
• Written a bunch of books & made a ton of video courses for Cisco Press
Collapsed Core
Core Layer
Layer
Distribution
Collapsed
Three-Tier
CoreArchitecture
Architecture
Layer A two-tier
A network
topology
topology
wheredivided
the Core
into and
the Access,
Distribution
Layers
Distribution,
have been
and consolidated.
Core layers.
Access Layer
Spine-Leaf Design for Data Centers
Logically, One Switch
Spine Switches
Leaf Switches
Nodes
On-Premise vs. Cloud Designs
Internet
VPN
Private WAN
MPLS
Metro Ethernet
Considerations
• With a Cloud deployment, there’s no need to maintain local redundant power or hardware.
• With a Cloud deployment, you pay for resource usage instead of purchasing physical hardware.
• Many deployments, called Hybrid deployments, combine both On-Premise and Cloud deployments.
Fabric Capacity Planning
Higher Costs
• Redundant Components
• UPS/Generator
• FHRP
Redundant Design
Types of Backups
• Full: Backs up all data.
• Power
• HVAC
• Floor Space
• Power
• HVAC • Power
• Floor Space • HVAC
• Server Hardware • Floor Space
• Synchronized Data • Server Hardware
IP: 10.1.1.100
DG: 10.1.1.1
PC 1
Virtual Router Redundancy Protocol (VRRP)
Internet
10.1.1.1
Advertisement Interval (1 second)
Virtual Router
R1 Gig 0 4 R2
/1: 10 / 2
Master .1.1.1 0 . 1 .1.2 Backup
Master
/24 / 1: 1
Gig 0
SW1
IP: 10.1.1.100
DG: 10.1.1.1
PC 1
Gateway Load Balancing Protocol (GLBP)
The MAC address of The MAC address of
10.1.1.1 is 10.1.1.1 is
1111.1111.1111. 2222.2222.2222.
Internet
AVG
R1 R2
• Round-Robin
AVF Virtual IP: 10.1.1.1 AVF
MAC: 1111.1111.1111 MAC: 2222.2222.2222
Host-Dependent
•
• Weighted ARP
ARP SW1 What is the MAC address
What is the MAC address of 10.1.1.1?
of 10.1.1.1?
PC1 Active
ActiveVirtual
VirtualForwarder
Gateway (AVG)
(AVF) PC2
Responds to ARP queries
Forwardsasking
trafficforoffthe
of MAC
the local
address
subnet.
of a default gateway.
Default Gateway: 10.1.1.1 Default Gateway: 10.1.1.1
Stateful Switchover (SSO)
RP1 Neigh
borsh
ip
R1 ip
R2
o r s h
eig h b
N
RP2
The Main Issue: Failing over to a backup route processor might cause
routing protocol neighborships to reset.
Stateful Switchover (SSO)
RP1 Neigh
borsh
ip
R1 ip
R2
o r s h
eig h b
N
RP2
SSO: Sync (Config and State Information)
The Secondary Issue: Packets might be dropped until the forwarding
table is rebuilt.
Stateful Switchover (SSO)
RP1
CEF Neigh
borsh
ip
R1 ip
R2
o r s h
eig h b
N
RP2
SSO: Sync (Config and State Information)
AP 1 AP 2 AP 3
Wireless Deployment Options
VLAN 100 VLAN 100
WLC1 WLC2
CAPWAP Tunnels
Network:
AP1 10.1.1.0/24 AP2
10.1.1.50 10.1.1.50
Wireless Deployment Options
VLAN 100 VLAN 200
WLC1 CAPWAP WLC2
Anchor Foreign
Controller Controller
CAPWAP Tunnels
10.1.1.50 10.1.1.50
Wireless Deployment Options
Cisco FlexConnect:
• Configure and control remote wireless network
• Similar to Layer 3 roaming with CAPWAP
Central Switched:
• Normal CAPWAP mode of operation
• Typically not the recommended mode
Local Switched:
• Map user traffic to VLAN on adjacent switch
• Control and management traffic still sent over CAPWAP to WLC
Location Services
Location Services
-45 dBm
-75 dBm
Location Services
Cisco Solutions:
• Real-Time Location Services (RTLS)
• Cisco DNA Spaces
• Cisco Meraki platform
Software-Defined WAN
(SD-WAN)
Overview of SD-WAN Technology
Overview of SD-WAN Technology
Enterprise WAN:
• Dedicated circuits traditionally used
• Provide reliability and security
• Rise in cloud usage requires simplicity
Overview of SD-WAN Technology
Inspection and
Security Services
Inspection and
Security Services
MPLS Circuit
SD-WAN
Controller
Cisco SD-WAN:
• Data plane
• Control plane
• Management plane
• Orchestration plane
SD-WAN Implementation
vManage: User interface Management &
Orchestration
vBond: Orchestration and provisioning Plane
Data
Cisco vEdge: Edge routers
Plane
SD-WAN Implementation
Cloud Physical
Data Data
Center Center
LTE
MPLS
Main Satellite
Campus
BR2
Secure provisioning
and configuration
BR1
SD-WAN Implementation
Cloud Physical
Data Data
Center Center
Main Satellite
Campus Edge Router Software Platforms:
BR2
• CSR 1000v Router
• vEdge Cloud Router running Viptela OS
BR1
cisco.com/go/sdwandemos
Software-Defined
Access (SD-Access)
Overview of SD-Access Technology
SD-Access Advantages:
• Next-generation policy enforcement
• Security Group Access Control Lists (SGACLs)
• Policies are based on identity rather than addresses
Overview of SD-Access Technology
SD-Access Advantages:
• Secure network segmentation
• Virtualization of physical network
• Separate virtual networks can have separate policies
Overview of SD-Access Technology
Campus Fabric
Overview of SD-Access Technology
Campus Fabric
Overview of SD-Access Technology
Overlay Network
Underlay Network
Overview of SD-Access Technology
SD-Access Fabric
PHYSICAL
On-site Server Room
SD-Access Fabric
Fabric Edge Nodes
SD-Access Fabric
Fabric Edge Nodes
Traditional Wireless:
CAPWAP Tunnel between SD-Access Fabric
AP and WLC for all traffic
On-site Server Room
SD-Access Wireless:
CAPWAP Tunnel between SD-Access Fabric
AP and WLC only for
management traffic
VXLAN Tunnel:
Data from AP to network
On-site Server Room
SD-Access Fabric
Quality of Service (QoS)
Do You Need QoS?
Gig Fast E IP WAN
SW1 R1
Speed Mismatch
Server 1 Gig
Gig Gig
Server 2 Gig SW2
Periodic
Congestion
3 Categories of QoS
Less Strict
DiffServ
Strict
IntServ
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
Best
VoIP
VoIP Effort
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Common QoS Mechanisms
• Classification and
Marking
• Queuing
• Congestion Avoidance
• Policing and Shaping
• Link Efficiency
Wi-Fi Multimedia (WMM)
Tag Control
Information Bytes
CoS Bits
Type of Service (ToS) Byte
Traffic Class Byte in IPv6
IPv4 or IPv6 Packet
ToS Byte
1 2 3 4 5 6 7 8
IP Precedence
DSCP
RED Drop Ranges
RED Profiles
Probability of Full Dropping
Discard
100 %
Drop Drop Drop
Profile Profile Profile
for for for
AF13, AF12, AF11,
AF23, AF22, AF21,
AF33, & AF32, & AF31, &
25 % AF43 AF42 AF41
Average
25 30 35 100 Queue
Depth
CIR = Bc / Tc
CIR (Committed Information Rate) = AVERAGE speed over the period of a second
Bc (Committed Burst) = Number of bits (for shaping) or bytes (for policing) that are deposited in the token bucket
during a timing interval
128 kbps
Tc (Timing Interval) = The interval at which tokens are deposited in the token bucket
Line Speed
Tc 1 Tc 2 Tc 3 Tc 4 Tc 5 Tc 6 Tc 7 Tc 8
Timing Intervals
Switching Mechanisms
Process Switching
Process Switching
Process Switching:
• Oldest method for Cisco IOS switching
• Every packet is inspected by CPU
Process Switching
Process Switching
Process Switching:
• Processor is directly involved with every packet
• Not ideal in modern networks
• Available on every Cisco router platform
• Debugging uses process switching
Cisco Express Forwarding (CEF)
Cisco Express Forwarding (CEF)
CEF Benefits:
• Less CPU-intensive than older switching methods
• Distributed CEF (dCEF) allows line card forwarding
• CEF Forwarding Information Base (FIB)
• CEF Adjacency Table
Cisco Express Forwarding (CEF)
Forwarding
Information
Base
Cisco Express Forwarding (CEF)
Adjacency
Table
SW1
198.51.100.0 /24
Gig 0/1 .1
R1
Gig 0/2 .1
CEF Demo 203.0.113.0 /24
Gig 0/1 .2
R2
Gig 0/2 .1
192.0.2.0 /24
SW2
CAM vs. TCAM
CAM vs. TCAM
SW1
Fa
1/
Fa 1/0/13
0/
14
Fa 0/3
Fa
0/
3
Fa 0/1 Fa 0/1
Fa 0/2 Fa 0/2
SW2 SW3
MAC Address MAC Address
0011.bbda.ea00 0014.69ac.2000
FIB vs. RIB
FIB vs. RIB
BEST PATH